Operations | Monitoring | ITSM | DevOps | Cloud

Understanding and mitigating CVE-2020-8566: Ceph cluster admin credentials leaks in kube-controller-manager log

While auditing the Kubernetes source code, I recently discovered an issue (CVE-2020-8566) in Kubernetes that may cause sensitive data leakage. You would be affected by CVE-2020-8566 if you created a Kubernetes cluster using ceph cluster as storage class, with logging level set to four or above in kube-controller-manager. In that case, your ceph user credentials will be leaked in the cloud-controller-manager‘s log.

3 secrets of professional hackers your software team needs to know about

“My job here at Atlassian is to commit crimes and then write very, very detailed confession letters – metaphorically speaking.” Meet Alex: an engineer on our security intelligence team with a wry wit and a penchant for pop-color hair. Less metaphorically speaking, the team’s job (our red team, in particular) is to hack Atlassian’s systems exactly as real attackers would.

FTP and SFTP: What's The Difference?

In the Information Age, data is currency. Controlling the flow of information and more importantly, protecting it has increasingly become a focal point for companies who want to remain competitive in modern markets. Improving data efficiency, integrity, and security is often how companies separate themselves from their peers. We present two of the most common methods for data transfers: FTP and SFTP.

Communicate with Service Status Messaging

Sometimes an organization gets bogged down with the details. It happens. You have all of this fantastic data in SCOM, and you’re trying to share it, but your users don’t care. That’s not true. They care, but what they don’t care about is the server. To put it another way, they care if the service or application they depend on is working. But here’s the catch, you can’t do this in SCOM.

Empowering Digital Transformation Through Network Automation

2020 has seen a real acceleration in the adoption of new digital business models. At Capacity Europe last week, PCCW Global’s VP of Digital Innovation Marketing, Neil Templeton, took to the virtual stage to explain how network automation is helping businesses embrace digital transformation. “Since March and the onset of COVID 19, we’ve seen an accelerated pace of change with businesses and their move to digital transformation.

Managing Remote Teams: 3 Steps to Success

At times, directing projects in multiple locales from a desktop or laptop feels like conducting an orchestra in the dark. Coordinating with diverse, remote teams of developers producing software on an agile schedule of continual updates and releases can be especially nerve-wracking. At Sleuth, we’re crushing the remote-work challenge because, in 20 years of managing from afar, we’ve learned a thing or two — actually three — about how to do it right.

Tips for Updating Your Cybersecurity Plan

Every year brings new opportunities for federal IT professionals to reduce risk by addressing threats—both existing and emerging—with new tools, technologies, and tactics. This year has proven to be a little different, with the emergence of COVID-19 forcing federal agencies to make the jump to remote work. Although the world at large is currently working from home, bad actors from criminals to nation-state actors are still working, too.

How PagerDuty and Slack Empower the "Work Where You Are" Mindset

Our reliance on digital services continues to be heightened by the ongoing COVID-19 pandemic. For work, school, and play, digital remains the primary channel. This puts huge pressure on ITOps and DevOps teams, making it critical that they can collaborate easily to resolve incidents rapidly. Many modern ITOps and DevOps teams rely on one of PagerDuty’s key integration partners, Slack, to meet this need.

10 Reasons Network Monitor Software is a Must

Ever since the 1980s, network monitoring systems have been in place for companies that rely on computer networks to perform their daily operations. Since their implementation, they’ve undergone drastic changes and now, provide IT teams with incredible tools to ensure best practices for everything from servers to application performance.

Digital Retail Tips: Reduce Downtime on Black Friday (and Cyber Monday)

Black Friday is one of the biggest days of the year for online consumers and retailers alike. This year, the coronavirus (COVID-19) pandemic is reshaping Black Friday shopping — and digital consumers and retailers must plan accordingly. The coronavirus pandemic will likely cause Black Friday shopping to decline this year. As such, many digital retailers are launching early Black Friday sales, so they can capture consumers’ interest ahead of the competition.