Plan
active
Post-Exploitation Identity Spoofing via SPIFFE/SPIRE on K8s Nodes
- Engineer — Learn: Research details how node-level root access lets an attacker abuse SPIFFE/SPIRE to harvest SVIDs for co-located workloads, effectively pivoting laterally using stolen workload identities. No CVE or configuration fix is available, but teams running SPIFFE/SPIRE on Kubernetes should review node isolation boundaries and treat node compromise as full workload-identity compromise for that host.
- SOC/IR — Plan: This documents a concrete post-exploitation TTP: harvesting co-located SPIFFE SVIDs after gaining K8s node root; worth building detections for anomalous SPIFFE/SPIRE API calls or unexpected workload identity usage patterns this quarter if your estate includes SPIRE-enabled clusters.
- Leader — Learn: Technical research on workload identity abuse in Kubernetes with no active exploitation signal; useful context for understanding the blast radius of a compromised K8s node in environments that rely on SPIFFE/SPIRE for zero-trust workload auth, but requires no leadership action now.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.