Start with the path in the platform's own statement: one internally leaked cloud
admin key, into a shared cluster, VPN access to
the control plane from inside the cluster, into the main database — then a deliberate,
targeted query-and-export of user environment variables, specifically hunting AI API keys.
Hold that chain up against yesterday's rules and every link is a textbook demonstration:
one key opens the whole platform (rule 1: blast radius per tenant); secrets could be
queried and exported straight out of a database (rule 2: secrets move only as ciphertext);
and through the whole thing the attacker never touched a single customer's service —
they hit the one point where everyone's secrets
converge. Exactly yesterday's thesis: the leak path isn't lateral movement,
it's the convergence point scraped once.
Update, 31 August 2026: the full path deserves a
sharper reading than this. The route to the convergence point was lateral
movement, out of a shared cluster that was being decommissioned and still held internal
access to the core database — so network isolation was one of two gates here, not an
irrelevance.
One of yesterday's five questions to ask your PaaS was: "Can your admin token read
tenant secrets?" This incident is what the wrong answer looks like.