logoalt Hacker News

tlntoday at 12:36 PM1 replyview on HN

Have any of the cloud providers disclosed this?

"Once they have root on a single machine, agents rapidly escalate privileges and move laterally throughout the container-as-a-service infrastructure environment"

Sounds like ECS - IAM is mentioned.


Replies

bradfatoday at 12:56 PM

And Azure Key Vault mentioned. Not that either one was hacked or exploited but the agents got credentials and used them for something (which doesn’t seem fully disclosed). Given that the agents simply obtained totally allowed credentials, which were improperly protected, I don’t think either cloud provider would consider this a breach of their system. Valid credentials are valid. Customer screwed up protecting the credentials.