Kubernetes

Critical Kyverno Vulnerability — CVE-2026-54523

Critical Kyverno Vulnerability — CVE-2026-54523 On July 13, 2026, a critical vulnerability was disclosed in Kyverno, the Kubernetes-native policy engine used broadly across the cloud native ecosystem for policy-as-code enforcement. The vulnerability, tracked as CVE-2026-54523 (GHSA-79gf-7frw-68m9), allows a tenant with permission to create a NamespacedMutatingPolicy…

0

Nirmata Collaborates with Broadcom to Deliver Enterprise Kubernetes Governance for VMware Cloud Foundation

Organizations are rapidly adopting Kubernetes to modernize applications and accelerate software delivery. Yet as Kubernetes deployments grow, maintaining consistent security, compliance, and operational governance across clusters becomes increasingly challenging. Today, we’re excited to announce that Nirmata is working with Broadcom to bring enterprise-grade policy governance…

0

Policy as Code, AI Governance & a Milestone Moment: Nirmata at KubeCon Europe 2026

KubeCon Europe 2026 in Amsterdam made something unmistakably clear. Policy as code is no longer emerging. It is becoming foundational. Across keynote stages, breakout sessions, and co-located events, the industry is converging on a new reality. Infrastructure is no longer static, and increasingly, it is…

0

From Policy Engine to AI-Native Platform: Introducing Cloud Agents for Infrastructure Governance

PRODUCT LAUNCH  Nirmata’s new Cloud Agents give platform engineers a one-click way to run deterministic, LLM-powered diagnostics directly on their clusters — no scripts, no setup, no surprises. When we launched Nirmata, the goal was straightforward: give teams a better way to govern Kubernetes at…

0

Kubernetes nodes/proxy GET → RCE: how “telemetry” permissions can compromise a cluster

A subtle (and frankly surprising) Kubernetes authorization behavior has resurfaced as a practical cluster-compromise path: an identity granted nodes/proxy access with an HTTP Get can be leveraged to execute commands in Pods across the cluster—effectively turning what many teams treat as “read-only node telemetry access”…

0

CNCF Annual Cloud Native Survey 2025: Kubernetes Is Becoming the Default AI Runtime – But “AI Platform Readiness” Is the Real Differentiator

A familiar pattern is playing out again. A decade ago, the big shift wasn’t “containers” themselves—it was everything that had to solidify around them: repeatable delivery, production operations, observability, and guardrails that made change safe, i.e. making everything container-native. Many of us at Nirmata lived…

0