Most Container Images You Pull Today Are Already Full of Vulnerabilities
Container image security has quietly stayed stuck on the same problem it had a decade ago. Finding vulnerabilities is trivial — every major scanner returns pages of them from the average image ...
Remote Code Execution Vulnerabilities Surface in Ingress Nginx
Tel-Aviv’s Wiz Research team says it has identified a series of unauthenticated Remote Code Execution (RCE) vulnerabilities in the Ingress Nginx Controller for Kubernetes. ...
Solving Container Security Challenges: Vulnerabilities, Shadow Deployments and Deployment Gaps
In containerized environments security risks can exist in three areas: Vulnerabilities in software, shadow containers and deployment problems ...
Proactive Container Security: Prioritizing Vulnerabilities with Reachability
Did you know 70% of container vulnerabilities are never exploited? But the 30% that are can be devastating. In today’s fast-paced DevOps environment, ensuring the security of containerized applications is more critical ...
Best of 2023: Three Newly-Discovered Kubernetes Ingress Vulnerabilities Create Security Challenge
Three vulnerabilities were disclosed that impact ingress controllers based on open source Nginx software embedded within Kubernetes clusters ...
Live Workshop on ‘SCA 2.0’: Using Runtime Analysis to Find High-Risk SCA Vulnerabilities
Picture this: Your application is composed of 12 Docker containers. Together, they have 400 packages. Your SCA scan detects 120 critical and high vulnerabilities. Your dev team doesn’t have the cycles to ...
KSOC Shares List of Top Eight Kubernetes Vulnerabilities
Kubernetes Security Operations Center (KSOC) has published a list of the eight Kubernetes vulnerabilities that are most likely to be exploited. The list is based on an Exploit Prediction Scoring System (EPSS) ...
ARMO Employs eBPF to Identify Severe Kubernetes Vulnerabilities
ARMO today announced it has added a capability to its Kubernetes security platform that makes it simpler to prioritize remediation of vulnerabilities based on their relevancy. Ben Hirschberg, ARMO CTO, says this ...
Learning From Kubernetes Vulnerabilities
As Kubernetes has become a widely popular and critical infrastructure component in the modern software stack for small to large organizations, it has also become more susceptible to attacks. Developers typically use ...
Sysdig Shines Spotlight on Container Vulnerabilities Based on Level of Risk
Sysdig today made available a Risk Spotlight tool as part of its cloud service for securing and monitoring container environments that makes it easier to prioritize the vulnerabilities that need to be ...

