Hacker Timesnew | past | comments | ask | show | jobs | submit | olearysec's commentslogin

I'm the researcher. You've nailed it — Backup Contributor automatically granted cluster-admin via Trusted Access, no K8s permissions required. Microsoft called it "expected behavior," then silently patched it.

Full writeup with CERT/CC timeline and evidence: https://olearysec.com/research/azure-backup-aks-silent-patch...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: