logo

Kubernetes Exposed: One Yaml away from Disaster

ID: 33bdfa6d-51cd-57c7-b6da-ff387ec2e253

STIX ID: report--33bdfa6d-51cd-57c7-b6da-ff387ec2e253

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2023-08-08

Date Updated: 2026-04-26

...
...

This report presents a three-month investigation that uncovered 350+ publicly accessible Kubernetes clusters—many misconfigured to allow anonymous or proxied API access—resulting in roughly 60% showing active compromise by cryptomining and backdoor campaigns (notable actors/campaigns include Lchaia/xmrig, ssww, Dero, RBAC buster, and TeamTNT). It details what attackers can access (secrets, SCM tokens, registries, cloud credentials), demonstrates exploitation methods (daemonsets, host mounts, metadata service abuse, exposed internal services), provides IOC examples (malicious container images, Monero pool/wallet, leaked keys), and recommends mitigations such as enforcing RBAC/admission controls, securing kubectl proxy, auditing, and developer training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.