SBOM

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort’s new integration with CrowdStrike Falcon Cloud Security targets the gap between vulnerability detection and remediation in Kubernetes environments. By ingesting SBOM and CVE data from Falcon and automating container image hardening, the two vendors aim to close a loop that has historically required significant manual intervention. The integration has particular relevance for federal and defense organizations operating in air-gapped environments.

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap Read More »

Traefik's Distroless Zero Targets Container Attack Surface

Traefik’s Distroless Zero Targets Container Attack Surface

Traefik Labs has announced Distroless Zero, a hardened container model that removes C libraries and system dependencies to eliminate attack surface rather than scan for it. With FIPS 140-3 and EU CRA deadlines arriving this fall, the timing is deliberate. ECI Research data shows software supply chain security is a top investment priority for nearly half of engineering organizations surveyed.

Traefik’s Distroless Zero Targets Container Attack Surface Read More »

Eclipse Foundation & OWASP Unite for CRA Open Source Security

Eclipse Foundation & OWASP Unite for CRA Open Source Security

The Eclipse Foundation and OWASP have signed an MOU to strengthen open source security and support EU Cyber Resilience Act compliance. With mandatory reporting obligations taking effect September 11, 2026, the partnership targets SBOM adoption, supply chain security, and maintainer readiness. ECI Research data shows supply chain security is a top-12-month investment priority for nearly half of enterprise respondents.

Eclipse Foundation & OWASP Unite for CRA Open Source Security Read More »

The 2026 Artifact Management Enforcement Gap | ECI Research

The 2026 Artifact Management Enforcement Gap | ECI Research

Cloudsmith’s second annual Artifact Management Report finds that AI-generated code has become near-universal, but governance hasn’t kept pace. Three in four organizations generate SBOM data without using it for real-time security enforcement. ECI Research examines what the EU Cyber Resilience Act deadline means for teams still relying on manual remediation.

The 2026 Artifact Management Enforcement Gap | ECI Research Read More »

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary has launched a permanently free tier of its AI-powered security platform for AlmaLinux, covering up to 25 machines with full feature access. The offer includes SBOM management, CIS compliance, patch management, and AI agent monitoring. It’s a freemium land-and-expand play targeting lean ops teams with growing AI exposure.

Codenotary Free AI-Powered Linux Security for AlmaLinux Read More »

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus is opening its entire catalog of near-zero CVE container images for free, with no registration required. ECI Research examines why the move targets the growing asymmetry between AI-accelerated vulnerability discovery and slow remediation, and what it means for enterprise DevSecOps strategy. Signed SBOMs and an agent-ready CLI make this more than a freemium play.

Minimus Opens Free Secure Container Image Catalog | ECI Research Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom has released the largest Spring security update in the framework’s history, introducing commercial-first CVE-only patches and a SLSA Level 3-validated Java supply chain. AI-accelerated threat discovery has broken traditional patching cycles, and Broadcom’s response sets a new benchmark for open source stewardship under commercial cover. ECI Research examines what this means for enterprise risk posture, developer workflows, and the competitive landscape.

Broadcom Bets Big on Spring Ecosystem Security | ECI Research Read More »

SolidRun + Peridio: Closing the Physical AI Deployment Gap

SolidRun + Peridio: Closing the Physical AI Deployment Gap

SolidRun and Peridio have combined purpose-built vision AI hardware with a production-grade OS to address the infrastructure gap between prototype and deployed fleet. The integration delivers atomic OTA updates, SBOM support, and EU Cyber Resilience Act alignment as day-one capabilities. For enterprise buyers, this shifts physical AI deployment from a months-long infrastructure project to a weeks-long integration effort.

SolidRun + Peridio: Closing the Physical AI Deployment Gap Read More »

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM and Red Hat have announced Project Lightwell, a $5 billion initiative pairing 20,000 engineers with AI to secure enterprise open source software at scale. The clearinghouse model targets supply chain vulnerabilities across independent libraries, AI frameworks, and data streaming platforms. ECI Research examines what this means for ITDMs and developers navigating an increasingly fragmented open source security landscape.

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale Read More »