# cves

Published articles for cves.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

DevFeed: [Oracle September 2026 Critical Security Patch Update addresses 672 CVEs](<https://devfeed.tech/articles/oracle-september-2026-critical-security-patch-update-addresses-672-cves-26926.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves>)

Author: Research Special Operations

Published: 2026-09-15T21:00:28Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Oracle's September 2026 Critical Security Patch Update fixes 672 unique CVEs through 673 security updates across 17 Oracle product families. It includes 104 critical patches, with Oracle E-Business Suite receiving the most patches.

### Source excerpt

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches Background On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%. This month's update includes 104 critical patches across 104 CVEs. SeverityIssues PatchedCVEsCritical104104High503503Medium5958Low77Total673672 Analysis This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches. A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite15919Oracle Fusion Middleware15378Oracle Hyperion10250Oracle Siebel CRM6326Oracle Analytics508Oracle Communications3123Oracle Commerce2716Oracle Supply Chain195Oracle Virtualization191Oracle PeopleSoft164Oracle Database Server115

## curl 8.22.0

DevFeed: [curl 8.22.0](<https://devfeed.tech/articles/curl-8-22-0-18904.md>)

Original publisher: [Read original article](<https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/>)

Author: Daniel Stenberg

Published: 2026-09-02T05:52:46Z

Content type: release

Language: en

Sources: [Daniel Stenberg](<https://devfeed.tech/sources/daniel-stenberg.md>)

Topics: [cURL](<https://devfeed.tech/topics/curl.md>), [Security](<https://devfeed.tech/topics/security.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [API](<https://devfeed.tech/topics/api.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [curl](<https://devfeed.tech/tags/curl.md>), [curl-and-libcurl](<https://devfeed.tech/tags/curl-and-libcurl.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [http](<https://devfeed.tech/tags/http.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The curl 8.22.0 release includes six changes, 302 bug fixes, and nine curl/libcurl security fixes plus one wcurl fix. It adds Apple GSS Framework support, API guards, experimental HTTP Message Signatures support, and Apple fast UDP, while blocking NTLM fallback in SPNEGO and dropping TLS-SRP support.

### Source excerpt

Welcome to this new release. Get it as always from https://curl.se. If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days. Release presentation Numbers the 276th release6 changes70 days (total: 10,887)302 bugfixes (total: 14,489)525 commits (total: 39,608)0 new public libcurl function (total: 100)4 new ... Continue reading curl 8.22.0 ->

## \[CVE\] \[URGENT\] Squid v19.2.6 and Tentacle v20.2.4 released

DevFeed: [\[CVE\] \[URGENT\] Squid v19.2.6 and Tentacle v20.2.4 released](<https://devfeed.tech/articles/cve-urgent-squid-v19-2-6-and-tentacle-v20-2-4-released-12345.md>)

Original publisher: [Read original article](<https://ceph.io/en/news/blog/2026/v20-2-4-v19-2-6-combo-released/>)

Author: Patrick Donnelly

Published: 2026-08-19T00:00:00Z

Content type: release

Language: en

Sources: [Ceph Blog](<https://devfeed.tech/sources/ceph-blog.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [client](<https://devfeed.tech/topics/client.md>), [monitor](<https://devfeed.tech/topics/monitor.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [en-article](<https://devfeed.tech/tags/en-article.md>), [en-blog-post](<https://devfeed.tech/tags/en-blog-post.md>), [errors](<https://devfeed.tech/tags/errors.md>), [linux](<https://devfeed.tech/tags/linux.md>), [process](<https://devfeed.tech/tags/process.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [rest](<https://devfeed.tech/tags/rest.md>), [rgw](<https://devfeed.tech/tags/rgw.md>), [squid](<https://devfeed.tech/tags/squid.md>), [tentacle](<https://devfeed.tech/tags/tentacle.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

The Ceph project released Tentacle 20.2.4 and Squid 19.2.6 as hotfixes addressing four CVEs. The article urgently recommends upgrading and explains changes to CephX key types, daemon-key rotation, authentication controls, recovery procedures, and multisite RGW request signing.

### Source excerpt

The Ceph project has released Tentacle 20.2.4 and Squid 19.2.6 hotfixes for four CVEs across several components. This is the sixth backport release in the Squid series. This is the fourth backport release in the Tentacle series. We strongly recommend that all Ceph operators upgrade to one of these releases as soon as possible. Release Date ¶ August 19, 2026 Critical Upgrade Steps ¶ The fix for CVE-2025-30156 introduces a new CephX key type, aes256k. This is the first time Ceph has introduced a new key type for CephX credentials. Therefore, a new procedure exists for upgrading and rotating Ceph daemon keys as part of this CVE. Before upgrading a Ceph cluster, the operator should familiarize themselves with the procedure to upgrade CephX keys. These steps are for package-based deployments of Ceph. In other sections, the document also includes new information about key rotation procedures, monitor authentication controls, and emergency recovery procedures. Deployments using cephadm will automate the process except for client keys. You may notice that Cephadm spends more time than normal on the upgrade after updating all daemon images. This is due to a new process rotating the OSD and MDS keys. Please be patient. There are plans to improve this in the future. Deployments using Rook will also automate rotation of some client keys with some exclusions. Look to the Rook project's announcement for more details. Client and kernel upgrades are recommended to support aes256k. Note that upstream Linux kernel client support began in kernel 7.0 and has been backported to CentOS Stream 9 and 10. Check with your distribution vendor for backported key support before rotating client keys used by the kernel. As part of upgrading a Ceph cluster, six new health warnings and errors will be generated. This is normal. As part of the process to upgrade/rotate entity keys, you will address the warnings and errors as you go. These are documented beginning here. The CephX documentation has bee

## Patching Vulnerabilities Without an Upstream Fix

DevFeed: [Patching Vulnerabilities Without an Upstream Fix](<https://devfeed.tech/articles/this-shit-is-hard-patching-a-vulnerability-that-has-no-fix-13287.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-patching-a-vulnerability-that-has-no-fix>)

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>)

Tags: [ai-security](<https://devfeed.tech/tags/ai-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cves](<https://devfeed.tech/tags/cves.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard describes how its Athena vulnerability clearinghouse addresses exploitable vulnerabilities when no upstream fix exists. The article explains that generating an AI-written patch is straightforward, while proving the patch is correct and safe requires extensive engineering and validation inside a microVM sandbox.

### Source excerpt

Generating an AI security patch is easy. Trusting it is hard. Learn how Chainguard proves zero-day fixes are safe before they ship.

## Why zero CVEs matters in mobile airgapped deployments

DevFeed: [Why zero CVEs matters in mobile airgapped deployments](<https://devfeed.tech/articles/why-zero-cves-matters-in-mobile-airgapped-deployments-13334.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-zero-cves-matters-in-mobile-airgapped-deployments>)

Published: 2026-07-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains why disconnected mobile and air-gapped systems become increasingly exposed as vulnerabilities accumulate while patching and live feeds are unavailable. It argues that starting with low-CVE container images and refreshing them before departure can reduce the vulnerability backlog, citing Chainguard Containers' stated CVE reduction and daily rebuild practices.

### Source excerpt

Disconnected systems can't patch. Learn how minimal, zero-CVE containers help reduce vulnerability accumulation in air-gapped environments.

## What are CVEs, and how to read them

DevFeed: [What are CVEs, and how to read them](<https://devfeed.tech/articles/what-are-cves-and-how-to-read-them-12260.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/what-are-cves-and-how-to-read-them>)

Author: Neil Carpenter

Published: 2026-07-23T05:40:01Z

Content type: tutorial

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Software](<https://devfeed.tech/topics/software.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [learn](<https://devfeed.tech/tags/learn.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This tutorial demystifies Common Vulnerabilities & Exposures (CVE) records and explains how practitioners can evaluate and respond to software vulnerabilities. It covers CVE identifiers, record enrichment, CVSS severity scores, and CPE applicability information, with discussion of the jargon and assumptions involved.

### Source excerpt

A CVE record is dense with jargon and hidden assumptions. Demystify the Common Vulnerabilities & Exposures (CVE) system and learn how to read and respond effectively to new vulnerabilities, including understanding CVSS severity scores, CPEs for applicability, and CWEs for root cause analysis

## The true cost of Kubernetes release support for Platform Engineers

DevFeed: [The true cost of Kubernetes release support for Platform Engineers](<https://devfeed.tech/articles/the-true-cost-of-kubernetes-release-support-for-platform-engineers-12251.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/the-true-cost-of-kubernetes-release-support-for-platform-engineers>)

Author: Bruce Gain

Published: 2026-07-23T05:40:01Z

Content type: comparison

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Amazon EKS](<https://devfeed.tech/topics/amazon-eks.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [rancher](<https://devfeed.tech/topics/rancher.md>)

Tags: [amazon-eks](<https://devfeed.tech/tags/amazon-eks.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cves](<https://devfeed.tech/tags/cves.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [operational](<https://devfeed.tech/tags/operational.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [private-cloud](<https://devfeed.tech/tags/private-cloud.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [support](<https://devfeed.tech/tags/support.md>), [testing](<https://devfeed.tech/tags/testing.md>), [upgrades](<https://devfeed.tech/tags/upgrades.md>), [vmware-cloud-foundation](<https://devfeed.tech/tags/vmware-cloud-foundation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article compares the operational and financial trade-offs of Kubernetes release support models. It explains that the CNCF's 14-month support window requires frequent upgrades, creating testing, coordination, maintenance, and service-disruption risks. Hyperscalers such as Amazon EKS, Google GKE, and Azure AKS offer paid extended support, while VMware Cloud Foundation provides 24 months of standard support without incremental fees and Red Hat OpenShift offers a 36-month support window.

### Source excerpt

Compare the true cost and operational trade-offs of Kubernetes extended support fees from hyperscalers (AWS, GCP, Azure) versus the longer, predictable maintenance cycles of VMware VCF and other enterprise distributions.

## Hydrate, Hack, Repeat: Security Summer Camp 2026

DevFeed: [Hydrate, Hack, Repeat: Security Summer Camp 2026](<https://devfeed.tech/articles/hydrate-hack-repeat-security-summer-camp-2026-27479.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/07/22/hydrate-hack-repeat-security-summer-camp-2026/>)

Author: jgamblin

Published: 2026-07-22T21:34:54Z

Content type: opinion

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [data](<https://devfeed.tech/topics/data.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [bsides](<https://devfeed.tech/tags/bsides.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [con](<https://devfeed.tech/tags/con.md>), [cves](<https://devfeed.tech/tags/cves.md>), [data](<https://devfeed.tech/tags/data.md>), [kev-catalog](<https://devfeed.tech/tags/kev-catalog.md>), [management](<https://devfeed.tech/tags/management.md>), [models](<https://devfeed.tech/tags/models.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [talks](<https://devfeed.tech/tags/talks.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

A personal guide to the author's 2026 security conference schedule, new role as Head of Research at Empirical Security, and recommended CVE and vulnerability talks. It argues that effective vulnerability management requires granular, transparent, accurate data, citing the growth in CVEs and the limited share listed in CISA KEV.

### Source excerpt

My schedule, a new role at Empirical Security, and the CVE and vulnerability talks worth your time. It is almost the first week of August, which means it is time to point myself at the desert one more time. BSides Las Vegas, Black Hat, and DEF CON all land back to back, and for me ... Read more

## CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare

DevFeed: [CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare](<https://devfeed.tech/articles/cve-mid-year-2026-check-in-volume-vertical-exploitation-rare-27478.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/07/01/3528/>)

Author: jgamblin

Published: 2026-07-01T15:47:10Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This mid-year review finds that 35,364 CVEs were published in the first half of 2026, up 49.5% from the same period in 2025, while only 85 had entered CISA's KEV list. The article argues that the main challenge is distinguishing exploitable vulnerabilities from the rapidly growing volume of disclosures.

### Source excerpt

We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published in the first half of 2026 (Jan 1 - Jun 30, 2026), the volume, the severity, what is actually being exploited, and who ... Read more

## The State of Trusted Open Source: June 2026

DevFeed: [The State of Trusted Open Source: June 2026](<https://devfeed.tech/articles/the-state-of-trusted-open-source-june-2026-13271.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-june-2026>)

Published: 2026-06-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [cves](<https://devfeed.tech/tags/cves.md>), [data](<https://devfeed.tech/tags/data.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [node](<https://devfeed.tech/tags/node.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [state-of-trusted-open-source](<https://devfeed.tech/tags/state-of-trusted-open-source.md>), [trends](<https://devfeed.tech/tags/trends.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard's June 2026 report analyzes vulnerability data from more than 2,400 container image projects and 18,016 vulnerability instances observed from March through May 2026. It reports 886 distinct CVEs, with 63.1% of observed instances classified as high severity, and examines how AI-assisted development and security research are affecting software supply-chain risk.

### Source excerpt

AI is accelerating vulnerability discovery. Explore the latest trusted open source trends, dependency risks, and CVE insights from Chainguard's report.

## Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java

DevFeed: [Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java](<https://devfeed.tech/articles/fewer-cves-more-accurate-findings-wiz-now-scans-chainguard-libraries-for-python-and-java-13335.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wiz-now-scans-chainguard-libraries-for-python-and-java>)

Published: 2026-06-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [Java](<https://devfeed.tech/topics/java.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wiz-chainguard-libraries](<https://devfeed.tech/tags/wiz-chainguard-libraries.md>), [wiz-chainguard-scanner](<https://devfeed.tech/tags/wiz-chainguard-scanner.md>)

### AI overview

Wiz now scans Chainguard Libraries for Python and Java. The partnership combines source-built dependencies and backported fixes with Wiz's risk context and visibility, helping organizations assess vulnerabilities, prioritize remediation, and verify artifact provenance.

### Source excerpt

Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.

## Harness May 2026 Product Updates: 60+ New Features

DevFeed: [Harness May 2026 Product Updates: 60+ New Features](<https://devfeed.tech/articles/harness-may-2026-product-updates-60-new-features-13476.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/shipped-in-may-2026>)

Author: Chinmay Gaikwad

Published: 2026-06-03T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [MCP](<https://devfeed.tech/topics/mcp.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Development](<https://devfeed.tech/topics/development.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [Security](<https://devfeed.tech/topics/security.md>), [Claude](<https://devfeed.tech/topics/claude.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [api](<https://devfeed.tech/tags/api.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [coding-assistant](<https://devfeed.tech/tags/coding-assistant.md>), [connectors](<https://devfeed.tech/tags/connectors.md>), [cves](<https://devfeed.tech/tags/cves.md>), [development](<https://devfeed.tech/tags/development.md>), [features](<https://devfeed.tech/tags/features.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integration](<https://devfeed.tech/tags/integration.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [product-updates](<https://devfeed.tech/tags/product-updates.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Harness reports more than 60 product updates shipped in May 2026 across AI-native development, software delivery, security, cost management, and engineering insights. Highlights include AI cost tracking, AI adoption metrics, Claude connector access, and expanded MCP Server capabilities.

### Source excerpt

See 60+ Harness updates from May 2026 across AI-native development, software delivery, security, artifact management, cost visibility, and engineering insights. | Blog

## Building for the AI era: Chainguard partners with Endor Labs

DevFeed: [Building for the AI era: Chainguard partners with Endor Labs](<https://devfeed.tech/articles/building-for-the-ai-era-chainguard-partners-with-endor-labs-12905.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-for-the-ai-era-chainguard-partners-with-endor-labs>)

Published: 2026-05-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Library](<https://devfeed.tech/topics/library.md>), [Agent Skill](<https://devfeed.tech/topics/agent-skill.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [endor](<https://devfeed.tech/tags/endor.md>), [endor-labs](<https://devfeed.tech/tags/endor-labs.md>), [observability](<https://devfeed.tech/tags/observability.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard partners with Endor Labs to help teams building with AI coding agents secure the software supply chain. Chainguard provides source-built artifacts, daily rebuilds, signed SBOMs, and SLSA Level 3 provenance, while Endor Labs analyzes application context to identify vulnerabilities that are genuinely reachable and exploitable.

### Source excerpt

Chainguard and Endor Labs help teams build securely at AI speed with source-built artifacts, exploitability analysis, and fewer vulnerabilities to triage.

## Kubernetes User Namespaces Improve Pod Isolation but Do Not Isolate the Shared Kernel

DevFeed: [Kubernetes User Namespaces Improve Pod Isolation but Do Not Isolate the Shared Kernel](<https://devfeed.tech/articles/kubernetes-finally-lands-user-namespace-support-but-shared-kernel-problem-remains-17633.md>)

Original publisher: [Read original article](<https://thenewstack.io/kubernetes-user-namespace-security/>)

Author: Kaylin Trychon

Published: 2026-05-06T14:50:05Z

Content type: opinion

Language: en

Sources: [Kubernetes Overview, News and Trends | The New Stack](<https://devfeed.tech/sources/kubernetes-overview-news-and-trends-the-new-stack.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [edera](<https://devfeed.tech/tags/edera.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [security](<https://devfeed.tech/tags/security.md>), [sponsor-edera](<https://devfeed.tech/tags/sponsor-edera.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>)

### AI overview

Kubernetes user namespaces can reduce the impact of some container escapes by remapping pod root identities to unprivileged host identities. The article argues that this improves isolation but does not address the security limitations of a shared kernel.

### Source excerpt

Kubernetes shipped a long-awaited security feature last week: user namespace support for pods. It may sound like an obscure feature The post Kubernetes finally lands user namespace support, but shared kernel problem remains appeared first on The New Stack.

## Building the business case for a secure open source supply chain

DevFeed: [Building the business case for a secure open source supply chain](<https://devfeed.tech/articles/building-the-business-case-for-a-secure-open-source-supply-chain-12911.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-the-business-case-for-a-secure-open-source-supply-chain>)

Published: 2026-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [engineering-culture](<https://devfeed.tech/topics/engineering-culture.md>)

Tags: [chainguard-assemble](<https://devfeed.tech/tags/chainguard-assemble.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-customers](<https://devfeed.tech/tags/chainguard-customers.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [continuous-delivery](<https://devfeed.tech/tags/continuous-delivery.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [kyndryl](<https://devfeed.tech/tags/kyndryl.md>), [kyndryl-open-source](<https://devfeed.tech/tags/kyndryl-open-source.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how organizations can build a business case for a secure open source supply chain. It describes a shift from framing open source security solely around CVEs, scanner results, and patching toward presenting trusted open source as a driver of productivity, resilience, and delivery speed. It also explains why traditional vulnerability management struggles with continuous delivery, distributed systems, frequently rebuilt container images, changing dependencies, and global cloud infrastructure.

### Source excerpt

Learn how Kyndryl reframed open source security as a business driver -- reducing risk, lowering costs, and accelerating developer productivity.

## Going beyond CVEs: Chainguard's one day KEV SLA

DevFeed: [Going beyond CVEs: Chainguard's one day KEV SLA](<https://devfeed.tech/articles/going-beyond-cves-chainguard-s-one-day-kev-sla-13068.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/going-beyond-cves-chainguards-one-day-kev-sla>)

Published: 2026-04-28T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cves](<https://devfeed.tech/tags/chainguard-cves.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-kevs](<https://devfeed.tech/tags/chainguard-kevs.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [kevs](<https://devfeed.tech/tags/kevs.md>), [known-exploitable-vulnerabilities](<https://devfeed.tech/tags/known-exploitable-vulnerabilities.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard announces a one-calendar-day SLA for remediating CVEs added to the CISA Known Exploited Vulnerabilities Catalog when they affect Chainguard container images. The article explains the SLA's relationship to exploited-vulnerability prioritization and Chainguard's continuous remediation processes.

### Source excerpt

Chainguard introduces a 1-day KEV SLA, ensuring exploited vulnerabilities are fixed fast--aligned with how security teams prioritize real-world threats.

## AI is finding vulnerabilities faster than anyone can patch them. Now what?

DevFeed: [AI is finding vulnerabilities faster than anyone can patch them. Now what?](<https://devfeed.tech/articles/ai-is-finding-vulnerabilities-faster-than-anyone-can-patch-them-now-what-12867.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ai-is-finding-vulnerabilities-faster-than-anyone-can-patch-them-now-what>)

Published: 2026-04-10T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard-for-ai](<https://devfeed.tech/tags/chainguard-for-ai.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-mythos-preview](<https://devfeed.tech/tags/claude-mythos-preview.md>), [cves](<https://devfeed.tech/tags/cves.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that AI systems such as Claude Mythos Preview are discovering zero-day vulnerabilities faster than organizations and open-source maintainers can patch them. It describes the resulting risks for software supply chains, including faster exploitation, uneven vendor response, and increased pressure on maintainers, while presenting verifiable-source, secure-by-default artifacts as a defensive approach.

### Source excerpt

Project Glasswing and Claude Mythos Preview reveal a surge in zero-days. Learn why reactive patching fails and how secure-by-default supply chains keep you safe.

## SecDB is the past, OSV is the future

DevFeed: [SecDB is the past, OSV is the future](<https://devfeed.tech/articles/secdb-is-the-past-osv-is-the-future-13218.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/secdb-is-the-past-osv-is-the-future>)

Published: 2026-04-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard packages](<https://devfeed.tech/topics/chainguard-packages.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [cves](<https://devfeed.tech/tags/cves.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secdb](<https://devfeed.tech/tags/secdb.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard is deprecating its SecDB vulnerability feed and plans to sunset it at the end of 2026. The company is moving toward the OSV schema because it supports more precise vulnerability data, including unfixed vulnerabilities and component-level advisory details.

### Source excerpt

Chainguard is deprecating SecDB in favor of OSV, delivering more accurate, granular vulnerability data and better visibility for modern software supply chains.

## Protect your AI workloads from supply chain attacks

DevFeed: [Protect your AI workloads from supply chain attacks](<https://devfeed.tech/articles/protect-your-ai-workloads-from-supply-chain-attacks-13205.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/protect-your-ai-workloads-from-supply-chain-attacks>)

Published: 2026-01-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [PyTorch](<https://devfeed.tech/topics/pytorch.md>), [Tensorflow](<https://devfeed.tech/topics/tensorflow.md>), [MLOps](<https://devfeed.tech/topics/mlops.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-containers](<https://devfeed.tech/tags/ai-containers.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-ai](<https://devfeed.tech/tags/chainguard-for-ai.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cudnn](<https://devfeed.tech/tags/cudnn.md>), [cves](<https://devfeed.tech/tags/cves.md>), [data-processing](<https://devfeed.tech/tags/data-processing.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [kserve](<https://devfeed.tech/tags/kserve.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [mlops](<https://devfeed.tech/tags/mlops.md>), [nemo](<https://devfeed.tech/tags/nemo.md>), [ollama](<https://devfeed.tech/tags/ollama.md>), [python](<https://devfeed.tech/tags/python.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

The article discusses security and operational challenges in AI/ML workloads, including complex dependencies, bloated artifacts, infrastructure sprawl, and unremediated CVEs. It presents Chainguard Containers' minimal images for AI workloads as a way to reduce attack surface, storage needs, and deployment overhead, and cites a 50 MB gpu-operator image compared with a 170 MB upstream equivalent.

### Source excerpt

Chainguard secures AI adoption with minimal, zero-CVE containers and source-built libraries that prevent supply chain malware while keeping developers fast.

## How Chainguard OS Uses Automated Package Garbage Collection to Reduce Security Risk

DevFeed: [How Chainguard OS Uses Automated Package Garbage Collection to Reduce Security Risk](<https://devfeed.tech/articles/this-shit-is-hard-keeping-chainguard-os-lean-current-and-secure-the-power-of-garbage-collection-13286.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-keeping-chainguard-os-lean-current-and-secure-the-power-of-garbage-collection>)

Published: 2025-12-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [APK](<https://devfeed.tech/topics/apk.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Process](<https://devfeed.tech/topics/process.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [automated](<https://devfeed.tech/tags/automated.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-operating-system](<https://devfeed.tech/tags/chainguard-operating-system.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-wolfi](<https://devfeed.tech/tags/chainguard-wolfi.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Chainguard automates garbage collection for Chainguard OS and Wolfi APK repositories. It describes filtering older packages and checking dependencies and image usage before removal to keep repositories current and reduce potential attack surface while preserving image customization workflows.

### Source excerpt

Learn how we keep Chainguard OS and Wolfi lean and secure with automated package garbage collection that cuts attack surface while preserving reproducibility.

## Three Ways to Make Your SDLC Secure-by-Default

DevFeed: [Three Ways to Make Your SDLC Secure-by-Default](<https://devfeed.tech/articles/three-ways-to-make-your-sdlc-secure-by-default-13293.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/three-ways-to-make-your-sdlc-secure-by-default>)

Published: 2025-10-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sdlc](<https://devfeed.tech/topics/sdlc.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cves](<https://devfeed.tech/tags/cves.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article presents secure-by-default software development lifecycle practices. It recommends embedding security throughout development, standardizing trusted foundations, securing dependencies and base images, and integrating security into developer tools, CI/CD workflows, and runtime artifacts.

### Source excerpt

Build secure software faster with Chainguard. Learn how secure-by-default SDLC practices eliminate CVEs, automate compliance, and embed trust from code to cloud.

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust

DevFeed: [Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust](<https://devfeed.tech/articles/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust-13155.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust>)

Published: 2025-10-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains how Chainguard helps businesses meet stricter software security requirements for self-hosted, cloud, packaged-agent, and embedded software. It focuses on zero known CVEs at delivery, verifiable SBOMs, provenance attestations, compatibility with security tooling, and the challenges of open source dependencies and container images.

### Source excerpt

Chainguard's zero-CVE containers come with broad compatibility, custom assembly, verifiable provenance and SBOMs, and more to help you ship secure software.

## Jerry Gamblin Announces Two CVE Ecosystem Talks at BSides Las Vegas and DEF CON

DevFeed: [Jerry Gamblin Announces Two CVE Ecosystem Talks at BSides Las Vegas and DEF CON](<https://devfeed.tech/articles/vegas-bound-for-security-summer-camp-27473.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2025/07/30/vegas-bound-for-security-summer-camp/>)

Author: jgamblin

Published: 2025-07-30T18:05:00Z

Content type: opinion

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [bsides](<https://devfeed.tech/tags/bsides.md>), [cves](<https://devfeed.tech/tags/cves.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

Jerry Gamblin announces that he will give two talks on the CVE ecosystem during Security Summer Camp, including appearances at BSides Las Vegas and the AppSec Village at DEF CON.

### Source excerpt

It's that time of year again! The first week of August means my annual trip to the desert for "Security Summer Camp"--the whirlwind of BSides Las Vegas, Black Hat, and DEF CON. It's always an exhausting but amazing week, and I can't wait to dive in, catch up with everyone, and talk about what I've ... Read more

[Next page](<https://devfeed.tech/tags/cves.md?cursor=WyIyMDI1LTA3LTMwVDE4OjA1OjAwKzAwOjAwIiwgIjVkNTBlMWNiLWYxNzctNDlmNy1iYjlkLTk2MGI1MmQyODJhOSJd>)