
Ronen Shustin
@ronenshh
Followers
2K
Following
3K
Media
10
Statuses
70
With this research, we hope to raise awareness within the @kubernetesio community about this often-underestimated attack surface. ☁️⚠️.
0
0
5
This was a huge effort from the team. With every small primitive we discovered, we got closer—until we finally landed a full unauthenticated RCE. I had a ton of fun working on this research. ☸️👇.
We (+@sagitz_ @ronenshh @hillai) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX". The impact?. From zero permissions ➡️ to complete cluster takeover 🤯. This is the story of #IngressNightmare 🧵⬇️
3
3
51