Five Kubernetes Security Gaps Attackers Chain Together

Kubernetes security testing checks whether a cluster's controls hold up under an attacker's logic, not just whether they exist on paper. There are five misconfiguration categories our testers find most often. 1) RBAC gaps granting too much access. 2) Exposed control-plane components. 3) Missing network policies. 4) Unsafe pod defaults. 5) Weak admission control. Pentesters …

KEDA audit by 7ASecurity

7ASecurity shares results of a KEDA security audit: 15 security-impact findings (4 high), 5 hardening recommendations, SLSA supply-chain review, and future security guidance.

LinkerD Security Audit by 7ASecurity

7ASecurity is proud to share the results of a recent security audit of Linkerd. Linkerd is an open source service mesh for Kubernetes which prioritizes reliability, security, and simplicity. Thanks to the help of the Open Source Technology Improvement Fund (OSTIF) and the Cloud Native Computing Foundation, this project can continue to provide a lightweight …