DevSecOps

Stacklet's Autonomous Cloud Governance Play at FinOps X

Stacklet’s Autonomous Cloud Governance Play at FinOps X

Stacklet is expanding its agentic AI layer and AI-resource coverage at FinOps X, positioning its Cloud Custodian policy engine as the enterprise control plane for autonomous cloud governance. The company’s decade of open-source context and proven remediation track record differentiate it in a market where governance tooling mostly produces findings rather than fixes. ECI Research analysis covers what this means for IT decision-makers managing AI cloud spend and for developers navigating AI-generated infrastructure code.

Stacklet’s Autonomous Cloud Governance Play at FinOps X Read More »

AI Governance Compliance: Closing the Gap Before August 2026

AI Governance Compliance: Closing the Gap Before August 2026

Most enterprises are applying security tooling to an AI governance problem, and the mismatch is creating real compliance exposure. With EU AI Act high-risk provisions taking full force in August 2026 and updated HIPAA rules now demanding decision-level evidence, the window to close this gap is narrowing. This note examines what Trussed.ai’s approach means for ITDMs and developers building on agentic architectures.

AI Governance Compliance: Closing the Gap Before August 2026 Read More »

SolidRun + Peridio: Closing the Physical AI Deployment Gap

SolidRun + Peridio: Closing the Physical AI Deployment Gap

SolidRun and Peridio have combined purpose-built vision AI hardware with a production-grade OS to address the infrastructure gap between prototype and deployed fleet. The integration delivers atomic OTA updates, SBOM support, and EU Cyber Resilience Act alignment as day-one capabilities. For enterprise buyers, this shifts physical AI deployment from a months-long infrastructure project to a weeks-long integration effort.

SolidRun + Peridio: Closing the Physical AI Deployment Gap Read More »

Financial Services Faces a Two-Front Cyber Threat in 2026

Financial Services Faces a Two-Front Cyber Threat in 2026

Black Kite’s 2026 State of Financial Services report documents a simultaneous rise in direct ransomware attacks and vendor ecosystem vulnerabilities. Q1 2026 ransomware incidents jumped 76% year-over-year while critical CVEs across finance-concentrated vendors rose 387%. ECI Research examines what this two-front threat means for ITDMs and security teams.

Financial Services Faces a Two-Front Cyber Threat in 2026 Read More »

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM and Red Hat have announced Project Lightwell, a $5 billion initiative pairing 20,000 engineers with AI to secure enterprise open source software at scale. The clearinghouse model targets supply chain vulnerabilities across independent libraries, AI frameworks, and data streaming platforms. ECI Research examines what this means for ITDMs and developers navigating an increasingly fragmented open source security landscape.

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale Read More »

Open Source Summit 2026 wrap-up

Open Source Summit 2026 Wrap-Up: Governance, Sustainability, and the New Reality of Open Innovation

A detailed Open Source Summit 2026 wrap-up covering AI governance, maintainer sustainability, runtime security, open infrastructure, and the future of open innovation.

Open Source Summit 2026 Wrap-Up: Governance, Sustainability, and the New Reality of Open Innovation Read More »

Valkey 9.1: Open Source Database Eyes AI Workloads

Valkey 9.1: Open Source Database Eyes AI Workloads

Valkey 9.1 expands beyond caching with full-text and vector search, per-database access controls, and multithreading improvements. The Linux Foundation project is positioning itself as a consolidated in-memory data platform for AI and modernization workloads. ECI Research examines the competitive implications and what the Valkey 10 roadmap signals for enterprise infrastructure strategy.

Valkey 9.1: Open Source Database Eyes AI Workloads Read More »

Humanix Detects Live Help Desk Procedure Violations | ECI Research

Humanix Detects Live Help Desk Procedure Violations | ECI Research

Humanix has announced the first capability to detect live procedure violations during IT help desk interactions, flagging social engineering attacks at the moment a policy is bypassed. ECI Research analyzes why this human-layer security gap remains underserved and what it means for enterprise security teams. The capability targets the precise window between procedural failure and unauthorized access.

Humanix Detects Live Help Desk Procedure Violations | ECI Research Read More »

Edera at Open Source Summit 2026: Container Runtime Security

Edera at Open Source Summit 2026: Container Runtime Security

At Open Source Summit 2026, Edera made the case that containers were never security boundaries and that runtime isolation is the missing layer in most enterprise security stacks. A new partnership with Minimus pairs rapid patching with runtime protection. ECI Research examines the implications for cloud-native security strategy.

Edera at Open Source Summit 2026: Container Runtime Security Read More »

Google AI Threat Defense: Autonomous Security Arrives | ECI Research

Google AI Threat Defense: Autonomous Security Arrives | ECI Research

Google Cloud has launched Google AI Threat Defense, an autonomous platform designed to prioritize and remediate vulnerabilities faster than attackers can exploit them. ECI Research examines the competitive implications, the developer experience questions, and the governance gaps enterprises must close before deploying autonomous security at scale.

Google AI Threat Defense: Autonomous Security Arrives | ECI Research Read More »