It's Not a Best Practice If No One Can Follow It: Learning From... Alex Zenla, Edera & John Morello

Presenters Alex Zenla John Morello Source OpenSource SecurityCon NA 2025 Embracing the Future: Making Container Security Effortless and Effective 🚀 Remember the days when containers and Kubernetes felt like cutting-edge wizardry? Well, that era has rapidly transformed into our everyday reality. What was once revolutionary is now commonplace, yet the quest for truly secure containerized environments is far from over. This session dives deep into the fascinating evolution of container security, exploring the bumps we’ve hit and charting a course toward solutions that are not just powerful, but genuinely usable. ...

November 24, 2025 · 6 min

Lightning Talk: Baking a Security Community From Scratch - Helen Woeste

Presenters Helen Woeste Source OpenSource SecurityCon NA 2025 Beyond the Bake-Off: Crafting Thriving Open Source Communities 🚀 Ever dreamt of building a bustling, engaged open source community? It might sound like a daunting task, but what if we told you the secret sauce is surprisingly similar to what goes into a perfect Victoria sponge? Helen Wuesty from the Open Source Technology Improvement Fund (OSTIF) shared some brilliant insights at a recent tech conference, drawing a delightful parallel to the beloved Great British Bake Off. Her “recipe” is all about moving beyond just existing to actively cultivating advocates and fostering deep, meaningful engagement. ...

November 24, 2025 · 4 min

Lightning Talk: Federate, Scale, and Secure: Practical SPIFFE/SPIRE for Containers... Anjali Telang

Presenters Anjali Telang Source OpenSource SecurityCon NA 2025 🚀 Revolutionizing Workload Identity: Your Guide to Production-Ready SPIFFE and SPIRE In the ever-evolving landscape of cloud-native computing, securing what your applications are is just as critical as securing where they are. Gone are the days when network perimeters were enough. Today, workloads, just like users, need verifiable identities. Enter SPIFFE and SPIRE, two CNCF-graduated projects that are set to become the bedrock of your zero-trust strategy. Anjali Tang, a Product Manager for OpenShift specializing in identity and access control, recently shared her deep dive into making these powerful tools production-ready, and we’re here to break it down for you! ✨ ...

November 24, 2025 · 6 min

Panel: Balancing Developer Fre... Adrian Mouat, Cat Morris, Gaurav Saxena, Marcus Eagan & Alex Zenla

Presenters Adrian Mouat Cat Morris Gaurav Saxena Marcus Eagan Alex Zenla Source OpenSource SecurityCon NA 2025 Balancing the Scales: Developer Freedom vs. Security in the Age of Rapid Innovation 🚀 In today’s fast-paced tech world, the buzz around rapid innovation, especially with technologies like containers, is palpable. Developers are empowered to move at lightning speed, achieving feats previously unimaginable. But with this incredible agility comes a perennial challenge: how do we keep our systems secure without stifling that crucial developer freedom? This is the central question that sparked a fascinating discussion at a recent tech conference, and it’s one that resonates deeply with every engineering team out there. ...

November 24, 2025 · 8 min

SAFE-MCP: A Security Framework for AI+MCP (Model Context Protocol) - Frederick Kautz, TestifySec

Presenters Frederick Kautz Source OpenSource SecurityCon NA 2025 Navigating the Frontier: Building Secure Agentic Systems with Safe MCP 🚀 The world of AI is moving at lightning speed, and with the rise of powerful Large Language Models (LLMs) and their ever-expanding toolkits, comes a new frontier of security challenges. How do we ensure these intelligent agents are not only innovative but also safe? This is where Safe MCP steps in, offering a structured and comprehensive approach to mapping risks, threats, and mitigations for these complex systems. ...

November 24, 2025 · 5 min