Grilled Cheese

ExploreLog inSign up

Explore

PostsPeople
LatestRanked
@hendryadrian.bsky.socialOct 2, 2026, 4:30 AM

One Kubernetes YAML can abuse Config Connector when org-level IAM is too broad, letting a low-privilege K8s user escalate to Google Cloud org control through the ConfigConfusion confused deputy flaw. #ConfigConnector #KCC #ConfigConfusion

@threadlinqs.bsky.socialSep 23, 2026, 2:40 PM

A single Kubernetes YAML can hand an attacker full GCP org ownership. Google's verdict: working as designed. https://intel.threadlinqs.com/threat/TL-2026-2629 #ThreatIntel #ConfigConfusion #GCP #Kubernetes

ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize Organization Owner
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT