Last week, Sven and I had the incredible opportunity to give our first talk at Black Hat USA 2026, titled Breaking Multi-Tenancy Over and Over, and What We Can Learn From This.
In our presentation, we explored the security challenges of namespace-based multi-tenancy in Kubernetes. We demonstrated real-world attacks against Kubeflow, Istio, and Traefik that can break the intended isolation between namespaces and workloads. One of the highlights was demonstrating a privilege-escalation attack we discovered that allowed us to gain cluster-admin privileges.
As part of our Black Hat talk, we also published ERNW Whitepaper 78: Breaking Multi-Tenancy in Kubernetes Over and Over, and What We Can Learn From This. The white paper explains the vulnerabilities we discovered in detail, provides the necessary technical background, and expands on our methodology with practical guidance for assessing the security of multi-tenant Kubernetes environments.

Beyond the technical content, standing on the Black Hat stage for the first time was an unforgettable experience. Presenting our research to such an engaged audience of security professionals was both exciting and humbling.
What made the experience even more rewarding was the response from the community. After the talk and throughout the rest of the conference, we received thoughtful questions, had many valuable discussions, and heard a great deal of positive feedback. It is incredibly motivating to see our research resonate with practitioners facing these challenges in the real world.
Even a week later, we are still energized by the experience. We are already looking forward to the next Black Hat, whether to present new research or simply to reconnect with the many inspiring people who make this community so special.
A big thank you to everyone who attended our talk, asked questions, or stopped by afterward to chat. We truly appreciate it.
Cheers,
Lorin & Sven
If you’re interested in offensive Kubernetes security, we will also be offering an Offensive Kubernetes Security 101 training in December.
If you enjoyed our Black Hat talk, the training is a great opportunity to dive deeper into Kubernetes security from an attacker’s perspective and gain hands-on experience.