OperTraitors: How Kubernetes Operators Betray Your Security Posture
Palo Alto Networks, Tuesday, September 29th, 2026
Unit 42 releases OperTraitor, an open source LLM tool that flags over-privileged Kubernetes operators acting as silent backdoors.
Unit 42 warns that Kubernetes operators often run with highly privileged service accounts and broad wildcard RBAC permissions, turning trusted components into potential backdoors.
It released OperTraitor, an open source LLM-powered engine that ingests RBAC configurations from installed operators and the OperatorHub catalog, compares each operator's documented functionality with its actual granted privileges and produces a normalized risk score.
Using it, researchers found abandoned and overly permissive components in default registries such as OperatorHub.