logo

Lateral movement risks in the cloud and how to prevent them – Part 3: from compromised cloud resource to Kubernetes cluster takeover

ID: 47e99aa2-d9b7-52b7-855b-595773ea15a5

STIX ID: report--47e99aa2-d9b7-52b7-855b-595773ea15a5

Feed Name: Wiz Blog

Date Published: 2023-02-23

Date Updated: 2026-05-01

...
...

This research post analyzes cloud-to-Kubernetes lateral movement techniques across AWS EKS, GCP GKE, and Azure AKS, focusing on abuse of IAM/AAD credentials, exposed kubeconfig files, and container registry image tampering, with nuanced differences by cloud provider (e.g., AKS local accounts granting cluster-admin by default, GKE/IAM integration, and EKS RBAC via aws-auth). It presents three best practices to reduce risk: avoid long-term keys in workloads (use roles/managed identities), remove and tightly secure kubeconfig files and API access (e.g., private endpoints and strict network controls), and restrict/lock down container registries with least privilege, immutability, and no public access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.