Search results for: kubernetes


HelpNetSecurity: "Kubernetes security matures: Inside the project’s first audit"

Posted on August 12, 2019

Auditing 1.5 million lines of code is a heroic undertaking. With resources provided by the Cloud Native Computing Foundation (CNCF), the Kubernetes Project leadership created the Security Audit Working Group to perform an audit in an open, transparent,…


Security Boulevard: "CNCF-led open source Kubernetes security audit reveals 37 flaws in Kubernetes cluster; recommendations proposed"

Posted on August 9, 2019

Last year, the Cloud Native Computing Foundation (CNCF) initiated a process of conducting third-party security audits for its own projects. The aim of these security audits was to improve the overall security of the CNCF ecosystem.


EnterpriseAI: "Kubernetes gets a security audit"

Posted on August 9, 2019

An open source group is expanding its third-party security audits to include the popular but vulnerable Kubernetes cluster orchestrator.


ZDNet: "Kubernetes reports the results of its open-source security audit"

Posted on August 8, 2019

All programs need security audits, but the Cloud Native Computing Foundation (CNCF) took a new open-source approach and revealed all to its users.


SDxCentral: "Kubernetes looks inside and finds security holes"

Posted on August 7, 2019

The Kubernetes ecosystem took a look in the security mirror and found it has some work to do in order to ensure a better security posture for the container orchestration platform. The move comes as a rash of…


The New Stack: "CNCF open sources security audit of core Kubernetes components"

Posted on August 6, 2019

This week, the Cloud Native Computing Foundation (CNCF) has released the final results of a two-month-long, third-party security audit of eight core Kubernetes components, uncovering a variety of vulnerabilities.


Open sourcing the Kubernetes security audit

Posted on August 6, 2019 | By Chris Aniszczyk

Last year, the Cloud Native Computing Foundation (CNCF) began the process of performing and open sourcing third-party security audits for its projects in order to improve the overall security of our ecosystem. The idea was to start with…


SiliconANGLE: "Security audit reveals 34 vulnerabilities in Kubernetes code"

Posted on August 6, 2019

An audit released today by the Cloud Native Computing Foundation has uncovered no fewer than 34 vulnerabilities in the code for Kubernetes, the highly popular open-source container orchestration system.


The Register: "Captain, we've detected a disturbance in space-time. It's coming from Earth. Someone audited the Kubernetes source"

Posted on August 6, 2019

The CNCF engaged two security firms, Trail of Bits and Atredis Partners, to poke around Kubernetes code over the course of four months. The companies looked at Kubernetes components involved in networking, cryptography, authentication, authorization, secrets management, and…


Container Journal: "CNCF completes Kubernetes cybersecurity audit"

Posted on August 6, 2019

The Cloud Native Computing Foundation (CNCF) this week announced the results of its recent audit performed as part of its ongoing commitment to continuously improve Kubernetes security.