Patch an existing MutatingWebhookConfiguration to replace the clientConfig.url with an attacker-controlled endpoint
All requests matching the webhook's existing rules are now proxied through the attacker server
Capture SA tokens and secrets.
Silently mutate pod specs or block deployments
