TGViewer
#! VulnCity #! VulnCity @vulncity · 247 subscribers
Post #100 207
📎 K8S Red Team Attack Chain

- Initial Access
Discover exposed API Server (6443) or Kubelet (10250).

- Enumeration
Enumerate pods, namespaces, RBAC permissions, and service accounts.

- Privilege Escalation
Abuse over-permissive RBAC to create or control workloads.
Malicious Pod Deployment
Mount the host filesystem using hostPath.

- Credential Access
Extract Secrets from environment variables or mounted volumes.

- Lateral Movement
Access databases, internal services, and additional cluster resources.

- Full Cluster Compromise
Gain host access, persistence, and potential control of the entire Kubernetes environment.

👀 به زودی یه مقاله کامل در مورد K8S Red Team توی قسمت بلاگ سایت منتشر می کنیم.

🆔 @vulncity
  • 💯 2
More from @vulncity
  1. Oct 1, 2026🚀 کمپین «شروع امن» VulnCity شروع شد! خیلی از استارتاپ‌ها و شرکت‌های کوچیک، نیاز به امنیت…
  2. Sep 27, 2026یک وبینار خوب در مورد ADCS از SpecterOps 🤖زیرنویس توسط Qwen 3.7 plus ایجاد شده است. کانال…
  3. Sep 27, 2026photo post
  4. Sep 13, 2026۴۰ نکته برای کاهش Attack Surface و افزایش امنیت سرورهای Linux دانلود فایل 🆔 @vulncity
  5. Sep 12, 2026📌 آسیب‌پذیری بحرانی GitLab با CVSS 10 یک آسیب‌پذیری Path Traversal با شناسه CVE-2026-8570…
  6. Sep 7, 2026قابلیت‌های امنیتی Windows server 2025 📎 امنیت در زیرساخت‌های Windows Server همیشه یکی از…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →