Introduction
Kubescape 4.0 marks a major leap forward in Kubernetes security, blending enterprise-grade stability with cutting-edge threat detection. This release introduces AI integration, runtime monitoring, and streamlined architecture to address modern cloud-native challenges. Whether you’re securing AI workloads or optimizing cluster performance, Kubescape 4.0 offers tools to future-proof your infrastructure.
Runtime Threat Detection Reaches General Availability
The crown jewel of Kubescape 4.0 is its General Availability (GA) Runtime Threat Detection. Built on CEL-based rules, this engine provides real-time visibility into:
- System interactions (processes, capabilities, system calls)
- Network and HTTP events
- File system activities
By managing detection rules as Kubernetes CRDs, teams can export alerts to AlertManager, SIEM, or custom webhooks. This architecture ensures scalability for large clusters while maintaining low overhead.
Kubescape Storage Enters Production
Kubescape Storage now operates at GA, leveraging Kubernetes Aggregated APIs to centralize security metadata. This shift:
- Reduces etcd load by isolating Application Profiles, SBOMs, and vulnerability manifests
- Improves performance for high-density clusters
- Enables seamless integration with enterprise monitoring tools
As Amir Malka demonstrated at KubeCon 2025, this design unlocks new capabilities for security teams managing complex environments.
Streamlined Architecture with Enhanced Node-Agent
Kubescape 4.0 simplifies cluster security by:
- Deprecating the intrusive host-sensor DaemonSet
- Merging host-agent functionality into the node-agent
- Establishing direct API communication between components
This change reduces cluster complexity, minimizes privilege escalation risks, and creates a single point of management for security operations.
Securing the AI Era
Empowering AI Security Sidekicks
Kubescape 4.0 introduces a KAgent-native plugin that transforms AI agents into security assistants. Key capabilities include:
- Automated vulnerability scanning for CVEs and RBAC issues
- Real-time remediation guidance
- Runtime observability via ApplicationProfiles and NetworkNeighborhoods
This integration enables AI to analyze security states, identify risks, and recommend fixes—acting as a proactive security partner.
Scanning AI Agent Posture
As AI systems gain autonomy, Kubescape 4.0 ensures their infrastructure is secure. New features include:
- 15 Rego-based controls for KAgent configurations
- Detection of empty security contexts and over-privileged namespaces
- 42 security-critical checks for AI orchestration workflows
These measures prevent AI agents from becoming attack vectors while maintaining compliance with enterprise standards.
Compliance and Industry Standards
Kubescape 4.0 supports:
- CIS Benchmark 1.12 for Vanilla Kubernetes
- CIS Benchmark 1.8 for EKS and AKS
This ensures organizations meet regulatory requirements while adopting modern cloud-native practices.
Community and Adoption
The Kubescape community continues to grow with:
- New maintainer Amir Malka
- Emeritus recognition for David Wertenteil and Craig Box
- Open calls for user stories and adopter contributions
Join the Kubescape community to share use cases, ask questions, and help shape the future of Kubernetes security.
Conclusion
Kubescape 4.0 redefines Kubernetes security by combining runtime threat detection, AI integration, and simplified architecture. Whether you’re securing traditional workloads or AI-native systems, this release provides the tools to build resilient, compliant infrastructure. Start exploring the documentation today to experience enterprise-grade security for your clusters.








