Over 900,000 misconfigured Kubernetes clusters were found exposed on the Internet to potentially malicious scans, some even vulnerable to data-exposing cyberattacks.
Kubernetes is a highly flexible open-source container orchestration system for hosting web services and managing container workloads through a single API interface.
See also: Microsoft: Fixes Windows RRAS, VPN issues for all users

It enjoys huge adoption and growth rates thanks to scalability, flexibility in multi-cloud environments, portability, cost, application development, and system development time reductions.
However, if Kubernetes is not configured properly, remote actors may have access to internal resources and private data that was not intended to be made public.
Additionally, depending on the configuration, attackers could escalate privileges from containers and spin up into host processes, giving them initial access to internal corporate networks for further attacks.
See also: Bank of the West: Debit card numbers and PINs stolen via ATM skimmers
Finding exposed Kubernetes
Cyble researchers conducted an exercise to identify exposed Kubernetes instances on the internet, using similar scanning tools and search queries to those used by malicious actors.
The results show 900,000 Kubernetes servers, with 65% of them (585,000) located in the United States, 14% in China, 9% in Germany, while the Netherlands and Ireland account for 6% each.

Of the exposed servers, the top most exposed TCP ports were “443”, with just over a million instances, “10250” counting 231,200 and “6443” with 84,400 results.
It is important to emphasize that not all of these exposed clusters are exploitable, and even among those that are, the level of risk varies depending on the individual configuration.
High-risk instances
To assess how many of the exposed instances may be at significant risk, Cyble examined the error codes returned in unauthenticated requests to the Kubelet API.
See also: USA, Brazil: Removal of 272 sites that allowed illegal music downloads
The vast majority of exposed instances return error code 403, meaning that the unauthenticated request is forbidden and cannot be processed, so attacks against them cannot occur

Then, there is a subset of about five thousand instances that respond with a 401 error code, indicating that the request is unauthorized.

However, this response gives a potential attacker a tip that the cluster is working and could try additional attacks based on exploits and vulnerabilities.
Finally, there is a small subset of 799 Kubernetes instances returning a status code of 200, which are fully exposed to external attackers.
In these instances, threat actors can access nodes in the Kubernetes Dashboard without a password, access all secrets, perform actions, etc.

While the number of vulnerable Kubernetes servers is quite low, all it takes is one remote exploitation vulnerability to be discovered for a much larger number of devices to become vulnerable to attacks.
To ensure that your cluster is not among those 799 or even the less exposed set of 5,000 instances, consult the NSA and CISA guidance on hardening your Kubernetes system security.
Information source: bleepingcomputer.com
