software supply chain security

Cinchy PeriMind: AI Action Governance for Enterprise Trust

Cinchy PeriMind: AI Action Governance for Enterprise Trust

Cinchy has launched PeriMind, an AI governance suite that gives enterprises real-time visibility and policy enforcement over AI agents in production. The product targets the growing gap between AI adoption speed and operational trust. ECI Research data shows AI governance spending is rising, and software supply chain security is a top enterprise investment priority for 2026.

Cinchy PeriMind: AI Action Governance for Enterprise Trust Read More »

Mirantis Earns CNCF Kubernetes AI Conformance for k0s and k0rdent

Mirantis Earns CNCF Kubernetes AI Conformance for k0s and k0rdent

Mirantis has achieved CNCF Certified Kubernetes AI Conformance for both k0s and k0rdent at Kubernetes v1.35, independently validating GPU orchestration, distributed training, and fleet-scale AI operations without proprietary dependencies. The certification provides procurement teams with publicly reproducible evidence in a market crowded with unverifiable vendor claims. ECI Research data shows why this matters: engineering capacity is scarce, AI governance spending is rising, and software supply chain security is a top investment priority for nearly half of enterprises surveyed.

Mirantis Earns CNCF Kubernetes AI Conformance for k0s and k0rdent Read More »

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary has launched a permanently free tier of its AI-powered security platform for AlmaLinux, covering up to 25 machines with full feature access. The offer includes SBOM management, CIS compliance, patch management, and AI agent monitoring. It’s a freemium land-and-expand play targeting lean ops teams with growing AI exposure.

Codenotary Free AI-Powered Linux Security for AlmaLinux Read More »

Cisco Acquires Astrix to Lead Non-Human Identity Security

Cisco Acquires Astrix to Lead Non-Human Identity Security

Cisco has acquired Astrix Security to extend its Cloud Control platform into non-human identity governance for AI agents. The deal addresses a fast-growing attack surface as autonomous agents proliferate across enterprise environments. ECI Research examines the strategic rationale, integration risks, and competitive implications.

Cisco Acquires Astrix to Lead Non-Human Identity Security Read More »

Red Hat Digital Sovereignty & Lightwell: EMEA Analyst Take

Red Hat Digital Sovereignty & Lightwell: EMEA Analyst Take

Red Hat’s EMEA Analyst Update advanced three strategic themes: OpenShift crossing $2B ARR, the GA of Confirmed Sovereign Support for EU customers, and the launch of Project Lightwell, a Red Hat and IBM supply chain security clearinghouse. ECI Research analysis finds the sovereignty and supply chain security plays are structurally durable, backed by regulatory mandates and a €5B engineering commitment to secure 150,000-plus open-source packages.

Red Hat Digital Sovereignty & Lightwell: EMEA Analyst Take Read More »

Recast Bundles Endpoint Patch Management Tools as CVE Surge Hits 341%

Recast Bundles Endpoint Patch Management Tools as CVE Surge Hits 341%

Recast has launched a bundled offering combining endpoint remediation, third-party patching, and hardware lifecycle management in response to a 341% surge in CVEs tracked in the first half of 2026. The announcement reflects a broader shift in enterprise IT: patching is no longer a scheduled task but a continuous operational requirement. ECI Research data shows that most engineering teams spend the vast majority of their time on maintenance rather than innovation, making operational efficiency tools like this bundle a high-priority investment.

Recast Bundles Endpoint Patch Management Tools as CVE Surge Hits 341% Read More »

Argon2 Password Security: Stronger Hashing, Smarter Limits

Argon2 Password Security: Stronger Hashing, Smarter Limits

Specops Software has published research showing Argon2id is 451 million times slower to crack than SHA256, but a $2,100 CPU still outpaces an eight-GPU rig. The findings highlight why stronger hashing must be paired with continuous compromised credential monitoring. ECI Research data shows software supply chain security is a top enterprise investment priority for 2026.

Argon2 Password Security: Stronger Hashing, Smarter Limits Read More »

GitLab 19.2: Agentic DevSecOps Tackles the AI Code Backlog

GitLab 19.2: Agentic DevSecOps Tackles the AI Code Backlog

GitLab 19.2 introduces agentic automation designed to clear the review and security backlog that AI-generated code creates. Key features include Dependency Scanning Auto-Remediation, Security Review Flow, and Custom Flows, all governed by native audit trails and approval gates. ECI Research data shows why this architectural bet aligns with where enterprise engineering pain actually sits.

GitLab 19.2: Agentic DevSecOps Tackles the AI Code Backlog Read More »

Why Standard Software Still Matters in the AI Era | ECI Research

Why Standard Software Still Matters in the AI Era | ECI Research

anynines CEO Julian Fischer argues that AI-generated software feeds on knowledge created by the standard software ecosystem rather than replacing it. ECI Research data shows engineering teams spend most of their time on maintenance, not innovation, making the promise of AI prototyping seductive but incomplete. The vendors that survive will be those who can prove their products contain judgment, accountability, and operational depth that no prompt can reproduce.

Why Standard Software Still Matters in the AI Era | ECI Research Read More »

EU AI Act Compliance: Why Observability Isn't Enough for High-Risk AI

EU AI Act Compliance: Why Observability Isn’t Enough for High-Risk AI

Diagrid’s Catalyst platform addresses two structural gaps in EU AI Act compliance that observability tools leave open: the inability to produce cryptographically verifiable agent records and the absence of runtime authorization controls. Built on the CNCF-graduated Dapr runtime, Catalyst targets the high-risk AI categories where regulatory exposure is greatest. With the compliance deadline extended to December 2027, the procurement window for agentic execution infrastructure is opening now.

EU AI Act Compliance: Why Observability Isn’t Enough for High-Risk AI Read More »