A recent large-scale cryptocurrency mining attack against Kubernetes clusters was recently discovered by Azure Security Center. Within two hours a malicious container was deployed on tens of clusters. The attacker gained access to a single container in the cluster and used the internal networking of the cluster for accessing the dashboard. This could lead to exposure of connection strings, passwords, and other secrets which might enable lateral movement. The attack was triggered on some of the attacked clusters by security alerts on the exposure of the dashboard to the Internet. This is one of the many examples that Microsoft’s Security Center can help you protect your KuberNETes clusters from threats.”]

