I am going to quote the BleepingComputer article by Sergiu Gatlan to illustrate the reach of the vulnerability in Fluent Bit.
“Fluent Bit is an extremely popular logging and metrics solution for Windows, Linux, and macOS embedded in major Kubernetes distributions, including those from Amazon AWS, Google GCP, and Microsoft Azure.”
Critical Fluent Bit flaw impacts all major cloud providers – BleepingComputer
A patch has been released and distributed but this story shows how a small a small component in a large supply chain – that many depend on – can be a feeding frenzy for the threat actors if they find it first. This is the zero-day problem.
Your takeaway
Read my zero-day primer and then consider that our security operations centre – starting at just £10 per month – looks for “indicators of compromise” to alert us to your information being compromised. It is one of the only defences against the zero-day problem.
Clive Catton MSc (Cyber Security) – by-line and other articles