GKE/Gmail vulnerability: notes and tips
ID: 7147c86e-71b8-5606-ab03-62f20aecd252
STIX ID: report--7147c86e-71b8-5606-ab03-62f20aecd252
Feed Name: Expel Blog
Security researchers have identified a GKE misconfiguration where the system:authenticated group can include any Google-authenticated account (including external Gmail accounts), which may allow attackers to take control of Kubernetes clusters; researchers estimate up to 250,000 clusters could be at risk. The report emphasizes misconfigurations as a major Kubernetes security problem, recommends auditing role bindings (especially system:anonymous, system:unauthenticated, and system:authenticated) and scoping permissions, and points to investigative resources such as a Kubernetes mind map and cheat sheet for mapping attacker tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
