Detect Container Escape Vulnerabilities with Osquery
<a></a>
1. Container Escapes—Small Bug, Big Blast-Radius
Modern runtimes such as runc and containerd rely on namespace and cgroup isolation to keep a container’s processes away from the host. A single kernel or runtime mistake, however, can punch a hole through that boundary.