An Amazon EKS cluster can manipulate the networking of other EC2 instances, even those in other VPCs, thanks to the Amazon VPC CNI plugin for Kubernetes. This allows an attacker with access to an EKS cluster to potentially exploit services in other VPCs.
















