New attack vectors in EKS
ID: f069142f-a186-501d-b5a6-db5ec6132955
STIX ID: report--f069142f-a186-501d-b5a6-db5ec6132955
Feed Name: Wiz Blog
This report analyzes how AWS EKS Access Entries/Policies and EKS Pod Identity expand both administrative convenience and the attack surface, detailing adversary TTPs for lateral movement between cloud and Kubernetes (enumerating clusters and access mappings, escalating via RBAC/policy associations) and demonstrating a hostNetwork-based man-in-the-middle to intercept Pod Identity credentials from the 169.254.170.23 endpoint; it maps EKS access policies to Kubernetes roles (view, edit, admin, cluster-admin), highlights highly privileged APIs (CreateAccessEntry, AssociateAccessPolicy), and recommends least-privilege IAM/RBAC, namespace scoping, and considering IRSA to mitigate MitM risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
