Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters
Researchers studying cybersecurity have found a vulnerability in Google Kubernetes Engine (GKE) that can allow hostile actors to take over a Kubernetes cluster by using their Google account.
The cloud security company Orca has called this major flaw Sys:All. The estimated number of active GKE clusters in the wild that are vulnerable to the attack vector is up to 250,000.
Security researcher Ofir Yakobi stated in a report that it "stems from a likely widespread misconception that the system: authenticated group in Google Kubernetes Engine includes only verified and deterministic identities, whereas it includes any Google-authenticated account read more Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters.
Get up to date on the latest cybersecurity news and enh...

