Tag
Kubernetes
Every Kubernetes story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 26 · 2026
Read the issue →-
Grab Builds Secure Agentic AI Workload Platform
Grab's new Palana platform provides a secure, isolated runtime for autonomous AI agents to prevent security breaches like prompt injection and credential theft. It leverages Kubernetes-native features and proxy-based secrets management to ensure high-level security and auditability.
Week 24 · 2026
Read the issue →-
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam
Researchers at elttam have identified critical vulnerabilities in Jupyter Enterprise Gateway that enable cluster-wide compromise. By exploiting improper validation of environment variables, an attacker can bypass security constraints to gain root access within a Kubernetes pod.
-
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Threat actors have successfully compromised dozens of Microsoft-owned repositories to deploy the Miasma malware via supply-chain attacks. The malware is designed to steal cloud credentials and spread laterally through developer environments by exploiting AI coding agents.
Week 23 · 2026
Read the issue →-
Red Hat npm packages compromised to steal developer credentials
More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.
Week 21 · 2026
Read the issue →-
Article: Kernel-Level Ground Truth: Why eBPF is Replacing User-Space Agents for Security Observability
The article argues that traditional user-space security monitoring agents are structurally weak because they share privileges with the workloads they monitor, allowing attackers to easily disable them. eBPF solves this by embedding probes directly into the Linux kernel's syscall interface, providing robust, high-performance, and persistent visibility into all system activity.
-
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
The US Cybersecurity and Infrastructure Security Agency (CISA) was found to have left a massive GitHub repository containing plain-text credentials and infrastructure secrets public for six months. The leak, discovered by a GitGuardian researcher, exposed access to critical systems like AWS, Azure, and Kubernetes, highlighting severe internal security lapses.
Week 20 · 2026
Read the issue →-
Postmortem: TanStack npm supply-chain compromise
An attacker successfully compromised 42 TanStack npm packages by chaining GitHub Actions cache poisoning with OIDC token extraction. The breach allowed for the unauthorized publication of malicious versions that could exfiltrate sensitive cloud and infrastructure credentials.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free