InfoQ Homepage Security Content on InfoQ
-
Andres Almiray on How to Release Any Software to Any OS with JReleaser
Andres Almiray, a serial open-source contributor and the creator of JReleaser, discusses the project's state, noting that the tool is usable across any ecosystem, not just Java. He also touches on the Common House Foundation's mission.
-
Startup Software Architecture - You Never Really Throw it Away: a Conversation with David Gudeman
In this podcast, Michael Stiefel spoke with David Gudeman about software architecture for startups. The discussion starts by illuminating how to make decisions with imperfect information, and how uncertainty and ambiguity flow through all aspects of developing the architecture. This leads to analyzing how the architect must focus on both product strategy and technical decisions.
-
GenAI Security: Defending Against Deepfakes and Automated Social Engineering
In this episode, QCon AI New York 2025 Chair Wes Reisz speaks with Reken CEO and Google Trust & Safety founder Shuman Ghosemajumder about the erosion of digital trust. They explore how deepfakes and automated social engineering are scaling cybercrime and argues defenders must move beyond default trust, utilizing behavioral telemetry and game theory to counter attacks that simulate human behavior.
-
Cloud Security Challenges in the AI Era - How Running Containers and Inference Weaken Your System
Marina Moore, a security researcher and the co-chair of the security and compliance TAG of CNCF, shares her concerns about the security vulnerabilities of containers. She explains where the issues originate, providing solutions and discussing alternative routes to using micro-VMs rather than containers. Additionally, she highlights the risks associated with AI inference.
-
The Hidden Vulnerability of the Open Source Software Supply Chain: the Underlying Infrastructure
Software supply chain veteran Brian Fox unpacks the security implications of the new EU Cyber Resilience Act and its profound impact on open-source projects. He reveals the hidden infrastructure risks threatening open-source projects and shares insights for senior software leaders navigating this regulatory landscape.
-
Vulnerabilities and Risks in the Software Supply Chain
Shane Hastie spoke to Brian Fox of Sonatype about vulnerabilities and risks inherent in the modern software supply chain and how to overcome them.
-
The Challenges of DevOps and the Importance of Developer Experience with Jyoti Bansal
In this podcast, Shane Hastie spoke to Jyoti Bansal about the challenges of DevOps today and the importance of developer experience for effective software development today.
-
Nishant Bhajaria on Security, Privacy and Ethics
In this podcast Shane Hastie, lead editor for culture & methods, spoke to Nishant Bhajaria about security, data privacy, ethics and privacy by design .
-
Derek Weeks on the 2020 DevSecOps Community Survey Results
In this podcast Shane Hastie, Lead Editor for Culture & Methods, spoke to Derek Weeks of Sonatype about the results of the 2020 DevSecOps Community Survey and the All Day DevOps conference.
-
Chris Matts & Tony Grout on IT Risk Management Framework as a Catalyst for Change
In this podcast Shane Hastie, Lead Editor for Culture & Methods, talks to Tony Grout and Chris Matts about building an IT risk management framework at a large bank and using that as a catalyst for a digital transformation.