software supply chain security

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort’s new integration with CrowdStrike Falcon Cloud Security targets the gap between vulnerability detection and remediation in Kubernetes environments. By ingesting SBOM and CVE data from Falcon and automating container image hardening, the two vendors aim to close a loop that has historically required significant manual intervention. The integration has particular relevance for federal and defense organizations operating in air-gapped environments.

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap Read More »

Echo Acquires Minimus: Secure-by-Default Market Consolidates

Echo Acquires Minimus: Secure-by-Default Market Consolidates

Echo has acquired key technology assets from Minimus, positioning itself as the first distro-agnostic, secure-by-default software platform. The deal signals market consolidation around two players: Echo and Chainguard. ECI Research data on open source validation and AI compliance friction reveals why this category matters now.

Echo Acquires Minimus: Secure-by-Default Market Consolidates Read More »

Traefik's Distroless Zero Targets Container Attack Surface

Traefik’s Distroless Zero Targets Container Attack Surface

Traefik Labs has announced Distroless Zero, a hardened container model that removes C libraries and system dependencies to eliminate attack surface rather than scan for it. With FIPS 140-3 and EU CRA deadlines arriving this fall, the timing is deliberate. ECI Research data shows software supply chain security is a top investment priority for nearly half of engineering organizations surveyed.

Traefik’s Distroless Zero Targets Container Attack Surface Read More »

SAFE Framework: NVIDIA Proposes AI Cybersecurity Transparency Standard

SAFE Framework: NVIDIA Proposes AI Cybersecurity Transparency Standard

NVIDIA, Cisco, CrowdStrike, and Red Hat have proposed SAFE, a new framework for sharing agentic AI cybersecurity incidents under Linux Foundation governance. The initiative targets a critical gap in AI supply chain security where existing controls have limited reach. ECI Research data shows software supply chain security is already a top investment priority for nearly half of enterprise engineering organizations.

SAFE Framework: NVIDIA Proposes AI Cybersecurity Transparency Standard Read More »

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ has extended its vulnerability management workflow to macOS devices and added ticketing integrations with Zendesk, ServiceNow, and Halo. Three new APIs allow teams to push endpoint, vulnerability, and deployment data into external systems programmatically. The release positions PDQ as a unified endpoint management and security data platform for mixed Windows and macOS environments.

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms Read More »

Cequence Brings Agentic AI Governance Across MCP, API, and LLM

Cequence Brings Agentic AI Governance Across MCP, API, and LLM

Cequence Security has released AI Discovery, API Registry, LLM Registry, and Skill Registry for AI Gateway, alongside upgraded Agent Personas that bind an AI agent’s tools, model, and APIs to a single policy-enforced job description. The approach, which Cequence calls Agentic Zero Trust, is the first to govern MCP, LLM, and API surfaces under a unified agent-bound identity. This research note examines the architectural logic, the competitive stakes, and what it means for enterprise security and development teams.

Cequence Brings Agentic AI Governance Across MCP, API, and LLM Read More »

Codenotary Uses Claude AI to Secure immudb Development

Codenotary Uses Claude AI to Secure immudb Development

Codenotary has been accepted into Anthropic’s Claude for OSS program, deploying AI assistance to accelerate development of immudb, its open source immutable database. The company is using Claude to detect subtle bugs, analyze concurrency issues, and generate regression tests, while maintaining mandatory human review of all code changes. The move positions Codenotary to ship faster at a moment when enterprise demand for software supply chain security infrastructure is near peak.

Codenotary Uses Claude AI to Secure immudb Development Read More »

Eclipse Foundation & OWASP Unite for CRA Open Source Security

Eclipse Foundation & OWASP Unite for CRA Open Source Security

The Eclipse Foundation and OWASP have signed an MOU to strengthen open source security and support EU Cyber Resilience Act compliance. With mandatory reporting obligations taking effect September 11, 2026, the partnership targets SBOM adoption, supply chain security, and maintainer readiness. ECI Research data shows supply chain security is a top-12-month investment priority for nearly half of enterprise respondents.

Eclipse Foundation & OWASP Unite for CRA Open Source Security Read More »

Conifers Resilient Cyber Defense: The AI SOC Built for Frontier Models

Conifers Resilient Cyber Defense: The AI SOC Built for Frontier Models

Conifers has introduced Resilient Cyber Defense, an agentic AI SOC platform that connects threat intelligence, detection engineering, and remediation into a single governed operating loop. The platform claims 99%+ accuracy across nearly 500,000 investigations and reduced median detection-to-containment time to under ten minutes in production. ECI Research data shows AI-assisted development has increased security risk for over 60% of practitioners, making this launch timely.

Conifers Resilient Cyber Defense: The AI SOC Built for Frontier Models Read More »

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security

Traefik Labs has introduced Distro Zero, a hardened container image that ships a single static Go binary with FIPS 140-3 validated cryptography and no C library substrate. The announcement targets regulated enterprises facing the FIPS 140-2 sunset deadline and EU Cyber Resilience Act reporting obligations. Advanced gateway capabilities are unlocked by license on the same binary, eliminating re-validation when requirements grow.

Traefik Distro Zero: Memory-Safe, FIPS 140-3 Gateway Security Read More »