DevSecOps in Kubernetes
The talk is about how to or how to not implement cloud native projects in highly regulated environments.
24.5.2024
Muhammad Ihsan Haikal Sukmana
2 min

Table of Contents
Contributors
Muhammad Ihsan Haikal Sukmana
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
The talk is about how to or how not to implement cloud-native projects in highly regulated environments. You will get some insights into real-world projects where Kubernetes is used to run the latest applications and control critical infrastructure in Germany and Europe.The examples include container gardening and how to convince developers to deliver minimal and compliant containers, onboarding security team members to get the Sec into DevOps, running CI/CD pipelines with 3rd party vendors, air-gapped cloud-native architectures, and running clusters with the highest availability.
Watch the talk here.
Andere interessante Blogbeiträge lesen
Blog ansehen

Cloud Sicherheit
Die gängigsten Cloud-Angriffstechniken verständlich erklärt
March 22, 2025
Red Canary hat kürzlich den Threat Detection Report 2025 veröffentlicht. Dieser Artikel beleuchtet die im Bericht genannten, am häufigsten auftretenden Cloud-Angriffstechniken und bietet weiterführende Einblicke sowie praktische Gegenmaßnahmen für
Mehr lesen
Cloud-Sicherheit, Cloud-Angriffsemulation, AWS-Sicherheit, Azure-Sicherheit

Cloud Sicherheit
LLMJacking-Angriffe auf Amazon Bedrock verstehen
October 13, 2024
LLMJacking-Angriffe zielen zunehmend auf GenAI-Workloads in Amazon Bedrock ab. Bei diesen Angriffen verschaffen sich Cyberkriminelle unbefugten Zugriff auf Large Language Models und verkaufen diesen Zugang gewinnbringend über Chatbots weiter.
Mehr lesen
Security für GenAI, AWS Security, Cloud-Sicherheit

Cloud Sicherheit
AgentCore or AgentSore: Cross-Agent Privilege Escalation in Bedrock AgentCore
June 22, 2026
Bedrock AgentCore starter toolkit ships an overly permissive IAM role that attackers exploit to compromise critical AgentCore components. This article discusses practical exploitation of these weaknesses, detection opportunities & countermeasures.
Mehr lesen
Cloud Attack Emulation, AI Security, Cloud Security, AI Red Teaming

Cloud Sicherheit
Effective Red Teaming in the Agentic Era: Amazon Bedrock (Part I)
May 17, 2026
AI Red Teaming plays a central role in AI quality of service, ensuring end users are not harmed or frustrated by malicious output. This article provides practical AI Red Teaming guidance for Amazon Bedrock.
Mehr lesen
AI Red Teaming, Red Teaming, Cloud Security, AWS Security

Cloud Sicherheit
Feature Release: Cloud Penetration Testing with Prowler and Wiz Integrations
April 10, 2026
Mitigant Cloud Pentests now integrate with Prowler and Wiz, enabling seamless validation of CSPM findings through real, safe attack execution that surfaces SCP-aware privilege-escalation paths, fully visualized and mapped to compliance benchmarks.
Mehr lesen
cloud security,cloud attack emulation, cloud penetration testing

Cloud Sicherheit
The Best of Mitigant Blog Articles in 2025
January 8, 2026
This article highlights our top blog articles in 2025, from AI security to Cloud Attack Emulation, including research referenced in Splunk's Security Analytics Story and pioneering Adversarial Exposure Validation.
Mehr lesen
cloud security, cloud attack emulation,

Cloud Sicherheit
Mitigant Threat Catalog: 61 Techniques & 12 AWS Services Added
March 18, 2026
Mitigant Threat Catalog massive update! We added 61 techniques & 12 AWS services, totalling 91 techniques across 32 AWS services. The catalog now includes techniques across 11 MITRE ATT&CK tactics.
Mehr lesen
adversary emulation, cloud security, red team, purple team
.png)
Cloud Sicherheit
Mitigant Attack Builder: Custom Cloud Attacks in Seconds
November 21, 2025
Mitigant Attack Builder empowers defenders to build cloud attacks within seconds, enabling production-ready security tests without sacrificing time and quality.
Mehr lesen
Mitigant Attack Builder: Custom Cloud Attacks in Seconds

Cloud Sicherheit
Cloud Attack Emulation 101: Shallow Waters
October 23, 2025
In Part I of this series, we explored why adopting the adversary mindset matters. In this second part, we explore how cloud attack emulation works, examine fundamental attack building blocks, and outline how to evolve an effective security strategy.
Mehr lesen
cloud attack emulation, AWS Security, Cloud Security

Cloud Sicherheit
Ultimative Kombination: Cloud-Angriffsemulation trifft auf Microsoft Sentinel
August 4, 2025
Dieser Artikel befasst sich mit der starken Synergie zwischen Microsoft Sentinel und Mitigant Cloud Attack Emulation.Zusammen bilden diese Cloud-nativen Sicherheitsprodukte eine ultimative Kombination, die proaktive Erkennung und Reaktion ermöglicht.
Mehr lesen
Cloud Attack Emulation, Azure Security, Threat Detection, Security Operations

Cloud Sicherheit
Feature Release: Multi-Cloud Attack Emulation
July 25, 2025
We are excited to announce several features recently added to the Mitigant Cloud Security Platform. Multi-cloud attack emulation is a key feature, enabling seamless orchestration of attacks across AWS and Azure.
Mehr lesen
cloud attack emulation, cloud security, adversary emulation, kubernetes security, azure security, aws security

Cloud Sicherheit
Cloud Attack Emulation 101: Getting Started
June 9, 2025
This blog post provides foundational information on leveraging Cloud Attack Emulation for security effectiveness by adopting the attacker's mindset and playing the devil's advocate to detect security flaws and blind spots.
Mehr lesen
cloud attack emulation, cloud security, adversary emulation

Cloud Sicherheit
Feature Release: Adversary Emulation Meets GenAI & More
August 1, 2024
We are excited to release powerful features to the Mitigant Security Platform: Attack Emulation for AWS GenAI services, Mitigant API, and support for AWS Organizations. These features empower organizations to use GenAI cloud services securely.
Mehr lesen
GenAI, Adversary Emulation, Attack Emulation, AWS Security, Cloud Security, Cyber Resilience

Cloud Sicherheit
Bedrock or Bedsand: Attacking Amazon Bedrock’s Achilles Heel
July 10, 2024
Amazon Bedrock's Achilles heel is the adoption of S3 as a RAG data source, leading to several GenAI attack vectors, including data poisoning, denial of service & S3 ransomware. This article delves into these attack vectors, detection, and mitigation.
Mehr lesen
cloud security, aws security, cloud attack emulation, GenAI security

Cloud Sicherheit
Emulating and Detecting Scattered Spider-like Attacks
July 23, 2024
This article shows how to leverage Threat-Informed Defense to effectively tackle cloud threat actors, e.g., Scattered Spider. Practical attacks & appropriate defense are demonstrated using Mitigant Cloud Attack Emulation & the Sekoia SOC Platform.
Mehr lesen
cloud attack emulation, threat detection, adversary emulation, AWS Security
.webp)
Cloud Sicherheit
Cloud Attack Emulation: Democratizing Security Operations in the Cloud
July 2, 2024
Security operations are the nerve of organizational cybersecurity efforts. An organization’s security policy typically aims to keep it safe by implementing preventive, detective, and recovery measures. Security operations ensure this ambition by s...
Mehr lesen
cloud-security, cloud-attack-emulation, aws-security
Übernehmen Sie die Kontrolle über Ihre Cloud-Sicherheitslage
Übernehmen Sie in wenigen Minuten die Kontrolle über Ihre Cloud-Sicherheit. Keine Kreditkarte erforderlich.


















