<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://talks.container-security.site/feed.xml" rel="self" type="application/atom+xml" /><link href="https://talks.container-security.site/" rel="alternate" type="text/html" /><updated>2026-04-12T08:10:03+00:00</updated><id>https://talks.container-security.site/feed.xml</id><title type="html">Cloud Native Security Talks</title><subtitle>This site hosts a list of talks from various conferences on the topic of Cloud Native security. </subtitle><author><name>About</name></author><entry><title type="html">🎤 Who Wants To Secure Clusters ? - Henrik Rexed &amp;amp; Simon Reisinger, Dynatrace</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Who-Wants-To-Secure-Clusters-Henrik-Rexed/" rel="alternate" type="text/html" title="🎤 Who Wants To Secure Clusters ? - Henrik Rexed &amp;amp; Simon Reisinger, Dynatrace" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/-----Who-Wants-To-Secure-Clusters-----Henrik-Rexed</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Who-Wants-To-Secure-Clusters-Henrik-Rexed/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Securing a k8s cluster isn’t just a task—it’s a team sport. From writing secure code to locking down containers, networks, and runtime environments, security spans every layer of the cloud-native stack. But let’s face it: it can be overwhelming.So, what if learning about k8s security was as thrilling as a game show?Join us for an interactive, high-energy session inspired by Who Wants to Be a Millionaire?—where the audience becomes the contestant, and the grand prize is… a fully secured cluster!In Who Wants to Secure Your Cluster?, we’ll explore:🔐 Best practices across the k8s security lifecycle🛠️ Hands-on comparisons of popular open source CNCF security tools🎯 Actionable recommendations from real-world experienceThis session blends education, entertainment, and expertise. Whether you’re a developer, DevOps engineer, or security lead, you’ll walk away with practical insights, and maybe even bragging rights as the one who secured it all.Are you ready to play?</p>

<p><a href="https://kccncna2025.sched.com/event/afeb498d16f8b1574c665cca46a85834">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/8UXgIHSh8K0" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Aligning Enterprise AI Security With MITRE ATLAS Using Open Source Technologies - Doron Caspin &amp;amp; Valentina Rodriguez Sosa, Red Hat</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Aligning-Enterprise-AI-Security-With-MITRE-ATLAS-U/" rel="alternate" type="text/html" title="Aligning Enterprise AI Security With MITRE ATLAS Using Open Source Technologies - Doron Caspin &amp;amp; Valentina Rodriguez Sosa, Red Hat" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Aligning-Enterprise-AI-Security-With-MITRE-ATLAS-U</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Aligning-Enterprise-AI-Security-With-MITRE-ATLAS-U/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>As AI becomes integral to enterprise applications, securing AI/ML systems is paramount. While MITRE ATLAS provides a robust framework for understanding adversarial threats to AI, enterprises often struggle to adopt it in cloud-nativeenvironments. This session demonstrates practical strategies for using open-source tools to operationalize AI security and align with the MITRE ATLAS framework.We’ll explore real-world use cases illustrating how tools like Kubeflow, Clair, Falco, StackRox, and Kubescape can be combined to detect and mitigate threats such as data poisoning, model extraction, and evasion attacks throughout the AIlifecycle—from training to inference.Attendees will gain insights into:Understanding the MITRE ATLAS framework and its significance for AI/ML security, Mapping open-source tools to the ATLAS matrix for actionable, layered defenses, Integrating security controls into MLOps pipelines using Kubernetes-native tooling.</p>

<p><a href="https://kccncna2025.sched.com/event/f70f64f39d7571cc868c480fa9b8f216">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/Va45Tx0RifI" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Authenticating and Authorizing Every Connection at Uber - Yangmin Zhu &amp;amp; Matt Mathew, Uber</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Authenticating-and-Authorizing-Every-Connection-at/" rel="alternate" type="text/html" title="Authenticating and Authorizing Every Connection at Uber - Yangmin Zhu &amp;amp; Matt Mathew, Uber" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Authenticating-and-Authorizing-Every-Connection-at</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Authenticating-and-Authorizing-Every-Connection-at/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Uber operates one of the world’s largest and most complex microservice architectures, composed of thousands of services built in diverse languages and maintained by independent teams. Ensuring consistent, secure service-to-service communication, without requiring code changes, posed a massive challenge.In this talk, we’ll share how we built and scaled a platform-level authentication and authorization solution based on Envoy, SPIRE, and the SPIFFE standard. Over a 3-year journey, we rolled out a Zero Trust architecture securing every service interaction with mTLS, authenticating workloads using SPIFFE identities, and enforcing fine-grained policies through a unified control plane.Attendees will learn about the architectural decisions, operational hurdles, and user-experience tradeoffs we faced along the way. Whether you’re starting your Zero Trust journey or looking to scale Envoy/SPIRE across a large org, this talk will offer practical insights from real-world deployment at scale.</p>

<p><a href="https://kccncna2025.sched.com/event/42e9e881d8c30eaa25d2c5149949ae61">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/GYVNg0_FpwQ" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Securing Data Applications at Pinterest With Finer Grained Access Control on Kubernetes - Soam Acharya &amp;amp; William Tom, Pinterest</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Securing-Data-Applications-at-Pinterest-With-Finer/" rel="alternate" type="text/html" title="Securing Data Applications at Pinterest With Finer Grained Access Control on Kubernetes - Soam Acharya &amp;amp; William Tom, Pinterest" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Securing-Data-Applications-at-Pinterest-With-Finer</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Securing-Data-Applications-at-Pinterest-With-Finer/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>At Pinterest, our data processing platform runs nearly 90K jobs on 20K nodes ingesting about 200PB of data daily, powering ML models, user insights, data lakes, and more. This massive scale, while pushing the limits of cloud computing, requires secure, least-privileged data management that also has to meet evolving regulations. To address these needs, we introduced Finer Grained Access Control (FGAC) into Moka, our new Kubernetes-based processing platform. FGAC integrates Kubernetes and AWS features (namespaces, sidecars, service accounts, RBAC, STS, EKS, IRSA) to authenticate with internal services (servicemesh, mTLS, IAM proxy) for a secure multi-tenant environment supporting Spark, Ray, and Flink. In this talk, we detail our design for Moka FGAC and current migration status. We also share the trade-offs and design decisions that led to better data isolation, scale, improved resource utilization and an overall simpler approach compared to our previous Hadoop/Kerberos based solution.</p>

<p><a href="https://kccncna2025.sched.com/event/9248015d029bded98a02cef0e7f63f6f">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/jPS6P3mTbqo" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">The Ultimate Container Challenge: An Interactive Trivia Game on Supply Chain Security - Aurélie Vache, OVHcloud &amp;amp; Sherine Khoury, Red Hat</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/The-Ultimate-Container-Challenge-An-Interactive-T/" rel="alternate" type="text/html" title="The Ultimate Container Challenge: An Interactive Trivia Game on Supply Chain Security - Aurélie Vache, OVHcloud &amp;amp; Sherine Khoury, Red Hat" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/The-Ultimate-Container-Challenge--An-Interactive-T</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/The-Ultimate-Container-Challenge-An-Interactive-T/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Congratulations! You’ve successfully built and pushed your container image to a registry, but are you ready to deploy to production? Is your SecOps team confident with your container’s robustness in the face of production environments?How do you ensure the image you’ve built is the one running? Are you sure it is composed of vulnerability-free software and that your supply chain hasn’t been compromised along the way?Don’t panic! In this fun and dynamic talk, you can learn and/or improve your knowledge, about the way to secure your containers, with supply chain security.With a mix of quiz and live demos, you will discover or dig into several supply chain concepts and frameworks, CNCF and open source projects like SBOM, SigStore, SLSA, OpenSSF, VEX, GUAC, in-toto and many more!Are you up for this new quiz challenge? Icing on the cake: Top scores will win some swags.</p>

<p><a href="https://kccncna2025.sched.com/event/3ce7ff94622173556f4972a889cc3380">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/n_tkj5KmzzE" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Tools and Strategies for Making the Most of Kubernetes Access Control - Lucas Käldström, Upbound &amp;amp; Micah Hausler, AWS</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Tools-and-Strategies-for-Making-the-Most-of-Kubern/" rel="alternate" type="text/html" title="Tools and Strategies for Making the Most of Kubernetes Access Control - Lucas Käldström, Upbound &amp;amp; Micah Hausler, AWS" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Tools-and-Strategies-for-Making-the-Most-of-Kubern</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Tools-and-Strategies-for-Making-the-Most-of-Kubern/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Have you ever struggled writing least-privilege access control policies for Kubernetes? Are you concerned about the wide permissions of installed Helm charts? Do you manage to regularly audit who has access to sensitive resources?   In this talk, Kubernetes contributors Micah and Lucas introduce you to open source tools that help you on your defense in depth journey for securing the Kubernetes API surface. They demonstrate how to right-size your RBAC rules semi-automatically, audit who can access sensitive resources, and check whether policy refactors are correct.   This talk is part of a journey to improve Kubernetes access control in core. However, to make this initiative successful, user feedback is needed throughout the process. You’ll learn about the planned Kubernetes Conditional Authorization feature, which will make authoring right-sized policies easier.   By the end of the talk, you will know how to get involved, and future directions for improved Kubernetes access control.</p>

<p><a href="https://kccncna2025.sched.com/event/b0919524b70b4bd69f0efd746472ea23">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/JBM0PRyDaPs" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">You Deployed What?! Data-Driven Lessons on Unsafe Helm Chart Defaults - Yossi Weizman, Microsoft</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/You-Deployed-What-Data-Driven-Lessons-on-Unsafe/" rel="alternate" type="text/html" title="You Deployed What?! Data-Driven Lessons on Unsafe Helm Chart Defaults - Yossi Weizman, Microsoft" /><published>2025-11-13T00:00:00+00:00</published><updated>2025-11-13T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/You-Deployed-What---Data-Driven-Lessons-on-Unsafe-</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/You-Deployed-What-Data-Driven-Lessons-on-Unsafe/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Most breach post-mortems start with “Which CVE?” However, ours usually end with “There wasn’t one.” We analyzed 10 B Kubernetes audit events and scanned over 3000 clusters to map compromise paths that rely solely on insecure defaults shipped by default in widely trusted Helm charts. The pattern is painfully consistent: world-reachable Service/Ingress, authentication set to “off by default,” and a pod that have permissions to go wild. We’ll chain those three defaults against Apache Pinot, Selenium Grid and Meshery all without a single vulnerability.To flip the script, we’ll walk through hardening the same workloads using existing community tools like OPA Gatekeeper, Kyverno, Pod Security Admission, and GitHub Actions to enforce guardrails before someone in your organization is going to deploy an “official” Helm chart.</p>

<p><a href="https://kccncna2025.sched.com/event/631d858dc3de962ad5a246e5dbf56233">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/tssAofKij6g" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Patch Me If You Can: Tackling Outdated Addons Before They Become a Risk - Stevie Caldwell &amp;amp; Andy Suderman, Fairwinds</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Patch-Me-If-You-Can-Tackling-Outdated-Addons-Befo/" rel="alternate" type="text/html" title="Patch Me If You Can: Tackling Outdated Addons Before They Become a Risk - Stevie Caldwell &amp;amp; Andy Suderman, Fairwinds" /><published>2025-11-12T00:00:00+00:00</published><updated>2025-11-12T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Patch-Me-If-You-Can--Tackling-Outdated-Addons-Befo</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Patch-Me-If-You-Can-Tackling-Outdated-Addons-Befo/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Kubernetes addons often sit quietly behind the scenes—until they become your biggest security liability. Whether it’s an old version of a DNS provider, metrics server, or ingress controller, these components are essential to your cluster’s operation but rarely treated as part of a regular update cycle. In this session, we’ll dive into the risks of neglecting addon maintenance and share practical strategies for getting ahead of potential failures or vulnerabilities. You’ll learn how to assess addon health, prioritize updates, and communicate the business case for proactive maintenance—even when everything seems to be working “just fine.” Walk away with tools to build a repeatable, low-friction update plan that boosts both the security and reliability of your clusters.</p>

<p><a href="https://kccncna2025.sched.com/event/d7ea2570a72e83a56f1f9fa0890798c5">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/2SoLCWl800w" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Quantum-Resistant Kubernetes: Realities, Risks &amp;amp; (Versioning) Pitfalls - Fabian Kammel, ControlPlane</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Quantum-Resistant-Kubernetes-Realities-Risks/" rel="alternate" type="text/html" title="Quantum-Resistant Kubernetes: Realities, Risks &amp;amp; (Versioning) Pitfalls - Fabian Kammel, ControlPlane" /><published>2025-11-12T00:00:00+00:00</published><updated>2025-11-12T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Quantum-Resistant-Kubernetes--Realities--Risks----</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Quantum-Resistant-Kubernetes-Realities-Risks/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>Post-Quantum Cryptography (PQC) is no longer theoretical. With Go 1.24+ enabling ML-KEM by default, Kubernetes v1.33+ inherits significant quantum resistance for key exchange. This talk dives into the practical realities. We’ll briefly cover the current state of PQC standardization, such as ML-KEM (FIPS-203) and then critically examine real-world implications: how K8s “accidentally” already benefits from PQC key exchange, the subtle but critical downgrade risks from mismatched Go versions (e.g., Go 1.23’s <code class="language-plaintext highlighter-rouge">X25519Kyber768Draft00</code> vs. 1.24’s <code class="language-plaintext highlighter-rouge">X25519MLKEM768</code>), and the “tldr.fail” issue where large PQC key shares can break TLS handshakes due to packet size limits. We’ll explore these challenges with evidence from the K8s ecosystem, offering insights for maintainers and advanced users navigating the PQC transition.</p>

<p><a href="https://kccncna2025.sched.com/event/18f775687be4e97fd48a0e5eca4a63e4">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/3yOwAIpbuQ0" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry><entry><title type="html">Red Vs. Blue: A Live Attacker-Defender Showdown in Kubernetes Security - Lucy Sweet, Uber &amp;amp; Sandeep Kanabar, Gen</title><link href="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Red-Vs.-Blue-A-Live-Attacker-Defender-Showdown-in/" rel="alternate" type="text/html" title="Red Vs. Blue: A Live Attacker-Defender Showdown in Kubernetes Security - Lucy Sweet, Uber &amp;amp; Sandeep Kanabar, Gen" /><published>2025-11-12T00:00:00+00:00</published><updated>2025-11-12T00:00:00+00:00</updated><id>https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Red-Vs.-Blue--A-Live-Attacker-Defender-Showdown-in</id><content type="html" xml:base="https://talks.container-security.site/kubecon%20+%20cloudnativecon%20north%20america%202025/Red-Vs.-Blue-A-Live-Attacker-Defender-Showdown-in/"><![CDATA[<h2 id="abstract">Abstract</h2>

<p>What if learning Kubernetes security could be thrilling, practical - and a little chaotic?   In this interactive session, we stage a live attacker-versus-defender “chess match” inside a Kubernetes cluster. One speaker plays the role of a determined attacker, exploiting common misconfigurations, privilege escalations, and overly permissive RBAC. The other, a vigilant defender, responds with best-practice mitigations and live troubleshooting.   You’ll watch a Kubernetes environment come under siege - and see how thoughtful, layered defenses can stop even persistent attackers in their tracks. Expect live demos, sharp insights, and just enough chaos to keep it real.   We’ll cover escalating security scenarios, from pod privilege abuse to namespace isolation, resource quotas and Admission Webhooks, showing not just what to do, but why it matters.   This isn’t theory-it’s security by example, performed live.</p>

<p><a href="https://kccncna2025.sched.com/event/06240bf0211e12d819661750a01cee98">Sched URL</a></p>

<h2 id="video">Video</h2>

<iframe src="https://www.youtube.com/embed/q6ckwAXeeew" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen=""></iframe>]]></content><author><name>About</name></author><category term="KubeCon + CloudNativeCon North America 2025" /><summary type="html"><![CDATA[Abstract]]></summary></entry></feed>