Root on One Kubernetes Node Could Become Every Workload on It

Cryptographic workload identities cannot prove which process asked for them if an attacker controls the node making that claim. Unit 42 demonstrated the risk in SPIFFE/SPIRE.

Cryptographic workload identities cannot prove which process asked for them if an attacker controls the node making that claim. Unit 42 demonstrated the risk in SPIFFE/SPIRE.

McKesson confirmed unauthorised access to third-party applications and data exfiltration. ShinyHunters claims 284 million patient-related data rows, but the scale and data types remain unverified.

ReliaQuest says a stolen password and approved MFA push produced a valid session, but device trust blocked every attempt to reach company applications.