#KubernetesSecurity

George stevengeorge801
2025-06-03

🎯 Preparing for the Certified Kubernetes Security Specialist (CKS) exam?
🔐 Master Kubernetes security and boost your cloud native skills!

I’ve written a detailed blog covering:
✅ What’s in the CKS exam
✅ Key domains & tips
✅ How to prepare effectively

📖 Read it here: bit.ly/4knIgLR

2025-05-06

Man, Microsoft isn't mincing words about Kubernetes and Helm Charts! That whole "plug-and-play" thing? It can go south, *fast*. It's wild how many people forget that default settings are often basically an open door for trouble.

You know, working as a pentester, I see this kind of thing constantly. We're talking services just hanging out online with no real protection, authentication totally MIA... and then, *bam*, the data's just gone. It's a nightmare scenario, but it happens.

So, for real, everyone – you've *got* to dig into your YAML files and Helm charts. Don't just skim 'em; really get in there and check things over.

What are your biggest K8s security headaches? Seriously, what keeps you up at night with your setups? Drop a comment below!
#KubernetesSecurity #Pentesting #CloudSecurity

2025-05-05

Default Helm charts in Kubernetes might be like leaving your front door unlocked – sensitive data and weak settings could be inviting trouble. Is your deployment really secure?

thedefendopsdiaries.com/enhanc

#kubernetessecurity
#helmcharts
#cybersecurity
#devsecops
#cloudsecurity

2025-04-27

Let's level up our EKS security game! Join our hands-on webinar on "Shift Right Security for EKS" with Bion Consulting and Anchore. Learn practical techniques to identify and remediate vulnerabilities in your scaling EKS applications. We will focus on:
- Kubernetes Runtime Inventory and why it matters for container security
- How to install and configure Anchore's Runtime Inventory on Amazon EKS
- How Anch... get.anchore.com/shift-right-se #EKS #KubernetesSecurity #DevSecOps #Anchore #SecurityWebinar

Code Labs Academycodelabsacademyupdates
2025-04-13

Want to level up your Kubernetes game? This article covers certifications, security, and your next steps! Check it out!

Continue reading the full article codelabsacademy.com/en/blog/ku

Tedi Heriyantotedi@infosec.exchange
2024-12-01

Making Sense of Kubernetes Initial Access Vectors

- Part 1: www.wiz.io/blog/making-sense-of-kubernetes-initial-access-vectors-part-1-control-plane

- Part 2: wiz.io/blog/kubernetes-data-pl

#kubernetes #k8s #KubernetesSecurity

Thomas Fricke (he/him)thomasfricke@23.social
2024-11-10
2024-10-08

Does #cybersecurity really need another #Kubernetes vulnerability scanner? 👉 Heck yes!

💪 Find out WHY and HOW we built our newest tool in this candid behind-the-scenes by Security Research Engineer David Bors: pentest-tools.com/blog/how-and

#offensivesecurity #penetrationtesting #kubernetessecurity

Career Swamicareerswami
2024-08-17

How to ace a Kubernetes Administrator Interview in 2024: Key Concepts, Practical Skills, and Expert Tips

zurl.co/ohRX

2024-08-06

Adversary Village at DEFCON 32 Workshop,
Julien Terriac (Adversary Simulation Engineer at datadog) will be giving a workshop on, “Hands-on Kubernetes security with KubeHound(Purple Teaming)”.
Workshop schedule: 12:00-14:00 PDT, Aug 10th 2024 at Adversary Village Workshop Stage, Las Vegas Convention Center.
More information on the Workshop: adversaryvillage.org/adversary

Schedule for Adversary Village at DEF CON 32: adversaryvillage.org/adversary
Join our Discord server: adversaryvillage.org/discord

#AdversaryVillage #DEFCON #WeEngage #DEFCON32 #AdversaryTactics #adversaryemulation #Kubernetessecurity #purpleteaming #Kubehound

Tedi Heriyantotedi@infosec.exchange
2024-07-12

A Guide To Kubernetes Logs That Isn't A Vendor Pitch: grahamhelton.com/blog/k8slogs/?

#KubernetesSecurity #kubernetes_monitoring

Tedi Heriyantotedi@infosec.exchange
2024-05-04

Kubenomicon, this site serves as a wiki and reference for Kubernetes attacks and detection opportunities, and it's mapped across MITRE ATT&CK: kubenomicon.com/Kubenomicon.ht

#KubernetesSecurity #mitreattack #threatdetection

Tedi Heriyantotedi@infosec.exchange
2024-02-27

Mastering Kubernetes security: Safeguarding your container kingdom: redcanary.com/blog/kubernetes-

#KubernetesSecurity

2023-12-22

Does anyone have good links for where I can learn a bit more about egress proxies? Particularly for Kubernetes?

Use-case: I need to request a lot of potentially large media from servers outside of my control (one's that exist on the fediverse), and I'd like to do this as safely as possible, without exposing anything internal to my network/cluster.

#DevOps #SRE #kubernetes #KubernetesSecurity #DevSecOps

Tedi Heriyantotedi@infosec.exchange
2023-11-30

Appsecco published a two-part blog series on vulnerabilities they usually identify during Kubernetes Penetration Tests:

- A Pentester’s Approach to Kubernetes Security — Part 1: blog.appsecco.com/a-pentesters

- A Pentester’s Approach to Kubernetes Security — Part 2: blog.appsecco.com/a-pentesters

#kubernetes #KubernetesSecurity

Tedi Heriyantotedi@infosec.exchange
2023-09-17

How to Protect Yourself From the New Kubernetes Attacks in 2023: walks through four attacks targeting Kubernetes (Dero and Monero crypto miners, Scarleteel, RBAC-Buster), and security mitigations to prevent them.

ksoc.com/blog/how-to-protect-y

#kubernetes #KubernetesSecurity

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst