This is super interesting. If you actually look at a Loadbalancer logs without a WAF in place, you will see huge amount of bot activity.
What is not clear in the blogs is how did they actually accessed the API server without a valid service token. Secondly, they index alot on IPs, that implied these are k8s cluster that are not managed (EKS, GKE etc).
Is my assumption correct?