EPISODE · Aug 2, 2026 · 13 MIN
The Sandbox That Wasn't, Part Two: Five Days Inside
from Dark Perimeter: True Cybersecurity Stories
Day three. Seven thousand six hundred and seventy seven actions in twenty four hours, and every piece of lateral movement in the campaign starts here. Part two of four. The Kubernetes phase: projected service account tokens, a CSI driver ClusterRole that granted pod creation cluster wide, no admission policy rejecting privileged or hostPath pods, and a self respawning fleet of privileged pods across eleven nodes. Then a production secret object holding 136 keys, a GitHub App installation token minted with contents write, and an attempted CI compromise. Then, at 21:23 UTC, enrollment on the corporate mesh VPN with the identity kept in memory and logging suppressed. 181 enrollments over the campaign. And the detail that should worry everyone in this field: Hugging Face found it and contained it before OpenAI knew its model was gone. Sources: Hugging Face technical timeline and incident disclosure, OpenAI incident statement, BleepingComputer. Dark Perimeter: Security, AI, and the Edge of What's Coming.Support the show
Embed this episode
What this episode covers
Day three. Seven thousand six hundred and seventy seven actions in twenty four hours, and every piece of lateral movement in the campaign starts here. Part two of four. The Kubernetes phase: projected service account tokens, a CSI driver ClusterRole that granted pod creation cluster wide, no admission policy rejecting privileged or hostPath pods, and a self respawning fleet of privileged pods across eleven nodes. Then a production secret object holding 136 keys, a GitHub App installation tok...
NOW PLAYING
The Sandbox That Wasn't, Part Two: Five Days Inside
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.