Companies frequently ask SpecterOps some version of the same question: How are you using AI in offensive security, and how can we begin using it too? They want practical guidance. Which parts of an…
Serial Number: AV26-804 Date: August 11, 2026 Updated: September 24, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET…
Posted by Nathan Herz on Sep 23 Hello Kubernetes Community, An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symbolic link that…
Posted by Nathan Herz on Sep 23 Hello Kubernetes Community, A confused deputy attack exists in the StatefulSet controller that allows a user with namespace-scoped write permissions on StatefulSet and…
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis…
Analyser une compromission sur Amazon EKS revient à reconstituer des preuves réparties sur trois couches : le control plane Kubernetes managé, les nodes workers et les services AWS environnants. Cet…
Synacktiv a découvert une vulnérabilité d'exécution de code arbitraire sans authentification dans le composant repo-server d'ArgoCD, permettant potentiellement la compromission totale du cluster. Cet…
Durant l'audit d'un cluster Kubernetes, nous avons découvert une injection dans un template Helm déployé par ArgoCD. Étonnamment, il existe très peu de ressources concernant l’injection YAML dans un…
En 2025, le CSIRT Synacktiv a observé une augmentation significative des attaques et des compromissions ciblant les environnements Kubernetes. Le constat est que ces attaques sont vouées à continuer…
TLDR: CiliumHound is a BloodHound OpenGraph extension for auditing Cilium network policies. It ingests a folder of JSON or YAML policies and creates a searchable, Kubernetes namespace-scoped graph…
TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user…