April 2017
InfoQ

Cloud and AWS Security Special Report

Sponsored by
InfoQ
Latest Content, Top Viewed Content, News, Top Articles, Top Presentations
 
In this special newsletter we bring you up to date on all the new content and news related to Cloud and AWS Security on InfoQ. We are also maintaining a portal page for this content on InfoQ at: https://www.infoq.com/cloud-computing and https://www.infoq.com/aws.
Assuring Crypto-code with Automated Reasoning (presentations, Apr 13, 2017)
AWS Organizations Offers Centralized Policy-Based Account Management (news, Mar 31, 2017)
Public Docker Image Vulnerability Research Findings Released (news, Mar 30, 2017)
Security War Stories: The Battle for the Internet of Things (presentations, Mar 22, 2017)
A Security Approach for a Cloudy World: An Interview with Pete Cheslock (articles, Mar 17, 2017)

Rugged DevOps - 10 Ways to Embed Security into DevOps Patterns

This eBook provides advice from 10 SecDevOps leaders on how to bake security into DevOps practices rather than treating it as an afterthought. Download Now.

Sponsored content

Running Docker Containers Securely in Production (news, Dec 17, 2016)
An Authentication and Authorization Architecture for a Microservices World (presentations, Oct 19, 2016)
Apache Eagle, Originally from eBay, Graduates to top-level project (news, Jan 24, 2017)
Apache Ranger Graduates to Top-Level Project (news, Mar 14, 2017)
A Human Error Took Down AWS S3 US-EAST-1 (news, Mar 03, 2017)

Study Shows the Web is Crowded with Outdated, Vulnerable JavaScript Libraries

A recent study has found that 37% of Alexa top 75K websites has at least one vulnerability and almost 10% at least two. Maybe even more shockingly, 26% of Alexa top 500 websites use vulnerable libraries.

Bitbucket Introduces Required Two-Factor Authentication and IP Whitelisting

Atlassian has announced two new features aimed to make Bitbucket more secure: IP whitelisting and required two-factor verification.

Top 10 AWS Cloud Security Risks

Here are the top 10 risks that show up in AWS. Are you making those same mistakes? We bet you are. Download now.

Sponsored content

Cloudbleed - Cloudflare Proxies Memory Leak

A buffer overflow bug has caused a small number of requests to Cloudflare proxies to leak data from unrelated requests, including potentially sensitive data such as passwords and other secrets. The issue, which has been named ‘Cloudbleed’, was discovered by Google Project Zero vulnerability researcher Tavis Ormandy.

HashiCorp Release Terraform 0.8, Including an Interactive Console, and Vault and Nomad Providers

HashiCorp have released Terraform 0.9., which includes: significant improvements to how remote state is managed, including state locking, ‘state environments’ and a new centralised initialisation command ‘terraform init’; destroy provisioners that can be configured run before a resource is destroyed; and resource interrupts, allowing the immediate interrupts to be handled with custom logic.

Is it Possible to Test Programmable Infrastructure? Matt Long at QCon London Made the Case for Yes

At QCon London, Matt Long, QA Consultant at OpenCredo presented “Testing Programmable Infrastructure with Ruby”. Key takeaways included: it is possible to test programmable infrastructure at the unit, integration, and acceptance level; Ruby provides the power of a full programming language for integration and acceptance tests, and is often understood by both testers and sysadmins.

Roundtable: The Role of Enterprise Architecture in a Cloudy World

Do enterprise architects still matter? Has a cloud-native development model fundamentally changed how we think about enterprise architecture? In this roundtable with architects, we discuss.

The Container Landscape: Docker Alternatives, Orchestration, and Implications for Microservices

The orchestration of containers is key for success, and various technologies are competing for market share. This article examines the current tooling and how this relates to deploying microservices.

Lessons Learned from Scheduling One Million Containers with HashiCorp Nomad

HashiCorp's Million Container Challenge is a test for how efficiently its scheduler, Nomad, can schedule one million containers across 5,000 hosts. This post outlines the lessons learned.

Lambda Functions versus Infrastructure - Are we Trading Apples for Oranges?

Amazon's AWS Lambda service is a serverless offering that lets us run code without provisioning servers. This article compares the tradeoffs of serverless models with VM/Container based models.

Top 10 Security Best Practices for AWS

Here are the 10 best practices you should follow for better cloud security and success in AWS. Download Now.

Sponsored content

Managing Secrets at Scale

Mark Paluch discusses keeping the security bar high while running services that require secrets, securely sharing and managing secrets (certificates, passwords, keys) using Vault and Spring Boot.

Modern Web Security, Lazy But Mindful Like a Fox

Albert Yu presents a few viable, usable and effective defensive techniques that developers have often overlooked.

From Data Science to Production: Deploy, Scale, Enjoy

Sergii Khomenko introduces best practices in development, covers production deployments to the AWS stack, and using the serverless architecture for data applications.

Spring Cloud on AWS

Agim Emruli presents common patterns and best-practices to run the application on the AWS cloud and how to use the platform provided services efficiently.

Elegant AWS Lambda

Mario Aquino demonstrates deploying services to the AWS Lambda platform, configuring these services, and interacting with them through logging and monitoring.
 

Connect with InfoQ on Twitter

Connect with InfoQ on Facebook

Connect with InfoQ on LinkedIn

Connect with InfoQ on Google Plus

Connect with InfoQ on Youtube

If you no longer wish to receive these emails, please click on the following link: Unsubscribe


C4Media Inc. (InfoQ.com),
2275 Lake Shore Boulevard West,
Suite #325,
Toronto, Ontario, Canada,
M8V 3Y3