InfoQ Homepage Security Content on InfoQ
-
GenAI Security: Defending Against Deepfakes and Automated Social Engineering
In this episode, QCon AI New York 2025 Chair Wes Reisz speaks with Reken CEO and Google Trust & Safety founder Shuman Ghosemajumder about the erosion of digital trust. They explore how deepfakes and automated social engineering are scaling cybercrime and argues defenders must move beyond default trust, utilizing behavioral telemetry and game theory to counter attacks that simulate human behavior.
-
Cloud Security Challenges in the AI Era - How Running Containers and Inference Weaken Your System
Marina Moore, a security researcher and the co-chair of the security and compliance TAG of CNCF, shares her concerns about the security vulnerabilities of containers. She explains where the issues originate, providing solutions and discussing alternative routes to using micro-VMs rather than containers. Additionally, she highlights the risks associated with AI inference.
-
The Hidden Vulnerability of the Open Source Software Supply Chain: the Underlying Infrastructure
Software supply chain veteran Brian Fox unpacks the security implications of the new EU Cyber Resilience Act and its profound impact on open-source projects. He reveals the hidden infrastructure risks threatening open-source projects and shares insights for senior software leaders navigating this regulatory landscape.
-
Is WebAssembly the Secure, Efficient Alternative Everybody was Waiting for?
Laurent Doguin and Geoffroy Couprie discuss their pioneering work with Wasm on the infrastructure side. They walk us through the benefits and challenges of building a platform over WebAssembly and why it’s the safer alternative to containers.
-
Implement the EU Cyber Resilience Act's Requirements to Strengthen Your Software Project
Eddie Knight, OSPO lead at Sonatype, discusses how the EU Cyber Resilience Act can help with improving your software project’s security and in the same time to slow down the alarming acceleration of software supply chain attacks.
-
Vulnerabilities and Risks in the Software Supply Chain
Shane Hastie spoke to Brian Fox of Sonatype about vulnerabilities and risks inherent in the modern software supply chain and how to overcome them.
-
The Challenges of DevOps and the Importance of Developer Experience with Jyoti Bansal
In this podcast, Shane Hastie spoke to Jyoti Bansal about the challenges of DevOps today and the importance of developer experience for effective software development today.
-
Nishant Bhajaria on Security, Privacy and Ethics
In this podcast Shane Hastie, lead editor for culture & methods, spoke to Nishant Bhajaria about security, data privacy, ethics and privacy by design .
-
Derek Weeks on the 2020 DevSecOps Community Survey Results
In this podcast Shane Hastie, Lead Editor for Culture & Methods, spoke to Derek Weeks of Sonatype about the results of the 2020 DevSecOps Community Survey and the All Day DevOps conference.
-
Chris Matts & Tony Grout on IT Risk Management Framework as a Catalyst for Change
In this podcast Shane Hastie, Lead Editor for Culture & Methods, talks to Tony Grout and Chris Matts about building an IT risk management framework at a large bank and using that as a catalyst for a digital transformation.