logo

Understanding the threat landscape for Kubernetes and containerized assets

ID: 9a242454-f403-58ec-8bf7-58ec35d496d8

STIX ID: report--9a242454-f403-58ec-8bf7-58ec35d496d8

Feed Name: Microsoft Security

Threat Score
65/100

Date Published: 2025-04-23

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

**Microsoft Threat Intelligence: Container and Kubernetes Threats — executive summary:** This report outlines common attack vectors against containerized environments (compromised accounts, vulnerable/misconfigured images, environment misconfigurations, app- and node-level attacks, and unauthorized traffic), details a case study where the AzureChecker password-spray campaign (Storm-1977) led to tenant compromise and deployment of >200 containers for cryptomining, and provides detection capabilities, hunting queries, and best-practice mitigations across the CI/CD, deployment, runtime, identity, image, and network layers to reduce risk and detect active abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.