LIVE · cybersecurity feed
Live wire
cloudcritical

The Journey towards Logically Air-Gapped Deployment

Achieve digital autonomy in critical infra with a 'logically air-gapped' model using eBPF, Cilium, and Cisco for secure, compliant cloud-native operations.

zeroday.news · 8d ago

Organizations managing critical infrastructure are increasingly seeking to balance the agility of cloud-native environments with the stringent security and control traditionally associated with physically isolated, or air-gapped, systems. This pursuit is further driven by escalating regulatory pressures from frameworks such as GDPR, NIS2, and DORA, which emphasize digital autonomy.

A proposed "logically air-gapped" governance model aims to address this challenge by extending principles from Data Vault scenarios, as established by AWS and IBM, across an entire application stack and its associated workflows. This model seeks to enable organizations to harness cloud-native benefits while maintaining complete, autonomous, and authoritative governance over their data and infrastructure.

The foundation of this autonomy rests on three core requirements: data residency, ensuring full control over data storage, access, and governing legal frameworks; technological autonomy, mitigating vendor lock-in through open standards and independent infrastructure; and operational autonomy, maintaining the ability to manage digital services independently without third-party interference.

Traditional physical air-gapping is often incompatible with the dynamic nature of modern containerized applications. Consequently, the logical air-gapping approach replaces physical barriers with a robust, software-defined cryptographic perimeter. At the core of this innovation is eBPF (extended Berkeley Packet Filter), a Linux-based technology that provides high-performance, low-impact security and observability at the kernel level, effectively rendering the infrastructure invisible and inaccessible to unauthorized entities.

OpenAI has adopted the Isovalent networking platform, powered by Cilium, as its standard for Kubernetes stacks, demonstrating a concrete application of this approach. This choice provides OpenAI with a unified foundation for managing CNI, IPAM, and L4/L7 filtering, ensuring operational consistency across both cloud and bare-metal environments. Isovalent was acquired by Cisco in 2024.

Cilium leverages eBPF to translate kernel capabilities into an orchestrated platform capable of managing complex data flows, transparent encryption, and network segmentation with high efficiency and scalability. This uniformity is crucial for rapidly scaling organizations, supporting security and compliance by eliminating the need to treat each environment as a siloed networking challenge and streamlining troubleshooting for platform teams. eBPF provides deep, real-time visibility into network traffic and application behavior, enabling granular, dynamic security policy enforcement directly at the kernel level.

The logically air-gapped governance model achieves its full operational potential through Live Protect, a runtime security module. Live Protect elevates protection from the configuration plane to dynamic execution, using eBPF within the kernel to monitor, detect, and mitigate threats in real-time as they attempt to bypass perimeter controls. This transforms the infrastructure into a self-defending environment.

In bare-metal scenarios, the solution extends eBPF capabilities to provide a logically isolated environment, representing the closest digital equivalent to a physical air gap. By eliminating dependency on third-party hypervisors, organizations can achieve total governance through a private control plane and superuser administration functions across the entire application stack. This drastically reduces the attack surface, ensuring that even non-containerized workloads benefit from granular segmentation, secure host networks, and end-to-end protection managed with total autonomy.

Digital autonomy is exercised by shifting network and security control into the operating system kernel. This enables deep observability without modifying source code, which is essential for demonstrating regulatory compliance. Isovalent, through Cilium Enterprise, extends these capabilities with transparent encryption (such as WireGuard or IPsec) and Egress Gateways, which force traffic toward internal checkpoints, preventing unauthorized exfiltration and ensuring sensitive information remains within defined jurisdictions.

Cisco integrates Isovalent's execution power with the governance of Cisco Secure Workload to offer a unified security model covering containerized, virtualized, and bare-metal environments. The integration between Cilium and systems like SPIRE allows the infrastructure to assign unique cryptographic identities to workloads, eliminating dependence on cloud provider proprietary IAM. Furthermore, the integration between Hubble and analytics platforms provides real-time flow mapping, enabling operators to identify bottlenecks or unauthorized connection attempts rapidly, thereby reducing resolution times.

This governance model adheres to established industry standards, including NIST SP 800-210, the Gaia-X trust framework, and ENISA’s EUCS requirements, integrating trusted execution environments as recommended by the Confidential Computing Consortium. Digital autonomy is presented not as a static state, but as a continuous process of control, trust, and resilience. By adopting a "presume breach" mentality and leveraging the combined power of eBPF and Cisco’s governance tools, enterprises can embrace innovation while maintaining the rigorous autonomy required to protect critical infrastructure transparently and scalably.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.