One Kubernetes YAML can abuse Config Connector when org-level IAM is too broad, letting a low-privilege K8s user escalate to Google Cloud org control through the ConfigConfusion confused deputy flaw. #ConfigConnector #KCC #ConfigConfusion
Explore
A single Kubernetes YAML can hand an attacker full GCP org ownership. Google's verdict: working as designed. https://intel.threadlinqs.com/threat/TL-2026-2629 #ThreatIntel #ConfigConfusion #GCP #Kubernetes
