← Back to feed
research Unit 42

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Unit 42 Kubernetes

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The po...

Read the full story Unit 42 →

Related Coverage

research SAML: A fractal of bad design Trail of Bits · Sep 21 research Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO Kaspersky Securelist · Sep 21 research From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies Unit 42 · Sep 21