Container Security stories
Growing use by major tech groups is helping open source secrets manager OpenBao win trust as cloud and AI credential risks mount.
Researchers can claim up to USD $1 million for breaking Vercel Sandbox's isolation, as the cloud provider opens its boundary to public scrutiny.
The accreditation strengthens Adfinis's hand with customers seeking secure open source tools for hybrid cloud systems and digital sovereignty.
The preview could help GKE users enforce cluster-wide security without clashing with namespace rules, especially in multi-tenant environments.
Security teams could spot newly disclosed flaws within minutes as rising CVE volumes and faster attacks squeeze response windows.
Tests on an n2-standard-48 virtual machine showed Google Cloud's sandbox and orchestration tweaks could cut per-agent costs by up to 75%.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Security and compliance teams can now patch buildpack-based containers from a single hardened base, rather than chasing Dockerfiles across repositories.
Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Security teams can now spot hidden AI workloads in live Kubernetes clusters, as Google's new tool also creates immutable ML bills of materials.
Developers can now isolate AI-generated code and user scripts inside Cloud Run, reducing the risk of exposing credentials or host data.
Rising use of AI coding tools is widening software supply-chain risks for businesses across the Middle East, Türkiye and Africa.
Private cloud operators may cut hardware costs by a third as Broadcom folds AI-assisted threat prevention and API security into VMware tools.
Security teams can now track newly disclosed CVEs in live systems, as RapidFort expands its supply chain tools into production monitoring.
The update aims to cut remediation costs and stop teams wasting time by re-analysing vulnerabilities without enough business context.
Open source package attacks can now be blocked earlier, as NetRise brings trust checks into editors, command lines and AI coding tools.
Security teams can now automate triage and remediation as risks emerge, with early access to AI agents that still require human oversight.
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.