/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers infiltrated Tesla Kubernetes consoles that were not password protected, took AWS credentials, began crypto-mining; issue now fixed

RedLock Blog :

RedLock Blog

Context & Ripple Effects

RedLock's disclosure lands mid-arc for Kubernetes: earlier in 2018 the platform was already under scrutiny, and by December a Kubernetes flaw letting any user gain full admin privileges on cluster nodes would force another round of patching. The Tesla breach is the misconfiguration variant of the same problem — no exploit needed, just an open console.

The credential-theft thread also runs through the broader corpus: hackers later walked away with 71K+ Nvidia staff credentials, many cracked and circulated, and Resecurity reported stolen logins for customer-support systems at Amazon, Apple, BMW and others. Tesla's case is the earliest data point here of cloud credentials themselves becoming the loot.

First-order effects

  • Tesla is directly paying the bill: miners ran on its AWS account using exfiltrated credentials, so the immediate fix is locking the consoles and rotating the exposed keys.
  • AWS absorbs the abuse on its side — hijacked customer credentials mean unauthorized compute billed to a legitimate account, the exact scenario its shared-responsibility messaging leaves to customers.

Second-order effects

  • Every other company running Kubernetes consoles now faces the same scan-and-mine playbook, since attackers who found one open console had every incentive to sweep for more.
  • Cloud security vendors like RedLock gain the commercial opening: continuous monitoring for exposed management surfaces becomes a sellable product line rather than an audit afterthought.

Third-order effects

  • If the pattern holds — open consoles, then stolen staff credentials at Nvidia, then harvested support logins at major brands — the industry shifts toward default-deny configurations and centralized secrets management instead of long-lived keys embedded in clusters.
  • Kubernetes' security posture gets defined less by core features than by the accumulation of these incidents, pushing operators toward hardened distributions and managed offerings where defaults are locked down.

The trend: Cloud infrastructure attacks are converging on stolen credentials and misconfigured control planes, with crypto-mining as the monetization layer.

Discussion

  • @michenriksen Michael Henriksen on x
    Pretty sure the criminals could have made much more money by just submitting the finding to Tesla's bugbounty program and get a $10K reward. http://blog.redlock.io/...
  • @unv_annihilator Sean Schwartz on x
    “In addition, the cyberattackers hid the true IP address of the mining pool to keep CPU usage low and prevent a level of suspicious traffic which would likely have been quickly detected.” Additional Reading: https://blog.redlock.io/... https://twitter.com/...
  • @kennwhite Kenn White on x
    Interesting twist: attacker's launched mining scripts through CloudFlare to mask their origin. Also, buried lede: HSM maker Gemalto was hit last year as well. https://cdn2.hubspot.net/... pic.twitter.com/rvH0YX8qpD
  • @kennwhite Kenn White on x
    Gemalto is one of the largest suppliers of hardware security to banks, telecoms, and militaries in the world. Part of their fleet orchestration systems getting trivially hacked seems like a big deal. pic.twitter.com/AVDWkyAYNo