Kubernetes Exposed: One Yaml away from Disaster
ID: 33bdfa6d-51cd-57c7-b6da-ff387ec2e253
STIX ID: report--33bdfa6d-51cd-57c7-b6da-ff387ec2e253
Feed Name: Aqua Security Blog
This report presents a three-month investigation that uncovered 350+ publicly accessible Kubernetes clusters—many misconfigured to allow anonymous or proxied API access—resulting in roughly 60% showing active compromise by cryptomining and backdoor campaigns (notable actors/campaigns include Lchaia/xmrig, ssww, Dero, RBAC buster, and TeamTNT). It details what attackers can access (secrets, SCM tokens, registries, cloud credentials), demonstrates exploitation methods (daemonsets, host mounts, metadata service abuse, exposed internal services), provides IOC examples (malicious container images, Monero pool/wallet, leaked keys), and recommends mitigations such as enforcing RBAC/admission controls, securing kubectl proxy, auditing, and developer training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
