Kubernetes attack surface explodes: number of threats quadruples

TL;DR AI
2 min readKey summary
Palo Alto Networks Unit 42 reported a sharp rise in Kubernetes attack attempts.
Attackers are abusing stolen service account tokens, malicious pods, and cloud app vulnerabilities.
A crypto exchange breach was linked to compromised Kubernetes credentials.
Attacks spiked rapidly after the disclosure of React2Shell, CVE-2025-55182.
Weaknesses in cluster identities and app layers can put cloud systems and assets at scale at risk.



