Container Escapes 101
Welcome to Container Escapes 101 at the AppSec Village at DEF CON 34!! 🎯 Goal: to have a working knowledge of container escapes and how each security measure or risk maps to potential for exploit...
Welcome to Container Escapes 101 at the AppSec Village at DEF CON 34!! 🎯 Goal: to have a working knowledge of container escapes and how each security measure or risk maps to potential for exploit...
Cryptography seems deceptively simple until you get into implementation. Tempted by shortcuts to save money, organizations ship something “just good enough” to pass compliance checks. I see this ...
This talk was first presented at the Boulder Secure AI & DevOps group on 20 April 2026. The end goal is enough knowledge to (1) take some first steps on your own and (2) to see the path is w...
There’s nothing quite like the feeling of a successful proof-of-concept becoming a production system, but we’re not there yet. It turns out money makes for the hardest problems on the path to prod...
We left off with a laptop and a database serving as a bare-minimum proof of concept. It works, but not enough to be usable. Starting a project from scratch doesn’t have to be toil. Moving this i...
How do you know how much each business unit is using across any number of licensed software or consumably-billed SaaS or compute products? Let’s scope actually doing this having done it before. I...
You’ve locked down your runtime, orchestrator, and hosts. Now how about what’s actually running inside of those containers? Container images are too often treated as black boxes until something g...
All of these containers are images … somewhere. That ‘somewhere’ is an artifact (or container) registry. What risks can we find in our container registry? Broadly speaking, there are two types o...
The magic of putting your application in a container is scaling to run even bigger workloads than could fit in a single machine. Container orchestrators have their own risks too. This new layer h...
Let’s walk through how to verify a container image (or any other artifact) signed with Cosign. While open-source software is built in the public, on the internet, it’s still possible to verify sig...