Skip to main content

Share story

Security Infrastructure

Kubernetes permissions can expose Google Cloud organizations through Config Connector

Kubernetes permissions can expose Google Cloud organizations through Config Connector Image: Primary
A configuration of Google Kubernetes Config Connector can let a user with limited cluster access grant themselves broad Google Cloud permissions, security researcher Justin O'Leary found. The user needs permission to create an IAM policy resource in a namespace watched by the connector; the connector then submits the requested change through its own Google service account. If that service account has organization-level authority, Google Cloud accepts a request the Kubernetes user could not make directly. The exposure depends on both broad connector permissions and access to submit the relevant resource. Google says the connector is working as designed and recommends limiting its authority.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products
Products

Bird.com raises $450 million in JPMorgan-led debt financing

Bird.com, a customer messaging company, raised $450 million in debt financing led by JPMorgan Chase & Co., Bloomberg reported. The company is seeking to return cash to its investors and employees. The transaction adds debt capital...

Capital Infrastructure
Capital Infrastructure

Hubble Network raises $200 million for satellite Bluetooth network

Satellite startup Hubble Network raised $200 million in a new funding round, Bloomberg reported, taking its valuation to $1.6 billion. The company is working on a network of spacecraft intended to provide global Bluetooth connecti...

Security Infrastructure
Security Infrastructure

F5 patches exploited BIG-IP APM flaw as U.S. agencies face Friday deadline

F5 has released security updates for a critical BIG-IP APM flaw that it says attackers have exploited to run code remotely. BIG-IP APM manages access to organizational networks and applications. The vulnerability affects configura...

Robotics Capital
Robotics Capital

Tekever reaches first close of funding round targeting $580 million

Portuguese surveillance drone developer Tekever has reached the first close of a funding round targeting $580 million, Bloomberg reports. The company is seeking acquisitions following that close. The $580 million figure is the tar...

Infrastructure AI
Infrastructure AI

German and Dutch agencies launch €40 million AI chip design challenge

Germany's SPRIND and the Netherlands' NADI have launched a joint €40 million challenge to fund European AI chip design. The agencies plan to select seven teams for an initial stage, awarding each €2.6 million, then advance three t...