home.social

#ingressnightmare — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ingressnightmare, aggregated by home.social.

fetched live
  1. #IngressNightmare – czyli jak przejąć klaster Kubernetes

    Podatności określane jako krytyczne mogą wzbudzać skrajne emocje. W sekuraku jesteśmy pewni, że nie wszyscy zgodzą się z punktacją CVSS 3.1 (9.8/10) przypisaną do serii podatności określonych jako IngressNightmare, które zostały opisane 24.04.2025 przez badaczy z wiz.io. TLDR: Problematycznym komponentem jest Ingress NGINX Controller, czyli ingress controller (kontroler ruchu wejściowego,...

    #WBiegu #Ingress #K8s #Kubernetes #Nginx #Podatność #Rce

    sekurak.pl/ingressnightmare-cz

  2. '... series of unauthenticated ... [RCE] vulnerabilities in Ingress NGINX Controller for Kubernetes dubbed #IngressNightmare ...

    '... about 43% of cloud environments are vulnerable to these vulnerabilities, with our research uncovering over 6,500 clusters, including Fortune 500 companies, that publicly expose vulnerable Kubernetes ingress controllers’ admission controllers to the public internet ...

    'Using Ingress-NGINX is one of the most common methods for exposing Kubernetes applications externally.

    'Our research show that over 41% of internet-facing clusters are running Ingress-NGINX'.
    wiz.io/blog/ingress-nginx-kube

  3. I wrote up some details on exploiting #IngressNightmare #CVE-2025-1974:
    www.averlon.ai/blog/kuberne...

    Where are we at with releasing a full PoC?

  4. This week a critical security vulnerability in #Kubernetes, dubbed "#IngressNightmare", was published.

    As we are using #Rancher managed Kubernetes clusters ourselves, we share our analysis in our latest #blog post.

    How Rancher RKE clusters are affected, how the #vulnerability can be mitigated and when a fix can be expected.

    infiniroot.com/blog/1478/kuber

  5. Attention all k8s people: There's an #IngressNightmare in progress.
    > "Based on our analysis, about 43% of cloud environments are vulnerable to these vulnerabilities, with our research uncovering over 6,500 clusters, including Fortune 500 companies, that publicly expose vulnerable Kubernetes ingress controllers’ admission controllers to the public internet—putting them at immediate critical risk."
    wiz.io/blog/ingress-nginx-kube

  6. #NGINX Critical Ingress NGINX Controller for #Kubernetes Vulnerability Allows #RCE Without Authentication. A set of 5 critical security CVE with CVSS scores 4.8-9.8 affecting ~43% of cloud environments globally:

    #IngressNightmare

    thehackernews.com/2025/03/crit

  7. 🎙️ All you need to know on our latest discovery #IngressNightmare 🚨

    In this episode of Crying Out Cloud, Amitai Cohen & Eden Naftali are joined by Nir Ohfeld — Head of Vulnerability Research at Wiz.

    Nir and his team have uncovered some of the most impactful vulnerabilities affecting cloud and SaaS applications. In this episode, he's diving into the latest discovery, a critical vulnerability in Ingress-NGINX:

    • How the team uncovered a critical unauthenticated RCE in #NGINX Ingress Controller
    • Why Kubernetes admission controllers might be the next big attack surface
    • The wild journey of hunting vulnerabilities in the cloud

    🔗 Listen now:

    🍏 podcasts.apple.com/us/podcast/
    🎧 open.spotify.com/episode/0G1Mm
    📺 youtube.com/watch?v=mjwLEbGA4m

  8. #IngressNightmare: Wiz Research uncovers a critical vulnerability in Ingress-NGINX 🚨

    Wiz Research found a novel attack vector in one of Kubernetes's most fundamental projects, Ingress-NGINX, which is rated CVSS 9.8.

    Why does this matter?
    Ingress-NGINX is found in over 40% of cloud environments. If you're using this project, your infrastructure could be at risk.

    🔑 What's at risk?
    This vulnerability allows attackers to gain access to all secrets across all namespaces in a Kubernetes cluster — essentially enabling a cluster takeover.

    🔒 What should you do?
    A patch is available.
    Upgrade to version v1.12.1, v1.11.5 to protect your environment.

    Wiz research has worked closely with the Kubernetes maintainers over the last couple of months to mitigate this attack surface fully

    📝 For full technical details and a remediation guide, check out our blog:

  9. 🚨 Breaking News: #Kubernetes users rejoice as *IngressNightmare* becomes the hottest new way to turn your #cloud environment into a hacker's paradise! Who needs #security when you can have "complete cluster takeover" as a feature? 🎉 Just a casual reminder that your #secrets are their secrets now. 🙈🔓
    wiz.io/blog/ingress-nginx-kube #IngressNightmare #breach #hacker #news #HackerNews #ngated