Magno Logan
7 articles
-
ResearchEnhancing Software Supply-Chain Security: Navigating SLSA Standards and the MITRE ATT&CK Framework
Attackers abuse different supply-chain scenarios to indirectly compromise organizations and applications. We delve into how a software pipeline works, where attacks could come from, and how to improve security.
January 31st, 2024 6 minMagno Logan
Read article -
ResearchUnderstanding the Kubernetes Security Triad: Image Scanning, Admission Controllers, and Runtime Security
Kubernetes, also known as K8s, is a very complex open-source platform that requires detailed attention to security. Despite previous efforts to increase its security, Kubernetes remains insecure by default and requires different security tools to protect the cluster.
November 21st, 2023 12 minMagno Logan
Read article -
ResearchA Deep Dive Into Kubernetes Threat Modeling
This report explores the aspects and considerations required to properly perform threat modeling within a Kubernetes environment, a piece of technology that many organizations worldwide rely on and a leading container orchestration platform.
October 31st, 2023 12 minMagno Logan
Read article -
ResearchThe State of Ransomware: 2020’s Catch-22
Ransomware continues the trend of targeted attacks but with the added challenge of double extortion. Organizations need to be one step ahead of such coercive tactics to avoid potential disruptions, financial losses, and reputational damage.
February 3rd, 2021 17 minMagno Logan, Erika Mendoza, Ryan Maglaque, Nikko Tamaña
Read article -
ResearchA Look at Linux: Threats, Risks, and Recommendations
This article aims to discuss the Linux threat landscape and examine how Linux has become an attractive target for attackers, as well as how it can be prone to a variety of threats and risks.
January 26th, 2021 14 minMagno Logan, Pawan Kinger
Read article -
ResearchThe Basics of Keeping Kubernetes Clusters Secure
With Kubernetes’ popularity and high adoption rates, its security should always be prioritized. We provide vital tips and recommendations on keeping the master node, the API server, etcd, RBAC, and network policies secure.
October 14th, 2020 11 minMagno Logan
Read article -
ResearchSecuring the 4 Cs of Cloud-Native Systems: Cloud, Cluster, Container, and Code
Cloud-native security adopts the defense-in-depth approach and divides the security strategies utilized in cloud-native systems into four different layers: cloud, container, cluster, code.
May 27th, 2020 12 minMagno Logan
Read article