The increasing reliance on open-source software coupled with the accelerated pace of software development has created a growing need for support of deprecated packages. The significant majority of open-source software packages are not actively maintained, meaning vulnerabilities are not patched, thereby leaving systems open to attack. Malicious actors often target deprecated open-source packages for this very reason.
The standout themes at KubeCon + CloudNativeCon Europe 2025 in London strongly centered on how identity is rapidly becoming the linchpin for securing cloud-native infrastructure. The recurring theme I saw wasn’t just Kubernetes innovation—it was the rising urgency of securing the who behind every action across platforms, clusters, services, and tools.
In this video, I put OpenAI's latest model, ChatGPT-4.1, to the test to see if it can generate secure code. Can AI really help us write safer, bug-free applications? Or does it still fall into common security pitfalls like SQL injection, XSS, and insecure auth flows? Stay tuned to find out!
Kubernetes 1.33 marks another exciting milestone in the evolution of this widely adopted container orchestration platform. A big shoutout to the release team for their hard work and contributions! In this update, Kubernetes continues to enhance its capabilities to meet the ever-evolving demands of modern cloud-native environments. Let’s take a closer look at the key security improvements and other features that caught our attention.
Need to recover individual files from a Kubernetes Persistent Volume Claim (PVC)? In this demo, CloudCasa Field CTO Martin Fon walks you through file-level restore from PVC using CloudCasa’s intuitive user interface. No need to modify backup jobs—just point, click, and restore files or folders directly to your original or alternate cluster. Key highlights: • Explore PVC contents from your backup Whether you're dealing with accidental file deletion or need selective recovery for compliance, CloudCasa makes granular file recovery from Kubernetes backups simple and powerful.
With DHS ending MITRE’s CVE funding, the future of global vulnerability tracking is uncertain. Here’s what it means for security teams and what comes next.
AI security threats are evolving at roughly the same speed that AI itself is: extremely fast. One of the most recent—and least understood—vulnerabilities involves vector and embedding weaknesses. These issues have gained attention with their addition to the OWASP Top 10 for LLMs, and the risks are becoming more urgent as Retrieval-Augmented Generation (RAG) continues to dominate enterprise AI adoption.
As many of you may know, MITRE’s DHS contract to manage the CVE and CWE programs expired on April 16, 2025. While emergency funding has since been restored for a short time, the long-term future of these programs still remains uncertain. Understandably, this situation has raised concerns throughout the cybersecurity community about the stability and continuity of vulnerability tracking and management systems that many organizations have come to rely upon.