Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsPalo Alto Networks

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Palo Alto Networks, Thursday, September 10th, 2026

Root on a compromised Kubernetes node lets attackers use SPIFFE/SPIRE metadata to spoof co-located workload identities.

Unit 42 shows how root access on a compromised Kubernetes node lets an attacker abuse SPIFFE/SPIRE metadata to spoof and harvest the identities of workloads running alongside it.

Workload identity frameworks are widely adopted precisely to replace long-lived secrets, so the finding matters: node compromise now yields the identities of every pod on that node rather than only the credentials one application held.

The research covers detection approaches and the node-level controls that limit blast radius, which is the practical mitigation available today.

more →  ·  More from Palo Alto Networks →