Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jkaftzan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
MongoDB CVE CVE-2025-14847 – what K8s users should know?
(armosec.io)
2 points
by
jkaftzan
9mo ago
|
1 comments
2.
▲
by
jkaftzan
9mo ago
A newly disclosed MongoDB vulnerability, tracked as CVE-2025-14847 and informally referred to as MongoBleed, allows unauthenticated remote attackers to leak uninitialized memory from a MongoDB server. A public proof-of-concept exploit is al
3.
▲
by
jkaftzan
3y ago
CVE-2023-5043, CVE-2023-5044 and CVE-2022-4886 can be exploited by attacker to steal secret credentials from K8s cluster. Three security issues were reported on October 27th by the Kubernetes security community, all of them related to the p
4.
▲
Three new Nginx ingress controller vulnerabilities and the affect on Kubernetes
(armosec.io)
5 points
by
jkaftzan
3y ago
|
1 comments
5.
▲
Kubernetes Validating Admission Policies: A Practical Example
(kubernetes.io)
1 points
by
jkaftzan
3y ago
|
0 comments
6.
▲
by
jkaftzan
4y ago
Try Kubescape
7.
▲
by
jkaftzan
4y ago
Here you go https://github.com/kubescape/kubescape
8.
▲
by
jkaftzan
4y ago
Cool! Happy you like it!
9.
▲
by
jkaftzan
4y ago
Kubescape, an end-to-end open-source Kubernetes security platform, embarks on a new journey. Kubescape, created by ARMO, will fully migrate to the CNCF. This coincides with the launch of ARMO Platform, a hosted, managed security solution po
10.
▲
CNCF accepts Kubescape as its first security and compliance scanner project
(sdxcentral.com)
27 points
by
jkaftzan
4y ago
|
16 comments
11.
▲
by
jkaftzan
4y ago
CVE-2022-47633: Kyverno’s container image signature verification can be bypassed by a malicious registry or proxy
12.
▲
by
jkaftzan
4y ago
All the main K8s vulnerabilities from 2022 consolidated into one article. Put together by Ben Hirschberg, founder of ARMO, the makers of Kubescape.
13.
▲
by
jkaftzan
4y ago
Check this new survey on the state of OSS K8s security
14.
▲
by
jkaftzan
4y ago
Grafana Labs published a security advisory for a new critical vulnerability in its open-source product. The vulnerability, marked as CVE-2022-39328, enables attackers to bypass authorization on arbitrary service endpoints.
15.
▲
by
jkaftzan
4y ago
ARMO have open sourced yet another important component – Kubescape operator. This operator can be installed in-cluster using Helm, and is responsible, for the continuous configurations and image vulnerability scanning, among other nifty cap
16.
▲
Kubescape operator is now open source as well
(github.com)
3 points
by
jkaftzan
4y ago
|
1 comments
17.
▲
by
jkaftzan
4y ago
Kubescape, an open source K8s security solution, is celebration one year anniversary. now all the major components of Kubescape are open source
18.
▲
Ask HN: How do you scan K8s in offline mode (e.g. air-gapped environment)?
2 points
by
jkaftzan
5y ago
|
1 comments
19.
▲
Kubernetes ingress-nginx controller vulnerability
(armosec.io)
51 points
by
jkaftzan
5y ago
|
47 comments
20.
▲
by
jkaftzan
5y ago
to check Kubescape: https://github.com/armosec/kubescape
21.
▲
Show HN: How to download and run Kubescape [video]
(vimeo.com)
2 points
by
jkaftzan
5y ago
|
1 comments
22.
▲
New and expanded version of Kubescape is released
2 points
by
jkaftzan
5y ago
|
0 comments
23.
▲
by
jkaftzan
5y ago
Do you scan your K8s YAML files for misconfigurations? if not you should...and with Kubescape it's easy and free
24.
▲
by
jkaftzan
5y ago
There are so many different Frameworks to use when it comes to Kubernetes security and compliance - CIS, NIST, NSA&CISA, PCI. which one is good for you? and why? in this article i'm trying to cover the main frameworks in the market
25.
▲
by
jkaftzan
5y ago
well, this is probably the reason why the adoption rate of K8s is so high? and why so many organizations are using it or going to use it as their "operating system" of cloud native environments?
26.
▲
by
jkaftzan
5y ago
A new HIGH severity vulnerability was found in Kubernetes in which users may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. The issue is af
27.
▲
Kubernetes new high severity vulnerability CVE-2021-25741 – are you exposed?
(armosec.io)
3 points
by
jkaftzan
5y ago
|
3 comments
28.
▲
by
jkaftzan
5y ago
You have probably heard of Kubernetes role-based access control (RBAC). In this article, Amir Kashaunsky, ARMO VP Product, will walk you through this method so that in the end, you will be able to determine whether RBAC is something you nee
29.
▲
by
jkaftzan
5y ago
check this article by -Lachlan Evenson https://medium.com/@LachlanEvenson/kubernetes-hardening-usin... You can also run Kubescape against Kubernetes manifests which is a great way to stop violations before the resource
30.
▲
by
jkaftzan
5y ago
We are continuing to work on Kubescape and enhance it with more features and capabilities: Kubescape can now check that YAML files and HELM charts are configured correctly as defined by NSA and CISA guidance. No cluster is required and you
More ›