On Securing the Kubernetes Dashboard
Recently Tesla (the car company) was alerted, by security firm RedLock, that their Kubernetes infrastructure was compromised. The attackers were using Tesla's infrastructure resources to mine cryptocurrency. This type of attack has been called "cryptojacking". The vector of attack in this case was a Kubernetes Dashboard that was exposed to the general internet with no authentication and elevated privileges.
https://blog.heptio.com/on-securing-the-kubernetes-dashboard-16b09b1b7aca