<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/application-programming-interface-api"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Application-programming-interface-api ]]></title>
                <link>https://www.itpro.com/uk/tag/application-programming-interface</link>
        <description><![CDATA[ All the latest application-programming-interface-api content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Fri, 28 Nov 2025 10:14:10 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ OpenAI hailed for ‘swift move’ in terminating Mixpanel ties after data breach hits developers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/openai-mixpanel-data-breach-response</link>
                                                                            <description>
                            <![CDATA[ The Mixpanel breach prompted OpenAI to launch a review into its broader supplier ecosystem ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MDQfVCJ8MCJubZ3CYXKfEP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Nov 2025 10:14:10 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Nov 2025 10:14:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:description>                                                            <media:text><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has admitted a <a href="https://www.itpro.com/business-operations/supply-chain-management-scm/361208/supply-chain-cyber-security-breach-impacted">security breach at a third-party supplier</a> exposed customer emails, location information, and “limited analytics data related to some users of the API”.</p><p>The supplier, Mixpanel, provides data analytics services via OpenAI’s developer platform. OpenAI said the platform is used to help “understand product usage” and improve services for its API product, <em>platform.openai.com</em>. </p><p>On 9 November, Mixpanel discovered an attacker gained unauthorized access to systems. They then exfiltrated a dataset containing “limited customer identifiable information and analytics information”.</p><p>A full outline of data exposed, per an <a href="https://openai.com/index/mixpanel-incident/" target="_blank"><u>OpenAI statement</u></a> on the breach, includes:</p><ul><li>Names provided via Mixpanel API accounts</li><li>Email addresses associated with the API account</li><li>“Aproximate course location based on API user browsers” (including city, state, and country)</li><li>Information on operating systems and browsers used to access the API account</li><li>Referring websites associated with the API account</li></ul><p>OpenAI has been keen to stress that the breach only affects developers and not general <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT </a>users. It also said developer credentials – including passwords, payment information, and government IDs – weren’t exposed.</p><p>OpenAI added that it’s currently in the process of notifying those affected by the incident.</p><h2 id="a-swift-response-from-openai">A swift response from OpenAI </h2><p>Upon discovery of the breach, OpenAI said it removed Mixpanel from production services and began a review of affected datasets.</p><p>While the investigation is still ongoing, the company noted it has so far found “no evidence of any effect on systems or data outside Mixpanel’s environment”.</p><p>The company has since terminated its use of the data analytics platform and said it will conduct a review of its broader supplier ecosystem.</p><p>“Trust, security, and privacy are foundational to our products, our organisation, and our mission, OpenAI said in a statement. “We also hold our partners and vendors accountable for the highest bar for security and privacy of their services.” </p><p>Jake Moore, global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>advisor at ESET, commended OpenAI for its “swift move” in alerting users and cutting ties with the supplier. Many organizations try to minimize security incidents and keep them “under the radar”, he said.</p><p>“Companies often fear the aftermath of an attack and presume it will be brand damaging,” Moore commented. “However, openness is now deemed far more important and speed is usually of the essence in making anyone affected aware of the situation.” </p><h2 id="developers-warned-to-remain-vigilant">Developers warned to remain vigilant</h2><p>OpenAI said information exposed in the breach could be used by hackers to carry out future attacks on users and encouraged them to “remain vigilant”. </p><p>These types of warnings are common in the wake of a data breach, according to Moore.</p><p>“Even though the exposed data was low-sensitivity, it could still be misused in the likes of <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques or via phishing attacks because attackers could combine the data such as name, email, even approximate location data to craft convincing fraudulent messages,” he explained.</p><p>“As within the wake of typical data compromises, those affected need to remain vigilant for suspicious emails or other strange communications.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/gartner-says-40-percent-of-enterprises-will-experience-shadow-ai-breaches-by-2030-educating-staff-is-the-key-to-avoiding-disaster">Gartner says 40% of enterprises will experience ‘shadow AI’ breaches by 2030</a></li><li><a href="https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life">AI breaches aren’t just a scare story any more – they’re happening in real life</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/impact-of-asahi-cyber-attack-laid-bare-as-company-confirms-1-5-million-customers-exposed">Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LevelBlue and Akamai are teaming up to launch a managed web application and API protection service ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/levelblue-and-akamai-are-teaming-up-to-launch-a-managed-web-application-and-api-protection-service</link>
                                                                            <description>
                            <![CDATA[ The new Managed WAAP offering aims to help organizations secure their rapidly expanding web app and API ecosystems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">irRMPb6UaNC5Am3kyR95wK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/87BSyCjjR5QVShx4NmwLPF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Aug 2025 11:45:58 +0000</pubDate>                                                                                                                                <updated>Fri, 15 Aug 2025 11:46:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/87BSyCjjR5QVShx4NmwLPF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SaaS security concept imaging showing centralized cloud symbol with orange coloring connecting to different data points. ]]></media:description>                                                            <media:text><![CDATA[SaaS security concept imaging showing centralized cloud symbol with orange coloring connecting to different data points. ]]></media:text>
                                <media:title type="plain"><![CDATA[SaaS security concept imaging showing centralized cloud symbol with orange coloring connecting to different data points. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/87BSyCjjR5QVShx4NmwLPF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>LevelBlue has announced a new strategic partnership with <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>vendor Akamai to provide new managed web application and <a href="https://www.itpro.com/security/api-attacks-are-spiraling-out-of-control">API protection</a> services.</p><p>The new Managed Web Application and API Protection (WAAP) service aims to deliver flexible web app and API protection to help organizations consolidate, simplify, and scale their security.</p><p>Powered by Akamai’s App & API Protector technology, the offering combines next-gen web application firewall (WAF), distributed-denial-of-service (DDoS) mitigation, bot protection, and foundational API security capabilities, backed by LevelBlue’s WAAP Operations team.</p><p>In an announcement, LevelBlue president, Sundhar Annamalai, said the service offers a solution to the complexity, silos, and rising costs of the modern web app and API security landscape.</p><p>“LevelBlue offers an alternative: proven services that consolidate and simplify protections with predictable investment,” he added. “By combining LevelBlue’s operational expertise with Akamai’s proven technology, organizations can stay ahead of evolving threats and create cyber resilience for critical digital capabilities.” </p><h2 id="what-the-partnership-means-for-customers">What the partnership means for customers</h2><p>Available in two tiers, Essential and Advanced, LevelBlue Managed WAAP combines AI-driven threat detection with global threat intelligence to catch anomalies, adapt to new attack vectors, and stay ahead of threats.</p><p>Organizations also benefit from automatic app and API prioritization, automated policy management to drive efficiency and reduce false positives, as well as around-the-clock access to WAAP specialists for support, monitoring, and advisory assistance.</p><p>The release comes as businesses continue to ramp up their use of web apps and APIs as part of their digital-first strategies. </p><p>According to research from Enterprise Strategy Group, the average number of web apps per organization is expected to rise from 145 to over 200 in the next two years, while those with over half their apps using APIs will shoot up from 32% to 80%</p><p>This sharp increase in ecosystem complexity brings fresh security challenges, particularly around app and API deployments and scaling, compounded further by industry staff constraints and skills gaps.</p><p>Rupesh Chokshi, senior vice president and general manager of Akamai’s Application Security Portfolio, said the company saw more than 311 billion web app attacks in 2024 alone. </p><p>“As AI accelerates, threats are harder to spot, and security is tougher to control,” he explained. </p><p>“<a href="https://www.itpro.com/cloud/cloud-computing/akamai-has-high-hopes-for-its-new-gecko-edge-cloud-service-but-can-it-target-competition-with-hyperscalers">Akamai </a>and LevelBlue’s partnership gives customers access to a trusted, reliable team that combines industry-leading technology with the deep operational expertise of one of the world’s largest MSSPs.</p><p>“It’s a powerful combination with a flexible solution that can fast-track organizations to resilient protection and compliance."</p><h3 class="article-body__section" id="section-more-from-channelpro"><span>MORE FROM CHANNELPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/msps-beware-these-two-ransomware-groups-are-ramping-up-attacks-and-have-claimed-hundreds-of-victims">MSPs beware – these two ransomware groups are ramping up attacks </a></li><li><a href="https://www.itpro.com/security/firewalls/sonicwall-launches-new-firewalls-as-part-of-generation-8-refresh">SonicWall launches new firewalls as part of Generation 8 refresh</a></li><li><a href="https://www.itpro.com/business/business-strategy/we-are-helping-organizations-strengthen-their-overall-security-postures-fortinet-hits-major-milestone-as-partner-program-surpasses-400-partners">Fortinet hits major milestone as partner program surpasses 400 partners</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The ultimate guide to getting your killer app off the ground ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/development/how-to-getting-your-killer-app-off-the-ground</link>
                                                                            <description>
                            <![CDATA[ When building software, the process of designing, testing, prototyping, and perfecting your project is never ending ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5Bj8vpnhTVN9nzWfNJDQET</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rdXepjowHHLjJXozgZEmrh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 03 Jun 2023 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Development]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon Spinage ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rdXepjowHHLjJXozgZEmrh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An infinity sign surrounded by graphics that are involved in the software development process]]></media:description>                                                            <media:text><![CDATA[An infinity sign surrounded by graphics that are involved in the software development process]]></media:text>
                                <media:title type="plain"><![CDATA[An infinity sign surrounded by graphics that are involved in the software development process]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rdXepjowHHLjJXozgZEmrh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There are many things to do when <a href="https://www.itpro.com/business-strategy/startups/368921/can-startups-succeed-in-a-recession"><u>starting a company</u></a>. Find desk space, register the company, get a bank account, set up the website, and all the other tasks that require different hats to be worn. If the idiom were reality, hatters and milliners would be present at every startup accelerator. </p><p>You quickly need a product or service to offer your customers. Without this, you won’t be in business for long, unless you already have other revenue streams or your investors or lenders are patient. Funnily enough, they never seem to be. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/startups/368698/investment-starvation-could-stall-startup-innovation">Investment starvation could stall startup innovation</a></p></div></div><p>You’ve probably already thought of an idea already; you think it’s going to change the world for the better, solve someone’s problem, or mitigate someone’s risk – possibly you hope it’ll do all three. So how are you going to get from A to B, where A is nothing but a headful of ideas, and B is a product in someone’s hand being used “in production”?  </p><p>We faced the same challenge when we started a company six years ago, armed only with a couple of laptops and a list of good contacts. You’ll need to work hard on networking throughout your journey – it’s hard to bring a product to life without a lot of help from others. </p><h2 class="article-body__section" id="section-laying-the-groundwork"><span>Laying the groundwork</span></h2><p>We wanted to disrupt existing practices in an area of healthcare research that aims to understand patient outcomes and experiences, outside of clinical trials, in almost any disease area. First, we needed to establish at least an outline “product-market fit”. We knew we had to ask ourselves – and answer – some very searching questions. These include: </p><ul><li>Who are your customers?</li><li>What problem(s) are you trying to solve for them?</li><li>Do your customers even know what problem(s) they have?</li><li>Will customers pay (and continue to pay) for that solution?</li><li>What are they currently doing instead?</li><li>If something already exists, how does it compare?</li><li>How will you measure success?</li><li>What does good look like?</li><li>Are there any early KPIs/OKRs you can use to judge your progress?</li></ul><p>We set out to validate our ideas by working with senior clinicians at The Royal Marsden Hospital in London, one of the world’s leading hospitals dedicated to cancer treatment and research. They helped us understand the contours of patient experience in oncology, many aspects of which extend across other disease areas too. We also ideated at length with industry experts at major pharmaceutical companies to gain insight into the types of evidential gaps they are trying to fill and where our solution could help with that.  </p><p>Finally, we checked the regulatory landscape to understand external constraints such as ethics, pharmacovigilance, <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018"><u>data protection</u></a>, and security requirements. Make sure you know who your key opinion leaders are and then ask as many questions as you can – most people are happy to have a chat over coffee, especially if you aim to improve the way things work in their industry. </p><h2 class="article-body__section" id="section-the-building-phase"><span>The building phase </span></h2><p>With your assumptions challenged and your offer refined, you can move on to a highly creative and productive phase that will shape your product much further and quicker than you have so far. You need to <a href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work"><u>start product iteration</u></a>, which is a cycle of designing, testing, prototyping, and perfecting. Regular inspections and feedback are key to this process; as is listening. Remember the Lean methodology of “think big, act small, fail fast, learn quickly”. </p><p>For this, we created the cheapest, quickest version of the product that we could and got feedback on it as early as possible. This way the cost of “failure” was very low, and we could easily pivot or simply remove functionality and try something new. You can find several ways to create minimally viable versions – wireframing tools help a lot here, but I’ve seen early product ideation done on paper.  </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work">The four major software development lifecycle models</a></p></div></div><p>In our early user testing, we implemented clickable wireframes for mobile devices, which we chose as our initial target form factor. One version was a fully featured prototype that had the feel of a complete app but was built at a fraction of the cost. There are also now <a href="https://www.itpro.com/software/development/367576/low-code-vs-no-code"><u>no-code or low-code solutions</u></a> that go a stage further and provide basic functionality that further blurs the lines between prototype and minimum viable product (MVP). </p><h2 class="article-body__section" id="section-asking-for-feedback"><span>Asking for feedback</span></h2><p>Who should you ask for feedback? It could be anyone: friends, family, and colleagues will all have useful thoughts. All feedback is a gift, and this is one that keeps giving. The best option is to ask your prospective end users.  </p><p>Don’t get too stuck on exactly who to ask. I guarantee the minute the rubber hits the road, you’ll start learning things you didn’t realize, or think were important yet. When we got feedback from people living with an autoimmune condition that caused muscle weakness, particularly in their eyelids, we soon realized it was hard for them to scan up and down a long screen of text or icons – we hadn’t expected that, but now it became obvious. </p><p>We then organized phone calls, online surveys, and even in-person focus groups at venues in London, Paris, and Milan. There are many options where people can take part remotely, even remotely screen and voice-recording to get stream-of-consciousness feedback from users, but in-person testing is still important as the level of insight it provides is great.  </p><h2 class="article-body__section" id="section-choosing-your-priorities"><span>Choosing your priorities </span></h2><p>When you have some feedback, organize it into areas of functionality; let’s call them “epics”, given we’re already considering <a href="https://www.itpro.com/agile-development/28040/what-is-agile-development"><u>an agile approach</u></a>. At this point, you’ll be creating a backlog of product ideas. You can’t really expect your users to tell you which of them will provide the most value; it’s up to you to listen carefully. Find out what they’re doing now: can you imagine them switching from that to using your shiny, new application instead?  </p><p>As part of our discovery, we wanted to know if people track things about their disease already, such as medication, side effects, and treatments. If so, where do they already do that? We found quite a few people using spreadsheets to do this. If you give them your app, is there any friction in moving over to it – how likely is it to happen?  </p><p>You’re often not competing with the things you think you are, such as better features and functionality. Often you’re competing for people’s attention, the span of which is now frighteningly short. Dealing with patients suffering from acute or chronic diseases, we found users already have a lot going on in their lives and spend time managing their condition, treatments, and side effects – we usually couldn’t expect them to spend long using our app too. There are exceptions, such as a group we studied who needed regular blood transfusions which take the best part of a day in the hospital during which they had time to provide feedback. A different consideration here is hospitals are often places with restricted connectivity, which can limit the use of mobile devices. </p><h2 class="article-body__section" id="section-finalizing-your-product-roadmap"><span>Finalizing your product roadmap</span></h2><p>Finally, it’s time to review the backlog and the epics you identified. Try to arrange these into a product roadmap. There is much to cover in product management but this would be a good time to familiarise yourself with two key frameworks. </p><p>First is the Kano Model, which helps us prioritize features on a product roadmap according to the degree to which they will satisfy users. I like this framework because it focuses on user delight while creating the biggest bang for your buck. It also explains why today’s “wow” feature soon becomes expected. </p><p>The other model is the Design Council’s Double Diamond. This encourages you to take a two-stage approach in your thinking; initially divergent exploration, and then convergent focus. It does this across two areas called the problem space and the solution space. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/development/356827/how-to-become-a-developer-a-beginners-guide">How to become a developer: A beginner&apos;s guide</a></p></div></div><p>We’ve used this to great effect as a means of moderating conversations while planning our product roadmap. The idea is to prevent you or your stakeholders from jumping straight to the first solution they can think of. Taking the time to check if you really understand the nature of the problem and brainstorming for several competing solutions sounds like common sense but be prepared to explain the Double Diamond repeatedly on your journey to a successful product. </p><p>As you can see, the process of designing, testing, prototyping, and perfecting is endless but you’ll recognize when you have something good enough.  </p><p>Our first oncology study app was quite basic, but we soon added more functionality. It’s also about removing features. Users had asked us for a feature that found people nearby with a similar stage of disease for support, but it wasn’t used as much as we had hoped. In the end, we withdrew it. Nothing in product management is an exact science and the data and feedback can only tell you so much. Don’t be precious about any of your ideas or assumptions as they will probably all be challenged at some point and your product will usually end up looking quite different when your journey from A arrives at B.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is the Kubernetes security deficit widening? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/is-the-kubernetes-security-deficit-widening</link>
                                                                            <description>
                            <![CDATA[ Kubernetes and containerization are surging in popularity but organizations are worrying over unaddressed cyber security risks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aNK9sV4onxjZ6xhTgkH4AE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BuoUN8B3PAAj4qpKrgtb4S-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Jun 2023 09:15:08 +0000</pubDate>                                                                                                                                <updated>Wed, 21 Jun 2023 10:47:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BuoUN8B3PAAj4qpKrgtb4S-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The steering wheel of a ship made up of binary against a blue background]]></media:description>                                                            <media:text><![CDATA[The steering wheel of a ship made up of binary against a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[The steering wheel of a ship made up of binary against a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BuoUN8B3PAAj4qpKrgtb4S-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Despite Kubernetes adoption soaring in recent years, users are concerned security strategies haven’t kept pace. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">What is Kubernetes</a></p></div></div><p>A significant minority (38%) feel <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>security</u></a> isn’t taken seriously enough, according to Red Hat’s latest <em>State of Kubernetes </em>report, or that investment in containerized operations is inadequate. This is a rise of 7% against the previous year. </p><p>These concerns are affecting the implementation of cloud native technologies, with 67% reporting delaying deployments due to security issues. </p><h2 id="kubernetes-security-pain-points">Kubernetes security pain points</h2><p>Security pain points include tooling around signing and verification according to Jeffrey Sica, principal developer experience engineer at the Cloud Native Computing Foundation (CNCF). “If the solution to a problem is difficult to implement, developers will go out of their way to shift – or not even address – the problem,” he tells <em>ITPro</em>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UHcZNnXqYMrrqYNDz9hpHN" name="Automating application-driven container elasticity_listing.jpg" caption="" alt="Image of warehouse with multiple shelves of containers and pick truck" src="https://cdn.mos.cms.futurecdn.net/UHcZNnXqYMrrqYNDz9hpHN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Automating application-driven container elasticity</strong></p><p class="fancy-box__body-text"><em>For platform and DevOps engineers looking to operationalize speed to market while assuring application performance</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/containers/370420/automating-application-driven-container-elasticity"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Policy is also an issue, not only in terms of enforcement but also definition. “Businesses need some examples or sane defaults to build off of, and it seems there’s somewhere of a gap there,” Sica says. </p><p>More than half of Red Hat’s respondents worry about misconfiguration and vulnerabilities due to <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes’</a> level of customization, while the focus on upgradeability also poses security risks in some people’s eyes. </p><p>One of Kubernete’s guiding principles is backward compatibility and so a default configuration release will never break an existing deployment. This means teams must pay special attention to new security features that may be disabled by default, notes Sandy Carielli, a principal analyst at Forrester. </p><p>She also points to the fact more organizations need to realize Kubernetes security goes far beyond the <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a> itself. “Because Kubernetes security also extends into application security, container security, identity management, and <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a>, security professionals must have basic familiarity with all of them and be able to collaborate across the team,” she adds. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/five-zero-trust-pitfalls-to-avoid">Why zero trust strategies fail</a></p></div></div><p>“Kubernetes is a Venn diagram over security disciplines and organizations can’t confine their discussion of Kubernetes security to just the Kubernetes settings.”</p><p>“At its core, Kubernetes is simply an API that allows the scheduling of containers. In that sense, the attack surface is the API server, or the containers being scheduled by Kubernetes,” continues Sica, who says that as container run times and Kubernetes, itself and defaults, have become more hardened, the focus has moved to the <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1"><u>supply chain</u></a>.</p><h2 id="is-there-a-kubernetes-security-deficit">Is there a Kubernetes security deficit?</h2><p>To some, these issues point to a security deficit, but Sica disagrees, instead pointing out if you compare the Kubernetes security space from 2018 to now, it’s night and day. His view is that there’s never been more effort and focus on security within Kubernetes and the cloud native ecosystem, which is down to adoption and maturity. </p><p>“Five years ago there was a proverbial gold rush to adopt Kubernetes because it was <em>the </em>pattern to follow in application development. People and organizations alike had to go through the growing pains of adopting what was at the time radically new technology.</p><p>“Now that there’s less of a scramble to learn about Kubernetes, there’s a greater focus on the stability of the codebase and creating secure defaults,” he explains. </p><p>There are many examples of how the cloud native community is addressing security concerns. For example, the CNCF instigated a Kubernetes security audit. This raised concerns about network permissions and intra-component communications, which have been – or are in the process of being – resolved by the community. </p><p>In terms of supply chain security, Sica mentions Chainguard has been working closely with the Open Source Security Foundation (Open SSF) in creating extensive tooling for the signing and verification of software artifacts. </p><p>Another large focus in terms of security is extended Berkeley Packet Filter (eBPF). “Notably Sysdig&apos;s Falco project, which can use either a kernel module or eBPF probe to monitor/log any kernel-level calls that a container can make,” says Sica. “This is the next logical step in observing or preventing any privilege escalation or container escapes.” </p><h2 id="strategies-to-boost-kubernetes-security-xa0">Strategies to boost Kubernetes security </h2><p>The majority of organizations with security concerns are taking steps to address them, and are seeking the services of a handful of vendors, which are focusing on some or all aspects of the security challenge.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z5o5av8Qme7nhYwTzVLsuC" name="Everything is connected_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/z5o5av8Qme7nhYwTzVLsuC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Uncovering the ransomware threat from global supply chains</strong></p><p class="fancy-box__body-text"><em>Everything is connected</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370165/uncovering-the-ransomware-threat-from-global-supply-chains"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“I don’t find that security is putting companies off going down this path, or from doing more in this area. They’re carrying on – but with a focus on having secure containers,” says Charlie Winckless, a senior director analyst at Gartner. </p><p>Winckless recommends adopting a tool that validates the security not just of your containers, but your Kubernetes environment – and preferably a single tool that does both. </p><p>He notes a growing number of vendors are moving into this area, with some companies including Sidero Labs and Tigera focusing specifically on container security, while ‘big picture’ cloud security posture management (CSPM) vendors such as Wiz, Aqua, Orca and Palo Alto Networks are adding container security features to their platforms.</p><p>“Some are very much focused on that bigger picture, while others are addressing those micro markets,” he says.</p><iframe width="100%" frameborder="0" allow="encrypted-media" data-lazy-priority="high" data-lazy-src="https://open.spotify.com/embed-podcast/episode/66jzMmxAReZD2rYnsm6P46"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/containers/370050/how-to-reduce-kubernetes-costs">How to reduce Kubernetes costs</a></p></div></div><p>Beyond tapping into the market, organizations can take a number of steps internally to shore up their container security. Winckless’ top tip is to “automate, then automate, and automate some more”. “If you don’t,” he continues, “then trying to keep up with the dynamism of these environments is very difficult.”</p><p>He also recommends validating (and automating that validation) your setup in the same way you’d treat other cloud providers, and in some cases using a managed Kubernetes environment. </p><p>“A lot of people are adopting EKS in Amazon, GKE in Google, AKS in Azure to have something where at least in my underlying Kubernetes environment, some of that security responsibility is delegated to a cloud provider.</p><p>“For the most part – exceptions include choices Microsoft made that led to the <a href="https://www.itpro.com/cloud/microsoft-azure/360825/azure-container-instances-users-urged-to-revoke-privileged-credentials"><u>Azurescape vulnerability</u></a> for example – we still see the large cloud providers able to a do a better job of it than you can.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Forrester Wave API management solutions, Q3 2022 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/development/application-programming-interface-api/369374/the-forrester-wave-api-management</link>
                                                                            <description>
                            <![CDATA[ The 15 providers that matter most and how they stack up ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iEpvkym5jnjBV9JEpjpxEk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hqd9pR8PmHnnrm8oCLzidj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Oct 2022 11:14:26 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Sep 2023 10:41:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ dale.walker@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                <dc:description><![CDATA[ https://cdn.mos.cms.futurecdn.net/JpDGYSnD7yNNModq5jFThm.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hqd9pR8PmHnnrm8oCLzidj-1280-80.jpg">
                                                            <media:credit><![CDATA[IBM]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title, image of contributor, and text]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title, image of contributor, and text]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title, image of contributor, and text]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hqd9pR8PmHnnrm8oCLzidj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A good API strategy is a key foundation for your digital transformation, with APIs optimising customer experiences, creating dynamic, digital ecosystems, and building platform business models.</p><p>In this report you will learn how API Management is critical to driving digital business and how IBM compares with other vendors in the API Management landscape based on current offerings, strategy, and market presence scores.</p><p>Download the report now to learn:</p><ul><li>How each solution measures up and their inclusion criteria</li><li>Strengths and weaknesses of top API management vendors</li><li>The comprehensive set of evaluation criteria</li></ul><p><em>Provided by </em> <strong>IBM</strong></p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49813/ibm-q4-2022-forrester-wave-api-management-solutions-2018-redirect-1?locale=1&p=false&wp=10334"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>