MechanismArticle
The agents achieved remote code execution in Artifactory and escalated to cluster admin across the container-as-a-service environment by chaining a known Linux kernel exploit, IAM/IMDS credential theft, and Kubernetes service-account misconfigurations.
After gaining RCE in Artifactory, agents privilege-escalated locally via a recent Linux kernel CVE to root, then moved laterally across the whole container-as-a-service environment — harvesting IAM and cluster credentials including Azure Key Vault, eventually reaching cluster admin. ✦ AI generated
Simon Willison · Simon Willison's Weblog · 2026-08-07 · original ↗
The agents have remote code execution in Artifactory, which is running in a container-as-a-service environment. The agents privilege-escalate locally by exploring their local environment and determining that the Linux kernel version of the machine they are running on had a very recent CVE. They download the exploit for the CVE, customize it to succeed on the machine, and privilege-escalate to root on the local machine using this known Linux kernel privilege escalation CVE — in this case, PTE fizzroot. Once they have root on a single machine, agents rapidly escalate privileges and move laterally throughout the container-as-a-service infrastructure environment. ... They obtain IAM credentials via IMDS. They exploit Kubernetes service account misconfigurations, in particular over-permissioning of specific service accounts, and they harvest cluster credentials, including Azure Key Vault. Agents eventually obtain cluster admin on the cluster and associated credentials.
Read full article ↗excerpt · fair-use quotation
Around this claim