Critical Kubernetes zero-day exposes global cloud infrastructure
Researchers disclosed zero-day CVE-2024-12345 in the Kubernetes 1.28 and 1.29 API server, where a race condition in token validation lets remote attackers execute code and gain admin access to clusters. AWS, Azure and GCP issued emergency advisories, while detection alerts for suspicious API activity jumped 40%.
- The flaw affects the API server in Kubernetes 1.28 and 1.29
- Attack exploits a race condition in authentication token validation
- Suspicious API server alerts rose 40% in 48 hours
- AWS, Azure and GCP urged immediate patching of managed clusters
Read next
Security