Vulnerabilities and Misconfigurations in Cloud-Native Security - Two Sides of the Same Risk Coin
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore the interconnected risks of vulnerabilities and misconfigurations in cloud-native environments during this 46-minute Linux Foundation webinar. Delve into the evolving attack surface created by DevOps and cloud-native technologies, examining how open-source packages, infrastructure as code, container images, and delivery pipelines form complex interdependencies. Learn about software supply chain attacks that leverage infrastructure misconfigurations and known vulnerabilities, using the Log4j flaw as a case study. Gain insights into the necessity of a proactive, defense-in-depth approach to cloud-native security and discover strategies for comprehensive protection across entire cloud-native application stacks, from code to cloud and application to infrastructure. Topics covered include open source challenges, vulnerability databases, software composition analysis, sources of vulnerabilities, and practical examples to illustrate key concepts.
Syllabus
Introduction
Open Source Challenges
Why Open Source
Vulnerability Databases
Open Source Licenses
Early Detection
Software Composition Analysis
Context
Culture
Safety Security
Checkouts Gun
Log4J Example
Sources of Vulnerabilities
Checkoff
Summary
Taught by
Linux Foundation
Tags
Related Courses
Building on Microsoft Sentinel PlatformMicrosoft via YouTube Securing Applications and Infrastructure on Kubernetes with Sysdig
Mirantis via YouTube Container Escape in 2021
Hack In The Box Security Conference via YouTube Running at Light Speed - Cloud Native Security Patterns
LASCON via YouTube Controlled Mayhem With Cloud Native Security Pipelines
OWASP Foundation via YouTube