Skip to main content

Blog

Insights, tutorials, and updates on Kubernetes security, AppArmor, and container protection.

Fragnesia Makes Three: Why It Couldn't Touch Workloads Under a Tailored AppArmor Profile Either
TechnicalProduct1 June 2026

Fragnesia Makes Three: Why It Couldn't Touch Workloads Under a Tailored AppArmor Profile Either

Fragnesia (CVE-2026-46300) is the third universal Linux kernel LPE in the Dirty Frag class to land in under two weeks. It abuses the XFRM ESP-in-TCP path to write into the page cache of read-only files with no race condition, and ships with a one-line public exploit. For workloads running under a behaviour-generated AppArmor profile, the surface it needs was never in the allow list. This is the same non-event, a third time. Here's why, and how to confirm your exposure in seconds.

By Hannes UllmanRead more
Shai-Hulud Rides Again: The Bitwarden CLI Compromise and the Cascade We're Now Living In
Technical24 April 2026

Shai-Hulud Rides Again: The Bitwarden CLI Compromise and the Cascade We're Now Living In

On April 22, 2026, @bitwarden/cli@2026.4.0 was published with a credential-stealing payload — via a GitHub Action that was itself compromised in the Checkmarx breach a month earlier. The cascade is not a metaphor; it is the mechanism. Why supply chain velocity is outpacing upstream defences, and why runtime enforcement is the only surface attackers cannot bypass.

By Hannes UllmanRead more
When Trusted Security Tools Turn Against You: The TeamPCP Campaign and Why Runtime Protection Is No Longer Optional
Technical31 March 2026

When Trusted Security Tools Turn Against You: The TeamPCP Campaign and Why Runtime Protection Is No Longer Optional

In March 2026, the threat actor TeamPCP compromised Trivy, KICS, and LiteLLM — turning trusted security tools into credential stealers across thousands of CI/CD pipelines. We break down how the attacks cascaded, why traditional defences failed, and how tailored AppArmor profiles enforce runtime protection that stops compromised components regardless of how they were infected.

By Hannes UllmanRead more
CrackArmor: Our Assessment for Managed Kubernetes Workloads
Technical17 March 2026

CrackArmor: Our Assessment for Managed Kubernetes Workloads

Qualys disclosed nine vulnerabilities in Linux's AppArmor module, collectively named CrackArmor, affecting every distribution shipping AppArmor by default. We break down what this means for managed Kubernetes workloads, assess the real exploitability, and outline what you should do now.

By bifrost teamRead more
1 minute about AppArmor
TechnicalProduct25 September 2025

1 minute about AppArmor

AppArmor is a mandatory access control (MAC) Security Module that restricts the capabilities and permissions of a containerised workload. The permissions are...

By Hannes UllmanRead more
Summer Greetings!
Company News27 June 2025

Summer Greetings!

As summer rolls in, it’s time to take a break and recharge our batteries. We’re grateful for everything we’ve accomplished together this spring! Last week we...

By Yra Olsen ÖbrinkRead more
How to Navigate DORA
ComplianceProduct24 June 2025

How to Navigate DORA

As financial services become increasingly tech-driven, the risks associated with digital systems also grow. Cyberattacks, system failures, and data breaches...

By Yra Olsen ÖbrinkRead more
The Role of LSMs
Technical17 June 2025

The Role of LSMs

Linux powers everything from cloud servers to smart devices. With so much depending on it, robust security is a must, and that’s where Linux Security Modules...

By Bifrost TeamRead more
bifrost at SecurityFest
Events13 June 2025

bifrost at SecurityFest

Last week bifrost attended SecurityFest in Gothenburg! It was two days filled with interesting talks, hallway meetups, fun CTFs, lock-picking, and even some...

By Yra Olsen ÖbrinkRead more
For Developers
Product11 June 2025

For Developers

bifrost integrates in seconds, learns in minutes, and protects at your next release. Just four lines of annotations, that’s all it takes to enable bifrost. No...

By Bifrost TeamRead more
bifrost in Gothenburg
Events29 May 2025

bifrost in Gothenburg

On June 4th and 5th, bifrost security will attend Security Fest in Gothenburg. We look forward to connecting with fellow cybersecurity enthusiasts and...

By Bifrost TeamRead more
For DevSecOps Teams 🔐
Product23 May 2025

For DevSecOps Teams 🔐

Shipping fast is a non-negotiable, but every new service, dependency, and release widens the attack surface. Security is supposed to be integrated, but most...

By Bifrost TeamRead more
Touchdown Helsinki 🇫🇮
Events6 May 2025

Touchdown Helsinki 🇫🇮

The bifrost team has arrived in Finland and we're excited to be at **KCD Helsinki** Attending the event? Swing by our booth or catch us during a coffee break,...

By Bifrost TeamRead more
Product4 May 2025

Want to see bifrost in action?

We’re committed to building a safer Kubernetes ecosystem, where runtime security is proactive, continuous, and automated, not an afterthought. It’s a vision we...

By Bifrost TeamRead more

For DevOps

**For DevOps ⚙️** We get it, DevOps is all about speed, reliability, and efficiency. But security? It often feels like an afterthought. Traditional security...

By Bifrost TeamRead more
KCD Helsinki 🇫🇮
EventsCompany News28 March 2025

KCD Helsinki 🇫🇮

Exciting News! Kubernetes Community Days is coming to Helsinki! 🇫🇮 bifrost security is proud to be a Gold Sponsor of the @Helsinki Kubernetes Community Days,...

By Bifrost TeamRead more
Deep Dive: Visibility
Product26 March 2025

Deep Dive: Visibility

In software management, visibility is significant for understanding and improving performance. Bifrost offers insights into your software’s behaviour, providing...

By Bifrost TeamRead more
Deep dive: Effortless Set-up
Product27 February 2025

Deep dive: Effortless Set-up

Streamlining setup and simplifying access management of software services can significantly reduce the administration of many development teams. Our service is...

By Bifrost TeamRead more
Deep dive: Security Made Simple
Product8 February 2025

Deep dive: Security Made Simple

Many organisations find it challenging to effectively protect their containerised applications in a world of complex cloud security. bifrost is designed with...

By Bifrost TeamRead more
Wrapping up Simplify and Secure
Events7 February 2025

Wrapping up Simplify and Secure

A big thank you to everyone who joined Simplify and Secure – The Future of Infrastructure and DevOps event at Norrsken House! It was great to see the...

By Bifrost TeamRead more
After-CNCF with bifrost
EventsTechnical19 November 2024

After-CNCF with bifrost

The Cloud Native Community Group - Meet up is approaching ☁️ bifrost’s very own CEO and Co-founder @Hannes Ullman is a speaker at the event. Don't miss out on...

By Bifrost TeamRead more
Save the date! 🚀
Events7 November 2024

Save the date! 🚀

We are thrilled to announce that @Hannes Ullman, CEO and Co-Founder of Bifrost Security, will be speaking at the Stockholm @Cloud Native Community Group -...

By Bifrost TeamRead more
ONE conference 2024
Events1 October 2024

ONE conference 2024

Today marks the start of the ONE Conference in The Hague! 🇳🇱 bifrost’s Hannes and Konrad have arrived in the Netherlands and are eager to discuss recent...

By Bifrost TeamRead more
Talos 1.8 is here! 🚀
Technical27 September 2024

Talos 1.8 is here! 🚀

Today we celebrate the newest release of Talos Linux! Talos Linux is Linux reimagined for the kubernetes world. It is designed from the ground up with a...

By Bifrost TeamRead more
TalosCon 2024
Events18 September 2024

TalosCon 2024

Touchdown in London! ✈️ @Hannes and @Konrad from bifrost security are attending TalosCon today. We share their security focus and are happy to have contributed...

By Bifrost TeamRead more

Stay updated

Runtime security thinking and incident analyses, about twice a month.