Yakir Kadkoda and Assaf Morag from Aqua Security discuss the potential risks and attack vectors associated with compromised Docker registries.
They highlight scenarios where attackers can exploit private tokens to access container images and search for sensitive information, expanding their attack surface.
They also explain the danger of having write access to container registries, which could allow attackers to backdoor images, facilitating initial access and lateral movement within the network.
Watch the full episode: https://ku.bz/5RKVBGlQR
Post #1202
504
Forwarded from KubeFM