Azure Kubernetes Bug Lays Open Cluster Secrets
ID: 5f436736-6739-5dfe-9afa-fb0cbbbb2e85
STIX ID: report--5f436736-6739-5dfe-9afa-fb0cbbbb2e85
Feed Name: Dark Reading
Mandiant disclosed a critical AKS privilege-escalation vulnerability where an attacker with command execution in a pod could access an undocumented WireServer endpoint to retrieve TLS bootstrap tokens and generate kubelet certificates, enabling full cluster compromise; the flaw impacted AKS clusters using Azure CNI and Azure Network Policy, did not require root or hostNetwork, and Microsoft patched the issue—organizations are advised to audit AKS configurations, rotate Kubernetes secrets, enforce strict pod security and NetworkPolicies, and improve logging and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
