Google Kubernetes Clusters Suffer Widespread Exposure to External Attackers
ID: 04639034-d832-51b4-a9a9-99fe1064053f
STIX ID: report--04639034-d832-51b4-a9a9-99fe1064053f
Feed Name: Dark Reading
Date Published: 2024-01-25
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Orca Security disclosed a GKE authentication misconfiguration dubbed 'Sys:All' in which administrators binding the Kubernetes 'system:authenticated' group unintentionally grant access to any Google-account holder; researchers found hundreds of reachable vulnerable clusters (and estimate the true scope may exceed one million), demonstrated proof-of-concept compromises that exposed credentials and internal services, and prompted Google to issue mitigations (including blocking cluster-admin binding in GKE 1.28+), while advising least-privilege and continuous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
