<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Kubernetes</title><description>Cybersecurity articles tagged #Kubernetes on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TeamPCP&apos;s Evolving Threat: Redis, Cloud Native &amp; Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-s-evolving-threat-redis-cloud-native-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-s-evolving-threat-redis-cloud-native-supply-chain-attacks</guid><description>TeamPCP, active since 2020, now targets Redis, Docker, Kubernetes, and supply chains, deploying wipers and backdoors.</description><pubDate>Fri, 07 Aug 2026 08:47:09 GMT</pubDate><category>TeamPCP</category><category>Cloud Native</category><category>Supply Chain Attack</category><category>Kubernetes</category><category>Wiper</category></item><item><title>Unpatched Argo CD repo-server RCE via Internal Port Exposure</title><link>https://runtimerebel.com/blog/unpatched-argo-cd-repo-server-rce-via-internal-port-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/unpatched-argo-cd-repo-server-rce-via-internal-port-exposure</guid><description>An unpatched vulnerability in the Argo CD repo-server allows unauthenticated attackers to achieve RCE and potentially take over Kubernetes clusters.</description><pubDate>Thu, 02 Jul 2026 00:58:30 GMT</pubDate><category>Argo CD</category><category>Kubernetes</category><category>GitOps</category><category>RCE</category><category>Synacktiv</category></item><item><title>Azure Backup for AKS Vulnerability: Risks of Silent Patches</title><link>https://runtimerebel.com/blog/azure-backup-for-aks-vulnerability-risks-of-silent-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/azure-backup-for-aks-vulnerability-risks-of-silent-patches</guid><description>A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.</description><pubDate>Sun, 17 May 2026 00:54:57 GMT</pubDate><category>Azure</category><category>AKS</category><category>Kubernetes</category><category>Microsoft</category><category>Cloud Security</category></item><item><title>PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments</title><link>https://runtimerebel.com/blog/pcpjack-worm-analyzing-the-malware-displacement-in-cloud-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/pcpjack-worm-analyzing-the-malware-displacement-in-cloud-environments</guid><description>PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.</description><pubDate>Fri, 08 May 2026 08:38:51 GMT</pubDate><category>PCPJack</category><category>TeamPCP</category><category>Cloud Security</category><category>Docker</category><category>Kubernetes</category><category>Credential Theft</category></item><item><title>CVE-2024-9486: Critical Kubernetes Image Builder Flaws Exposed</title><link>https://runtimerebel.com/blog/cve-2024-9486-critical-kubernetes-image-builder-flaws-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-9486-critical-kubernetes-image-builder-flaws-exposed</guid><description>Critical vulnerabilities in Kubernetes Image Builder allow root access via hardcoded credentials. Update to version v0.1.38 to mitigate potential exploits.</description><pubDate>Tue, 28 Apr 2026 05:12:51 GMT</pubDate><category>CVE-2024-9486</category><category>CVE-2024-9487</category><category>Kubernetes</category><category>Proxmox</category><category>Nutanix</category><category>Privilege Escalation</category></item><item><title>TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise</title><link>https://runtimerebel.com/blog/teampcp-backdoors-litellm-1-82-7-1-82-8-via-ci-cd-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-backdoors-litellm-1-82-7-1-82-8-via-ci-cd-compromise</guid><description>TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.</description><pubDate>Tue, 24 Mar 2026 20:18:30 GMT</pubDate><category>LiteLLM</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>Python Security</category><category>Kubernetes</category></item><item><title>TeamPCP Targets Kubernetes Clusters with Iran-Specific Wiper Malware</title><link>https://runtimerebel.com/blog/teampcp-targets-kubernetes-clusters-with-iran-specific-wiper-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-targets-kubernetes-clusters-with-iran-specific-wiper-malware</guid><description>TeamPCP is targeting misconfigured Kubernetes clusters to deploy a data-wiping script that specifically triggers on Iranian system configurations and locales.</description><pubDate>Mon, 23 Mar 2026 20:17:25 GMT</pubDate><category>TeamPCP</category><category>Kubernetes</category><category>Wiper Malware</category><category>Cloud Security</category><category>Iran</category></item><item><title>Trivy Supply Chain Attack: Malicious Docker Hub Images Identified</title><link>https://runtimerebel.com/blog/trivy-supply-chain-attack-malicious-docker-hub-images-identified</link><guid isPermaLink="true">https://runtimerebel.com/blog/trivy-supply-chain-attack-malicious-docker-hub-images-identified</guid><description>Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.</description><pubDate>Mon, 23 Mar 2026 12:22:52 GMT</pubDate><category>Trivy</category><category>Docker Hub</category><category>Kubernetes</category><category>Infostealer</category><category>Wiper</category></item><item><title>Proactive Defense: Hardening Against Destructive Cyberattacks (2026 Edition)</title><link>https://runtimerebel.com/blog/proactive-defense-hardening-against-destructive-cyberattacks-2026-edition</link><guid isPermaLink="true">https://runtimerebel.com/blog/proactive-defense-hardening-against-destructive-cyberattacks-2026-edition</guid><description>Comprehensive guide on hardening against destructive cyberattacks, including wipers, ransomware, and data destruction tactics across on-premises and cloud environments.</description><pubDate>Fri, 06 Mar 2026 16:26:03 GMT</pubDate><category>Destructive Attacks</category><category>Wiper Malware</category><category>Ransomware</category><category>Hardening</category><category>Cyber Resilience</category><category>MFA</category><category>Backup</category><category>Active Directory</category><category>Kubernetes</category><category>CI CD</category><category>Cloud Security</category><category>Network Segmentation</category></item><item><title>Securing AI Infrastructure: Mitigation Strategies for Lifecycle Vulnerabilities</title><link>https://runtimerebel.com/blog/securing-ai-infrastructure-mitigation-strategies-for-lifecycle-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-ai-infrastructure-mitigation-strategies-for-lifecycle-vulnerabilities</guid><description>An assessment of architectural risks in AI deployments, emphasizing infrastructure-level threats and model supply chain vulnerabilities over application-layer prompt…</description><pubDate>Mon, 23 Feb 2026 05:35:03 GMT</pubDate><category>AI Security</category><category>Kubernetes</category><category>Container Escape</category><category>Supply Chain</category></item></channel></rss>