logo
Lineaje launches AI-powered self-healing for software security

Lineaje launches AI-powered self-healing for software security

Techday NZ23-04-2025

Lineaje has announced new end-to-end capabilities aimed at improving software supply chain security for organisations.
The new offerings include agentic AI-powered self-healing for open-source software, source code, and containers, alongside Gold Open Source Packages, Gold Open Source Images, and a software risk analysis engine called SCA360.
Lineaje's AI Labs research indicates that 90% of modern applications incorporate open-source packages, while 95% of vulnerabilities in applications originate from these dependencies. This environment makes it difficult for developers as development, security, and operations (DevSecOps) teams must address rapidly shifting prioritised risks, often leading to high vulnerability backlogs and resource pressure.
According to the Enterprise Strategy Group, 91% of organisations experienced software supply chain incidents in the previous 12 months, leading to significant operational impacts.
The company's new solutions aim to mitigate these issues by combining agentic AI, Gold Open Source, and SCA360 scanning technology to eliminate software supply chain vulnerabilities and streamline workflows for development and security teams.
The agentic AI functionality enables automatic detection and remediation of security risks within codebases and container environments. These AI agents can compare software versions, generate reports, and analyse compatibility at scale.
With these capabilities, thousands of containers and hundreds of repositories are monitored and updated autonomously, reducing the direct burden on developers. The system scans code for security issues, including common vulnerabilities and exposures (CVE), identifies compatible updates, and can apply fixes automatically upon approval.
Application-aware, self-healing secure containers further allow vulnerabilities to be identified and patched across multiple layers. New container clones are generated automatically and are intended to be compatible and secure prior to deployment, enabling remediation as part of the build and deployment pipeline.
Melinda Marks, Practice Director, Cybersecurity at Enterprise Strategy Group, commented, "As developers increasingly utilise third-party and open-source software to save time as they develop their applications, security teams face challenges with software supply chain security. And the complexity of the software supply chain will continue to grow as developers utilise AI to further increase their productivity."
"It is exciting to see Lineaje apply agentic AI to automatically scan and remediate vulnerabilities in open-source software, source code, and containers to help organisations manage software supply chain risk, as this technology holds the promise of creating self-healing systems to alleviate security teams from the challenges of supporting rapidly scaling software development."
The Gold Open Source programme allows organisations to access pre-attested, vulnerability-free open-source packages and images, with each package offering full transparency through more than 100 tracked attributes, such as vulnerabilities, licences, and code quality. The offering includes over 3 million Gold Packages and 2,000 Gold Images used in enterprise environments. These catalogues are updated and monitored by Lineaje's AI capabilities, which now track more than 408 billion security data points.
For customised needs, developers can generate bespoke Gold Images by specifying public container images, which are then hardened and added to client subscriptions.
Premium Gold Open Source functionality addresses security risks associated with abandoned or incompatible open-source packages. According to Lineaje AI Labs data, more than half of all open-source packages are abandoned, leaving potential vulnerabilities exposed in these widely used components.
SCA360, a contextual risk analysis engine newly introduced by Lineaje, unifies software analysis for source code, repositories and containers. It operates within an organisation's security perimeter, offering scanning without moving critical data outside corporate boundaries. The tool includes a dependency and reachability scanner, static code analysis, and a malware scanner that detects embedded malicious code or tampered packages.
Pippin Wallace, Senior Security Engineer at Favor Delivery, said, "As a food delivery service, our entire business model rests upon the success of our software. A faulty component or vulnerability could potentially disrupt thousands of deliveries daily, impacting our revenue, customer satisfaction, reputation with partners, which could impact our employees and customers."
"We required a solution to proactively address these risks and protect our business. Lineaje's SCA360 helps us manage security risks by scanning all software in our delivery platform, ensuring that everything can stay secure. It helps our developers focus on serving up more value to our partners and end users by fixing issues before they become bigger threats."
Lineaje states that its solutions can integrate with other corporate tools to allow for full-lifecycle software supply chain security and simplified management across the development pipeline, including the new capabilities for self-healing systems and automated risk reduction.
Javed Hasan, co-founder and CEO of Lineaje, said, "Full-lifecycle software supply chain security capabilities enable organisations to deliver transparently secure software. Our new Agentic AI capability in Lineaje AI, combined with Gold Open Source and SCA360, enables organisations to eliminate software supply chain risks while dramatically reducing developer, DevOps, and DevSecOps overhead and chaos created by existing AppSec tools."

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Riverbed expands acceleration platforms to meet rising AI demand
Riverbed expands acceleration platforms to meet rising AI demand

Techday NZ

time14-05-2025

  • Techday NZ

Riverbed expands acceleration platforms to meet rising AI demand

Riverbed has introduced an updated portfolio of acceleration platforms and services aimed at improving enterprise network performance, security, and agility in response to a surge in data-heavy artificial intelligence deployments. The expanded range features ten new SteelHead acceleration solutions powered by the latest iteration of Riverbed's RiOS software, RiOS 10. These solutions are designed to enhance the transfer and security of data across cloud environments, data centres, and edge locations. The update also includes the launch of Riverbed Flex, a new subscription model that enables clients to transition licenses across hardware, virtual, and cloud deployments and scale capacity according to business requirements. According to Riverbed, the roll-out comes after a 59% increase, year-on-year, in bookings for its Acceleration business, amid growing demand from enterprises deploying artificial intelligence solutions that produce and process significant volumes of data. Industry data highlighted by Riverbed shows global networks experiencing annual increases of 35% in data volume, putting strain on existing infrastructure. Research from Enterprise Strategy Group (ESG) indicates that 91% of IT leaders see AI as a factor making network acceleration solutions essential, while 85% believe AI is directly influencing network planning and operations. As enterprise data creation and use by AI applications rises, network capacity and speed have become key concerns for IT teams. Dave Donatelli, Chief Executive Officer at Riverbed, commented: "Riverbed was founded 23 years ago this month with a focus on accelerating applications and the movement of data over networks. AI and data-hungry applications have introduced new and more demanding network requirements. I'm proud that Riverbed continues to solve our customers' most critical challenges, as demonstrated today by our largest Acceleration launch in seven years. In the first quarter of this year, we saw strong demand in our Acceleration business, achieving 59% year-over-year bookings growth. These new solutions build on our momentum and deliver a proven return on investment by helping customers move data faster, optimise application performance, and strengthen business resilience." RiOS 10 introduces architectural enhancements designed to support cloud computing, data centre operations, and edge deployments, with new provisions for post-quantum cryptography, platform security, and confidential computing. The SteelHead 90 series includes models tailored for specific deployment needs, such as the Data Centre-ready CXA-8090, capable of delivering up to 60 Gbps of data movement over optimised WANs, and the CXA-2090, intended for edge locations. SteelHead 6090 targets mid-size data centres with up to 20 Gbps of optimised data movement, while SteelHead 4090 and 2090 address mid-sized data centre and edge cases, supporting accelerated traffic loads of 500 Mbps and 200 Mbps, respectively, and up to 10 Gbps of traffic for application classification requirements. Chalan Aras, Senior Vice President and General Manager of Acceleration at Riverbed, stated: "Network congestion is no longer just a nuisance—it's a choke point that can cripple a business. Without fast and efficient data movement over networks, enterprises will quickly find themselves falling behind, missing out on the promise of AI. Riverbed's new resilient networking solutions help organisations stay ahead of the curve by securely managing growing data volumes and application performance demands, while also improving IT agility to support the dynamic demands of cloud, data centre and edge computing." For workloads in virtualised environments, RiOS 10 also powers SteelHead Virtual, a software-only solution compatible with VMware ESXI, KVM, and Microsoft Hyper-V and aimed at private cloud deployments. Riverbed also announced SteelHead RS, a software offering developed to support edge computing operations by enabling near real-time synchronisation with data centres, local processing, and consistency across distributed locations. SteelHead Cloud, also powered by RiOS 10, expands compatibility to Amazon Web Services, Microsoft Azure, Oracle Cloud Infrastructure, and Google Cloud Platform. The new solution is available via each provider's marketplace and is designed to support enterprise data and application transfers at up to 20 Gbps. Jim Frey, Principal Analyst for Networks at Enterprise Strategy Group, shared: "AI initiatives are increasing the criticality of network performance, requiring reduced latency, increased bandwidth, and richer network observability. While performance can be improved by upgrading network gear and external services, organisations should also prioritise continuous optimisation of network connections. These are all requirements that Riverbed's resilient networking solutions address for successfully supporting growing AI workloads." The Riverbed Flex subscription model has been designed to give businesses flexibility, investment protection, and ease of scalability by allowing dynamic license reassignment and hardware upgrades in line with evolving IT requirements. Dr. Alexei Vederko, Senior Director of Engineering at Viasat Energy Services, remarked: "Riverbed Flex allows us to continue to manage our network performance in a smarter, more agile way - exactly what we need in the fast-moving world of offshore operations. With rigs constantly relocating, IT must scale, move, and optimise network acceleration on demand. The Flex model allows us to replace and upgrade hardware: minimising risk when equipment is lost or outdated. As a long-time SteelHead customer, our work with Riverbed allows us to effectively deliver critical data to our oil platforms and ensure operational resiliency. Riverbed Flex is a further step forward in future proofing our network with greater flexibility and control." The newly announced solutions are expected to be generally available in May 2025. Additional features, including some capabilities for post-quantum cryptography and expanded cloud support, are anticipated to be introduced in the second half of 2025.

Delinea enhances cloud identity platform to secure AI at scale
Delinea enhances cloud identity platform to secure AI at scale

Techday NZ

time13-05-2025

  • Techday NZ

Delinea enhances cloud identity platform to secure AI at scale

Delinea has announced new enhancements to its cloud-native identity security platform to help organisations secure and manage AI and machine identities. The updates respond to a noted shift in enterprise infrastructure, where research from Delinea Labs has found that machine identities now outnumber human identities on enterprise networks by a ratio of 46 to 1. Delinea's latest capabilities are designed to provide automated guardrails that discover, manage, and protect both machine and AI identities, which are now a prevalent target for cyber threats and compliance challenges. The newly announced features include Vault AI, which automates credential access and password management for AI systems, and Secure AI, which enforces least privilege access to AI infrastructures, thereby managing entitlements and reducing the risk associated with undesired access or malfunction. Features still to come include Discover AI, scheduled for preview in the second quarter of 2025, which will assist IT administrators in identifying unauthorised AI use and the spread of machine identities across multi-cloud and hybrid environments. AI-Driven Authorisation, planned for preview in the latter half of 2025, is aimed at delivering just-in-time access for both human and machine identities with a particular focus on agentic AI, using real-time decision-making to assign and revoke privileges as needed. Another planned feature, Identity AI, will provide a native large-language model for privileged accounts and is intended to help regulated organisations meet compliance requirements while making use of advanced AI within their own environments. According to Delinea, the intent is to simplify and reinforce the management and authentication processes for all types of identities within enterprise environments. This is achieved using holistic, AI-driven security controls that are integrated into the cloud-native platform, supporting a zero-trust posture and enabling improved operational efficiency. Todd Thiemann, Principal Analyst at the Enterprise Strategy Group, commented on the significance of the new direction. He said, "Enterprises are entering an important phase where securing AI isn't just a technical challenge – it's a strategic imperative that enables the core business. Delinea's new machine identity and AI capabilities address the underappreciated risks created by the accelerating growth of non-human identities. Delinea is delivering a smart approach to AI that can discover and secure AI infrastructure as well as apply AI to improve its own technologies." With the prevalence of AI adoption in the business sector, Delinea is responding to the complexities this brings, particularly in relation to identity sprawl and compliance requirements. By providing specific solutions for AI and machine identity governance, the company states that organisations will be better positioned to secure their infrastructure at scale while maintaining productivity. Vault AI aims to help organisations align with industry best practices by automating aspects of credential management such as password rotation for AI systems. Secure AI serves to implement and manage access controls on sensitive AI infrastructure by strictly limiting access according to assigned privileges. These controls are designed to reduce potential attack surfaces or the impact of system failures. Upcoming tools such as Discover AI are expected to provide IT teams with visibility into the use of unauthorised or shadow AI tools and help ascertain the extent of machine identity sprawl within their infrastructure. AI-Driven Authorisation seeks to integrate just-in-time access management, ensuring that privileges are granted based on current needs and automatically revoked when no longer required. Identity AI, once available, is anticipated to support organisations seeking to implement AI securely while adhering to stringent regulations regarding data use and privacy, particularly in sensitive industries. Phil Calvin, Chief Product Officer at Delinea, reinforced the business implications of AI identity growth for enterprise security. He said, "AI has become an integral driver of business transformation, and it's fueling a population boom of machine identities that are reshaping the foundation of enterprise security. The power and flexibility of Agentic AI adds immense complexity to already challenging machine-to-machine authorisation. The Delinea Platform simplifies the management and authorisation of both human and machine identities, making it easier for organisations to leverage AI responsibly and safely so they can keep innovating and driving business outcomes. Other identity security platforms aren't built for AI like ours." Delinea's new and forthcoming feature set is intended to help organisations meet the dual challenge of securing their use of AI technologies and employing AI itself to strengthen overall identity security within their infrastructures.

Palo Alto Networks unveils Prisma SASE browser for AI security
Palo Alto Networks unveils Prisma SASE browser for AI security

Techday NZ

time30-04-2025

  • Techday NZ

Palo Alto Networks unveils Prisma SASE browser for AI security

Palo Alto Networks has introduced new capabilities in its Prisma SASE platform, including the Prisma Access Browser 2.0, aiming to address contemporary security risks associated with increased browser-based workflows and generative AI usage in modern workplaces. According to Palo Alto Networks, approximately 85 percent of work currently takes place within browsers, elevating risks related to data exposure and endpoint monitoring. The company's 2025 Unit 42 Incident Report highlights that 44 percent of reported security incidents are connected to activities conducted through employee browsers, including phishing, URL redirect abuse, and malware downloads. John Grady, Principal Analyst at Enterprise Strategy Group, now part of Omdia, commented on the announcement: "A secure browser extends SASE protection to where knowledge workers spend most of their time, securing third-party access, supporting BYOD, and reducing an organisation's reliance on legacy infrastructure like VDI. Palo Alto Networks unique approach of integrating its Prisma Access Browser with Prisma SASE helps organisations extend the same protection from advanced threats, user experience monitoring, and GenAI app protection from the network into the browser, ensuring users are protected, efficient, and productive." The Prisma Access Browser 2.0, positioned as the only SASE-native secure browser, is developed to support secure access for a distributed and cloud-focused workforce. It introduces several features aimed at safeguarding the use of generative AI applications, real-time data loss prevention, and advanced threat protection directly within the browser. The new browser incorporates capabilities such as real-time visibility and access control for generative AI use. By implementing large language model-powered context-based data classification, the system is designed to detect and prevent the unintentional leakage of sensitive data through clipboard functions, printing, screenshots, or typing. In addition, the browser is equipped with threat detection mechanisms powered by Precision AI, intended to identify sophisticated web-based attacks. These defences address threats such as AI-generated cloaking, SaaS-hosted phishing, evasive code, and malicious injections targeting compromised websites, which often go undetected outside the browser environment. The platform also aims to provide an improved user experience. Users can reportedly access both modern web and SaaS applications, as well as legacy infrastructure—including virtual desktop infrastructure applications—from a unified, browser-based interface. Aathir Ahad, CISO at Wipro Limited, shared his perspective: "In the AI-first era, safeguarding customer data and intellectual property is paramount. Prisma Access Browser aligns with our Zero Trust strategy and our commitment to leveraging advanced technologies for rapid threat prevention, enhanced user experience, and robust data & privacy protection." Expanding on the strategic importance, Anand Oswal, Senior Vice President and General Manager of Network Security at Palo Alto Networks, stated: "Secure browsers are absolutely essential for the modern workforce because today's work is increasingly remote, cloud-based, and data-intensive. This shift demands a unified, modern approach to security — a SASE natively integrated secure browser — that uniquely safeguards productivity, helps ensure resilience, and does so with a seamless user experience, making it the optimal choice for securing today's dynamic work environments." In addition to Prisma Access Browser 2.0, Palo Alto Networks has introduced other new features to its SASE portfolio. These include Endpoint Data Loss Prevention (DLP) to enhance shadow data discovery and insider risk mitigation, App Acceleration for improved productivity app performance branching through Prisma SD-WAN, and the Next-Generation Unified SASE Agent for streamlining IT operations. The company has also extended its partnership with Oracle Cloud Infrastructure, aiming to enhance global cloud reach and resilience for Prisma SASE customers. Karan Batta, Senior Vice President at Oracle Cloud Infrastructure, commented: "Our long-standing collaboration with Palo Alto Networks helps organisations across the world securely accelerate their cloud journey. By leveraging OCI to run Prisma SASE globally, Palo Alto Networks can provide its customers with operational resiliency, high performance, and an exceptional user experience. In addition, Prisma SASE helps our customers protect their OCI environments against emerging and sophisticated cyber threats." According to the company, the newly announced SASE features are intended to be available in the fourth quarter of its fiscal year 2025.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store