Some interesting research by my colleague @christophetd on default service accounts in GCP. Looks at how default rights can be in place and some of the risks to GKE environments.
https://securitylabs.datadoghq.com/articles/google-cloud-default-service-accounts/