Application Security

Traefik's Distroless Zero Targets Container Attack Surface

Traefik’s Distroless Zero Targets Container Attack Surface

Traefik Labs has announced Distroless Zero, a hardened container model that removes C libraries and system dependencies to eliminate attack surface rather than scan for it. With FIPS 140-3 and EU CRA deadlines arriving this fall, the timing is deliberate. ECI Research data shows software supply chain security is a top investment priority for nearly half of engineering organizations surveyed.

Traefik’s Distroless Zero Targets Container Attack Surface Read More »

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ has extended its vulnerability management workflow to macOS devices and added ticketing integrations with Zendesk, ServiceNow, and Halo. Three new APIs allow teams to push endpoint, vulnerability, and deployment data into external systems programmatically. The release positions PDQ as a unified endpoint management and security data platform for mixed Windows and macOS environments.

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms Read More »

Cequence Brings Agentic AI Governance Across MCP, API, and LLM

Cequence Brings Agentic AI Governance Across MCP, API, and LLM

Cequence Security has released AI Discovery, API Registry, LLM Registry, and Skill Registry for AI Gateway, alongside upgraded Agent Personas that bind an AI agent’s tools, model, and APIs to a single policy-enforced job description. The approach, which Cequence calls Agentic Zero Trust, is the first to govern MCP, LLM, and API surfaces under a unified agent-bound identity. This research note examines the architectural logic, the competitive stakes, and what it means for enterprise security and development teams.

Cequence Brings Agentic AI Governance Across MCP, API, and LLM Read More »

Crogl's Sovereign AI SOC Agent: Free, On-Prem, No Strings

Crogl’s Sovereign AI SOC Agent

Crogl has released its Enterprise AI SOC Agent as a free download, deployable in minutes within a customer’s own environment including air-gapped networks. The platform automates alert investigation and threat hunting without moving data outside the customer’s perimeter. ECI Research data on constrained engineering capacity and AI-generated security risk helps explain why this architecture is hitting the market at the right moment.

Crogl’s Sovereign AI SOC Agent Read More »

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI

Checkmarx has launched Fusion, a hybrid scanning architecture that pairs its deterministic AppSec engines with Anthropic’s Claude models via Amazon Bedrock. The product targets regulated enterprises where data residency has blocked AI-powered security adoption. ECI Research data shows nearly two-thirds of practitioners say AI-assisted development has increased security risk, making the timing strategic.

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI Read More »

Google Gemini 3.6 Flash: Cheaper, Faster Agentic AI

Google Gemini 3.6 Flash: Cheaper, Faster Agentic AI

Google Cloud has released Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber alongside the CodeMender autonomous vulnerability remediation agent. The releases target the economics of production agentic AI workloads, with 3.6 Flash delivering improved performance at lower token costs than its predecessor. CodeMender, integrated with Wiz, aims to automate the gap between vulnerability discovery and code remediation.

Google Gemini 3.6 Flash: Cheaper, Faster Agentic AI Read More »

AI Code Security: Why False Negatives Beat Hallucinations

AI Code Security: Why False Negatives Beat Hallucinations

Sonatype CTO Brian Fox argues that AI coding tools have become more dangerous as they’ve gotten smarter—trading visible hallucinations for silent false negatives that leave vulnerable dependencies undetected. The fix requires grounding AI models in real-time dependency intelligence, not just scanning code after it’s written. ECI Research data confirms AI code governance is the top enterprise security investment priority heading into 2026.

AI Code Security: Why False Negatives Beat Hallucinations Read More »

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus is opening its entire catalog of near-zero CVE container images for free, with no registration required. ECI Research examines why the move targets the growing asymmetry between AI-accelerated vulnerability discovery and slow remediation, and what it means for enterprise DevSecOps strategy. Signed SBOMs and an agent-ready CLI make this more than a freemium play.

Minimus Opens Free Secure Container Image Catalog | ECI Research Read More »

Cequence Platform 9.0: AI-Native API Security for the Agentic Era

Cequence Platform 9.0: AI-Native API Security for the Agentic Era

Cequence Security has launched Platform 9.0, an AI-native API security release featuring an open MCP server, a built-in AI Assistant, and 250-plus pre-built compliance rules mapped to 25 global frameworks. The release positions Cequence as a composable security capability for agentic enterprise workflows, arriving as AI code governance tops enterprise security investment priorities. ECI Research data shows the compliance and agentic integration gaps this release directly targets.

Cequence Platform 9.0: AI-Native API Security for the Agentic Era Read More »

Baz Planner Targets AI Code Governance at the Source

Baz Planner Targets AI Code Governance at the Source

Baz announced Baz Planner, a pre-code gateway that intercepts AI-generated code at the planning stage to eliminate vulnerabilities before they are written. The company also closed a $9M seed extension, bringing total funding to $17M. ECI Research identifies AI code governance as the top enterprise security investment priority heading into 2026.

Baz Planner Targets AI Code Governance at the Source Read More »