#container-security

[ follow ]
Information security
fromSecurityWeek
19 hours ago

RapidFort Raises $42M to Automate Software Supply Chain Security

RapidFort raised $42 million to scale an automated platform that eliminates vulnerabilities by analyzing, hardening containers, supplying curated near-zero-CVE images, and reducing runtime attack surface.
fromInfoQ
4 days ago

Chainguard Finds 98% of Container CVEs Lurking Outside the Top 20 Images

Chainguard draws on telemetry from 290,000 images and almost half a billion builds to examine how customers actually consume and maintain open source components. It finds that foundational language and infrastructure images such as Python, Node, nginx, Go and Redis dominate production usage, forming what it describes as the baseline stack for the modern AI-driven software ecosystem.
Information security
fromTechzine Global
4 days ago

Developers struggle with container security

Almost a quarter of those surveyed said they had experienced a container-related security incident in the past year. The bottleneck is rarely in detecting vulnerabilities, but mainly in what happens next. Weeks or months can pass between the discovery of a problem and the actual implementation of a solution. During that period, applications continued to run with known risks, making organizations vulnerable, reports The Register.
Information security
Java
fromTheregister
5 days ago

Java devs want container security - not the hassle

Many Java developers prefer pre-hardened container providers because securing containers and related tooling is time-consuming, error-prone, and constrained by organizational resources.
DevOps
fromInfoQ
1 month ago

Docker Makes Hardened Images Free in Container Security Shift

Docker released over 1,000 hardened container images under Apache 2.0, providing secure, non-root, minimal base images with SBOMs and SLSA provenance for all developers.
Information security
fromTechzine Global
1 month ago

Docker removes paywall for hardened images

Docker is releasing Docker Hardened Images as free, Apache 2.0–licensed, Debian/Alpine-based pre-secured container images accessible to developers, teams, and organizations without license fees.
Information security
fromInfoQ
1 month ago

BellSoft Unveils Hardened Java Images

BellSoft's Hardened Images significantly reduce container vulnerabilities and resource use by combining Java runtime optimisation, OS hardening, and proactive CVE remediation.
fromTechzine Global
3 months ago

Docker makes secure images accessible to smaller businesses

Docker is launching a new subscription service for its Hardened Images catalog. The secure container images are designed to help organizations achieve near-zero CVEs without the high costs that were previously associated with this. With this launch, Docker is committed to democratizing container security. Every developer often starts their journey at Docker Hub. According to the company, this first step should be secure by default, without a premium price tag.
Information security
#docker
E-Commerce
fromMedium
6 months ago

Migrating Amazon EKS to Bottlerocket AMI: Architecture, Real-World Issues & Fixes

Migrated to Bottlerocket OS for Kubernetes on Amazon EKS for better security and performance.
fromHackernoon
8 months ago

Mastering MCP Server Management with ToolHive | HackerNoon

In this blog, we're delving into ToolHive, a small tool that makes managing and deploying MCP servers remarkably simple and safe.
DevOps
DevOps
fromInfoQ
8 months ago

Flux 2.6 GA Release and Security Advancements

Flux v2.6.0 introduces OCI Artifacts and enhances GitOps practices by enabling independent operation of Flux controllers from Git repositories.
#cybersecurity
fromDevOps.com
9 months ago
DevOps

Minimus Unfurls Service for Accessing Secure Software Artifacts - DevOps.com

Minimus launched a managed service securing application development with minimal container images and virtual machines.
fromThe Hacker News
9 months ago
Privacy professionals

Storm-1977 Hits Education Clouds with AzureChecker, Deploys 200+ Crypto Mining Containers

Storm-1977 is targeting the education sector with cloud-based password spraying attacks using specialized tools.
[ Load more ]