A local malicious user can circumvent the Falco detection engine through 0.28.1 by running a program that alters arguments of system calls being executed. Issue is fixed in Falco versions >= 0.29.1.
No PoCs from references.
- https://github.com/leodido/demo-cloud-native-ebpf-day