Making Sense of Kubernetes Initial Access Vectors Part 2 - Data Plane
ID: 53baf540-0af7-539b-864e-0a0b0cf884f3
STIX ID: report--53baf540-0af7-539b-864e-0a0b0cf884f3
Feed Name: Wiz Blog
This blog (part two of a series) examines Kubernetes initial access on the data plane, detailing how attackers pivot from compromised workloads through service account/RBAC abuse, container/neighbor escapes, misconfigured NodePort exposure, untrusted images/supply chain, and execution-as-a-service platforms. It references prior research (e.g., runc "Leaky Vessels" and cross-tenant AI service issues) and provides layered mitigations: strict namespace separation and PSS, least-privilege RBAC, network policies, user namespaces, sandboxing (gVisor/Kata/seccomp/AppArmor), node-per-tenant scheduling, and robust image trust/signing with admission controls, emphasizing defense-in-depth to reduce lateral movement and escalation risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
