bitcoin
bitcoin

$81131.293825 USD

4.61%

ethereum
ethereum

$2629.223982 USD

5.70%

tether
tether

$0.999644 USD

0.06%

bnb
bnb

$762.001372 USD

0.94%

xrp
xrp

$1.419903 USD

7.09%

usd-coin
usd-coin

$0.999900 USD

0.01%

solana
solana

$111.987892 USD

5.89%

tron
tron

$0.337691 USD

0.55%

zcash
zcash

$1568.013373 USD

5.10%

hyperliquid
hyperliquid

$93.260937 USD

6.24%

dogecoin
dogecoin

$0.087155 USD

3.41%

monero
monero

$565.955936 USD

6.55%

chainlink
chainlink

$12.346409 USD

4.60%

cardano
cardano

$0.223297 USD

4.51%

unus-sed-leo
unus-sed-leo

$8.875656 USD

-0.19%

Cryptocurrency News Video

What is Kubernetes security and how does a cluster actually get hacked?

Sep 19, 2026 at 04:27 pm K8s Under Attack

#kubernetes #k8s #containersecurity Kubernetes security defends four layers. Clusters fall through the workload layer: one reachable pod, five moves, cluster-admin. One reachable pod becomes cluster-admin in five moves, and every move rides a single line of YAML that someone typed on purpose. This video walks the real chain: foothold, service account token, RBAC escalation, container escape, cloud pivot. Then it shows the one control that cuts each link. In this video you will learn: - Why the workload layer, not the API server, is where most Kubernetes compromises start - How IngressNightmare (CVE-2025-1974, CVSS 9.8) turned one request into cluster-wide secret access - Why every pod ships a live API credential and the one line that stops it: automountServiceAccountToken: false - How a ClusterRoleBinding to cluster-admin and wildcard verbs turn one pod into the whole cluster - Why privileged: true plus a hostPath mount is a container escape without a kernel exploit - The five controls from the NSA/CISA hardening guide that break each link of the chain For platform engineers, SREs and security teams who run or review Kubernetes clusters in production. Sources: Red Hat State of Kubernetes Security Report 2024 (89% of organisations had at least one container or Kubernetes incident in 12 months); Wiz Research on CVE-2025-1974 IngressNightmare (6,500+ exposed admission controllers); Kubernetes docs on service account tokens and Pod Security Admission (PSP removed in v1.25); NSA/CISA Kubernetes Hardening Guide v1.2; Wired on the 2018 Tesla cryptojacking incident. Chapters follow the five steps of the compromise chain, then the fixes. K8s Under Attack is produced by Wiz, the cloud security platform that maps attack paths across Kubernetes and cloud accounts. Source: https://www.redhat.com/en/resources/state-kubernetes-security-report-2024-overview Subscribe to K8s Under Attack for one real cluster compromise chain, and the manifest line that stops it, every week. #kubernetes #k8s #containersecurity #RBAC #cloudnative #kubernetessecurity #devsecops #cloudsecurity #containers Chapters: 00:00 - What Kubernetes security is: four layers, one that gets attacked 00:51 - Step 1: the foothold (IngressNightmare) 02:03 - Step 2: the service account token 03:18 - Step 3: RBAC escalation to cluster-admin 04:33 - Step 4: container escape with privileged and hostPath 05:41 - Step 5: the pivot to the cloud account 06:44 - The five fixes that cut the chain 08:02 - One manifest away
Video source:Youtube

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other videos published on Sep 20, 2026