--- URGENT: Major security flaw in Kubernetes: Update Kubernetes at all costs! ---
Detailed info: https://github.com/kubernetes/...

If you are running any unpatched versions of Kubernetes, you must update now. Anyone might be able to send commands directly to your backend through a forged network request, without even triggering a single line in the log, making their attack practically invisible!

If you are running a version of Kubernetes below 1.10... there is no help for you. Upgrade to a newer version, e.g. 1.12.3.

  • 6
    Post written by @filthyranter
  • 29
  • 7
  • 14
    I am forwarding it to my coworkers, and if this was a stupid prank, imma report you
  • 7
    @dreadedghoul Dude, check the detailed info. Not a prank.
  • 8
    @filthyranter Thank you very much then for your services.
  • 3
    @dreadedghoul Check the project's Github
  • 3
    Definitely not a prank.
  • 4
    Thanks for the heads up! *runs off to check on stuff*
  • 3
    Don't run Kubernetes, but shared as good as I could 😅 Thanks!
  • 9
  • 0
  • 1
    @EvilArcher That's a big bummer for them, as they won't be able to mitigate this issue before someone attacks, without any log entries whatsoever as well.
  • 1
    @EvilArcher They will get into trouble then.
  • -1
  • 0
  • 1

    You know there's a "created_time" attribute in the api. Why don't you just take a look at its value so you won't raise the dead every time, like any other civilized bot does?
