logo

Making Sense of Kubernetes Initial Access Vectors Part 2 - Data Plane

ID: 53baf540-0af7-539b-864e-0a0b0cf884f3

STIX ID: report--53baf540-0af7-539b-864e-0a0b0cf884f3

Feed Name: Wiz Blog

Date Published: 2024-11-13

Date Updated: 2026-05-01

...
...

This blog (part two of a series) examines Kubernetes initial access on the data plane, detailing how attackers pivot from compromised workloads through service account/RBAC abuse, container/neighbor escapes, misconfigured NodePort exposure, untrusted images/supply chain, and execution-as-a-service platforms. It references prior research (e.g., runc "Leaky Vessels" and cross-tenant AI service issues) and provides layered mitigations: strict namespace separation and PSS, least-privilege RBAC, network policies, user namespaces, sandboxing (gVisor/Kata/seccomp/AppArmor), node-per-tenant scheduling, and robust image trust/signing with admission controls, emphasizing defense-in-depth to reduce lateral movement and escalation risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.