Thursday, 27 February 2025
26.5 C
Singapore
27.1 C
Thailand
20.2 C
Indonesia
24.7 C
Philippines

Tenable research reveals major security risks in Kubernetes environments

Tenable's latest report finds that 78% of organisations have publicly exposed Kubernetes API servers, increasing cyber risks. Hereโ€™s how businesses can secure their environments.

A new report from Tenable Cloud Research has found that organisations worldwide, including those in the Asia-Pacific (APAC) region, face growing security risks in their Kubernetes environments. As more businesses adopt Kubernetes to manage cloud infrastructure, many are failing to secure their systems, leaving them vulnerable to cyberattacks.

The 2024 Tenable Cloud Risk Report highlights that the widespread use of containerised applications, combined with weak security controls, is exposing businesses to potential data breaches, service outages, and unauthorised access to critical workloads.

โ€œKubernetes is the backbone of many cloud-native applications, but organisations in APAC are struggling to secure these environments properly,โ€ said Ari Eitan, Research Director at Tenable. โ€œPublicly exposed Kubernetes API servers and overprivileged containers are serious risks that leave businesses vulnerable to attacks. Without the right security measures in place, these misconfigurations can lead to catastrophic breaches.โ€

Key security threats in Kubernetes environments

The report identifies several major risks affecting Kubernetes deployments:

  • Publicly accessible Kubernetes API servers: 78% of organisations have Kubernetes API servers exposed to the public internet, making them easy targets for cybercriminals. Of these, 41% allow inbound internet access, increasing the risk of unauthorised entry. Attackers can exploit these weak configurations to access sensitive systems and, in some cases, take control of entire cloud environments.
  • Overuse of privileged containers: 44% of organisations run containers in privileged mode, granting them unrestricted access to the host system. This increases the risk of attackers escalating their privileges and gaining deeper access to the cloud infrastructure.
  • Excessive cluster-admin permissions: 58% of organisations have cluster-admin role bindings, giving users and applications full control over Kubernetes environments. If attackers gain access to these roles, they can modify workloads, extract sensitive data, or even disrupt entire systems.

How businesses can secure Kubernetes environments

To reduce these security risks, Tenable recommends that organisations implement the following best practices:

  • Limit Kubernetes API exposure: Ensure API servers are not publicly accessible. Use firewall and security group rules to restrict inbound traffic and segment networks to isolate sensitive workloads.
  • Minimise privileged containers: Avoid running containers in privileged mode unless absolutely necessary. Follow industry security guidelines such as the CIS Kubernetes Benchmark and NIST recommendations to restrict container access to host resources.
  • Strengthen role-based access control (RBAC): Regularly review and tighten permissions for cluster-admin roles. Implement the principle of least privilege by assigning only the necessary access rights to users and service accounts.
  • Conduct regular security audits: Perform frequent security reviews of Kubernetes configurations to identify and fix misconfigurations. Disable anonymous access to the Kubelet API and encrypt all communications within the cluster.

“The growing adoption of Kubernetes is a double-edged sword. While it offers great agility for cloud operations, it also introduces a new layer of complexity and security risks. APAC businesses must prioritise Kubernetes security, particularly by closing exposure gaps and enforcing strict access controls. Proactive measures today will protect organisations from becoming tomorrowโ€™s headline breaches,” added Eitan.

Hot this week

Mobile Legends: Bang Bang added to 2026 Asian Games as esports lineup expands

Mobile Legends: Bang Bang will be a medalled event at the 2026 Asian Games, joining a growing esports lineup at the international competition.

Adobe launches free Photoshop app for iOS; Android version coming soon

Adobe has launched a free Photoshop app for iOS, with an Android version on the way. The app offers core editing tools and a premium plan.

Web Summit attendees push back against Scale AI CEOโ€™s call for U.S. dominance in AI

Scale AI CEO Alexandr Wangโ€™s call for U.S. AI dominance sparks debate at Web Summit Qatar, with attendees pushing back on his bold stance.

Hyundaiโ€™s NACS port faces a major issue at Tesla charging stations

The 2025 Hyundai Ioniq 5โ€™s new Tesla charging port faces real-world challenges due to its placement. Find out how this affects EV owners.

Google expands in-car apps, turning vehicles into mobile entertainment hubs

Google is expanding its in-car apps, bringing more streaming and gaming options to vehicles with built-in Google services, starting with Volvo and Polestar.

Amazon launches dedicated website and app for Alexa Plus

Amazon is launching a new Alexa.com website and mobile app for Alexa Plus, offering new AI-powered features for users. Alexa Plus costs US$19.99/month.

Samsung unveils its first PCIe Gen 5 SSD, the 9100 Pro, launching in March

Samsung is launching its first PCIe Gen 5 SSD, the 9100 Pro series, in March, with speeds up to 14.8GBps and capacities up to 8TB.

The future of Framework Laptop 16 remains uncertain

The CEO of Framework says that Laptop 16 isn't finished, but its future remains unclear as the company focuses on its new modular desktop.

Power meets portability: ROG reveals new details on the 2025 Flow Z13

ROG confirms that the 2025 Flow Z13 gaming tablet will launch on February 28. It will feature AMDโ€™s Ryzen AI Max+ 395 and improved cooling.

Related Articles