logo

New attack vectors in EKS

ID: f069142f-a186-501d-b5a6-db5ec6132955

STIX ID: report--f069142f-a186-501d-b5a6-db5ec6132955

Feed Name: Wiz Blog

Date Published: 2024-02-09

Date Updated: 2026-05-01

...
...

This report analyzes how AWS EKS Access Entries/Policies and EKS Pod Identity expand both administrative convenience and the attack surface, detailing adversary TTPs for lateral movement between cloud and Kubernetes (enumerating clusters and access mappings, escalating via RBAC/policy associations) and demonstrating a hostNetwork-based man-in-the-middle to intercept Pod Identity credentials from the 169.254.170.23 endpoint; it maps EKS access policies to Kubernetes roles (view, edit, admin, cluster-admin), highlights highly privileged APIs (CreateAccessEntry, AssociateAccessPolicy), and recommends least-privilege IAM/RBAC, namespace scoping, and considering IRSA to mitigate MitM risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.