CuraSec

tag: Kubernetes · 1 items

  • Engineer — Learn: Research details how node-level root access lets an attacker abuse SPIFFE/SPIRE to harvest SVIDs for co-located workloads, effectively pivoting laterally using stolen workload identities. No CVE or configuration fix is available, but teams running SPIFFE/SPIRE on Kubernetes should review node isolation boundaries and treat node compromise as full workload-identity compromise for that host.
  • SOC/IR — Plan: This documents a concrete post-exploitation TTP: harvesting co-located SPIFFE SVIDs after gaining K8s node root; worth building detections for anomalous SPIFFE/SPIRE API calls or unexpected workload identity usage patterns this quarter if your estate includes SPIRE-enabled clusters.
  • Leader — Learn: Technical research on workload identity abuse in Kubernetes with no active exploitation signal; useful context for understanding the blast radius of a compromised K8s node in environments that rely on SPIFFE/SPIRE for zero-trust workload auth, but requires no leadership action now.