
Talks not to be missed at Kubecon North America 2021 - Cloud Security News
Quenn D
Description
<p><strong>Cloud Security News this week 21 October 2021</strong></p> <p>It's a month full of conferences and as promised we are back with our 2nd episode this week to bring you the cloud security highlights from KubeCon. In this episode we will share some of our team’s favourite from Kubecon 2021 North America</p> <p>If you aren't quite familiar with the wonderful world of Kubernetes, there are a few weird and wonderful open source acronyms in today’s episode. TUF refers to The Update Framework, SPIFFE refers to Secure Production Identity Framework for Everyone SPIFFE, SPIRE is the SPIFFE’s Runtime Environment). Now that we are all across cool Kube words - lets into the talks</p> <ul> <li>Starting off with the talk from Andrew Martin, Co-Founder of Control Plane and Author of Hacking Kubernetes and Kubernetes Threat Modelling. He spoke about<a href="https://kccncna2021.sched.com/event/lUzv/kubernetes-supply-chain-security-the-software-factory-andrew-martin-control-plane?iframe=no"><u> Kubernetes Supply Chain Security</u></a> - he showcased work to build a Kubernetes Software Factory with Tekton and Deep dived on signing and verification approaches to securely build software with (TUF) SPIFFE, SPIRE and sigstore</li> <li>Ian Coldwater from Twilio; Brad Geesaman & Rory McCune from Aqua Security Duffie Cooley from Isovalent combined forces to share with the community how they do security research or hacking Kubenetes clusters using a recently discovered Kubernetes CVE (Common Vulnerability and exposure) - Their talk was called <a href="https://sched.co/lV0J"><u>Exploiting a Slightly Peculiar Volume Configuration with SIG-Honk</u></a></li> <li>Matt Jarvis from Synk shared what to do if your container has a huge number of Vulnerabilities - how to prioritise them and remediate them in his talk <a href="https://sched.co/lV1T"><u>My Container Image has 500 Vulnerabilities, Now What? </u></a></li> <li>Talking about containers and Vulnerability scanning If you want to know about how
Uploader
Episodes
Talks not to be missed at Kubecon North America 2021 - Cloud Security News
Quenn D