Linux Hardening, Architecture & Isolation
Linux hardening is not the act of enabling every restrictive setting a distribution provides. It is the work of reducing
Read More04-01
Linux hardening is not the act of enabling every restrictive setting a distribution provides. It is the work of reducing
Read MoreLondon, UK – August 25, 2026 – Following our initial collaboration announcement in March 2026, Canonical and Arduino (a subsidiary
Read MoreCode merged for the Linux 7.3 development cycle changes the measured boot evidence produced by the Integrity Measurement Architecture, or
Read MoreA Linux BPF patch posted on August 21, 2026, expands validation for program replacement across cgroup and Linux Security Module
Read MoreA Linux TCP query can touch congestion-control memory after a concurrent BPF update has freed it. Two new use-after-free reports
Read MoreA flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to
Read MoreRecent KVM work exposed a gap between what Linux says a TDX protection supports and what the TDX-specific code actually
Read MoreA flaw in Kata Containers weakened container security in some Confidential Containers deployments. It allowed a malicious host operator to
Read MoreeBPF security is often summarized in one sentence: Linux loads an eBPF program only after the kernel verifier accepts it
Read MoreConfidential computing can protect sensitive workloads even when the cloud host cannot be fully trusted. Confidential virtual machines can shield
Read More