Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters
ID: 69df0cd1-9f70-5d16-b6bf-56315fbda881
STIX ID: report--69df0cd1-9f70-5d16-b6bf-56315fbda881
Feed Name: The Hacker News
Researchers disclosed a GKE misconfiguration (Sys:All) where administrators granting privileges to the Kubernetes system:authenticated group— which includes any Google-authenticated account—can enable external attackers with a Google account and an OAuth token to gain cluster access and perform follow-on activities (lateral movement, cryptomining, data theft). Orca Security estimated up to ~250,000 clusters affected; Google mitigated the risk by preventing cluster-admin bindings to system:authenticated in GKE 1.28+, adding detection rules to Security Command Center, and notifying affected users while advising removal of unsafe bindings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
