From Interview Questions to Cluster Damage: Adventures in k8s Cluster Hacking

Amit Serper

BSides NYC 2025 (0x05) · Day 1 · Tech - Red

In this insightful talk from BSides NYC, Amit Serper, a security researcher at CrowdStrike, delves into the often-overlooked security implications of Kubernetes' inherent complexity and native features. Co-prepared with Travis Low, the presentation explores how common interview questions about Kubernetes can unravel into sophisticated attack vectors, allowing adversaries to exfiltrate sensitive data and even cause widespread cluster damage using only built-in functionalities. The talk highlights that despite Kubernetes' omnipresence in modern cloud infrastructure, its "overengineered" nature and reliance on YAML configurations often lead to critical misconfigurations that security teams frequently miss.

AI review

Competent, well-structured K8s abuse talk that covers three legitimate attack vectors — CoreDNS destruction, webhook-based exfiltration, and quiet recon via exposed metrics endpoints — with working demos. Nothing here will surprise a K8s security practitioner, but it's delivered honestly and without vendor nonsense, which puts it ahead of most cloud-native content at this tier of conference.

Watch on YouTube