The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Networks, Thursday, September 10th, 2026
Root on a compromised Kubernetes node lets attackers use SPIFFE/SPIRE metadata to spoof co-located workload identities.
Unit 42 shows how root access on a compromised Kubernetes node lets an attacker abuse SPIFFE/SPIRE metadata to spoof and harvest the identities of workloads running alongside it.
Workload identity frameworks are widely adopted precisely to replace long-lived secrets, so the finding matters: node compromise now yields the identities of every pod on that node rather than only the credentials one application held.
The research covers detection approaches and the node-level controls that limit blast radius, which is the practical mitigation available today.