The scary part of an agent-driven container escape is not the container escape.
That sounds wrong, so let me be precise.
The primitives in Sysdig's latest threat research are not new magic. A mounted Docker socket has been a bad idea for years. Over-permissioned Kubernetes service accounts have been a bad idea for years. Privileged containers are dangerous. Host namespace tricks are dangerous. Secrets reachable from application pods are dangerous.
None of this should surprise anyone who has had to review production Kubernetes setups with a straight face.
The new part is the operator.







