Exploring Google Cloud Default Service Accounts: Deep Dive and Real-World Adoption Trends
ID: aa3ef63f-d287-5851-aef4-b42b20439b6e
STIX ID: report--aa3ef63f-d287-5851-aef4-b42b20439b6e
Feed Name: Datadog Security Labs
This research analyzes how Google Cloud default service accounts and access scopes expose GCE and GKE workloads to over-privileged access via the metadata server, enabling attackers to enumerate permissions and use OAuth tokens to read GCS and pull private images—especially when unrestricted or default scopes are applied. It demonstrates credential theft from a compromised pod in GKE, provides practical auditing commands, and recommends mitigations including enabling Workload Identity Federation, enforcing the automatic grant restriction policy, and tightening scopes/roles. Prevalence data shows that over a third of compute instances and nearly half of GKE clusters use the default service account, with significant portions operating under risky scopes and many clusters lacking Workload Identity Federation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
