InfoQ Homepage Security Content on InfoQ
-
Enchant Your AI and APIs with eBPF Magic 🪄
Dan Finneran explains how to use eBPF and AI gateways in Kubernetes to transparently observe, modify, and control unowned AI agent API calls without altering source code.
-
Adopting Memory-Safety and Fine-Grained Compartmentalisation with CHERI
David Chisnall explains how CHERI architecture unifies hardware capabilities and pointer metadata to deliver memory safety and fine-grained, efficient software compartmentalization.
-
Leveraging Adversary Emulation for GenAI Red Teaming
Kennedy Torkura explains how to apply GenAI red teaming to secure AWS Bedrock models and knowledge bases, leveraging MITRE ATLAS to discover cloud supply chain vulnerabilities.
-
Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation
Celine Pypaert explains the shift from reactive firefighting to proactive risk management by identifying vulnerabilities, utilizing SCA tools, and defining ownership within the software supply chain.
-
Are We Ready for the Next Cyber Security Crisis Like Log4shell?
Soroosh Khodami shares a "horror story" on supply chain attacks. He explains how one Maven or npm command can gift hackers a reverse shell and shares critical strategies like SBOMs to defend teams.
-
Security and Architecture: to Betray One is to Destroy Both
Shana Dacres-Lawrence discusses the "betrayals" between security and architecture. She explains how delivery pressure and assumed trust lead to failures and shares five strategies for a lasting union.
-
Panel: Security against Modern Threats
The panelists discuss the challenges in securing the software supply chain against modern threats.
-
Busting AI Myths and Embracing Realities in Privacy & Security
Katharine Jarmul keynotes on common myths around privacy and security in AI and explores what the realities are, covering design patterns that help build more secure, more private AI systems.
-
Platforms for Secure API Connectivity with Architecture as Code
Jim Gough explains how "Architecture as Code" and the CALM model bridge the gap between developers and infrastructure, sharing patterns to automate security reviews and accelerate API deployment.
-
Securing AI Assistants: Strategies and Practices for Protecting Data
Andra Lezza reviews the OWASP Top 10 for LLMs and contrasts security controls for independent vs. integrated copilot architectures.
-
Trust No One: Securing the Modern Software Supply Chain with Zero Trust
Emma Yuan Fang discusses how to apply Zero Trust principles to secure the software supply chain and CI/CD pipeline, detailing mitigation for major attacks like SolarWinds and dependency confusion.
-
The Way We Manage Compliance is Wrong… and is Changing! Bringing DevOps Principles to Controls and Audit
Ian Miell shares the open-source Continuous Compliance Framework, discussing how to revolutionize audits. He explains shifting from periodic checks to continuous monitoring with DevOps and OSCAL.