This session moves beyond initial cluster access to explore a highly stealthy persistence vector: the weaponization of Mutating Admission Controllers. While typically used for security policy enforcement, these controllers can be subverted to inject malicious sidecars or modify pod specs in real-time without altering original deployment manifests. We will demonstrate how an attacker can maintain a "ghost" presence that survives standard audits, image updates, and pod restarts, effectively turning the Kubernetes control plane against itself.
Presented at Security Fest 2026.
Speakers: Harshita Varma, Nikita VermaWith a background that bridges technical engineering and product strategy, Harshita has a unique perspective on scaling complex systems while maintaining a high bar for quality and security. She was awarded the Dan Kohn Scholarship to attend KubeCon EU 2023 and recently co-presented the session "From Noise to Clarity: Humanizing Observability" at KubeCon + CloudNativeCon North America 2025 in Atlanta. Harshita is an active international speaker, with upcoming engagements at ContainerDays London 2026. Traveling from India, she is passionate about fostering a "Security-First" culture within DevOps teams and advocating for more inclusive, sustainable open-source communities.
Nikita Verma is a Platform Engineer and Cloud Native Advocate with over three years of experience building resilient, automated infrastructure. A dedicated open-source contributor, Nikita has worked on core Kubernetes projects and cloud-native automation, including impactful work with Moja Global during an Outreachy internship. Beyond engineering, Nikita is a passionate educator who has mentored over 10,000 students in Data Structures, Algorithms, and Cloud Native technologies. As an active member of the global tech community, she has shared her expertise at major conferences across the globe, including KubeCon + CloudNativeCon North America 2025 in Atlanta, ContainerDays London, and SeleniumConf Valencia.