Cloud-Native Security
RapidFort Creates Multiple Alliances to Better Secure Cloud-Native Applications
RapidFort, a provider of curated open source container images, has allied with both Wiz and Aqua Security to streamline DevSecOps workflows for organizations building and deploying cloud-native applications. Additionally, RapidFort has inked ...
Why Kubernetes RBAC Misconfigurations Are the Easiest Privilege Escalation You’ll Ever Find
Ask any penetration tester which part of a Kubernetes assessment reliably produces a finding, and RBAC comes up almost every time. Not because Kubernetes’ permission model is poorly designed — it’s genuinely ...
Production-Safe Security Testing: A Missing Layer in Cloud-Native Application Security
Cloud-native applications keep changing after deployment, making production-safe security testing essential for validating real vulnerabilities, misconfigurations and access-control gaps without disrupting live systems ...
Dharmesh Acharya | | API security, application security, attack surface management, business logic flaws, CI/CD security, cloud native security, cloud security, container security, continuous security testing, DevSecOps, IAM security, microservices security, misconfiguration, non-destructive testing, penetration testing, production security testing, production validation, runtime security, security posture, vulnerability validation
Manifestly Safer, Why Kubernetes Wants Developers to Speak KYAML
KYAML gives Kubernetes developers a stricter, more predictable YAML dialect designed to reduce configuration errors, ambiguity, indentation problems and unexpected type coercion ...
Adrian Bridgwater | | CI/CD, cloud native, cloud native security, cloud-native architecture, configuration management, containers, devops, DevSecOps, Helm, KEP 5295, kubectl, kubernetes, Kubernetes configuration, Kubernetes manifests, Kubernetes security, Kubernetes YAML, KYAML, open source, platform engineering, SIG CLI, YAML, YAML errors
RapidFort Allies with CrowdStrike to Harden Container Images
RapidFort this week revealed it has integrated its container vulnerability remediation platform with the cloud security platform provided by CrowdStrike. Announced at the Fal.Con 2026 event hosted by CrowdStrike, the integration enables ...
From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments
The standard process of building governance, risk, and compliance (GRC) programs has been straightforward: define a control, document a control, test the control on a regular basis, and generate a report for ...
BellSoft Rings Change Bringing Zero-CVE Images to Buildpacks Users
BellSoft is bolstering Paketo Buildpacks. As an OpenJDK vendor known for providing tested (and commercially supported) Java distributions, Bellsoft is now offering a new hardened builder image for Paketo Buildpacks ...
The Pipeline That Thinks: Building an AI-Powered DevSecOps Pipeline on AWS EKS
The organizations building pipelines that think, review, secure, monitor and recover, are defining what the next baseline looks like ...
Security Flaw in Argo CD Can Let Attackers Take Over Kubernetes Clusters
Argo CD has become a widely popular open source tool for developers who use GitOps for deploying cloud-native applications to Kubernetes. For cyberthreat actors who are already increasingly focusing their attention on ...
The AI Remediation Bottleneck: Why the Software Supply Chain Demands Radical Openness
For years, the DevSecOps movement has operated on a foundational premise that if you detect a vulnerability, you triage it, patch it, and redeploy. This cycle assumes that our capability to remediate ...

