A security risk labeled "insecure" surviving 8 years? I was reading #CoreDNS docs (as one does) and found pods insecure, a default in most #K8s clusters. I raised it with #SIGSecurity, but also built a chain that breaks #Cilium FQDN policies: https://t.co/Jqt8Xjtpto
How did you get started with open source?
For me, it always starts with becoming a user first. By using the software, you're more likely to stumble upon bugs, missing features, or areas for improvement—perfect starting points for your first contribution!
https://t.co/6B6avx2XOa
I'm excited to share some groundbreaking research that @wakewarduk and I have been working on. We've discovered a significant vulnerability in #VSCode that allows malicious extensions to steal secrets from other extensions.
https://t.co/W1IJxptrUu
Just came out of a deep rabbit hole after wondering: “Why does my laptop get hot watching YouTube?"
In case you want to find answer to questions you never had about hardware acceleration and Intel iGPUs on Linux: https://t.co/VmxdzngtHU
Great post / data from @datosh18 showing that only 2% of GitHub repos pin @github actions to a commit SHA to make them immutable.😔Thanks for calling out the #oss tool Frizbee (created by @jaosorior and other Stackers) as a way to automate this! https://t.co/aBtEtXLQw2
Checking network connectivity between your #Kubernetes objects has never been easier!
With #NetAssertV2, verify connectivity between K8s objects and remote hosts. Iteratively build, test and deploy Kubernetes network policies.
Download the tool from https://t.co/ebKTvFjAdJ
I'm excited to share that I wrote a blog post with Mikko Ylinen & Tobin Feldman-Fitzthum, to detail how #confidentialcomputing can help to improve security in #k8s and the #cloudnative world.
https://t.co/Lp1lhnb5qI
I’m excited to present my talk, The Irresistible Rise of Cloud Native: What the Future Means for YOU, at #CodetoCloud#CybersecuritySummit, a virtual event presented by @PaloAltoNetworks.
Register to get your ticket for FREE: https://t.co/rD1qjnA8wm
A KubeCon offer from @controlplaneio: Lightspeed Security in our Threat Room⚡https://t.co/2OQuwY3f5B — threat model projects, systems, supply chains, glints of the eye, we appraise and review it all in 25m sessions with our trademark high-impact threat modelling process ☸️🌩️ Cloud native security SMEs will avail you of their expertise and provide next steps to deliver usable security controls for you and your team. No experience necessary, all levels are welcome!
See what else we're doing at KubeCon, including talks, running the official CTF, booth SU57 and our BoothCTF, sponsoring the very musical Kuberoke and Amsterjam, contributing to the brand new Security Village and more 🎉 https://t.co/RiqABRp1rd
📣Join us at the Kubernetes & Cloud Native Berlin Meetup on Dec. 8th!📣
@datosh18, Senior Security Engineer at Edgeless Systems, will present security best practices as a Golang K8s developer.
He'll demo signing git commits, scanning container images for vulnerabilities & more!
And it's a wrap! 🎉🎉
Our first @msdev meetup at the @MSFTReactor Berlin was so exciting and full of engaging banter!
The pictures speak for themselves!
See you folks for our meetups in December! 🥳🥳
Recently our Senior Security Engineer @datosh18 wrote an easy-to-read series on why and how we generate SBOMs, keep track of vulnerabilities and bring support to the customers who have to use them. 🙌
Join me at Kubernetes & Cloud Native Berlin Inaugural Meetup https://t.co/U0AwTHqJnW #Meetup via @Meetup
I will be talking about all things security for K8s & cloud devs, with #gitsign, #syft & #ko.
Zero-trust security is a buzzword for vendors but an important framework to implement for cybersecurity. @EdgelessSystems discussed how it ensured its software was delivered securely using @projectsigstore in #techtrends2023
https://t.co/NfxqhZjhXQ