The root cause was a chain of known exploits due to very out of date software:
* RunC v1.0.0-rc2 was released on Oct. 1, 2016, and was vulnerable to at least two container breakout CVEs.
* ACI was hosted on clusters running either Kubernetes v1.8.4, v1.9.10 or v1.10.9. These versions were released between November 2017 and October 2018 and are vulnerable to multiple publicly known vulnerabilities.
Running multitenant workloads in Kubernetes is notoriously difficult, and staying on top of patches is simply table-stakes.