- Engineer — Plan: GKE users running Config Connector should audit the service account’s IAM permissions and restrict who can submit YAML to affected clusters — a limited K8s principal could escalate to GCP org-level access via the connector’s delegated authority. No public PoC or active exploitation, but the attack path is now documented; tighten Config Connector RBAC and review org-level bindings this quarter.
- SOC/IR — Learn: A new confused-deputy escalation path from K8s YAML to GCP org control is worth adding to the analyst mental model for GKE environments, but there are no IOCs or active campaigns to hunt. File as a technique to watch if hunting lateral movement in GCP-connected clusters.
- Leader — Skip