Aqua Blog
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance
Do Containers Provide Better Protection Against Meltdown and Spectre?

Do Containers Provide Better Protection Against Meltdown and Spectre?

About Meltdown and Spectre

Following the trend of ‘branding’ vulnerabilities, Meltdown and Spectre vulnerabilities (CVE-2017-5754, CVE-2017-5753, and CVE-2017-5715) are ‘brand’ names given to currently known variants of vulnerabilities of a similar nature, related to speculative execution. The general idea is rather …

Continue reading ›
Container Events Not to be Missed in 2018

Container Events Not to be Missed in 2018

The container technology ecosystem is coming of age and with it the number of container events across the globe that offer advice, insight, and learning opportunities is rapidly growing as well. To help you plan your conference attendance, we’ve put together a list of some of the best events for container …

Continue reading ›
2017 in Review: Major Developments in the Container Ecosystem

2017 in Review: Major Developments in the Container Ecosystem

From a “humble” $762 million in 2016, containers are predicted to grow faster than any other technology this year (as well as the next) and are on the way to become a $2.7B industry by 2020.

Continue reading ›
Grafeas and Image Vulnerability Scanning

Grafeas and Image Vulnerability Scanning

A couple of months ago Aqua Security were part of a group of companies supporting the launch of Grafeas, an open source API initially introduced by Google that allows users to manage and query metadata about software artifacts. We wrote an article about our plans to support Grafeas and now it’s time to see it in …

Continue reading ›
DevSecOps Will Ensure That Time-to-Market and Security Don’t Clash

DevSecOps Will Ensure That Time-to-Market and Security Don’t Clash

According to a recent survey by Veracode, 52% of developers worry that application security will delay development and threaten deadlines. This is huge percentage, especially considering how crucial finding, fixing and preventing security vulnerabilities is to any development effort.

Continue reading ›
Container Technology Wiki – Your Container Knowledge Hub

Container Technology Wiki – Your Container Knowledge Hub

Last week McKinsey & Company named container technology and DevOps as two of the top Ten trends redefining enterprise IT infrastructure and for good reason. No longer considered as “bleeding edge”, containers, combined with DevOps, are revolutionizing the way applications are built and deployed. In a recent survey …

Continue reading ›
Survey: DevSecOps Own Enterprise Containerized Application Security

Survey: DevSecOps Own Enterprise Containerized Application Security

There’s a lot going on in the container world. Just last month we learned that Docker added Kubernetes support to their platform in a move that clearly indicates Kubernetes’ dominance in the container orchestration world. Prior to that, Kubernetes added RBAC Authorization and Support for Outbound Network Policies and …

Continue reading ›
Securing Struts in AWS Fargate

Securing Struts in AWS Fargate

Today at re:Invent, Amazon is announcing AWS Fargate, a container service that allows you to provision containers in AWS without having to worry about the VM instances for them to run on. We had an early preview, and the opportunity to see how Aqua’s Container Security Platform works to protect containers running in …

Continue reading ›
Image Scanning in VPCs with Aqua and AWS PrivateLink

Image Scanning in VPCs with Aqua and AWS PrivateLink

Amazon Web Services announced today at re:Invent an to a recent feature PrivateLink, that enables AWS Virtual Private Cloud customers to consume apps outside their VPCs through service endpoints, using their own private IP addresses and security groups. This is a non-trivial task since VPCs are made to be isolated, so …

Continue reading ›
How Aqua Scans Container Images On-Demand From The AWS Marketplace

How Aqua Scans Container Images On-Demand From The AWS Marketplace

Today we announced the availability of a new offering on AWS - our on-demand, pay-per-scan security scanner for container images is now available in the AWS Marketplace. The scanner is a full-featured version of Aqua's image scanning capabilities found in the Aqua Container Security Platform, but with a licensing …

Continue reading ›
10 Top Talks and Resources About DevSecOps

10 Top Talks and Resources About DevSecOps

One of the most distinctive traits of DevOps is agility. The development cycle is not only fast, but also divided into multiple components that are constantly updated. At runtime, constant updates and at times episodic workloads, challenge the security of any environment.

Continue reading ›