Container Security stories
Leaked AI credentials and unpatched dependencies are leaving production systems exposed across US and European organisations, Orca Security said.
Sensitive chats and uploaded files could have been quietly leaked from ChatGPT via DNS tunnelling before OpenAI fixed the flaw.
Nutanix Kubernetes Platform users can now add CloudCasa tools for backup, recovery and migration across on-premises, edge and cloud sites.
Enterprises could cut in-house patching as the deal brings supported, security-focused database container images to production environments.
Distributed sites will get tighter controls as HPE adds AI prompt filtering, recovery and encryption updates to guard against data leakage and attacks.
Enterprises could spot compromised maintainers sooner, as the new tool maps open-source contributors, dependencies and policy breaches across builds.
Red Hat survey finds 97% of organisations hit by cloud-native security incidents, forcing delays, higher costs and loss of customer trust.
Akamai injects new AI into Guardicore Segmentation to automate Zero Trust policies, curb lateral movement and shrink breach blast radius.
HPE rolls out new AI-aware security tools from edge firewalls to cloud recovery, aiming to tighten protection as enterprise AI spreads.
Akamai infuses Guardicore Segmentation with AI to automate zero trust policies and curb lateral movement across hybrid and cloud estates.
Zero Networks has unveiled Kubernetes Access Matrix, a visual tool mapping cluster traffic to help teams curb lateral movement and policy sprawl.
Red Hat reports 97% of organisations suffered cloud-native security incidents last year, exposing basic failings in configuration and governance.
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Zenarmor extends its SASE platform to mobile endpoints and containers, touting distributed, sovereign security without central cloud inspection.
Miggo and Grafana link runtime security to Grafana Cloud telemetry, promising major cuts to critical vulnerability noise for joint users.
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
Upwind integrates its runtime cloud security with Azure, offering unified protection and Sentinel tie-ins via the Microsoft Marketplace.
CrackArmour flaws in AppArmour could let local Linux users gain root, bypass namespaces and weaken container isolation at scale.
Endor Labs unveils AURI, a security intelligence platform embedding reachability-led checks into AI coding assistants and CI/CD pipelines.
Droplet warns UK that identity-based cyber defences are failing against state-backed attackers, urging multi-layered, 'never trust' security.