logo

Kubernetes UI Tools Turn into a Weapon

ID: 50261530-e940-52dc-81d0-f150734552bb

STIX ID: report--50261530-e940-52dc-81d0-f150734552bb

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2021-11-18

Date Updated: 2026-04-26

...
...

This report examines how misconfigured Kubernetes UI tools (Weave Scope, Kubernetes Dashboard, Octant) exposed on the internet can grant attackers full visibility and control over clusters—allowing shell access to pods, manipulation of deployments, and retrieval of secrets. The authors enumerated exposed instances via Shodan, observed signs of active exploitation (including TeamTNT and Tsunami-related activity), and recommend hardening, access controls, allow-listing images, runtime protections, and blocking malicious domains and binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.