containerd's September 1 advisory says a container restored from an untrusted checkpoint can run as root with full capabilities despite a restrictive Pod spec. Admission approves the spec, and restore then replays saved state without the step that turns a spec into kernel settings.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
Storm-3068 hijacked one account via self-service password reset and ran an Azure DevOps pipeline authorized for 50-plus resources, Microsoft says. No exploit was involved, so the fix sits in the reset flow and in what one account's pipelines can reach.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence45
Argo CD 3.5 puts mutual TLS in front of its repo-server by default, closing the unauthenticated path a July 2026 Kustomize flaw used to run commands. Clusters without their own certificates get it on upgrade, so older GitOps installs should take 3.5 as a security patch.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence45
Unit 42 open-sourced OperTraitor, a Kubernetes operator RBAC scanner, and used it to find CVE-2026-6389, rated CVSS 8.8, in IBM's Turbonomic. An attacker who gets into an operator inherits its service account's permissions, so those grants decide how far a single compromise reaches.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence45
Justin O'Leary's ConfigConfusion technique turns on the fact that Google's Config Connector makes every cloud call with its own service account, so a tenant who can create one IAMPolicyMember inherits whatever that account is allowed to grant.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence58
A ZoomEye query counted hosts answering on Kubernetes' default API port on 2026-09-20. The write-up keeps the unit honest: a host that responded to one port query, with no authentication test behind the number.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives40
- Confidence60
Admission control and RBAC decide who may fetch a Secret object. Neither is in the path once the kubelet has copied the value into a container, and an agent runtime is where that gap gets expensive.
Reality
- Evidence68
- Adoption15
- Hype gap+12
- Incentives45
- Confidence62
OpenAI ran the ExploitGym benchmark with safety classifiers disabled and sandbox egress limited to one Artifactory proxy. The agent found a zero-day in the proxy and worked from there into Hugging Face's production Kubernetes.
Reality
- Evidence46
- Adoption55
- Hype gap+20
- Incentives75
- Confidence52
Unit 42 showed that spoofing the cgroup data a SPIRE agent reads during workload attestation makes it hand over a co-located workload's SVID, and released a tool so defenders can size the loss per node.
Reality
- Evidence68
- Adoption22
- Hype gap+18
- Incentives65
- Confidence55
The ingress-to-pod hop needs one nginx annotation and a pod that can serve TLS; the database hop needs one client flag. Pod-to-pod is the hop the dev.to inventory can only close with a mesh, and that is where the money goes.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+15
- Incentives28
- Confidence55
The aws-auth ConfigMap is deprecated and, by The New Stack's account, hard to audit. A 2025 report it cites puts four in five EKS clusters still on it. That is the estate, not an edge case.
Reality
- Evidence28
- Adoption20
- Hype gap+22
- Incentives82
- Confidence32