← Back to Feed

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

September 10, 2026 · Unit 42 · Severity: HIGH

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.

Key Takeaways

  • Unit 42 analyzes post-exploitation identity attacks
  • Attackers abuse identity systems after initial compromise
  • Focus on AD, Azure AD, and cloud identity abuses
☕ Buy a Coffee