open source security

AI Code Security: Why False Negatives Beat Hallucinations

AI Code Security: Why False Negatives Beat Hallucinations

Sonatype CTO Brian Fox argues that AI coding tools have become more dangerous as they’ve gotten smarter—trading visible hallucinations for silent false negatives that leave vulnerable dependencies undetected. The fix requires grounding AI models in real-time dependency intelligence, not just scanning code after it’s written. ECI Research data confirms AI code governance is the top enterprise security investment priority heading into 2026.

AI Code Security: Why False Negatives Beat Hallucinations Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

IBM's Enterprise AI Push: Google, ServiceNow, Apptio & Red Hat

IBM’s Enterprise AI Push: Google, ServiceNow, Apptio & Red Hat

IBM has launched four interconnected moves spanning a Google Cloud consulting practice, a ServiceNow modernization collaboration, Apptio FinOps AI updates, and a $5 billion open source security commitment with Red Hat. ECI Research analysts break down what the announcements mean for ITDMs and developers navigating enterprise AI deployment. The pattern points toward infrastructure incumbents consolidating control over the agentic AI stack.

IBM’s Enterprise AI Push: Google, ServiceNow, Apptio & Red Hat Read More »

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom has released the largest Spring security update in the framework’s history, introducing commercial-first CVE-only patches and a SLSA Level 3-validated Java supply chain. AI-accelerated threat discovery has broken traditional patching cycles, and Broadcom’s response sets a new benchmark for open source stewardship under commercial cover. ECI Research examines what this means for enterprise risk posture, developer workflows, and the competitive landscape.

Broadcom Bets Big on Spring Ecosystem Security | ECI Research Read More »

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM and Red Hat have announced Project Lightwell, a $5 billion initiative pairing 20,000 engineers with AI to secure enterprise open source software at scale. The clearinghouse model targets supply chain vulnerabilities across independent libraries, AI frameworks, and data streaming platforms. ECI Research examines what this means for ITDMs and developers navigating an increasingly fragmented open source security landscape.

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale Read More »

Mythos and Open Source Security: What the Panic Gets Wrong

Mythos and Open Source Security: What the Panic Gets Wrong

AI-powered vulnerability tool Mythos has sparked alarm across the open source community, but the fear-mongering misses the point. ECI Research breaks down the real risk, the rational response, and why upstream contribution matters more than reactive security spending.

Mythos and Open Source Security: What the Panic Gets Wrong Read More »

KubeCon + CloudNativeCon Europe 2026 Wrap-Up: Sovereignty, Security, and the Shift from AI Experimentation to Production Reality

KubeCon + CloudNativeCon Europe 2026 Wrap-Up: Sovereignty, Security, and the Shift from AI Experimentation to Production Reality

A detailed KubeCon EU 2026 wrap-up covering AI production, sovereignty, platform engineering, open source security, and cloud-native trends.

KubeCon + CloudNativeCon Europe 2026 Wrap-Up: Sovereignty, Security, and the Shift from AI Experimentation to Production Reality Read More »

Open Source Security Becomes a Platform Requirement at KubeCon EU 2026

Open Source Security Becomes a Platform Requirement at KubeCon EU 2026

At KubeCon EU 2026, Minimus positioned open source security as more than a community issue. Between SBOM pressure, software supply chain risk, and the Cyber Resilience Act, enterprises are being pushed to treat dependency visibility and hardened container images as part of baseline security posture.

Open Source Security Becomes a Platform Requirement at KubeCon EU 2026 Read More »