惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
V2EX
WordPress大学
WordPress大学
U
Unit 42
I
InfoQ
A
About on SuperTechFans
宝玉的分享
宝玉的分享
J
Java Code Geeks
博客园 - 司徒正美
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
G
Google Developers Blog
人人都是产品经理
人人都是产品经理
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
L
LangChain Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
aimingoo的专栏
aimingoo的专栏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
腾讯CDC
Recent Announcements
Recent Announcements

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Top Security Talks from KubeCon Europe 2023
Shay Berkovich · 2023-05-11 · via Wiz Blog | RSS feed

KubeCon + CloudNativeCon Europe 2023 took place last week in Amsterdam with over 10,000 attendees, nearly 280 sessions, and multiple keynote speeches. All the conference’s videos have been released on YouTube.

Here are some of our favorite KubeCon 2023 talks:

Can You Keep a Secret? on Secret Management in Kubernetes – Every production application today utilizes secrets. Gal Cohen and Liav Yona from Firefly provide an overview of the use cases and challenges of secrets in Kubernetes. They then discuss the benefits of secret store providers before delving into the Secrets Container Storage Interface (CSI), a novel, secure way of using secrets. Both the architecture and the demo presented during the talk are extremely helpful to practitioners.

Practical Challenges with Pod Security Admission – Now is the time to migrate from Pod Security Policies (PSP) to Pod Security Standards (PSS). The problem is, many workloads require some degree of privilege not easily mappable to PSS. In this timely talk, V. Körbes and Christian Schlotter from VMware tackle K8s workload migration to Pod Security Admission and describe the steps needed to identify issues with node deployments and the Container Storage Interface (CSI) controller. It is gratifying that a technical process as complex as PSP migration is getting the attention it deserves.

Least Privilege Containers: Keeping a Bad Day from Getting Worse – “Don’t run containers as root” is the security mantra that has been with us for years. Nevertheless, most containers run as root because of migration difficulties and the privileges required by numerous processes. Greg Castle and Vinayak Goyal from Google offer their unique perspective on migrating GKE containers to non-root at scale. They explain the challenges they faced and the design choices behind their solutions. The last part of the talk is devoted to an increasingly relevant topic: Kubernetes adoption of user namespaces and its game-changing potential for container security.

Canals and Bridges: Using Amsterdam’s Transit System to Secure K8s Networks – Cailyn Edwards from Shopify provides a fresh take on Kubernetes by comparing it to the Amsterdam canal system. This analogy proves effective in explaining general Kubernetes security controls with an emphasis on secure networking within its components. Her demo contains an application of the inspektor gadget tool to showcase how easy it is to create a workload seccomp profile and a network policy. This is a useful talk for those looking to upgrade their cluster security via stricter policies.

What Can Go Wrong When You Trust Nobody? Threat Modeling Zero Trust – In another solid modeling session by Control Plane, James Callaghan and Richard Featherstone present Zero Trust environment threat modeling. Their demos are especially valuable in showing the practical applications of security controls (including Spire and OPA) used during the mitigation stage.

Last but not least, if you run managed GKE, AKS, or EKS clusters and want to know what kind of security risks they carry, you are invited to watch our talk, Cluster Grey Zone: Risks in Managed Cluster Middleware. It sheds a light on an overlooked attack surface in managed Kubernetes clusters and reveals some cool attack chains originating from middleware components that you might not be aware of.

This has been both the largest KubeCon + CloudNativeCon and largest open-source conference in Europe so far, with 58% of participants attending for their first time. Given the exponential growth this community has been experiencing recently, we are sure there are more record-breaking events to come.

We are now looking ahead to the next conference: KubeCon NA in Chicago.