A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.
Casky was already ahead
This CVE exploits attack patterns that Casky's 312matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-42965 exposes a critical vulnerability in OpenShift Router where users with EndpointSlice write permissions can redirect traffic to cloud metadata endpoints by creating Services backed by FQDN-based EndpointSlices. This bypasses IP address validation controls that previously protected cloud metadata services like AWS IMDSv1/v2, Azure IMDS, and GCP metadata endpoints. Attackers exploit this to extract instance credentials, role ARNs, temporary tokens, and other sensitive metadata without direct network access—effectively turning the router into a proxy for credential theft. Any organization running OpenShift in cloud environments is affected, particularly those with multi-tenant clusters where service account permissions are broadly distributed.
Casky's 312 matched skills detect this attack pattern by mapping to MITRE ATT&CK techniques TA0001 (Initial Access) and TA0006 (Credential Access). Claude's extended reasoning identifies suspicious behavioral patterns: EndpointSlice creation with FQDN values pointing to known metadata service ranges (169.254.x.x, metadata.google.internal, etc.), anomalous proxy traffic destined for cloud metadata endpoints, and credential material appearing in router logs or audit events. Practitioners using Casky would see findings flagged for unusual Service configurations with external FQDNs, unexpected outbound connections from the router to metadata endpoints, and correlations between EndpointSlice modifications and subsequent credential exposure events—enabling detection of both configuration-based exploitation and post-compromise credential exfiltration.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
These skills use Claude AI's reasoning model to surface findings in the same attack categories as CVE-2026-42965.
Casky has 312 skills that investigate the attack patterns behind CVE-2026-42965. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →analyzing-office365-audit-logs-for-compromise
cloud security · low
auditing-aws-s3-bucket-permissions
cloud security · low
auditing-azure-active-directory-configuration
cloud security · low
auditing-cloud-with-cis-benchmarks
cloud security · low
auditing-gcp-iam-permissions
cloud security · low
auditing-kubernetes-cluster-rbac
cloud security · low
auditing-terraform-infrastructure-for-security
cloud security · low
building-c2-infrastructure-with-sliver-framework
red teaming · high
building-cloud-siem-with-sentinel
cloud security · low
building-devsecops-pipeline-with-gitlab-ci
devsecops · low
building-identity-federation-with-saml-azure-ad
identity access management · low
building-identity-governance-lifecycle-process
identity access management · low
building-patch-tuesday-response-process
vulnerability management · medium
building-phishing-reporting-button-workflow
phishing defense · medium
building-red-team-c2-infrastructure-with-havoc
red teaming · high
building-role-mining-for-rbac-optimization
identity access management · low
building-vulnerability-aging-and-sla-tracking
vulnerability management · medium
building-vulnerability-dashboard-with-defectdojo
vulnerability management · medium
building-vulnerability-exception-tracking-system
vulnerability management · medium
bypassing-authentication-with-forced-browsing
web application security · medium
conducting-api-security-testing
penetration testing · medium
conducting-cloud-penetration-testing
cloud security · low
conducting-domain-persistence-with-dcsync
red teaming · high
conducting-external-reconnaissance-with-osint
penetration testing · medium
conducting-full-scope-red-team-engagement
red teaming · high
conducting-internal-network-penetration-test
penetration testing · medium
conducting-internal-reconnaissance-with-bloodhound-ce
red teaming · high
conducting-mobile-app-penetration-test
penetration testing · medium
conducting-network-penetration-test
penetration testing · medium
conducting-pass-the-ticket-attack
red teaming · high
conducting-social-engineering-penetration-test
penetration testing · medium
conducting-social-engineering-pretext-call
red teaming · high
conducting-spearphishing-simulation-campaign
red teaming · high
conducting-wireless-network-penetration-test
penetration testing · medium
configuring-active-directory-tiered-model
identity access management · low
configuring-aws-verified-access-for-ztna
zero trust architecture · low
configuring-certificate-authority-with-openssl
cryptography · low
configuring-hsm-for-key-storage
cryptography · low
configuring-identity-aware-proxy-with-google-iap
zero trust architecture · low
configuring-ldap-security-hardening
identity access management · low
configuring-microsegmentation-for-zero-trust
zero trust architecture · low
configuring-multi-factor-authentication-with-duo
identity access management · low
configuring-oauth2-authorization-flow
identity access management · low
configuring-tls-1-3-for-secure-communications
cryptography · low
configuring-zscaler-private-access-for-ztna
zero trust architecture · low
deploying-cloudflare-access-for-zero-trust
zero trust architecture · low
deploying-palo-alto-prisma-access-zero-trust
zero trust architecture · low
deploying-software-defined-perimeter
zero trust architecture · low
deploying-tailscale-for-zero-trust-vpn
zero trust architecture · low
detecting-anomalous-authentication-patterns
identity access management · low
detecting-api-enumeration-attacks
api security · medium
detecting-aws-cloudtrail-anomalies
cloud security · low
detecting-aws-credential-exposure-with-trufflehog
cloud security · low
detecting-aws-guardduty-findings-automation
cloud security · low
detecting-aws-iam-privilege-escalation
cloud security · low
detecting-azure-lateral-movement
cloud security · low
detecting-azure-service-principal-abuse
cloud security · low
detecting-azure-storage-account-misconfigurations
cloud security · low
detecting-broken-object-property-level-authorization
api security · medium
detecting-business-email-compromise
phishing defense · medium
detecting-business-email-compromise-with-ai
phishing defense · medium
detecting-cloud-threats-with-guardduty
cloud security · low
detecting-compromised-cloud-credentials
cloud security · low
detecting-cryptomining-in-cloud
cloud security · low
detecting-misconfigured-azure-storage
cloud security · low
detecting-mobile-malware-behavior
mobile security · low
detecting-oauth-token-theft
cloud security · low
detecting-qr-code-phishing-with-email-security
phishing defense · medium
detecting-s3-data-exfiltration-attempts
cloud security · low
detecting-serverless-function-injection
cloud security · low
detecting-shadow-api-endpoints
api security · medium
detecting-shadow-it-cloud-usage
cloud security · low
detecting-spearphishing-with-email-gateway
phishing defense · medium
detecting-suspicious-oauth-application-consent
cloud security · low
executing-active-directory-attack-simulation
penetration testing · medium
executing-phishing-simulation-campaign
penetration testing · medium
executing-red-team-engagement-planning
red teaming · high
executing-red-team-exercise
penetration testing · medium
exploiting-active-directory-certificate-services-esc1
red teaming · high
exploiting-active-directory-with-bloodhound
red teaming · high
exploiting-api-injection-vulnerabilities
api security · medium
exploiting-broken-function-level-authorization
api security · medium
exploiting-broken-link-hijacking
web application security · medium
exploiting-constrained-delegation-abuse
red teaming · high
exploiting-deeplink-vulnerabilities
mobile security · low
exploiting-excessive-data-exposure-in-api
api security · medium
exploiting-http-request-smuggling
web application security · medium
exploiting-idor-vulnerabilities
web application security · medium
exploiting-insecure-data-storage-in-mobile
mobile security · low
exploiting-insecure-deserialization
web application security · medium
exploiting-jwt-algorithm-confusion-attack
api security · medium
exploiting-kerberoasting-with-impacket
red teaming · high
exploiting-mass-assignment-in-rest-apis
web application security · medium
exploiting-ms17-010-eternalblue-vulnerability
red teaming · high
exploiting-nopac-cve-2021-42278-42287
red teaming · high
exploiting-nosql-injection-vulnerabilities
web application security · medium
exploiting-oauth-misconfiguration
web application security · medium
exploiting-prototype-pollution-in-javascript
web application security · medium
exploiting-race-condition-vulnerabilities
web application security · medium
exploiting-server-side-request-forgery
web application security · medium
exploiting-sql-injection-vulnerabilities
penetration testing · medium
exploiting-sql-injection-with-sqlmap
web application security · medium
exploiting-template-injection-vulnerabilities
web application security · medium
exploiting-type-juggling-vulnerabilities
web application security · medium
exploiting-vulnerabilities-with-metasploit-framework
vulnerability management · medium
exploiting-websocket-vulnerabilities
web application security · medium
exploiting-zerologon-vulnerability-cve-2020-1472
red teaming · high
implementing-aes-encryption-for-data-at-rest
cryptography · low
implementing-anti-phishing-training-program
phishing defense · medium
implementing-api-abuse-detection-with-rate-limiting
api security · medium
implementing-api-gateway-security-controls
api security · medium
implementing-api-key-security-controls
api security · medium
implementing-api-rate-limiting-and-throttling
api security · medium
implementing-api-schema-validation-security
api security · medium
implementing-api-security-posture-management
api security · medium
implementing-api-security-testing-with-42crunch
api security · medium
implementing-api-threat-protection-with-apigee
api security · medium
implementing-aqua-security-for-container-scanning
devsecops · low
implementing-attack-path-analysis-with-xm-cyber
vulnerability management · medium
implementing-aws-config-rules-for-compliance
cloud security · low
implementing-aws-iam-permission-boundaries
identity access management · low
implementing-aws-macie-for-data-classification
cloud security · low
implementing-aws-nitro-enclave-security
cloud security · low
implementing-aws-security-hub
cloud security · low
implementing-aws-security-hub-compliance
cloud security · low
implementing-azure-ad-privileged-identity-management
identity access management · low
implementing-azure-defender-for-cloud
cloud security · low
implementing-beyondcorp-zero-trust-access-model
zero trust architecture · low
implementing-cisa-zero-trust-maturity-model
zero trust architecture · low
implementing-cloud-dlp-for-data-protection
cloud security · low
implementing-cloud-security-posture-management
cloud security · low
implementing-cloud-trail-log-analysis
cloud security · low
implementing-cloud-vulnerability-posture-management
vulnerability management · medium
implementing-cloud-waf-rules
cloud security · low
implementing-cloud-workload-protection
cloud security · low
implementing-code-signing-for-artifacts
devsecops · low
implementing-conditional-access-policies-azure-ad
identity access management · low
implementing-continuous-security-validation-with-bas
vulnerability management · medium
implementing-delinea-secret-server-for-pam
identity access management · low
implementing-device-posture-assessment-in-zero-trust
zero trust architecture · low
implementing-digital-signatures-with-ed25519
cryptography · low
implementing-dmarc-dkim-spf-email-security
phishing defense · medium
implementing-email-sandboxing-with-proofpoint
phishing defense · medium
implementing-end-to-end-encryption-for-messaging
cryptography · low
implementing-envelope-encryption-with-aws-kms
cryptography · low
implementing-epss-score-for-vulnerability-prioritization
vulnerability management · medium
implementing-fuzz-testing-in-cicd-with-aflplusplus
devsecops · low
implementing-gcp-binary-authorization
cloud security · low
implementing-gcp-organization-policy-constraints
cloud security · low
implementing-gcp-vpc-firewall-rules
cloud security · low
implementing-github-advanced-security-for-code-scanning
devsecops · low
implementing-google-workspace-admin-security
identity access management · low
implementing-google-workspace-phishing-protection
phishing defense · medium
implementing-google-workspace-sso-configuration
identity access management · low
implementing-hashicorp-vault-dynamic-secrets
identity access management · low
implementing-identity-governance-with-sailpoint
identity access management · low
implementing-identity-verification-for-zero-trust
zero trust architecture · low
implementing-infrastructure-as-code-security-scanning
devsecops · low
implementing-just-in-time-access-provisioning
identity access management · low
implementing-jwt-signing-and-verification
cryptography · low
implementing-microsegmentation-with-guardicore
zero trust architecture · low
implementing-mimecast-targeted-attack-protection
phishing defense · medium
implementing-mobile-application-management
mobile security · low
implementing-pam-for-database-access
identity access management · low
implementing-passwordless-auth-with-microsoft-entra
identity access management · low
implementing-passwordless-authentication-with-fido2
identity access management · low
implementing-patch-management-workflow
vulnerability management · medium
implementing-policy-as-code-with-open-policy-agent
devsecops · low
implementing-privileged-access-management-with-cyberark
identity access management · low
implementing-privileged-session-monitoring
identity access management · low
implementing-proofpoint-email-security-gateway
phishing defense · medium
implementing-rapid7-insightvm-for-scanning
vulnerability management · medium
implementing-rsa-key-pair-management
cryptography · low
implementing-saml-sso-with-okta
identity access management · low
implementing-scim-provisioning-with-okta
identity access management · low
implementing-secret-scanning-with-gitleaks
devsecops · low
implementing-secrets-management-with-vault
cloud security · low
implementing-secrets-scanning-in-ci-cd
devsecops · low
implementing-semgrep-for-custom-sast-rules
devsecops · low
implementing-vulnerability-management-with-greenbone
vulnerability management · medium
implementing-vulnerability-remediation-sla
vulnerability management · medium
implementing-vulnerability-sla-breach-alerting
vulnerability management · medium
implementing-web-application-logging-with-modsecurity
web application security · medium
implementing-zero-knowledge-proof-for-authentication
cryptography · low
implementing-zero-standing-privilege-with-cyberark
identity access management · low
implementing-zero-trust-dns-with-nextdns
zero trust architecture · low
implementing-zero-trust-for-saas-applications
zero trust architecture · low
implementing-zero-trust-in-cloud
cloud security · low
implementing-zero-trust-network-access
cloud security · low
implementing-zero-trust-network-access-with-zscaler
zero trust architecture · low
implementing-zero-trust-with-hashicorp-boundary
zero trust architecture · low
integrating-dast-with-owasp-zap-in-pipeline
devsecops · low
integrating-sast-into-github-actions-pipeline
devsecops · low
intercepting-mobile-traffic-with-burpsuite
mobile security · low
managing-cloud-identity-with-okta
cloud security · low
performing-access-recertification-with-saviynt
identity access management · low
performing-access-review-and-certification
identity access management · low
performing-active-directory-bloodhound-analysis
red teaming · high
performing-active-directory-penetration-test
penetration testing · medium
performing-active-directory-vulnerability-assessment
vulnerability management · medium
performing-adversary-in-the-middle-phishing-detection
phishing defense · medium
performing-agentless-vulnerability-scanning
vulnerability management · medium
performing-android-app-static-analysis-with-mobsf
mobile security · low
performing-api-fuzzing-with-restler
api security · medium
performing-api-inventory-and-discovery
api security · medium
performing-api-rate-limiting-bypass
api security · medium
performing-api-security-testing-with-postman
api security · medium
performing-asset-criticality-scoring-for-vulns
vulnerability management · medium
performing-authenticated-scan-with-openvas
vulnerability management · medium
performing-authenticated-vulnerability-scan
vulnerability management · medium
performing-aws-account-enumeration-with-scout-suite
cloud security · low
performing-aws-privilege-escalation-assessment
cloud security · low
performing-blind-ssrf-exploitation
web application security · medium
performing-clickjacking-attack-test
web application security · medium
performing-cloud-asset-inventory-with-cartography
cloud security · low
performing-cloud-forensics-with-aws-cloudtrail
cloud security · low
performing-cloud-log-forensics-with-athena
cloud security · low
performing-cloud-native-forensics-with-falco
cloud security · low
performing-cloud-native-threat-hunting-with-aws-detective
cloud security · low
performing-cloud-penetration-testing-with-pacu
cloud security · low
performing-container-image-hardening
devsecops · low
performing-content-security-policy-bypass
web application security · medium
performing-credential-access-with-lazagne
red teaming · high
performing-cryptographic-audit-of-application
cryptography · low
performing-csrf-attack-simulation
web application security · medium
performing-cve-prioritization-with-kev-catalog
vulnerability management · medium
performing-directory-traversal-testing
web application security · medium
performing-dmarc-policy-enforcement-rollout
phishing defense · medium
performing-dynamic-analysis-of-android-app
mobile security · low
performing-entitlement-review-with-sailpoint-iiq
identity access management · low
performing-external-network-penetration-test
penetration testing · medium
performing-gcp-penetration-testing-with-gcpbucketbrute
cloud security · low
performing-gcp-security-assessment-with-forseti
cloud security · low
performing-graphql-depth-limit-attack
api security · medium
performing-graphql-introspection-attack
api security · medium
performing-graphql-security-assessment
web application security · medium
performing-hardware-security-module-integration
cryptography · low
performing-hash-cracking-with-hashcat
cryptography · low
performing-http-parameter-pollution-attack
web application security · medium
performing-initial-access-with-evilginx3
red teaming · high
performing-ios-app-security-assessment
mobile security · low
performing-iot-security-assessment
penetration testing · medium
performing-jwt-none-algorithm-attack
api security · medium
performing-kerberoasting-attack
red teaming · high
performing-lateral-movement-with-wmiexec
red teaming · high
performing-mobile-app-certificate-pinning-bypass
mobile security · low
performing-oauth-scope-minimization-review
identity access management · low
performing-open-source-intelligence-gathering
red teaming · high
performing-phishing-simulation-with-gophish
phishing defense · medium
performing-physical-intrusion-assessment
red teaming · high
performing-post-quantum-cryptography-migration
cryptography · low
performing-privilege-escalation-assessment
penetration testing · medium
performing-privilege-escalation-on-linux
red teaming · high
performing-privileged-account-access-review
identity access management · low
performing-privileged-account-discovery
identity access management · low
performing-sca-dependency-scanning-with-snyk
devsecops · low
performing-second-order-sql-injection
web application security · medium
performing-security-headers-audit
web application security · medium
performing-serverless-function-security-review
cloud security · low
performing-service-account-audit
identity access management · low
performing-service-account-credential-rotation
identity access management · low
performing-soap-web-service-security-testing
api security · medium
performing-ssl-certificate-lifecycle-management
cryptography · low
performing-subdomain-enumeration-with-subfinder
web application security · medium
performing-thick-client-application-penetration-test
penetration testing · medium
performing-threat-modeling-with-owasp-threat-dragon
devsecops · low
performing-vulnerability-scanning-with-nessus
penetration testing · medium
performing-web-application-firewall-bypass
web application security · medium
performing-web-application-penetration-test
penetration testing · medium
performing-web-application-scanning-with-nikto
vulnerability management · medium
performing-web-application-vulnerability-triage
vulnerability management · medium
performing-web-cache-deception-attack
web application security · medium
performing-web-cache-poisoning-attack
web application security · medium
performing-wireless-network-penetration-test
penetration testing · medium
prioritizing-vulnerabilities-with-cvss-scoring
vulnerability management · medium
remediating-s3-bucket-misconfiguration
cloud security · low
reverse-engineering-ios-app-with-frida
mobile security · low
scanning-containers-with-trivy-in-cicd
devsecops · low
scanning-infrastructure-with-nessus
vulnerability management · medium
securing-api-gateway-with-aws-waf
cloud security · low
securing-aws-iam-permissions
cloud security · low
securing-aws-lambda-execution-roles
cloud security · low
securing-azure-with-microsoft-defender
cloud security · low
securing-container-registry-images
cloud security · low
securing-github-actions-workflows
devsecops · low
securing-kubernetes-on-cloud
cloud security · low
securing-serverless-functions
cloud security · low
testing-android-intents-for-vulnerabilities
mobile security · low
testing-api-authentication-weaknesses
api security · medium
testing-api-for-broken-object-level-authorization
api security · medium
testing-api-for-mass-assignment-vulnerability
api security · medium
testing-api-security-with-owasp-top-10
web application security · medium
testing-cors-misconfiguration
web application security · medium
testing-for-broken-access-control
web application security · medium
testing-for-business-logic-vulnerabilities
web application security · medium
testing-for-email-header-injection
web application security · medium
testing-for-host-header-injection
web application security · medium
testing-for-json-web-token-vulnerabilities
web application security · medium
testing-for-open-redirect-vulnerabilities
web application security · medium
testing-for-sensitive-data-exposure
web application security · medium
testing-for-xml-injection-vulnerabilities
web application security · medium
testing-for-xss-vulnerabilities
penetration testing · medium
testing-for-xss-vulnerabilities-with-burpsuite
web application security · medium
testing-for-xxe-injection-vulnerabilities
web application security · medium
testing-jwt-token-security
web application security · medium
testing-mobile-api-authentication
mobile security · low
testing-oauth2-implementation-flaws
api security · medium
testing-websocket-api-security
api security · medium
triaging-vulnerabilities-with-ssvc-framework
vulnerability management · medium
© 2026 Casky.AI, Inc. · AI Security Investigation