<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Kubernetes Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Kubernetes.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts</title><link>https://elastic.co/security-labs/esql-completion-curl-wget-detection-triage</link><guid isPermaLink="false">cst-3130</guid><description>Elastic Security deployed a detection rule for curl and wget file transfers that uses ES|QL COMPLETION, an LLM-powered triage feature, to filter out legitimate cloud activity before alerts reach analysts. Running the rule on Elastic's production fleet for seven days, the system reduced noise by using deterministic filtering and LLM reasoning to distinguish between expected automation, CI/CD jobs, and potential attacker activity. The approach maintains security visibility for file transfer detection in cloud environments while eliminating false positives that would otherwise overwhelm security teams.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens</title><link>https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html</link><guid isPermaLink="false">cst-2778</guid><description>A Go-based botnet named NadMesh emerged in early July 2024, targeting exposed AI services to harvest AWS keys and Kubernetes tokens. The malware uses Shodan scanning to identify vulnerable instances of tools like ComfyUI, Ollama, and Gradio that are often deployed without adequate firewall protection. The operator's dashboard reportedly tracks over 3,800 unique AWS credentials stolen from these compromised systems.</description><pubDate>Fri, 17 Jul 2026 17:12:23 GMT</pubDate></item><item><title>Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters</title><link>https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html</link><guid isPermaLink="false">cst-41</guid><description>Argo CD, a Kubernetes deployment tool, contains an unpatched vulnerability in its repo-server component that allows unauthenticated code execution for attackers with network access to the internal port. The flaw could enable full cluster takeover and was reported to maintainers by Synacktiv, though no CVE or patch currently exists.</description><pubDate>Wed, 01 Jul 2026 19:40:06 GMT</pubDate></item><item><title>Microsoft named a leader in the Frost Radar for cloud and application runtime security</title><link>https://microsoft.com/en-us/security/blog/2026/07/01/microsoft-named-a-leader-in-the-frost-radar-for-cloud-and-application-runtime-security</link><guid isPermaLink="false">cst-324</guid><description>Frost &amp; Sullivan named Microsoft a visionary leader in its 2026 Frost Radar for Cloud and Application Runtime Security, recognizing the shift in cloud security from visibility and compliance to contextual risk reduction across the full technology stack. The report highlights that modern cloud environments demand unified platforms that correlate signals across infrastructure, applications, APIs, and workloads to prioritize exploitable vulnerabilities rather than severity alone. Leading platforms now integrate cloud detection and response with application detection and response into a single operational model spanning development, operations, and security teams.</description><pubDate>Wed, 01 Jul 2026 16:00:00 GMT</pubDate></item><item><title>CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms</title><link>https://microsoft.com/en-us/security/blog/2026/06/24/cnapp-evolution-how-microsoft-aligns-with-leading-cloud-risk-management-platforms</link><guid isPermaLink="false">cst-331</guid><description>Microsoft's Defender for Cloud is positioned as a leading Cloud-Native Application Protection Platform (CNAPP) that correlates risk signals across code, cloud, identity, and runtime environments to prioritize exploitable vulnerabilities rather than isolated findings. The CNAPP category is evolving from point solutions focused on visibility and compliance toward unified platforms that operationalize continuous risk reduction across the application lifecycle in multicloud and complex modern environments. Leading platforms now integrate development, operations, and security workflows to help teams address the most critical attack paths rather than managing overwhelming volumes of individual alerts.</description><pubDate>Wed, 24 Jun 2026 18:00:00 GMT</pubDate></item><item><title>PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</title><link>https://sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale</link><guid isPermaLink="false">cst-606</guid><description>SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.</description><pubDate>Thu, 07 May 2026 10:00:17 GMT</pubDate></item><item><title>Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity</title><link>https://wiz.io/blog/introducing-ai-cyber-model-arena-a-real-world-benchmark-for-ai-agents-in-cybersec</link><guid isPermaLink="false">cst-1348</guid><description>Wiz Research has created AI Cyber Model Arena, a benchmark that evaluates offensive AI security capabilities across 257 real-world scenarios including zero-day vulnerabilities, CVEs, API and web attacks, and cloud misconfigurations on AWS, Azure, Google Cloud, and Kubernetes. The benchmark measures what AI models and agents can accomplish in practical cybersecurity contexts.</description><pubDate>Thu, 12 Feb 2026 18:05:58 GMT</pubDate></item><item><title>Bringing Visibility to Kubernetes: Unified Inventory and Network Insight</title><link>https://wiz.io/blog/bringing-visibility-to-kubernetes</link><guid isPermaLink="false">cst-1402</guid><description>The article discusses improved visibility solutions for Kubernetes environments that consolidate inventory data and network information across multiple clusters, enabling better collaboration between platform operations and security teams.</description><pubDate>Fri, 24 Oct 2025 21:14:51 GMT</pubDate></item><item><title>Securing the Container Frontier: Kubernetes Trends Report 2025</title><link>https://wiz.io/blog/kubernetes-report-preview-2025</link><guid isPermaLink="false">cst-1504</guid><description>A new Kubernetes Security Report for 2025 examines the evolving threat landscape and defensive measures in container environments, highlighting both attack trends and security strategies. The report provides insights into the current state of Kubernetes security practices and challenges.</description><pubDate>Thu, 23 Jan 2025 14:00:00 GMT</pubDate></item><item><title>Kubernetes Audit Log “Gotchas”</title><link>https://wiz.io/blog/overcoming-kubernetes-audit-log-challenges</link><guid isPermaLink="false">cst-1528</guid><description>Kubernetes audit logs present challenges and security gaps for forensics and attack detection. Organizations using Kubernetes must understand these limitations to effectively investigate incidents and identify threats. Proper configuration and analysis of audit logs are essential for comprehensive security visibility in containerized environments.</description><pubDate>Thu, 14 Nov 2024 18:44:21 GMT</pubDate></item><item><title>Making Sense of Kubernetes Initial Access Vectors Part 2 - Data Plane</title><link>https://wiz.io/blog/kubernetes-data-plane</link><guid isPermaLink="false">cst-1530</guid><description>This article discusses Kubernetes data plane access vectors, focusing on the applications, container images, and execution-as-a-service workloads that operate within clusters. It is the second part of a series examining initial access methods in Kubernetes environments.</description><pubDate>Wed, 13 Nov 2024 17:04:16 GMT</pubDate></item><item><title>Defeating Kubernetes Privilege Escalation: A Cloud Detection &amp; Response Case Study</title><link>https://wiz.io/blog/defeating-kubernetes-privilege-escalation-a-cloud-detection-response-case-study</link><guid isPermaLink="false">cst-1559</guid><description>A case study examines how to detect and respond to privilege escalation attacks targeting Kubernetes environments in cloud deployments. The analysis emphasizes the need for rapid, heuristic-based, and contextual detection methods tailored to cloud infrastructure.</description><pubDate>Wed, 21 Aug 2024 16:00:00 GMT</pubDate></item><item><title>Stay safe with Wiz's winning hand for securing Kubernetes</title><link>https://wiz.io/blog/wiz-covers-owasp-top-10-for-kubernetes</link><guid isPermaLink="false">cst-1598</guid><description>Wiz has released guidance for securing Kubernetes environments aligned with OWASP's Kubernetes Top 10 framework, including reporting and remediation capabilities. The offering aims to help organizations identify and address security issues in container orchestration platforms.</description><pubDate>Tue, 23 Apr 2024 18:10:06 GMT</pubDate></item><item><title>Sailing Securely Across the SDLC: Introducing Wiz's Image Trust and Kubernetes Audit Log Collector</title><link>https://wiz.io/blog/sailing-securely-across-the-sdlc-introducing-wiz-s-image-trust-and-kubernetes-aud</link><guid isPermaLink="false">cst-1615</guid><description>Wiz has introduced Image Trust and Kubernetes Audit Log Collector, new capabilities designed to help organizations verify container image integrity and monitor Kubernetes control plane activity in near-real time. These tools aim to strengthen security throughout the software development lifecycle by preventing untrusted images from being deployed and detecting anomalous behavior.</description><pubDate>Mon, 18 Mar 2024 17:16:04 GMT</pubDate></item><item><title>NamespaceHound: protecting multi-tenant K8s clusters</title><link>https://wiz.io/blog/introducing-namespacehound-for-cross-tenant-violation-assessments</link><guid isPermaLink="false">cst-1617</guid><description>NamespaceHound is an open-source security tool designed to identify namespace isolation violations and unauthorized access risks in multi-tenant Kubernetes clusters. The tool helps detect configuration issues that could allow workloads to cross namespace boundaries or access resources without proper authentication.</description><pubDate>Wed, 13 Mar 2024 17:57:49 GMT</pubDate></item><item><title>Announcing the K8s LAN Party Challenge</title><link>https://wiz.io/blog/k8s-lan-party-challenge</link><guid isPermaLink="false">cst-1619</guid><description>A new Capture The Flag (CTF) event called the K8s LAN Party Challenge has been announced to test participant investigation skills and Kubernetes network knowledge. The competition appears designed to assess hands-on capabilities in container orchestration environments.</description><pubDate>Mon, 11 Mar 2024 14:06:14 GMT</pubDate></item><item><title>Announcing the Release of "Kubernetes Security for Dummies"</title><link>https://wiz.io/blog/kubernetes-security-for-dummies</link><guid isPermaLink="false">cst-1639</guid><description>Wiz has released a new guide titled "Kubernetes Security for Dummies" in collaboration with Wiley publications. The book provides comprehensive coverage of security practices and considerations for Kubernetes environments.</description><pubDate>Thu, 25 Jan 2024 14:14:24 GMT</pubDate></item><item><title>Unveiling eBPF: Harnessing Its Power to Solve Real-World Issues</title><link>https://wiz.io/blog/unveiling-ebpf-harnessing-its-power-to-solve-real-world-issues</link><guid isPermaLink="false">cst-1658</guid><description>This article examines how extended Berkeley Packet Filter (eBPF) technology can be applied to defend against Kubernetes attacks and discusses related security best practices. The piece explores practical applications of eBPF in detecting and preventing threats within container orchestration environments.</description><pubDate>Sun, 19 Nov 2023 22:06:56 GMT</pubDate></item><item><title>Key takeaways from the Wiz 2023 Kubernetes Security Report</title><link>https://wiz.io/blog/key-takeaways-from-the-wiz-2023-kubernetes-security-report</link><guid isPermaLink="false">cst-1662</guid><description>Wiz released its 2023 Kubernetes Security Report, which provides findings and recommendations on the security state of Kubernetes deployments. The report analyzes trends, vulnerabilities, and misconfigurations across containerized environments.</description><pubDate>Wed, 08 Nov 2023 16:37:49 GMT</pubDate></item><item><title>Ensuring Supply Chain Security: Verify container image integrity with the Wiz Admission Controller</title><link>https://wiz.io/blog/ensuring-supply-chain-security-verify-container-image-integrity-with-the-wiz-admi</link><guid isPermaLink="false">cst-1664</guid><description>Wiz has released an admission controller designed to enforce container image verification in Kubernetes environments, allowing organizations to restrict deployments to trusted images only. This tool addresses supply chain security concerns by preventing unauthorized or compromised container images from being deployed to production systems.</description><pubDate>Mon, 06 Nov 2023 17:00:00 GMT</pubDate></item><item><title>Announcing the EKS Cluster Games</title><link>https://wiz.io/blog/announcing-the-eks-cluster-games</link><guid isPermaLink="false">cst-1667</guid><description>Wiz is sponsoring a capture-the-flag competition called the EKS Cluster Games designed to test participants' investigation skills and Kubernetes knowledge.</description><pubDate>Wed, 01 Nov 2023 15:29:42 GMT</pubDate></item><item><title>Wiz enhances real-time threat detection and response capabilities to stop threats from becoming incidents</title><link>https://wiz.io/blog/wiz-runtime-sensor-is-generally-available-enhances-real-time-detection-and-response</link><guid isPermaLink="false">cst-1683</guid><description>Wiz announced general availability of its Runtime Sensor for Kubernetes, a tool designed to detect cloud attacks in real-time and provide response capabilities tailored to cloud-native environments. The sensor offers customizable detection options and response automation to help organizations prevent security incidents in containerized infrastructure.</description><pubDate>Tue, 12 Sep 2023 14:55:00 GMT</pubDate></item><item><title>Docker and Kubernetes, we have got you covered: Wiz simplifies compliance and security posture management for Docker and Kubernetes environments.</title><link>https://wiz.io/blog/docker-and-kubernetes-we-have-got-you-covered-wiz-simplifies-compliance-and-secur</link><guid isPermaLink="false">cst-1689</guid><description>Wiz announced new capabilities to help organizations manage security posture and compliance for Docker and Kubernetes environments against CIS benchmarks. The offering provides reporting and remediation guidance for identified issues.</description><pubDate>Mon, 21 Aug 2023 16:55:51 GMT</pubDate></item><item><title>Kubernetes API limitations in finding non-standard pods and containers</title><link>https://wiz.io/blog/kubernetes-api-limitations-in-finding-non-standard-pods-and-containers</link><guid isPermaLink="false">cst-1698</guid><description>Kubernetes environments contain several types of non-standard pods and containers, such as static pods, mirror pods, init containers, pause containers, and ephemeral containers, that may not be easily discoverable through standard API queries. Monitoring these non-standard workloads is important because they can exist outside typical visibility frameworks and may represent security blind spots in cluster observability.</description><pubDate>Wed, 19 Jul 2023 14:23:29 GMT</pubDate></item><item><title>Kubernetes Grey Zone: Risks in Managed Cluster Middleware</title><link>https://wiz.io/blog/kubernetes-grey-zone-risks-in-managed-cluster-middleware</link><guid isPermaLink="false">cst-1706</guid><description>The article examines security risks associated with middleware components in managed Kubernetes clusters. It discusses how organizations can identify and mitigate these risks to improve cluster security posture.</description><pubDate>Mon, 12 Jun 2023 15:42:33 GMT</pubDate></item><item><title>Wiz: First agentless cloud security vendor to attain CIS SecureSuite Vendor Certification for cloud-managed Kubernetes</title><link>https://wiz.io/blog/wiz-first-agentless-cloud-security-vendor-to-attain-cis-securesuite-vendor-certif</link><guid isPermaLink="false">cst-1723</guid><description>Wiz has achieved CIS SecureSuite Vendor Certification for cloud-managed Kubernetes compliance, becoming the first agentless vendor to do so. The certification enables organizations to generate compliance reports and remediate issues against CIS Benchmarks for Kubernetes environments.</description><pubDate>Tue, 18 Apr 2023 20:14:19 GMT</pubDate></item><item><title>From Pod Security Policies to Pod Security Standards – a Migration Guide</title><link>https://wiz.io/blog/from-pod-security-policies-to-pod-security-standards-a-migration-guide</link><guid isPermaLink="false">cst-1738</guid><description>Kubernetes removed Pod Security Policies (PSPs) in version 1.25, and organizations using the deprecated feature need to transition to Pod Security Standards (PSSs). This guide provides the steps and considerations for migrating from the legacy security mechanism to its modern replacement.</description><pubDate>Thu, 09 Mar 2023 17:27:05 GMT</pubDate></item><item><title>Lateral movement risks in the cloud and how to prevent them – Part 3: from compromised cloud resource to Kubernetes cluster takeover</title><link>https://wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-them-part-3-from-compromis</link><guid isPermaLink="false">cst-1747</guid><description>This blog post discusses lateral movement risks that enable attackers to move from compromised cloud resources into Kubernetes clusters, covering attacker tactics and defensive best practices for securing cloud environments.</description><pubDate>Thu, 23 Feb 2023 16:22:45 GMT</pubDate></item><item><title>Enhancing Kubernetes security with user namespaces</title><link>https://wiz.io/blog/enhancing-kubernetes-security-with-user-namespaces</link><guid isPermaLink="false">cst-1754</guid><description>Kubernetes v1.25 introduced user namespaces as a security feature to strengthen cluster isolation and protection. User namespaces enable better separation of user identities and processes within containers, reducing the blast radius of potential compromises. This feature helps organizations implement defense-in-depth strategies for Kubernetes deployments.</description><pubDate>Mon, 23 Jan 2023 15:29:10 GMT</pubDate></item><item><title>Wiz rapidly finds and removes risks across the container development lifecycle and entire cloud environment</title><link>https://wiz.io/blog/wiz-removes-risks-across-the-container-development-lifecycle</link><guid isPermaLink="false">cst-1781</guid><description>Wiz announced new capabilities designed to identify and prioritize security risks across containers, Kubernetes, and cloud environments using deep context and visibility without requiring agents. The solution integrates container development lifecycle protection with broader cloud environment security scanning.</description><pubDate>Mon, 24 Oct 2022 12:55:23 GMT</pubDate></item><item><title>Meet Wiz at KubeCon North America</title><link>https://wiz.io/blog/meet-wiz-at-kubecon</link><guid isPermaLink="false">cst-1783</guid><description>Wiz, a cloud security vendor, is attending and sponsoring KubeCon North America for the first time and plans to share guidance on securing container and Kubernetes environments.</description><pubDate>Wed, 19 Oct 2022 14:51:22 GMT</pubDate></item></channel></rss>