#KubernetesSecurity
Learn how #KubeArmor leverages Linux Security Modules (LSMs) like AppArmor, SELinux, and BPF-LSM to secure your cluster, enforce policies, and provide deep observability.

#kubernetes #cloudsecurity #runtimesecurity #kubernetessecurity #k8s #platformengineering

youtube.com/shorts/vhLC_...
KubeArmor Deep Dive: Securing Kubernetes with eBPF & LSM
YouTube video by Is it Observable
youtube.com
December 9, 2024 at 2:52 PM
Service accounts with wide perms are top K8s sec flaw. WI & IRSA solve this by avoiding long-term creds. Example: Dev team uses separate service acc for each project, reducing risk. #kubernetessecurity #iambestpractice
August 28, 2026 at 9:00 PM
🚨 New #Kubernetes security alert! CVE-2025-22872 (CVSS 6.5) patches released for @SUSE distributions. Read more: 👉 tinyurl.com/yc7ja7b6 #KubernetesSecurity #DevOps
Critical Kubernetes Security Update: CVE-2025-22872 Patch Guide for SUSE Systems
Blog com notícias sobre, Linux, Android, Segurança , etc
tinyurl.com
July 18, 2025 at 2:45 PM
Kubescape doesn't just find security problems in a Kubernetes cluster. It also watches how workloads behave at runtime and turns that into hardening policy proposals. But how?

Watch the full 🌩️Thunder episode:
https://youtu.be/z008cHQDA2Q

#Kubescape #KubernetesSecurity #eBPF #CloudNative
August 18, 2026 at 1:39 PM
Kubernetes has really transformed how we deploy and manage applications. However, with this power, security becomes a big responsibility.

Please follow my LinkedIn page to get more updates: https://lnkd.in/eG63ACWN
#KubernetesSecurity #CloudSecurity #CyberSecurity #KubernetesTools #TechBlog
Best Kubernetes Security Tools: How to Choose! – 2024
Discover the top Kubernetes security tools to fortify your containerized applications. Learn how to choose the Kubernetes security tools for robust optimization
cloudautocraft.com
July 28, 2024 at 4:59 PM
Network policies are the firewall wizards of Kubernetes! From frontend to backend traffic becomes an exclusive club. Just don't forget to RSVP the CoreDNS. #KubernetesSecurity
The Default Deny Dilemma: A Practical Guide to Kubernetes Network Policies
another post form Cybertec
www.cybertec-postgresql.com
September 11, 2026 at 7:35 AM
Falco in Production: Runtime Security Without Drowning in Alerts

Installing Falco takes ten minutes. Making it useful takes months. A practical guide to runtime security that survives contact with production — rule maturity, tuning out noise, and wh…

#falco #runtimesecurity #kubernetessecurity
Falco in Production: Runtime Security Without Drowning in Alerts
Installing Falco takes ten minutes. Making it useful takes months. A practical guide to runtime security that survives contact with production — rule maturity, tuning out noise, and what to actually alert on.
www.alekseialeinikov.com
August 11, 2026 at 9:00 AM
Secure-by-Default GKE: A Reference Architecture for 2026

A practical secure-by-default GKE reference architecture for 2026: defense in depth across identity, network, supply chain, admission, runtime, and observability — with Workload Identity Federation and B…

#gke #kubernetessecurity #gcp
Secure-by-Default GKE: A Reference Architecture for 2026
A practical secure-by-default GKE reference architecture for 2026: defense in depth across identity, network, supply chain, admission, runtime, and observability — with Workload Identity Federation and Binary Authorization at the core.
www.alekseialeinikov.com
July 6, 2026 at 4:35 PM
Kubernetes secrets protect sensitive data like API keys against threats at rest, in transit, and via API abuse. Key considerations include environment variables, mounted files, RBAC limits, and etcd encryption. #KubernetesSecurity #etcdEncryption
Kubernetes security fundamentals: Secrets
This article explains Kubernetes secrets management, focusing on the main threat models for secrets at rest, in transit, and through API abuse, as well as how native Secret objects and external solutions address them. It also highlights practical security tradeoffs such as environment variables versus mounted files, RBAC limitations, etcd encryption, and risks like storing sensitive data in ConfigMaps. #Kubernetes #etcd #RBAC #RKE #ConfigMaps
www.hendryadrian.com
May 8, 2026 at 11:30 PM
Wazuh enhances Kubernetes security by collecting audit logs via DaemonSet deployment, analyzing them with custom rules mapped to MITRE ATT&CK for detecting privilege escalation, persistence, and container breakout attempts. #KubernetesSecurity #AlmaLinux
Detecting Kubernetes attacks with Wazuh
This article describes how to simulate multiple Kubernetes attack techniques using the Stratus Red Team framework and detect them by collecting and analyzing Kubernetes audit logs with Wazuh. It provides step‑by‑step procedures to deploy Minikube, enable audit logging, install the Wazuh agent as a DaemonSet, create Wazuh detection rules mapped to...
www.hendryadrian.com
May 2, 2026 at 5:45 AM
CVE-2020-8561 exploits an SSRF flaw in Kubernetes API server’s ValidatingWebhookConfiguration and profiling endpoints to expose full responses. Requires cluster-admin creds to escalate impact. #KubernetesSecurity #SSRF #CVE20208561
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561 | Datadog Security Labs
This article explains CVE-2020-8561, an unpatchable Kubernetes vulnerability that combines an SSRF vector via ValidatingWebhookConfiguration objects with the API server's profiling endpoints to escalate impact by exposing full responses. The exploit requires valid cluster credentials (typically cluster-admin) to change the API server log level and then trigger webhook-initiated requests to probe internal services. #CVE-2020-8561 #kube-apiserver
www.hendryadrian.com
March 27, 2026 at 2:00 PM
🔓 La función de telemetría de Kubernetes compromete completamente los clústeres

Una nueva vulnerabilidad crítica se suma a los problemas de los administradores.

https://thenewstack.io/kubernetes-telemetry-feature-fully-compromises-clusters/

#KubernetesSecurity #Telemetry #DevSecOps #RoxsRoss
January 30, 2026 at 1:50 AM
March 25, 2026 at 5:02 PM
February 9, 2026 at 5:00 PM
🚀 Check out this insightful video on Kubescape Operator & SaaS! Learn how to deploy Kubescape and leverage the SaaS GUI for enhanced Kubernetes security. Thanks to @rawkode.dev for sharing this valuable content! #KubernetesSecurity
Kubescape Operator & SaaS
Watch on the Rawkode Academy
rawkode.academy
August 12, 2025 at 10:00 AM
Good mix of some lightweight and more tricky questions, but an extra good thing is that I got lots of ideas for blog posts while preparing for this exam 😁

A blog post with KCSA preparation material to follow of course - stay tuned! 😉

#KubernetesSecurity #DevSecOps #K8s
March 5, 2025 at 9:26 AM
Critical vulnerability alert! 6,500+ Kubernetes clusters at risk due to Ingress NGINX Controller flaws. Update ASAP to prevent cluster takeover & unauthorized code execution thehackernews.com/2025/03/crit... #IngressNightmare #KubernetesSecurity
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code execution.
thehackernews.com
March 29, 2025 at 9:21 PM
🔴 Kubernetes Misconfigs Hackers Exploit in 2024

Hackers exploit Kubernetes misconfigs daily - no zero-days needed. We cover the top 3: anonymous auth, overprivileged RBAC, and privileged containers.

https://www.youtube.com/watch?v=Fj5s2g1pub8

#KubernetesSecurity #CloudSecurity #DevSecOps #Contain
April 26, 2026 at 3:48 PM