Enumerate pods to find one running as root, privileged, or with a powerful SA
Exec or attach into it
Steal the mounted SA token, access the node, or move laterally
If the pod sets shareProcessNamespace, the exec'd container sees every sibling container's processes and /proc, letting the attacker read another container's env vars and in-memory secrets
Rights needed, any one set:
· any one; both give container stdio
· any one; both give container stdio
