Attacks that start at the application layer, then move down into the workload and cloud layers:
MoveIt
XZ Utils
Polykill
CUPS
Log4j
Spring4Shell
Confluence RCE
Apache Struts
tj-actions
ingress-nginx
Attack pattern:
- Initial Compromise at the Application Layer
Attackers exploit a bug in application code or a core library to execute malicious code or commands.
- Pivot to the Workload Layer
Once they have code execution, adversaries drop webshells, escalate privileges, or access environment variables, effectively “owning” the container or VM.
- Spread to the Cloud Layer
Armed with service account credentials, API keys, or privileged roles, attackers interact directly with cloud services—reading data, spinning up crypto miners, or exfiltrating sensitive information
pulse.latio.tech/p/runtime-c…
#TrustEverybodyButCutTheCards