{"id":45739,"date":"2022-03-16T15:16:04","date_gmt":"2022-03-16T15:16:04","guid":{"rendered":"http:\/\/acc7b02b-7f84-4bb9-a4b8-6575a0028775"},"modified":"2022-03-16T15:16:04","modified_gmt":"2022-03-16T15:16:04","slug":"nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/","title":{"rendered":"NSA and CISA: Here&#8217;s how to improve your Kubernetes cluster security"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\" class=\"ff-og-image-inserted\"><\/div>\n<p>The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) have published updated guidance about how to harden Kubernetes for managing container applications.&nbsp;<\/p>\n<p>Kubernetes is an open-source system that automates deployment, scaling, and management of applications run in containers.<\/p>\n<p>The <a href=\"https:\/\/media.defense.gov\/2021\/Aug\/03\/2002820425\/-1\/-1\/0\/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">updated guidance<\/a> refreshes the two agencies&#8217; first Cybersecurity Technical Report regarding Kubernetes hardening guidance from August 2021. CISA says the update contains <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/03\/15\/updated-kubernetes-hardening-guide\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">additional details and explanations<\/a> based on feedback from industry, including more detailed info on logging and threat detection in addition to other clarifications.&nbsp;<\/p>\n<p>Some of the updates are subtle but important for those who protect Kubernetes clusters. NSA and CISA do not list what the changes are in the updated guidance, but the initial recommendations weren&#8217;t met with universal approval.&nbsp;<\/p>\n<p>For example <a href=\"https:\/\/research.nccgroup.com\/2021\/09\/09\/nsa-cisa-kubernetes-security-guidance-a-critical-review\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">NCC Group noted<\/a> that advice about Kubernetes authentication was &#8220;largely incorrect when it states that Kubernetes does not provide an authentication method by default&#8221;, whereas most customer implementations NCCGroup had reviewed &#8220;support both token and certification authentication, both of which are supported natively.&#8221; NCCGroup advised against both for production loads because Kubernetes does not support certificate revocation, which can be a problem if an attacker has gained access to a certificate issued to privileged accounts. The updated guidance now says that &#8220;several user authentication mechanisms are supported but not enabled by default.&#8221;<\/p>\n<p>Otherwise, key points of the original document appear to be unchanged. It looks at hardening within the context of typical Kubernetes cluster designs that include the control plane, worker nodes (for running containerized apps for the cluster), and pods for containers that are hosted upon these nodes. These clusters are often hosted in the cloud and often across multiple clouds in AWS, Azure, Google and elsewhere.&nbsp; &nbsp;<\/p>\n<p>The agencies maintain that Kubernetes is commonly targeted for data theft, computational power theft, or denial of service. Historically, flaws in Kubernetes and various dependencies as well as misconfigurations have been used to deploy cryptominers on victim&#8217;s infrastructure. &nbsp; &nbsp;<\/p>\n<p>It also maintains that Kubernetes is exposed to significant supply chain risks because clusters often have software and hardware dependences built by third-party developers.&nbsp;<\/p>\n<p>For example, security analysts <a href=\"https:\/\/www.zdnet.com\/article\/researchers-find-new-attack-vector-against-kubernetes-clusters-via-misconfigured-argo-workflows-instances\/\">last year warned<\/a> of attacks against Kubernetes clusters via misconfigured Argo Workflows container workflow engine for K8s clusters. &nbsp;<\/p>\n<p>Besides supply chain risks, other key actors in the agencies&#8217; threat model include malicious outsiders and insider threats. These help define its hardening recommendations.<\/p>\n<p>For example, there is a common cloud case where workloads that aren&#8217;t managed by a given Kubernetes cluster share the same physical network. In that instance, a workload may have access to the kubelet and to control plane components, such as the API server. So, the agencies recommend network level isolation.&nbsp; &nbsp;<\/p>\n<p>The agencies provide advice on how to ensure strict workload isolation between pods running on in same node in a cluster, given that Kubernetes doesn&#8217;t by default guarantee this separation. &nbsp;<\/p>\n<p><a href=\"https:\/\/www.nsa.gov\/Press-Room\/News-Highlights\/Article\/Article\/2716980\/nsa-cisa-release-kubernetes-hardening-guidance\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Announcing the updated guidance, the NSA says<\/a>: &#8220;Primary actions include the scanning of containers and pods for vulnerabilities or misconfigurations, running containers and pods with the least privileges possible, and using network separation, firewalls, strong authentication, and log auditing.&#8221;<\/p>\n<p>The agencies also recommend periodic reviews of Kubernetes settings and vulnerability scans to ensure appropriate risks are account for and security patches are applied.&nbsp;<\/p>\n<p>But patching is not easy in the context of Kubernetes. CISA regularly publishes alerts about new Kubernetes related vulnerabilities. In February for example it <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/bulletins\/sb22-059\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">warned<\/a> of a critical (severity score 8.8 out of 10) privilege escalation flaw,&nbsp;<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23652\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">CVE-2022-23652<\/a>, which affected the capsule-proxy reverse proxy for Capsule Operator.&nbsp;<\/p>\n<p>But as NCCGroup points out: &#8220;patching everything is hard&#8221;, partly because of the pressure to avoid downtime but also because relevant vulnerabilities span Kubernetes,&nbsp;<a href=\"https:\/\/research.nccgroup.com\/2020\/12\/10\/abstract-shimmer-cve-2020-15257-host-networking-is-root-equivalent-again\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Containerd<\/a>, runc, the Linux kernel and more.<\/p>\n<p>&#8220;This is something that Kubernetes can help with, as the whole concept of orchestration is intended to keep services running even as nodes go on and offline. Despite this, we still regularly see customers running nodes that haven&#8217;t had patches applied in several months, or even years. (As a tip, server uptime isn&#8217;t a badge of honour as much as it used to be; it&#8217;s more likely indicative that you&#8217;re running an outdated kernel),&#8221; NCCGroup noted.&nbsp;<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The NSA and CISA update their advice to help hardened Kubernetes clusters against attack.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-45739","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NSA and CISA: Here&#039;s how to improve your Kubernetes cluster security 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSA and CISA: Here&#039;s how to improve your Kubernetes cluster security 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-16T15:16:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"NSA and CISA: Here&#8217;s how to improve your Kubernetes cluster security\",\"datePublished\":\"2022-03-16T15:16:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/\"},\"wordCount\":730,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/36eacd57be8cf45d5617f398302d88af4e47917b\\\/2021\\\/12\\\/06\\\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\\\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/\",\"name\":\"NSA and CISA: Here's how to improve your Kubernetes cluster security 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/36eacd57be8cf45d5617f398302d88af4e47917b\\\/2021\\\/12\\\/06\\\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\\\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"datePublished\":\"2022-03-16T15:16:04+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/36eacd57be8cf45d5617f398302d88af4e47917b\\\/2021\\\/12\\\/06\\\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\\\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/36eacd57be8cf45d5617f398302d88af4e47917b\\\/2021\\\/12\\\/06\\\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\\\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NSA and CISA: Here&#8217;s how to improve your Kubernetes cluster security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSA and CISA: Here's how to improve your Kubernetes cluster security 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/","og_locale":"en_US","og_type":"article","og_title":"NSA and CISA: Here's how to improve your Kubernetes cluster security 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-03-16T15:16:04+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"NSA and CISA: Here&#8217;s how to improve your Kubernetes cluster security","datePublished":"2022-03-16T15:16:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/"},"wordCount":730,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/","url":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/","name":"NSA and CISA: Here's how to improve your Kubernetes cluster security 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","datePublished":"2022-03-16T15:16:04+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/36eacd57be8cf45d5617f398302d88af4e47917b\/2021\/12\/06\/65e99cdf-bb9a-43e6-b9f2-7bbcfab2c195\/hacker-hands-typing-on-a-keyboard.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/nsa-and-cisa-heres-how-to-improve-your-kubernetes-cluster-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"NSA and CISA: Here&#8217;s how to improve your Kubernetes cluster security"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45739","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=45739"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45739\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=45739"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=45739"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=45739"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}