logo

Google Kubernetes Clusters Suffer Widespread Exposure to External Attackers

ID: 04639034-d832-51b4-a9a9-99fe1064053f

STIX ID: report--04639034-d832-51b4-a9a9-99fe1064053f

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-01-25

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Orca Security disclosed a GKE authentication misconfiguration dubbed 'Sys:All' in which administrators binding the Kubernetes 'system:authenticated' group unintentionally grant access to any Google-account holder; researchers found hundreds of reachable vulnerable clusters (and estimate the true scope may exceed one million), demonstrated proof-of-concept compromises that exposed credentials and internal services, and prompted Google to issue mitigations (including blocking cluster-admin binding in GKE 1.28+), while advising least-privilege and continuous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.