Smarticu5
@smarticu5.bsky.social
1.2K followers 200 following 33 posts
Cloud-native offsec at AmberWolf
Posts Media Videos Starter Packs
smarticu5.bsky.social
Just under a week left until kcduk.io, hosted this year in beautiful Edinburgh. If you haven’t got a ticket yet, there are still some available. I can guarantee some excellent company and talks. Weather may vary, but the city’s still pretty in the drizzle.
Kubernetes Community Days UK - Edinburgh 2025 | CNCF
In-person Event - Kubernetes Community Days UK - Edinburgh 2025
kcduk.io
smarticu5.bsky.social
Good luck coming up with an effective keymap for that bad boy.
Reposted by Smarticu5
gralefrit.bsky.social
This is just great.
brainmage.bsky.social
I've edited a video! Of some of my standup! Like you're supposed to when you're a comedian!
Please enjoy "My jokes are good, actually, and here are the reasons why".

Shares/fawning praise etc obviously appreciated x

www.youtube.com/watch?v=s93X...
My jokes are good, actually, and here are the reasons why.
YouTube video by Guy Kelly
www.youtube.com
Reposted by Smarticu5
michaeloneill.org
Please enjoy today, 25/9/2025, the last square date until 2116 (5^2/3^2/45^2).
Reposted by Smarticu5
mccune.org.uk
My talk at @containerdays.bsky.social this week was on Kubernetes and post exploitation. I've had a couple of requests for a companion blog post, so here it is. The post looks at some things attackers might do in clusters they've compromised to retain access.

raesene.github.io/blog/2025/09...
Beyond the surface - Exploring attacker persistence strategies in Kubernetes
raesene.github.io
smarticu5.bsky.social
Completely agreed. It’s possible to do multi-tenancy securely, as long as you’re aware of the edge cases which look safe but aren’t. Having processes, monitoring, and guardrails in place helps hugely with not opening up new attack vectors.
smarticu5.bsky.social
Unsurprisingly, I have opinions about Kubernetes, particularly when it comes to multitenancy and how easy it is to break out of common deployments. Today I wrote about them for @amberwolfsec.bsky.social

blog.amberwolf.com/blog/2025/se...
Breaking Boundaries - Kubernetes Namespaces and multi-tenancy
AmberWolf Security Research Blog
blog.amberwolf.com
Reposted by Smarticu5
pjvphotography.bsky.social
"Pat, why do you carry that ridiculous 600mm lens on long hikes?"

Buddy, I can see mountains reflected in the eyes of a trailside pika.
A pika sits on a mossy rock. Tighter crop of the same pika, focusing on its head. An even tighter crop, focusing more on the pika's eye. An extremely tight crop of the pika's eye, emphasizing their reflection of an early morning mountain scene.
smarticu5.bsky.social
I’ve been considering making the switch from iPhone for a Pixel 10. Of course I managed to drop and smash the iPhone as soon as I’d clicked a trade in valuation.
Reposted by Smarticu5
rawkode.dev
Is your company hiring? Would I be useful to your team?

I think I'm ready to open discussions for 2026.

I still have commitments to finish over the next 6 months, but let's start talking.

I'm in no rush and looking to find the right product / team / company.

RTs appreciated
smarticu5.bsky.social
The camera can also act as temporary glasses when the real glasses were sat down somewhere safe, and then apparently vanished from existence.
smarticu5.bsky.social
How did you not just melt in the heat!?
Reposted by Smarticu5
kcduk.bsky.social
Give a talk at KCD Edinburgh! You don’t even have to be funny (but it helps). CFP here: kcduk.io
smarticu5.bsky.social
Heck yes, this is incredible!
Reposted by Smarticu5
kcduk.bsky.social
Some say the learning curve for Kubernetes is steep. Try the walk up Calton Hill!
smarticu5.bsky.social
Some musings on the use of the “exec” directive in a kubeconfig, and how they might be useful to a red teamer or other nasty internet person: blog.iainsmart.co.uk/posts/kubect...
Kubectl Get Hacked
Discussing some ways kubeconfig files can bite
blog.iainsmart.co.uk
smarticu5.bsky.social
If anyone at #KubeConEU hasn't ever tried a Tunocks caramel wafer, hit me up. I'm travelling prepared.
smarticu5.bsky.social
Gutted to only be at two days of #KubeCon this year. Flying down tomorrow for a swift 36 hours in London catching up with some wonderful people. /honk remotely to everyone already there!
smarticu5.bsky.social
Does anyone who follows me happen to run a blog or similar which they spellcheck with cspell, and have a custom dictionary of container/Linux words?

Apparently the git repo I just ran it on has several hundred typos, but most of those are just "suid" or "containerd" or similar.
smarticu5.bsky.social
After CVE-2024-9042 dropped yesterday, I had a play about to see if I could reproduce the vuln. Spoiler alert, yes I could. I've just published some notes over on the @amberwolfsec.bsky.social blog

blog.amberwolf.com/blog/2025/ja...
Reproducing CVE-2024-9042: Command Injection in Windows Kubernetes Nodes
AmberWolf Security Research Blog
blog.amberwolf.com