Unit 42 demonstrated that an attacker with root access to a Kubernetes node running SPIFFE/SPIRE can falsify Linux cgroup metadata during workload attestation and obtain SVIDs for other workloads co-located on that node. The attacker can then impersonate those workloads with valid, short-lived cryptographic identities, enabling access to services and potential lateral movement without stealing long-lived credentials.
The technique relies on SPIRE's trust in node and kernel-provided process metadata and is not exploitable without node-level compromise; Unit 42 reported no observed in-the-wild exploitation. The researchers released the open-source Spooffe assessment tool for enumerating identities exposed through selector spoofing, and recommend treating root compromise of a SPIRE-enabled node as compromise of every workload identity on it, restricting root and host access, prohibiting privileged containers, and avoiding weak or easily spoofed selectors.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Unit 42 released Spooffe, an open-source defensive tool that enumerates workloads on a SPIRE-enabled node, spoofs matching cgroup paths, and queries the local SPIRE Agent for resulting workload identities. The tool also assesses potential SPIRE Agent impersonation against the SPIRE Server.
Unit 42 disclosed research showing that an attacker with root access to a Kubernetes node can spoof cgroup metadata during SPIRE workload attestation and obtain SVIDs for co-located workloads. The researchers stated they had not observed the technique exploited in the wild.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.