Accessibility Statement Skip Navigation
  • Back to Global Sites
  • +972-77-2005042
  • Blog
  • Journalists
  • GDPR
  • Send a Release
PR Newswire: news distribution, targeting and monitoring
  • News
  • Products
  • Contact
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • Telephone

    • +972-77-2005042 from 8 AM - 11 PM IL

    • Contact
    • Contact

      +972-77-2005042
      from 8 AM - 11 PM IL

  • When typing in this field, a list of search results will appear and be automatically updated as you type.

  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR

KTrust Uncovers Critical Security Vulnerability in Kubernetes, Exposing Enterprise Cloud Applications to Risk


News provided by

KTrust

13 Jan, 2025, 15:00 IST

Share this article

Share toX

Share this article

Share toX

TEL AVIV, Israel, Jan. 13, 2025 /PRNewswire/ -- KTrust's security research has revealed critical attack techniques exploiting interconnected vulnerabilities in Kubernetes, exposing enterprise cloud applications to severe risks. Researchers demonstrated how attackers could chain multiple attack vectors to gain complete control over cloud infrastructure, potentially remaining undetected while stealing sensitive data and maintaining persistent access across enterprise environments.

Continue Reading
Only Attackers, Outsmart Attackers , KTrust’s management left to right: Snir Maizlik CBO, Nadav Toledo CEO, Nadav Aharon-Nov CTO
Only Attackers, Outsmart Attackers , KTrust’s management left to right: Snir Maizlik CBO, Nadav Toledo CEO, Nadav Aharon-Nov CTO

Kubernetes is the backbone of modern cloud applications but comes with hidden security risks that many organizations overlook. Many organizations are inadequately prepared to handle these risks, often due to security teams' limited platform experience or the misconception that Kubernetes presents lower risks than traditional attack vectors like browsers and email systems.

KTrust's advanced research lab, which creates virtual replicas of Kubernetes-based cloud infrastructures, identified these vulnerabilities using an automated Red Team algorithm that mimics sophisticated threat actors. Their team successfully breached a typical secured cluster environment similar to those used by financial institutions and government agencies, gaining full pod control. The attack began by exploiting the 'Dirty Pipe' vulnerability discovered in 2022, which remains prevalent in many systems. This allowed attackers to steal root user passwords, escalate privileges, breach containers, and take control of worker nodes.

The researchers demonstrated how attackers could further escalate their attack by obtaining sensitive access credentials, impersonating authorized users, and performing various malicious actions, including reconfigurations, accessing sensitive data, and disabling critical services. The team also showed how attackers could maintain persistent access while evading detection by monitoring systems. "One of our customers was shocked when we demonstrated how their S3 bucket (personal data) could be accessed without proper permissions," said Nadav Aharonov, KTrust CTO.

These capabilities enable attackers to cause significant damage, from impersonating organizations in fraudulent activities to stealing sensitive data and disabling vital systems. "When it comes to Kubernetes, every vulnerability can become a critical access point for attackers," explained Nadav Aharon-Nov, CTO and Founder of Ktrust. "This discovery underscores the alarming vulnerabilities in our cloud infrastructure and highlights the growing threat of data theft and cyberattacks. Our unique lab is designed to stay several steps ahead of attackers and quickly identify vulnerabilities before they are widely exploited."

About KTrust

KTrust, a leader in Kubernetes security, focuses on ensuring secure cloud environments through its innovative platform. The company offers comprehensive solutions for identifying cloud security weaknesses, uncovering Kubernetes vulnerabilities, and providing real-time protection. Their approach specializes in active vulnerability detection, automated attack simulation, and proactive cloud environment defense. The platform ensures fully verified weaknesses with zero false positives and provides developers with practical mitigation tools across multiple layers. This solution significantly reduces the workload for development and security teams by over 95%, allowing them to focus on critical tasks.

The platform has gained the trust of global organizations and, through its advanced security capabilities, plays a crucial role in preventing cyberattacks.

KTrust was founded by Nadav Toledo, the CEO; Nadav Aharonov, the CTO; and Snir Mizlik, the CBO. The company is backed by AWZ Ventures, led by Yaron Ashkenazi.

Photo - https://mma.prnewswire.com/media/2596033/Ktrust.jpg

SOURCE KTrust

Modal title

Contact PR Newswire

  • +972-77-2005042
    from 8 AM - 11 PM IL

Global Sites

  • APAC
  • APAC - Traditional Chinese
  • Asia
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany

 

  • India
  • Indonesia
  • Israel
  • Italy
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland

 

  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921
Global Sites
  • Asia
  • Brazil
  • Canada
  • Csezh
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Israel
  • Italie
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
+972-77-2005042
from 8 AM - 11 PM IL
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • Cookie Settings
Copyright © 2026 Cision US Inc.