chiprook
← Security
SecurityOctober 11, 2026, 17:42

Critical Kubernetes zero-day exposes global cloud infrastructure

Researchers disclosed zero-day CVE-2024-12345 in the Kubernetes 1.28 and 1.29 API server, where a race condition in token validation lets remote attackers execute code and gain admin access to clusters. AWS, Azure and GCP issued emergency advisories, while detection alerts for suspicious API activity jumped 40%.

Critical Kubernetes zero-day exposes global cloud infrastructure
#Kubernetes#AWS#Azure#GCP
Read next
Security

Critical zero-day in popular AI API library exposed developer secrets

Security

ConfigConfusion: one Kubernetes YAML grants GCP organization owner rights

Software

Pinecone expands managed vector database to AWS, Azure and GCP with BYOC

Security

Storm-3068 hijacked account via SSPR and stole Kubernetes credentials