All CosmicBytez Labs articles tagged #Kubernetes, across news, security advisories, how-to guides, and projects.
Critical Kyverno flaw lets a namespace-scoped policy invoke generator.apply() with an arbitrary namespace, creating RoleBindings in kube-system.
A CVSS 9.9 flaw in the StackGres Kubernetes operator lets a low-privilege tenant escalate to full cluster admin rights.
A CVSS 9.9 flaw in multicloud-operators-subscription lets tenants bypass security controls via malicious HelmRelease CRs, enabling privileged Helm execution.
CVSS 9.3 critical: KubeVirt's FakeFish BMC emulator ignores provided credentials, letting any user claim admin access.
A critical CVSS 9.9 flaw in the MaaS API allows any pod within a Kubernetes cluster to bypass the Kuadrant AuthPolicy gateway by forging X-MaaS-Username and X-MaaS-Group headers, enabling full privilege escalation without authentication.
A critical vulnerability in Kata Containers prior to 4.0.0 allows a pod user to load an arbitrary TOML file on the host through an unvalidated annotation, leading to root-level code execution and full container escape.
A critical privilege escalation vulnerability in Red Hat's Multicluster Engine for Kubernetes allows a tenant administrator to exploit the ClusterCurator controller to mint cluster-scoped tokens, bypassing namespace isolation.
A critical privilege escalation flaw in Red Hat Advanced Cluster Management for Kubernetes allows a namespace-scoped user to hijack cluster-admin privileges by pointing a Channel resource at a malicious Helm repository.
A CVSS 10.0 vulnerability in Microsoft Azure Kubernetes Service allows unauthenticated attackers to escalate privileges over the network due to missing...
A critical symlink validation flaw in KubeVirt's virt-handler lets authenticated OpenShift users with edit access in a single namespace escalate to arbitrary.
A stored cross-site scripting vulnerability in vCluster Platform allows attackers to inject and execute arbitrary JavaScript via the name field of a...
A high-severity security bypass in Argo Workflows (CVSS 8.1) allows users with Workflow creation permissions to escape templateReferencing: Strict mode,...
A high-severity vulnerability in Argo CD's ServerSideDiff feature allows authenticated users to read Kubernetes Secret data in cleartext, affecting...
Learn how to use Trivy to scan container images, Dockerfiles, Kubernetes manifests, and Terraform for vulnerabilities and misconfigurations — then...
The Trivy supply chain attack has expanded dramatically beyond GitHub Actions: malicious Docker Hub images (versions 0.69.4–0.69.6) carry an infostealer,...
A critical command injection vulnerability in kubectl-mcp-server allows unauthenticated attackers to execute arbitrary OS commands through unsanitized...
Step-by-step guide to deploying Falco as a Kubernetes runtime security engine. Covers Helm installation, custom rule authoring, Falcosidekick alerting...
Researchers uncover VoidLink, an 88,000-line Zig-based malware framework built with AI assistance that targets AWS, Azure, GCP, and Kubernetes environments.
Implement network microsegmentation in Kubernetes with Network Policies. Covers default deny, allow rules, namespace isolation, egress policies, and debugging.
Securely manage Kubernetes secrets using External Secrets Operator. Covers ESO installation, SecretStore configuration, syncing from Azure Key Vault and...
Build a production-grade K3s cluster on Proxmox/bare metal with Longhorn storage, Traefik ingress, cert-manager, and ArgoCD for GitOps.
Welcome to the first issue of the CosmicBytez Labs newsletter! This week: major security vulnerabilities, Kubernetes best practices, and cloud...
Learn essential Docker security practices including image scanning, runtime protection, network isolation, and secrets management for production environments.