WhisperX tag archive

#apiCall

This page collects WhisperX intelligence signals tagged #apiCall. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-29 10:54:16 · GitHub Issues

1. Kyverno Flaw Auto-Attaches Kubernetes ServiceAccount Tokens to External API Calls, Raising Exfiltration Risk

A vulnerability in Kyverno's apiCall service mode silently attaches admission controller ServiceAccount (SA) tokens to all outbound HTTP requests, creating a credential exposure pathway when requests reach external or attacker-controlled endpoints. The flaw operates as an insecure default behavior, meaning policy autho...