Understanding the threat landscape for Kubernetes and containerized assets
ID: 9a242454-f403-58ec-8bf7-58ec35d496d8
STIX ID: report--9a242454-f403-58ec-8bf7-58ec35d496d8
Feed Name: Microsoft Security
**Microsoft Threat Intelligence: Container and Kubernetes Threats — executive summary:** This report outlines common attack vectors against containerized environments (compromised accounts, vulnerable/misconfigured images, environment misconfigurations, app- and node-level attacks, and unauthorized traffic), details a case study where the AzureChecker password-spray campaign (Storm-1977) led to tenant compromise and deployment of >200 containers for cryptomining, and provides detection capabilities, hunting queries, and best-practice mitigations across the CI/CD, deployment, runtime, identity, image, and network layers to reduce risk and detect active abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
