Microsoft Defender for Cloud can help organizations identify these vulnerabilities through alerts on exposed Kubernetes services and visualization of internet-exposed workloads through the Cloud Security Explorer. According to a report published on May 5, 2025, by Microsoft Defender for Cloud Research team, these pre-packaged deployment templates often prioritize convenience over security, creating significant vulnerabilities. “Without carefully reviewing the YAML manifests and Helm charts, organizations may unknowingly deploy services lacking any form of protection, leaving them fully exposed to attackers,” the researchers stated. Microsoft researchers discovered actual incidents where attackers exploited misconfigured Apache Pinot workloads to access users’ data. Microsoft researchers found multiple popular applications with similar vulnerabilities after searching GitHub repositories for YAML files containing indicators of misconfigured workloads like “type: LoadBalancer”. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Kaaviya is a Security Editor and fellow reporter with Cyber Security News. This dangerous combination creates an environment where attackers can easily access sensitive data or even gain administrative control over cloud resources. Authentication capabilities, like those available in Apache Pinot 0.8.0+, should be enabled rather than using default configurations that leave services exposed.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 06 May 2025 14:50:09 +0000