Search results for: security


Announcing the completion of Linkerd’s 2022 Security Audit

Posted on June 28, 2022 | William Morgan

Linkerd project cross-post by William Morgan Today we’re happy to announce the completion of Linkerd’s annual security audit, conducted by Trail of Bits and funded by the Cloud Native Computing Foundation. As part of Linkerd’s commitment to openness, transparency,…



Cloud Native SecurityCon Europe

Posted on June 27, 2022

Cloud Native SecurityCon is designed to foster collaboration, discussion and knowledge sharing of cloud native security projects and how to best use these to address security challenges and opportunities. The goal is not just to propose…


Efficient GRC with cybersecurity tooling

Posted on June 27, 2022 | Iwan Price-Evans

Guest post originally published on the Snapt blog by Iwan Price-Evans “Governance, risk, and compliance” (GRC) might be dirty words for many people working in application development and delivery. Strict rules and processes can be obstacles…


The role of cloud native + security – Recap from RSA Conference 2022

Posted on June 20, 2022

Last week, CNCF participated at RSA Conference in San Francisco. As part of the DevOps Connect: DevSecOps co-located event, our GM Priyanka Sharma gave a keynote with Frederick Kautz. In their presentation, Priyanka and Frederick discussed…


Know your cloud security acronyms: CWPP, CSPM, CIEM and CNAPP

Posted on June 13, 2022

Guest post originally published on the Orca Security blog by Ty Murphy and Sarah Smith Acronyms help communicate lengthy phrases, but they can sometimes be confusing. This is especially true in the security industry, which has…


How to security harden Kubernetes in 2022

Posted on June 7, 2022 | Elastisys team

Guest post originally published on the Elastisys blog by the Elastisys team The NSA/CISA guidelines summarized, with Elastisys hands-on advice and real-world recommendations. Kubernetes is now the most popular container orchestration platform. Practically gone are the Mesoses…


Introduction to the Cloud Native Security Controls Catalog

Posted on June 7, 2022

Community post by Jon Zeolla, CTO and Co-Founder of Seiso The CNCF Security Technical Advisory Group (“Security TAG”) has provided a wealth of information to assist organizations in the planning and design of secure cloud native…


Ada Logics: CRI-O holistic security audit engagement

Posted on June 6, 2022 | David Korczynski + Adam Korczynski

Community post originally on the Ada Logics blog by David Korczynski, Security Research & Security Engineering and Adam Korczynski, Security Engineering & Security Automation, Ada Logics Ada Logics Ltd. recently performed a holistic security audit of CRI-O….


How to test application security

Posted on June 6, 2022 | Craig Risi

Guest post originally published on the Snapt blog by Craig Risi We constantly read about leaks and security attacks that hit well-known applications. Businesses cannot take security for granted. With so much critical data in play,…