Indeed, serverless functions outside AWS are used as a small corner cases. Interestingly, it’s the whole “serverless” motion which is more popular in AWS extending to new services every year while in the other cloud providers it’s steal a catch-up game.
It seems like @awscloud is the only provider really pushing Lambda/Functions for a broad range of workloads today. Hard to find solid @Azure use cases too.
Link to the full GCP blog - https://t.co/jlT1XhKwqd
I'm really excited that Pod Security Admission is stable in #Kubernetes v1.25. It provides super-simple out-of-the-box pod security, and I'm optimistic that it will raise the bar for baseline Kubernetes hardening.
https://t.co/te02IFuX2f
@c0d3G33k I'm not sure I'd classify it as "shift left " security. Yes, it all runs in automatic pipelines and use open source tools, but the big question is what do you do with all the findings? how do you triage and prioritize them?
We are big fans 👍👍 of serverless applications...but even they are vulnerable to attacks and hacks 👾. Get the details on how to prevent others from tampering with your code before #deployment in this #CiscoTechBlog from @ArielShuper:
It’s a good question which requires evaluation when we test modern micro services applications. IMO some of the classical tests/techniques require a big change (and not simple adaptations like insertion to CI/CD pipelines)
I just wrapped up a Twitter List of all speakers on CNCF's #SecurityCon event in-case you want to follow-up on what they are up to: https://t.co/DjOSJpAaMe
It's colocated with KubeCon here in Valencia 🇪🇸
See y'all tomorrow on the 1st day 👋
PM job interview really depends on how the specific company defines the PM role /their expectations. The PM spectrum is wide, between inbound and outbound
#OWASP Dependency-Track v4.4.0 now available and supports:
Vulnerability Exploitability Exchange (VEX) allows software creators to communicate the exploitability of vulnerable components to software consumers.
VEX is native to #CycloneDX and is vital for operationalizing SBOM.
Is #IaC files a new target for #software#supplychain attacks? great article from @xssfox about potential exploits https://t.co/4MCdalEX7e
Time to think about #codesigning extension for cloud deployments files
@JLLeitschuh No doubt that the CVE scoring and numbering requires revision. Saw lots of complains about the process and it’s outcome. Yet, it would be better to agree on a certain standard/unified scoring mechanism vs individual scoring
How did we decide that "Goat" would be used for intentionally-vulnerable test environments (WebGoat, Terragoat)? Did someone just look at a goat and think "wow, that's a vulnerable animal?" 🐐