Rhino Security Labs

Strategic & Technical Blog

GKE Kubelet TLS Bootstrap Privilege Escalation

Jack Ganbold

Kubernetes is becoming increasingly popular and the de facto standard for container orchestration. In recent Google Cloud Platform (GCP), Amazon Web Service (AWS), and Azure cloud pentests, we have seen many of our clients using Kubernetes…

Weaponizing AWS ECS Task Definitions
to Steal Credentials From Running Containers

CloudGoat AWS Scenario Walkthrough: “EC2_SSRF”

Privilege Escalation in
Google Cloud Platform – Part 2 (Non-IAM)

Spencer Gietzen

This is a continuation of the 2-part blog series on Privilege Escalation in Google Cloud. 
If you haven’t already read Part 1 of this blog series, check it out here.
This part of the blog focuses on non-IAM service privilege escalation…