AppSec

Traefik's Distroless Zero Targets Container Attack Surface

Traefik’s Distroless Zero Targets Container Attack Surface

Traefik Labs has announced Distroless Zero, a hardened container model that removes C libraries and system dependencies to eliminate attack surface rather than scan for it. With FIPS 140-3 and EU CRA deadlines arriving this fall, the timing is deliberate. ECI Research data shows software supply chain security is a top investment priority for nearly half of engineering organizations surveyed.

Traefik’s Distroless Zero Targets Container Attack Surface Read More »

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI

Checkmarx has launched Fusion, a hybrid scanning architecture that pairs its deterministic AppSec engines with Anthropic’s Claude models via Amazon Bedrock. The product targets regulated enterprises where data residency has blocked AI-powered security adoption. ECI Research data shows nearly two-thirds of practitioners say AI-assisted development has increased security risk, making the timing strategic.

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI Read More »

Google Gemini 3.6 Flash: Cheaper, Faster Agentic AI

Google Gemini 3.6 Flash: Cheaper, Faster Agentic AI

Google Cloud has released Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber alongside the CodeMender autonomous vulnerability remediation agent. The releases target the economics of production agentic AI workloads, with 3.6 Flash delivering improved performance at lower token costs than its predecessor. CodeMender, integrated with Wiz, aims to automate the gap between vulnerability discovery and code remediation.

Google Gemini 3.6 Flash: Cheaper, Faster Agentic AI Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

Outpost24 Brings AI to DAST Authentication Configuration

Outpost24 Brings AI to DAST Authentication Configuration

Outpost24 has launched AI-powered authentication for its Scale DAST platform, replacing script-based configuration with natural-language instructions executed by an AI agent. The move targets one of the most persistent operational barriers to authenticated scanning at scale. ECI Research analyst coverage examines the business case, competitive implications, and what security and DevSecOps teams should evaluate.

Outpost24 Brings AI to DAST Authentication Configuration Read More »