Thursday, September 3, 2026
Cloud Native Now

Cloud Native Now


MENUMENU
  • Home
  • Webinars
    • Upcoming
    • On-Demand
    • Calendar View
  • Podcasts
    • Cloud Native Now Podcast
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
  • About
  • Sponsor
MENUMENU
  • News
    • Latest News
    • News Releases
  • Cloud-Native Development
  • Cloud-Native Platforms
  • Cloud-Native Networking
  • Cloud-Native Security
Containers Features Kubernetes Social - Facebook Social - LinkedIn Social - X Topics 

BellSoft’s 3-in-1 Strategy for Container Security

November 11, 2025 Jeff Burt 3-in-1 approach, AI threats, Chainguard, cloud native security, cloud security, container hardening, container incidents, container security, container vulnerabilities, containerized applications, CVE remediation, distroless containers, hardened containers, Hardened Images, Java runtime optimization, kubernetes, lightweight Linux, regulatory compliance, runtime security, secure container images, secure DevOps, software supply chain, Vulnerability Management
by Jeff Burt

Containers have made life a lot easier for programmers, making application development portable and solving what cybersecurity firm SentinelOne calls the “it only works in my machine” problem. Given that, it’s not surprising that container adoption among developers continues to grow rapidly. 

But with that popularity comes attention from threat actors looking to exploit container use and the inherent weaknesses in them. NetRise found that two-thirds of organizations in 2024 experienced a container-related security incident, while a Red Hat study said a typical container image carries more than 600 known vulnerabilities, almost half of which are years old.  

Techstrong Gang Youtube

In addition, Datadog researchers found that 44% of Java services contain security flaws that have been exploited. 

“The adoption of container technology is rapidly growing, largely because it is lightweight and easy to manage,” NetRise CEO Thomas Pace said late last year. “However, while containers have changed how many modern applications are designed, deployed, and managed, they appear to be among the weakest cybersecurity links in the software supply chain.” 

Hardened Images 

BellSoft is rolling out Hardened Images, a tool for improving the security of containerized applications in Kubernetes by removing package managers and non-essential components, which the company said will reduce vulnerabilities and limit the attack vectors. They also include a locked configuration that can’t be modified, which keeps attackers from injecting malware or tampering with the runtime environment. 

“Our solution addresses seemingly an impossible task,” BellSoft CEO Alex Belokrylov told Cloud Native Now. “From now on, we can provide a foundation that can be trusted and depended on for years.” 

It’s part of a trend by vendors to ensure the security of containers by removing unnecessary elements that can open them up to security threats. For example, Chainguard has a growing list of its own images in a repository that gives developers access to hardened container images that are free of known-exploited vulnerabilities. 

Not a New Problem 

“This isn’t a new problem,” Belokrylov said. “The industry has been addressing it for decades through various approaches: lightweight Linux distributions, distroless images, and now hardened containers. Each represents an evolution in our collective effort to build more secure systems. What’s fundamentally different today is the convergence of three forces that are transforming this from a technical challenge into a strategic solution.” 

Those forces include global regulatory frameworks that require organizations to ensure unprecedented levels and security accountability and a threat landscape being remade by AI. 

“Vulnerability exploitation that once took weeks or months now happens in days or even hours,” the CEO said. “We’re in a time-based competition, and the clock is accelerating.” 

He added that “large enterprises find themselves in an increasingly untenable position: growing codebases, aging legacy systems, and expanding regulatory requirements, all while the threat environment becomes more sophisticated.” 

Security and Performance 

Bellsoft’s Hardened Images are based on what the vendor calls its “3-in-1” approach that delivers complete security and performance coverage via Java runtime optimization, custom maintenance for the vendor’s Alpaquita Linux OS, and proactive remediation of common vulnerabilities and exposures (CVEs). 

The strategy separates BellSoft from a growing field of firms with container security solutions, Belokrylov said. Most of them focus on vulnerability detection and remediation; a solution also needs to be able to fix bugs, which requires deep expertise in the runtime OS and an understanding of how components fundamentally interact, which he said BellSoft has. 

“That kind of expertise makes the difference when you need actual fixes, not just randomly available patches,” he said.  

A Unified Approach 

However, a challenge is that when an urgent fix is needed, the runtime support can come from one vendor and the hardened images from another, which raises such questions as who validates compatibility and who’s accountable if something breaks. BellSoft’s 3-in-1 approach means the vendor provides support for the Liberica JDK runtime and Alpaquita Linux OS. 

“When an issue emerges, there’s no finger-pointing between different vendors, no integration challenges, no question about who owns the solution,” Belokrylov said. “We do. This represents a shift from the fragmented approach that has dominated the market. From now on, there is an integrated solution built on deep runtime expertise, with clear accountability from day one.”

  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Reddit (Opens in new window) Reddit

Related

  • ← Buoyant to Add MCP Support to Linkerd Service Mesh
  • CNCF: Total Number of Cloud Native Developers Reaches 15.6M →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

UPCOMING WEBINARS

  • CloudNativeNow.com
  • Error
  • SecurityBoulevard.com
The Economics of Infrastructure Modernization
4 November 2026
The Economics of Infrastructure Modernization
Modernize for the AI Era
14 October 2026
Modernize for the AI Era
Migrating Apache Solr Workloads to Amazon OpenSearch Service
29 September 2026
Migrating Apache Solr Workloads to Amazon OpenSearch Service

RSS Error: Retrieved unsupported status code "403"

Practitioner Perspective: Achieving Fine-Grained Control for Data and AI on the Endpoint
20 October 2026
Practitioner Perspective: Achieving Fine-Grained Control for Data and AI on the Endpoint
Agentic Runtime Security on AWS: Identity, Least Privilege, and Audit for AI Agents with IBM Verify Identity Access and HashiCorp Vault
1 October 2026
Agentic Runtime Security on AWS: Identity, Least Privilege, and Audit for AI Agents with IBM Verify Identity Access and HashiCorp Vault
Closing the Loop on AI Coders: 3,200 Vulns Fixed with Zero Human Triage
1 October 2026
Closing the Loop on AI Coders: 3,200 Vulns Fixed with Zero Human Triage

Podcast


Listen to all of our podcasts

Press Releases

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Deloitte Partners with Memcyco to Combat ATO and Other Online Attacks with Real-Time Digital Impersonation Protection Solutions

Deloitte Partners with Memcyco to Combat ATO and Other Online Attacks with Real-Time Digital Impersonation Protection Solutions

SUBSCRIBE TO CNN NEWSLETTER

MOST READ

Kubernetes Key Management Streamlined by HashiCorp Vault Plug-In

August 6, 2026

Docker Desktop Gets a Hypervisor of its Own

August 13, 2026

Red Hat Readies an MCP Server to Help LLMs Manage Kubernetes

August 19, 2026

Kubeflow’s Graduation Is a Vote for Kubernetes as the AI Control Plane

August 19, 2026

CNCF Graduates Kubeflow for Production AI on Kubernetes

August 18, 2026

RECENT POSTS

Containers Became the Unit of Speed. AI Agents Are Making VMs the Unit of Trust
Containers Features News Social - Facebook Social - LinkedIn Social - X Topics 

Containers Became the Unit of Speed. AI Agents Are Making VMs the Unit of Trust

September 2, 2026 Alan Shimel 0
DataAgent Emerges From Stealth To Bring Autonomous Remediation to Kubernetes
Cloud-Native Architecture Features Kubernetes Observability Open Source Social - Facebook Social - LinkedIn Social - X Topics 

DataAgent Emerges From Stealth To Bring Autonomous Remediation to Kubernetes

September 1, 2026 Jaime Hampton 0
Kubernetes v1.37 Enhances Dynamic Resource Allocation
Cloud-Native Development Container Orchestration Features Kubernetes Kubernetes - Beyond Orchestration Open Source Social - Facebook Social - LinkedIn Social - X 

Kubernetes v1.37 Enhances Dynamic Resource Allocation

August 28, 2026 Joab Jackson 0
From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments
Cloud-Native Security Cloud-Native Security Compliance Contributed Content DevSecOps Social - Facebook Social - LinkedIn Social - X Topics 

From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments

August 27, 2026 Ramachander Rao Thallada 0
Echo Acquires Hardened Container Assets from Minimus
Cloud-Native Development Containers DevSecOps Features Social - Facebook Social - LinkedIn Social - X 

Echo Acquires Hardened Container Assets from Minimus

August 27, 2026 Mike Vizard 0
  • About
  • Media Kit
  • Sponsor Info
  • Write for Cloud Native Now
  • Copyright
  • TOS
  • Privacy Policy
Powered by Techstrong Group
Copyright © 2026 Techstrong Group, Inc. All rights reserved.
×

Modern Software Development and Delivery 

1Q1
2Q2
3Q3
4Q4
5Q5
6Q6
How would you best describe your organization's current software delivery environment(s) on mainframe computers? (Select all that apply)(Required)
Which outcomes are most important to your organization's software delivery strategy today? (Select up to three)(Required)
What, if anything, is limiting your organization's mainframe software delivery progress? (Select up to three)(Required)
In which areas of your mainframe software delivery environment are you currently using AI? (Select all that apply)(Required)
As software delivery responsibilities expand beyond traditional build, test, and deploy, which of the following areas is the most challenging for your organization today with respect to mainframe software delivery? (Select one)(Required)
Which of the following do you expect is most likely to accelerate your organization's mainframe software delivery progress over the next 12-18 months? (Select one)(Required)

×