CNCF Publishes the Kubernetes Policy Management Whitepaper
InfoQ » DevSecOps
by
1w ago
The CNCF recently published a new whitepaper about Kubernetes Policy Management. The whitepaper highlights the importance of Kubernetes policy management when it comes to the security and automation of clusters as well as workloads. Also, it goes in-depth into the problems Kubernetes policies solve and the proper implementation of such policies ..read more
Visit website
Snyk Announces General Availability of Snyk Cloud and Enhancements to its Platform
InfoQ » DevSecOps
by
1w ago
Snyk, a developer security platform, recently announced the general availability of their cloud security tool, Snyk Cloud, and improvements to their platform. Extending support for software bill of materials (SBOM), the improvements include new reporting capabilities and self-service resources ..read more
Visit website
Software Supply Chain Framework OSC&R Created to Help Mitigate Security Threats
InfoQ » DevSecOps
by
1w ago
In collaboration with companies including Google, Microsoft, and GitLab, OX Security has released a security framework for assessing and evaluating software supply chain security risks. The Open Software Supply Chain Attack Reference (OSC&R) is a MITRE-like framework covering containers, open-source software, secrets hygiene, and CI/CD posture ..read more
Visit website
Permit Elements Enables Low-Code User-Managed Access Control
InfoQ » DevSecOps
by
1w ago
Permit.io has released Permit Elements, a low-code end-user authentication interface builder. Permit Elements allows developers to embed interfaces enabling their end-users to decide which roles have permission to perform actions. At the time of release, there are elements available for user management and audit logs ..read more
Visit website
CloudNativeSecurityCon 2023: SBOMs, VEX, and Kubernetes
InfoQ » DevSecOps
by
1w ago
At CloudNativeSecrityCon 2023 in Seattle, WA, Kiran Kamity, founder and CEO of Deepfactor, led a panel discussion on software supply chain security, the practical side of SBOMs, and VEX ..read more
Visit website
AI a “Must-Have” in GitLab’s 2023 Global DevSecOps Report
InfoQ » DevSecOps
by
1w ago
GitLab has released their 2023 Global DevSecOps AI report, with the key finding that AI and ML use is evolving from a "nice-to-have" to a "must-have". The report shows that 23% of organizations are already using AI in software development, and of those, 60% are using it daily. Furthermore, 65% of respondents said they are using AI and ML for testing now, or would be within the next three years ..read more
Visit website
Cloudflare, Google and AWS Disclose HTTP/2 Zero-Day Vulnerability
InfoQ » DevSecOps
by
1w ago
On October 10th, Cloudflare, Google, and AWS disclosed a novel zero-day vulnerability attack known as the "HTTP/2 Rapid Reset." This attack exploits a weakness in the HTTP/2 protocol to generate enormous Distributed Denial of Service (DDoS) attacks, up to almost 400 million requests per second (rps ..read more
Visit website
OpenSSF Adds Attestations to SBOMs to Validate How Software is Built
InfoQ » DevSecOps
by
1w ago
The Open Source Security Foundation (OpenSSF) has recently announced SBOMit, a tool designed to bolster Software Bills of Materials (SBOMs) with in-toto attestations. This development, announced under the OpenSSF Security Tooling Working Group, increases transparency and security in the software development process ..read more
Visit website
Google Cloud Launches Security Command Center Enterprise
InfoQ » DevSecOps
by
1w ago
Google Cloud has launched Security Command Center (SSC) Enterprise, a cloud risk management solution that offers proactive cloud security with enterprise security operations. The solution helps customers manage and mitigate risk across multi-cloud environments and is enhanced by Mandiant expertise ..read more
Visit website
Google Cloud Launches Security Command Center Enterprise
InfoQ » DevSecOps
by
1M ago
Google Cloud has launched Security Command Center (SSC) Enterprise, a cloud risk management solution that offers proactive cloud security with enterprise security operations. The solution helps customers manage and mitigate risk across multi-cloud environments and is enhanced by Mandiant expertise ..read more
Visit website

Follow InfoQ » DevSecOps on FeedSpot

Continue with Google
Continue with Apple
OR