{"id":11346,"date":"2022-04-01T07:00:00","date_gmt":"2022-04-01T15:00:00","guid":{"rendered":"https:\/\/formtek.com\/blog\/?p=11346"},"modified":"2021-08-17T12:19:57","modified_gmt":"2021-08-17T20:19:57","slug":"security-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks\/","title":{"rendered":"Security: Hackers Exploit Kubernetes Misconfigurations, but also Use it as a Tool to Scale Their Attacks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Software misconfiguration is one of the easiest ways that a hacker can exploit software, and unfortunately, misconfiguration problems are common.  <a href=\"https:\/\/outpost24.com\/blog\/Top-vulnerability-trends-and-how-to-fix-them\" data-type=\"URL\" data-id=\"https:\/\/outpost24.com\/blog\/Top-vulnerability-trends-and-how-to-fix-them\">One study found that more than 80 percent<\/a> of  systems were vulnerable because of misconfiguration problems &#8212; firewall, web server, application servers, and applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.hackerone.com\/blog\/rise-misconfiguration-and-supply-chain-vulnerabilities\" data-type=\"URL\" data-id=\"https:\/\/www.hackerone.com\/blog\/rise-misconfiguration-and-supply-chain-vulnerabilities\">Gartner said that misconfigurations<\/a> are typically self-inflicted problems.  95 percent of misconfiguration issues are due to mistakes or unintentional oversights of the organization.  In particular, moving software that was running on one machine to another is notorious for introducing security misconfigurations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s no surprise then that complex software like Kubernetes and containers often have misconfiguration issues. <a href=\"https:\/\/www.stackrox.com\/press-releases\/2020\/02\/stackrox-report-reveals-that-container-and-kubernetes-security-concerns-are-inhibiting-business-innovation\/\" data-type=\"URL\" data-id=\"https:\/\/www.stackrox.com\/press-releases\/2020\/02\/stackrox-report-reveals-that-container-and-kubernetes-security-concerns-are-inhibiting-business-innovation\/\">A Flexera study <\/a>found that 94 percent of container users had experienced a security vulnerability over the course of one year.  In that same study, 61 percent said that container and Kubernetes security misconfigurations were their biggest worry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just because the cloud infrastructure that you run on is certified as secure does not imply that the software that you&#8217;ve deployed into it will inherit that security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.intezer.com\/blog\/container-security\/new-attacks-on-kubernetes-via-misconfigured-argo-workflows\/\" data-type=\"URL\" data-id=\"https:\/\/www.intezer.com\/blog\/container-security\/new-attacks-on-kubernetes-via-misconfigured-argo-workflows\/\">A report from Intezer<\/a> found that &#8220;even if your cluster is deployed on a managed cloud Kubernetes service such as Amazon Web Service (AWS), EKS or Azure Kubernetes Service (AKS), the shared responsibility model still states that the cloud customer, not the cloud provider, is responsible for taking care of all necessary security configurations for the applications they deploy.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s interesting to note that Kubernetes is a favorite of hackers to exploit because of its complexity, but i&#8217;s also a favorite tool for hackers to use themselves when launching large-scale attacks.  Attacks by the Russian group known as &#8216;Fancy Bear&#8217; has employed Kubernetes clusters to conduct widespread and rapid-fire attacks to exploit many systems simultaneously at scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/saumitramdas\/\" data-type=\"URL\" data-id=\"https:\/\/www.linkedin.com\/in\/saumitramdas\/\">Saumitra Das<\/a>, CTO and Cofounder of Blue Hexagon, <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/nsa-and-gchq-warn-that-russian-hackers-frequently-brute-force-passwords-at-scale-using-kubernetes-clusters\/\" data-type=\"URL\" data-id=\"https:\/\/www.cpomagazine.com\/cyber-security\/nsa-and-gchq-warn-that-russian-hackers-frequently-brute-force-passwords-at-scale-using-kubernetes-clusters\/\">said that the attack<\/a> &#8220;used Kubernetes to orchestrate and scale their attacks to continuously attempt initial access into organizations. This implies high-level automation and semi-autonomous attack capabilities to target a wide list and then focus on where they are able to brute force in.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Software misconfiguration is one of the easiest ways that a hacker can exploit software, and unfortunately, misconfiguration problems are common. One study found that more than 80 percent of systems were vulnerable because of misconfiguration problems &#8212; firewall, web server,<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-hackers-exploit-kubernetes-misconfigurations-but-also-use-it-to-scale-their-attacks\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-11346","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=11346"}],"version-history":[{"count":2,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11346\/revisions"}],"predecessor-version":[{"id":11368,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11346\/revisions\/11368"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=11346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=11346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=11346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}