TGViewer
Kubesploit Kubesploit @kubesploit · 2.13K subscribers
Post #941 335

Forwarded from KubeFM

In this KubeFM episode, Hillai and Ronen, security researchers at Wiz, explore the intricacies of hacking Alibaba Cloud's Kubernetes cluster.

They share their experiences and insights on identifying and exploiting vulnerabilities, mainly focusing on misconfigurations and their impact on cloud security.

You will learn:

- How Hillai and Ronen gained access to a Kubernetes cluster through a Postgres database.
- How they moved laterally and managed to obtain push and pull rights to a private container registry.
- Recommendations for securing multi-tenant Kubernetes clusters and maintaining environment hygiene.

Watch (or listen to) it here: https://kube.fm/hacking-alibaba-ronen-hillai

🙏 Many thanks to Sysdig for supporting our work and sponsoring this episode. Make sure to check out their Kubernetes security checklist https://sysdig.com/content/c/sysdig-kubernetessec?x=o_J3ln&utm_source=kubefm&utm_medium=referral&utm_campaign=podcast

With @Birthmarkb "🤌" Farrell
More from @kubesploit
  1. Oct 7, 2026This tutorial teaches how to secure Kubernetes AI platforms with RBAC, NetworkPolicy, secr…
  2. Oct 7, 2026This week on Learn Kubernetes Weekly 204: 🧠 Workload-Aware Scheduling in Kubernetes 1.37…
  3. Oct 6, 2026WaaS creates browser-accessible Linux and Windows desktops as Kubernetes resources, with G…
  4. Oct 6, 2026This tutorial teaches how to preserve the real client IP behind an Istio ambient gateway w…
  5. Oct 6, 2026Dilshan Wijesooriya, Senior Cloud Engineer at Coolblue, explains how upgrading from Amazon…
  6. Oct 6, 2026Why can a Go service be OOM-killed while its heap looks healthy? The heap is only part of…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →