cloud security
Production-Safe Security Testing: A Missing Layer in Cloud-Native Application Security
Cloud-native applications keep changing after deployment, making production-safe security testing essential for validating real vulnerabilities, misconfigurations and access-control gaps without disrupting live systems ...
Dharmesh Acharya | | API security, application security, attack surface management, business logic flaws, CI/CD security, cloud native security, cloud security, container security, continuous security testing, DevSecOps, IAM security, microservices security, misconfiguration, non-destructive testing, penetration testing, production security testing, production validation, runtime security, security posture, vulnerability validation
From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments
The standard process of building governance, risk, and compliance (GRC) programs has been straightforward: define a control, document a control, test the control on a regular basis, and generate a report for ...
Prompt Injection in Cloud-Native AI Is Now an Access Control Problem
For a long time, prompt injection was treated like other model behavior problems, such as jailbreaks or strange responses. The usual fix was to improve the system prompt, add stronger filters, or ...
Building a Secure Software Development Lifecycle (SSDLC) for Cloud-Native Teams
As cloud-native architectures continue to redefine how applications are built and deployed, security must evolve alongside them. Often bolted on at the end of development, traditional approaches are no longer sufficient in ...
The Pipeline That Thinks: Building an AI-Powered DevSecOps Pipeline on AWS EKS
The organizations building pipelines that think, review, secure, monitor and recover, are defining what the next baseline looks like ...
Self-Healing Kubernetes Gets Real—and Risky: Running AI Agents on Amazon EKS
For years, “self-healing Kubernetes” meant a liveness probe restarting a crashed pod. In 2026 it means something far more literal: an autonomous agent that reads your cluster’s logs and metrics, forms a ...
The Questions Every Team Asks About Docker Sandboxes
Docker Sandboxes launched in March 2026. Since then, I’ve heard the same questions at meetups, on Slack, and during Docker Captain briefings. Instead of writing another overview piece, I want to answer ...
BellSoft’s 3-in-1 Strategy for Container Security
BellSoft debuts Hardened Images for Kubernetes, reducing vulnerabilities with locked, lightweight containers built on Alpaquita Linux and Liberica JDK for secure performance ...
Jeff Burt | | 3-in-1 approach, AI threats, Chainguard, cloud native security, cloud security, container hardening, container incidents, container security, container vulnerabilities, containerized applications, CVE remediation, distroless containers, hardened containers, Hardened Images, Java runtime optimization, kubernetes, lightweight Linux, regulatory compliance, runtime security, secure container images, secure DevOps, software supply chain, Vulnerability Management
Runtime Visibility & AI-powered Security in Cloud-Native Environments
Kubernetes and cloud-native platforms have transformed software delivery — but also redefined the attack surface. As threats shift to runtime, visibility and real-time response have become the new security frontline. AI-driven anomaly ...
Alan Shimel | | AI copilot, AI governance, AI in cybersecurity, anomaly detection, automated response, CI/CD security, cloud native security, cloud security, cloud-native defense, container security, DevSecOps, explainable AI, kubernetes, LLMs in security, observability, platform engineering, runtime protection, runtime security, runtime visibility, security automation, security telemetry, service mesh, threat detection, zero-trust
The Future of Workload Isolation with Emily Long
Edera CEO Emily Long, in the wake of the company picking up an additional $15 million in funding, explains why a new approach to isolating workloads is needed to better secure IT ...

