<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ControlPlane</title><link>https://control-plane.io/posts/</link><description>ControlPlane</description><language>en-uk</language><copyright>© 2026 ControlPlane</copyright><lastBuildDate>Tue, 26 May 2026 00:00:00</lastBuildDate><atom:link href="https://control-plane.io/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>The Post Quantum Radar</title><link>https://control-plane.io/posts/the-post-quantum-radar/</link><pubDate>Tue, 26 May 2026</pubDate><guid>https://control-plane.io/posts/the-post-quantum-radar/</guid><description>Keeping track of PQC availability</description></item><item><title>Tampered Tokenizers: An AI Supply Chain Meltdown</title><link>https://control-plane.io/posts/tampered-tokenizers-an-ai-supply-chain-meltdown/</link><pubDate>Fri, 22 May 2026</pubDate><guid>https://control-plane.io/posts/tampered-tokenizers-an-ai-supply-chain-meltdown/</guid><description>The tokenizer attack that existing scanners can&amp;rsquo;t catch, and the supply chain tooling that can.</description></item><item><title>Validating Zero Trust: Network Policy Testing with Flux CD and Netassert</title><link>https://control-plane.io/posts/validating-zero-trust/</link><pubDate>Fri, 15 May 2026</pubDate><guid>https://control-plane.io/posts/validating-zero-trust/</guid><description>GitOps revolutionised how we deliver applications, enabling faster deployments and managing infrastructure with targeted declarative precision. However, this precision doesn’t extend to securing dynamic environments and remains incredibly difficult.
Consider a historical three-tier application architecture: a frontend web service, backend API, and data store. The engineer’s accountability ended when the application code was pushed to version control, and automation carried it to production (that developers may not be permitted to access).</description></item><item><title>The End of Safe Software? No, It's Not.</title><link>https://control-plane.io/posts/the-end-of-safe-software/</link><pubDate>Tue, 05 May 2026</pubDate><guid>https://control-plane.io/posts/the-end-of-safe-software/</guid><description>In the wake of Anthropic’s announcement of Mythos and Project Glasswing, and with the still-emerging blast radius of Aqua Security’s Trivy compromise, many security professionals are predicting the end of safe software.
We do not agree.
Instead, they simply highlight and reinforce:
Security standards are rising, and proactivity breeds assurance Security basics are more important than ever Open source is resilient The Attack Chains that Matter What does this mythical LLM and an open source project’s compromise have to do with each other?</description></item><item><title>Defusing CanisterWorm: How Bun and Deno Secure the JavaScript Supply Chain</title><link>https://control-plane.io/posts/defusing-canisterworm-bun-deno-supply-chain/</link><pubDate>Thu, 30 Apr 2026</pubDate><guid>https://control-plane.io/posts/defusing-canisterworm-bun-deno-supply-chain/</guid><description>TeamPCP&amp;rsquo;s CanisterWorm is exploiting npm&amp;rsquo;s postinstall hooks. Learn how modern JavaScript runtimes like Bun and Deno neutralise this threat by default.</description></item><item><title>How LLMs Are Ending The Attacker-Defender Stalemate (And What to Do About It)</title><link>https://control-plane.io/posts/llms-ending-attacker-defender-stalemate/</link><pubDate>Tue, 28 Apr 2026</pubDate><guid>https://control-plane.io/posts/llms-ending-attacker-defender-stalemate/</guid><description>Frontier Large Language Models (LLMs) are reshaping how software is built, attacked, and secured. Their impact is most visible in code generation and vulnerability discovery, where they reduce the time and expertise required to produce outputs that previously demanded specialist knowledge. As organisations rush to adopt AI tools into development and operations, a practical question arises: in a world where AI can autonomously write exploits and generate patches, what is the role of human-driven security?</description></item><item><title>The Vercel Breach: When Roblox Cheats, AI Tools, and Poor Secrets Management Collide</title><link>https://control-plane.io/posts/vercel-breach-roblox-secrets-management/</link><pubDate>Tue, 21 Apr 2026</pubDate><guid>https://control-plane.io/posts/vercel-breach-roblox-secrets-management/</guid><description>The recent breach at Vercel is a textbook example of how modern supply-chain compromises unfold, starting with a Roblox cheat script.</description></item><item><title>ControlPlane Enterprise for OpenBao - Meet the Team</title><link>https://control-plane.io/posts/openbao-meet-the-team/</link><pubDate>Tue, 07 Apr 2026</pubDate><guid>https://control-plane.io/posts/openbao-meet-the-team/</guid><description>Meet the team behind the new ControlPlane Enterprise for OpenBao</description></item><item><title>sandbox-probe: Putting AI sandboxing to the test</title><link>https://control-plane.io/posts/sandbox-probe-release/</link><pubDate>Mon, 23 Mar 2026</pubDate><guid>https://control-plane.io/posts/sandbox-probe-release/</guid><description>Announcing ControlPlane&amp;rsquo;s sandbox-probe: testing the limits of AI Agent Sandboxes</description></item><item><title>Why We Are Throwing Our Weight Behind OpenBao</title><link>https://control-plane.io/posts/why-we-support-openbao/</link><pubDate>Fri, 20 Mar 2026</pubDate><guid>https://control-plane.io/posts/why-we-support-openbao/</guid><description>We are expanding our open source commitment to include OpenBao. Here is why we believe in true digital sovereignty, meeting market demand, and providing sustainable support for the maintainers of critical security projects.</description></item><item><title>ControlPlane Launches Enterprise Support For OpenBao To Strengthen Secrets Security</title><link>https://control-plane.io/posts/controlplane-enterprise-for-openbao-launch/</link><pubDate>Thu, 12 Mar 2026</pubDate><guid>https://control-plane.io/posts/controlplane-enterprise-for-openbao-launch/</guid><description>Announcing the launch of a new offering designed to help organizations securely adopt and operate the OpenBao secrets management platform.</description></item><item><title>Out on the GenAI Wild West: Part II - The Long Arm of the Law</title><link>https://control-plane.io/posts/ai-red-teaming-wild-west-part-2/</link><pubDate>Tue, 03 Mar 2026</pubDate><guid>https://control-plane.io/posts/ai-red-teaming-wild-west-part-2/</guid><description>As AI agents execute workflows and access sensitive systems, organizations must shift from model safety to architectural controls, continuous testing, and framework-aligned governance.</description></item><item><title>Check Point and ControlPlane Partner to Help Enterprises Securely Scale AI and Accelerate Agentic Innovation</title><link>https://control-plane.io/posts/check-point-partnership/</link><pubDate>Tue, 24 Feb 2026</pubDate><guid>https://control-plane.io/posts/check-point-partnership/</guid><description>The partnership delivers a comprehensive, regulator-ready security framework to enable organizations to move confidently from AI experimentation to production deployment.</description></item><item><title>Open Source Security Risks: Countering the Threat</title><link>https://control-plane.io/posts/sc-magazine-open-source-security-risks/</link><pubDate>Thu, 19 Feb 2026</pubDate><guid>https://control-plane.io/posts/sc-magazine-open-source-security-risks/</guid><description>Open source supply chain attacks are on the rise. What can businesses do to protect themselves?</description></item><item><title>FluxCon Atlanta Was Just the Start</title><link>https://control-plane.io/posts/fluxcon-in-2026/</link><pubDate>Tue, 17 Feb 2026</pubDate><guid>https://control-plane.io/posts/fluxcon-in-2026/</guid><description>Reflecting on eight years of Flux deployment, two years of Enterprise and a watershed moment.</description></item><item><title>Making TDD Work for You, Part 2: crossing TDD's tribal lines</title><link>https://control-plane.io/posts/make-tdd-work-for-you-p2/</link><pubDate>Tue, 26 Aug 2025</pubDate><guid>https://control-plane.io/posts/make-tdd-work-for-you-p2/</guid><description>Second and final part of a series about how to make TDD work for you.</description></item><item><title>Out on the GenAI Wild West: Part I - Red Team Redemption</title><link>https://control-plane.io/posts/ai-red-teaming-wild-west-part-1/</link><pubDate>Fri, 15 Aug 2025</pubDate><guid>https://control-plane.io/posts/ai-red-teaming-wild-west-part-1/</guid><description>Multi-turn agentic adversarial testing uncovers vulnerabilities in foundational models, highlighting the need for adaptive defenses, model-specific strategies, and continuous evaluation to secure GenAI</description></item><item><title>Penetration Testing and Purple Teaming: Essential for Financial Services Security</title><link>https://control-plane.io/posts/pentesting-purple-teaming-financial-services/</link><pubDate>Tue, 05 Aug 2025</pubDate><guid>https://control-plane.io/posts/pentesting-purple-teaming-financial-services/</guid><description>The financial services sector is increasingly targeted by cybercriminals, with cyberattacks leading to significant financial losses and reputational damage. Penetration testing and purple teaming are two security testing methodologies essential in enhancing cybersecurity posture and readiness. In this article, we will explore the importance of penetration testing and purple teaming in protecting financial services institutions against ever-evolving threats.
The Impact of Cybercrime on Financial Services Financial institutions are enticing targets for cybercriminals due to the potential for direct financial gain and access to vast amounts of valuable data.</description></item><item><title>Trust Issues: Navigating Open Source and Software Supply Chain Risk</title><link>https://control-plane.io/posts/trust-issues-navigating-open-source-and-software-supply-chain-risk/</link><pubDate>Thu, 24 Jul 2025</pubDate><guid>https://control-plane.io/posts/trust-issues-navigating-open-source-and-software-supply-chain-risk/</guid><description>A two-part journey through the lens of large banks, regulated industries, and security consultancies</description></item><item><title>The Quantum Leap: Navigating PQC Adoption in Today's Digital Infrastructure</title><link>https://control-plane.io/posts/the-quantum-leap-navigating-pqc-adoption-in-todays-digital-infrastructure/</link><pubDate>Fri, 18 Jul 2025</pubDate><guid>https://control-plane.io/posts/the-quantum-leap-navigating-pqc-adoption-in-todays-digital-infrastructure/</guid><description>Key insights on PQC adoption in today&amp;rsquo;s digital infrastructure</description></item><item><title>DevSecOps is the New DevOps</title><link>https://control-plane.io/posts/devsecops-is-the-new-devops/</link><pubDate>Fri, 04 Jul 2025</pubDate><guid>https://control-plane.io/posts/devsecops-is-the-new-devops/</guid><description>A look at transforming to DevSecOps from a technical and cultural perspective, including a deeper look some supply-chain considerations.</description></item><item><title>Making TDD Work for You, Part 1: When to Invest and Essential Practices</title><link>https://control-plane.io/posts/make-tdd-work-for-you-p1/</link><pubDate>Tue, 10 Jun 2025</pubDate><guid>https://control-plane.io/posts/make-tdd-work-for-you-p1/</guid><description>First part of a series about how to make TDD work for you.</description></item><item><title>Improve your OPA policies user-based with Gatekeeper</title><link>https://control-plane.io/posts/gatekeeper-opa-policies-user-based/</link><pubDate>Wed, 28 May 2025</pubDate><guid>https://control-plane.io/posts/gatekeeper-opa-policies-user-based/</guid><description>For Open Policy Agent (OPA), most of the policies that are written are based on Kubernetes resources. For example, the deployment of Pods should be avoided with the tag latest. But sometimes it is necessary to write more fine-grained OPA policies based on Kubernetes users, groups or service accounts. Let me give you an example so that the code and explanations can be better understood.
Example of a use case Imagine you have a Jenkins job that creates Namespaces for tenants.</description></item><item><title>Beyond Compliance: Strategic Cyber Resilience in Financial Services Under the EU’s CRA</title><link>https://control-plane.io/posts/beyond-compliance-strategic-cyber-resilience-in-financial-services-under-the-eus-cra/</link><pubDate>Thu, 08 May 2025</pubDate><guid>https://control-plane.io/posts/beyond-compliance-strategic-cyber-resilience-in-financial-services-under-the-eus-cra/</guid><description>The EU’s Cyber Resilience Act (CRA) isn’t just another regulatory hurdle; it’s a fundamental shift in how we approach digital security.</description></item><item><title>Back to the Future: Next-Generation Cloud Native Security - A talk by Andrew Martin &amp; Matt Jarvis</title><link>https://control-plane.io/posts/back-to-the-future/</link><pubDate>Thu, 01 May 2025</pubDate><guid>https://control-plane.io/posts/back-to-the-future/</guid><description>In this talk, Andrew Martin and Matt Jarvis explored the history of cloud-native computing, examined the current security landscape, and shared their predictions for the decade ahead.</description></item><item><title>Kubernetes and the UK</title><link>https://control-plane.io/posts/kubernetes-and-the-uk/</link><pubDate>Fri, 11 Apr 2025</pubDate><guid>https://control-plane.io/posts/kubernetes-and-the-uk/</guid><description>Kubernetes marked its 10th anniversary last year, and the CNCF commemorates a decade of remarkable success this year.</description></item><item><title>ControlPlane at KubeCon EU London ‘25 - Recap</title><link>https://control-plane.io/posts/kubecon-eu-25-recap/</link><pubDate>Thu, 10 Apr 2025</pubDate><guid>https://control-plane.io/posts/kubecon-eu-25-recap/</guid><description>A recap of ControlPlane&amp;rsquo;s activities at KubeCon EU in London</description></item><item><title>Flux D2 Reference Architecture – Gitless GitOps for Secure Multi-Tenancy</title><link>https://control-plane.io/posts/d2-reference-architecture-guide/</link><pubDate>Thu, 03 Apr 2025</pubDate><guid>https://control-plane.io/posts/d2-reference-architecture-guide/</guid><description>Introducing Gitless GitOps and the Flux Operator for secure, scalable multi-tenant Kubernetes environments.</description></item><item><title>ControlPlane is Heading to KubeCon EU '25 London</title><link>https://control-plane.io/posts/controlplane-at-kubecon-eu-2025/</link><pubDate>Tue, 25 Mar 2025</pubDate><guid>https://control-plane.io/posts/controlplane-at-kubecon-eu-2025/</guid><description>ControlPlane&amp;rsquo;s events and CTF at KubeCon EU in London</description></item><item><title>Ephemeral Environments for GitLab Merge Requests with Flux Operator</title><link>https://control-plane.io/posts/ephemeral-environments-for-gitlab-merge-requests/</link><pubDate>Mon, 17 Mar 2025</pubDate><guid>https://control-plane.io/posts/ephemeral-environments-for-gitlab-merge-requests/</guid><description>Flux Operator creates ephemeral environments for GitLab MRs. Each MR gets an automatic, dedicated preview instance for faster validation and iteration.</description></item><item><title>See it, Hack It, Sort It: How Open Source Software Protects Our AI Enablers</title><link>https://control-plane.io/posts/see-it-hack-it-sort-it-how-open-source-software-protects-our-ai-enablers/</link><pubDate>Mon, 24 Feb 2025</pubDate><guid>https://control-plane.io/posts/see-it-hack-it-sort-it-how-open-source-software-protects-our-ai-enablers/</guid><description>Protecting GPU resources in cloud infrastructure: threat modeling, attack vectors, and practical security measures using open source tools.</description></item><item><title>What is Continuous Delivery &amp; How Does It Work?</title><link>https://control-plane.io/posts/what-is-continuous-delivery-and-how-does-it-work/</link><pubDate>Wed, 12 Feb 2025</pubDate><guid>https://control-plane.io/posts/what-is-continuous-delivery-and-how-does-it-work/</guid><description>An exploration of what Continuous Delivery is, how it differs from related concepts, and how Flux can help.</description></item><item><title>Securing Kubernetes Clusters: Lessons and Best Practices from the Field</title><link>https://control-plane.io/posts/securing-kubernetes-clusters/</link><pubDate>Thu, 06 Feb 2025</pubDate><guid>https://control-plane.io/posts/securing-kubernetes-clusters/</guid><description>Key lessons from ControlPlane&amp;rsquo;s KubeCon EU 2023 talk, covering Kubernetes threat modelling, attack techniques, and essential security measures to protect clusters.</description></item><item><title>Celebrating a Year of Commitment to CNCF Flux: Sustainability, Innovation, and Growth</title><link>https://control-plane.io/posts/celebrating-1-year-of-commitment-to-cncf-flux/</link><pubDate>Fri, 24 Jan 2025</pubDate><guid>https://control-plane.io/posts/celebrating-1-year-of-commitment-to-cncf-flux/</guid><description>ControlPlane supported CNCF Flux over the past year by enabling ongoing development, innovation, and community engagement.</description></item><item><title>What is Flux CD</title><link>https://control-plane.io/posts/what-is-fluxcd/</link><pubDate>Fri, 24 Jan 2025</pubDate><guid>https://control-plane.io/posts/what-is-fluxcd/</guid><description>Flux is an open source tool used to keep Kubernetes clusters in sync with configuration artefacts, especially when that configuration needs to change regularly, like when you update your software or a dependent part of your system receives a patch.
Flux has been built from the ground up to use native Kubernetes APIs and to integrate with the wider Kubernetes ecosystem tools like Prometheus. It supports multi-tenancy clusters and scales massively with support for syncing multiple Git Repositories or other sources of configuration artefacts.</description></item><item><title>Streamlining Application Delivery with Flux and the Generic Helm Chart Pattern</title><link>https://control-plane.io/posts/flux-and-the-generic-helm-chart-pattern/</link><pubDate>Wed, 15 Jan 2025</pubDate><guid>https://control-plane.io/posts/flux-and-the-generic-helm-chart-pattern/</guid><description>Based on the excellent technical article written by Flux Core Maintainer and fellow ControlPlaner Stefan Prodan.</description></item><item><title>What is GitOps</title><link>https://control-plane.io/posts/what-is-gitops/</link><pubDate>Fri, 13 Dec 2024</pubDate><guid>https://control-plane.io/posts/what-is-gitops/</guid><description>This is the first in a series of articles about Flux CD, and introduces the foundational knowledge of GitOps.
GitOps is a term coined by Weaveworks in 2018. It has been referred to as the best thing since Infrastructure as Code, and has also been referred to as being versioned CI/CD on top of declarative infrastructure.
Much like how DevOps broke down the silos between Developers and Operations/Infrastructure Teams, GitOps merges the concerns for application deployment with infrastructure deployment.</description></item><item><title>Unlocking Delivery Success: Overcoming Framework Limitations in Regulated Environments</title><link>https://control-plane.io/posts/unlocking-delivery-success-overcoming-framework-limitations-in-regulated-environments/</link><pubDate>Tue, 10 Dec 2024</pubDate><guid>https://control-plane.io/posts/unlocking-delivery-success-overcoming-framework-limitations-in-regulated-environments/</guid><description>ControlPlane pioneers delivery success by blending Agile adaptability with Waterfall structure to overcome regulatory challenges and drive efficiency.</description></item><item><title>Automated Cloud Native Incident Response with Kubernetes and Service Mesh</title><link>https://control-plane.io/posts/automated-cloud-native-incident-response/</link><pubDate>Tue, 19 Nov 2024</pubDate><guid>https://control-plane.io/posts/automated-cloud-native-incident-response/</guid><description>ControlPlane is a proud member of and long-term contributor to the Fintech Open Source Foundation (FINOS), and almost a third of our firm’s consultants contribute to initiatives like the AI Readiness SIG, Common Cloud Controls, and Compliant Financial Infrastructure.</description></item><item><title>Open Source in Finance Forum New York 2024 Recap</title><link>https://control-plane.io/posts/the-evolution-of-open-source-and-cloud-native-in-fsis/</link><pubDate>Tue, 12 Nov 2024</pubDate><guid>https://control-plane.io/posts/the-evolution-of-open-source-and-cloud-native-in-fsis/</guid><description>ControlPlane is a proud member of and long-term contributor to the Fintech Open Source Foundation (FINOS), and almost a third of our firm’s consultants contribute to initiatives like the AI Readiness SIG, Common Cloud Controls, and Compliant Financial Infrastructure.</description></item><item><title>The Path to Zero CVEs: Vanquishing Cyber Threats</title><link>https://control-plane.io/posts/the-path-to-zero-cves-vanquishing-cyber-threats/</link><pubDate>Mon, 11 Nov 2024</pubDate><guid>https://control-plane.io/posts/the-path-to-zero-cves-vanquishing-cyber-threats/</guid><description>Addressing Common Vulnerabilities and Exposures (CVEs) is no longer optional—aiming to eliminate them is a critical priority for securing modern systems.</description></item><item><title>Enterprise for Flux CD Now Available on AWS Marketplace</title><link>https://control-plane.io/posts/enterprise-for-flux-cd-on-aws-marketplace/</link><pubDate>Wed, 06 Nov 2024</pubDate><guid>https://control-plane.io/posts/enterprise-for-flux-cd-on-aws-marketplace/</guid><description>Our products and services are now available through our partnership with AWS</description></item><item><title>ControlPlane at KubeCon NA '24 Salt Lake City</title><link>https://control-plane.io/posts/controlplane-at-kubecon-na-2024/</link><pubDate>Fri, 01 Nov 2024</pubDate><guid>https://control-plane.io/posts/controlplane-at-kubecon-na-2024/</guid><description>ControlPlane&amp;rsquo;s events and CTF at KubeCon NA in Salt Lake City</description></item><item><title>The Landscape Podcast: Flux with Core Maintainer Stefan Prodan</title><link>https://control-plane.io/posts/flux-in-modern-devops/</link><pubDate>Tue, 22 Oct 2024</pubDate><guid>https://control-plane.io/posts/flux-in-modern-devops/</guid><description>Stefan Prodan, core maintainer of Flux, discusses its role in automating Kubernetes with GitOps, enhancing security, and scaling infrastructure management</description></item><item><title>Introducing the Flux Operator - GitOps on Autopilot Mode</title><link>https://control-plane.io/posts/flux-operator-introduction/</link><pubDate>Mon, 14 Oct 2024</pubDate><guid>https://control-plane.io/posts/flux-operator-introduction/</guid><description>Stefan Prodan, core maintainer of the CNCF Flux project, introduces the Flux Operator.</description></item><item><title>ControlPlane Outreach: Exposing At-Risk Students to Careers in Tech</title><link>https://control-plane.io/posts/controlplane-outreach-exposing-at-risk-students-to-careers-in-tech/</link><pubDate>Mon, 07 Oct 2024</pubDate><guid>https://control-plane.io/posts/controlplane-outreach-exposing-at-risk-students-to-careers-in-tech/</guid><description>ControlPlane partnered with Spark! to empower at-risk students through workshops that introduced them to tech careers, continuous learning, and future possibilities.</description></item><item><title>Future Open Source LLM Killchains! A Talk by Vicente Herrera</title><link>https://control-plane.io/posts/future-open-source-llm-killchains-a-talk-by-vicente-herrera/</link><pubDate>Fri, 04 Oct 2024</pubDate><guid>https://control-plane.io/posts/future-open-source-llm-killchains-a-talk-by-vicente-herrera/</guid><description>In The Security Ai Summit 2024, Principal Consultant Vicente Herrera explores how advanced adversaries could exploit vulnerabilities in the open-source AI ecosystem, particularly in large language models (LLMs), by targeting MLOps infrastructure, with a focus on mitigation strategies to prevent such attacks.</description></item><item><title>FINOS AI Readiness Open Sourced</title><link>https://control-plane.io/posts/finos-ai-readiness-open-sourced/</link><pubDate>Tue, 01 Oct 2024</pubDate><guid>https://control-plane.io/posts/finos-ai-readiness-open-sourced/</guid><description>ControlPlane&amp;rsquo;s pivotal role in the FINOS AI Governance Framework highlights our commitment to advancing AI readiness in financial services.</description></item><item><title>Smarter Than Your Average SBOM! A Talk by Matt Jarvis &amp; Andrew Martin</title><link>https://control-plane.io/posts/smarter-than-your-average-sbom-a-talk-by-matt-jarvis-andrew-martin/</link><pubDate>Mon, 02 Sep 2024</pubDate><guid>https://control-plane.io/posts/smarter-than-your-average-sbom-a-talk-by-matt-jarvis-andrew-martin/</guid><description>In Kubernetes Community Day UK 2023 Snyk, Director Matt Jarvis and ControlPlane CEO Andrew Martin teamed up and deeply delved into the Software Bill of Materials (SBOMs) world</description></item><item><title>FINOS AI Governance Framework</title><link>https://control-plane.io/posts/cnsc-secure-ai-summit-finos/</link><pubDate>Wed, 14 Aug 2024</pubDate><guid>https://control-plane.io/posts/cnsc-secure-ai-summit-finos/</guid><description>At the Secure AI Summit earlier this year, ControlPlane’s Torin van den Bulk delivered an eye-opening talk on the &amp;lsquo;Invisible infiltration of AI supply chains by adversarial actors&amp;rsquo;. This talk examines the importance of securing the data, models, and pipelines involved at each step of an AI supply chain.</description></item><item><title>ControlPlane at the Bleeding Edge: Ending the Pain of Periods</title><link>https://control-plane.io/posts/controlplane-at-the-bleeding-edge-ending-the-pain-of-periods/</link><pubDate>Mon, 12 Aug 2024</pubDate><guid>https://control-plane.io/posts/controlplane-at-the-bleeding-edge-ending-the-pain-of-periods/</guid><description>The ControlPlane Agile team is proudly taking steps toward breaking down awkwardness, stigma, and workplace barriers to menstrual health.</description></item><item><title>I'll Let Myself In: Kubernetes Privilege Escalation Tactics</title><link>https://control-plane.io/posts/ill-let-myself-in-kubernetes-privilege-escalation-tactics/</link><pubDate>Wed, 24 Jul 2024</pubDate><guid>https://control-plane.io/posts/ill-let-myself-in-kubernetes-privilege-escalation-tactics/</guid><description>ControlPlane&amp;rsquo;s talk at KubeCon Europe 2024 gave attendees an overview of Cloud-Native Penetration Test and privilege escalation tactics to make cloud native systems more secure</description></item><item><title>The Impact of the Polyfill Supply Chain Attack</title><link>https://control-plane.io/posts/the-impact-of-the-polyfill-supply-chain-attack/</link><pubDate>Mon, 08 Jul 2024</pubDate><guid>https://control-plane.io/posts/the-impact-of-the-polyfill-supply-chain-attack/</guid><description>How the Polyfill supply chain attack highlights the issues with trust in open source software and what approaches can be taken to mitigate the risk.</description></item><item><title>Mastering the Cloud Native Wave: Security Resilience in Modern Systems</title><link>https://control-plane.io/posts/mastering-the-cloud-native-wave-security-resilience-in-modern-systems/</link><pubDate>Fri, 28 Jun 2024</pubDate><guid>https://control-plane.io/posts/mastering-the-cloud-native-wave-security-resilience-in-modern-systems/</guid><description>ControlPlane&amp;rsquo;s talk at InfoSec Europe 2024 gave attendees an overview of observations and techniques to make cloud native systems more resilient&amp;quot;</description></item><item><title>Abusing VSCode: From Malicious Extensions to Stolen Credentials (Part 1)</title><link>https://control-plane.io/posts/abusing-vscode-from-malicious-extensions-to-stolen-credentials-part-1/</link><pubDate>Wed, 26 Jun 2024</pubDate><guid>https://control-plane.io/posts/abusing-vscode-from-malicious-extensions-to-stolen-credentials-part-1/</guid><description>Attack paths for remotely compromising Visual Studio Code</description></item><item><title>Abusing VSCode: From Malicious Extensions to Stolen Credentials (Part 2)</title><link>https://control-plane.io/posts/abusing-vscode-from-malicious-extensions-to-stolen-credentials-part-2/</link><pubDate>Wed, 26 Jun 2024</pubDate><guid>https://control-plane.io/posts/abusing-vscode-from-malicious-extensions-to-stolen-credentials-part-2/</guid><description>How malicious VSCode extensions can steal your credentials</description></item><item><title>Open Source Dynamics in the Era of Licence Innovation</title><link>https://control-plane.io/posts/open-source-dynamics-era-licence-innovation/</link><pubDate>Tue, 28 May 2024</pubDate><guid>https://control-plane.io/posts/open-source-dynamics-era-licence-innovation/</guid><description>This blog post explores innovative business models for open source projects, focusing on enterprise support and subscription services, and discusses the balance between community contributions and sustainable growth.</description></item><item><title>How to create a Table Top Exercise for Cyber Incident Responders</title><link>https://control-plane.io/posts/how-to-create-a-table-top-exercise-for-cyber-incident-responders/</link><pubDate>Wed, 15 May 2024</pubDate><guid>https://control-plane.io/posts/how-to-create-a-table-top-exercise-for-cyber-incident-responders/</guid><description>OpenSSF and ControlPlane created, hosted and ran a tabletop exercise for Incident Responders in the format of a panellist discussion. Let’s have a look behind the scenes and uncover tips and tricks how a security team can carry out a similar exercise.</description></item><item><title>Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native Ecosystem</title><link>https://control-plane.io/posts/brewing-the-kubernetes-storm-centre-kceu24/</link><pubDate>Wed, 08 May 2024</pubDate><guid>https://control-plane.io/posts/brewing-the-kubernetes-storm-centre-kceu24/</guid><description>James Callaghan, principal consultant at ControlPlane, and Constanze Roedig discuss open source cloud native threat intelligence at KubeCon + CloudNativeCon Europe 2024</description></item><item><title>Flux CD Architecture Overview</title><link>https://control-plane.io/posts/fluxcd-architecture-overview/</link><pubDate>Thu, 02 May 2024</pubDate><guid>https://control-plane.io/posts/fluxcd-architecture-overview/</guid><description>Stefan Prodan, core maintainer of the CNCF Flux project, provides a comprehensive overview of Flux CD architectures for multi-cluster continuous delivery</description></item><item><title>Isovalent and ControlPlane's Joint Whitepaper</title><link>https://control-plane.io/posts/isovalent-compliance-whitepaper/</link><pubDate>Thu, 25 Apr 2024</pubDate><guid>https://control-plane.io/posts/isovalent-compliance-whitepaper/</guid><description>Engineers, product managers and consultants from both companies explore how Cilium can tackle the challenges of cloud native compliance</description></item><item><title>The Lowdown on Locked Namespaces</title><link>https://control-plane.io/posts/lowdown-on-locked-namespaces-kceu24/</link><pubDate>Mon, 15 Apr 2024</pubDate><guid>https://control-plane.io/posts/lowdown-on-locked-namespaces-kceu24/</guid><description>Marco De Benedictis, senior consultant at ControlPlane, discusses how Kubernetes namespaces have grown from an optional feature to a security boundary at KubeCon + CloudNativeCon Europe 2024</description></item><item><title>Zero Trust Training Courses with the Linux Foundation</title><link>https://control-plane.io/posts/linux-foundation-zero-trust-training/</link><pubDate>Wed, 03 Apr 2024</pubDate><guid>https://control-plane.io/posts/linux-foundation-zero-trust-training/</guid><description>ControlPlane has authored two Zero Trust training courses for the Linux Foundation</description></item><item><title>ControlPlane at KubeCon EU Paris ‘24 - Recap</title><link>https://control-plane.io/posts/kubecon-eu-recap/</link><pubDate>Thu, 28 Mar 2024</pubDate><guid>https://control-plane.io/posts/kubecon-eu-recap/</guid><description>A recap of ControlPlane&amp;rsquo;s activities at KubeCon EU in Paris</description></item><item><title>Flux CD: D1 Reference Architecture</title><link>https://control-plane.io/posts/flux-d1-reference/</link><pubDate>Wed, 27 Mar 2024</pubDate><guid>https://control-plane.io/posts/flux-d1-reference/</guid><description>ControlPlane&amp;rsquo;s commitment to supporting the Flux Project continues, providing a model and a guide for multi-cluster, multi-tenant environments</description></item><item><title>The Envoy Gateway End User Threat Model, in collaboration with the Linux Foundation</title><link>https://control-plane.io/posts/envoy-gateway-threat-model/</link><pubDate>Wed, 27 Mar 2024</pubDate><guid>https://control-plane.io/posts/envoy-gateway-threat-model/</guid><description>ControlPlane has collaborated with the Linux Foundation to threat model Envoy Gateway and generate an End User guide</description></item><item><title>ControlPlane at KubeCon EU '24 Paris</title><link>https://control-plane.io/posts/controlplane-at-kubecon-eu-2024/</link><pubDate>Thu, 14 Mar 2024</pubDate><guid>https://control-plane.io/posts/controlplane-at-kubecon-eu-2024/</guid><description>ControlPlane&amp;rsquo;s talks and events schedule for KubeCon EU in Paris</description></item><item><title>Container Security Basics at Securi-Tay 2024</title><link>https://control-plane.io/posts/container-security-workshop-securitay/</link><pubDate>Mon, 04 Mar 2024</pubDate><guid>https://control-plane.io/posts/container-security-workshop-securitay/</guid><description>ControlPlane&amp;rsquo;s principal consultant, Iain Smart, talks about Container and Kubernetes Security at Abertay Hackers&amp;rsquo; Securi-Tay 2024</description></item><item><title>NIST Special Publication 800-204D calls for GitOps approaches</title><link>https://control-plane.io/posts/nist-special-publication-800-204d-calls-for-gitops-approaches/</link><pubDate>Sun, 03 Mar 2024</pubDate><guid>https://control-plane.io/posts/nist-special-publication-800-204d-calls-for-gitops-approaches/</guid><description>Exploring how NIST&amp;rsquo;s latest publication underscores the necessity of integrating GitOps strategies in software supply chain security within DevSecOps CI/CD pipelines</description></item><item><title>Bringing light to risks lurking in the black boxes of AI models</title><link>https://control-plane.io/posts/bringing-light-to-risks-lurking-in-the-black-boxes-of-ai-models/</link><pubDate>Fri, 16 Feb 2024</pubDate><guid>https://control-plane.io/posts/bringing-light-to-risks-lurking-in-the-black-boxes-of-ai-models/</guid><description>ControlPlane&amp;rsquo;s principal consultant, Vicente Herrera, talks about AI Security at OpenUK&amp;rsquo;s &amp;ldquo;State of Open Con 2024&amp;rdquo;</description></item><item><title>ControlPlane and Scott Logic Collaborate on Scottish Government Identity and Payments Systems</title><link>https://control-plane.io/posts/controlplane-and-scott-logic-collaborate-on-scottish-government-identity-and-payments-systems/</link><pubDate>Thu, 15 Feb 2024</pubDate><guid>https://control-plane.io/posts/controlplane-and-scott-logic-collaborate-on-scottish-government-identity-and-payments-systems/</guid><description>Collaborative efforts between ControlPlane and Scott Logic on the Scottish Government identity and payment systems: security architectures, platform integrations, and project assurance</description></item><item><title>ControlPlane backs the CNCF Flux Project by Employing Maintainers</title><link>https://control-plane.io/posts/controlplane-backs-the-cncf-flux-project-by-employing-maintainers/</link><pubDate>Thu, 15 Feb 2024</pubDate><guid>https://control-plane.io/posts/controlplane-backs-the-cncf-flux-project-by-employing-maintainers/</guid><description>ControlPlane&amp;rsquo;s support for the CNCF Flux project ensures the sustainability and security of critical systems through open source maintenance and innovative enterprise solutions</description></item><item><title>Tangible Value with ControlPlane Enterprise for Flux CD</title><link>https://control-plane.io/posts/tangible-value-with-controlplane-enterprise-for-flux-cd/</link><pubDate>Mon, 12 Feb 2024</pubDate><guid>https://control-plane.io/posts/tangible-value-with-controlplane-enterprise-for-flux-cd/</guid><description>ControlPlane Enterprise elevates Flux CD with enhanced security, support, and compliance, catering to diverse needs in Kubernetes deployments</description></item><item><title>AI Software Development Lifecycle on Kubernetes</title><link>https://control-plane.io/posts/ai-software-development-lifecycle-on-kubernetes/</link><pubDate>Tue, 30 Jan 2024</pubDate><guid>https://control-plane.io/posts/ai-software-development-lifecycle-on-kubernetes/</guid><description>AI software&amp;rsquo;s evolution on Kubernetes: current methodologies, potential future developments, and inherent risks</description></item><item><title>ControlPlane at OpenSSF and Open Source Summit Japan, 2023</title><link>https://control-plane.io/posts/openssf-and-open-source-summit-japan-2023/</link><pubDate>Fri, 26 Jan 2024</pubDate><guid>https://control-plane.io/posts/openssf-and-open-source-summit-japan-2023/</guid><description>ControlPlane&amp;rsquo;s journey to Japan and an overview of some of the talks presented</description></item><item><title>Navigating Cloud Security and Automation with Eficode</title><link>https://control-plane.io/posts/navigating-cloud-security-and-automation-with-eficode/</link><pubDate>Thu, 18 Jan 2024</pubDate><guid>https://control-plane.io/posts/navigating-cloud-security-and-automation-with-eficode/</guid><description>Talking to Eficode about Cloud Native Security Challenges</description></item><item><title>Play the 2023 CNCF CTF Scenarios with the Revamped Simulator</title><link>https://control-plane.io/posts/2023-cncf-ctf-scenarios-and-getting-started/</link><pubDate>Fri, 12 Jan 2024</pubDate><guid>https://control-plane.io/posts/2023-cncf-ctf-scenarios-and-getting-started/</guid><description>The public release of the 2023 CNCF CTF Scenarios is here! In this blog post, we&amp;rsquo;ll walk you through the revamped simulator and how to get started with the challenges.</description></item><item><title>Cloud Native and Kubernetes Security Predictions 2024</title><link>https://control-plane.io/posts/cloud-and-kubernetes-security-predictions-2024/</link><pubDate>Thu, 11 Jan 2024</pubDate><guid>https://control-plane.io/posts/cloud-and-kubernetes-security-predictions-2024/</guid><description>A look into the tumultuous waters of cloud and Kubernetes security in 2024</description></item><item><title>Andrew Martin on "Nerding Out With Viktor" — Security, Penetration Testing, and Threat Modelling</title><link>https://control-plane.io/posts/nerding-out-with-viktor/</link><pubDate>Thu, 04 Jan 2024</pubDate><guid>https://control-plane.io/posts/nerding-out-with-viktor/</guid><description>The inaugral &amp;ldquo;Nerding Out With Viktor&amp;rdquo; podcast with ControlPlane CEO, Andrew Martin</description></item><item><title>Unveiling the Future of CI/CD Security: A Deep Dive into Advanced Practices</title><link>https://control-plane.io/posts/dev-ops-con-munich-2023-workshop/</link><pubDate>Mon, 18 Dec 2023</pubDate><guid>https://control-plane.io/posts/dev-ops-con-munich-2023-workshop/</guid><description>The “Advanced CI/CD Security” workshop we ran at DevOpsCon 2023 in Munich provided a deep dive into the latest practices shaping the future of cloud security</description></item><item><title>Conference Recap: ControlPlane at KubeCon NA '23 Chicago</title><link>https://control-plane.io/posts/recap-cp-at-kcna-2023/</link><pubDate>Mon, 27 Nov 2023</pubDate><guid>https://control-plane.io/posts/recap-cp-at-kcna-2023/</guid><description>Reflecting upon our experience at KubeCon North America 2023</description></item><item><title>ControlPlane at KubeCon NA '23 Chicago</title><link>https://control-plane.io/posts/cp-at-kcna-2023/</link><pubDate>Mon, 06 Nov 2023</pubDate><guid>https://control-plane.io/posts/cp-at-kcna-2023/</guid><description>Where to find ControlPlane talks and events at KubeCon North America 2023 in Chicago</description></item><item><title>Take Zero Trust to the Next Level with Confidential Virtual Machines</title><link>https://control-plane.io/posts/spiffe-confidential-computing-august-2023/</link><pubDate>Tue, 29 Aug 2023</pubDate><guid>https://control-plane.io/posts/spiffe-confidential-computing-august-2023/</guid><description>SPIFFE and confidential computing are two security projects that minimize the level of implicit trust a user needs to place into a computing system. We will show how to combine these approaches to minimize the trust we need to place in public cloud services</description></item><item><title>The National Cybersecurity Strategy Implementation Plan</title><link>https://control-plane.io/posts/national-cybersecurity-strategy-july-2023/</link><pubDate>Tue, 18 Jul 2023</pubDate><guid>https://control-plane.io/posts/national-cybersecurity-strategy-july-2023/</guid><description>The first annual iteration of the National Cybersecurity Strategy Implementation Plan has been released, detailing how the US government plans to achieve the goals previously outlined in 2021&amp;rsquo;s National Cybersecurity Strategy</description></item><item><title>Dark Matter Cloud Anonymous: Andrew Martin and Amanda Brock discuss open source and OpenUK's report</title><link>https://control-plane.io/posts/cloud-anonymous-july-2023/</link><pubDate>Thu, 13 Jul 2023</pubDate><guid>https://control-plane.io/posts/cloud-anonymous-july-2023/</guid><description>The event took questions from an audience of industry veterans and discussed open source security, developer understanding of Kubernetes, FinOps for cloud, and more</description></item><item><title>Charting Zero Trust and High Assurance: ControlPlane’s Takeaways from the NIST Multi-Cloud and OSCAL Conferences</title><link>https://control-plane.io/posts/cp-at-nist-con-2023/</link><pubDate>Fri, 16 Jun 2023</pubDate><guid>https://control-plane.io/posts/cp-at-nist-con-2023/</guid><description>ControlPlane&amp;rsquo;s Experience at the 4th Annual OSCAL and Multi-Cloud Conferences Sponsored by NIST</description></item><item><title>Conference Recap: ControlPlane at KubeCon EU '23</title><link>https://control-plane.io/posts/cp-at-kceu-2023-retro/</link><pubDate>Mon, 24 Apr 2023</pubDate><guid>https://control-plane.io/posts/cp-at-kceu-2023-retro/</guid><description>ControlPlane talk &amp;amp; event write-ups from KubeCon EU in Amsterdam</description></item><item><title>KubeCon EU '23: Open Source Releases</title><link>https://control-plane.io/posts/2023-04-21-kubecon-eu-23-open-source-releases/</link><pubDate>Fri, 21 Apr 2023</pubDate><guid>https://control-plane.io/posts/2023-04-21-kubecon-eu-23-open-source-releases/</guid><description>ControlPlane open sources security and threat model knowledge</description></item><item><title>Threat Modelling Zero Trust at KubeCon EU 2023 Amsterdam</title><link>https://control-plane.io/posts/threat-modelling-zero-trust/</link><pubDate>Fri, 21 Apr 2023</pubDate><guid>https://control-plane.io/posts/threat-modelling-zero-trust/</guid><description>ControlPlane show you how to threat model Zero Trust architectures at KubeCon Europe 2023 in Amsterdam</description></item><item><title>Collie: A toolkit for securing cloud controller provisioned infrastructure</title><link>https://control-plane.io/posts/collie-open-source-release/</link><pubDate>Thu, 20 Apr 2023</pubDate><guid>https://control-plane.io/posts/collie-open-source-release/</guid><description>Demonstrating compliance and securing infrastructure provisioned by Kubernetes Cloud Infrastructure Controllers</description></item><item><title>Netassert v2: Network Security Testing</title><link>https://control-plane.io/posts/netassert-v2-release/</link><pubDate>Thu, 20 Apr 2023</pubDate><guid>https://control-plane.io/posts/netassert-v2-release/</guid><description>How to write, test, and secure your network configurations</description></item><item><title>ControlPlane at DevSecCon UK Meet-up</title><link>https://control-plane.io/posts/controlplane-at-devseccon-uk-2023/</link><pubDate>Tue, 11 Apr 2023</pubDate><guid>https://control-plane.io/posts/controlplane-at-devseccon-uk-2023/</guid><description>ControlPlane at DevSecCon UK Meet-up</description></item><item><title>ControlPlane at KubeCon EU 2023 Amsterdam</title><link>https://control-plane.io/posts/controlplane-at-kubecon-eu-2023/</link><pubDate>Thu, 16 Mar 2023</pubDate><guid>https://control-plane.io/posts/controlplane-at-kubecon-eu-2023/</guid><description>Where to find ControlPlane talks and events at KubeCon Europe 2023 in Amsterdam</description></item><item><title>Intro to the CloudNative SecurityCon CTF</title><link>https://control-plane.io/posts/intro-cloudnative-securitycon-ctf/</link><pubDate>Mon, 06 Mar 2023</pubDate><guid>https://control-plane.io/posts/intro-cloudnative-securitycon-ctf/</guid><description>Capture-the-Flag platform demo with The New Stack 🔐🏴‍☠️</description></item><item><title>The Most Excellent Learnings of CloudNative SecurityCon 2023</title><link>https://control-plane.io/posts/inaugural-cloudnativesecuritycon/</link><pubDate>Tue, 07 Feb 2023</pubDate><guid>https://control-plane.io/posts/inaugural-cloudnativesecuritycon/</guid><description>The Cloud Native security community is vibrant and strong 🌩🎉</description></item><item><title>SPIFFE: The Keystone Species of Cloud Native Security</title><link>https://control-plane.io/posts/spiffe-keystone-of-cloud-native/</link><pubDate>Mon, 16 Jan 2023</pubDate><guid>https://control-plane.io/posts/spiffe-keystone-of-cloud-native/</guid><description>Short-lived cryptographic identities are the basis upon which secure communication and access control are built 🗟🙊</description></item><item><title>The Inaugural CloudNative SecurityCon, North America, and Security Zero Day</title><link>https://control-plane.io/posts/inaugural-cloudnativesecuritycon-na/</link><pubDate>Mon, 16 Jan 2023</pubDate><guid>https://control-plane.io/posts/inaugural-cloudnativesecuritycon-na/</guid><description>Cloud Native security bursts onto the conference circuit 🌩🎉</description></item><item><title>Cloud Native and Kubernetes Security Predictions 2023</title><link>https://control-plane.io/posts/kubernetes-predictions-for-2023/</link><pubDate>Fri, 13 Jan 2023</pubDate><guid>https://control-plane.io/posts/kubernetes-predictions-for-2023/</guid><description>A speculative look into the perils and opportunities that 2023 holds 🕵️🔎</description></item><item><title>KCD UK 2022</title><link>https://control-plane.io/posts/kcduk-2022/</link><pubDate>Thu, 24 Nov 2022</pubDate><guid>https://control-plane.io/posts/kcduk-2022/</guid><description>Kubernetes Community Days 2022 at CodeNode, London ☸</description></item><item><title>ControlPlane Accelerates International Expansion</title><link>https://control-plane.io/posts/controlplane-accelerates-international-expansion/</link><pubDate>Tue, 22 Nov 2022</pubDate><guid>https://control-plane.io/posts/controlplane-accelerates-international-expansion/</guid><description>ControlPlane expands into North America and APAC with two key executive hires 📈</description></item><item><title>KubeCon NA 2022 - Techstrong TV interview</title><link>https://control-plane.io/posts/kubecon-na-2022-techstrong-tv/</link><pubDate>Mon, 21 Nov 2022</pubDate><guid>https://control-plane.io/posts/kubecon-na-2022-techstrong-tv/</guid><description>Andrew Martin joins Mitch Ashley of Techstrong TV for a chat about ControlPlane, Hacking Kubernetes, and avoiding configuration gotchas 📺</description></item><item><title>An evening of network security</title><link>https://control-plane.io/posts/tailscale-controlplane-nov-2022/</link><pubDate>Mon, 14 Nov 2022</pubDate><guid>https://control-plane.io/posts/tailscale-controlplane-nov-2022/</guid><description>An evening of network security by Tailscale and ControlPlane 🔐</description></item><item><title>ControlPlane at KubeCon NA 2022 Detroit</title><link>https://control-plane.io/posts/controlplane-at-kubecon-na-2022/</link><pubDate>Sun, 23 Oct 2022</pubDate><guid>https://control-plane.io/posts/controlplane-at-kubecon-na-2022/</guid><description>Where to find ControlPlane talks and events at KubeCon North America 2022, Detroit ☸</description></item><item><title>The Future of Open Source Technology in Financial Services</title><link>https://control-plane.io/posts/open-source-technology-in-financial-services/</link><pubDate>Wed, 19 Oct 2022</pubDate><guid>https://control-plane.io/posts/open-source-technology-in-financial-services/</guid><description>ControlPlane&amp;rsquo;s New York City event with FINOS 🏙</description></item><item><title>What's New - Kubernetes 1.25 Security Features</title><link>https://control-plane.io/posts/kubernetes-1.25-whats-new/</link><pubDate>Tue, 27 Sep 2022</pubDate><guid>https://control-plane.io/posts/kubernetes-1.25-whats-new/</guid><description>Overview of new security features in Kubernetes v1.25 ⚸🔐</description></item><item><title>VEXing challenges - ControlPlane at the Open Source Summit Europe 2022, Dublin</title><link>https://control-plane.io/posts/oss-europe-2022-dublin/</link><pubDate>Tue, 13 Sep 2022</pubDate><guid>https://control-plane.io/posts/oss-europe-2022-dublin/</guid><description>ControlPlane and OpenUK information at the Open Source Summit Europe 2022 in Dublin 🔐</description></item><item><title>OpenUK Reports on the State of Open: The UK in 2022</title><link>https://control-plane.io/posts/state-of-open-report-openuk-2022/</link><pubDate>Sun, 10 Jul 2022</pubDate><guid>https://control-plane.io/posts/state-of-open-report-openuk-2022/</guid><description>ControlPlane contributes to the definitive open source report for the UK</description></item><item><title>Walking the talks - ControlPlane at KubeCon Europe 2022</title><link>https://control-plane.io/posts/kubecon-eu-2022-talks/</link><pubDate>Tue, 28 Jun 2022</pubDate><guid>https://control-plane.io/posts/kubecon-eu-2022-talks/</guid><description>ControlPlane talks at KubeCon EU, 2022 ☸</description></item><item><title>Shift Left: Where Cloud Native Computing Security Is Going (The New Stack)</title><link>https://control-plane.io/posts/new-stack-where-cloudnative-security-going/</link><pubDate>Fri, 03 Jun 2022</pubDate><guid>https://control-plane.io/posts/new-stack-where-cloudnative-security-going/</guid><description>DevSecOps leaders on the direction of CloudNative Security</description></item><item><title>Hacking Kubernetes Book Released</title><link>https://control-plane.io/posts/hacking-kubernetes-book-release/</link><pubDate>Sat, 06 Nov 2021</pubDate><guid>https://control-plane.io/posts/hacking-kubernetes-book-release/</guid><description>A threat-based guide to Kubernetes security 📖</description></item><item><title>Securing the Kubernetes Supply Chain: Software Factory Reference Architecture</title><link>https://control-plane.io/posts/the-software-factory-secure-reference-architecture/</link><pubDate>Wed, 13 Oct 2021</pubDate><guid>https://control-plane.io/posts/the-software-factory-secure-reference-architecture/</guid><description>Sophisticated mechanisms and best practices to enhance defenses against supply chain threats in Kubernetes</description></item><item><title>Hardening Git for GitOps</title><link>https://control-plane.io/posts/hardening-git-for-gitops/</link><pubDate>Wed, 12 May 2021</pubDate><guid>https://control-plane.io/posts/hardening-git-for-gitops/</guid><description>ControlPlane whitepaper on securing GitOps workflows at source ✍</description></item><item><title>CNCF Cloud Native Security Whitepaper</title><link>https://control-plane.io/posts/cloud-native-security-whitepaper/</link><pubDate>Tue, 01 Dec 2020</pubDate><guid>https://control-plane.io/posts/cloud-native-security-whitepaper/</guid><description>ControlPlane collaborates with authors in sig-security 📜</description></item><item><title>Hands-on Kubernetes Security</title><link>https://control-plane.io/posts/hands-on-k8s-security/</link><pubDate>Thu, 12 Nov 2020</pubDate><guid>https://control-plane.io/posts/hands-on-k8s-security/</guid><description>Learning Kubernetes the Secure Way 💻</description></item><item><title>Kubernetes Predictions 2019</title><link>https://control-plane.io/posts/kubernetes-predictions-for-2019/</link><pubDate>Wed, 09 Jan 2019</pubDate><guid>https://control-plane.io/posts/kubernetes-predictions-for-2019/</guid><description>5 predictions and 5 wishes for Kubernetes in the year ahead 🕵️🔎</description></item><item><title>ControlPlane Sponsors PhD of in-toto Author Santiago Torres</title><link>https://control-plane.io/posts/controlplane-sponsors-phd-of-in-toto-author-santiago-torres/</link><pubDate>Thu, 15 Nov 2018</pubDate><guid>https://control-plane.io/posts/controlplane-sponsors-phd-of-in-toto-author-santiago-torres/</guid><description>ControlPlane, the open source and cloud native security company, sponsors the PhD work of in-toto author Santiago Torres, furthering the advancement of software supply chain security.</description></item><item><title>11 Ways (Not) to Get Hacked</title><link>https://control-plane.io/posts/11-ways-not-to-get-hacked/</link><pubDate>Tue, 05 Jun 2018</pubDate><guid>https://control-plane.io/posts/11-ways-not-to-get-hacked/</guid><description>An overview of essential security features for Kubernetes, and a glance to the future 👨‍🚀</description></item></channel></rss>