Filter
Exclude
Time range
-
Near
🪪 SPIFFE and SPIRE: Every K8s pod gets a cryptographic X.509 identity. Service-to-service authentication without static credentials or shared secrets! #Kubernetes #SPIFFE #SPIRE #WorkloadIdentity
2
🌩️ Hybrid identity = major attack surface. 🔐 Harden Entra Connect 👤 Review & restrict MSOL_ sync accounts 🚫 Remove overprivileged defaults 🔑 Eliminate long-lived creds → move to cert-based auth 🛡 Enforce Conditional Access 🏗 Isolate Tier-0 🎓Master hybrid attack paths with #BreachingAzure. Train like an attacker, Stop Tomorrow's Cloud Breach 👉 cloudbreach.io/breachingazur… #CloudBreach #CloudSecurity #AzureSecurity #HybridIdentity #EntraID #AzureAD #EntraConnect #MSOL #IAM #IdentitySecurity #ZeroTrust #AttackSurface #AttackSurfaceReduction #Tier0 #ConditionalAccess #WorkloadIdentity #CloudSec #CyberSecurity #Infosec #SecurityArchitecture #RedTeam #BlueTeam #PurpleTeam #OffensiveSecurity #DefensiveSecurity
2
2
124
20 Aug 2025
Agentic AI Identity and Access Management: A New Approach - linkedin.com/feed/update/urn… by @cloudsa Agentic AI is pushing the boundaries of automation, autonomy, and decision-making at machine speed. But traditional identity and access management (IAM) protocols, designed for static applications and human users, can’t keep up. This publication from the Cloud Security Alliance (CSA) introduces a purpose-built Agentic AI IAM framework that accounts for autonomy, ephemerality, and delegation patterns of AI agents in complex Multi-Agent Systems (MAS). It provides security architects and identity professionals with a blueprint to manage agent identities using Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and Zero Trust principles, while addressing operational challenges like secure delegation, policy enforcement, and real-time monitoring. Authors: @kenhuangus, Vineeth Sai Narajala, @YoTheShow, @rossja, @Mahesh_Lambe, @raskarmit, Youssef Harkati, Jerry Huang, @habler78827, @ResilientCyber, Akram Sheriff, @StafordTitusS, Stephen Lumpe, Stephen Smith, John Jiang, Elad Luz, Syed Aamir, @EaltiliSK, @bhavin_jethra, Yuanji Sun, Suhas M, Govindaraj Palanisamy (Govi), Victor Ronin, Pratyush Mishra, Ramesha Reddy, Ashwin Sharma, Michael Morgenstern, Vatsal Gupta, Josephine, Anirudh Murali, Mahesh Kukreja, Estevenson Solano, Harpreet Singh, Schandrasekhar Varma, Sheetal Kawle, Mohsin Khan, Krishna R Maddikara, Rajiv Dewan, Nirupam Samanta, Jayesh Dalmet, Josephine Liu Source: cloudsecurityalliance.org/re… #AgenticAI #AIIdentity #AgentIAM #ZeroTrust #DecentralizedID #VerifiableCredentials #MultiAgent #SecureDelegation #PolicyEnforcement #RealtimeMonitoring #IdentityFabric #WorkloadIdentity #MachineIdentity #AccessControl #IdentityGovernance #PolicyEngine #CredentialManagement #TrustFramework #RuntimeAuthorization #AICompliance
2
9
396
6 Aug 2025
Implementing MCP Dynamic Client Registration With SPIFFE and Keycloak - blog.christianposta.com/impl… - By @christianposta The MCP Authorization spec recommends using OAuth Dynamic Client Registration (DCR) for registering MCP clients with MCP servers. More specifically, it suggests using anonymous DCR: meaning any client should be able to discover how to register itself and dynamically obtain an OAuth client without any prior credentials. In a recent blog post, I explored why this model can be problematic in enterprise environments where anonymous registration is often restricted or outright disabled. In this blog, we’ll look at how SPIFFE can be used for dynamic client registration. #MCP #SPIFFE #SPIRE #OAuth2 #DynamicClientRegistration #Keycloak #ZeroTrust #IAM #IdentityFederation #WorkloadIdentity #JWT #SoftwareStatements #OAuthFlows #CloudSecurity #Authorization #ClientRegistration #OAuthSecurity #ServiceIdentity #SPIREPlugins #EnterpriseSecurity
1
4
404
4 Aug 2025
An AI research team leaked 38TB of internal data via a SAS token on GitHub. Not manual human error. Not malicious. Just automation — doing exactly what it was told. That's the risk of ungoverned machine identity. Learn how to address it in our latest paper 📄 goteleport.com/resources/whi… #NHI #AI #CyberSecurity #WorkloadIdentity #DevSecOps
1
103
23 Jul 2025
CI/CD bots should build trust, not break it. With Teleport @projectsigstore, you can sign software with cryptographically backed workload identity—not static secrets. 🔐 Identity-aware CI/CD 🧾 Artifact provenance 🛠️ SPIFFE sigstore FTW Read → goteleport.com/blog/workload… #sigstore #workloadidentity #supplychainsecurity #devsecops
2
80
🎙️ Why do security standards matter for modern technology? SPIRL's Pieter Kasselman breaks it down in this short video. To dive in more on #WorkloadIdentity standards, read his latest latest blog. 📖 bit.ly/3Xtqldy #CloudSecurity #ZeroTrust #IdentityStandards
2
3
489
Jump into our latest #LearningByte where we dive into cloud-native customer managed #WorkloadIdentity 🕵️‍♂️ See how to set up a managed identity on Astro for #GCP, ensuring passwordless authentication and seamless integration with #Airflow 💨 bit.ly/3PDvgV4
2
190
#アーキテクチャ紹介】 Yappli社(@yappli_jp)三橋さん Workload IdentityとECS/Fargateが連携した場合の認証処理の流れ🔀 #WorkloadIdentity 連携により、外部IDプロバイダ(#IdP)と連携してサービスアカウントを使用せずにGoogle Cloudリソースを呼び出すことができます🔔 bit.ly/3P7C9Od
2
208
It's always a great feeling to write a blog post after months of research. This time, deep-dive content on #EntraID #WorkloadIdentity security monitoring. It will cover also custom detections and enrichments. For example, enhancement of incident data from #EntraID Protection.
6
8
102
16,892
24 Oct 2023
A few months ago, I wrote an article about how you can use #Azure App Configuration Service to sync your key/value pairs into #K8s ConfigMaps. Fast forward a few months and auth mechanism just got better with #WorkloadIdentity 🙌 github.com/Azure/AppConfigur…

14 Jun 2023
In this post, I walk you though the process of deploying the #Azure #App #Configuration #Kubernetes Provider into your #AKS cluster to automatically sync externally managed key-value pairs to Kubernetes ConfigMaps and Secrets 🚀 dev.to/azure/efficient-confi…
1
6
520
Finally, #AzureDevOps 🚀 is starting to support #WorkloadIdentity 🔐Federation. Microsoft has published a blog post with samples how-to use it in combination with #Terraform. Very nice... techcommunity.microsoft.com/…

1
7
27
4,776
Continuous delivery of your containers is essential to the #cloudnative development workflow. In this guide, I'll walk you through setting up a CI/CD pipeline to push your #multiarch #containers into #ACR using GitHub Actions with Entra #WorkloadIdentity aka.ms/cloudnative/PushingMu…
2
692
I hope that’s not a surprise for you all that we are building a product (which I’m very excited about) including #workloadidentity and #SPIFFE
I'm super excited to start sharing a little more about what I've been working on with @elinesterov and other members of the #SPIFFE community since last year 😁 this is just the beginning, and there's lots more to come .. stay tuned! spirl.com/blog/hello-world/
3
1
16
3,097