Vulnerability Management

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary has launched a permanently free tier of its AI-powered security platform for AlmaLinux, covering up to 25 machines with full feature access. The offer includes SBOM management, CIS compliance, patch management, and AI agent monitoring. It’s a freemium land-and-expand play targeting lean ops teams with growing AI exposure.

Codenotary Free AI-Powered Linux Security for AlmaLinux Read More »

Recast Bundles Endpoint Patch Management Tools as CVE Surge Hits 341%

Recast Bundles Endpoint Patch Management Tools as CVE Surge Hits 341%

Recast has launched a bundled offering combining endpoint remediation, third-party patching, and hardware lifecycle management in response to a 341% surge in CVEs tracked in the first half of 2026. The announcement reflects a broader shift in enterprise IT: patching is no longer a scheduled task but a continuous operational requirement. ECI Research data shows that most engineering teams spend the vast majority of their time on maintenance rather than innovation, making operational efficiency tools like this bundle a high-priority investment.

Recast Bundles Endpoint Patch Management Tools as CVE Surge Hits 341% Read More »

PDQ Summer 2026: Endpoint Management Consolidation Arrives

Endpoint Management Consolidation Arrives with PDQ

PDQ’s summer 2026 update adds macOS Package Library support, Windows update visibility, one-click reboots, and a new insights dashboard. ECI Research analysts examine why the consolidation play matters more than the feature list, and what IT decision-makers should watch before committing macOS management to the platform.

Endpoint Management Consolidation Arrives with PDQ Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom has released the largest Spring security update in the framework’s history, introducing commercial-first CVE-only patches and a SLSA Level 3-validated Java supply chain. AI-accelerated threat discovery has broken traditional patching cycles, and Broadcom’s response sets a new benchmark for open source stewardship under commercial cover. ECI Research examines what this means for enterprise risk posture, developer workflows, and the competitive landscape.

Broadcom Bets Big on Spring Ecosystem Security | ECI Research Read More »

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM and Red Hat have announced Project Lightwell, a $5 billion initiative pairing 20,000 engineers with AI to secure enterprise open source software at scale. The clearinghouse model targets supply chain vulnerabilities across independent libraries, AI frameworks, and data streaming platforms. ECI Research examines what this means for ITDMs and developers navigating an increasingly fragmented open source security landscape.

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale Read More »

Google AI Threat Defense: Autonomous Security Arrives | ECI Research

Google AI Threat Defense: Autonomous Security Arrives | ECI Research

Google Cloud has launched Google AI Threat Defense, an autonomous platform designed to prioritize and remediate vulnerabilities faster than attackers can exploit them. ECI Research examines the competitive implications, the developer experience questions, and the governance gaps enterprises must close before deploying autonomous security at scale.

Google AI Threat Defense: Autonomous Security Arrives | ECI Research Read More »

PDQ Connect MSP Features: Multitenancy, Patching & Integrations

PDQ Connect MSP Features: Multitenancy, Patching & Integrations

PDQ has launched MSP-focused capabilities in PDQ Connect, including multitenant architecture, reusable deployment packages, and integrations with Freshworks, Jira, and Zapier. The update targets the margin and security challenges MSPs face when managing endpoints across multiple client environments at scale. This analysis examines the business case, competitive positioning, and what’s still missing.

PDQ Connect MSP Features: Multitenancy, Patching & Integrations Read More »

Mythos and Open Source Security: What the Panic Gets Wrong

Mythos and Open Source Security: What the Panic Gets Wrong

AI-powered vulnerability tool Mythos has sparked alarm across the open source community, but the fear-mongering misses the point. ECI Research breaks down the real risk, the rational response, and why upstream contribution matters more than reactive security spending.

Mythos and Open Source Security: What the Panic Gets Wrong Read More »

Outpost24 Brings AI to DAST Authentication Configuration

Outpost24 Brings AI to DAST Authentication Configuration

Outpost24 has launched AI-powered authentication for its Scale DAST platform, replacing script-based configuration with natural-language instructions executed by an AI agent. The move targets one of the most persistent operational barriers to authenticated scanning at scale. ECI Research analyst coverage examines the business case, competitive implications, and what security and DevSecOps teams should evaluate.

Outpost24 Brings AI to DAST Authentication Configuration Read More »