Search results for: security


The CNCF Technology Radar Report: Workflow Orchestration, App Delivery and Security & Policy Management

Posted on March 23, 2026

Developer trust is converging around a new generation of cloud native tools. The CNCF Technology Radar Report, featuring insights from 400+ developers, reveals which technologies are leading across workflow automation, application delivery, and security – and…


Kusari and CNCF: Advancing software supply chain security for cloud native projects

Posted on March 23, 2026 | Michael Lieberman, Kusari Co-Founder and CTO

Open source has become the foundation of modern software — but the scale and speed of today’s software supply chains are creating new security challenges. Applications depend on hundreds or thousands of components across complex environments,…


KubeCon + CloudNativeCon Europe 2026 Co-located Event Deep Dive: Open Source SecurityCon

Posted on February 23, 2026 | Co-chairs Brandt Keller & Constanze Roedig

Open Source SecurityCon (evolved from Cloud Native SecurityCon) returns for its second event, co-located with KubeCon + CloudNativeCon Europe 2026. The conference is dedicated to advancing innovation and collaboration across open source software security and cloud…


Security Slam Returns for 2026 — Now Open to All Open Source Projects

Posted on February 11, 2026 | Eddie Knight, Sonatype

The CNCF Technical Advisory Group for Security & Compliance is excited to announce the upcoming 2026 Security Slam at KubeCon + CloudNativeCon Europe, in partnership with Sonatype and OpenSSF. The event will run from Friday, February…


Cloud Native Live: Kyverno 1.17 Release — Advancing with CEL and Supply Chain Security

Posted on February 10, 2026

Kyverno 1.17 marks a major milestone in the project’s evolution, significantly expanding the power and flexibility of policy as code for Kubernetes platform teams. In this Cloud Native Live session, Kyverno maintainers will demo and walk…


KubeVirt undergoes OSTIF security audit

Posted on December 17, 2025 | By Helen Woeste Operations, Communications, and Community at Open Source Technology Improvement Fund

The Open Source Technology Improvement Fund (OSTIF) is proud to share the results of a recent security audit of KubeVirt, a Kubernetes virtualization API and runtime for managing virtual machines. With the continued support of Quarkslab…


Kubernetes Security: 2025 Stable Features and 2026 preview

Posted on December 15, 2025 | Matteo Bisi, DevSecOps Team Leader, ReeVo Cloud & Cyber Security

It’s time to recap the key Kubernetes security highlights from 2025 and outline features likely to graduate to stable in early 2026. From a DevSecOps perspective, 2025 brought several meaningful security improvements that directly influenced day-2…


Help Net Security: “Prometheus: Open-source metrics and monitoring systems and services”

Posted on December 15, 2025

Prometheus is an open-source monitoring and alerting system built for environments where services change often and failures can spread fast. For security teams and DevOps engineers, it has become a common way to track system behavior, spot early…


The Landscape: “Kubernetes 1.34: Security, Performance, and DRA Go GA”

Posted on October 15, 2025

Vyom Yadav, Kubernetes Release Team Lead and Software Engineer at Canonical, joins Sylvain Kalache to discuss what’s new in Kubernetes 1.34.


Auditing user activity in pods and nodes with the Security-Profiles-Operator

Posted on October 7, 2025 | Neeraj Krishna Gopalakrishna & Red Hat OpenShift Node Team

Kubernetes’ native audit logs are essential for tracking control plane activities, but they fail to capture what happens inside a container or on the host node itself during kubectl debugging sessions. This creates a security and…