Cloud Native
Security Talks
RSS

Index · 2016–2026

Cloud Native Security Talks

KubeCon, CloudNativeSecurityCon and Cloud Native Security Day talks on container and Kubernetes security, each with its abstract and recording. Search every abstract, or narrow the list by event series and year.

Talks
Events
Since
Latest
Line drawing of stacked shipping containers in front of a ship's helm wheel; one container door is open to show a red padlock.
Plate 01Containers, secured

Every talk

Newest first, grouped by event. Search matches titles, speakers and full abstracts.

KC-EU-26

KubeCon Europe 2026

24 talks
  1. The Shared Service Blueprint: A Guide to Multi-Tenancy, Illustrated With KEDAAya Igarashi, Preferred Networks, Inc. 2026-03-26
  2. Tailor Made: Dynamic Fine-Grained Authorization for API TrafficErica Hughberg, Tetrate & Andres Aguiar, Okta 2026-03-26
  3. SPIFFE Meets OAuth: Federated Identity for Cloud Native WorkloadsYoshiyuki Tabata, Hitachi, Ltd. 2026-03-26
  4. SB💣💣M: Making SBOMs Play TogetherJacopo Bufalino, CNAM & Agathe Blaise, Thales SIX GTS France 2026-03-26
  5. Why Security of Kubernetes Comes Down to Linux SecurityMarina Moore, Edera 2026-03-25
  6. Why Isn't the Fix in My Container? Tracking CVE Propagation Across 10,000 ProjectsMor Weinberger, Echo Security & Lior Kaplan, Kaplan Open Source 2026-03-25
  7. Signed, Sealed, Delivered: Why Reverse Proxies Outperform VPNsPeter ONeill, Teleport & Boris Kurktchiev, Independent 2026-03-25
  8. Kubernetes Third Party Audit ReviewIain Smart, AmberWolf; Amir Montazery, Open Source Technology Improvement Fund; Rey Lejano, Red Hat; Tabitha Sable, Datadog; Pietro Tirenna, Shielder 2026-03-25
  9. Kubernetes Security at Shopify Scale: Automating Security Across an Infrastructure MonorepoJie Wu & Pulkit Garg, Shopify 2026-03-25
  10. Invisible Guardrails: Enabling Developer Velocity With a Secure PlatformJames Elías Sigurðarson & Vignir Hafsteinsson, Asana 2026-03-25
  11. How To Break Multi-Tenancy Again and Again ...and What We Can Learn From ItLorin Lehawany & Sven Nobis, ERNW 2026-03-25
  12. Hacking GPU Observability: eBPF & Ephemeral Containers in Action on KubernetesBrandon Kang, Akamai Technologies 2026-03-25
  13. Hack Me If You Can: Learning Kubernetes Security Through a Role-Play BattleAoi Takahashi, Recruit Co., Ltd. & Keita Mochizuki, NTT DATA Japan Corporation 2026-03-25
  14. Exploring NRI for Automated CA Trust InjectionTsuzuki Tsuchiya & Kento Kubo, LY Corporation 2026-03-25
  15. Detect, Decide, Defend: Building Cloud Native Security That Fights BackMatthias Bertschy, ARMO 2026-03-25
  16. Bob and Alice Revisited: Understanding Encryption in KubernetesJackie Maertens & Mitch Connors, Microsoft 2026-03-25
  17. Automating and Scaling of Threat Modelling for Cloud Native ArchitectureHanna Papirna & Emma Yuan Fang, EPAM Systems 2026-03-25
  18. Automate Once, Run Anywhere: The Docker Moment for Security WorkflowsNancy Chauhan & Aseem Shrey, ShipSecAI 2026-03-25
  19. Audit-Ready Kubernetes: How Chase UK Leveraged Policy as Code for Continuous ComplianceJim Bugwadia, Nirmata & Nischay Goyal, JP Morgan Chase 2026-03-25
  20. When Multitenancy Goes Wrong: A Deep Dive Into Kcp’s First CVEMarvin Beckers, ClickHouse 2026-03-24
  21. What LLMs Do, and Don't, Know About Securing KubernetesRory McCune, Datadog 2026-03-24
  22. Real-World Supply-Chain SecurityAlex Leong, Buoyant 2026-03-24
  23. Privacy as Infrastructure: Declarative Data Protection for AI on KubernetesJoaquin Rodriguez, Microsoft & Krishnendu Dasgupta, AXONVERTEX AI 2026-03-24
  24. Policy Engines for Kubernetes: Picking One Without Losing Your MindNabarun Pal, Broadcom 2026-03-24
KC-NA-25

KubeCon North America 2025

21 talks
  1. You Deployed What?! Data-Driven Lessons on Unsafe Helm Chart DefaultsYossi Weizman, Microsoft 2025-11-13
  2. Tools and Strategies for Making the Most of Kubernetes Access ControlLucas Käldström, Upbound & Micah Hausler, AWS 2025-11-13
  3. The Ultimate Container Challenge: An Interactive Trivia Game on Supply Chain SecurityAurélie Vache, OVHcloud & Sherine Khoury, Red Hat 2025-11-13
  4. Securing Data Applications at Pinterest With Finer Grained Access Control on KubernetesSoam Acharya & William Tom, Pinterest 2025-11-13
  5. Authenticating and Authorizing Every Connection at UberYangmin Zhu & Matt Mathew, Uber 2025-11-13
  6. Aligning Enterprise AI Security With MITRE ATLAS Using Open Source TechnologiesDoron Caspin & Valentina Rodriguez Sosa, Red Hat 2025-11-13
  7. 🎤 Who Wants To Secure Clusters ?Henrik Rexed & Simon Reisinger, Dynatrace 2025-11-13
  8. Security Theater or Real Defense? Navigating Open Source Security in a Cloud Native WorldRotem Refael, ARMO; Constanze Roedig, Technical University of Vienna; Megan Wolf, Defense Unicorns; Stefana Muller, Salesforce; Oshrat Nir, Independent 2025-11-12
  9. Securing AI Agent Infrastructure: AuthN/AuthZ Patterns for MCP and A2AYoshiyuki Tabata, Hitachi, Ltd. 2025-11-12
  10. Safely Sourcing OSS - Beyond 0 CVEsJohn Kjell, ControlPlane 2025-11-12
  11. Red Vs. Blue: A Live Attacker-Defender Showdown in Kubernetes SecurityLucy Sweet, Uber & Sandeep Kanabar, Gen 2025-11-12
  12. Quantum-Resistant Kubernetes: Realities, Risks & (Versioning) PitfallsFabian Kammel, ControlPlane 2025-11-12
  13. Patch Me If You Can: Tackling Outdated Addons Before They Become a RiskStevie Caldwell & Andy Suderman, Fairwinds 2025-11-12
  14. The Good, the Bad, and the Ugly: Hacking 3 Cloud Native AI Services With 1 VulnerabilityHillai Ben-Sasson & Nir Ohfeld, Wiz 2025-11-11
  15. Modern PostgreSQL Authorization With Keycloak: Cloud Native Identity Meets Database SecurityYoshiyuki Tabata, Hitachi, Ltd. & Gabriele Bartolini, EDB 2025-11-11
  16. It’s 2025; Why Are You OK With an Insecure Network? 🤯Alex Leong, Buoyant 2025-11-11
  17. In AI We Trust? Securing the Future, One Agent at a TimeLin Sun & Yuval Kohavi, Solo.io; Hannah Foxwell, Mindgard.ai; Andrew Martin, ControlPlane; Ricardo Aravena, CNCF 2025-11-11
  18. Hybrid-Confidential-Cloud: Democratize Secure AI With GPUs and Confidential ContainersZvonko Kaiser, NVIDIA 2025-11-11
  19. From Bespoke To Bulletproof: SPIFFE/SPIRE With ESO for Enterprise Zero TrustMay Large & Ivy Alkhaz, State Farm 2025-11-11
  20. End-to-End Security With gRPC in KubernetesShiva & Abhishek Agrawal, Google 2025-11-11
  21. Demonstration of Automatic Kubernetes Network Policies GenerationBoaz Michaely, Red Hat & Adi Sosnovich, IBM Research 2025-11-11
KC-EU-25

KubeCon Europe 2025

19 talks
  1. Zero Trust at Shopify Scale: Automating MTLS Across Thousands of ServicesDani Santos & Michelle Mali, Shopify 2025-04-04
  2. Why Don’t We Have Both? Track Build- and Run-time Information for Security With Kubescape and GUACJeff Mendoza, Kusari & Ben Hirschberg, ARMO 2025-04-04
  3. From Chaos To Control: Migrating Access Control To OpenFGA in a Multi-Tenant WorldJo Guerreiro, Grafana Labs & Poovamraj Thanganadar Thiagarajan, Okta 2025-04-04
  4. Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub ImagesGuillaume Valadon, GitGuardian 2025-04-04
  5. Enhancing Software Composition Analysis Resilience Against Container Image ObfuscationAgathe Blaise, Thales & Jacopo Bufalino, CNAM 2025-04-04
  6. EVAPorating Kubernetes Security Risk: Adopting Validating Admission Policy at ScaleKaitlyn Lee & Jordan Conard, Datadog 2025-04-04
  7. Do Your Containers Even Lift – A Hardening Guide for K8s ContainersCailyn Edwards & Daniel Murphy, Okta 2025-04-04
  8. Container Runtimes... on Lockdown: The Hidden Costs of Multi-tenant WorkloadsLewis Denham-Parry, Edera & Caleb Woodbine, ii.nz 2025-04-04
  9. Compliance at the Speed of Innovation: Leveraging AI-Driven Automation for Real-Time Regulatory ReadLarry Carvalho, RobustCloud LLC; Simon Metson, EnterpriseDB; Robert Ficcaglia, Sunstone Secure, LLC; Anca Sailer, Red Hat / IBM; Yuji Watanabe, IBM Japa 2025-04-04
  10. Weaving a VEX Feed Through the Kubernetes ProjectAdolfo García Veytia, Stacklok 2025-04-03
  11. Redefining Access Control: Scaling Policy as Code for Humans and AI AgentsRaz Cohen, Permit.io 2025-04-03
  12. Open Source Malware or a Vulnerability? The Philosophical Debate and How To MitigateBrian Fox, Sonatype; Madelein van der Hout, Forrester Research Inc.; Santiago Torres-Arias, Purdue University 2025-04-03
  13. Mind the Gap: Bridging Supply Chain Policy With Git-less GitOps and GUACMichael Lieberman, Kusari & Andrew Martin, ControlPlane 2025-04-03
  14. Identity-based Trust - Till Death Do We Part?John Kjell, ControlPlane & Kairo De Araujo, Independent 2025-04-03
  15. IAM, Agent: Identity for Autonomous AIMatthew Bates, Cofide 2025-04-03
  16. ​​SPIFFE in Practice: Universal Identity for WebAssembly WorkloadsJoonas Bergius, Cosmonic & Colin Murphy, Adobe 2025-04-03
  17. Trust No One: Secure Storage With Confidential ContainersAurélien Bombo, Microsoft 2025-04-02
  18. Signed, Sealed, Delivered - Sign and Verify All the ThingsJeremy Rickard, Microsoft 2025-04-02
  19. Securing AI Workloads: Building Zero-Trust Architecture for LLM ApplicationsRohit Ghumare, Taikun & Joinal Ahmed, NTG 2025-04-02
KC-NA-24

KubeCon North America 2024

22 talks
  1. Why Perfect Compliance Is the Enemy of Good Kubernetes SecurityMichele Chubirka, Google 2024-11-15
  2. The Policy Engines ShowdownGabriel L. Manor, Permit.io; Andres Aguiar, Okta; Omri Gazitt, Aserto; Pauline Jamin, Agicap; Tyler Schade, Geico; Joy Scharmen, StrongDM 2024-11-15
  3. Seccomp and eBPF; What’s the Difference? Why Do I Need to Know?Natalia Reka Ivanko & Duffie Cooley, Isovalent @ Cisco 2024-11-15
  4. SPIFFE the Easy Way: Universal X509 and JWT Identities Using cert-managerTim Ramlot & Ashley Davis, Venafi 2024-11-15
  5. SPIFFE Deployments in Non-Kubernetes EnvironmentsNadin El-Yabroudi & Eli Nesterov, SPIRL 2024-11-15
  6. Rogue No More: Securing Kubernetes with Node-Specific RestrictionsAnish Ramasekar, Microsoft & James Munnelly, Apple 2024-11-15
  7. Practical Supply Chain Security: Implementing SLSA Compliance from Build to RuntimeEnguerrand Allamel, Ledger 2024-11-15
  8. Powering Automatic Authorization in Envoy Through Live Traffic InspectionDom Del Nano, Pixie core maintainer 2024-11-15
  9. What Agent to Trust with Your K8s: Falco, Tetragon or KubeArmor?Henrik Rexed, Dynatrace 2024-11-14
  10. Multi-Tier Security in WasmCloud: From Developer Constraints to Platform ExtensibilityBrooks Townsend, Cosmonic 2024-11-14
  11. Mish-Mesh: Abusing the Service Mesh to Compromise Kubernetes EnvironmentsHillai Ben-Sasson & Nir Ohfeld, Wiz 2024-11-14
  12. It's Dangerous to Build It Alone, Take This.Jeremy Rickard & Ashna Mehrotra, Microsoft 2024-11-14
  13. From Standards to Practice: The Journey to Container MaturityCarmen Chow & Thomas Robinson, Yelp 2024-11-14
  14. From Silicon to Service: Ensuring Confidentiality in Serverless GPU Cloud FunctionsZvonko Kaiser, NVIDIA 2024-11-14
  15. Workload Identity Federation – Stop Using Long-Lived CredentialsBenjamin Dronen, Ford Motor Company & Anjali Telang, Red Hat 2024-11-13
  16. GitOops... I Did It Again! Protecting Your GitOps System from Being Used for Privilege EscalationOreen Livni & Elad Pticha, Cycode 2024-11-13
  17. From Observability to Enforcement: Lessons Learned Implementing eBPF Runtime SecurityAnna Kapuścińska & Kornilios Kourtis, Isovalent 2024-11-13
  18. Expanding the Capabilities of Kubernetes Access ControlJimmy Zelinskie, authzed & Lucas Käldström, Upbound 2024-11-13
  19. CEL-Ebrating Simplicity: Mastering Kubernetes Policy EnforcementKevin Conner, Getup Cloud & Anish Ramasekar, Microsoft 2024-11-13
  20. Bridging Clouds: TikTok’s Blueprint for Unified OIDC Access on Multi-Cloud KubernetesNaveen Mogulla, TikTok 2024-11-13
  21. Breaking Free from Vulnerability Scanning Noise: Automated VEX Aggregation for AccuracyTeppei Fukuda, Aqua Security Software Ltd. 2024-11-13
  22. AuthZEN: The “OpenID Connect” for AuthorizationOmri Gazitt, Aserto 2024-11-13
KC-EU-24

KubeCon Europe 2024

27 talks
  1. You Shall Not Pass! Unless You Are GUAC Verified….Parth Patel, Kusari & Dejan Bosanac, Red Hat 2024-03-22
  2. Living off the Land Techniques in Managed Kubernetes ClustersRonen Shustin & Shay Berkovich, Wiz 2024-03-22
  3. Leveraging OCI 1.1 for Enhanced SBOM Integration and Vulnerability Scanning in HarborAnais Urlichs, Aqua Security & Shengwen Yu, VMware 2024-03-22
  4. Lessons Learned from Generating 100M SBOMs: Google’s Approach to SBOM ComplianceBrandon Lum & Isaac Hepworth, Google 2024-03-22
  5. Kubernetes Security Blind Spot: Misconfigured System PodsShaul Ben Hai, Palo Alto Networks 2024-03-22
  6. Kubernetes MLSec: Securing AI in SpaceFrancesco Beltramini & James Callaghan, ControlPlane 2024-03-22
  7. Keeping Kubernetes Safe: The Lowdown on Locked NamespacesMarco De Benedictis, ControlPlane 2024-03-22
  8. It's Not Just About SBOMs: Perspectives on Cloud Native Supply Chain SecurityMichael Lieberman, Kusari; Dana Wang, OpenSSF - The Linux Foundation; Marina Moore, New York University; John Kjell, TestifySec; Arnaud Le Hors, IBM 2024-03-22
  9. IAM Confused: Analyzing 8 Identity Breach IncidentsMaya Levine, Sysdig 2024-03-22
  10. Why Barricade the Door if the Window Is Open? Making Sense of Kubernetes Initial Access VectorsShay Berkovich, Wiz 2024-03-21
  11. VEXinating Your Container Images: The European WayDina Truxius, Federal Office for Information Security (BSI) & Jose Antonio Carmona Fombella, VMware 2024-03-21
  12. Stop Leaking Kubernetes Service Information via DNS!John Belamaric, Google & Yong Tang, Ivanti 2024-03-21
  13. Navigating the Software Supply Chain Defense LandscapeMarina Moore & Aditya Sirish A Yelgundhalli, New York University 2024-03-21
  14. Misconfigurations in Helm Charts: How Far Are We from Automated Detection and Mitigation?Francesco Minna, Vrije Universiteit Amsterdam & Agathe Blaise, Thales SIX 2024-03-21
  15. Memory Armor for SPIRE: Fortifying SPIRE with Confidential Containers (CoCo)Matthew Bates, Stealth Security Startup & Suraj Deshmukh, Microsoft 2024-03-21
  16. Keep Hackers Out of Your Cluster with These 5 Simple TricksChristophe Tafani-Dereeper & Frederic Baguelin, Datadog 2024-03-21
  17. Federated IAM for Kubernetes with OpenFGAJonathan Whitaker, Okta 2024-03-21
  18. Confidential Containers for GPU Compute: Incorporating LLMs in a Lift-and-Shift Strategy for AIZvonko Kaiser, NVIDIA 2024-03-21
  19. Cloud Native Security: Cell-Based Architecture & K8sRostyslav Myronenko & Shweta Vohra, Booking.com 2024-03-21
  20. Bringing SPIFFE to Linkerd for Mesh ExpansionZahari Dichev, Buoyant 2024-03-21
  21. Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native EcosystemConstanze Roedig, Technische Universität Wien & James Callaghan, ControlPlane 2024-03-21
  22. Securing the Supply Chain with Sigstore Artifacts Signatures at ScaleDmitry Savintsev & Yonghe Zhao, Yahoo 2024-03-20
  23. Safety or Usability: Why Not Both? Towards Referential Auth in K8sRob Scott, Google & Mo Khan, Microsoft 2024-03-20
  24. SLSA and FRSCA: Beyond Snacks and Soda!Christopher Hanson, RX-M, llc. 2024-03-20
  25. Playing Defense: The Reactive Cloud Native Security BattleAyse Kaya, Slim.AI 2024-03-20
  26. OAuth2 Token Exchange for Microservice API SecurityAhmet Soormally & Letz Yaara, Tyk 2024-03-20
  27. I'll Let Myself In: Kubernetes Privilege Escalation TacticsAndrew Martin & Iain Smart, ControlPlane 2024-03-20
KC-NA-23

KubeCon North America 2023

23 talks
  1. Supercharge Your Software Supply Chain Security Strategy with Multi-SBOM IntegrationPallavi Kalapatapu, Cisco 2023-11-09
  2. Safeguarding Clusters: Exploring the Benefits and Navigating the Dangers of Admission ControllersAmine Hilaly & Igor Velichkovich, AWS 2023-11-09
  3. RBACdoors: How Cryptominers Are Exploiting RBAC MisconfigsGreg Castle & Vinayak Goyal, Google 2023-11-09
  4. OIDC and Workload Identity in KubernetesAshutosh Kumar, Elastic & Anish Ramasekar, Microsoft 2023-11-09
  5. K8s Post-Exploitation: Privilege Escalation, Sidecar Container Injection, and Runtime SecurityMagno Logan, GoHacking 2023-11-09
  6. The Next Frontier: Exploring the Confidentiality of Kubernetes Control PlanesJens Freimann, Red Hat 2023-11-08
  7. Securing Identity and Authorization in MicroservicesAtul Tulshibagwale, SGNL 2023-11-08
  8. Paint the Picture! - Detecting Suspicious Data Patterns in Encrypted Traffic with eBPF and KTLSNatalia Reka Ivanko & John Fastabend, Isovalent 2023-11-08
  9. K8s Auth{N,Z} at Robinhood - Learning from Reductions, Migrations and Designing AutomationSujith Katakam & Karen Tu, Robinhood Markets, Inc. 2023-11-08
  10. Identity-Based Segmentation: An Emerging Standard for Zero Trust from NISTZack Butcher, Tetrate 2023-11-08
  11. Grifts Ahoy! Bracing for the AI TideShane Lawrence, Shopify 2023-11-08
  12. Forget Everything You Know About Image Vulnerability and PrioritizationBen Hirschberg, ARMO 2023-11-08
  13. Five Years of Cloud Native RustAlex Leong, Buoyant 2023-11-08
  14. Eraser: Cleaning up Vulnerable Images from Kubernetes NodesPeter Engelbert & Ashna Mehrotra, Microsoft 2023-11-08
  15. Wolfi: Intro to the Linux Undistro Helping Build Small, up-to-Date, CVE Free Cloud ImagesJames Rawlings, Chainguard 2023-11-07
  16. The Attacker Perspective - Insights From Hacking Alibaba Cloud's Managed K8s EnvironmentsHillai Ben-Sasson & Ronen Shustin, Wiz 2023-11-07
  17. Securing Kubernetes: Migrating from Long-Lived to Time-Bound Tokens Without Disrupting Existing AppsYuan Chen & James Munnelly, Apple Inc. 2023-11-07
  18. Cloud Native Application Threat Modeling and Adversary Emulation : Techniques and ToolsRafik Harabi, Sysdig 2023-11-07
  19. No video Clean up on Aisle Cloud!Sara Johnson, Boeing 2023-11-07
  20. Challenge to Implementing “Scalable” Authorization with KeycloakYoshiyuki Tabata, Hitachi, Ltd. 2023-11-07
  21. Arbitrary Code & File Execution in R/O FS – Am I Write?Golan Myers, WithSecure 2023-11-07
  22. All Cloud-Native Services Are Vulnerable — Block Exploits with Security Behavior AnalyticsDavid Hadas, IBM Research & Roland Huß, Red Hat 2023-11-07
  23. A Wind of Change for Threat DetectionMelissa Kilby, Apple 2023-11-07
KC-EU-23

KubeCon Europe 2023

35 talks
  1. What Can Go Wrong When You Trust Nobody? Threat Modeling Zero TrustJames Callaghan & Richard Featherstone, ControlPlane 2023-04-21
  2. The Next Log4jshell?! Preparing for CVEs with eBPF!Natalia Reka Ivanko & John Fastabend, Isovalent 2023-04-21
  3. Prevent Embarrassing Cluster Takeovers with This One Simple Trick!Daniele de Araujo dos Santos & Shane Lawrence, Shopify 2023-04-21
  4. Practical Challenges with Pod Security AdmissionV Körbes & Christian Schlotter, VMware 2023-04-21
  5. Malicious Compliance: Reflections on Trusting Container ScannersIan Coldwater, Independent; Duffie Cooley, Isovalent; Brad Geesaman, Ghost Security; Rory McCune, Datadog 2023-04-21
  6. Least Privilege Containers: Keeping a Bad Day from Getting WorseGreg Castle & Vinayak Goyal, Google 2023-04-21
  7. Can You Keep a Secret? on Secret Management in KubernetesLiav Yona & Gal Cohen, Firefly 2023-04-21
  8. Building SLSA 3 Conforment Attestors for Artifacts Generated on GitHubIan Lewis & Asra Ali, Google 2023-04-21
  9. A Look Under the Hood of CNCF Security AuditsAdam Korczynski & David Korczynski, Ada Logics 2023-04-21
  10. 🦝 The Top 10 List of Istio Security Risks and Mitigation StrategiesJosé Carlos Chávez, Tetrate 2023-04-21
  11. 🦝 Secure the Build, Secure the Cloud: Using OIDC Tokens in CI/CD PipelinesAlex Ilgayev & Elad Pticha, Cycode 2023-04-21
  12. Running Not Root Made EasyLuboslav Pivarc, Red Hat 2023-04-20
  13. Rotate Roots Right Round: Using Cert-Manager for Safer Private PKIAshley Davis, Jetstack 2023-04-20
  14. Mind the Gap! Bringing Together Cloud Services and Managed K8s EnvironmentsChristophe Tafani-Dereeper, Datadog & Diego Comas, Sourcegraph 2023-04-20
  15. Kubernetes Defensive Monitoring with PrometheusDavid de Torres Huerta & Mirco De Zorzi, Sysdig 2023-04-20
  16. Improve Vulnerability Management with OCI Artifacts – It Is That Easy!Itay Shakury, Aqua Security & Toddy Mladenov , Microsoft 2023-04-20
  17. Image Signing and Runtime Verification at Scale: Datadog's JourneyEthan Lowman, Datadog 2023-04-20
  18. Cluster Grey Zone: Risks in Managed Cluster MiddlewareShay Berkovich & Barak Sharoni, Wiz 2023-04-20
  19. Checking the Chains at the Gate: Building Supply Chain Policies with Gatekeeper and RatifyJeremy Rickard, Microsoft 2023-04-20
  20. Back to the Future: Next-Generation Cloud Native SecurityMatt Jarvis, Snyk & Andrew Martin, Control Plane 2023-04-20
  21. Automated Cloud-Native Incident Response with Kubernetes and Service MeshMatt Turner, Tetrate & Francesco Beltramini, Control Plane 2023-04-20
  22. No video 🦝 Minimalism: Key to Cloud SecurityBarun Acharya, Accuknox 2023-04-20
  23. 🦝 Interactive Playground to Learn Kubernetes and Cloud Native SecurityMadhu Akula 2023-04-20
  24. 🦝 Guardians of the Runtime: Leveraging Behavioral Analysis and PoliciesBen Hirschberg, ARMO 2023-04-20
  25. Zero Privilege ArchitecturesThijs Ebbers & Diana Iordan, ING 2023-04-19
  26. Using OpenTelemetry for Application Security, with a Real Life ExampleRon Vider, Oxeye 2023-04-19
  27. The Hacker's Guide to KubernetesPatrycja Wegrzynowicz, Form3 2023-04-19
  28. From SBOMs to IBOMs - Know What's Happening in Your ClustersIdo Neeman, Firefly 2023-04-19
  29. Confidential Containers Made EasyFabiano Fidencio, Intel & Jens Freimann, Red Hat 2023-04-19
  30. Cert-Manager Can Do SPIFFE? Solving Multi-Cloud Workload Identity Using a De Facto Standard ToolThomas Meadows, Jetstack & Joshua Van Leeuwen, Diagrid 2023-04-19
  31. Anatomy of a Cloud Security Breach - 7 Deadly SinsMaya Levine, Sysdig 2023-04-19
  32. Adopting Network Policies in Highly Secure EnvironmentsRaymond de Jong, Isovalent 2023-04-19
  33. A Confidential Story of Well-Kept SecretsLukonde Mwila, AWS 2023-04-19
  34. 🦝 RBAC to the Future: Untangling Authorization in KubernetesJimmy Mesta, KSOC 2023-04-19
  35. 🦝 Canals and Bridges: Using Amsterdam’s Transit System To Secure K8s NetworksCailyn Edwards, Shopify 2023-04-19
CNSC-NA-23

CloudNativeSecurityCon North America 2023

64 talks
  1. Zero Trust in the Cloud with WebAssembly and WasmCloudKevin Hoffman, Cosmonic 2023-02-02
  2. When SysAdmins Quit: Protecting Kubernetes Clusters When the Owner of Multiple Admin KUBECONFIGs QuitsArun Krishnakumar, VMware 2023-02-02
  3. The Four Golden Signals of Security ObservabilityDuffie Cooley, Isovalent 2023-02-02
  4. Taming Attestation for the Cloud Native World with ParsecPaul Howard, Arm 2023-02-02
  5. Spicing up Container Image Security with SLSA & GUACIan Lewis, Google 2023-02-02
  6. Solving Multi-Service Without a Service MeshEvan Anderson, VMware 2023-02-02
  7. Sharing Security Secrets: How to Encourage Security AdvocatesCailyn Edwards, Shopify 2023-02-02
  8. Self Healing GitOps: Continuous, Secure GitOps Using Argo CD, Helm and OPAUpkar Lidder , Tenable 2023-02-02
  9. Security That Enables: Breaking Down Security Silos in the DevOps EcosystemSaurabh Wadhwa, Uptycs 2023-02-02
  10. Security++: Hide Your Secrets via a Distributed Hardware Security ModuleIris Ding & Malini Bhandaru, Intel 2023-02-02
  11. Securing the Superpowers: Who Loaded That EBPF Program?John Fastabend & Natalia Reka Ivanko, Isovalent 2023-02-02
  12. SBOMs, VEX, and KubernetesKiran Kamity, Deepfactor; Jonathan Meadows , Citi; Dr. Allan Friedman, Cybersecurity and Infrastructure Security Agency; Andrew Martin, Control Plane; Rose Judge, VMware 2023-02-02
  13. Not All That’s Signed Is Secure: Verify the Right Way with TUF and SigstoreZachary Newman, Chainguard, Inc. & Marina Moore, New York University 2023-02-02
  14. Modifying the Immutable: Attaching Artifacts to OCI ImagesBrandon Mitchell, BoxBoat, an IBM Company 2023-02-02
  15. Mapping Motives Tells a Story: Analysis of 2,000 Enterprise Cloud DetectionsDavid Wolf & Joshua Smith, Devo 2023-02-02
  16. Leveraging SBOMS to Automate Packaging, Transfer, and Reporting of Dependencies Between Secure EnvironmentsIan Dunbar-Hall & Jerod Heck, Lockheed Martin 2023-02-02
  17. Learning from Supply Chain Failures and Best Practices in Other IndustriesDemian Ginther, Superorbital, LLC 2023-02-02
  18. Keyless Code Signing Without FulcioNathan Smith, Chainguard 2023-02-02
  19. Journey to Cloud-Native, K8s and Trying to Secure It.Graham E. Chukwumaobi, Independent 2023-02-02
  20. Handling JWTs: Understanding Common PitfallsBruce MacDonald, InfraHQ 2023-02-02
  21. Good Fences Make Good Neighbors: Making Cross-Namespace References More Secure with ReferenceGrantNick Young, Isovalent 2023-02-02
  22. Do This, Not That – Lessons from 7 Headline Grabbing Security BreachesMaya Levine, Sysdig 2023-02-02
  23. Delivering Secure Healthcare Applications with OSSRobert Wood, Centers for Medicare and Medicaid Services (CMS) & Gedd Johnson, Defense Unicorns 2023-02-02
  24. Container Patching: Making It Less Gross Than the Seattle Gum WallGreg Castle & Weston Panther, Google 2023-02-02
  25. Container Factory for Aerospace & Defense EnterprisesSarah Miller & Melissa Robertson, Collins Aerospace 2023-02-02
  26. CSI Container: Can You DFIR It?Alberto Pellitteri & Stefano Chierici, Sysdig 2023-02-02
  27. CNI or Service Mesh? Comparing Security Policies Across ProvidersRob Salmond, SuperOrbital & Christine Kim, Google 2023-02-02
  28. 12 Essential Requirements for Policy Enforcement and Governance with OSCALRobert Ficcaglia, SunStone Secure, LLC 2023-02-02
  29. No video 🦝 TAG Security Cloud Native Security Whitepapers OverviewShlomo Zalman Heigh, CyberArk 2023-02-02
  30. No video 🦝 Security Threat Modeling Live from Scratch SessionAndrew Martin, Control Plane 2023-02-02
  31. No video 🦝 A Sneak Peak Into Security Reviews with the CommunityRagashree MC, Carnegie Mellon University 2023-02-02
  32. Zero Trust Workload Identity in KubernetesMichael Peters, Red Hat 2023-02-01
  33. Yes, Application Security Leads to Better Business Value. Learn How from Experts.Larry Carvalho, RobustCloud; Hillary Benson, Gitlab; Kirsten Newcomer, Red Hat; David Zendzian, VMware 2023-02-01
  34. Who Are You? I Really Want to Know… the Magic Behind OIDCEddie Zaneski, Chainguard 2023-02-01
  35. What's a Zero-Trust Tunnel? Exploring Security and Simpler Operations with Istio Ambient MeshJim Barton & Marino Wijay, Solo.io 2023-02-01
  36. Verifiable GitHub Actions with eBPFJose Donizetti & Itay Shakury, Aqua Security 2023-02-01
  37. Unpacking Open Source Security in Public Repos & RegistriesBen Hirschberg, ARMO 2023-02-01
  38. Standardization and Security - A Perfect MatchRavi Devineni & Vinny Carpenter, Northwestern Mutual 2023-02-01
  39. So You Want to Run Your Own Sigstore: Recommendations for a Secure SetupHayden Blauzvern, Google 2023-02-01
  40. Security as Code: A DevSecOps ApproachXavier René-Corail, GitHub 2023-02-01
  41. Security Does Not Need to Be Fun: Ignoring OWASP to Have a Terrible TimeDwayne McDaniel, GitGuardian 2023-02-01
  42. Securing User to Service Access in KubernetesMaya Kaczorowski & Maisem Ali, Tailscale 2023-02-01
  43. Securing Self-Hosted GitHub Actions with Kubernetes and Actions-Runner-ControllerNatalie Somersall, GitHub 2023-02-01
  44. Securing Diverse Supply Chains Across Interconnected SystemsWayne Starr, Defense Unicorns & Aaron Creel, SpaceX 2023-02-01
  45. Package Transparency for WebAssembly RegistriesKyle Brown, SingleStore 2023-02-01
  46. On Establish a Production Zero Trust ArchitectureFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  47. OmniBOR: Bringing the Receipts for Supply Chain SecurityFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  48. Network Security at Scale: L3 Through L7 at SplunkMitch Connors, Aviatrix & Bernard Van De Walle, Splunk 2023-02-01
  49. More Than Just a Pretty Penny! Why You Need Cybersecurity in Your CultureCallan Andreacchi & Michaela Flatau, Defense Unicorns 2023-02-01
  50. Improving Secure Pod-to-Pod Communication Within Kubernetes Using Trust BundlesThomas Edward Hahn, TCB Technologies, Inc & Mark Hahn, Qualys 2023-02-01
  51. Identity Based Segmentation for a ZTAZack Butcher, Tetrate & Ramaswamy Chandramouli, National Institute of Standards and Technology 2023-02-01
  52. How to Secure Your Supply Chain at ScaleHemil Kadakia & Yonghe Zhao, Yahoo 2023-02-01
  53. How Do You Trust Your Open Source Software?Naveen Srinivasan, Endor Labs & Brian Russell, Google 2023-02-01
  54. Get Your Security Priorities Straight! How to Identify Workloads Under Real Threat with ContextBen Hirschberg, ARMO & Arie Haenel, Intel 2023-02-01
  55. From the Cluster to the Cloud: Lateral Movements in KubernetesYossi Weizman & Ram Pliskin, Microsoft 2023-02-01
  56. From Illuminating to Eliminating Crypto Jacking Techniques in Cloud NativeMor Weinberger, Aqua Security 2023-02-01
  57. Finding the Needles in a Haystack: Identifying Suspicious Behaviors with eBPFJeremy Cowan & Wasiq Muhammad, Amazon Web Services 2023-02-01
  58. Demystifying Zero-Trust for Cloud Native TechnologiesKishore Nadendla, TIAA; Mariusz SABATH, IBM Research; Asad Faizi, Eskala.io; Aradhna Chetal, CNCF Security TAG; Philip Griffiths, NetFoundry 2023-02-01
  59. Cryptographic Agility: Preparing Modern Apps for Quantum Safety and BeyondNatalie Fisher, VMware 2023-02-01
  60. Cloud Native Security Landscape: Myths, Dragons, and Real TalkEdd Wilder-James & Loris Degioanni, Sysdig; Kim Lewandowski, Chainguard; Isaac Hepworth, Google; Randall Degges, Snyk 2023-02-01
  61. Cloud Native Security 101: Building Blocks, Patterns and Best PracticesRafik Harabi, Sysdig 2023-02-01
  62. Beyond Cluster-Admin: Getting Started with Kubernetes Users and PermissionsTiffany Jernigan, VMware 2023-02-01
  63. Avoiding IAC Potholes with Policy + Cloud ControllersAndrew Martin, ControlPlane 2023-02-01
  64. No video 🦝 Let’s Talk Software Supply Chains with TAG SecurityMichael Lieberman, Kusari 2023-02-01
KC-NA-22

KubeCon North America 2022

22 talks
  1. You Like It Or Not; You Need It! - PKI And Certificate ManagementShweta Vohra, IBM 2022-10-28
  2. What Data Tells Us About Software Supply Chain Security & What To Do About ItJosh Bressers, Anchore; Tracy Miranda, Chainguard; John Yeoh, Cloud Security Alliance; Eric Tice, Wipro 2022-10-28
  3. Tutorial: Reducing the Sticker Price Of Kubernetes SecurityPushkar Joglekar, VMware 2022-10-28
  4. The Insider Threat: Third-Party Applications In Your ClusterDagan Henderson, Raft, LLC & Will Kline, Dark Wolf Solutions 2022-10-28
  5. So, SBOMs Matter…Now What?Sophie Wigmore & Frankie Gallina-Jones, VMware 2022-10-28
  6. Putting Hackers Breaching Your Cluster In Automatic QuarantineZiv Nevo, IBM 2022-10-28
  7. Fuzzing Session: Finding Bugs and Vulnerabilities AutomaticallyDavid Korczynski & Adam Korczynski, Ada Logics 2022-10-28
  8. B’Envoy-age to Pre-Quantum EncryptionDaniel Rouhana, Independent; Emma Dickenson, Washington State University; Doron Podoleanu, F5 2022-10-28
  9. Securing Edge Workloads With Cert-Manager And SPIFFESitaram IYER & Riaz Mohamed, Jetstack Ltd 2022-10-27
  10. Run As “Root”, Not Root: User Namespaces In K8sMarga Manterola, Isovalent & Rodrigo Campos Catelin, Microsoft 2022-10-27
  11. Path To Production: Sustainable Compliance In Strict EnvironmentsChip Zoller, Nirmata & Brandt Keller, Defense Unicorns 2022-10-27
  12. Migrating From PodSecurityPolicyTim Allclair & Sam Stoelinga, Google 2022-10-27
  13. It's Dangerous To SLSA Alone Out There! Take This Artifact Knowledge Graph!Mihai Maruseac, Google & Michael Lieberman, Independent 2022-10-27
  14. How the Argo Project Transitioned From Security Aware To Security FirstHenrik Blixt & Michael Crenshaw, Intuit 2022-10-27
  15. Hack Back; Let’s Learn Security With CTFs!Lewis Denham-Parry, Chainguard & Natalia Reka Ivanko, Isovalent 2022-10-27
  16. Using the EBPF Superpowers To Generate Kubernetes Security PoliciesMauricio Vásquez Bernal & Alban Crequy, Microsoft 2022-10-26
  17. Untrusted Execution: Attacking the Cloud Native Supply ChainAndrew Martin, ControlPlane 2022-10-26
  18. Securing the IaC Supply ChainJesse Sanford, Autodesk & Jason Hall, Chainguard 2022-10-26
  19. SLSA FRSCA Recipe For Secure Supply ChainParth Patel & Michael Lieberman, Kusari 2022-10-26
  20. SBOM X-Ray Superpowers: Making Better SBOMs, Using SBOMsBrandon Lum, Google & Chris Phillips, Anchore 2022-10-26
  21. Kubernetes to Cloud Attack Vectors: Demos InsideDanny Hershko Shemesh & Alon Schindel, Wiz 2022-10-26
  22. Armoring Cloud Native Workloads With LSM SuperpowersBarun Acharya, Accuknox 2022-10-26
CNSC-NA-22

CloudNativeSecurityCon North America 2022

22 talks
  1. The Eye of Falco: You Can Escape but Not HideStefano Chierici & Lorenzo Susini, Sysdig 2022-10-25
  2. Source Attestations with GitsignBilly Lynch, Chainguard 2022-10-25
  3. See It to Believe It: Bringing Observability to Otherwise Opaque Container BuildsParth Patel, Kusari & Shripad Nadgowda, Intel 2022-10-25
  4. Secure CI/CD Using JSON Web Token (JWT)Dov Hershkovitch, GitLab 2022-10-25
  5. Pwning the CI (with GitHub Action Workflows)Stephen Giguere, Bridgecrew 2022-10-25
  6. Policy-Based Governance for End-to-End Integrity Control of PoliciesYuji Watanabe, IBM Research & Jayashree Ramanathan, Red Hat 2022-10-25
  7. Panel Discussion: Say Hi to the New Couple in the Town – DockerSlim and Kyverno – Making Your Kubernetes Workloads More Secure!Mritunjay Sharma, Slim.AI; Shuting Zhao , Nirmata; Ruhika Bulani, D.Y. Patil College of Engineering, Aku 2022-10-25
  8. Know Your Dependencies: A Guide to Automating Dependency AssuranceSteve Judd, Jetstack 2022-10-25
  9. Introducing the OWASP Top Ten for KubernetesJimmy Mesta, KSOC Labs, Inc. 2022-10-25
  10. Getting More Confident with Your Security Helper Libraries Thanks to Go FuzzingJeremy Matos, Grafana Labs 2022-10-25
  11. Fileless Attack - Detecting the UndetectableCarolina Valencia, Aqua Security 2022-10-25
  12. Beyond Proof of Concept: Keys to a Successful SPIRE Rollout in ProductionEli Nesterov, N/A 2022-10-25
  13. Why Machines Deserve Rights: Rethinking Automated Infrastructure Access with OSS Teleport Machine IDKenneth DuMez, Teleport 2022-10-24
  14. Verifiable eBPF Traces for Supply Chain Artifacts with Witness and TetragonCole Kennedy, TestifySec 2022-10-24
  15. Uncovering the History of Your Software ArtifactsMikhail Swift, TestifySec 2022-10-24
  16. Securing Access to Kubernetes Infrastructure with Kubernetes Zero Trust PrinciplesMohan Atreya, Rafay Systems 2022-10-24
  17. Panel Discussion: Securing the Golden Path: Adding Guardrails for Developers Without Getting in Their Way!Aradhna Chetal, TIAA; Elizabeth Vasquez Alban, Barclays; Kapil Bareja, Saviyant; Jim Bugwadia, Nirmata & Anil Karmel, RegScale 2022-10-24
  18. How’s Your Supply Chain with Your Insecure OSS Ingestion?James Holland, Citi 2022-10-24
  19. Day in the Life of a Base Image: The Evolution of Vulnerabilities in the Most Popular ContainersAyse Kaya, Slim.AI 2022-10-24
  20. Conan.Io – Lessons Learned from Securing 40,000 C++ PackagesDiego Rodriguez-Losada Gonzalez, JFrog 2022-10-24
  21. Cloud Native Security for the Rest of UsTiffany Jernigan, VMware 2022-10-24
  22. Building Images for the Secure Supply ChainAdrian Mouat, Chainguard 2022-10-24
KC-EU-22

KubeCon Europe 2022

18 talks
  1. Too Much to Choose – Making Sense of a Smorgasbord of Security StandardsAnais Urlichs & Rory McCune, Aqua Security 2022-05-20
  2. Throw Away Your Passwords: Trusting Workload IdentityRic Featherstone, ControlPlane 2022-05-20
  3. Three Surprising K8s Networking “Features” and How to Defend Against ThemJames Cleverley-Prance, ControlPlane 2022-05-20
  4. Multi-Cloud Workload Identity With SPIFFEJake Sanders & Charlie Egan, Jetstack 2022-05-20
  5. Full Mesh Encryption in Kubernetes with WireGuard and CalicoPeter Kelly, Tigera 2022-05-20
  6. Attacking & Defending Kubernetes TEE Enclaves in Critical InfrastructureRobert Ficcaglia, SunStone Secure, LLC 2022-05-20
  7. Threat Modelling Kubernetes: A Lightspeed IntroductionLewis Denham-Parry, Control Plane 2022-05-19
  8. Securing Your Container Native Supply Chain with SLSA, Github and TektonLaurent Simon, Google & Priya Wadhwa, Chainguard 2022-05-19
  9. Make the Secure Kubernetes Supply Chain Work for YouAdolfo García Veytia, Chainguard 2022-05-19
  10. Fun with Continuous ComplianceAnn Wallace, Shopify & Zeal Somani, Google 2022-05-19
  11. Distributing Supply Chain Artifacts with OCI & ORAS ArtifactsSteve Lasker, Microsoft 2022-05-19
  12. Trampoline Pods: Node to Admin PrivEsc Built Into Popular K8s PlatformsYuval Avrahami & Shaul Ben Hai, Palo Alto Networks 2022-05-18
  13. The Hitchhiker's Guide to Pod SecurityLachlan Evenson, Microsoft 2022-05-18
  14. Securing Kubernetes Applications by Crafting Custom Seccomp ProfilesSascha Grunert, Red Hat 2022-05-18
  15. K8s and Active Directory Can Be Friends! How to Use Dex to Bridge the GapOnkar Bhat, Kasten by Veeam 2022-05-18
  16. How Attackers Use Exposed Prometheus Server to Exploit Kubernetes ClustersDavid de Torres Huerta & Miguel Hernández, Sysdig 2022-05-18
  17. Bypassing Falco: How to Compromise a Cluster without Tripping the SOCShay Berkovich, BlackBerry 2022-05-18
  18. Lightning Talk: Secure Multi User HPC Jobs in Kubernetes with KyvernoTrey Dockendorf, Ohio Supercomputer Center 2022-05-17
CNSC-EU-22

CloudNativeSecurityCon Europe 2022

18 talks
  1. Vanquishing Vulnerabilities in ValenciaAlba Ferri Fitó, Sysdig & Eric Smalling, Synk 2022-05-17
  2. Towards the Hardened Cloud-Native Cornerstone: Container Runtime Protection from Security to PrivacyKailun Qin, Intel 2022-05-17
  3. Top 5 Reasons (and 5 Myths Debunked) to Invest in Securing the Software Supply ChainHector Linares, Microsoft 2022-05-17
  4. Shrinking Software Attack Surface with WebAssembly & CNCF WasmcloudLiam Randall, Cosmonic 2022-05-17
  5. Securing the Supply Chain with WitnessCole Kennedy, TestifySec 2022-05-17
  6. Real Time Security - eBPF for Preventing attacksLiz Rice, Isovalent 2022-05-17
  7. Putting the Supply Chain Pieces together: A Deep Dive into the Secure software FactoryMichael Lieberman, Citi 2022-05-17
  8. Purple Teaming Like Sky’s the Limit – Adversary Emulation in the Cloud with Stratus Red TeamChristophe Tafani-Dereeper, Datadog 2022-05-17
  9. Deep Dive: Serverless Security (STAG Presentation)Andrew J Krug, Datadog; Ragashree M C, Nokia; Ashish Rajan, CISO & Ariel Shuper, Cisco 2022-05-17
  10. VEX! or... How to Reduce CVE Noise With One Simple Trick!Frederick Kautz 2022-05-16
  11. Using CNCF Best Practices for Software Supply Chain to Guide and Enhance Your Security PostureRyan Gibbons, 3m & Conor Rogers, Stelligent 2022-05-16
  12. The Unexpected Demise of Open Source LibrariesLiran Tal, Synk 2022-05-16
  13. TUF Maintainer Panel DiscussionAndrew Krug, Datadog; Asra Ali, Google; Marina Moore, NYU; Trishank Karthik Kuppusamy, Datadog; & Jussi Kukkonen, VMware 2022-05-16
  14. Security Champions: The What, Why, and HowAnn Marie Fred, Red Hat 2022-05-16
  15. Protect the Pipe! A Policy-based Approach for Securing CI/CD PipelinesShripad Nadgowda, IBM Research & Jim Bugwadia, Nirmata 2022-05-16
  16. Fuzzing the CNCF LandscapeAdam Korczynski & David Korczynski, Ada Logics 2022-05-16
  17. Dissecting the Discovery of the 0-Day Supply Chain Vulnerability in Argo CDMoshe Zioni, Apiiro 2022-05-16
  18. CTF Overview and ExperienceLewis Denham-Parry, Control Plane 2022-05-16
KC-CN-21

KubeCon China 2021 (Virtual)

2 talks
  1. Redteam 观点:K8s 集群管理员的安全实践 | Redteam Views: Security Practice of K8s Cluster AdministratorZebin Zhou, Tencent 2021-12-09
  2. 代理开放政策深潜 | Open Policy Agent Deep DiveAnders Eknert, Styra 2021-12-09
KC-NA-21

KubeCon North America 2021

14 talks
  1. We Built the Kubernetes SBOM and Now You Can Write Your Own!Adolfo García Veytia, uServers 2021-10-15
  2. The Hitchhiker's Guide to Kubernetes VulnerabilitiesRobert Clark & Micah Hausler, Amazon 2021-10-15
  3. Everything Wrong with K8s Authentication and How We Worked Around ItMo Khan & Margo Crawford, VMware 2021-10-15
  4. Bridging the Great Divide: SPIFFE/SPIRE for Cross-Cluster AuthenticationAndrew Harding, VMware 2021-10-15
  5. Untangling the Multi-Cloud Identity and Access Problem With SPIFFE TornjakBrandon Lum & Mariusz Sabath, IBM 2021-10-14
  6. Know Your Enemy: Mapping Security Risks Using Threat Matrix for KubernetesYossi Weizman & Ram Pliskin, Microsoft 2021-10-14
  7. Keeping Up with the CVEs: How to Find a Needle in a Haystack?Pushkar Joglekar, VMware 2021-10-14
  8. Insights into Unsecured Kubernetes in the WildJay Chen & Aviv Sasson, Palo Alto Networks 2021-10-14
  9. Fine-Grained User Authorization for Kubernetes with OPA and LDAPCagri Cetin & Quentin Long, Yelp Inc. 2021-10-14
  10. sigstore: How We Started, Where We Are, Where We are HeadedBob Callaway, Red Hat & Dan Lorenc, Google 2021-10-13
  11. My Container Image has 500 Vulnerabilities, Now What?Matt Jarvis, Snyk 2021-10-13
  12. Kubernetes Supply Chain Security: The Software FactoryAndrew Martin, Control Plane 2021-10-13
  13. Kubernetes Exposed! Seven of Nine Hidden Secrets That Will Give You PauseIan Coldwater, Twilio & Brad Geesaman, Aqua Security 2021-10-13
  14. Exploiting a Slightly Peculiar Volume Configuration with SIG-HonkIan Coldwater, Twilio; Brad Geesaman & Rory McCune, Aqua Security; Duffie Cooley, Isovalent 2021-10-13
CNSC-NA-21

CloudNativeSecurityCon North America 2021

10 talks
  1. The State of Vulnerability in Cloud Native SecurityMagno Logan, Trend Micro 2021-10-12
  2. The Long and Windy Road that leads to Cloud Native SecurityFrederick Kautz, Sharecare 2021-10-12
  3. Security Chaos Engineering for Fun and ProfitKennedy Torkura, Firebolt Analytics 2021-10-12
  4. Replacing PSPs? Keep Bad Pods out of your cluster using Kyverno!Shuting Zhao, Nirmata 2021-10-12
  5. Protecting the Omniverse: How NVIDIA is Securing ContainersAdam Wallis, NVIDIA 2021-10-12
  6. Data Security and Storage Hardening in Rook and CephFederico Lucifredi, Red Hat 2021-10-12
  7. Data Security: Theoretical and Real World Approaches to CompartmentalizationAna McTaggart & Michael Hackett, Red Hat; Sean Anderson, Portland State University 2021-10-12
  8. Cryptographic Signatures: A Building Block Not A PanaceaMarina Moore, NYU 2021-10-12
  9. Cloud Native Security LexiconRagashree M C, Nokia 2021-10-12
  10. Change is Hard - Securing the Future TodayAndrew Clay Shafer, Red Hat 2021-10-12
CNSD-21

Cloud Native Security Day 2021

8 talks
  1. Top 5 Concerns Every InfoSec Team Has And How To Overcome Them With eBPFNatalia Reka Ivanko, Isovalent 2021-05-04
  2. Security Nutrition Labels for Cloud Native ProjectsJohn Kinsella, Accurics 2021-05-04
  3. Securing the Software Supply Chain with the in-toto and SPIRE projectsCole Kennedy & Mikhail Swift, BoxBoat Technologies 2021-05-04
  4. Secure Code Development and Lessons Learned from etcd Security AuditSahdev Zala, IBM & Hitoshi Mitake, Indeed 2021-05-04
  5. Making Dynamic Admission Control Even More Dynamic Using WebAssemblyFlavio Castelli & Rafael Fernández López, SUSE 2021-05-04
  6. Integrating Security in the Build PipelineAnirban Saha, Allianz Direct 2021-05-04
  7. Beyond signatures: Using TUF and Notary to Secure Software DistributionMarina Moore, New York University 2021-05-04
  8. A First Look at the Security of Serverless ApplicationsEduard Marin, Telefonica Research 2021-05-04
KC-NA-20

KubeCon North America 2020 (Virtual)

11 talks
  1. Using Open Policy Agent to Meet Evolving Policy RequirementsJeremy Rickard, VMware 2020-11-20
  2. Seccomp: What Can It Do For You?Justin Cormack, Docker 2020-11-20
  3. Customizing OPA for a Perfect Fit Authorization SidecarPatrick East, Styra 2020-11-20
  4. Bypass FalcoLeonardo Di Donato, Sysdig 2020-11-20
  5. Secure Policy Distribution With OPAAsh Narkar, Styra 2020-11-19
  6. Lives On the Line. Learning Disaster Response From the Coronavirus PandemicKris Nova & Dr. Rachel Beda, Wisepatient 2020-11-19
  7. Kubernetes-native Security with StarboardLiz Rice & Daniel Pacak, Aqua Security 2020-11-19
  8. DevOps All the Things: Creating a Pipeline to Validate Your OPA PoliciesGoran Osim & Karpagam Balan, Booz Allen Hamilton 2020-11-19
  9. Static Analysis of Kubernetes ManifestsBarak Schoster, Bridgecrew 2020-11-18
  10. Security Kill Chain Stages in a 100k+ Daily Container Environment with FalcoNatch Ruengsakulrach & Eric Hollis, MathWorks 2020-11-18
  11. PKI the Wrong Way: Simple TLS Mistakes and Surprising ConsequencesTabitha Sable, Datadog 2020-11-18
CNSD-NA-20

Cloud Native Security Day North America 2020

13 talks
  1. Why OpenID Connect is More Secure then CertificatesMarc Boorshtein, Tremolo Security, Inc. 2020-11-17
  2. Welcome and IntroductionsEmily Fox, National Security Agency 2020-11-17
  3. Hardware Backed Security For Multitenancy at the Edge with SPIFFE & PARSECPaul Howard, Arm & Andres Vega, VMware 2020-11-17
  4. Exit Stage Left: Replacing Theater with ChaosKelly Shortridge, Capsule8 2020-11-17
  5. Event Closing Talk 2020-11-17
  6. Enabling Autonomous Teams With Policy Enforcement at YubicoJames Alseth & John Reese, Yubico 2020-11-17
  7. Dynamic Image Scanning Through System TracingItay Shakury, Aqua Security 2020-11-17
  8. Designing Secure Applications in the CloudAdora Nwodo, Microsoft 2020-11-17
  9. Cloud Security and how to leverage the shared responsibility model to your advantageEshrak Assaf & David Lebutsch, IBM 2020-11-17
  10. Cartography: using graphs to improve and scale security decision-makingAlex Chantavy, Lyft & Marco Lancini, Thought Machine 2020-11-17
  11. Capture the Flag Wrap Up & SummaryAndrew Martin, Control Plane & Magno Logan, Trend Micro 2020-11-17
  12. Building Effective Attack Detection in the CloudAlfie Champion & Nick Jones, F-Security Consulting 2020-11-17
  13. A Tale of a Meshi Kafka: Securing Kafka Deployment When Istio Is UsedAriel Shuper, Portshift & Nikolas Mousouros, Marlow Navigation 2020-11-17
KC-NA-19

KubeCon North America 2019

16 talks
  1. Securing Communication Between Meshes and Beyond with SPIFFE FederationEvan Gilman, Scytale & Oliver Liu, Google 2019-11-21
  2. Prepare to Be Boarded! A Tale of Kubernetes, Plunder, and CryptobootyJames Condon, Lacework 2019-11-21
  3. Kubernetes Policy Enforcement Using OPA At Goldman SachsMiguel Uzcategui, Goldman Sachs & Tim Hinrichs, Styra 2019-11-21
  4. Identity Bootstrapping in Multi-tenant Multi-cluster KubernetesManish Mehta, Volterra & Derek Suzuki, The Voleon Group 2019-11-21
  5. How Yelp Moved Security From the App to the Mesh with Envoy and OPADaniel Popescu, Yelp & Ben Plotnick, Cruise 2019-11-21
  6. How Kubernetes Components Communicate Securely in Your ClusterMaya Kaczorowski, Google 2019-11-21
  7. Redesigning Notary in a Multi-registry WorldJustin Cormack, Docker 2019-11-20
  8. Piloting Around the Rocks: Avoiding Threats in KubernetesRobert Tonic & Stefan Edwards, Trail of Bits 2019-11-20
  9. No video On the Security of Copying To and From Live ContainersAriel Zelivansky & Yuval Avrahami, Palo Alto Networks 2019-11-20
  10. Knative - The Security Platypus?Ariel Shuper, Aqua Security 2019-11-20
  11. Binary Authorization in KubernetesAysylu Greenberg, Google & Liron Levin, Palo Alto Networks 2019-11-20
  12. Walls Within Walls: What if Your Attacker Knows Parkour?Tim Allclair & Greg Castle, Google 2019-11-19
  13. The Devil in the Details: Kubernetes’ First Security AssessmentAaron Small, Google & Jay Beale, InGuardians 2019-11-19
  14. Panel: Control Plane vs Data Plane: Untangling the Tenets of MultitenancyTasha Drew, VMware; Sanjeev Rampal, Cisco; Ryan Bezdicek, Cray Inc.; Adrian Ludwin, Google; & Fei Guo, Alibaba 2019-11-19
  15. Enforcing Automatic mTLS with Linkerd and OPA GatekeeperIvan Sim, Buoyant & Rita Zhang, Microsoft 2019-11-19
  16. CAP_NET_RAW and ARP Spoofing in Your Cluster: It's Going Downhill From HereLiz Rice, Aqua Security 2019-11-19
CNSD-19

Cloud Native Security Day 2019

8 talks
  1. Trusted Software Supply Chain with JTESteven Terrana, Booz Allen Hamilton 2019-11-18
  2. The Path Less Traveled: Abusing Kubernetes DefaultsDuffie Cooley, VMware & Ian Coldwater, Heroku 2019-11-18
  3. The Devil in the Details: Kubernetes’ First Security AssessmentJay Beale, InGuardians & Aaron Small, Google 2019-11-18
  4. Slowing Our Role: Moving Towards Policy at PlexJohn Reese, Plex Systems 2019-11-18
  5. Palo Alto Networks Sponsored Session - How to Choose Which Cloud Native Technologies Work Best for Specific WorkloadsJohn Morello, Palo Alto Networks 2019-11-18
  6. MLGuard -- Detecting Malicious Web Requests using a Serverless-based Machine Learning SystemAbhinav Srivastava, Frame.io 2019-11-18
  7. IBM Sponsored Session - Protecting Kubernetes Workloads from AttacksChris Rosen, IBM 2019-11-18
  8. Continuous Assurance and Continuous Compliance via Data, Graph, Query and CodeErkang Zheng, LifeOmic 2019-11-18
KC-CN-19

KubeCon China 2019

5 talks
  1. Secure Container with SGX: Protecting Secret in Cloud EnvironmentIsaku Yamahata, Intel & Xiaoning Li, Alibaba 2019-06-26
  2. Upgrade Images by Digging Out and Automatically Fixing the VulnerabilitiesLin Ru, DaoCloud & Yan Wang, VMware 2019-06-25
  3. Protecting Sensitive Code with Encrypted Container Images on KubernetesBrandon Lum & Harshal Patil, IBM 2019-06-25
  4. How SPIFFE Helps Istio in Service Mesh FederationYonggang Liu & Wencheng Lu, Google 2019-06-25
  5. Gatekeeper: Flexible, Shareable Policy for KubernetesCraig Peters, Mircosoft 2019-06-25
KC-EU-19

KubeCon Europe 2019

17 talks
  1. Uber x Security: Why and How We Built Our Workload Identity PlatformTyler Julian, Uber & Daniel Feldman, Scytale 2019-05-23
  2. Securing Multi-Cloud Cross-Cluster Communication with SPIFFE and SPIREEvan Gilman, Scytale, Inc. 2019-05-23
  3. Securing Kubernetes with Trusted Platform Module (TPM)Alex Tcherniakhovski & Andrew Lytvynov, Google 2019-05-23
  4. Secrets Store CSI Driver-Bring Your Own Enterprise Secrets Store to K8sRita Zhang, Microsoft & Anubhav Mishra, HashiCorp 2019-05-23
  5. Protecting the Data LakeAsh Narkar, Styra, Inc 2019-05-23
  6. DIY Pen-Testing for Your Kubernetes ClusterLiz Rice, Aqua Security 2019-05-23
  7. Zero Trust Service Mesh with Calico, SPIRE, and EnvoyShaun Crampton, Tigera & Evan Gilman, Scytale 2019-05-22
  8. Smarter Kubernetes Access Control: A Simpler Approach to AuthRob Scott, ReactiveOps 2019-05-22
  9. Inside the CNCF Project Security ReviewsJustin Cormack, Docker 2019-05-22
  10. Crafty Requests: Deep Dive Into Kubernetes CVE-2018-1002105Ian Coldwater, Heroku 2019-05-22
  11. Container Forensics: What to Do When Your Cluster is a ClusterMaya Kaczorowski & Ann Wallace, Google 2019-05-22
  12. Caller ID in KubernetesMichael Danese, Google 2019-05-22
  13. Using eBPF to Bring Kubernetes-Aware Security to the Linux KernelDan Wendlandt, Isovalent 2019-05-21
  14. Portable, Universal Single Sign-On for Your ClustersMiguel Martinez, Bitnami 2019-05-21
  15. Kubernetes + Encrypted Memory = Security * PrivacyHarshal Patil & Pradipta Banerjee, IBM 2019-05-21
  16. Fine-Grained Permissions in Kubernetes: What’s Missing, and How to Fix ThatVallery Lancey, Lyft & Seth McCombs, Triller 2019-05-21
  17. Envoy SDS: Fortifying Istio SecurityYonggang Liu & Quanjie Lin, Google 2019-05-21
KC-NA-18

KubeCon North America 2018

14 talks
  1. Single Sign-On for KubernetesJoel Speed, Pusher 2018-12-13
  2. Shopify’s $25k Bug Report, and the Cluster Takeover That Didn’t HappenGreg Castle, Google & Shane Lawrence, Shopify 2018-12-13
  3. Using Application Identity to Correlate Metrics: A Look at SPIFFE and SPIREPriyanka Sharma, GitLab 2018-12-12
  4. So You Want to Run Vault in Kubernetes?Seth Vargo, Google 2018-12-12
  5. Scrutinizing SPIRE to Sensibly Strengthen SPIFFE SecurityMatt Moyer, Heptio & Evan Gilman, Scytale 2018-12-12
  6. Navigating Workload Identity in KubernetesMichael Danese, Google & Spike Curtis, Tigera 2018-12-12
  7. How We Survived Our First PCI/HIPAA Compliant Check with KubernetesTravis Jeppson, Nav 2018-12-12
  8. Friends Don’t Let Friends Leave Their Kubernetes Data UnprotectedRita Zhang, Microsoft 2018-12-12
  9. This Year, It’s About SecurityMaya Kaczorowski & Brandon Baker, Google 2018-12-11
  10. Securing Kubernetes With Admission ControllersDave Strebel, Microsoft 2018-12-11
  11. Recent Advancements in Container IsolationTim Allclair & Adin Scannell, Google 2018-12-11
  12. How Symlinks Pwned Kubernetes (And How We Fixed It)Michelle Au, Google & Jan Šafránek, Red Hat 2018-12-11
  13. Hardening Kubernetes Setups: War Stories from the Trenches of ProductionPuja Abbassi, Giant Swarm 2018-12-11
  14. Athenz with Istio: Single Access Control Model in Cloud InfrastructuresTatsuya Yano, Yahoo Japan Corporation 2018-12-11
KC-CN-18

KubeCon China 2018

10 talks
  1. The State of Your Supply ChainAndrew Martin, ControlPlane & Maya Kaczorowski, Google 2018-11-15
  2. Nabla Containers: A New Approach to Container IsolationBrandon Lum & Ricardo Koller, IBM 2018-11-15
  3. Layers of Isolation in KubernetesTim Allclair, Google 2018-11-15
  4. Istio Certificate Management Through VaultLei Tang & Yonggang Liu, Google 2018-11-15
  5. Implementing AuthorizationTorin Sandall, Styra 2018-11-15
  6. Hardening Multi-Cloud Kubernetes Clusters as a ServiceDirk Marwinski, SAP SE & Alban Crequy, Kinvolk GmBH 2018-11-15
  7. Turtles All the Way Down: Securely Managing Kubernetes Secrets With SecretsMaya Kaczorowski & Alexandr Tcherniakhovski, Google 2018-11-14
  8. Three Years of Lessons Running Potentially Malicious Code Inside ContainersBen Hall, Katacoda 2018-11-14
  9. Securing the Deploy PipelineFelix Glaser, Shopify 2018-11-14
  10. Access Policies for Hybrid Cloud EnvironmentsRuiyi Wang, Google 2018-11-14
KC-EU-18

KubeCon Europe 2018

18 talks
  1. TL;DR NIST Container Security StandardsElsie Phillips, CoreOS 2018-05-04
  2. Secure PodsTim Allclair, Google 2018-05-04
  3. Multi-Tenancy in Kubernetes: Best Practices Today, and Future DirectionsDavid Oppenheimer, Google 2018-05-04
  4. Kubernetes Runtime Security: What Happens if a Container Goes Bad?Jen Tong & Maya Kaczorowski, Google 2018-05-04
  5. From Kubelet to Istio: Kubernetes Network Security DemystifiedAndrew Martin, ControlPlane 2018-05-04
  6. A Hacker's Guide to Kubernetes and the CloudRory McCune, NCC Group PLC 2018-05-04
  7. OPA: The Cloud Native Policy EngineTorin Sandall, Styra 2018-05-03
  8. Good Enough for the Finance Industry: Achieving High Security at Scale with Microservices in KubernetesZachary Arnold & Austin Adams, Ygrene Energy Fund 2018-05-03
  9. Entitlements: Understandable Container Security ControlsJustin Cormack & Nassim Eddequiouaq, Docker 2018-05-03
  10. Container Isolation at Scale (Introducing gVisor)Dawn Chen & Zhengyu He, Google 2018-05-03
  11. Case Study: How Containers Makes Security and Compliance Instantly EasierJohn Morello, Twistlock 2018-05-03
  12. Applying Least Privileges through Kubernetes Admission ControllersBenjy Portnoy, Aqua Security 2018-05-03
  13. The Route To Rootless ContainersEd King, Pivotal & Julz Friedman, IBM 2018-05-02
  14. Securing your Kubernetes Delivery Pipelines with Notary and TUFLiam White & Michael Hough, IBM 2018-05-02
  15. Improving your Kubernetes Workload Security with Hardware VirtualizationFabian Deutsch, Red Hat & Samuel Ortiz, Intel 2018-05-02
  16. Establishing Image Provenance and Security in KubernetesAdrian Mouat, Container Solutions 2018-05-02
  17. Completely Securing the Software Supply Chain using Grafeas + in-totoLukas Puehringer, NYU & Wendy Dembowski, Google 2018-05-02
  18. No video Cloud Native Identity ManagementAndreas Zitzelsberger, QAware GmbH & Andrew Jessup, Scytale Inc. 2018-05-02
KC-NA-17

KubeCon North America 2017

6 talks
  1. When the Going Gets Tough, Get TUF Going! [I]David Lawrence & Ashwini Oruganti, Docker 2017-12-06
  2. The Power of Application Intent Analysis for Container Security [I]John Morello, Twistlock 2017-12-06
  3. Introducing SPIFFE: An Open Standard for Identity in Cloud Native Environments [I]Evan Gilman, Scytale 2017-12-06
  4. IAM on Hybrid Cloud: Next Generation Security Model to Create an Interoperable Cloud [I]Jeyappragash JJ & Kamil Pawlowski, padme.io 2017-12-06
  5. How Netflix Is Solving Authorization Across Their Cloud [I]Manish Mehta & Torin Sandall, Netflix 2017-12-06
  6. Building a Secure, Multi-Protocol and Multi-Tenant Cluster for Internet-Facing Services [A]Bich Le, Platform9 2017-12-06
KC-NA-16

KubeCon North America 2016

4 talks
  1. Technical View: Comparison of Container Orchestration and Management SystemsLei Zhang, HyperHQ 2016-11-09
  2. Sentinel: A Platform for Fine-grained Application SecuritySudheendra Murthy, eBay, Inc. 2016-11-09
  3. Plumbing the Cloud for ContainersMichael Friis, Docker 2016-11-09
  4. A Security State of Mind: Compliance and Vulnerability Audits for ContainersChris Van Tuin, Red Hat 2016-11-09