
TRC analysis shows attackers chaining CVE-2024-4433 and CVE-2024-4434 in Zilliz Attu to achieve full Kubernetes namespace takeover. Missing authentication plus regex bypass enabled lateral movement across cluster resources. Runtime segmentation could help contain post-compromise activity in cloud AI infrastructure. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/zilliz-attu-kubernetes-namespace-takeover-2024
