<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Posts on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/posts/</link>
    <description>Recent content in Posts on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 10 Jul 2026 08:30:00 +0100</lastBuildDate>
    <atom:link href="https://www.msbiro.net/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ECB on AI-Enabled Cybersecurity Threats: What Banks Must Do by October 2026</title>
      <link>https://www.msbiro.net/posts/ecb-ai-enabled-cybersecurity-threats-letter/</link>
      <pubDate>Fri, 10 Jul 2026 08:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/ecb-ai-enabled-cybersecurity-threats-letter/</guid>
      <description>ECB letter on AI-enabled cybersecurity threats: action plan due October 2026, ITRQ deadline extension, CNAPP, hardened images, SBOMs and DORA resilience.</description>
    </item>
    <item>
      <title>Local AI Meeting Minutes with Docker Model Runner and Docker Agent: No Cloud, No Leaks</title>
      <link>https://www.msbiro.net/posts/local-ai-meeting-minutes-docker-agent/</link>
      <pubDate>Mon, 06 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/local-ai-meeting-minutes-docker-agent/</guid>
      <description>Local AI meeting minutes on Apple Silicon: on-device transcription with speaker diarization, then minutes from a 14B model through Docker Model Runner and Docker Agent. No cloud, no data flow to third parties, plus the story of a bug Docker fixed the same day I reported it.</description>
    </item>
    <item>
      <title>Back to Basics: TLS and PKI from the Ground Up</title>
      <link>https://www.msbiro.net/posts/back-to-basics-tls-pki/</link>
      <pubDate>Mon, 29 Jun 2026 07:49:50 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/back-to-basics-tls-pki/</guid>
      <description>TLS and PKI explained from the ground up: what an X.509 certificate actually contains, how the chain of trust works, what happens during a TLS handshake step by step, and how Kubernetes builds a full PKI with kubeadm that most engineers never read. Practical openssl commands throughout.</description>
    </item>
    <item>
      <title>In 2026 I Am Still Asked Why You Need a Hardened Container Image Catalog</title>
      <link>https://www.msbiro.net/posts/hardened-images-catalog-2026-non-negotiable/</link>
      <pubDate>Wed, 24 Jun 2026 09:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/hardened-images-catalog-2026-non-negotiable/</guid>
      <description>Why hardened container image catalogs are non-negotiable in 2026: the technological case, the DORA mandate, and the NIS2 obligations explained.</description>
    </item>
    <item>
      <title>Engineering Managers Are Your Real Culture: Why CTOs Must Invest in Middle Management</title>
      <link>https://www.msbiro.net/posts/engineering-managers-culture-cto-force-multiplier/</link>
      <pubDate>Sun, 21 Jun 2026 16:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/engineering-managers-culture-cto-force-multiplier/</guid>
      <description>Engineering managers are the real culture carriers in your organization. McKinsey 2026 data explains why CTOs must prioritize investment in their middle management layer.</description>
    </item>
    <item>
      <title>Athena Coalition: Coordinated Open Source Defense in the AI Vulnerability Era</title>
      <link>https://www.msbiro.net/posts/athena-coalition-open-source-security/</link>
      <pubDate>Tue, 16 Jun 2026 10:14:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/athena-coalition-open-source-security/</guid>
      <description>Athena is a new industry coalition for coordinated open source vulnerability defense. Here is what it means for DevSecOps teams and security leaders.</description>
    </item>
    <item>
      <title>Apple container 1.0 and container machine: hands-on security test</title>
      <link>https://www.msbiro.net/posts/apple-container-1-container-machine-hands-on/</link>
      <pubDate>Fri, 12 Jun 2026 09:45:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/apple-container-1-container-machine-hands-on/</guid>
      <description>Hands-on Apple container 1.0 test of container machine on macOS, covering home-mount security, networking, systemd, and Docker or Podman alternatives.</description>
    </item>
    <item>
      <title>Zero Trust for AI Agents: Why Anthropic&#39;s New eBook Should Be on Your Reading List</title>
      <link>https://www.msbiro.net/posts/zero-trust-for-ai-agents-anthropic-ebook/</link>
      <pubDate>Wed, 10 Jun 2026 06:42:27 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/zero-trust-for-ai-agents-anthropic-ebook/</guid>
      <description>A review of Anthropic&amp;#39;s Zero Trust for AI Agents eBook: a practical security framework for deploying autonomous AI agents, covering threat modeling for security leaders and an implementation guide for architects and engineers.</description>
    </item>
    <item>
      <title>Cloud Native Days Italy 2026: A Wrap-Up from Bologna</title>
      <link>https://www.msbiro.net/posts/cloud-native-days-italy-2026-recap/</link>
      <pubDate>Fri, 22 May 2026 06:29:04 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/cloud-native-days-italy-2026-recap/</guid>
      <description>Cloud Native Days Italy 2026 wrapped up in Bologna. A personal recap from one of the organizers: speakers, MCs, sponsors, and a community worth celebrating.</description>
    </item>
    <item>
      <title>SentinelOne Purple MCP: A Hands-On Guide to Singularity AI Integration</title>
      <link>https://www.msbiro.net/posts/sentinelone-purple-mcp-singularity/</link>
      <pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/sentinelone-purple-mcp-singularity/</guid>
      <description>Hands-on review of SentinelOne&amp;#39;s purple-mcp: how to connect Singularity alerts, vulnerabilities, and threat hunting to Claude Code for faster SOC triage.</description>
    </item>
    <item>
      <title>Lazarus Group Hides Malware in Git Hooks to Target Developers</title>
      <link>https://www.msbiro.net/posts/lazarus-group-git-hooks-malware-developers/</link>
      <pubDate>Wed, 06 May 2026 09:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/lazarus-group-git-hooks-malware-developers/</guid>
      <description>North Korea&amp;#39;s Lazarus Group embeds malware in git hooks to compromise developers through fake job interviews. Attack breakdown and five practical defences.</description>
    </item>
    <item>
      <title>CVE-2026-31431 Copy Fail: A Nine-Year-Old Kernel Bug, a 732-Byte Script, and a Root Shell</title>
      <link>https://www.msbiro.net/posts/cve-2026-31431-copy-fail-linux-kernel-privilege-escalation/</link>
      <pubDate>Fri, 01 May 2026 09:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/cve-2026-31431-copy-fail-linux-kernel-privilege-escalation/</guid>
      <description>CVE-2026-31431 Copy Fail is a local privilege escalation in the Linux kernel exploitable with a 732-byte Python script. This post covers what it is, how to fix it, what to do when patching isn&amp;#39;t immediate, and why runtime detection is the control that actually matters.</description>
    </item>
    <item>
      <title>Ubuntu 26.04 LTS: What Changes for Security and Container Workloads</title>
      <link>https://www.msbiro.net/posts/ubuntu-2604-lts-security-container-workloads/</link>
      <pubDate>Thu, 30 Apr 2026 07:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/ubuntu-2604-lts-security-container-workloads/</guid>
      <description>Ubuntu 26.04 LTS &amp;#39;Resolute Raccoon&amp;#39; just shipped. For teams running RHEL or Ubuntu on servers, this post breaks down what actually changed in security and container/Kubernetes workloads compared to 24.04 LTS, and whether it justifies starting the golden master rebuild now.</description>
    </item>
    <item>
      <title>Supply Chain Attacks Won&#39;t Stop: 8 Controls to Reduce Your Exposure</title>
      <link>https://www.msbiro.net/posts/supply-chain-attack-prevention-8-controls/</link>
      <pubDate>Sun, 26 Apr 2026 12:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/supply-chain-attack-prevention-8-controls/</guid>
      <description>Bitwarden CLI, Trivy, and Axios compromised in three weeks. Your EDR won&amp;#39;t catch postinstall scripts. 8 practical controls to reduce the blast radius.</description>
    </item>
    <item>
      <title>Kubernetes 1.36: The Release That Said Goodbye to Ingress NGINX</title>
      <link>https://www.msbiro.net/posts/kubernetes-1-36-security-release/</link>
      <pubDate>Tue, 21 Apr 2026 12:35:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubernetes-1-36-security-release/</guid>
      <description>Kubernetes 1.36 releases tomorrow with a significant security focus: user namespace isolation and SELinux volume labeling reaching GA, the end of Ingress NGINX, and a set of long-overdue removals that tighten the security posture of every cluster.</description>
    </item>
    <item>
      <title>Linux 7.0: What Platform and Security Leaders Should Know</title>
      <link>https://www.msbiro.net/posts/linux-70-what-platform-security-leaders-should-know/</link>
      <pubDate>Thu, 16 Apr 2026 10:11:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/linux-70-what-platform-security-leaders-should-know/</guid>
      <description>Linux 7.0 is not a single-headline release, but it closes several real security gaps that cloud-native platforms have been working around for years. Here is what platform and security leaders should understand, plan for, and ask their teams.</description>
    </item>
    <item>
      <title>Testing GSD: From a Docs-Only Repo to Working Go Code in One Session</title>
      <link>https://www.msbiro.net/posts/gsd-sbom-drift-spec-driven-development/</link>
      <pubDate>Mon, 13 Apr 2026 05:32:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/gsd-sbom-drift-spec-driven-development/</guid>
      <description>Another SDD experiment: using GSD (Get Shit Done) v1.34.2 with GitHub Copilot and GPT-5.4 to bootstrap sbom-drift from a docs-only repo to working Go code. Installation, project initialization, Phase 1 execution, and honest lessons from the session.</description>
    </item>
    <item>
      <title>Docker Sandboxes: Running AI Agents in YOLO Mode, Safely</title>
      <link>https://www.msbiro.net/posts/docker-sandboxes-ai-agents/</link>
      <pubDate>Tue, 07 Apr 2026 12:22:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/docker-sandboxes-ai-agents/</guid>
      <description>Docker Sandboxes (sbx) promises to run AI coding agents in isolated microVMs with zero risk to your host. I installed it, broke it, fixed it, and ran GitHub Copilot CLI inside a sandbox on my MacBook. Here is what I found.</description>
    </item>
    <item>
      <title>Hardening ACTUI: Dependabot and OpenSSF Scorecard for a Side Project</title>
      <link>https://www.msbiro.net/posts/actui-security-hardening-dependabot-openssf-scorecard/</link>
      <pubDate>Thu, 02 Apr 2026 08:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/actui-security-hardening-dependabot-openssf-scorecard/</guid>
      <description>Back from KubeCon EU 2026 with a free Copilot Pro&#43; subscription, I turned my attention to the security posture of apple-container-tui. Here&amp;#39;s how I added Dependabot and OpenSSF Scorecard using GitHub Actions, spec-kit, and the GitHub CLI.</description>
    </item>
    <item>
      <title>KubeCon EU 2026: Community, Connections, and a New Hat</title>
      <link>https://www.msbiro.net/posts/kubecon-eu-2026-amsterdam-recap/</link>
      <pubDate>Mon, 30 Mar 2026 14:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubecon-eu-2026-amsterdam-recap/</guid>
      <description>KubeCon EU 2026 Amsterdam is behind us. My fourth in a row, and the first as a Cloud Native Days Italy organizer. Here&amp;#39;s a quick personal recap: the connections, the community, and a few words about where to find the technical content.</description>
    </item>
    <item>
      <title>The Trivy Supply Chain Attack: A Breakdown of Credential Theft and the CanisterWorm Escalation</title>
      <link>https://www.msbiro.net/posts/trivy-supply-chain-attack/</link>
      <pubDate>Sat, 21 Mar 2026 07:32:37 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/trivy-supply-chain-attack/</guid>
      <description>A comprehensive analysis of the March 2026 Trivy supply chain incident: from malicious GitHub Actions to the self-propagating CanisterWorm.</description>
    </item>
    <item>
      <title>Investing in the Future: $12.5 Million to Fortify Open Source Security</title>
      <link>https://www.msbiro.net/posts/investing-in-the-future-12-5-million-to-fortify-open-source-security/</link>
      <pubDate>Fri, 20 Mar 2026 05:45:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/investing-in-the-future-12-5-million-to-fortify-open-source-security/</guid>
      <description>A major coalition of tech giants including Microsoft, Google, AWS, and GitHub has announced a $12.5 million investment to strengthen open-source security. Managed by OpenSSF and Alpha-Omega, this funding aims to scale security defenses using AI and support overworked maintainers. Discover why this is a pivotal moment for the OSS ecosystem.</description>
    </item>
    <item>
      <title>GitHub Copilot: The High-ROI Multi-Model Powerhouse</title>
      <link>https://www.msbiro.net/posts/github-copilot-roi-multi-model-roi/</link>
      <pubDate>Tue, 17 Mar 2026 10:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/github-copilot-roi-multi-model-roi/</guid>
      <description>Why GitHub Copilot Pro is currently the best value for developers, offering instant access to SOTA models like Claude 4.6 Sonnet and GPT-5.4, plus a look at Enterprise administration.</description>
    </item>
    <item>
      <title>August 2026 Countdown: Are Your K8s AI Workloads EU AI Act Ready?</title>
      <link>https://www.msbiro.net/posts/august-2026-countdown-k8s-ai-compliance/</link>
      <pubDate>Mon, 16 Mar 2026 04:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/august-2026-countdown-k8s-ai-compliance/</guid>
      <description>With the EU AI Act&amp;#39;s full enforcement approaching in August 2026, it&amp;#39;s time to shift from manual compliance to automated, platform-level governance in Kubernetes. This post outlines the technical requirements and DevSecOps strategies for ensuring your AI workloads are ready.</description>
    </item>
    <item>
      <title>The Exploitability Gap: Insights from Datadog’s State of DevSecOps 2026</title>
      <link>https://www.msbiro.net/posts/datadog-state-of-devsecops-2026-report/</link>
      <pubDate>Fri, 06 Mar 2026 09:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/datadog-state-of-devsecops-2026-report/</guid>
      <description>Exploring the critical findings of the Datadog State of DevSecOps 2026 report, focusing on exploitable vulnerabilities, unmaintained libraries, and CI/CD security risks.</description>
    </item>
    <item>
      <title>Amsterdam Bound: Gearing Up for KubeCon EU 2026</title>
      <link>https://www.msbiro.net/posts/kubecon-eu-2026-amsterdam-preview/</link>
      <pubDate>Wed, 04 Mar 2026 10:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubecon-eu-2026-amsterdam-preview/</guid>
      <description>March is here, and all roads lead to the RAI Amsterdam! As we count down to KubeCon EU 2026, I’m preparing for a whirlwind of networking, booth management with ReeVo, and hunting for the latest in supply chain security.</description>
    </item>
    <item>
      <title>ACTUI Follow-Up: Submenus and Image Management</title>
      <link>https://www.msbiro.net/posts/actui-follow-up-team-usage-enhancements/</link>
      <pubDate>Fri, 27 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/actui-follow-up-team-usage-enhancements/</guid>
      <description>Follow-up on Apple Container Terminal UI: new submenus, dedicated image management, and iterative improvements driven by real usage.</description>
    </item>
    <item>
      <title>How Distillation Attacks Are Reshaping the Global AI Landscape</title>
      <link>https://www.msbiro.net/posts/distillation-attacks-anthropic-vs-chinese-ai/</link>
      <pubDate>Mon, 23 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/distillation-attacks-anthropic-vs-chinese-ai/</guid>
      <description>An analysis of the recent distillation attacks against Anthropic&amp;#39;s Claude models by three major Chinese AI companies, explaining what distillation is and its implications for the global AI landscape.</description>
    </item>
    <item>
      <title>Back to Basics: Why Containers Are Just Fancy Linux Processes</title>
      <link>https://www.msbiro.net/posts/back-to-basics-containers-linux-processes/</link>
      <pubDate>Fri, 20 Feb 2026 06:31:29 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/back-to-basics-containers-linux-processes/</guid>
      <description>Containers are Linux processes with namespaces and cgroups, nothing more. This article breaks down what Kubernetes securityContext, resource limits, and container escapes actually do at the kernel level, and shows you how to debug containers using standard Unix tools like nsenter and /proc.</description>
    </item>
    <item>
      <title>The Challenge of Securing AI Agents: A DevSecOps Perspective</title>
      <link>https://www.msbiro.net/posts/securing-ai-agents-devsecops-challenge/</link>
      <pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/securing-ai-agents-devsecops-challenge/</guid>
      <description>A DevSecOps team leader&amp;#39;s reflection on the challenge of securing customers who use AI agents that act like users, and how this connects to spec-driven development and MCP security.</description>
    </item>
    <item>
      <title>Testing Spec-Kit: Building a Functional Container TUI in 2.5 Hours</title>
      <link>https://www.msbiro.net/posts/spec-kit-hands-on-apple-container-tui/</link>
      <pubDate>Thu, 12 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/spec-kit-hands-on-apple-container-tui/</guid>
      <description>A hands-on journey building apple-container-tui from empty repository to working Go binary in 2.5 hours using spec-kit 0.1.0. Testing spec-driven development with a real POC.</description>
    </item>
    <item>
      <title>AI CLI Standardization: From Tool Lock-in to Portability</title>
      <link>https://www.msbiro.net/posts/ai-cli-standardization-guidelines/</link>
      <pubDate>Fri, 06 Feb 2026 06:38:56 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/ai-cli-standardization-guidelines/</guid>
      <description>A practical guide to standardizing AI CLI workflows with context files, AGENTS.md, and environment management for DevSecOps. Learn how to make your AI setup portable, reproducible, and secure across tools and teams.</description>
    </item>
    <item>
      <title>When Your Update System Becomes the Attack Vector: The Notepad&#43;&#43; Supply Chain Compromise</title>
      <link>https://www.msbiro.net/posts/notepad-plusplus-sdlc-compromise-2026/</link>
      <pubDate>Tue, 03 Feb 2026 22:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/notepad-plusplus-sdlc-compromise-2026/</guid>
      <description>Deep dive into the Notepad&#43;&#43; supply chain attack: how state-sponsored hackers compromised the hosting provider, hijacked updates, and what we can learn about SDLC security.</description>
    </item>
    <item>
      <title>ClawdBot → MoltBot → OpenClaw: A Case Study in Confusion Attacks and Security Risks</title>
      <link>https://www.msbiro.net/posts/openclaw-security-analysis/</link>
      <pubDate>Sat, 31 Jan 2026 01:44:33 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/openclaw-security-analysis/</guid>
      <description>A comprehensive security analysis of the OpenClaw AI assistant project. Examining three name changes in 10 days as a confusion attack pattern, exposed cloud instances due to misconfiguration, the fake VS Code plugin incident, and the hidden costs of running AI agents on your own API keys. Why I can&amp;#39;t use this tool with my real accounts despite being an AI enthusiast.</description>
    </item>
    <item>
      <title>Cloud Native Days Italy 2026: The Journey Continues</title>
      <link>https://www.msbiro.net/posts/cloud-native-days-italy-2026-update/</link>
      <pubDate>Thu, 29 Jan 2026 11:48:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cloud-native-days-italy-2026-update/</guid>
      <description>Update on Cloud Native Days Italy 2026 organization: hunting sponsors, CFP submissions pouring in, and ticket sales coming soon. Join us in Bologna on May 18-19, 2026!</description>
    </item>
    <item>
      <title>GitHub Spec-Kit: Why Structured AI Development Beats Vibe Coding</title>
      <link>https://www.msbiro.net/posts/github-spec-kit-spec-driven-development/</link>
      <pubDate>Wed, 21 Jan 2026 09:23:27 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/github-spec-kit-spec-driven-development/</guid>
      <description>A DevSecOps team leader&amp;#39;s perspective on GitHub Spec-Kit, spec-driven development, and why structured AI workflows matter for compliance, auditability, and team collaboration.</description>
    </item>
    <item>
      <title>From Delegation to Ownership: How to Keep Engineers Motivated</title>
      <link>https://www.msbiro.net/posts/from-delegation-to-ownership-how-to-keep-engineers-motivated/</link>
      <pubDate>Fri, 09 Jan 2026 09:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/from-delegation-to-ownership-how-to-keep-engineers-motivated/</guid>
      <description>Building on my previous post about becoming a Team Leader, I explore how to move beyond simple task delegation. Learn how to foster true ownership, involve engineers in high-level decision-making, and keep a remote team motivated by focusing on the &amp;#39;why&amp;#39; rather than just the &amp;#39;how&amp;#39;.</description>
    </item>
    <item>
      <title>Evaluating Oss Security Fresh Editor s2c2f</title>
      <link>https://www.msbiro.net/posts/evaluating-oss-security-fresh-editor-s2c2f/</link>
      <pubDate>Sat, 27 Dec 2025 16:37:11 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/evaluating-oss-security-fresh-editor-s2c2f/</guid>
      <description>Holiday hacking from the couch: evaluating Fresh editor&amp;#39;s security using OpenSSF Scorecard, Semgrep, and cargo audit. A practical guide to applying the S2C2F framework for secure OSS adoption without killing developer productivity. Learn how to vet unknown open-source tools in an afternoon before bringing them to corporate environments.</description>
    </item>
    <item>
      <title>Docker Hardened Images Are Now Free and Open Source</title>
      <link>https://www.msbiro.net/posts/docker-hardened-images-free/</link>
      <pubDate>Thu, 18 Dec 2025 09:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/docker-hardened-images-free/</guid>
      <description>Docker has made a significant move by releasing their Hardened Images catalog as free and open source. This post explores what this means for developers, the inclusion of Helm charts and MCP servers, and how the enterprise model supports this initiative.</description>
    </item>
    <item>
      <title>2025 CWE Top 25: Mitre&#39;s Critical Software Weakness Rankings and Trends</title>
      <link>https://www.msbiro.net/posts/top25mitre2025/</link>
      <pubDate>Wed, 17 Dec 2025 05:19:07 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/top25mitre2025/</guid>
      <description>Mitre&amp;#39;s 2025 CWE Top 25 reveals persistent threats like XSS and SQL Injection atop the list, with rising authorization flaws and memory bugs signaling DevSecOps priorities for cloud-native apps. Explore the top 10 changes from 2024, key trends, and how CWE root causes differ from CVEs.</description>
    </item>
    <item>
      <title>Kubernetes Security: 2025 Stable Features &amp; 2026 preview</title>
      <link>https://www.msbiro.net/posts/k8s-security-2025-graduates-2026-preview/</link>
      <pubDate>Mon, 08 Dec 2025 10:05:05 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/k8s-security-2025-graduates-2026-preview/</guid>
      <description>Recap of Kubernetes security features that reached stable in 2025 &#43; predictions for 2026 graduates. DevSecOps guide to production hardening.</description>
    </item>
    <item>
      <title>Back to Basics: My Opinionated 2025 sshd_config Hardening</title>
      <link>https://www.msbiro.net/posts/back-to-basics-sshd-hardening/</link>
      <pubDate>Wed, 03 Dec 2025 16:03:07 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/back-to-basics-sshd-hardening/</guid>
      <description>Back-to-basics sshd_config hardening for 2025: opinionated settings to disable root login, enforce key auth, modern ciphers, and timeouts. Secure your Linux servers from the ground up—no Kubernetes required</description>
    </item>
    <item>
      <title>Beyond CVE Scanning: The Case for a Hardened Container Image Catalog</title>
      <link>https://www.msbiro.net/posts/the-case-for-hardened-container-image-catalogs/</link>
      <pubDate>Sat, 29 Nov 2025 10:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/the-case-for-hardened-container-image-catalogs/</guid>
      <description>Why traditional vulnerability scanning isn&amp;#39;t enough and how a hardened image catalog is essential for modern enterprise security and regulatory compliance.</description>
    </item>
    <item>
      <title>LDAP: A Nostalgic Dive into Authentication and Why It&#39;s Still Kicking in 2025</title>
      <link>https://www.msbiro.net/posts/ldap-authentication-cheatsheet-2025/</link>
      <pubDate>Sat, 22 Nov 2025 15:37:05 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/ldap-authentication-cheatsheet-2025/</guid>
      <description>A trip down memory lane to the world of LDAP. This post is a cheatsheet for modern engineers on how to configure application authentication with LDAP and why this technology is still relevant today.</description>
    </item>
    <item>
      <title>Securely Working with Third-Party MCP Servers</title>
      <link>https://www.msbiro.net/posts/securely-using-third-party-mcp-servers/</link>
      <pubDate>Mon, 17 Nov 2025 00:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/securely-using-third-party-mcp-servers/</guid>
      <description>A guide to understanding and securely implementing third-party Model Context Protocol (MCP) servers, based on the OWASP GenAI security cheatsheet.</description>
    </item>
    <item>
      <title>Building My First AI Agent for Blog Publishing</title>
      <link>https://www.msbiro.net/posts/building-my-first-ai-agent-for-blog-publishing/</link>
      <pubDate>Sun, 09 Nov 2025 16:11:07 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/building-my-first-ai-agent-for-blog-publishing/</guid>
      <description>How I built an AI-powered automation agent to humanize, verify, and publish blog articles in minutes. A practical journey from chatbot to AI CLI tools.</description>
    </item>
    <item>
      <title>Runc Container Breakout Vulnerabilities</title>
      <link>https://www.msbiro.net/posts/runc-container-breakout-vulnerabilities-2025/</link>
      <pubDate>Fri, 07 Nov 2025 06:45:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/runc-container-breakout-vulnerabilities-2025/</guid>
      <description>A summary of the recently disclosed runc container breakout vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) and the recommended actions.</description>
    </item>
    <item>
      <title>MarkItDown: An AI-Boosting Tool Tested on Apple Containers</title>
      <link>https://www.msbiro.net/posts/markitdown-apple-containers/</link>
      <pubDate>Tue, 04 Nov 2025 01:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/markitdown-apple-containers/</guid>
      <description>A hands-on test of Microsoft&amp;#39;s MarkItDown, a powerful tool for AI workflows, and a first look at Apple&amp;#39;s new container technology on an M4 MacBook.</description>
    </item>
    <item>
      <title>A Halloween Tech Recap: Gearing Up for the Final Sprint of 2025</title>
      <link>https://www.msbiro.net/posts/halloween-tech-recap-2025/</link>
      <pubDate>Tue, 28 Oct 2025 10:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/halloween-tech-recap-2025/</guid>
      <description>A Halloween-themed recap of my first year at ReeVo, the exciting technical projects I&amp;#39;m working on, and my involvement in the cloud-native community as we head into the final months of 2025.</description>
    </item>
    <item>
      <title>Understanding the Power of SBOMs: Insights from OpenSSF&#39;s White Paper</title>
      <link>https://www.msbiro.net/posts/openssf-sbom-whitepaper/</link>
      <pubDate>Fri, 03 Oct 2025 16:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/openssf-sbom-whitepaper/</guid>
      <description>This article explores the OpenSSF white paper &amp;#39;Improving Risk Management Decisions with SBOM Data,&amp;#39; highlighting how Software Bill of Materials (SBOMs) provide critical visibility into software components, vulnerabilities, and licensing. It covers 13 practical SBOM use cases, the SBOM lifecycle from creation to consumption, and key OpenSSF tooling for managing SBOMs in cloud-native environments to enhance security, compliance, and supply chain risk management.</description>
    </item>
    <item>
      <title>My New Role with Cloud Native Days Italy</title>
      <link>https://www.msbiro.net/posts/cloud-native-days-team-news/</link>
      <pubDate>Thu, 25 Sep 2025 00:02:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cloud-native-days-team-news/</guid>
      <description>Exciting personal update: Joining Cloud Native Days Italy as organizer for 2026 Bologna event. Community work, tech events, and connections in focus.</description>
    </item>
    <item>
      <title>External Secrets Operator: Releases Resume and Governance Matures</title>
      <link>https://www.msbiro.net/posts/external-secrets-operator-releases-resume/</link>
      <pubDate>Sun, 14 Sep 2025 22:51:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/external-secrets-operator-releases-resume/</guid>
      <description>External Secrets Operator resumes releases on September 22 with clearer governance and a new contribution ladder—see what changed and how to get involved</description>
    </item>
    <item>
      <title>External Secrets Operator Team needs help!</title>
      <link>https://www.msbiro.net/posts/external-secrets-operator-team-needs-help/</link>
      <pubDate>Fri, 15 Aug 2025 02:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/external-secrets-operator-team-needs-help/</guid>
      <description>The External Secrets Operator project faces challenges with long-term maintenance and needs new contributors. Learn about the situation, its impact on the Kubernetes community, and how you can help support this essential open-source security tool.</description>
    </item>
    <item>
      <title>Urgent: Zero-Day CVEs Found in Two Major Secrets Managers — Have You Updated Yet?</title>
      <link>https://www.msbiro.net/posts/0day-cves-secrets-manager/</link>
      <pubDate>Mon, 11 Aug 2025 12:39:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/0day-cves-secrets-manager/</guid>
      <description>This article highlights recent zero-day vulnerabilities discovered in CyberArk and HashiCorp secrets managers, emphasizes the importance of timely software updates, and offers practical advice for staying proactive about security patches.</description>
    </item>
    <item>
      <title>The Critical Trio: Secrets Manager, Zero-CVE Images, and CNAPP are Needed (Not Only) for DORA Compliance!</title>
      <link>https://www.msbiro.net/posts/secrets-cnapp-0cve-dora/</link>
      <pubDate>Thu, 07 Aug 2025 06:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/secrets-cnapp-0cve-dora/</guid>
      <description>Why Secrets Manager, Zero-CVE container images, and CNAPPs are essential for cybersecurity resilience and DORA compliance</description>
    </item>
    <item>
      <title>From Senior System Engineer to Team Leader: My Journey and Key Leadership Principles</title>
      <link>https://www.msbiro.net/posts/from-senior-system-engineer-to-team-leader-journey-leadership-principales/</link>
      <pubDate>Wed, 16 Jul 2025 06:34:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/from-senior-system-engineer-to-team-leader-journey-leadership-principales/</guid>
      <description>Discover my personal journey from senior system engineer to team leader. I share key leadership lessons, remote management principles, and advice for engineers moving into people management—all focused on fostering team growth and a positive, collaborative culture.</description>
    </item>
    <item>
      <title>From Dev to Prod: Making Distroless Images Your Default </title>
      <link>https://www.msbiro.net/posts/from-dev-to-prod-making-distroless-images-your-default/</link>
      <pubDate>Tue, 17 Jun 2025 10:10:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/from-dev-to-prod-making-distroless-images-your-default/</guid>
      <description>Explore the importance of using distroless container images to reduce security vulnerabilities in production. This post covers practical advice on adopting distroless images using multi-stage builds, along with comprehensive debugging techniques including the open-source cdebug tool, Docker Debug, and Kubernetes&amp;#39; kubectl debug with ephemeral containers. Learn how strategic container image choices improve security, efficiency, and maintainability from development through production.</description>
    </item>
    <item>
      <title>Apple container announced</title>
      <link>https://www.msbiro.net/posts/apple-container-oss-macos26/</link>
      <pubDate>Tue, 10 Jun 2025 14:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/apple-container-oss-macos26/</guid>
      <description>Apple announced its new open-source container runtime for macOS 26, enabling developers to run OCI-compliant Linux containers natively on Apple silicon with enhanced isolation, security, and Rosetta 2 support. This post explores the features, requirements, and how this solution compares to Docker and Podman for macOS developers.</description>
    </item>
    <item>
      <title>Fresh Start: Moving My Blog from Blogger to Hugo</title>
      <link>https://www.msbiro.net/posts/fresh-start-moving-my-blog-from-blogger-to-hugo/</link>
      <pubDate>Sat, 07 Jun 2025 09:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/fresh-start-moving-my-blog-from-blogger-to-hugo/</guid>
      <description>After years on Blogger, I’ve migrated my blog to Hugo with the PaperMod theme, hosted on Cloudflare Pages and backed by GitHub. In this post, I share the reasons for the change, the migration process, and where to find the archives of my previous English and Italian blogs.</description>
    </item>
    <item>
      <title>Securing Kubernetes 1.33 Pods: The Impact of User Namespace Isolation</title>
      <link>https://www.msbiro.net/posts/kubernetes-133-user-namespace-isolation-security-matters/</link>
      <pubDate>Fri, 16 May 2025 09:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubernetes-133-user-namespace-isolation-security-matters/</guid>
      <description>Kubernetes 1.33 enables user namespace isolation by default for pods, greatly enhancing security by mapping container root users to unprivileged host UIDs. This post explores the feature’s security benefits including process isolation and lateral movement prevention, infrastructure requirements like Linux kernel 6.3 and compatible container runtimes, and how to enable user namespaces in your pod specifications. Learn why this advancement is crucial for securing Kubernetes workloads in modern environments.</description>
    </item>
    <item>
      <title>From Manual to GitOps: Simplifying Grafana Dashboard Configuration with Git Sync</title>
      <link>https://www.msbiro.net/posts/grafana-dashboard-configuration-with-gitops/</link>
      <pubDate>Mon, 12 May 2025 11:34:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/grafana-dashboard-configuration-with-gitops/</guid>
      <description>Starting with version 12, Grafana introduces the experimental Git Sync feature, enabling users to manage dashboards using a GitOps approach. This feature connects Grafana to a GitHub repository to synchronize dashboard JSON files, allowing version control, collaboration through pull requests, and seamless automated deployment of dashboards. Git Sync offers a scalable way to manage dashboards in complex environments, enhancing traceability, auditing, and consistency across multiple instances.</description>
    </item>
    <item>
      <title>OpenSSF - Open Source Project Security Baseline</title>
      <link>https://www.msbiro.net/posts/openssf-opensource-project-security-baseline/</link>
      <pubDate>Wed, 26 Feb 2025 11:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/openssf-opensource-project-security-baseline/</guid>
      <description>The OpenSSF Open Source Project Security Baseline is a new initiative providing a structured set of security checks across three levels that open-source projects can implement to demonstrate a strong security posture. This practical framework helps maintainers improve software security and certification, fostering safer open-source ecosystems. Learn about the baseline, its levels, and how to get involved.</description>
    </item>
    <item>
      <title>KubeCon EU 2025 London</title>
      <link>https://www.msbiro.net/posts/kubecon-2025-london/</link>
      <pubDate>Fri, 21 Feb 2025 09:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubecon-2025-london/</guid>
      <description>Heading to KubeCon EU 2025 in London for the third year in a row—this time representing ReeVo as a proud sponsor! I’ll be managing our booth, connecting with cloud-native professionals, partners, and contributors from across the globe. Join me in celebrating the power of community, collaboration, and innovation in the Kubernetes ecosystem—see you in London!</description>
    </item>
    <item>
      <title>Resolving &#39;Operation Not Permitted&#39; for CyberArk Conjur Cloud CLI on macOS</title>
      <link>https://www.msbiro.net/posts/resolving-operation-not-permitted-cyberark-conjur-cloud-cli-macos/</link>
      <pubDate>Fri, 17 Jan 2025 16:20:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/resolving-operation-not-permitted-cyberark-conjur-cloud-cli-macos/</guid>
      <description>This post details a troubleshooting journey resolving the &amp;#39;Operation Not Permitted&amp;#39; error when running the CyberArk Conjur Cloud CLI on macOS 15.2. The issue stems from macOS quarantining the binary, which can be fixed by removing the quarantine attribute via the xattr command. Follow this step-by-step guide to get your Conjur Cloud CLI up and running smoothly on macOS.</description>
    </item>
    <item>
      <title>macOS, Podman Desktop and the Podman Machine: Pay Close Attention to the Podman Version</title>
      <link>https://www.msbiro.net/posts/podman-desktop-and-podman-machine-on-macos-pay-attention-to-podman-version/</link>
      <pubDate>Fri, 10 Jan 2025 11:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/podman-desktop-and-podman-machine-on-macos-pay-attention-to-podman-version/</guid>
      <description>This post explores compatibility issues when using Podman Desktop on macOS, particularly the Podman machine failing to start due to legacy Podman installations. It shares practical troubleshooting steps including identifying version conflicts, removing unsupported Podman machines, and successfully recreating them for smooth container management. Essential reading for developers managing container runtimes on macOS.</description>
    </item>
    <item>
      <title>Confirmed as KubeWeekly Editor: Giving Back to the Cloud-Native Community in 2025</title>
      <link>https://www.msbiro.net/posts/confirmed-as-kubeweekly-editor-2025-giving-back-to-cloud-native-community-2025/</link>
      <pubDate>Thu, 09 Jan 2025 08:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/confirmed-as-kubeweekly-editor-2025-giving-back-to-cloud-native-community-2025/</guid>
      <description>Confirmed as KubeWeekly editor for 2025, continuing a community-driven role that curates the latest news and insights across Kubernetes and the cloud-native ecosystem. Learn what goes into KubeWeekly editorial, why this newsletter matters to the CNCF community, and how to get involved as a contributor or reader.</description>
    </item>
    <item>
      <title>KCD Italy Will Return in 2025 with a New Name</title>
      <link>https://www.msbiro.net/posts/kcd-italy-return-2025-as-cloud-native-days/</link>
      <pubDate>Thu, 05 Dec 2024 18:33:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kcd-italy-return-2025-as-cloud-native-days/</guid>
      <description>KCD Italy is coming back in June 2025 in Bologna, rebranded as Cloud Native Days Italy. While the name is changing, the event will continue its tradition of high-quality sessions and community engagement, bringing together developers, architects, and cloud-native enthusiasts from across Italy and beyond.</description>
    </item>
    <item>
      <title>Security Conference – BSides Galway, February 22nd, 2025</title>
      <link>https://www.msbiro.net/posts/bsides-galway-february-22-2025/</link>
      <pubDate>Sun, 17 Nov 2024 13:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/bsides-galway-february-22-2025/</guid>
      <description>BSides Galway debuts its first-ever local security conference on February 22nd, 2025, at the University of Galway. Bringing together cybersecurity professionals, enthusiasts, and students, the event fosters learning, networking, and community—all in the globally renowned BSides format. Learn about tickets, CFP, and opportunities to get involved in Ireland’s newest infosec event.</description>
    </item>
    <item>
      <title>CyberArk Conjur 13.4 – The Evolution Continues</title>
      <link>https://www.msbiro.net/posts/cyberark-conjur-134-evolution-continues/</link>
      <pubDate>Wed, 09 Oct 2024 07:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-conjur-134-evolution-continues/</guid>
      <description>CyberArk Conjur 13.4 introduces exciting new features including syncing empty safes from Vault for improved policy automation, dynamic application configuration through the conjur.yml file, and extended support for regex queries in the External Secrets Operator. This release marks another step in the continuous enhancement of Conjur Enterprise, making it more powerful and flexible for enterprise secrets management.</description>
    </item>
    <item>
      <title>cryptsetup: How to Protect Entire Disks or USB Keys – Notes on technical_notebook</title>
      <link>https://www.msbiro.net/posts/cryptsetup-protect-entire-disk-or-usb-key-notes-technical-notebook/</link>
      <pubDate>Mon, 15 Jul 2024 18:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cryptsetup-protect-entire-disk-or-usb-key-notes-technical-notebook/</guid>
      <description>A hands-on guide using cryptsetup to encrypt entire disks and USB keys on Linux, based on real tests and examples from the technical_notebook repository. Learn essential commands, concepts, and practical tips to secure your portable drives with open-source tools and biometric access.</description>
    </item>
    <item>
      <title>KubeCon 2024: Why Attending a Conference Is Important and Some Useful Resources</title>
      <link>https://www.msbiro.net/posts/kubecon-eu-2024-why-attending-a-conference-is-important/</link>
      <pubDate>Fri, 15 Mar 2024 05:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubecon-eu-2024-why-attending-a-conference-is-important/</guid>
      <description>Insights from attending KubeCon EU 2024 in Paris—why large-scale conferences matter for networking, learning, and community engagement in the cloud-native world. This post explores the unique opportunities to meet peers, vendors, and open-source contributors, attend top technical sessions, and access session recordings and resources provided by the CNCF.</description>
    </item>
    <item>
      <title>CyberArk Conjur 13.2 Released: Another Step in the Right Direction</title>
      <link>https://www.msbiro.net/posts/cyberark-conjur-132-released/</link>
      <pubDate>Thu, 01 Feb 2024 12:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-conjur-132-released/</guid>
      <description>CyberArk released Conjur 13.2 with important bug fixes, support for OpenShift 4.14, and new key features including high availability for the Vault Synchronizer and enhanced support for the Container Storage Interface (CSI) driver. This release improves disaster recovery strategies and optimizes secret injection into Kubernetes pods, representing another solid step in Conjur’s ongoing evolution.</description>
    </item>
    <item>
      <title>KubeWeekly – Get Weekly Kubernetes News in Your Inbox</title>
      <link>https://www.msbiro.net/posts/kubeweekly-k8s-newsletter/</link>
      <pubDate>Thu, 25 Jan 2024 11:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubeweekly-k8s-newsletter/</guid>
      <description>KubeWeekly is a curated newsletter delivering the latest Kubernetes and CNCF community news, articles, and videos straight to your inbox. As an editor during early 2024, I help select and share valuable content to keep the cloud-native community informed and connected. Discover how to subscribe and join this vibrant ecosystem of Kubernetes enthusiasts and professionals.</description>
    </item>
    <item>
      <title>KCD 2024 Italy Announced – Bologna, 20 June 2024</title>
      <link>https://www.msbiro.net/posts/kcd-italy-2024-bologna/</link>
      <pubDate>Wed, 17 Jan 2024 11:44:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kcd-italy-2024-bologna/</guid>
      <description>KCD Italy 2024 is announced for June 20, 2024, in Bologna at the Savoia Regency Hotel. This Kubernetes Community Day event, supported by CNCF and organized by the Italian Kubernetes community, welcomes developers, architects, and enthusiasts to share knowledge and experiences. The CFP is open with English sessions welcome, and sponsorship opportunities are available to engage with the vibrant cloud-native community.</description>
    </item>
    <item>
      <title>CyberArk Conjur 13.1 Released</title>
      <link>https://www.msbiro.net/posts/cyberark-conjur-131-released/</link>
      <pubDate>Thu, 07 Dec 2023 08:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-conjur-131-released/</guid>
      <description>CyberArk has released Conjur 13.1, a point update focusing on under-the-hood improvements that enhance the resiliency of Conjur followers. Key changes include major upgrades to the underlying container base image, PostgreSQL, and etcd versions, as well as enhanced flexibility in vault synchronization and secret segregation. This release is recommended for all Conjur Enterprise users seeking improved performance and stability.</description>
    </item>
    <item>
      <title>KubeCon EU 2024 Paris – Exploring the Kubetrain Initiative</title>
      <link>https://www.msbiro.net/posts/kubecon-eu-2024-paris-kubetrain/</link>
      <pubDate>Fri, 10 Nov 2023 06:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/kubecon-eu-2024-paris-kubetrain/</guid>
      <description>KubeCon EU 2024 will be held in Paris from March 19-22, featuring an innovative sustainability initiative called Kubetrain. This program encourages attendees to travel by train from major European cities like Amsterdam, Berlin, London, Lyon, Milan, and Zurich to reduce their carbon footprint while enjoying networking opportunities onboard. Early bird registration and CFP submissions are open, making it an exciting time to prepare for this premier cloud-native community event.</description>
    </item>
    <item>
      <title>The Value of Community Contributions: Exploring CNCF and OpenSSF</title>
      <link>https://www.msbiro.net/posts/the-value-of-community-contributions-exploring-cncf-openssf/</link>
      <pubDate>Wed, 01 Nov 2023 16:44:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/the-value-of-community-contributions-exploring-cncf-openssf/</guid>
      <description>This post explores the importance and impact of contributing to open-source community foundations, focusing on the Cloud Native Computing Foundation (CNCF) and the Open Source Security Foundation (OpenSSF). It shares personal experiences of involvement, the benefits of stepping outside one’s comfort zone, and practical links to join projects, events, and working groups. Gain insights into how participation fosters ecosystem growth and professional development.</description>
    </item>
    <item>
      <title>CyberArk Conjur 13 has been released.</title>
      <link>https://www.msbiro.net/posts/conjur-13-is-available/</link>
      <pubDate>Tue, 06 Jun 2023 18:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/conjur-13-is-available/</guid>
      <description>CyberArk has released Conjur 13.0, bringing notable enhancements like OIDC login support, secret data segregation for followers, optimized password management, and faster Vault synchronization for enterprise environments. This post covers the highlights of version 13, why you should consider upgrading, and how these improvements impact admins, security teams, and Kubernetes users.</description>
    </item>
    <item>
      <title>Resolving Podman Log Rotation Issues in CyberArk Conjur Container 12.9 Deployments</title>
      <link>https://www.msbiro.net/posts/resolving-podman-log-rotation-issue-conjur-enterprise-129/</link>
      <pubDate>Wed, 24 May 2023 17:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/resolving-podman-log-rotation-issue-conjur-enterprise-129/</guid>
      <description>This post addresses a log rotation issue seen in CyberArk Conjur 12.9 container deployments running on Podman. Unlike Docker, Podman requires the container to be recreated with the AUDIT_WRITE capability added and a specific permission set on the Nginx log directory for proper log rotation. The resolution was developed collaboratively with CyberArk support and is now documented for future updates. Essential guidance for operators using Podman with Conjur containers.</description>
    </item>
    <item>
      <title>SIGHUP Secure Containers: how do you choose the oci base image for your workload?</title>
      <link>https://www.msbiro.net/posts/sighup-secure-container-how-choose-base-image-security/</link>
      <pubDate>Thu, 13 Apr 2023 12:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/sighup-secure-container-how-choose-base-image-security/</guid>
      <description>This post discusses how to choose the right OCI base image for your workloads, emphasizing the importance of security, vulnerability management, and timely updates. It showcases SIGHUP’s Secure Containers service, which offers a curated, proactively patched container catalog with support, SLAs, and automation benefits to help teams maintain secure, compliant container supply chains.</description>
    </item>
    <item>
      <title>How Is It Possible to Make Both Developers and Security Officers Happy? Try Snyk!</title>
      <link>https://www.msbiro.net/posts/how-make-developers-and-security-officers-happy-with-snyk/</link>
      <pubDate>Fri, 13 Jan 2023 16:23:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/how-make-developers-and-security-officers-happy-with-snyk/</guid>
      <description>Snyk is a powerful security platform offering tools for static analysis (SAST), software composition analysis (SCA), container security, infrastructure as code, and cloud security. This post explains how Snyk helps developers maintain secure codebases while enabling security officers to oversee vulnerabilities without slowing development. Learn about Snyk’s integrations in IDEs, CI/CD, and Git workflows, customizable dashboards for security teams, and its open-source vulnerability database. A free plan makes testing easy for anyone interested in improving software security.</description>
    </item>
    <item>
      <title>Troubleshooting CyberArk Conjur Follower Setup and Postgres Connectivity</title>
      <link>https://www.msbiro.net/posts/troubleshooting-conjur-follower-setup-postgres-connectivity/</link>
      <pubDate>Mon, 21 Nov 2022 11:23:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/troubleshooting-conjur-follower-setup-postgres-connectivity/</guid>
      <description>This post covers troubleshooting a CyberArk Conjur follower setup issue where the follower pod could connect to the Conjur API leader but failed to connect to the Postgres database, causing replication to stall and system errors. The solution involved verifying Postgres connectivity using openssl s_client with TLS, revealing a network load balancer misconfiguration that was subsequently corrected. Learn how to use this simple openssl command for effective container and network diagnostics.</description>
    </item>
    <item>
      <title>CyberArk Vault Synchronizer – CASVM035E Vault Name Is Missing: How to Fix It</title>
      <link>https://www.msbiro.net/posts/cyberark-vault-synchronizer-casvm035e-fix/</link>
      <pubDate>Fri, 30 Sep 2022 07:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-vault-synchronizer-casvm035e-fix/</guid>
      <description>This post addresses the CyberArk Vault Synchronizer error &amp;#39;CASVM035E Vault name is missing&amp;#39; encountered during upgrade from version 11.7 to 12.7. It guides users through the straightforward fix by updating the INTEGRATION_VAULT_NAME value in the VaultConjurSynchronizer.exe.config file, restoring secrets synchronization functionality on Windows.</description>
    </item>
    <item>
      <title>CyberArk Impact 2022 World Tour – Will You Be There?</title>
      <link>https://www.msbiro.net/posts/cyberark-impact-world-tour-2022/</link>
      <pubDate>Wed, 21 Sep 2022 19:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-impact-world-tour-2022/</guid>
      <description>CyberArk announces the Impact World Tour, a series of global cybersecurity events featuring expert sessions and networking opportunities. This post shares details on tour locations, agenda, and registration, along with a personal note on attending the Milan event in October 2022.</description>
    </item>
    <item>
      <title>CyberArk Conjur, authenticators and integrations</title>
      <link>https://www.msbiro.net/posts/cyberark-conjur-authenticators-integrations/</link>
      <pubDate>Mon, 22 Aug 2022 10:26:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-conjur-authenticators-integrations/</guid>
      <description>detailing the variety of authenticators such as host/user API key, OIDC, AWS IAM, Kubernetes with SPIFFE-compliant mutual TLS, and more. Learn how these authenticators enable secure secrets retrieval and integrations with popular DevOps tools and cloud platforms, enhancing security and flexibility for dynamic environments.</description>
    </item>
    <item>
      <title>CyberArk Conjur: A Quick Overview of Architecture and System Requirements</title>
      <link>https://www.msbiro.net/posts/cyberark-conjur-architecture-system-requirements/</link>
      <pubDate>Sun, 24 Jul 2022 11:40:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/cyberark-conjur-architecture-system-requirements/</guid>
      <description>This post provides a comprehensive overview of CyberArk Conjur Enterprise architecture, detailing its multi-node cluster design with auto-failover capabilities, follower deployment for scaling, and essential system requirements for production and test environments. Essential reading for anyone planning to deploy Conjur as an enterprise-grade secrets manager.</description>
    </item>
    <item>
      <title>CyberArk Conjur - why you (probably) need an enterprise secrets manager</title>
      <link>https://www.msbiro.net/posts/why-you-need-kubernetes-secrets-manager/</link>
      <pubDate>Tue, 19 Jul 2022 16:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/why-you-need-kubernetes-secrets-manager/</guid>
      <description>Secrets management is critical to securing modern infrastructures, guarding sensitive information such as passwords, certificates, and keys from exposure and misuse. This post introduces CyberArk Conjur, an enterprise-grade secrets manager that protects secrets using programmable REST APIs, centralized security policies, and integration with CyberArk’s broader ecosystem. Learn why avoiding common mistakes like hardcoding secrets or pushing them to public repositories is vital, and how Conjur offers scalable, secure, and automated secrets management for cloud-native environments.</description>
    </item>
    <item>
      <title>I&#39;ve started a new journey as DevSecOps Team Leader</title>
      <link>https://www.msbiro.net/posts/new-job-devsecops-teamleader/</link>
      <pubDate>Wed, 25 May 2022 11:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/new-job-devsecops-teamleader/</guid>
      <description>Starting May 16, 2022, I embarked on a new journey as Senior DevSecOps Engineer at SIGHUP. This post marks the beginning of a shift towards cloud-native infrastructure security topics, including tools like CyberArk Conjur. While previous content remains available, expect fresh insights into securing modern cloud environments. My role as organizer of the LetsConnect user group continues, and I look forward to connecting at upcoming events.</description>
    </item>
  </channel>
</rss>
