I had an amazing time at #CNSCon this week! I learned so much and talked with so many interesting people!
Here is a brief recap of some of my highlights
https://buff.ly/4cGrio0
Elevating Cloud Security: Highlights from CloudNativeSecurityCon 2024

Explore insights from CloudNativeSecurityCon 2024, including securing machine identities, digesting SLSA and GUAC, and the impact of quality documentation.

GitGuardian Blog - Code Security for the DevOps generation
#CNSCon comes to a close with an extremely fun, colorful, and engaging session:
The Story of Crush: The Microservice That Navigated the Cloud Native Ocean with a SPIFFE Identity from Mattias Gees of Venafi & Tom Meadows from Testifysec
#CNSCon continues into the afternoon of day 2 with
IAM Confused: Decoding 8 Real World Cloud Identity Breaches from Maya Levine of Sysdig
A very informative talk at #CNSCon
"Guardians of the Dataverse: Securing the AI Supply and Data Chain" from Frederick Kautz of TestifySec
A food-filled session post lunch at #CNSCon:
"A Mouthful of Mayhem: Taste Test and Gut Response to SLSA, GUAC, and Supply Chain’s Plat Du Jour" from Shane Lawrence from Shopify

#CNSCon continues with
"How to Generate VEX Automatically for Your Project" from Shlomo Heigh of CyberArk & Ben Hirschberg of ARMO

"Vulnerability in image is NOT equal to an application exploit"

Amplifying Impact: Documentation and Supply Chain Security
from Michelle Irvine from the DORA team at Google Cloud at #CNSCon

"Security drives an organization's performance"

Final keynote at #CNSCon
"We’re VEXing the Cloud Native Landscape. Bring Your Code!" from Adolfo García Veytia, Staff Software Engineer at Stacklok

At #CNSCon we got the pleasure of seeing A Vision for a Secure Software Supply Chain from Dr. Marina Moore from New York University

Attackers know that attacking dependencies means they can reach more victims, much more effectively.

Sugar Ray.io on K8s: Shut the Door, Baby! from Google's Greg Castle & Cynthia Thomas
At #CNSCon