phishing OWASP Kubernetes security Veracode key management container security CNCF security secure Kubernetes

Understanding Container Security – Part Two: Security Recommendations

In part one of this series, we discussed the rise in container security threats. As containers have gained in popularity, they’ve also provided an expanding attack surface. We explored why so many ...
container security

Understanding Container Security – Part One: Security Gaps

In our recent interview with Aqua Security’s Rory McCune about CRI-O vulnerability CVE-2022-0811, he mentioned that he’d seen a sharp rise in container cybersecurity threats this year. His experience isn’t unusual; last ...
Fairwinds culture enablement Kubernetes service ownership

Fairwinds Melds Kubernetes Security and Governance

Fairwinds has updated its Kubernetes governance platform to include the ability to automatically scan YAML files and Helm charts stored in GitHub repositories. Announced at the recent KubeCon + CloudNativeCon Europe 2022 ...
containers Lacework zero-trust backup data recovery Red Hat Kubernetes security

Lacework Dives Deeper Into Kubernetes Security

At the KubeCon + CloudNativeCon Europe 2022 conference this week, Lacework extended the reach of its security platform deeper into Kubernetes clusters. The latest update to Lacework’s Polygraph Data Platform adds support ...
Sigstore Monitoring, Designed for Humans

Sigstore Sets Out to Secure Cloud-Native Supply Chain

Open source software (OSS) is pervasive — 90% of companies are now using OSS. But this reliance is a double-edged sword. Amid rising software supply chain attacks, we’re witnessing the fragility of ...
ingress Sysdig SUSE Siloscape security-as-code Docker

SUSE Integrates Container Security Platform With Rancher

At the KubeCon + CloudNativeCon Europe 2022 conference, SUSE announced it has made the NeuVector container security platform available as an open source product. That platform has also been submitted to the ...
devsecops, supply chain, Kubernetes, practices, DevSecOps, JFrog, DevSecOps, Snyk Cerbos DevSecOps authorization incident Deepfence misconfigured Kubernetes security

Deepfence Adds Managed Service to Secure Runtime Environments

Deepfence today at the KubeCon + CloudNativeCon Europe 2022 conference unveiled a managed cloud service through which IT teams can discover vulnerabilities in runtime environments. Owen Garrett, head of products and community ...
Oxeye Delivers CNAST Tool to Better Secure Microservices

Oxeye Delivers CNAST Tool to Better Secure Microservices

At the KubeCon + CloudNativeCon Europe 2022 conference, Oxeye today announced general availability of its Cloud Native Application Security Testing (CNAST) tool to pinpoint vulnerabilities in microservices-based applications. The Oxeye platform requires ...
APIs, microservices, Fermyon, Wasm, Gerrit, systems, services, microservices, JFrog, AI, microservices, tools, GitOps MicroK8s Red Hat Kogito D2iQ

Red Hat Strengthens DevSecOps for OpenShift Platform

Red Hat today made available a preview of patterns for the Red Hat OpenShift platform that promise to make it simpler to secure software supply chains. The patterns, announced at the Red ...
Nutanix, AI applications, platform, Mirantis TriggerMesh Angular Shipa Application security apps Shipa Release of CNX 2.1

Building Apps in Kubernetes? Think Security Everywhere

Cloud-native development practices are rapidly gaining momentum, especially in Kubernetes, as organizations continue to shift away from legacy technologies to take advantage of the reliability, scalability and portability that a cloud-native stack ...