The Ticking Supply Chain Attack Bomb of Exposed Kubernetes Secrets
ID: 5ca89951-7d68-5fb0-8d93-591ef0701312
STIX ID: report--5ca89951-7d68-5fb0-8d93-591ef0701312
Feed Name: Aqua Security Blog
This research analyzes the discovery of hundreds of base64-encoded Kubernetes secret files (.dockerconfigjson/.dockercfg) accidentally committed to public GitHub repositories; 203 of 438 candidates contained valid registry credentials (allowing pull/push), affecting private registries, Docker Hub, Quay, Red Hat, and a Fortune 500 artifacts repository (SAP). The study demonstrates that many open-source secret scanners miss encoded secrets by default, outlines real-world impact (including potential supply-chain attacks and exposed private images), and provides remediation guidance such as removing secrets from repos, using secrets managers, rotating credentials, and improving scanner rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
