Session

Poisoning the Well: Security Lessons from Vulnerability Research in Telemetry Pipelines

Observability pipelines are the nervous system of modern cloud-native infrastructure. However, the streaming platforms, vector databases, and log aggregators powering these environments have become high-value targets for threat actors. This session presents a real-world case study centered on security research that uncovered and reported critical vulnerabilities across enterprise streaming architectures and API infrastructures. The presentation explores how systemic architectural misconfigurations can expose data pipelines to severe exploits like DNS rebinding, Server-Side Request Forgery (SSRF), and malicious payload manipulation.

Moving beyond the exploits, the case study provides a detailed account of the remediation and hardening process. Attendees will learn practical strategies for integrating robust DevSecOps practices directly into their observability deployments. The speaker outlines how to enforce secure network boundaries around centralized data stores and utilize open-source tools like Prometheus and Fluentd to actively monitor the pipeline's health, ensuring the integrity of the telemetry stream against malicious exploitation.


Observability Summit Europe 2026, Prague, Czechia

Shuva Jyoti Kar

Palo Alto Networks, Sr Principal Engineer, Network R&D

Bengaluru, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top