Developer trust is converging around a new generation of cloud native tools. The CNCF Technology Radar Report, featuring insights from 400+ developers, reveals which technologies are leading across workflow automation, application delivery, and security – and…
Kusari and CNCF: Advancing software supply chain security for cloud native projects
Open source has become the foundation of modern software — but the scale and speed of today’s software supply chains are creating new security challenges. Applications depend on hundreds or thousands of components across complex environments,…
KubeCon + CloudNativeCon Europe 2026 Co-located Event Deep Dive: Open Source SecurityCon
Open Source SecurityCon (evolved from Cloud Native SecurityCon) returns for its second event, co-located with KubeCon + CloudNativeCon Europe 2026. The conference is dedicated to advancing innovation and collaboration across open source software security and cloud…
Security Slam Returns for 2026 — Now Open to All Open Source Projects
The CNCF Technical Advisory Group for Security & Compliance is excited to announce the upcoming 2026 Security Slam at KubeCon + CloudNativeCon Europe, in partnership with Sonatype and OpenSSF. The event will run from Friday, February…
Cloud Native Live: Kyverno 1.17 Release — Advancing with CEL and Supply Chain Security
Kyverno 1.17 marks a major milestone in the project’s evolution, significantly expanding the power and flexibility of policy as code for Kubernetes platform teams. In this Cloud Native Live session, Kyverno maintainers will demo and walk…
KubeVirt undergoes OSTIF security audit
The Open Source Technology Improvement Fund (OSTIF) is proud to share the results of a recent security audit of KubeVirt, a Kubernetes virtualization API and runtime for managing virtual machines. With the continued support of Quarkslab…
Kubernetes Security: 2025 Stable Features and 2026 preview
It’s time to recap the key Kubernetes security highlights from 2025 and outline features likely to graduate to stable in early 2026. From a DevSecOps perspective, 2025 brought several meaningful security improvements that directly influenced day-2…
Help Net Security: “Prometheus: Open-source metrics and monitoring systems and services”
Prometheus is an open-source monitoring and alerting system built for environments where services change often and failures can spread fast. For security teams and DevOps engineers, it has become a common way to track system behavior, spot early…
The Landscape: “Kubernetes 1.34: Security, Performance, and DRA Go GA”
Vyom Yadav, Kubernetes Release Team Lead and Software Engineer at Canonical, joins Sylvain Kalache to discuss what’s new in Kubernetes 1.34.
Auditing user activity in pods and nodes with the Security-Profiles-Operator
Kubernetes’ native audit logs are essential for tracking control plane activities, but they fail to capture what happens inside a container or on the host node itself during kubectl debugging sessions. This creates a security and…