Human error and misconfigurations primary source of Kubernetes security snafus, report says

cloudcomputing-news.net | February 21, 2020

StackRox, a provider of cloud-native, container and Kubernetes security, warned in its previous report that the security implications for Kubernetes were beginning to spill over to adoption – and the release of its updated winter study have proved the company right.The paper, the winter edition of its State of Container and Kubernetes Security Report, was put together alongside 451 Research and polled more than 500 industry professionals.94% of those polled said they had experienced security incidents in their container environments during the previous 12 months. As is frequently the case with other cloud security snafus, human error – in this case misconfigured containers – can be found as a root cause, a trend which StackRox said was ‘alarmingly common.More than two thirds (69%) of those polled said they had experienced a misconfiguration incident; just over a quarter (27%) found a security incident during runtime, with a similar number (24%0 having a major vulnerability to remediate.
86% of respondents said they were running containerised applications in Kubernetes the same number as in the spring survey. However, the way Kubernetes is being used is changing rapidly, as more organisations put trust in the hyperscalers managing their workloads. Just over a third (35%) of respondents said they manage Kubernetes directly today – down from 44% six months ago – with more respondents (37%) using Amazon EKS. More than one in five (21%) say they use Azure AKS and Google GKE, with both representing a significant increase from spring.In a similar theme, maturation is increasing in terms of cloud-only environments. While hybrid deployments remain more popular 46% compared to 40% for cloud-only it represented a big drop from the 53% who cited it six months ago. For cloud-only, organisations remain predominantly trusting a single cloud, although multi-cloud deployments are becoming more popular.

Spotlight

You know need to make data useful and readily accessible for business users. You know you need to make your data work for you with agility, flexibility. and scale. But how do you start? Start with Cloud Analytics Automations for Dummies This eBook is the perfect starting point for building a solid foundation for future data anal


Other News
Cloud App Management

Google Cloud Teams Up with StackPath to Expand Edge-Forward Cloud

StackPath | September 20, 2023

StackPath Edge Compute is now accessible via the Google Cloud Marketplace, allowing Google Cloud customers to expand their environment to the internet's edge. StackPath, a leading edge computing platform, has made its Edge Compute Virtual Machines and Containers available on the marketplace, with purchases counting towards users' committed Google Cloud expenditure. StackPath offers cloud computing instances at edge points of presence within 38 major global markets, ensuring proximity to data sources and destinations. This proximity enhances application distribution options. Tom Reyes, Chief Product Officer for StackPath, emphasized the synergy between edge and cloud computing, highlighting the cost and performance benefits of utilizing Google Cloud for latency-neutral workloads and StackPath for latency-sensitive tasks. Dai Vu, Managing Director at Google Cloud, reportedly stated, As a part of their digital transformation strategies, many enterprises are seeking solutions that help them optimize their workflows. With its solutions now available on Google Cloud Marketplace, StackPath is enabling companies of all types and sizes to achieve the speed, security, and efficiency they require. [Source: PR Newswire] Additionally, StackPath recently added support for Virtual Kubelet in StackPath Edge Compute, facilitating seamless integration of StackPath Edge Compute Containers into multi-cloud Kubernetes (K8s) clusters. K8s, born on Google Cloud, remain popular among Google Cloud users. Key features of StackPath Edge Compute include deploying VMs with certified Linux distributions, image capture for autoscaling and rollbacks, deploying compliant container images, and rapid provisioning in StackPath Edge locations. About StackPath StackPath is an edge cloud platform offering cloud services in close proximity to end users compared to core cloud providers. Its edge compute solutions, including virtual machines and containers, along with edge applications such as CDN and WAF, are strategically positioned in densely populated areas. These services are connected through a secure private network fabric and managed through a single system. Clients, ranging from Fortune 50 enterprises to startups, rely on StackPath to optimize the performance, security, and efficiency of their latency-sensitive workloads and applications. Headquartered in Dallas, TX, StackPath was founded in 2015 and specializes in SECaaS, CDN, WAF, and various other cloud-related services.

Read More

Cloud App Development

CloudBees Launches Groundbreaking Cloud-Native DevSecOps Platform

Business Wire | September 15, 2023

On September 14, 2023, CloudBees, a leading enterprise software delivery platform, introduces a groundbreaking cloud-native DevSecOps platform that prioritizes platform engineers and developer experiences. The platform, built on Tekton, employs a domain-specific language akin to GitHub Actions and incorporates feature flagging, security, compliance, pipeline orchestration, analytics, and value stream management (VSM) into a fully managed single-tenant SaaS, multi-tenant SaaS, or on-premise virtual private cloud instance. A spokesperson for CloudBees stated that the revolutionary platform was the market's most open and extensible DevSecOps solution, capable of orchestrating any tool in the software development toolkit. They added that it redefined DevSecOps by addressing the challenges of delivering secure, compliant, cloud-native software faster than ever. Meeting the Challenges of Cloud-Native Development As the rush towards cloud-native application development continues, software development and delivery teams grapple with the complexities of modern cloud-native architectures. This has led to the emergence of platform engineering as an evolution of DevOps practices. Platform engineering unites various roles such as site reliability engineers (SREs), DevOps engineers, security teams, product managers, and operations teams with the shared goal of integrating all organizations’ disparate technologies and tools into a streamlined path for developers. The CloudBees platform is purpose-built for this mission. The CloudBees Platform: Speed and Security The CloudBees platform empowers organizations to simplify complex cloud-native development and deployment processes across all DevOps tools, thereby accelerating innovation. It ensures a seamless journey from code development to successful deployment with a focus on: 1. Developer-centric experience: Enhancing developer experience by minimizing cognitive load and making DevOps processes nearly invisible through blocks, automations, and golden paths. 2. Open and extensible: Embracing the DevOps ecosystem, starting with Jenkins, and offering flexibility to orchestrate any other tool, protecting existing tooling investments. 3. Self-service model: Allowing platform engineers to customize the platform, providing autonomy for development teams. Developers can focus on innovation without waiting for automation or resources. 4. Security and compliance: Centralizing security and compliance with out-of-the-box workflow templates containing built-in security measures. Automated DevSecOps is integrated, incorporating checks across source code, binaries, cloud environments, data, and identity. Michel Lopez, founder and CEO at E2F, noted that the CloudBees platform had significantly reduced the time required for their ISO 27001 compliance audit, from 12 hours to just 60 minutes. He also mentioned that the CloudBees platform provided all controls. Shawn Ahmed, Chief Product Officer at CloudBees, emphasized, Our new platform empowers developers, unifies teams, and accelerates innovation while offering unprecedented flexibility and choice. [Source: Businesswire] The CloudBees platform promises to enhance developer experiences, streamline processes, and prioritize security, offering organizations a powerful tool to navigate the complexities of modern cloud-native architectures and accelerate innovation. About CloudBees CloudBees, headquartered in San Jose, California, has been a software development leader since 2010. The company thrives in an innovation-driven industry by addressing the need for balancing development freedom and regulatory governance through its pioneering end-to-end automated software delivery system. Its robust Software as a Service (SaaS) platform encompasses DevOps, Continuous Integration, Continuous Delivery, and more, ensuring secure and compliant innovation.

Read More

Cloud Security

Orca Security Simplifies Cloud Asset Discovery with AI Technology

Orca Security | September 14, 2023

Orca Security, a leader in agentless cloud security, has unveiled a groundbreaking AI-driven cloud asset search feature within its Orca Cloud Security Platform. This innovation positions Orca as the first provider to offer an AI-powered cloud asset search that's as simple as asking a question. This development empowers not only security professionals but also developers, DevOps teams, cloud architects, and risk governance and compliance teams to swiftly and effortlessly gain insights into their cloud environments. Building upon its existing integrations with ChatGPT and Microsoft Azure OpenAI GPT-4 for generating remediation instructions, Orca's new AI-driven search functionality revolutionizes accessibility by enabling users to pose natural language queries like, ‘Do I have any Log4j vulnerabilities exposed to the public?’ or ‘Are there any unencrypted databases with sensitive data accessible on the internet?’ This democratizes cloud security, making it accessible to individuals across the organization, regardless of their expertise, to rapidly respond to zero-day risks, optimize cloud assets, and assess exposure to threats. Gil Geron, CEO and co-founder of Orca Security, emphasized the platform's user friendliness, stating, With our latest AI-powered cloud asset search, we are delivering on our promise to provide cloud security that is easy to operate. We built the industry’s first agentless cloud security platform to eliminate lengthy and labor-intensive deployments. Now we are focused on democratizing cloud security by introducing solutions that do not require reading through lengthy documentation or extensive training to operationalize, allowing security teams, developers, and DevOps teams to get value from day one. [Source: Business wire] Cloud asset discovery is a critical process involving the identification, categorization, and mapping of all digital assets within a cloud environment. This includes virtual machines, databases, storage instances, containers, networking components, and applications. Yet many organizations lack access to this vital information. Orca's patented SideScanning technology offers 100% visibility for asset discovery and is now presenting this data intuitively to various teams across organizations, enabling a comprehensive understanding of their cloud environments. This capability is particularly crucial during zero-day threats, where speed is essential, facilitating faster and more effective mitigations. Orca's solution also eliminates the need for users to understand different naming conventions for each cloud provider. Instead, users can ask general questions, and Orca will automatically search for the relevant status names for each provider, streamlining the search process and ensuring accurate results. The AI-powered cloud asset search feature is immediately available through a feature request in the Orca Cloud Security Platform. About Orca Security Orca Security is a leading provider of cloud security solutions that offer full-stack visibility of the complete cloud infrastructure. It provides deep insights into vulnerabilities, malware, misconfigurations, and more across various platforms, including AWS, Azure, Google Cloud, Alibaba Cloud, and Kubernetes. The platform is designed to provide complete visibility of the entire cloud estate, from development to production, without requiring an agent. The company is known for innovative SideScanning technology that delivers instant-on, workload-level security.

Read More

Cloud Infrastructure Management

CoreWeave and VAST Data Join Forces to Build the Data Foundation for a Next Generation Public Cloud with NVIDIA AI

GlobeNewswire | September 27, 2023

VAST Data, the AI data platform company and CoreWeave, a specialized cloud provider powering many of the world’s leading generative AI efforts, today announced a strategic partnership that will further CoreWeave’s mission to deliver highly scalable and performant cloud infrastructure for AI and accelerated compute workloads. CoreWeave has selected the VAST Data Platform, the world’s first data platform designed for the AI era, to build a global, NVIDIA-powered accelerated computing cloud for deploying, managing and securing hundreds of petabytes of data for generative AI, high performance computing (HPC) and visual effects (VFX) workloads. CoreWeave did extensive research and testing before selecting VAST Data to power all of its data centers. The VAST Data Platform has the necessary scale, performance, and multi-tenant enterprise AI cloud capabilities required to power the massive AI and LLM training and inference applications that are now transforming everything from business, to science, to society itself. CoreWeave’s customers demand the most secure and scalable solutions on top of the industry’s fastest and most flexible infrastructure to keep their data safe," said Michael Intrator, CEO and co-founder of CoreWeave. We’re delighted to partner with VAST Data to deliver a multi-tenant and zero-trust environment purpose-built for accelerated compute use cases like machine learning, VFX and rendering, Pixel Streaming and batch processing that’s up to 35 times faster and 80 percent less expensive than legacy cloud providers. This partnership is rooted in a deep technical collaboration that will push the boundaries of data-driven accelerated computing to deliver the world’s most optimized AI cloud platform. Through their joint partnership CoreWeave and VAST Data are leveraging NVIDIA technology to engineer a new data platform architecture for large-scale, end-to-end data pipelines and deliver next-generation data services for AI workloads. To support this, the VAST Data Platform boasts an enterprise network attached data store that is certified for use with NVIDIA DGX SuperPOD and eliminates tiers and infrastructure silos to make large scale AI simpler, faster and easier to manage at virtually limitless levels of scale and performance. “Since our earliest days, VAST Data has had a single vision of building an architecture that could power the needs of the most demanding cloud-scale AI applications," said Renen Hallak, Founder and CEO of VAST Data. "We could not imagine a better cloud platform to realize this vision than what we’re creating with CoreWeave. We are humbled and honored to partner with the CoreWeave team to push the boundaries of modern AI computing and to build the infrastructure that will serve as the foundation of tomorrow’s AI-powered discoveries.” About VAST Data VAST Data is the data platform software company for the AI era. Accelerating time-to-insight for workload-intensive applications, the VAST data platform delivers scalable performance, radically simple data management and enhanced productivity. Launched in 2019, VAST is the fastest-growing data infrastructure company in history. For more information, please visit https://vastdata.com and follow VAST Data on Twitter and LinkedIn. About CoreWeave Founded in 2017, CoreWeave is a specialized cloud provider, delivering a massive scale of GPU compute resources on top of the industry's fastest and most flexible infrastructure. CoreWeave builds cloud solutions for compute-intensive use cases — machine learning and AI, VFX and rendering, life sciences, the Metaverse, and real-time streaming — that are up to 35 times faster and 80% less expensive than the large, generalized public clouds. Learn more at www.coreweave.com.

Read More

Spotlight

You know need to make data useful and readily accessible for business users. You know you need to make your data work for you with agility, flexibility. and scale. But how do you start? Start with Cloud Analytics Automations for Dummies This eBook is the perfect starting point for building a solid foundation for future data anal

Resources