惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
博客园_首页
量子位
T
Tailwind CSS Blog
博客园 - Franky
G
Google Developers Blog
D
DataBreaches.Net
Vercel News
Vercel News
B
Blog
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
爱范儿
爱范儿
博客园 - 【当耐特】
The Cloudflare Blog
H
Help Net Security
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
C
Check Point Blog
有赞技术团队
有赞技术团队
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Top security talks from KubeCon Europe 2025
Shay Berkovich · 2025-04-11 · via Wiz Blog | RSS feed

KubeCon Europe is the largest open source community conference in Europe, with hundreds of sessions—many of them focused on security. The event took place last week at the ExCeL Centre in London, drawing over 13,000 attendees. In this blog, we recap our favorite talks. 

Some of our favorite KubeCon 2025 sessions 

Kubernetes has entered its second decade, and this year’s KubeCon felt markedly different from past editions. The hype and glitz have noticeably faded—it almost felt like CNCF intentionally avoided competing with Black Hat on flashiness. Instead, the conference leaned hard into operationalization, with keynotes spotlighting real-world adoption stories, academic use cases, and AI integrations. True to CNCF tradition, the open source community remained a central theme. 

But this shift also came with tradeoffs: fewer offensive security talks and more sessions focused on secure operations and enterprise adoption. Whether that’s a good thing likely depends on your vantage point—but for those of us deep in cloud security, it reflected a maturing ecosystem prioritizing stability, scale, and long-term viability. 

And now, our favorite sessions: 

Encryption, Identities, and Everything in Between; Building Secure Kubernetes Networks 

Lior Lieberman from Google and Igor Velichkovich bravely took on a notoriously hard concept of Network Policies. Their talk highlighted the lack of mTLS for internal service communication and the shortcomings of current NetworkPolicy implementations. These challenges mirror issues we raised in a previous Kubernetes Security Report, especially around lateral movement risks. The session also proposed architectural and implementation strategies worth following closely in future updates. 

Redefining Access Control: Scaling Policy as Code for Humans and AI Agents  

It’s good to see AI identity finally getting the attention it deserves. Raz Cohen from Permit.io argued that existing identity frameworks fall short when applied to AI agents and services. His session proposed a new vision—and architecture—for AI-native access control. This space is just beginning to evolve, and the ideas presented here could be foundational.  

Lessons Learned in LLM Prompt Security 

Jakub Suchy’s short sponsored keynote was one of the more compelling ones. He introduced HAProxy’s work on an AI Gateway—a traffic-routing solution tailored for AI services—and detailed the real-world security challenges in prompt protection. The key tension: using AI to secure AI introduces performance and reliability tradeoffs. This felt like a teaser for a much deeper 30-minute session. We hope he expands it in a future event.  

Enhancing Software Composition Analysis Resilience Against Container Image Obfuscation 

A continuation of research first presented at KubeCon EU 2023, this talk showcased new image obfuscation techniques and stressed limitations in current software composition analysis (SCA) tools. More importantly, it didn’t just point out problems—it proposed practical improvements for SBOM generation algorithms, a rare but welcome move. 

And a noteworthy talk from Wiz - Kubernetes Security 2030

We gave a talk focused on what Kubernetes security will look like in the next five years—drawing lessons from working with half of the Fortune 100. The central idea: as Kubernetes use cases grow (thanks to its extensibility), threat models evolve, which, in turn. drives changes in security controls. That evolution will demand new types of security controls. 

Three areas we emphasized: 

  1. Securing AI workloads — and the new security layers required .

  2. Vulnerabilities in peripheral components — hello, #IngressNightmare.

  3. Cloud-cluster integration — because cloud security problems don’t stop at the Kubernetes boundary.

See the slides from the talk here.

Conclusion

We highly recommend attending KubeCon Europe! And if you’re interested in more beginner-level information on Kubernetes, see our CloudSec Academy section on Kubernetes Security Best Practices, or download our guide to Kubernetes Security for Dummies.