Cloud Security Podcast

Talks not to be missed at Kubecon North America 2021 - Cloud Security News


Listen Later

Cloud Security News this week 21 October 2021

It's a month full of conferences and as promised we are back with our 2nd episode this week to bring you the cloud security highlights from KubeCon. In this episode we will share some of our team’s favourite from Kubecon 2021 North America

If you aren't quite familiar with the wonderful world of Kubernetes, there are a few weird and wonderful open source acronyms in today’s episode. TUF refers to The Update Framework, SPIFFE refers to Secure Production Identity Framework for Everyone SPIFFE,  SPIRE  is the SPIFFE’s Runtime Environment). Now that we are all across cool Kube words - lets into the talks

  • Starting off with the talk from Andrew Martin, Co-Founder of Control Plane and Author of Hacking Kubernetes and Kubernetes Threat Modelling. He spoke about Kubernetes Supply Chain Security - he showcased work to build a Kubernetes Software Factory with Tekton and Deep dived on signing and verification approaches to securely build software with  (TUF) SPIFFE, SPIRE and sigstore
  • Ian Coldwater from Twilio; Brad Geesaman & Rory McCune from Aqua Security Duffie Cooley from Isovalent combined  forces to share with the community how they do security research or hacking Kubenetes clusters using a recently discovered Kubernetes CVE (Common Vulnerability and exposure) - Their talk was called Exploiting a Slightly Peculiar Volume Configuration with SIG-Honk
  • Matt Jarvis from Synk shared what to do if your container has a huge number of Vulnerabilities - how to prioritise them and remediate them in his talk My Container Image has 500 Vulnerabilities, Now What? 
  • Talking about containers and Vulnerability scanning If you want to know about how vulnerability scanners work, their blind spots and how to implement a practical risk based approach to remedy vulnerabilities that really matter to your organisation - check out Pushkar Joglekar’s Keeping Up with the CVEs: How to Find a Needle in a Haystack? 
  • If you find yourself asking “How do I access my S3 bucket in AWS from my GCP cluster?” Brandon Lum & Mariusz Sabath, IBM may have the answer for you in their talk Untangling the Multi-Cloud Identity and Access Problem With SPIFFE Tornjak where they talk about a proposed shift in the perspective of workload identity from being “platform specific” to “organization wide” using SPIFFE/SPIRE and the new SPIFFE Tornjak project.
  • Episode Show Notes on Cloud Security Podcast Website.

    Podcast Twitter - Cloud Security Podcast (@CloudSecPod)

    Instagram - Cloud Security News 

    If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:

    - Cloud Security Podcast:

    - Cloud Security Academy:

    ...more
    View all episodesView all episodes
    Download on the App Store

    Cloud Security PodcastBy Cloud Security Podcast Team

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    54 ratings


    More shows like Cloud Security Podcast

    View all
    Risky Business by Patrick Gray

    Risky Business

    360 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    628 Listeners

    The Cloudcast by Massive Studios

    The Cloudcast

    153 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    368 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,012 Listeners

    AWS Podcast by Amazon Web Services

    AWS Podcast

    201 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    313 Listeners

    Malicious Life by Malicious Life

    Malicious Life

    926 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    7,842 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    164 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    187 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    311 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    78 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    119 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners