ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Security researcher Justin O'Leary disclosed ConfigConfusion, a flaw in Google Kubernetes Config Connector (KCC) where a user with only namespace access can submit an IAMPolicyMember YAML to grant themselves roles/owner on an entire Google Cloud organization. KCC's service account executes the request without verifying the Kubernetes user's cloud permissions. Google says KCC works as designed, recommending scoped service accounts.
Tap to vote and see what everyone thinks.
Summary by ByteBrief