On Thursday 16 January 2025 I spent the evening at the Dutch Kubernetes/Cloud Native Meetup, hosted at the Palo Alto Networks office in Amsterdam. It ran in two halves: a container security talk from the Prisma Cloud team, then a talk on how AI is changing both sides of cyber security. The evening started with pizza.

Settling in before the first talk.
Opening: community and what’s next
The organisers opened with the meetup’s title slide, carrying the Meetup and Cloud Native Computing Foundation logos over an Amsterdam skyline. The next slides covered related events: a Green Software Netherlands meetup, and KubeCon + CloudNativeCon Europe 2025, which was coming up on 1–4 April 2025 in London, along with a community discount code.

The Dutch Kubernetes/Cloud Native Meetup title slide, with the CNCF logo and Amsterdam skyline.
Prisma Cloud: from Dockerfile to running pod
The first talk was “Securing the Container Lifecycle – From Dockerfile to Running Pod in a Kubernetes Cluster” by Milan Krstic and Goran Bogojevic of the Prisma Cloud team at Palo Alto Networks.

Milan Krstic and Goran Bogojevic with the Prisma Cloud title slide.
They started with a slide titled “Application Development: What Did Change?”, a grid covering four decades:
- Development process: Waterfall, then Agile, then DevOps
- Application architecture: monolithic, then N-tier, then microservices
- Deployment and packaging: physical servers, then virtual servers, then containers
- Application infrastructure: data centre, then hosted, then cloud
The core of the talk was one dense diagram, “Securing the Container Lifecycle”. It followed an image from the IDE to the VCS, through CI/CD and the registry, past admission control and into the running cluster. Runtime components like OpenSSL, curl, Go and Alpine sat next to the running workload. The point was that each stage gets its own check, not just one scan at the end.
After that came a live demo. It started from a deliberately suspicious Python app in a GitHub repository: it used Python’s built-in http.server and cloned a repository named “malware”. The demo then moved to the Prisma Cloud console, where the Dashboards, Inventory, Compliance and Alerts views showed the findings, including a CI vulnerability alert.
My take: the lifecycle diagram matches how I explain shift-left security to platform teams. Scanning in CI is necessary but not enough. Admission control and runtime visibility are where a policy actually stops a bad image. The tooling differs (Trivy, Kyverno, Gatekeeper or a commercial platform), but the stages are the same.
AI is everywhere, and so are the attacks
After a break, the second speaker opened with “AI is everywhere”: a slide of big consumer platform logos such as Google, Facebook and Amazon, with the question “But why?”. The next slide was “We are just at the start”.

A full room for the second half of the evening.
A “How it all started” slide featured Nicholas Carlini. Then “How does it look” showed a machine learning lifecycle (preparation, training, operational deployment, output and improvement), with the matching attacks marked on it: poisoning, backdoors, input evasion, membership inference and model stealing.
The talk then split into two lists. How to use AI to attack: advanced phishing, deepfakes, binary obfuscation and botnet command. How to use AI to defend: moving from reactive to proactive, company-owned local LLMs, AI firewalls, and cloud connectors and scanners. An “AI-powered SOC” slide followed, covering vulnerability discovery, risk prioritisation and automated patching.


Attack and defence, one slide each.
The last section went further out: “Quantum computer vs normal computer”, then “Is there any hope left?” with an Alice-and-Bob photon diagram of quantum key distribution, and finally “Combining quantum and neural cryptography”.

Closing on quantum and neural cryptography.
My take: “company-owned local LLMs” was the most practical item on the defence list. Teams that self-host models on their own Kubernetes clusters keep sensitive prompts and logs inside their own boundary. They also take on the same supply chain problem the first talk covered, now for model images and weights.
Wrapping up
Container security and AI security made a good pairing for one evening. The first talk mapped where controls belong in a Kubernetes delivery pipeline. The second showed how much of that pipeline thinking now applies to ML systems too. On the way out I stopped by the Palo Alto Networks sign.

Thanks to Palo Alto Networks for hosting the Dutch Kubernetes/Cloud Native Meetup.

