Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Amazon EKS Vulnerabilities Exposes Sensitive AWS Credentials and Escalate Privileges

Posted on June 23, 2025June 23, 2025 By CWS

Abstract
1.  Overprivileged containers can steal AWS credentials by focusing on the 169.254.170.23:80 endpoint by way of packet sniffing and API spoofing assaults.
2. Attackers use tcpdump to intercept plaintext site visitors or manipulate community settings to deploy faux HTTP servers that seize authorization tokens.
3.  Amazon considers this anticipated conduct below buyer accountability, not a safety vulnerability requiring patches.
4. Organizations should take away extreme container capabilities like CAP_NET_RAW, CAP_NET_ADMIN, and hostNetwork settings to stop exploitation.

Important vulnerabilities in Amazon Elastic Kubernetes Service (EKS) enable overprivileged containers to reveal delicate AWS credentials by way of packet sniffing and API spoofing assaults. 

The investigation, revealed on June 19, 2025, demonstrates how misconfigured containers can facilitate unauthorized entry and privilege escalation in cloud environments, highlighting important dangers within the AWS shared accountability mannequin.

Amazon EKS Pod Id Exposes Credentials

The vulnerability particularly targets Amazon EKS Pod Id, a characteristic designed to simplify AWS credential administration for pods working in EKS clusters. 

The service operates by way of the eks-pod-identity-agent add-on, which runs as a DaemonSet within the kube-system namespace and exposes an API on the link-local deal with 169.254.170.23 for IPv4 and [fd00:ec2::23] for IPv6 on port 80.

The agent accepts Kubernetes service account tokens within the Authorization header and calls the eks-auth:AssumeRoleForPodIdentity API motion. 

When purposes make AWS service requests, the SDK routinely retrieves non permanent credentials from the EKS Pod Id agent, which then interacts with the AWS API to acquire vital credentials for the related IAM function.

Researchers recognized two main assault vectors exploiting extreme container privileges. 

The primary entails packet sniffing, the place containers configured with hostNetwork: true settings can monitor community site visitors and intercept credentials transmitted in plaintext from the API endpoint 169.254.170.23:80. 

A proof-of-concept utilizing the usual tcpdump utility efficiently demonstrated credential interception in unencrypted HTTP site visitors.

Gaining elevated privileges by way of the tcpdump utility

The second assault vector employs API spoofing methods. Even when CAP_NET_RAW functionality is eliminated, containers retaining CAP_NET_ADMIN privileges can manipulate Community Interface Card (NIC) settings. 

Attackers can disable the eks-pod-identity-agent HTTP daemon by deleting the native hyperlink IP deal with, then deploy their very own HTTP server on 169.254.170.23:80 to intercept Authorization tokens. 

Development Micro developed a Python-based proof-of-concept utilizing the pyroute2 library to display this exploit.

API spoofing-based assault

 Mitigation Methods

The vulnerabilities had been reported to Amazon by way of the Development Micro Zero Day Initiative program.

Nonetheless, AWS decided that this conduct represents anticipated performance throughout the node’s belief boundary and falls below buyer accountability of their shared accountability mannequin.

To mitigate these dangers, organizations ought to implement the precept of least privilege when configuring containers and make the most of safety options like Development Imaginative and prescient One Container Safety. 

The platform can detect and block containers working with elevated privileges, together with these with CAP_NET_RAW, CAP_NET_ADMIN capabilities, or pods with hostNetwork flags set to true.

Cyber Security News Tags:Amazon, AWS, Credentials, EKS, Escalate, Exposes, Privileges, Sensitive, Vulnerabilities

Post navigation

Previous Post: NCSC Warns of ‘UMBRELLA STAND’ Malware Attacking Fortinet FortiGate Firewalls
Next Post: BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware

Related Posts

239 Malicious Android Apps on Google Play With Downloaded Over 40 Million Times Cyber Security News
5 SOC Analyst Tips for Super-Fast Triage  Cyber Security News
Want To Detect Incidents Before It’s Too Late? You Need Threat Intelligence Cyber Security News
Microsoft Teams “couldn’t connect” Error Following Recent Sidebar Update Cyber Security News
Threat Actors Breaking to Enterprise Infrastructure Within 18 Minutes From Initial Access Cyber Security News
Critical GNU Wget2 Vulnerability Let Remote Attackers to Overwrite Sensitive Files Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment
  • Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
  • Tim Kosiba Named NSA Deputy Director
  • Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment
  • Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
  • Tim Kosiba Named NSA Deputy Director
  • Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark