World Congress 2022 • Jun 15, 2022

Hacking Kubernetes: Live Demo Marathon

Andrew Martin

How fast can a single npm dependency compromise your Kubernetes cluster? Watch this live demonstration break container isolation to prove why active intrusion tripwires are your only failsafe.

Pause
Mute Enter Fullscreen
#1 about 5 min

Mapping the attack surface of a Kubernetes cluster

Starting a penetration test requires understanding how Linux container namespaces and orchestrator abstractions interact.

#2 about 7 min

Threat modeling techniques for cloud native infrastructure

Modeling adversaries from script kiddies to organized crime helps build proportionate and cost-effective security controls.

#3 about 7 min

Executing a software supply chain attack with dependencies

Abusing execution hooks in package managers allows attackers to steal context and establish reverse shells.

#4 about 9 min

Breaking out of overprivileged pods using host mapping

Misconfigured security policies that share the host process ID space allow attackers to manipulate root namespaces.

#5 about 10 min

Escaping unprivileged containers using the Dirty Pipe exploit

Overwriting out-of-bounds executable memory via execution symlinks allows an attacker to gain a root shell directly on the underlying host node.

#6 about 9 min

Pivoting from a compromised kubelet to cloud accounts

Enumerating orchestrator-injected secrets mapped on host volumes reveals credentials that can escalate privileges into wider cloud environments.

#7 about 3 min

Discussing container privilege escalation and volume security risks

Audience questions clarify the limits of rootless containers and highlight security risks introduced by shared volume mounts.

Matching moments

5:59 min

Live demonstration of vulnerability exploitation and zero trust mitigation

Jan Peer Stöcklmair Jan Peer Stöcklmair · WWC Europe 2026

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · WWC 2025

1:39 min

Introduction to Kubernetes security challenges and opportunities

Marc Nimmerrichter · WWC 2022

5:28 min

Executing a DNS exfiltration attack in Kubernetes

Ali Alp Ali Alp · WWC Europe 2026

4:27 min

Identifying software vulnerabilities and typical configuration weaknesses

Marc Nimmerrichter · WWC 2022

5:44 min

Demonstrating a container escape using kernel vulnerabilities

Marc Nimmerrichter · WWC 2022

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

Run your agents in Kubernetes: Build once, deploy anywhere. But really?

Michal Salanci

Senior Systems Engineer at ESET Cybersecurity

Michal Salanci
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg