A technical deep dive into runtime container scanning; How OverlayFS upperdir scanning, fanotify monitoring, and in-memory execution detection catch threats that build-time tools miss.
A taxonomy of real-world container abuse, from crypto miners, trojans, phishing kits, spam bots, and worse. Discovered by scanning container writable layers on a multi-tenant Kubernetes / OpenShift platforms.
Containers are ephemeral, so malware can't persist, right? Observations from scanning a production Kubernetes cluster reveal why the industry's favorite security assumption is dangerously wrong.