Are you familiar with Sidecars in Kubernetes? We spoke to Magno Logan about the complex world of Kubernetes security and the silent but deadly vulnerabilities associated with sidecar containers. Magno shares his extensive research and insights on how attackers can exploit these vulnerabilities to stay hidden within a Kubernetes environment, posing significant threats beyond the commonly discussed crypto mining attacks. Magno spoke about common attack paths targeting Kubernetes clusters, from exploiting application vulnerabilities to leveraging exposed Kubernetes services and compromised valid accounts.
Guest Socials: Magno Logan
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:26) A bit about Magno Logan
(01:49) Kubernetes Common Threats Explained
(02:23) Kubernetes Cluster Attack Entry Points
(04:28) How attackers maintain persistent access in Kubernetes?
(05:30) Container Escape Explained
(07:03) Maintaining Persistence in Kubernetes Clusters
(08:18) What are Sidecars?
(10:43) How to secure your sidecars?
(12:33) Where can people learn more about this
(13:57) The Fun Section
Resources spoken about on the podcast
Mitre Att&ck Containers Matrix
Microsoft Threat Matrix
2023 What Kubernetes Security Looks Like Today Series- DevSecOps
IS THERE DEVSECOPS IN CLOUD? 🤔
How to Build a Modern Cyber Security Program in 2023
HOW TO BUILD A CLOUD SECURITY PROGRAM - MEDIA INDUSTRY
How to Accelerate your AWS Security Maturity in 2023
How to Build AWS Multi-Account Infrastructure with Security and Speed
HOW TO GET FEDRAMP CERTIFIED IN AWS CLOUD
HOW TO BUILD A CLOUD SECURITY PROGRAM WITH CONTAINERS
AWS Cloud Penetration Testing Explained with Example
AWS Goat - Cloud Penetration Testing
Getting Started with Hacking AWS ECS
GETTING STARTED WITH HACKING AWS CLOUD
AWS Reinvent 2022 - RECAP for Cloud Security Professionals!
AWS EKS EXPLAINED!
Story of a Cloud Architect & Blurry Lines of Control with AWS
BECOME A CLOUD SECURITY ARCHITECT IN 2023
AWS Threat Detection for NOT SO COMMON AWS Services Explained
Ransomware attacks in AWS
How to become a Cloud Native Security Architect?
Compliance as Code in Kubernetes
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
The Unbelivable Truth - Series 1 - 26 including specials and pilot
Lex Fridman Podcast