Making Sense of Kubernetes Initial Access Vectors Part 1 – Control Plane
ID: e7fbab7d-899c-5bef-958c-68b37e604d33
STIX ID: report--e7fbab7d-899c-5bef-958c-68b37e604d33
Feed Name: Wiz Blog
This article outlines a taxonomy of Kubernetes control plane initial access vectors and their security implications, emphasizing how misconfigurations and weak defaults can enable unauthenticated API access, kubeconfig credential leakage (notably long-lived AKS certs), misuse of kubectl proxy, insecure Kubelet API exposure, and publicly accessible management dashboards. It provides risk context and high-level detection and prevention guidance, underscoring that securing initial access is critical to limiting lateral movement and privilege escalation within clusters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
