DevSecOps

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security

Traefik Labs has introduced Distro Zero, a hardened container image that ships a single static Go binary with FIPS 140-3 validated cryptography and no C library substrate. The announcement targets regulated enterprises facing the FIPS 140-2 sunset deadline and EU Cyber Resilience Act reporting obligations. Advanced gateway capabilities are unlocked by license on the same binary, eliminating re-validation when requirements grow.

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security Read More »

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI

Checkmarx has launched Fusion, a hybrid scanning architecture that pairs its deterministic AppSec engines with Anthropic’s Claude models via Amazon Bedrock. The product targets regulated enterprises where data residency has blocked AI-powered security adoption. ECI Research data shows nearly two-thirds of practitioners say AI-assisted development has increased security risk, making the timing strategic.

Checkmarx Fusion: Hybrid AppSec Scanning Meets Frontier AI Read More »

The 2026 Artifact Management Enforcement Gap | ECI Research

The 2026 Artifact Management Enforcement Gap | ECI Research

Cloudsmith’s second annual Artifact Management Report finds that AI-generated code has become near-universal, but governance hasn’t kept pace. Three in four organizations generate SBOM data without using it for real-time security enforcement. ECI Research examines what the EU Cyber Resilience Act deadline means for teams still relying on manual remediation.

The 2026 Artifact Management Enforcement Gap | ECI Research Read More »

Act Security Launches $60M Platform to Fix Cloud Access Sprawl

Act Security Launches $60M Platform to Fix Cloud Access Sprawl

Act Security has launched an action-centric cloud security platform backed by $60 million from Team8, Bessemer, and Notable Capital. Rather than surfacing vulnerability findings, the platform removes the access paths that make breaches possible. The announcement arrives as AI agents inherit unused cloud permissions and operate at machine speed inside production environments.

Act Security Launches $60M Platform to Fix Cloud Access Sprawl Read More »

Open Secure AI Alliance: NVIDIA's Bet on Open Cybersecurity

Open Secure AI Alliance: NVIDIA’s Bet on Open Cybersecurity

NVIDIA and more than 40 industry partners have formed the Open Secure AI Alliance, arguing that open AI models and harnesses are essential defensive assets for cybersecurity. The alliance is contributing open agent frameworks, supply chain integrity tools, and zero-trust identity infrastructure to a shared defense stack. ECI Research data shows enterprises already operate in blended open/closed security tooling models, making the alliance’s approach practically relevant today.

Open Secure AI Alliance: NVIDIA’s Bet on Open Cybersecurity Read More »

ServiceNow AI Growth Hits $1B ACV: Q2 2026 Results Analysis

ServiceNow AI Growth Hits $1B ACV: Q2 2026 Results Analysis

ServiceNow reported Q2 2026 results that beat guidance on every key metric, with subscription revenues up 24.5% year-over-year and AI ACV crossing $1 billion. ECI Research analysts examine what the 9x growth in agentic AI production deployments signals for enterprise platform strategy. The analysis covers implications for IT decision-makers consolidating AI spend and developers navigating governance-first architectures.

ServiceNow AI Growth Hits $1B ACV: Q2 2026 Results Analysis Read More »

Kata Containers 4.0: Open Source AI Agent Sandboxing Grows Up

Kata Containers 4.0: Open Source AI Agent Sandboxing Grows Up

Kata Containers 4.0 promotes its Rust-based runtime to default, replacing Go, and positions the project as the open source standard for isolating AI agents in Kubernetes. The release addresses real production risk as nearly two-thirds of organizations report elevated security exposure from AI tooling. Confidential Containers integration broadens the appeal to regulated industries facing data sovereignty requirements.

Kata Containers 4.0: Open Source AI Agent Sandboxing Grows Up Read More »

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary has launched a permanently free tier of its AI-powered security platform for AlmaLinux, covering up to 25 machines with full feature access. The offer includes SBOM management, CIS compliance, patch management, and AI agent monitoring. It’s a freemium land-and-expand play targeting lean ops teams with growing AI exposure.

Codenotary Free AI-Powered Linux Security for AlmaLinux Read More »

Forcepoint AI Data Security: One Platform for the Agentic Enterprise

Forcepoint AI Data Security: One Platform for the Agentic Enterprise

Forcepoint has launched AI Data Security, a platform that unifies data protection and AI governance across autonomous agents, shadow AI, and sanctioned applications. The move targets high-compliance enterprises facing escalating regulatory pressure around AI use. ECI Research data shows rising AI governance budgets and widespread concern that AI-assisted development is increasing security risk.

Forcepoint AI Data Security: One Platform for the Agentic Enterprise Read More »

Yugabyte Meko: Agent-Native Data Infrastructure for Enterprise AI

Yugabyte Meko: Agent-Native Data Infrastructure for Enterprise AI

Yugabyte has launched Meko, an agent-native data infrastructure layer built on YugabyteDB that gives multi-agent AI systems shared memory, reasoning traces, and compliance-ready auditability. The announcement targets the stateless agent problem that most enterprise AI deployments haven’t solved. ECI Research data shows the database scaling constraints and compliance pressures that make this a timely and well-positioned bet.

Yugabyte Meko: Agent-Native Data Infrastructure for Enterprise AI Read More »