Researchers studying cybersecurity have found a vulnerability in Google Kubernetes Engine (GKE) that can allow hostile actors to take over a Kubernetes cluster by using their Google account.
The cloud security company Orca has called this major flaw Sys:All. The estimated number of active GKE clusters in the wild that are vulnerable to the attack vector is up to 250,000.
Security researcher Ofir Yakobi stated in a report that it “stems from a likely widespread misconception that the system: authenticated group in Google Kubernetes Engine includes only verified and deterministic identities, whereas it includes any Google-authenticated account read more Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
