First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters
Attackers are exploiting Kubernetes RBAC to create backdoors and deploying DaemonSets to take over and hijack resources. The campaign is targeting at least 60 clusters and is caused by misconfigured API servers. The attacker gains persistence by creating a ClusterRole with admin-level privileges, b..