Tag: kubernetes
-
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August…
-
Token-Manipulation in Kubernetes-Management Hat-Schwachstelle gefährdet Cluster-Token in RHACM
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-rhacm-schwachstelle-cluster-tokens-argocd-umgehen-a-f7682eade53dede7ce8c599efb002e5a/
-
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the Rancher management plane and every downstream Kubernetes cluster it manages. This issue is tracked as CVE-2026-44945 and GHSA-v584-7w32-jwpq, affecting Rancher releases 2.11.0 through 2.11.15, 2.12.0 through 2.12.11, 2.13.0 through 2.13.7, and 2.14.0 through 2.14.1. Rancher has…
-
Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected hub cluster. This vulnerability is tracked as CVE-2026-10090 and affects the Application Subscription controller, specifically the multicluster-operators-subscription. It has a CVSS v3.1 score of 9.9…
-
Frontier AI Is Driving Urgency for Application Resilience and Security
Frontier AI models are challenging organizations to respond to AI-fueled attacks at unprecedented speed. At the same time, the rapid deployment of AI-powered services, automated processes, and real-time decision systems leveraging Kubernetes-based environments puts new pressures on digital infrastructure. The urgency has never been greater, and application delivery and security must keep pace. Traffic patterns..…
-
BSidesSF 2026 Sandboxes, Seccomp And Syscalls: Chasing Isolation In Kubernetes
Tags: kubernetesPresenter: Mark Manning Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-sandboxes-seccomp-and-syscalls-chasing-isolation-in-kubernetes/
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Laufzeitautorisierung für KI-Agenten: Warum Zugriffskontrolle innerhalb der Sitzung wichtiger wird
KI-Agenten verändern die Sicherheitsarchitektur in Unternehmen. Sie greifen autonom auf Datenbanken, Cloud-Konsolen, Kubernetes-Cluster oder SSH-Hosts zu und führen dort Aktionen mit hoher Geschwindigkeit aus. Klassische Identitäts- und Zugangskontrollen reichen dafür nur bedingt aus: Sie prüfen häufig, ob ein Zugriff erlaubt ist, aber nicht granular genug, was während der Sitzung tatsächlich geschieht. Laufzeitautorisierung setzt genau an……
-
Kubernetes Runtime Threats Explained
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/kubernetes-runtime-threats-explained

