Uploaded March 2026 | Updated September 2026, 1 week ago
Learn more by visiting our website: ioactive.com
IOActive Senior Security Consultant Simon Robin presented this hack::soho in January 2026.
The abstract for Robin's talk, 'Secure YAML, Insecure Clusters: Breaking Kubernetes Without Exploits,' is below!
hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.
ABSTRACT
Kubernetes security is increasingly reduced to static configuration reviews and misconfiguration scanners. While these tools provide value, they are often treated as authoritative indicators of real security posture. In this talk, we will show how Kubernetes clusters with clean scan results can still be compromised through realistic attack paths that require no kernel exploits, no zero-days, and no exotic techniques. Drawing on academic research, real incidents, and offensive security experience, we demonstrate how attackers chain legitimate Kubernetes features into high-impact compromises.
Learn more by visiting our website: ioactive.com
IOActive Senior Security Consultant Simon Robin presented this hack::soho in January 2026.
The abstract for Robin's talk, 'Secure YAML, Insecure Clusters: Breaking Kubernetes Without Exploits,' is below!
hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.
ABSTRACT
Kubernetes security is increasingly reduced to static configuration reviews and misconfiguration scanners. While these tools provide value, they are often treated as authoritative indicators of real security posture. In this talk, we will show how Kubernetes clusters with clean scan results can still be compromised through realistic attack paths that require no kernel exploits, no zero-days, and no exotic techniques. Drawing on academic research, real incidents, and offensive security experience, we demonstrate how attackers chain legitimate Kubernetes features into high-impact compromises.










