logo

Kubernetes Grey Zone: Risks in Managed Cluster Middleware

ID: 76167888-0877-5386-a166-466738220265

STIX ID: report--76167888-0877-5386-a166-466738220265

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2023-06-12

Date Updated: 2026-05-01

...
...

This blog post examines security risks introduced by managed cluster middleware (MCM) in cloud-managed Kubernetes offerings (AKS, EKS, GKE), demonstrates two attack chains—privilege escalation via Node Problem Detector custom plugins and Fluent Bit ConfigMap poisoning—that can achieve periodic root execution on hosts, token exfiltration, lateral movement, and persistence, and recommends mitigations such as avoiding root containers, using namespace granularity, CSP-side image minification, and increased transparency about worker-node components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.