Tag: kubernetes security
2 articles

Kubernetes Operators Expose Hidden Security Risks
A recent discovery revealed that Kubernetes Operators, like IBM Turbonomic, can harbor hidden security risks, including granting excessive access to sensitive cluster data, putting administrative tokens and credentials at risk. Meet OperTraitor, an innovative, open-source tool that helps you uncover these threats by analyzing operator permissions and identifying potential security gaps.

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft
Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.