IOActive's IOAsis - Horseshoe Las Vegas

hack::soho | January 2026 | Secure YAML, Insecure Clusters | Livestream Registration

Register for the Livestream Today!

Register for our livestream featuring our January hack::soho presentation from IOActive Senior Security Consultant Simon Robin. The abstract of the talk, 'Secure YAML, Insecure Clusters: Breaking Kubernetes Without Exploits,' is below!

The presentation will kick off at 7pm GMT. Fill out the form to get your calendar link!

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network. Spots are limited, so please use real contact details to confirm your registration.

We will not sell, distribute, or use your contact information outside of sending you details about upcoming hack::soho meetups.

We hope you can join us!

ABSTRACT

Kubernetes security is increasingly reduced to static configuration reviews and misconfiguration scanners. While these tools provide value, they are often treated as authoritative indicators of real security posture. In this talk, we will show how Kubernetes clusters with clean scan results can still be compromised through realistic attack paths that require no kernel exploits, no zero-days, and no exotic techniques. Drawing on academic research, real incidents, and offensive security experience, we demonstrate how attackers chain legitimate Kubernetes features into high-impact compromises. https://www.ioactive.com/contact/