POPULARITY
Patrick McKenzie (patio11) is joined by Garrison Lovely, journalist and author of Obsolete: The AI Industry's Trillion-Dollar Race to Replace Us and How to Stop It, to map the three-sided debate over AI risk and why the arguments keep talking past each other. They then turn to what cheap cognition does to surveillance that already exists: FinCEN receives roughly 4 million suspicious activity reports a year and reads almost none of them, ICE agents run about a million queries against that database annually, and every podcast ever recorded is now transcribable for approximately nothing. The conversation covers capabilities denialism, ablated open-weights models, the fraud supply chain, and why AI is also unusually good at writing the Regulation E letter that gets your bank to fix your problem.–Full transcript available here: https://www.complexsystemspodcast.com/cheap-cognition-and-the-end-of-practical-obscurity-with-garrison-lovely/ –Presenting Sponsors: Mercury, MongoDB & ChainguardComplex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. –Links:Obsolete: The AI Industry's Trillion Dollar Race to Replace Us―and How to Stop It: https://www.amazon.com/Obsolete-Power-Profit-Machine-Superintelligence/dp/1682196305 –Timestamps:(00:00) Preview(00:43) Intro(01:51) The three-sided debate over AI risk(05:32) Power, politics, and the tech backlash(09:49) Capabilities denialism and AI tells(14:54) The obsoleting machine(17:09) The Turing test is dead(18:56) Languages for free, then software engineering(22:37) Sponsors: Mercury | MongoDB(25:09) How high up the stack do the models decide?(29:11) Surveillance and cheap cognition(32:38) Podcasts, FinCEN, and the end of practical obscurity(38:35) Section 702 and the data broker loophole(39:35) Sponsor: Chainguard(40:55) Section 702 and the data broker loophole (cont'd)(47:23) Institutional friction and a million ICE queries(53:29) Security through obscurity no longer works(54:54) Scams, fraud, and ablated models(1:00:20) Personal utility versus societal backlash(1:02:16) AI as a tool for redress(1:06:34) State capacity and regulating what you understand(1:12:37) Tobacco, nuclear, and AlphaFold: strangle it or steer it(1:18:37) Where to find Garrison and the book(1:20:32) Wrap
This interview was recorded at GOTO Copenhagen 2025.https://gotocph.comAdrian Mouat - Developer Relations at Chainguard & Author of "Using Docker"Kief Morris - Author of "Infrastructure as Code" & Distinguished Engineer at ThoughtworksSam Newman - Author of "Building Microservices" & "Monolith to Microservices"RESOURCESAdrianhttps://bsky.app/profile/adrianmouat.comhttps://twitter.com/adrianmouathttps://github.com/amouathttps://linkedin.com/in/adrianmouathttp://www.adrianmouat.comKiefhttps://bsky.app/profile/kief.comhttps://twitter.com/kiefhttps://github.com/kiefhttps://www.linkedin.com/in/kiefmorrishttps://infrastructure-as-code.comhttps://kief.comSamhttps://twitter.com/samnewmanhttps://www.linkedin.com/in/samnewmanhttp://samnewman.iohttp://samnewman.io/bloghttps://github.com/snewmanABSTRACTIn this session, Sam Newman will interview Kief Morris and Adrian Mouat, both experts in their field. We will explore the current reality of security in the container world, how infrastructure automation is impacted by AI, and whether platform teams are actually working. We'll also be taking lots of questions from the audience! [...]Read the full abstract here:https://gotocph.com/2025/sessions/3938RECOMMENDED BOOKSAdrian Mouat • Using Docker • https://amzn.to/3PEYIJLLiz Rice • Container Security • https://amzn.to/3oU4iJeKief Morris • Infrastructure as Code • https://amzn.to/4e6EBQcSam Newman • Building Resilient Distributed Systems • https://www.oreilly.com/library/view/building-resilient-distributed/9781098163532Sam Newman • Monolith to Microservices • https://amzn.to/2Nml96EBlueskyInstagramLinkedInFacebookCHANNEL MEMBERSHIP BONUSJoin this channel to get early access to videos & other perks:https://www.youtube.com/channel/UCs_tLP3AiwYKwdUHpltJPuA/joinLooking for a unique learning experience?Attend the next GOTO conference near you! Get your ticket: gotopia.techSUBSCRIBE TO OUR YOUTUBE CHANNEL - new videos posted daily!
In this episode, Patrick McKenzie (patio11) is joined by Leila Clark, founder of Stardrift and formerly a software engineer at Jane Street, to discuss her essay "What Are You Getting Paid In?" They cover how a Jane Street manager staffed the firm's least lucrative corner by paying people in culture, why Ken Griffin is worth roughly fifty Taylor Swifts, and how a longtime Google product manager quietly ends up with Grammy-winner money. The conversation ranges from academia's brutal tournament structure and YC as a script to founderdom to the one currency Taylor Swift holds that Ken Griffin's $50 billion buys only awkwardly: a restaurant reservation anywhere in New York.–Full transcript available here: https://www.complexsystemspodcast.com/what-youre-actually-getting-paid-in-with-leila-clark/ –Presenting Sponsors: Mercury, Chainguard & MongoDB Complex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/.What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.–Links:What are you getting paid in: https://www.approachwithalacrity.com/p/what-are-you-getting-paid-in –Timestamps:(00:00) Intro(01:23) What are you getting paid in?(03:16) Scripts, teacher figures, and hitting capitalism(08:18) The academia trap(11:08) Paying people in culture: Jane Street's back office(14:03) Ken Griffin vs. Taylor Swift(16:53) Learning about finance by osmosis (or not)(20:44) Sponsors: Mercury | Chainguard(23:46) Musician money vs. Google money(30:03) Keeping up with the Joneses and the meritocratic ladder(33:12) YC as a script to founderdom(36:19) What entrepreneurship pays you in(39:12) Gratitude, culture, and quirky preferences(40:11) Sponsor: MongoDB(43:48) Does winning this script look like winning to you?(48:29) Don't end the week with nothing(51:06) Fame and living in bubbles(56:57) Restaurant reservations as a currency(1:02:57) Where to find Leila(01:03:35) Wrap
Patrick McKenzie is joined by returning guest Clara Collier, editor-in-chief of Asterisk Magazine, to discuss how working writers and reporters actually use LLMs. Patrick walks through the machinery behind his recent SPLC reporting, including "parallel construction" with LLMs: when sources can't go on the record, models can surface public confirmation of the same facts in unguarded podcast interviews, press releases, and prepared remarks. They also cover why the best smoking gun sat unnoticed on the coalition's own Twitter account, the David O. Selznick theory of the corporate memo, and where hardball politics in a democracy ends and crimes begin.–Full transcript available here: https://www.complexsystemspodcast.com/llms-and-writers-with-clara-collier-of-asterisk-magazine/–Presenting Sponsors: Mercury, MongoDB & ChainguardComplex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. –Links:Complex Systems on YouTube: https://www.youtube.com/@patio11podcast Asterisk Magazine: https://asteriskmag.com/ –Timestamps:(00:00) Preview(00:51) Intro(01:16) How legacy media feels about LLMs(05:02) Writing as thinking: why the byline matters(08:51) LLMs as feedback partners and simulated readers(12:39) The future of the corporate memo(15:58) Sponsor: Mercury | MongoDB(18:30) Memos, de-skilling, and thinking on paper(20:02) David O. Selznick's memos and the MrBeast production doc(23:28) Can models introspect on their own work?(30:06) Sponsor: Chainguard(31:27) The SPLC investigation(37:07) Chains of evidence and protecting sources(45:20) Parallel construction with LLMs(49:41) Mining podcasts for unguarded admissions(59:35) Deepen your strengths, don't just patch weaknesses(1:03:34) The smoking gun the LLM missed(1:04:48) Hardball politics versus crimes(1:10:48) Why a payments newsletter reported a political story(1:16:19) Reporting stories that will be weaponized(1:20:24) The tech right and internal company politics(1:23:44) Debanking discourse and drawing distinctions(1:30:21) Hate speech, social sanctions, and owning decisions(1:34:51) Wrap
In this episode of Complex Systems, Patrick McKenzie (patio11) is joined by Justin Kuiper, a longtime writer for MatPat's Game Theory family of channels and now creator of Proof Positive, to discuss the microeconomics of YouTube. They break down how creators actually get paid — from $3–$20 CPMs and the leaky funnel where a million views yields perhaps 50,000 actual ad views, to sponsor reads, Super Chats, and MrBeast selling chocolate bars as his own advertiser of last resort. Along the way, they explore how a successful channel becomes a firm that absorbs specialist labor from less successful peers, why the algorithm gives every upload a trial by attention, and what parasocial spending has in common with Mark Twain's speaking circuit.–Full transcript available here: https://www.complexsystemspodcast.com/justin-kuiper-youtube/ –Presenting Sponsors: Mercury, Chainguard & MongoDB Complex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.–Links:Proof Positive on YouTube: https://www.youtube.com/channel/UCns_C7cPAguFSv2YdltaOsg –Timestamps:(00:00) Preview(00:45) How creators make money on YouTube(04:06) CPMs and the international ad market(06:36) From solo creator to firm: working for MatPat(09:28) Sponsors: Mercury | Chainguard(12:30) From solo creator to firm: working for MatPat (cont'd)(13:49) YouTube as a farm league for other industries(17:15) Why now is the best time to start: discovery and universal basic attention(20:47) Power users and how recommendations work(24:23) Brand safety, rabbit holes, and the money laundering short(27:38) Fads, timing, and the day-two piece(35:52) The production function: scripts, shot lists, and editing labor(42:14) The aesthetics of authenticity(46:58) Sponsor: MongoDB(47:47) Why more people should make videos(53:52) Content marketing, sponsor reads, and remnant inventory(01:00:24) Chocolate bars, paint sets, and creator products(01:05:00) Parasocial relationships and the market in status(01:16:43) Where to find Justin: Proof Positive(01:18:58) Wrap
Patrick McKenzie (patio11) reads his 2023 essay "Deposit Franchises as Natural Hedges," written seven weeks into that year's banking crisis, making the case that deposit franchises are a natural hedge against interest rate risk (one regional banks were quietly encouraged to sell off by loading up on agency MBS). He walks through why "sweat and smiles" deposits were assumed to be sticky enough to fund long-duration assets, why that assumption broke down for retail and sophisticated depositors alike once rates rose, and how the resulting losses moved through bank balance sheets. Patrick closes with two years of hindsight: what the essay got right and wrong about how bad it would get.–Full transcript available here: https://www.complexsystemspodcast.com/deposit-franchises/ –Presenting Sponsors: Mercury, MongoDB & ChainguardComplex Systems is presented by Mercury—radically better banking for founders. Mercury's new feature Command brings an LLM directly into your banking interface, so checking balances, finding invoices, or sending a wire is as easy as asking. Apply online in minutes at https://mercury.com/. What's the point of building faster with AI if your database can't keep up? MongoDB's native data model mirrors the language LLMs already speak. Ship at the speed of AI while staying ACID compliant at Fortune 500 scale. Start building at https://mongodb.com/ai.If attackers are using AI to weaponize code faster than any team can review it, your scanners won't save you. Chainguard builds libraries and container images from source, verified all the way down, with near-zero CVEs and zero malware. Build safely at https://www.chainguard.dev/. –Links:Deposit franchises as natural hedges: https://www.bitsaboutmoney.com/archive/deposit-franchises-as-natural-hedges/ –Timestamps:(00:00) Intro(03:48) Natural hedges(07:38) Deposit franchises as an asset(10:53) The value of a deposit franchise increases with interest rates(11:30) A brief aside about deposit beta(14:58) Sponsors: Mercury | MongoDB(17:30) A brief aside about deposit beta(18:05) The deposit franchise as a hedge(21:52) Regional banks were instructed to load up on agency MBS(25:09) Why did the hedge bust?(29:42) Sponsor: Chainguard(31:03) Further bad news: the problem is bigger than MBS(34:01) It is no longer February(34:51) “Why didn't the hedger hedge?!”(35:37) So what do we do now?(37:59) Postscript(39:45) Wrap
Send us Fan MailToday's guest is Matt Moore, Co-Founder and CTO of Chainguard — the software supply chain security company on a mission to make the open-source ecosystem safe for enterprises everywhere. Matt's background spans some of the most consequential corners of the cloud-native world. Before co-founding Chainguard, he was a core contributor to the open-source ecosystem and played a pivotal role at Google, where he helped shape the Kubernetes and supply chain security landscape that underpins much of modern software infrastructure today.In today's conversation, we'll dive into Matt's journey from open-source engineering to founding a company, how Chainguard is tackling one of the most critical — and often overlooked — challenges in enterprise software, the philosophy behind building security into the foundation rather than bolting it on, what it takes to turn deep technical expertise into a venture-backed company, and his vision for the future of software supply chain security in an AI-first world.Support the show
It started with a fake car listing on eBay.What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of dollars siphoned from victims who had no idea.This is the story of Bayrob and the three men from Romanian who were behind it. And the long, strange road that led American investigators to their door.SponsorsSupport for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.This show is sponsored by Meter, the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that's built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com.This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what's actually exploitable, not just what's theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more.This episode is sponsored by Chainguard. Chainguard builds container images the right way — minimal, hardened, and built from source every single day. We're talking images with zero known CVEs, designed from the ground up for production. No bloat. No mystery packages. No 2 a.m. patching marathons because some transitive dependency lit up your dashboard. Stop patching images that are insecure. Start shipping clean. Head to chainguard.dev to see how secure your software supply chain can really be.
Fedora Hummingbird, RHEL Forever, and Red Hat's AI play: three big Summit takeaways, and why they matter far beyond Red Hat.Sponsored By:Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.Support LINUX UnpluggedLinks:
SUMMARY: How software development is rapidly evolving in the age of AI and automation. Matt Moore shares how his team is rethinking secure software supply chains, scaling infrastructure, and safely integrating AI agents into development workflows.GUEST: Matt Moore, CTO at Chainguard SHOW: 1022SHOW TRANSCRIPT: The Reasoning Show #1022 TranscriptSHOW VIDEO: https://youtu.be/9Q0kWkTYRs8SHOW SPONSORS:ShareGate - ShareGate Protect. Microsoft 365 Governance, we got this!Nasuni - Activate your data for AI and request a demoSHOW NOTES:Chainguard Factory 2.0DriftlessAFScaling Challenges & “Factory” EvolutionEarly automation relied on tools like GitHub ActionsAt scale, simple systems broke due to:Massive event volumesAPI rate limits (e.g., GitHub quotas)Exponential fan-out effectsKey innovation: custom work queue + reconciliation model~90% event deduplicationControlled throughput and backpressureImproved reliability and system stabilityIntroduced Driftless Built on reconciliation principles (inspired by Kubernetes):Compare desired vs. actual stateContinuously reconcile differencesBenefits:Resilience to missed eventsAutomatic retries and recoveryScales better than purely event-driven systemsAI Agents in Software DevelopmentAI is dramatically accelerating development workflowsChainguard uses agents to:Remediate vulnerabilities (CVEs)Update dependenciesFix failing tests and adapt to upstream changesKey Design PhilosophyLeast privilege → “least tool call”Avoid giving agents full system accessProvide narrowly scoped tools for specific tasksDelegate execution to sandboxed systems (e.g., CI pipelines)Focus on safe, controlled automationIndustry Shift: Velocity vs. SecurityExplosion of AI-driven tools (e.g., autonomous PR generation)Massive increase in development velocityNew risks:Poorly secured agent frameworksMalicious or unsafe automation patternsKey TakeawaysScale changes everythingSimple systems break under massive workloadsPurpose-built infrastructure becomes necessaryReconciliation > pure event-driven systems at scaleMore resilient, predictable, and controllableAI is a force multiplier—but requires guardrailsUnrestricted agents introduce serious riskConstrained, purpose-built agents are safer and more effectiveContinuous learning is mandatoryAI tooling is evolving too fast for static skillsetsTeams must actively experiment and adaptFEEDBACK?Email: show @ reasoning dot showBluesky: @reasoningshow.bsky.socialTwitter/X: @ReasoningShowInstagram: @reasoningshowTikTok: @reasoningshow
This interview was recorded for GOTO State of the Art in November 2025.https://gotopia.techRead the full transcription of this interview here:https://gotopia.tech/articles/425Adrian Mouat - Developer Relations at Chainguard & Author of 'Using Docker'Charles Humble - Freelance Techie, Podcaster, Editor, Author & ConsultantRESOURCESAdrianhttps://bsky.app/profile/adrianmouat.comhttps://twitter.com/adrianmouathttps://github.com/amouathttps://linkedin.com/in/adrianmouathttp://www.adrianmouat.comCharleshttps://bsky.app/profile/charleshumble.bsky.socialhttps://linkedin.com/in/charleshumblehttps://mastodon.social/@charleshumblehttps://conissaunce.comLinkshttps://images.chainguard.devhttps://www.cisa.gov/sbomhttps://www.chainguard.dev/supply-chain-security-101/the-npm-registry-cant-protect-you-the-new-javascript-supply-chain-attackshttps://oxide-and-friends.transistor.fm/episodes/discovering-the-xz-backdoor-with-andres-freundhttps://edu.chainguard.devDESCRIPTIONIn this State of the Art episode, Charles Humble speaks with Adrian Mouat, Developer Relations at Chainguard and author of "Using Docker", about the evolution of container security and the persistent challenge of outdated packages.Adrian explains how traditional Linux distributions weren't designed for the immutable, frequently-replaced nature of containers, leading to security vulnerabilities that scanners detect but teams struggle to address. He discusses how Chainguard tackles this problem by building everything from source using Wolfi, creating minimal "distroless" images with near-zero CVEs, and how concepts like SBOMs, attestations, and defense in depth are reshaping security practices.The conversation also covers major security incidents including the XZ Utils backdoor and Shai-hulud attacks, emphasizing the importance of building from source, using short-lived credentials, and replacing rather than updating containers – practices pioneered by companies like Google that are gradually spreading across the industry.RECOMMENDED BOOKSAdrian Mouat • Using Docker • https://amzn.to/3PEYIJLLiz Rice • Container Security • https://amzn.to/3oU4iJeLiz Rice • Kubernetes Security • https://www.oreilly.com/library/view/kubernetes-security/9781492039075BlueskyInstagramLinkedInFacebookCHANNEL MEMBERSHIP BONUSJoin this channel to get early access to videos & other perks:https://www.youtube.com/channel/UCs_tLP3AiwYKwdUHpltJPuA/joinLooking for a unique learning experience?Attend the next GOTO conference near you! Get your ticket: gotopia.techSUBSCRIBE TO OUR YOUTUBE CHANNEL - new videos posted daily!
Software Engineering Radio - The Podcast for Professional Software Developers
Dan Lorenc, co-founder and CEO of Chainguard, joins host Priyanka Raghavan to explore Sigstore and its role in securing the software supply chain. They unpack the challenges of supply chain security, including verifying the origin and integrity of software artifacts, and explain the problems Sigstore is designed to solve. The conversation goes under the hood to examine how Sigstore works, covering key components such as code signing, verification, the certificate authority model, and transparency logs—often compared conceptually to blockchain for their auditability. The episode also highlights real-world adoption, community resources for getting started, and closes with a discussion of Chainguard Images and how development teams can use them to build with more secure base images. This episode is sponsored by IEEE Computer Society.
Autonomous agents are pushing deployment speeds to the absolute limit, but is our security infrastructure ready for the consequences? Andrew sits down with Chainguard CEO Dan Lorenc to discuss the severe supply chain risks of this new frontier and what it takes to safely transition to an agent-first engineering model. They explore how engineering teams can safely accelerate deployments by turning restrictive guardrails into frictionless "guide rails" for their AI agents. Finally, the conversation unpacks the future of open source, detailing how AI might either spam projects into dormancy or solve the ecosystem's long-standing sustainability crisis by stepping in as automated, full-time maintainers.Follow the show:Subscribe to our Substack Follow us on LinkedInSubscribe to our YouTube ChannelLeave us a ReviewFollow the hosts:Follow AndrewFollow BenFollow DanFollow today's guest:Chainguard: Learn more about how Dan and his team are securing the software supply chain.Dan Lorenc on LinkedIn: Connect with Dan to follow his predictions and insights.Gastown, and where software is going: Read Dan's article exploring the Brownian Ratchet principle, multi-Claude, and eventual determinism.EmeritOSS: Explore Chainguard's initiative to provide sustainable stewardship for mature, end-of-life open-source projects.Daniel Stenberg's Blog: Insights from the Curl creator regarding the influx of AI-generated vulnerability reports.Chainguard Assemble: Catch up on the latest announcements from Chainguard's user conference.OFFERS Start Free Trial: Get started with LinearB's AI productivity platform for free. Book a Demo: Learn how you can ship faster, improve DevEx, and lead with confidence in the AI era. LEARN ABOUT LINEARB AI Code Reviews: Automate reviews to catch bugs, security risks, and performance issues before they hit production. AI & Productivity Insights: Go beyond DORA with AI-powered recommendations and dashboards to measure and improve performance. AI-Powered Workflow Automations: Use AI-generated PR descriptions, smart routing, and other automations to reduce developer toil. MCP Server: Interact with your engineering data using natural language to build custom reports and get answers on the fly.
In this episode, Ronald and Jan are joined by Hannah Hawken, partner sales at Chainguard, who brings a fresh perspective on something every Kubernetes team struggles with: security.What starts as a conversation about career paths quickly turns into a deeper discussion about how we've been approaching security all wrong for years. Coming from a background in development and later moving into security, she reflects on what it feels like to build software without truly understanding the risks—and why so many teams are still in that exact position today.Instead of reacting to vulnerabilities after they appear, the conversation explores a different mindset. One where security isn't something you bolt on later, but something you start with. Not “shift left”… but start left.From there, the discussion moves into the reality many teams face: thousands of CVEs, endless patching cycles, and security teams constantly playing catch-up. What if that entire model could be flipped? What if the software you build on is already secure by design?That idea opens the door to a broader conversation about trust in open source, the hidden complexity of dependencies, and the trade-offs between speed and security. Along the way, Ronald and Jan challenge what this means in practice. How do you actually adopt a different approach? What changes for developers? And where does this fit in real-world environments?The episode also touches on the future. Not just of Kubernetes, but of the infrastructure powering AI and modern applications. Because if workloads are becoming more complex and critical, the foundation they run on needs to evolve as well.By the end, one thing becomes clear:security isn't just a step in the process anymore… it's becoming the starting pointStuur ons een bericht.DevOps ConferenceThe Conference for CI/CD, Kubernetes, Platform Engineering & DevSecOps k8_Podcast voor 15% kortingSupport the showLike and subscribe! It helps out a lot.You can also find us on:De Nederlandse Kubernetes Podcast - YouTubeNederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTokDe Nederlandse Kubernetes PodcastWhere can you meet us:EventsThis Podcast is powered by:ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
This interview was recorded at GOTO Copenhagen 2025.https://gotocph.comAbby Bangser - Platform Engineering Insights from Syntasso delivering KratixAdrian Mouat - Developer Relations at Chainguard & Author of 'Using Docker'Holly Cummins - JavaOne Rock Star. Building Quarkus to Make the Cloud CloudierRESOURCESAbbyhttps://bsky.app/profile/abangser.bsky.socialhttps://twitter.com/a_bangserhttps://github.com/abangserhttps://www.linkedin.com/in/abbybangserhttps://www.syntasso.io/members-area/abby/profileAdrianhttps://bsky.app/profile/adrianmouat.comhttps://twitter.com/adrianmouathttps://github.com/amouathttps://linkedin.com/in/adrianmouathttp://www.adrianmouat.comHollyhttps://hollycummins.comhttps://hollycummins.com/type/bloghttps://bsky.app/profile/hollycummins.comhttps://hachyderm.io/@holly_cumminshttps://twitter.com/holly_cumminshttps://github.com/holly-cumminshttps://linkedin.com/in/holly-k-cumminsRECOMMENDED BOOKSAdrian Mouat • Using Docker • https://amzn.to/3PEYIJLLiz Rice • Container Security • https://amzn.to/3oU4iJeLiz Rice • Kubernetes Security • https://www.oreilly.com/library/view/kubernetes-security/9781492039075Anne Currie, Sarah Hsu, & Sara Bergman • Building Green Software • https://amzn.to/3UjSClvKief Morris • Infrastructure as Code • https://amzn.to/4e6EBQcBlueskyInstagramLinkedInFacebookCHANNEL MEMBERSHIP BONUSJoin this channel to get early access to videos & other perks:https://www.youtube.com/channel/UCs_tLP3AiwYKwdUHpltJPuA/joinLooking for a unique learning experience?Attend the next GOTO conference near you! Get your ticket: gotopia.techSUBSCRIBE TO OUR YOUTUBE CHANNEL - new videos posted daily!
Container base images (like Official Docker Hub images) are often updated without new tag versions. I call this Silent Rebuilds. There's no way to know this happens without image digest-checking automation like Dependabot and Renovate with specific settings. Failure to keep up-to-date is a prime source of vulnerabilities that can lead to serious security breaches. Automate the updates!Check out the video podcast version here: https://youtu.be/z_ahbsSc4Fo
Join Ryan Wallner and Bhavin Shah for season 6 of the Kubernetes Bytes podcast. In this episode Bhavin talks to Adrian Mouat, Dev Rel at Chainguard about all things Kubernetes Security. They discuss CVEs, the different vulnerability databases, and how platform engineers can use Chainguard images to protect against CVEs. Links: https://www.chainguard.dev/ https://www.linkedin.com/in/adrianmouat/ https://slsa.dev/
This week, we discuss the end of Cloud 1.0, AI agents fixing old apps, and Chainguard vs. Docker images. Plus, the mystery of Dutch broth is finally solved. Watch the YouTube Live Recording of Episode 556 Runner-up Titles His overall deal Been there and done that been ignoring that shift key for years Cloud is just fine I'll be back in Bartertown The “F” Word Hardened-washing We'll never do this, but we should check back in in 3 months Libraries are the best Elves don't belong in space Rundown Are we at the end of cloud or cloud 1.0 It's the beginning of Cloud 2.0 Spec-driven development system for Claude Code Anthropic and App Modernization A meta-prompting, context engineering and spec-driven development What comes next, if Claude Code is as good as people say. Microsoft Spending on Anthropic Approaches $500 Million a Year Claude Code Won't Fix Your Life Coté and Tony contemplate day two AI-generated apps, and an excerpt. Why We've Tried to Replace Developers Every Decade Since 1969 Well, that escalated quickly: Zero CVEs, lots of vendors Relevant to your Interests Beijing tells Chinese firms to stop using US and Israeli cybersecurity software China blacklists VMware, Palo Alto Networks software over national security fears Kroger taps Google Gemini, announces more key AI moves Texas judge throws out second lawsuit over CrowdStrike outage Apple will pay billions for Gemini after OpenAI declined Dell wants £10m+ from VMware if Tesco case goes against it Tailscale: The Best Free App Most Mac Power Users Aren't Using How WhatsApp Took Over the Global Conversation Our approach to advertising and expanding access to ChatGPT OpenAI's ARR reached over $20 billion in 2025, CFO says Simon Willison's take on Our approach to advertising and ChatGPT The AI lab revolving door spins ever faster | TechCrunch How Markdown took over the world An Interview with United CEO Scott Kirby About Tech Transformation Conferences cfgmgmtcamp 2026, February 2nd to 4th, Ghent, BE. Coté speaking - anyone interested in being an SDI guest? DevOpsDayLA at SCALE23x, March 6th, Pasadena, CA Use code: DEVOP for 50% off. Devnexus 2026, March 4th to 6th, Atlanta, GA. Use this 30% off discount code from your pals at Tanzu: DN26VMWARE30. KubeCon EU, March 23rd to 26th, 2026 - Coté will be there on a media pass. VMware User Groups (VMUGs): Amsterdam (March 17-19, 2026) Minneapolis (April 7-9, 2026) Toronto (May 12-14, 2026) Dallas (June 9-11, 2026) Orlando (October 20-22, 2026) SDT News & Community Join our Slack community Email the show: questions@softwaredefinedtalk.com Free stickers: Email your address to stickers@softwaredefinedtalk.com Follow us on social media: Twitter, Threads, Mastodon, LinkedIn, BlueSky Watch us on: Twitch, YouTube, Instagram, TikTok Book offer: Use code SDT for $20 off "Digital WTF" by Coté Sponsor the show Recommendations Brandon: The Library will loan you a 5G hotspot Matt: Deep Rock Galactic: Survivor (rogue-like Vampire Hunters-type game) Coté: Streamyard shorts generation. Salesforce was inspired by dolphins.
In this episode, Dave interviews Dan Lorenc, CEO and co-founder of Chainguard, about what happens when open source projects are abandoned.They discuss:How to figure out if a project has been abandonedThe role of companies in sponsoring open source projectsHow foundations play a role in maintaining projects
Noworoczny Short - pierwszy w 2026! Łukasz i Szymon wracają po przerwie świątecznej, a newsy technologiczne nie czekały. Postanowienia noworoczne? “Mniej YAML-a, więcej Postgresa” - jak zwykle nierealne.
This week, we discuss Oracle's AI vibes, Chainguard's EmeritOSS, and GitHub's pricing U-turn. Plus, a robust robot vacuum debate. Watch the YouTube Live Recording of Episode 551 (https://youtube.com/live/TpDLcvAXrqo?feature=share) Runner-up Titles It has CarPlay iPad Range Anxiety an Australian documentary Oracle got popped Intentions I don't feel bad for them Open Source old folks home Spreadsheets love it Robots are going to take care of us The Median User Nobody feels bad for the whales I have a dog I have a Korean microwave We're the Neal Stephenson of podcasts Rundown Ford pulls the plug on the all-electric F-150 Lightning pickup truck (https://www.npr.org/2025/12/15/nx-s1-5645147/ford-discontinues-all-electric-f-150-lightning) AI Investment Oracle plummets 11% on weak revenue, pushing down AI stocks like Nvidia and CoreWeave (https://www.cnbc.com/2025/12/10/oracle-orcl-q2-earnings-report-2026.html) Oracle Shares Drop the Most Since 2001 on Mounting AI Spending (https://www.bloomberg.com/news/articles/2025-12-10/oracle-posts-weak-cloud-sales-raising-fear-of-delayed-payoff) OpenAI in Talks to Raise At Least $10 Billion From Amazon and Use Its AI Chips (http://1 https://www.theinformation.com/articles/openai-talks-raise-least-10-billion-amazon-use-ai-chips) S&P 500 falls after nearing record as Oracle disappointment drags down AI stocks (https://www.cnbc.com/2025/12/10/stock-market-today-live-updates.html) Inside The $1T AI Economy (https://x.com/StockSavvyShay/status/2000920959000445220?s=20) Introducing Chainguard EmeritOSS: Sustainable stewardship for mature open source (https://www.chainguard.dev/unchained/introducing-chainguard-emeritoss) Runners Announcing powerful upgrades & a new pricing model for self-hosted runners (https://www.atlassian.com/blog/bitbucket/announcing-v5-self-hosted-runners) GitHub to charge for self-hosted runners from March 2026 (https://devclass.com/2025/12/17/github-to-charge-for-self-hosted-runners-from-march-2026/) GitHub postpones changes to self-hosted runners pricing plans (https://x.com/github/status/2001372894882918548?s=46) Why Git (https://www.youtube.com/watch?v=E3_95BZYIVs)H (https://www.youtube.com/watch?v=E3_95BZYIVs)ub Why? (https://www.youtube.com/watch?v=E3_95BZYIVs) Coursera to buy Udemy, creating $2.5 billion firm to target AI training (https://www.reuters.com/business/coursera-udemy-merge-deal-valuing-combined-firm-25-billion-2025-12-17/) Roomba Maker iRobot Files for Bankruptcy, With Chinese Supplier Taking Control (https://www.nytimes.com/2025/12/15/business/roomba-irobot-bankruptcy.html) Relevant to your Interests Harness raises a $240M Series E at a $5.5B valuation (https://www.axios.com/pro/enterprise-software-deals/2025/12/11/harness-goldman-sachs-series-e-software) A great platform as a product paper, and a fun platform philosophy thereof (https://cote.io/2025/12/12/a-great-platform-as-a.html) Google Launches Managed Remote MCP Servers for Its Cloud Services (https://thenewstack.io/google-launches-managed-remote-mcp-servers-for-its-cloud-services/) Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain (https://www.bitdefender.com/en-us/blog/labs/fake-leonardo-dicaprio-movie-torrent-agent-tesla-powershell) Useful patterns for building HTML tools (https://simonwillison.net/2025/Dec/10/html-tools/) Waymo Seeking Over $15 Billion Near $100 Billion Valuation (https://www.bloomberg.com/news/articles/2025-12-16/waymo-seeks-to-raise-funds-at-valuation-near-100-billion) Write your CV or resume as YAML, then run RenderCV, (https://github.com/rendercv/rendercv) (https://github.com/rendercv/rendercv)and get a PDF with perfect typography. No template wrestling. No broken layouts. Consistent spacing, every time (https://github.com/rendercv/rendercv) Roomba Maker iRobot Files for Bankruptcy, With Chinese Supplier Taking Control (https://www.nytimes.com/2025/12/15/business/roomba-irobot-bankruptcy.html) Nonsense The Full Text of Marco Rubio's Directive on State Department Typography, Re-Establishing Times New Roman (https://daringfireball.net/2025/12/full_text_of_marco_rubio_state_dept_directive_times_new_roman) Listener Feedback Sent stickers to Jelle in Belgium Conferences cfgmgmtcamp 2026 (https://cfgmgmtcamp.org/ghent2026/), February 2nd to 4th, Ghent, BE. Coté speaking and doing live SDI (https://www.softwaredefinedinterviews.com) with John Willis. DevOpsDayLA at SCALE23x (https://www.socallinuxexpo.org/scale/23x), March 6th, Pasadena, CA Use code: DEVOP for 50% off. Devnexus 2026 (https://devnexus.com), March 4th to 6th, Atlanta, GA. Whole bunch of VMUGs, mostly in the US. The CFPs are open (https://app.sessionboard.com/submit/vmug-call-for-content-2026/ae1c7013-8b85-427c-9c21-7d35f8701bbe?utm_campaign=5766542-VMUG%20Voice&utm_medium=email&_hsenc=p2ANqtz-_YREN7dr6p3KSQPYkFSN5K85A-pIVYZ03ZhKZOV0O3t3h0XHdDHethhx5O8gBFguyT5mZ3n3q-ZnPKvjllFXYfWV3thg&_hsmi=393690000&utm_content=393685389&utm_source=hs_email), go speak at them! Coté speaking in Amsterdam. Amsterdam (March 17-19, 2026), Minneapolis (April 7-9, 2026), Toronto (May 12-14, 2026), Dallas (June 9-11, 2026), Orlando (October 20-22, 2026) SDT News & Community Join our Slack community (https://softwaredefinedtalk.slack.com/join/shared_invite/zt-1hn55iv5d-UTfN7mVX1D9D5ExRt3ZJYQ#/shared-invite/email) Email the show: questions@softwaredefinedtalk.com (mailto:questions@softwaredefinedtalk.com) Free stickers: Email your address to stickers@softwaredefinedtalk.com (mailto:stickers@softwaredefinedtalk.com) Follow us on social media: Twitter (https://twitter.com/softwaredeftalk), Threads (https://www.threads.net/@softwaredefinedtalk), Mastodon (https://hachyderm.io/@softwaredefinedtalk), LinkedIn (https://www.linkedin.com/company/software-defined-talk/), BlueSky (https://bsky.app/profile/softwaredefinedtalk.com) Watch us on: Twitch (https://www.twitch.tv/sdtpodcast), YouTube (https://www.youtube.com/channel/UCi3OJPV6h9tp-hbsGBLGsDQ/featured), Instagram (https://www.instagram.com/softwaredefinedtalk/), TikTok (https://www.tiktok.com/@softwaredefinedtalk) Book offer: Use code SDT for $20 off "Digital WTF" by Coté (https://leanpub.com/digitalwtf/c/sdt) Sponsor the show (https://www.softwaredefinedtalk.com/ads): ads@softwaredefinedtalk.com (mailto:ads@softwaredefinedtalk.com) Recommendations Brandon: Humble Audiobook Bundle: Shadows, Stars & Screams: Epic Audiobooks (https://www.humblebundle.com/books/shadows-stars-screams-epic-audiobooks-dramas-realm-books) Matt: Termination Shock (https://www.goodreads.com/book/show/57094295-termination-shock) - Neal Stephenson Photo Credits Header (https://unsplash.com/s/photos/electric-vehicle?orientation=landscape&license=free)
Selling doesn't have to feel slimy. Open source doesn't have to feel risky. And leadership doesn't have to drain you. Dan Lorenc, CEO and founder of ChainGuard, has built a company - and a culture - around those beliefs. In this episode of North Start Leadership Podcast, Dan and Lindsay dig into what it means to build a “safe source for open source,” how to lead with authenticity, and why sometimes the best way to serve customers is to take work off their plate entirely. You'll hear them discuss: Why Dan, an engineer at heart, fell in love with sales once he realized it could be about solving real problems for people The hidden risks of open source software, and how ChainGuard is tackling them head on The difference between building another “smoke alarm” tool versus creating a fireproof foundation How Dan keeps his team aligned and motivated in a fully remote environment Why repetition is one of the most underrated leadership tools The company values that guide ChainGuard, including the reminder to take the work seriously without taking themselves too seriously Resources Dan Lorenc on the Chainguard | LinkedIn Lindsay Pedersen - Contact me to tell me who you'd like to hear as a guest! | Connect with me on LinkedIn
The FCC plans to roll back cybersecurity mandates that followed Salt Typhoon. The alleged cybercriminal MrICQ has been extradited to the U.S. Ransomware negotiators are accused of conducting ransomware attacks. Ernst & Young accidentally exposed a 4-terabyte SQL Server backup. A hacker claims responsibility for last week's University of Pennsylvania breach. The UK chronicles cyberattacks on Britain's drinking water suppliers. Monday business brief. Our guest is Caleb Tolin, host of Rubrik's Data Security Decoded podcast. Hackers massage the truth. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Caleb Tolin, host of Rubrik's Data Security Decoded podcast, as he is introducing himself and his show joining the N2K CyberWire network. You can catch new episodes of Data Security Decoded the first and third Tuesdays of each month on your favorite podcast app. Selected Reading FCC plans vote to remove cyber regulations installed after theft of Trump info from telecoms (The Record) Alleged Jabber Zeus Coder ‘MrICQ' in U.S. Custody (Krebs on Security) Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says (Chicago Sun Times) Ernst & Young cloud misconfiguration leaks 4TB SQL Server backup on Microsoft Azure (Beyond Machines) Penn hacker claims to have stolen 1.2 million donor records in data breach (Bleeping Computer) Hackers are attacking Britain's drinking water suppliers (The Record) JumpCloud acquires Breez. Chainguard secures $280 million in growth financing. Sublime Security closes $150 million Series C round. (N2K Pro) Hackers steal data, extort $350,000 from massage parlor clients (Korea JoongAng Daily) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Our cross-continent race to Texas Linux Fest culminates into fantastic meat, meetups, and more.Sponsored By:Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love. 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps. Unraid: A powerful, easy operating system for servers and storage. Maximize your hardware with unmatched flexibility. Support LINUX UnpluggedLinks:
In this episode, Jenna interviews Dan Lorenc, CEO of Chainguard, about the Shai-Hulud worm that has made its way through the npm ecosystem.They discuss:What Shai-Hulud is and why it's so badSecurity measures GitHub plans to implement in npm Best practices to follow to mitigate risk
Are you wrestling with how to scale your sales team without losing focus on what truly matters? Do you wonder how to maintain a customer-centric approach as your company experiences hypergrowth? Or maybe you're trying to figure out the right time and way to segment your go-to-market organization. This episode offers deep, practical insights on these pressing challenges, straight from one of cybersecurity's fastest-growing companies.In this conversation, we discuss:
This week, we cover AI going rogue, Cloudflare declaring independence, and the secure container craze. Plus, Matt bravely judges 9 new emoji. Watch the YouTube Live Recording of Episode (https://www.youtube.com/live/lRlWChvJ_m8?si=cZJ-0kzBrEH5ERZh) 530 (https://www.youtube.com/live/lRlWChvJ_m8?si=cZJ-0kzBrEH5ERZh) Runner-up Titles VP of getting it on Neutral trombone Good Margin Independent from what? The New Benevolence I have plenty of cynicism for other things Rundown Emojis Australian Bigfoot (https://en.wikipedia.org/wiki/Yowie) Unicode's new emoji refuses to put respect on Bigfoot's name (https://www.engadget.com/mobile/unicodes-new-emoji-refuses-to-put-respect-on-bigfoots-name-184412935.html) Matt's Rankings: Hairy Creature Trombone Treasure Chest Fight Cloud Orca Landslide Apple Core Ballet Dancers Distorted Face AI coding platform goes rogue during code freeze and deletes entire company database — Replit CEO apologizes after AI engine says it 'made a catastrophic error in judgment' and 'destroyed all production data' (https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-coding-platform-goes-rogue-during-code-freeze-and-deletes-entire-company-database-replit-ceo-apologizes-after-ai-engine-says-it-made-a-catastrophic-error-in-judgment-and-destroyed-all-production-data) Cloudflare Cloudflare 1.1.1.1 Incident on July 14, 2025 (https://blog.cloudflare.com/cloudflare-1-1-1-1-incident-on-july-14-2025/) Content Independence Day: no AI crawl without compensation! (https://blog.cloudflare.com/content-independence-day-no-ai-crawl-without-compensation/) Accidental Tech Podcast: 649: Prove It With Cameras (https://atp.fm/649) Anubis Web AI Firewall (https://github.com/TecharoHQ/anubis) Announcing Model Context Protocol (MCP) Server for AWS Price List (https://aws.amazon.com/about-aws/whats-new/2025/07/model-context-protocol-server-price-list/) Chainguard builds a market, everyone else wants in. (https://redmonk.com/jgovernor/2025/07/18/chainguard-builds-a-market-everyone-else-wants-in/) Bitnami Secure Images (https://github.com/bitnami/charts/issues/35164) Relevant to your Interests Browser extensions turn Trojan and infect 2.3 million Chrome and Edge users (https://cybernews.com/security/chrome-edge-hijacked-by-eighteen-malicious-extensions/) Code was the least interesting part of my multi-agent app, and here's what that means to me (https://seroter.com/2025/07/17/code-was-the-least-interesting-part-of-my-multi-agent-app-and-heres-what-that-means-to-me/) Dell employees are not OK (https://www.yahoo.com/news/dell-employees-not-ok-135038218.html) How Uber Became A Cash-Generating Machine (https://len-sherman.medium.com/how-uber-became-a-cash-generating-machine-ef78e7a97230) Clouded Judgement 7.18.25 - The Return of the Point Solution (https://cloudedjudgement.substack.com/p/clouded-judgement-71825-the-return?utm_source=post-email-title&publication_id=56878&post_id=168595292&utm_campaign=email-post-title&isFreemail=true&r=2l9&triedRedirect=true&utm_medium=email) Mid-Year 2025 CNCF Open Source Project Velocity (https://www.cncf.io/blog/2025/07/18/a-mid-year-2025-look-at-cncf-linux-foundation-and-the-top-30-open-source-projects/) new Date("wtf") (https://jsdate.wtf/) Intel axes Clear Linux, the fastest distribution on the market — company ends support, effective immediately (https://www.tomshardware.com/software/linux/intel-axes-clear-linux-the-fastest-distribution-on-the-market-company-ends-support-effective-immediately) The Epic Battle for AI Talent—With Exploding Offers, Secret Deals and Tears (https://www.wsj.com/tech/ai/meta-ai-recruiting-mark-zuckerberg-sam-altman-140d5861?st=pBmtib&reflink=article_copyURL_share) Cursor snaps up enterprise startup Koala in challenge to GitHub Copilot (https://techcrunch.com/2025/07/18/cursor-snaps-up-enterprise-startup-koala-in-challenge-to-github-copilot/) Lovable becomes a unicorn with $200M Series A just 8 months after launch (https://techcrunch.com/2025/07/17/lovable-becomes-a-unicorn-with-200m-series-a-just-8-months-after-launch/) Apple details how it trained its new AI models, see highlights (https://9to5mac.com/2025/07/21/apple-details-how-it-trained-its-new-ai-models-4-interesting-highlights/) Instacart's former CEO is taking the reins of a big chunk of OpenAI (https://www.theverge.com/openai/710836/instacarts-former-ceo-is-taking-the-reins-of-a-big-chunk-of-openai) The Enshittification of American Power (https://www.wired.com/story/enshittification-of-american-power/) Customer guidance for SharePoint vulnerability CVE-2025-53770 (https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/) Mike Lynch's Estate Ordered to Pay Hewlett Packard $945 Million (https://www.nytimes.com/2025/07/22/business/dealbook/mike-lynch-hp.html) OpenAI announces ChatGPT agent for web browsing (https://mashable.com/article/openai-announces-chatgpt-agent-web-browsing) OpenAI's new ChatGPT Agent can control an entire computer and do tasks for you (https://www.theverge.com/ai-artificial-intelligence/709158/openai-new-release-chatgpt-agent-operator-deep-research) ChatGPT Numbers (https://www.threads.com/@axios/post/DMXssSjuHax?xmt=AQF0UNyFv8CGZkBsSBbi7XWeXnW67U-Y-ZWQEwDod8lyhA) Move Mesos to the Attic (https://lists.apache.org/list.html?dev@mesos.apache.org) Anthropic hired back two of its employees — just two weeks after they left for a competitor. (https://www.theverge.com/ai-artificial-intelligence/708521/anthropic-hired-back-two-of-its-employees-just-two-weeks-after-they-left-for-a-competitor) Investors Float Deal Valuing Anthropic at More Than $100 Billion (https://www.theinformation.com/articles/investors-float-deal-valuing-anthropic-100-billion) Nonsense Coldplay's Kiss Cam Exposes Astronomer's CEO Andy Byron Alleged Affair With HR Chief Kristin Cabot (https://www.yahoo.com/entertainment/articles/coldplay-kiss-cam-exposes-astronomer-142620411.html) Unicode's new emoji refuses to put respect on Bigfoot's name (https://www.engadget.com/mobile/unicodes-new-emoji-refuses-to-put-respect-on-bigfoots-name-184412935.html) Atari Is Re-Releasing Its 2600+ To Celebrate Pac-Man's 45th Birthday (https://www.timeextension.com/news/2025/07/atari-is-re-releasing-its-2600plus-to-celebrate-pac-mans-45th-birthday) Conferences Sydney Wizdom Meet-Up (https://www.wiz.io/events/sydney-wizdom-meet-up-aug-2025), Sydney, August 7. Matt will be there. SpringOne (https://www.vmware.com/explore/us/springone?utm_source=organic&utm_medium=social&utm_campaign=cote), Las Vegas, August 25th to 28th, 2025. See Coté's pitch (https://www.youtube.com/watch?v=f_xOudsmUmk). Explore 2025 US (https://www.vmware.com/explore/us?utm_source=organic&utm_medium=social&utm_campaign=cote), Las Vegas, August 25th to 28th, 2025. See Coté's pitch (https://www.youtube.com/shorts/-COoeIJcFN4). Wiz Capture the Flag (https://www.wiz.io/events/capture-the-flag-brisbane-august-2025), Brisbane, August 26. Matt will be there. SREDay London (https://sreday.com/2025-london-q3/), Coté speaking, September 18th and 19th. Civo Navigate London (https://www.civo.com/navigate/london/2025), Coté speaking, September 30th. Texas Linux Fest (https://2025.texaslinuxfest.org), Austin, October 3rd to 4th. CFP closes August 3rd (https://www.papercall.io/txlf2025). CF Day EU (https://events.linuxfoundation.org/cloud-foundry-day-europe/), Frankfurt, October 7th, 2025. AI for the Rest of Us (https://aifortherestofus.live/london-2025), Coté speaking, October 15th to 16th, London. SDT News & Community Join our Slack community (https://softwaredefinedtalk.slack.com/join/shared_invite/zt-1hn55iv5d-UTfN7mVX1D9D5ExRt3ZJYQ#/shared-invite/email) Email the show: questions@softwaredefinedtalk.com (mailto:questions@softwaredefinedtalk.com) Free stickers: Email your address to stickers@softwaredefinedtalk.com (mailto:stickers@softwaredefinedtalk.com) Follow us on social media: Twitter (https://twitter.com/softwaredeftalk), Threads (https://www.threads.net/@softwaredefinedtalk), Mastodon (https://hachyderm.io/@softwaredefinedtalk), LinkedIn (https://www.linkedin.com/company/software-defined-talk/), BlueSky (https://bsky.app/profile/softwaredefinedtalk.com) Watch us on: Twitch (https://www.twitch.tv/sdtpodcast), YouTube (https://www.youtube.com/channel/UCi3OJPV6h9tp-hbsGBLGsDQ/featured), Instagram (https://www.instagram.com/softwaredefinedtalk/), TikTok (https://www.tiktok.com/@softwaredefinedtalk) Book offer: Use code SDT for $20 off "Digital WTF" by Coté (https://leanpub.com/digitalwtf/c/sdt) Sponsor the show (https://www.softwaredefinedtalk.com/ads): ads@softwaredefinedtalk.com (mailto:ads@softwaredefinedtalk.com) Recommendations Brandon: Magic Keyboard with Touch ID and Numeric Keypad for Mac (https://www.apple.com/shop/product/MXK83LL/A/magic-keyboard-with-touch-id-and-numeric-keypad-for-mac-models-with-apple-silicon-usb-c-us-english-black-keys?fnode=9586aab2077eb774c28648c4795309d1121a0be316d0cef51e8ecb4f03f94a17a88ca466c99d3d3ce977c5a3933a01e4a9d465d8c36e6a9db43dcd2fdd97c814f69fee0a947209242f7e16f10d07223c5fa2dd831c66ffc4bca1a0c99c10f58ec0b7562aa4f1a834e276771b7ef3bfa8&fs=f%3Dkeyboard%26fh%3D36f4%252B4603) Matt: Spirited (https://www.imdb.com/title/tt1524415/) Photo Credits Header (https://unsplash.com/photos/a-statue-of-a-gorilla-sitting-on-top-of-a-wooden-bench-p9uwu_LDmoc)
Today’s Packet Protector digs into risks and threats you might encounter in a Kubernetes environment, what to do about them, and why sometimes a paved path (or boring technology) is the smartest option. My guest is Natalie Somersall, Principal Solutions Engineer for the Public Sector at Chainguard. We talk about risks including identity and access... Read more »
Today’s Packet Protector digs into risks and threats you might encounter in a Kubernetes environment, what to do about them, and why sometimes a paved path (or boring technology) is the smartest option. My guest is Natalie Somersall, Principal Solutions Engineer for the Public Sector at Chainguard. We talk about risks including identity and access... Read more »
In this episode of The Tech Trek, Amir sits down with Matt Moore, CTO and co-founder of Chainguard, to explore the escalating importance of software supply chain security. From Chainguard's origin story at Google to the systemic risks enterprises face when consuming open source, Matt shares the lessons, best practices, and technical innovations that help make open source software safer and more reliable. The conversation also touches on AI's impact on the attack surface, mitigating threats with engineering rigor, and why avoiding long-lived credentials could be your best defense.
Segment 1: Erik Bloch Interview The math on SOC AI just isn't adding up. It's not easy to do the math, either, as each SOC automation vendor is tackling alert fatigue and SecOps assistants a bit differently. Fortunately for us and our audience, Erik Bloch met with many of these vendors at RSAC and is going to share what he learned with us! Segment 2: Enterprise Weekly News In this week's enterprise security news, 1. Some interesting new companies getting funding 2. Chainguard isn't unique anymore 3. AI slop coming to open source soon 4. Wiz dominance analysis 5. the IKEA effect in cybersecurity 6. LLM model collapse 7. vulnerabilities 8. DFIR reports 9. and fun with LinkedIn and prompt injection! Segment 3: RSAC Interviews runZero Interview with HD Moore Despite becoming a checkbox feature in major product suites, vulnerability management is fundamentally broken. The few remaining first-wave vulnerability scanners long ago shifted their investments and attention into adjacent markets to maintain growth, bolting on fragmented functionality that's added complexity without effectively securing today's attack surfaces. Meanwhile, security teams are left contending with massive blind spots and disparate tools that collectively fail to detect exposures that are commonly exploited by attackers. Our industry is ready for change. Jeff and HD explore the current state of vulnerability management, what's required to truly prevent real-world incidents, new perspectives that are challenging the status quo, and innovative approaches that are finally overcoming decades old problems to usher in a new era of vulnerability management. Segment Resources: Read more about runZero's recent launch, including new exposure management capabilities: https://www.runzero.com/blog/new-era-exposure-management/ Watch a two-minute summary and deeper dive videos here: https://www.youtube.com/@runZeroInc Tune into runZero's monthly research webcast, runZero Hour, to hear about the team's latest research findings and additional debate on all things exposure management: https://www.runzero.com/research/runzero-hour/ Try runZero free for 21 days by visiting https://securityweekly.com/runzerorsac. After 21 days, the trial converts into a free Community Edition license that is great for small environments and home networks. Imprivata interview with Joel Burleson-Davis Organizations in mission-critical industries are acutely aware of the growing cyber threats, like the Medusa ransomware gang attacking critical US sectors, but are wary that implementing stricter security protocols will slow productivity and create new barriers for employees. This is a valid concern, but organizations should not accept the trade-off between the inevitability of a breach by avoiding productivity-dampening security measures, or the drop in employee productivity and rise in frustration caused by implementing security measures that might mitigate a threat like Medusa. In this conversation, Joel will discuss how organizations can build a robust security strategy that does not impede productivity. He will highlight how Imprivata's partnership with SailPoint enables stronger enterprise identity security while enhancing efficiency—helping organizations strike the right balance. This segment is sponsored by Imprivata. Visit https://securityweekly.com/imprivatarsac to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-408
Segment 1: Erik Bloch Interview The math on SOC AI just isn't adding up. It's not easy to do the math, either, as each SOC automation vendor is tackling alert fatigue and SecOps assistants a bit differently. Fortunately for us and our audience, Erik Bloch met with many of these vendors at RSAC and is going to share what he learned with us! Segment 2: Enterprise Weekly News In this week's enterprise security news, 1. Some interesting new companies getting funding 2. Chainguard isn't unique anymore 3. AI slop coming to open source soon 4. Wiz dominance analysis 5. the IKEA effect in cybersecurity 6. LLM model collapse 7. vulnerabilities 8. DFIR reports 9. and fun with LinkedIn and prompt injection! Segment 3: RSAC Interviews runZero Interview with HD Moore Despite becoming a checkbox feature in major product suites, vulnerability management is fundamentally broken. The few remaining first-wave vulnerability scanners long ago shifted their investments and attention into adjacent markets to maintain growth, bolting on fragmented functionality that's added complexity without effectively securing today's attack surfaces. Meanwhile, security teams are left contending with massive blind spots and disparate tools that collectively fail to detect exposures that are commonly exploited by attackers. Our industry is ready for change. Jeff and HD explore the current state of vulnerability management, what's required to truly prevent real-world incidents, new perspectives that are challenging the status quo, and innovative approaches that are finally overcoming decades old problems to usher in a new era of vulnerability management. Segment Resources: Read more about runZero's recent launch, including new exposure management capabilities: https://www.runzero.com/blog/new-era-exposure-management/ Watch a two-minute summary and deeper dive videos here: https://www.youtube.com/@runZeroInc Tune into runZero's monthly research webcast, runZero Hour, to hear about the team's latest research findings and additional debate on all things exposure management: https://www.runzero.com/research/runzero-hour/ Try runZero free for 21 days by visiting https://securityweekly.com/runzerorsac. After 21 days, the trial converts into a free Community Edition license that is great for small environments and home networks. Imprivata interview with Joel Burleson-Davis Organizations in mission-critical industries are acutely aware of the growing cyber threats, like the Medusa ransomware gang attacking critical US sectors, but are wary that implementing stricter security protocols will slow productivity and create new barriers for employees. This is a valid concern, but organizations should not accept the trade-off between the inevitability of a breach by avoiding productivity-dampening security measures, or the drop in employee productivity and rise in frustration caused by implementing security measures that might mitigate a threat like Medusa. In this conversation, Joel will discuss how organizations can build a robust security strategy that does not impede productivity. He will highlight how Imprivata's partnership with SailPoint enables stronger enterprise identity security while enhancing efficiency—helping organizations strike the right balance. This segment is sponsored by Imprivata. Visit https://securityweekly.com/imprivatarsac to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-408
Segment 1: Erik Bloch Interview The math on SOC AI just isn't adding up. It's not easy to do the math, either, as each SOC automation vendor is tackling alert fatigue and SecOps assistants a bit differently. Fortunately for us and our audience, Erik Bloch met with many of these vendors at RSAC and is going to share what he learned with us! Segment 2: Enterprise Weekly News In this week's enterprise security news, 1. Some interesting new companies getting funding 2. Chainguard isn't unique anymore 3. AI slop coming to open source soon 4. Wiz dominance analysis 5. the IKEA effect in cybersecurity 6. LLM model collapse 7. vulnerabilities 8. DFIR reports 9. and fun with LinkedIn and prompt injection! Segment 3: RSAC Interviews runZero Interview with HD Moore Despite becoming a checkbox feature in major product suites, vulnerability management is fundamentally broken. The few remaining first-wave vulnerability scanners long ago shifted their investments and attention into adjacent markets to maintain growth, bolting on fragmented functionality that's added complexity without effectively securing today's attack surfaces. Meanwhile, security teams are left contending with massive blind spots and disparate tools that collectively fail to detect exposures that are commonly exploited by attackers. Our industry is ready for change. Jeff and HD explore the current state of vulnerability management, what's required to truly prevent real-world incidents, new perspectives that are challenging the status quo, and innovative approaches that are finally overcoming decades old problems to usher in a new era of vulnerability management. Segment Resources: Read more about runZero's recent launch, including new exposure management capabilities: https://www.runzero.com/blog/new-era-exposure-management/ Watch a two-minute summary and deeper dive videos here: https://www.youtube.com/@runZeroInc Tune into runZero's monthly research webcast, runZero Hour, to hear about the team's latest research findings and additional debate on all things exposure management: https://www.runzero.com/research/runzero-hour/ Try runZero free for 21 days by visiting https://securityweekly.com/runzerorsac. After 21 days, the trial converts into a free Community Edition license that is great for small environments and home networks. Imprivata interview with Joel Burleson-Davis Organizations in mission-critical industries are acutely aware of the growing cyber threats, like the Medusa ransomware gang attacking critical US sectors, but are wary that implementing stricter security protocols will slow productivity and create new barriers for employees. This is a valid concern, but organizations should not accept the trade-off between the inevitability of a breach by avoiding productivity-dampening security measures, or the drop in employee productivity and rise in frustration caused by implementing security measures that might mitigate a threat like Medusa. In this conversation, Joel will discuss how organizations can build a robust security strategy that does not impede productivity. He will highlight how Imprivata's partnership with SailPoint enables stronger enterprise identity security while enhancing efficiency—helping organizations strike the right balance. This segment is sponsored by Imprivata. Visit https://securityweekly.com/imprivatarsac to learn more about them! Show Notes: https://securityweekly.com/esw-408
Segment 1: Erik Bloch Interview The math on SOC AI just isn't adding up. It's not easy to do the math, either, as each SOC automation vendor is tackling alert fatigue and SecOps assistants a bit differently. Fortunately for us and our audience, Erik Bloch met with many of these vendors at RSAC and is going to share what he learned with us! Segment 2: Enterprise Weekly News In this week's enterprise security news, 1. Some interesting new companies getting funding 2. Chainguard isn't unique anymore 3. AI slop coming to open source soon 4. Wiz dominance analysis 5. the IKEA effect in cybersecurity 6. LLM model collapse 7. vulnerabilities 8. DFIR reports 9. and fun with LinkedIn and prompt injection! Segment 3: RSAC Interviews runZero Interview with HD Moore Despite becoming a checkbox feature in major product suites, vulnerability management is fundamentally broken. The few remaining first-wave vulnerability scanners long ago shifted their investments and attention into adjacent markets to maintain growth, bolting on fragmented functionality that's added complexity without effectively securing today's attack surfaces. Meanwhile, security teams are left contending with massive blind spots and disparate tools that collectively fail to detect exposures that are commonly exploited by attackers. Our industry is ready for change. Jeff and HD explore the current state of vulnerability management, what's required to truly prevent real-world incidents, new perspectives that are challenging the status quo, and innovative approaches that are finally overcoming decades old problems to usher in a new era of vulnerability management. Segment Resources: Read more about runZero's recent launch, including new exposure management capabilities: https://www.runzero.com/blog/new-era-exposure-management/ Watch a two-minute summary and deeper dive videos here: https://www.youtube.com/@runZeroInc Tune into runZero's monthly research webcast, runZero Hour, to hear about the team's latest research findings and additional debate on all things exposure management: https://www.runzero.com/research/runzero-hour/ Try runZero free for 21 days by visiting https://securityweekly.com/runzerorsac. After 21 days, the trial converts into a free Community Edition license that is great for small environments and home networks. Imprivata interview with Joel Burleson-Davis Organizations in mission-critical industries are acutely aware of the growing cyber threats, like the Medusa ransomware gang attacking critical US sectors, but are wary that implementing stricter security protocols will slow productivity and create new barriers for employees. This is a valid concern, but organizations should not accept the trade-off between the inevitability of a breach by avoiding productivity-dampening security measures, or the drop in employee productivity and rise in frustration caused by implementing security measures that might mitigate a threat like Medusa. In this conversation, Joel will discuss how organizations can build a robust security strategy that does not impede productivity. He will highlight how Imprivata's partnership with SailPoint enables stronger enterprise identity security while enhancing efficiency—helping organizations strike the right balance. This segment is sponsored by Imprivata. Visit https://securityweekly.com/imprivatarsac to learn more about them! Show Notes: https://securityweekly.com/esw-408
On this week’s GeekWire Podcast: Microsoft sees a future where humans manage fleets of AI agents — promising to fundamentally change the way companies are run and work gets done. Plus, we dive into the story of Chainguard, the $3.5 billion cybersecurity startup proving that a fully remote company can scale fast without a physical office. And we explore how AI is reshaping everyday life, from travel planning to home repairs. Related stories Meet your new AI teammate: Microsoft sees humans as ‘agent bosses,’ upending the workplace: Microsoft’s 2025 Work Trend Index envisions a future where employees manage AI agents, fundamentally reshaping organizational structures. Chainguard doesn’t have an office. Here’s how the $3.5B cybersecurity startup makes remote work: A look at how Chainguard successfully operates as a fully remote company, including intentional communication and periodic in-person gatherings. With GeekWire co-founder Todd Bishop and editor Taylor Soper. Edited by Curt Milton.See omnystudio.com/listener for privacy information.
Dan Lorenc is the Co-founder and CEO of Chainguard, the safe source for open source.The internet runs on free, open source software. But as its risen in popularity, its become the latest attack point targeted by hackers and nation states.This conversation with Dan gets into the history of open source software, cloud computing, Linux, the software supply chain, how AI will impact it, and what the next big cyber attack will look like.Dan is an engineer, but he also loves sales and go-to-market. We unpack how Chainguard went from zero to 150 customers and a $40m ARR in two years.Chainguard just announced a $350 million Series D led by Kleiner and IVP, and Dan unpacks the round, plus shares his secret methodology for valuing the company.A big thank you to Dan's Co-founder Kim Lewandowski, to Clay Fischer @ Spark, Bogomil Balkansky & Andrew Reed @ Sequoia, and Tom Loverro @ IVP for their help brainstorming topics for Dan.Thanks to Numeral for supporting this episode, the end-to-end platform for sales tax and compliance. Try it here: https://bit.ly/NumeralThePeelTimestamps:(3:26) A safe source for open source(4:57) The software supply chain(7:19) Can you trust open source code with contributors in Russia?(9:43) Malware attack that almost took down the entire internet(12:40) What the next big cyber attack will look like(15:12) How will AI impact the software supply chain(17:53) The history of cloud computing(21:42) Why all cloud computing runs on Linux(23:16) How Linux + Linux distros work(29:28) Automating open source security(32:43) Chainguard roadmap: Libraries and VMs(36:40) Focusing on FedRAMP(42:44) Impact of DOGE(44:06) Zero to $40m ARR in two years(45:40) Learning to love sales as a technical founder(47:24) Lessons from Frank Slootman(51:15) How to create urgency in sales(53:16) How to build a sales team(58:23) Hiring Ryan Carlson from Wiz & Okta(1:01:45) Inside Chainguard's $350m Series D(1:07:41) Vibe coding + Dan's software stack(1:09:51) Cutting his hair in front of the entire company(1:10:27) Wearing a different suit to each board meeting(1:12:32) Bogomil, world's best SDRReferencedCheck out Chainguard: https://www.chainguard.dev/Jobs at Chainguard: https://www.chainguard.dev/careersPrior episode with Dan: https://www.youtube.com/watch?v=AC4cOJ9n_Z8Linux Origin Email: https://www.reddit.com/r/linux/comments/mmmlh3/linux_has_a_interested_history_this_is_one_of/The Qualified Sales Leader: https://www.amazon.com/Qualified-Sales-Leader-Proven-Lessons/dp/0578895064Julius, AI data analysis: https://julius.ai/Claude Code: https://www.anthropic.com/claude-codeWorld's best SDR: https://x.com/BogieBalkansky/status/19132697148828143502025 Chainguard Assemble Keynote: https://www.youtube.com/watch?v=adfU9LJg3I0Follow DanTwitter: https://x.com/lorenc_danLinkedIn: https://www.linkedin.com/in/danlorenc/Follow TurnerTwitter: https://twitter.com/TurnerNovakLinkedIn: https://www.linkedin.com/in/turnernovakSubscribe to my newsletter to get every episode + the transcript in your inbox every week: https://www.thespl.it/
Chainguard, a software supply chain security startup, secured $356 million in a Series D funding round, achieving a valuation of $3.5 billion. The funding was co-led by Kleiner Perkins and IVP, with new investors including Salesforce Ventures and Datadog Ventures. The valuation reflects a threefold increase from the previous valuation of $1.12 billion after a $140 million Series C round. Chainguard focuses on secure software development tools, particularly for open-source software, and reported an annual recurring revenue of $40 million, aiming to exceed $100 million by fiscal year 2026. The company has raised a total of $612 million since its founding in 2021. Cybersecurity investment remains strong, with Exaforce recently raising $75 million in a Series A round and total funding for VC-backed cybersecurity startups surpassing $2.7 billion in Q1 2024, a 29% increase from the previous quarter.Learn more on this news visit us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.
In this episode of The New Stack Makers, recorded at KubeCon + CloudNativeCon Europe, Alex Williams speaks with Ville Aikas, Chainguard founder and early Kubernetes contributor. They reflect on the evolution of container security, particularly how early assumptions—like trusting that users would validate container images—proved problematic. Aikas recalls the lack of secure defaults, such as allowing containers to run as root, stemming from the team's internal Google perspective, which led to unrealistic expectations about external security practices.The Kubernetes community has since made strides with governance policies, secure defaults, and standard practices like avoiding long-lived credentials and supporting federated authentication. Aikas founded Chainguard to address the need for trusted, minimal, and verifiable container images—offering zero-CVE images, transparent toolchains, and full SBOMs. This security-first philosophy now extends to virtual machines and Java dependencies via Chainguard Libraries.The discussion also highlights the rising concerns around AI/ML security in Kubernetes, including complex model dependencies, GPU integrations, and potential attack vectors—prompting Chainguard's move toward locked-down AI images.Learn more from The New Stack about Container Security and AIChainguard Takes Aim At Vulnerable Java LibrariesClean Container Images: A Supply Chain Security RevolutionRevolutionizing Offensive Security: A New Era With Agentic AI Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
Are you struggling to implement robust container security at scale without creating friction with your development teams? In this episode, host Ashish Rajan sits down with Cailyn Edwards, Co-Chair of Kubernetes SIG Security and Senior Security Engineer, for a masterclass in practical container security. This episode was recorded LIVE at KubeCon EU, London 2025.In this episode, you'll learn about:Automating Security Effectively: Moving beyond basic vulnerability scanning to implement comprehensive automationBridging the Security-Developer Gap: Strategies for educating developers, building trust, fostering collaboration, and understanding developer use cases instead of just imposing rules.The "Shift Down" Philosophy: Why simply "Shifting Left" isn't enough, and how security teams can proactively provide secure foundations, essentially "Shifting Down."Leveraging Open Source Tools: Practical discussion around tools like Trivy, Kubeaudit, Dependabot, RenovateBot, TruffleHog, Kube-bench, OPA, and more.The Power of Immutable Infrastructure: Exploring the benefits of using minimal, immutable images to drastically reduce patching efforts and enhance security posture.Understanding Real Risks: Discussing the dangers lurking in default configurations and easily exposed APIs/ports in container environments.Getting Leadership Buy-In: The importance of aligning security initiatives with business goals and securing support from leadership.Guest Socials: Cailyn's LinkedinPodcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter - Cloud Security BootCampIf you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity PodcastQuestions asked:(00:00) Intro: Container Security at Scale(01:56) Meet Cailyn Edwards: Kubernetes SIG Security Co-Chair(03:34) Why Container Security Matters: Risks & Exposures Explained(06:21) Automating Container Security: From Scans to Admission Controls(12:19) Essential Container Security Tools (Trivy, OPA, Chainguard & More)(19:35) Overcoming DevSecOps Challenges: Working with Developers(21:31) Proactive Security: Shifting Down, Not Just Left(25:24) Fun Questions with CailynResources spoken about during the interview:Cailyn's talk at KubeCon EU 2025
Emily Long is the co-founder and CEO of Edera, the pioneer of strong workload isolation technology for cloud and AI infrastructure. She places the highest value on people and bringing diverse teams together to build something that is greater than the sum of its parts. Emily is a tactical and strategic leader who’s proven in scaling operations, fostering strong company cultures, and driving strategic execution. She’s also an unapologetic people person who believes in the capacity of humor and human connection to motivate and empower team members to achieve more. Prior to Edera, she was the COO at Chainguard, where she built, scaled, and led core business functions that helped lead the company to its Series C and Unicorn status. Emily also served as Chief Operating & People Officer at Anchore, where she oversaw business operations and sales and spearheaded its DEI initiatives. She’s also held strategic operations roles at LogicMonitor and KPMG. Emily is based in Santa Barbara, California and holds a Bachelor of Science in Business Administration from California Polytechnic State University, San Luis Obispo.See omnystudio.com/listener for privacy information.
Cybersecurity startups are experiencing a significant revenue surge as threats associated with artificial intelligence continue to multiply. Companies like ChainGuard have reported a remarkable seven-fold increase in annualized revenue, reaching approximately $40 million, while Island anticipates its revenue will hit $160 million by the end of the year. The rise in cyber attacks, particularly a 138% increase in phishing sites since the launch of ChatGPT, has created a greater demand for cybersecurity solutions. A recent report from Tenable highlights that 91% of organizations have misconfigured AI services, exposing them to potential threats, emphasizing the urgent need for organizations to adopt best practices in cybersecurity.Intel is undergoing a strategic reset under its new CEO, Lip Bu Tan, who announced plans to spin off non-core assets to focus on custom semiconductor development. While the specifics of what constitutes core versus non-core assets remain unclear, this move aims to streamline operations and enhance innovation in the semiconductor space. However, Intel's past struggles with execution raise questions about the effectiveness of this strategy. The company must leverage its strengths while shedding distractions to remain competitive in the evolving semiconductor landscape.Google has made strides in email security by allowing enterprise Gmail users to apply end-to-end encryption, a feature previously limited to larger organizations. This democratization of high-security email comes in response to rising email attacks, enabling users to control their encryption keys and reduce the risk of data interception. Meanwhile, Apple has addressed a significant vulnerability in its iOS 18.2 passwords app that exposed users to phishing attacks, highlighting the importance of rapid response to security flaws.CrowdStrike and SnapLogic are enhancing their partner ecosystems to improve security operations and streamline integration processes. CrowdStrike's new Services Partner program aims to promote the adoption of its next-gen security technology, while SnapLogic's Partner Connect program focuses on collaboration with technology and consulting partners. Additionally, OpenAI has increased its bug bounty program rewards, reflecting the need for ongoing vigilance in cybersecurity as AI becomes more prevalent. The convergence of AI and cybersecurity presents both challenges and opportunities, necessitating proactive measures to safeguard sensitive information. Four things to know today 00:00 Cybersecurity Startups See Revenue Surge as AI Threats Multiply—Are We Prepared?04:44 Intel's Strategic Reset: Spinning Off Non-Core Assets to Boost Custom Chip Development06:09 Google Brings Enterprise-Level Encryption to Gmail as Apple Patches Major iOS Vulnerability08:56 CrowdStrike and SnapLogic Step Up Partnerships While OpenAI Sweetens Bug Bounty Reward Supported by: https://syncromsp.com/ Join Dave April 22nd to learn about Marketing in the AI Era. Signup here: https://hubs.la/Q03dwWqg0 All our Sponsors: https://businessof.tech/sponsors/ Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/ Support the show on Patreon: https://patreon.com/mspradio/ Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com Follow us on:LinkedIn: https://www.linkedin.com/company/28908079/YouTube: https://youtube.com/mspradio/Facebook: https://www.facebook.com/mspradionews/Instagram: https://www.instagram.com/mspradio/TikTok: https://www.tiktok.com/@businessoftechBluesky: https://bsky.app/profile/businessof.tech
Send us a textSubscribe to AG Dillon Pre-IPO Stock Research at agdillon.com/subscribe;- Wednesday = secondary market valuations, revenue multiples, performance, index fact sheets- Saturdays = pre-IPO news and insights, webinar replays00:00 - Intro00:08 - Klarna Plans NYSE IPO at $15B Valuation 01:27 - Applied Intuition in Talks for $15B Valuation 02:36 - Anysphere Eyes $10B Valuation After Rapid ARR Growth 03:11 - Gemini Confidentially Files for IPO 03:55 - CoreWeave Signs $11.9B AI Infrastructure Deal With OpenAI 05:04 - Moveworks Acquired by ServiceNow for $2.85B 05:57 - Chainguard in Talks for $3.5B Valuation 06:31 - OpenAI and Oracle Launch $100B Stargate AI Infrastructure 08:02 - xAI Expands Memphis Data Center to 350K GPUs 08:43 - Anthropic Revenue +40% to $1.4B ARR 09:49 - Binance Secures $2B Investment From MGX 10:46 - TikTok US Deal with Oracle has High Potential
This week we're taking you backstage at TechCrunch Disrupt. Becca Szkutak had the chance to talk with Dan Lorenc, the CEO and co-founder of cybersecurity startup Chainguard following their conversation on stage with prominent investors, The Chainsmokers. They discuss how the EDM duo's venture fund MANTIS went from being viewed skeptically by traditional VCs to becoming a highly sought-after investment partner in the B2B space, how Lorenc scaled the company in a difficult time for cybersecurity, and what value celebrity investors can add to a startup.Check out the full onstage conversation here.00:00 - Introduction02:27 - Chainguard: Company Overview and Open Source Security 05:27 - Google Background and Solar Winds Impact 08:02 - Building Chain Guard: Product Evolution 11:44 - Early Fundraising and Timing 12:53 - The Legendary Alex Pall Cold Emails 15:01 - MANTIS Investment Impact 16:11 - Company Growth and Future Plans 16:51 - Learning from Early Mistakes Found posts every Tuesday. Subscribe on Apple, Spotify or wherever you listen to podcasts to be alerted when new episodes drop. Check out the other TechCrunch podcast: Equity . Subscribe to Found to hear more stories from founders each Connect with us:On TwitterOn InstagramVia email: found@techcrunch.com
RJJ Software's Software Development Service This episode of The Modern .NET Show is supported, in part, by RJJ Software's Podcasting Services, whether your company is looking to elevate its UK operations or reshape its US strategy, we can provide tailored solutions that exceed expectations. Show Notes "Okay. So I'll come on to that point is that's obviously something i'd like to talk about. But a couple of things I should mention, I guess. That I think you're absolutely right with all the points you raised, but we are trying to work on on everything there. So a couple of things are worth pointing out: one is docker-init; so nowadays if you start in like a new project with python or node or whatever, you can run the docker-init command, and what that will do is like create a dockerfile and a couple of other files, I think, to help you get started, and it sort of contains that the best practices. So to try and help you get over the hump of trying to understand how to create a dockerfile, and all the different ways you can build that without needing to know everything. So I think that really helps."—Adrian Mouat Welcome friends to The Modern .NET Show; the premier .NET podcast, focussing entirely on the knowledge, tools, and frameworks that all .NET developers should have in their toolbox. We are the go-to podcast for .NET developers worldwide, and I am your host: Jamie "GaProgMan" Taylor. In this episode, Adrian Mouat joined us to talk about Chainguard, what a distroless container is, a number of tools that you can use to check whether your containers have any CVEs present, attestations and reproducibility, and a number of ways to secure your applications once they are running in the wild. "Yeah, I like your point there about showing your receipts. So in attestations, you can also say things like, you know, “we did do this on this image.” You can create an attestation that says, “hey, I ran a scanner on this image and I had this output at this time.” And because it's all signed, you know that that did happen, if you like. Yeah, and also like, you know, you could have an attestation that said, “I ran these tests on this image at this time and this was the output,” sort of thing. So it's sort of proving that certain steps were taken."— Adrian Mouat Anyway, without further ado, let's sit back, open up a terminal, type in `dotnet new podcast` and we'll dive into the core of Modern .NET. Supporting the Show If you find this episode useful in any way, please consider supporting the show by either leaving a review (check our review page for ways to do that), sharing the episode with a friend or colleague, buying the host a coffee, or considering becoming a Patron of the show. Full Show Notes The full show notes, including links to some of the things we discussed and a full transcription of this episode, can be found at: https://dotnetcore.show/season-7/chainguard-and-securing-your-containers-with-adrian-mouat/ Useful Links Chainguard Container Hacks and Fun Images OODA Loop Snyk Grype docker scout the NVD (National Vulnerabilities Database) seccomp Google Distroless project github.com/wolfi-dev SBOMs Attestation Sigstore project edu.chainguard.dev Chainguard's YouTube channel Music created by Mono Memory Music, licensed to RJJ Software for use in The Modern .NET Show Editing and post-production services for this episode were provided (in part) by MB Podcast Services Supporting the show: Leave a rating or review Buy the show a coffee Become a patron Remember to rate and review the show on Apple Podcasts, Podchaser, or wherever you find your podcasts, this will help the show's audience grow. Or you can just share the show with a friend. And don't forget to reach out via our Contact page. We're very interested in your opinion of the show, so please get in touch. You can support the show by making a monthly donation on the show's Patreon page at: https://www.patreon.com/TheDotNetCorePodcast.
This episode is going to piss you off. Most founders struggle to raise their first few million. Many have to bootstrap for years. Even once there's revenue, many get rejected because they're "too early". Dan had dozens of VCs asking to invest before he even quit his job. He raised his first $5M with no deck, no story, and no product idea. All it took was two founders who wanted to build something in the security space. To add fuel to the fire, 6 months after he incorporated, he raised a $50M round from Sequoia... with no revenue!He didn't pitch dozens of VCs. He didn't create a deck. He just spoke to a partner at Sequoia and had a term sheet in 3 days. The reasons are part macro, part team, part market... and part just the insanity that sometimes happens in Startup Land.It's hard to beleive and makes little sense from the outside. But it often works. Chainguard just closed $140M Series C, has 100s of customers and does 8 figures in ARR. Here's how it happened.Why you should listen:Why launching multiple products at once worked for Dan.How to raise from a position of strength to get favourable terms.Why identifying the right markets can be such an important step. Why time to value and leads to fast growth and high close rates.Keywordsstartup, fundraising, product market fit, Sequoia, security, open source, venture capital, entrepreneurship, growth strategies, technology, innovationSend me a message to let me know what you think!
This week on, Defense Unicorns Podcast we welcome Eddie Zaneski, the tech lead for open source here at Defense Unicorns, who takes us through his fascinating career journey from aspiring math teacher to a key player in the tech industry. Eddie shares his experiences transitioning into computer science, his passion for developer relations, and his significant contributions to the Kubernetes project. We dive into the evolution of software deployment, from bare metal servers to virtual machines and containers, and how Kubernetes has become essential in managing large-scale containerized applications. Eddie also reflects on his time at DigitalOcean, Amazon, and ChainGuard, highlighting his work on software supply chain security projects like Protobomb and Sigstore.Our conversation then turns to the security of open-source communities, challenging the misconception that open-source software is less secure than its closed-source counterparts. Eddie discusses the advantages of transparency in open source, using the XZ library's recent security breach as a case study to emphasize the importance of trust and identity verification. We also explore the potential for similar vulnerabilities in closed-source projects and the growing importance of supply chain security measures, including building integrity and software bills of materials (SBOM). The episode concludes with a thought-provoking discussion on the benefits of transparency in open source and whether proprietary software incidents would be as openly shared or understood.Eddie shares his enthusiasm for leveraging government funding to support open-source projects. He expresses his excitement about engaging with soldiers, airmen, and guardians to understand their challenges and explore open-source solutions. We also touch on innovative tools for air-gapped environments, like Zarf, and their applications across various industries. Listen in as Eddie recounts his experiences at Bravo hackathons, the unique challenges faced by developers in constrained environments, and offers valuable career advice for those passionate about open source and software development.Key Quote“There's lots of misconceptions and I'm sure you and I can talk about all of them. One of the big ones is, just. It's less secure, right? that's a massive myth. Open source security is less secure because all the code is in the open and everyone can go find the holes and generally quite the opposite actually, because the code is in the open, everyone can do their own audits and everyone can see what's happening under the covers of the magic box that you usually can't peer into with proprietary software. We have entire teams of like security. So the Kubernetes project is divided up into special interest groups or SIGs. So we have SIGs for security, we have a product security council and committee that is the incident response people for when there is a new CVE or a bug found, and all sorts of different types of things that are just tailored around security.”-Eddie ZaneskiTime Stamps:(00:02) Kubernetes and Open Source Evolution(08:17) Security in Open Source Communities(20:43) Software Bill of Materials for Cybersecurity(24:04) Exploring Defense Unicorns and Open Source(31:43) Navigating Careers in Open Source(42:25) Breaking Barriers in Defense Innovation(46:42) Collaborating for Defense Open SourceLinksConnect with Eddie
Software supply chain attacks exploit interdependencies within software ecosystems. Security in the supply chain is a growing issue, and is particularly important for companies that rely on large numbers of open source dependencies. Chainguard was founded in 2021 and offers tools and secure container images to improve the security of the software supply chain. Matt The post Container Security with Matt Moore appeared first on Software Engineering Daily.
In this special Black Hat edition of the Breaking Badness Cybersecurity Podcast, Part 1 of a 5 Part Series, we dive deep into how artificial intelligence is transforming the cybersecurity landscape. Our guests—Mark Wojtasiak (VP of Product at Vectra AI), Carl Froggett (CIO at Deep Instinct), Dan Fernandez (Staff Product Manager at Chainguard), and Marcus Ludwig (CEO of Ticura)—join us to explore the evolution of Endpoint Detection and Response (EDR), the growing threats posed by generative AI, and the complexities of securing AI in supply chains. With AI becoming a tool for both attackers and defenders, this episode uncovers the ongoing "AI arms race" and highlights the urgent need for a more preventative approach to cybersecurity.
Topics covered in this episode: Dataherald Python's many command-line utilities Distroless Python functools.cache, cachetools, and cachebox Extras Joke Watch on YouTube About the show Sponsored by ScoutAPM: pythonbytes.fm/scout Connect with the hosts Michael: @mkennedy@fosstodon.org Brian: @brianokken@fosstodon.org Show: @pythonbytes@fosstodon.org Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesdays at 10am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Michael #1: Dataherald Interact with your SQL database, Natural Language to SQL using LLMs. Allows you to set up an API from your database that can answer questions in plain English Uses include Allow business users to get insights from the data warehouse without going through a data analyst Enable Q+A from your production DBs inside your SaaS application Create a ChatGPT plug-in from your proprietary data Brian #2: Python's many command-line utilities Trey Hunner Too many to list, but here's some fun ones json.tool - nicely format json data calendar - print the calendar current by default, but you can pass in year and month gzip, ftplib, tarfile, and other unixy things handy on Windows cProfile & pstats Michael #3: Distroless Python via Patrick Smyth What is distroless anyway? These are container images without package managers or shells included. Debugging these images presents some wrinkles (can't just exec into a shell inside the image), but they're a lot more secure. Chainguard, creates low/no CVE distroless images based on our FOSS distroless OS, Wolfi. Some Python use-cases: docker run -it cgr.dev/chainguard/python:latest # The entrypoint is a Python REPL, since no b/a/sh is included docker run -it cgr.dev/chainguard/python:latest-dev # This is their dev version and has pip, bash, apk, etc. Brian #4: functools.cache, cachetools, and cachebox functools cache and lru_cache - built in cachetools - “This module provides various memoizing collections and decorators, including variants of the Python Standard Library's @lru_cache function decorator.” cachebox - “The fastest caching Python library written in Rust” Extras Brian: Python 3.12.4 is out VSCode has some pytest improvements Michael: Time for a bartender alternative, I've switched to Ice. Rocket.chat as an alternative to Slack Joke: CSS Cartoons