Container Security stories
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.
Developers can now pull thousands of hardened container images for free, as the company drops registration and expands access across its library.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Security and compliance teams can now patch buildpack-based containers from a single hardened base, rather than chasing Dockerfiles across repositories.
Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Security teams can now spot hidden AI workloads in live Kubernetes clusters, as Google's new tool also creates immutable ML bills of materials.
Developers can now isolate AI-generated code and user scripts inside Cloud Run, reducing the risk of exposing credentials or host data.
The endorsement may help Tenable win buyers as security teams weigh AI risks alongside cloud, identity and container exposures.
The beta aims to stop unauthorised AI tools on corporate devices from reaching cloud services, repositories and production systems.
Enterprise buyers are treating software supply chain security as a standalone priority as Gartner creates a dedicated Magic Quadrant for the category.
Users of Dify's cloud service could have had private chats and files exposed after Zafran Security disclosed four flaws in the AI platform.
The recognition underlines rising demand for tools that secure software builds before attackers can exploit open source dependencies and pipelines.
Government agencies will gain wider access to application security tools as the partnership places Checkmarx products on Carahsoft's procurement channels.
Government buyers will gain wider access to Checkmarx tools as Carahsoft opens procurement routes through reseller networks and federal contracts.
Customers will be able to buy software supply chain security with advisory and managed services as NetRise widens its route to market through partners.
Older Liquibase Community users can now check release-by-release vulnerabilities in a free public library covering Docker images and binaries.
The update aims to simplify security operations as enterprises grapple with unmanaged devices, partners and multi-cloud workloads across AI projects.
Mid-market security teams can now get permanent vulnerability and cloud checks free, easing access to tools often priced for larger enterprises.