Container Security stories
Security teams could spot newly disclosed flaws within minutes as rising CVE volumes and faster attacks squeeze response windows.
Tests on an n2-standard-48 virtual machine showed Google Cloud's sandbox and orchestration tweaks could cut per-agent costs by up to 75%.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Security and compliance teams can now patch buildpack-based containers from a single hardened base, rather than chasing Dockerfiles across repositories.
Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Security teams can now spot hidden AI workloads in live Kubernetes clusters, as Google's new tool also creates immutable ML bills of materials.
Developers can now isolate AI-generated code and user scripts inside Cloud Run, reducing the risk of exposing credentials or host data.
The endorsement may help Tenable win buyers as security teams weigh AI risks alongside cloud, identity and container exposures.
The beta aims to stop unauthorised AI tools on corporate devices from reaching cloud services, repositories and production systems.
Enterprise buyers are treating software supply chain security as a standalone priority as Gartner creates a dedicated Magic Quadrant for the category.
Private cloud operators may cut hardware costs by a third as Broadcom folds AI-assisted threat prevention and API security into VMware tools.
Security teams can now track newly disclosed CVEs in live systems, as RapidFort expands its supply chain tools into production monitoring.
The update aims to cut remediation costs and stop teams wasting time by re-analysing vulnerabilities without enough business context.
Open source package attacks can now be blocked earlier, as NetRise brings trust checks into editors, command lines and AI coding tools.
Security teams can now automate triage and remediation as risks emerge, with early access to AI agents that still require human oversight.
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.
Mid-market security teams can now get permanent vulnerability and cloud checks free, easing access to tools often priced for larger enterprises.
Developers can now pull thousands of hardened container images for free, as the company drops registration and expands access across its library.