<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Cloud Security</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Cloud Security feed</description>
    <item>
      <title>Presentation: Fixing the AI Infra Scale Problem by Stuffing 1M Sandboxes in a Single Server</title>
      <link>https://www.infoq.com/presentations/unikraft-microvm-sandboxes-cloud-scaling/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</link>
      <description>&lt;img src="https://res.infoq.com/presentations/unikraft-microvm-sandboxes-cloud-scaling/en/mediumimage/felipe-huici-medium-1787813506607.jpg"/&gt;&lt;p&gt;Felipe Huici explains how Unikraft achieves millisecond cold boots, stateful scale-to-zero, and extreme density for sandboxing AI workloads. He discusses isolation primitives, Linux kernel optimizations, and snapshotting tricks, demonstrating how to maintain sub-10ms performance at scale while integrating seamlessly into Kubernetes environments with hardware-level security.&lt;/p&gt; &lt;i&gt;By Felipe Huici&lt;/i&gt;</description>
      <category>Performance &amp; Scalability</category>
      <category>Containers</category>
      <category>Transcripts</category>
      <category>QCon London 2026</category>
      <category>Cloud Security</category>
      <category>Virtualization</category>
      <category>Agents</category>
      <category>Kubernetes</category>
      <category>Platform Engineering</category>
      <category>Cloud</category>
      <category>Virtual Machines</category>
      <category>Artificial Intelligence</category>
      <category>Architecture &amp; Design</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>presentation</category>
      <pubDate>Wed, 09 Sep 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/unikraft-microvm-sandboxes-cloud-scaling/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</guid>
      <dc:creator>Felipe Huici</dc:creator>
      <dc:date>2026-09-09T11:00:00Z</dc:date>
      <dc:identifier>/presentations/unikraft-microvm-sandboxes-cloud-scaling/en</dc:identifier>
    </item>
    <item>
      <title>Article: Implementing Chaos Engineering in Financial Payment Systems: Lessons from Enterprise ECS Deployments</title>
      <link>https://www.infoq.com/articles/chaos-engineering-ecs-payments/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</link>
      <description>&lt;img src="https://res.infoq.com/articles/chaos-engineering-ecs-payments/en/headerimage/chaos-engineering-ecs-payments-header-1788254676411.jpg"/&gt;&lt;p&gt;Standard chaos engineering assumes experiments stop cleanly, blast radius is knowable in advance, and production is fair game. Payment systems violate all three. Salim Adedeji describes ECS-specific failure modes from enterprise deployments: a 60-second DNS TTL that produced 93-second failover, retry logic amplifying database load 2.4x, and AZ rebalancing loops that generic tooling misses.&lt;/p&gt; &lt;i&gt;By Salim Adedeji&lt;/i&gt;</description>
      <category>Containers</category>
      <category>Reliability</category>
      <category>Chaos Engineering</category>
      <category>Amazon Web Services</category>
      <category>Site Reliability Engineering</category>
      <category>Financial Applications</category>
      <category>Fault Tolerance</category>
      <category>Compliance</category>
      <category>Cloud</category>
      <category>Architecture &amp; Design</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>article</category>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/chaos-engineering-ecs-payments/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</guid>
      <dc:creator>Salim Adedeji</dc:creator>
      <dc:date>2026-09-08T09:00:00Z</dc:date>
      <dc:identifier>/articles/chaos-engineering-ecs-payments/en</dc:identifier>
    </item>
    <item>
      <title>How Figma Uses AI Agents for Security</title>
      <link>https://www.infoq.com/news/2026/09/figma-security-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/figma-security-agents/en/headerimage/generatedHeaderImage-1787900821229.jpg"/&gt;&lt;p&gt;The engineering team at software company Figma recently documented how they built AI agents to help their security team investigate alerts, search past incidents, check company systems, and even prepare code fixes. The agents learn from previous investigations, reducing repetitive work and helping engineers resolve complex alerts about 70% faster.&lt;/p&gt; &lt;i&gt;By Renato Losio&lt;/i&gt;</description>
      <category>Cloud Security</category>
      <category>Security Assessment</category>
      <category>Agents</category>
      <category>AI Security</category>
      <category>DevSecOps</category>
      <category>Application Security</category>
      <category>DevOps</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Sun, 06 Sep 2026 06:59:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/figma-security-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</guid>
      <dc:creator>Renato Losio</dc:creator>
      <dc:date>2026-09-06T06:59:00Z</dc:date>
      <dc:identifier>/news/2026/09/figma-security-agents/en</dc:identifier>
    </item>
    <item>
      <title>Beyond Zero: Google Publishes Successor to BeyondCorp</title>
      <link>https://www.infoq.com/news/2026/09/google-beyond-zero/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/google-beyond-zero/en/headerimage/generatedHeaderImage-1787655112500.jpg"/&gt;&lt;p&gt;In a recent research paper, Google introduced Beyond Zero, a “security model for the AI era” that extends Zero Trust to autonomous AI agents. The new approach moves access decisions from the application level to individual resources and actions, combining static authorization controls with dynamic AI-driven decisions to enable machine-speed enforcement for humans and agents.&lt;/p&gt; &lt;i&gt;By Renato Losio&lt;/i&gt;</description>
      <category>Cloud Security</category>
      <category>Google Cloud</category>
      <category>AI Security</category>
      <category>Application Security</category>
      <category>Enterprise Architecture</category>
      <category>Architecture &amp; Design</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Sat, 05 Sep 2026 10:40:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/google-beyond-zero/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</guid>
      <dc:creator>Renato Losio</dc:creator>
      <dc:date>2026-09-05T10:40:00Z</dc:date>
      <dc:identifier>/news/2026/09/google-beyond-zero/en</dc:identifier>
    </item>
    <item>
      <title>Article: Eliminating Long-Lived Credentials in GCP with Workload Identity Federation</title>
      <link>https://www.infoq.com/articles/gcp-wif-scale/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</link>
      <description>&lt;img src="https://res.infoq.com/articles/gcp-wif-scale/en/headerimage/gcp-wif-scale-header-1787838950646.jpg"/&gt;&lt;p&gt;Long-lived GCP service account keys are secrets that must be managed forever, are hard to rotate, and are easy to leak. Scaling Workload Identity Federation to 120+ production projects shows why it changes how machine identity is approached entirely: keys are secrets to manage, federated identities are trust relationships configured once, gated by attribute conditions.&lt;/p&gt; &lt;i&gt;By Shijin Nair&lt;/i&gt;</description>
      <category>Authentication</category>
      <category>Cloud Security</category>
      <category>Google Cloud</category>
      <category>DevSecOps</category>
      <category>Cloud</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>article</category>
      <pubDate>Mon, 31 Aug 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/gcp-wif-scale/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Cloud+Security</guid>
      <dc:creator>Shijin Nair</dc:creator>
      <dc:date>2026-08-31T11:00:00Z</dc:date>
      <dc:identifier>/articles/gcp-wif-scale/en</dc:identifier>
    </item>
  </channel>
</rss>
