Session

"I Own your Cluster" -Taking over AWS EKS cluster with Chain Attack

This presentation explores a research that reveals serious flaws in the AWS Elastic Kubernetes Service (EKS). We will examine two security issues in this session that could affect thousands of EKS clusters and pose serious security risks and the attack methodology I have developed for this service. Will talk about a chain attack that takes advantage of these flaws to take over K8s node and clusters, exposing the risk of unauthorized access and data compromise in Kubernetes environments on AWS.

In this session, we'll talk about how attackers with restricted access can bypass security measures, breach secured pods, and access privileged KubeAPI.

After that, we will analyze the AWS EKS architecture to highlight the vital parts that enable these attacks. You will learn about the intricacies of the attack chain and how it takes advantage of the AWS cloud infrastructure.

Chen Shiri

Cyber Security Researcher, Accenture Security

Tel Aviv, Israel

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top