Collected every two hours from specialised publications — each link leads to the original article.
A large number of servers running the Kubernetes API have been left exposed to the internet, which is not great: they're potentially vulnerable to abuse.
A large number of servers running the Kubernetes API have been left exposed to the internet, which is not great: they're potentially vulnerable to abuse.
Kubernetes has quickly become a de facto tool within enterprise software development environments, enabling DevOps engineers to scale large numbers of containe…
A newly disclosed security vulnerability in the Kubernetes container engine CRI-O calledcr8escapecould be exploited by an attacker to break out of containers a…
Hackers could exploit a Linux kernel bug to escape Kubernetes containers and access critical resources; however, the threat is minimized as any attacker needs …
Infrastructure security is important to get right so that attacks can be prevented''or, in the case of a successful attack, damage can be minimized. It is espe…
While it's come a long way over the past year, Kubernetes security has not yet reached maturity. But judging from the level of investment in 2021 into technolo…
The container caasp/v4/kubernetes-client was updated. The following patches have been included in this update:
NSA/CISA Kubernetes hardening guidance offers a solid foundation for securing Kubernetes environments. Here are the key components and why they're important.
Hardening guidance from the NSA and CISA seeks to educate IT administrators about cloud security risks and best practices for implementing and maintaining Kube…
The container caasp/v4.5/k8s-sidecar was updated. The following patches have been included in this update:
Kubernetes adoption is up - and so is the number of security incidents in container and Kubernetes environments. One of the ways that organizations can tackle …
Kubernetes has recently announced a much-needed step in the light of its popularity and the growing userbase. Reportedly, Kubernetes hasKubernetes Launch Bug B…
Want to help lock down Kubernetes and make some money while you're at it? The Cloud Native Computing Foundation has a new bug bounty program for you.
Update to v1.15.7 (CVE-2018-1002102 kubernetes: improper validation of URL redirection in the Kubernetes API server allows an attacker-controlled Kubelet to re…
An update that solves one vulnerability can now be installed.
An update that solves one vulnerability can now be installed.
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.A Shodan harveste…
An update that can now be installed.
An update that can now be installed.
Update to release v1.35.6 Resolves: rhbz#2467606 Upstream fixes
Update to release v1.34.9 Resolves: rhbz#2467605 Upstream fixes
Update to release 1.33.13 Resolves: rhbz#2467604 Upstream fix
Update to release v1.35.6 Resolves: rhbz#2467606 Upstream fixes