RapidFort Creates Multiple Alliances to Better Secure Cloud-Native Applications
TL;DR — Key Takeaways
– RapidFort has partnered with Wiz and Aqua Security to integrate its curated container image advisories and remediation data into widely used cloud security and vulnerability scanning tools.
– The integrations are designed to help DevSecOps teams move more quickly from vulnerability detection to remediation using hardened container images with fewer known CVEs.
– RapidFort has also entered a cooperative research and development agreement with SpaceWERX focused on improving cyber readiness and reducing authorization-to-operate timelines for the U.S. Space Force.
RapidFort, a provider of curated open source container images, has allied with both Wiz and Aqua Security to streamline DevSecOps workflows for organizations building and deploying cloud-native applications.
Additionally, RapidFort has inked a cooperative research and development agreement with SpaceWERX, an arm of the United States Space Force (USSF) and a division of the Air Force Research Laboratory (AFRL) that allies with IT vendors and academic institutions to find ways to apply commercial technologies to use cases involving the USSF space program.
Michael Wood, chief marketing officer for RapidFort, said RapidFort’s advisory feed will now surface directly within the Wiz cloud security platform and the Trivy scanner provided by Aqua Security. That capability will make it simpler for DevSecOps teams to identify instances of curated containers that can be used to remediate issues discovered by cybersecurity teams using tools provided by Wiz and Aqua Security. Those alliances come on the heels of a previous integration with CrowdStrike announced last month.
In general, the overall goal is to make it simpler for application development and cybersecurity teams to keep pace with the rate at which vulnerabilities are being remediated, added Wood.
It’s not clear at what pace application developers are adopting curated container images to improve application security, but as cybercriminals continue to rely more on artificial intelligence (AI) models to discover vulnerabilities and create exploits in a matter of hours, the issue is coming to a head. Far too often, application developers have tended to download images from multiple repositories without first checking for known vulnerabilities. Hopefully, any vulnerability that might exist is discovered before that code makes it into a production environment, but given the number of breaches that are traced back to a known vulnerability, it’s apparent that not enough diligence has been applied to application security.
Instead, organizations have prioritized speed of delivery to the point now where many of them have massive amounts of security debt in the form of vulnerabilities that are now being discovered at rates most DevSecOps teams are not prepared to remediate.
The level of DevSecOps maturity being applied naturally varies from one organization to another. Not very many, in fact, even have a dedicated team reviewing code, and when they do, the number of application developers building software usually far outnumbers the DevSecOps engineers tasked with nominally reviewing it. That issue has only become more problematic in the AI era as the volume of code being generated continues to exponentially increase. In theory at least, DevSecOps engineers should be able to rely more on AI to discover those vulnerabilities but, for now, not many DevSecOps teams have integrated AI agents for reviewing code into their pipelines.
Arguably, it’s now more a question of when, rather than if, DevSecOps workflows will be upgraded to achieve that goal as more known and newly discovered vulnerabilities are exploited. In the meantime, however, DevSecOps teams while continuing to hope for the best would be well-advised to prepare now for what might soon become the proverbial worst of times.
Frequently Asked Questions
What is RapidFort doing with Wiz and Aqua Security?
RapidFort is integrating its curated container image advisories and remediation data with Wiz and Aqua Security’s Trivy scanner to help teams identify safer container images when vulnerabilities are discovered.
How could these integrations help DevSecOps teams?
They could shorten the gap between identifying a vulnerable container and replacing or remediating it with a hardened image containing fewer known vulnerabilities.
What is RapidFort’s agreement with SpaceWERX focused on?
The cooperative research and development agreement is aimed at improving cyber readiness and reducing authorization-to-operate timelines for U.S. Space Force systems.


