
.avif)
Nicholas Thomson
Blog posts by Nicholas Thomson
Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into root
Dirty Frag turns low-privileged Linux access into root, and can escape containers. The affected CVEs, how to check if you're exposed, and how to fix it.
Top Trivy alternatives for container and cloud scanning in 2026
Six Trivy alternatives compared for 2026 on container scanning, IaC, SAST, prioritization, and fixes, with where each one actually fits.
Top DSPM tools in 2026
Compare the top DSPM tools of 2026: Aikido, Wiz, Cyera, Varonis, and Orca, on data access, remediation, and how they find exposure
Securing Docker images
Most of a container's vulnerabilities come from the base image. How to harden Docker images, why hardening is ongoing, and how to patch the base you already run.
Top Minimus alternatives in 2026
Minimus is shutting down. Compare Aikido, Chainguard, Docker Hardened Images, RapidFort, and Echo, and pick a hardened-image replacement that won't lock you in again.
Top image hardening tools in 2026
Image hardening tools compared for 2026: Aikido, Chainguard, Docker, RapidFort, Echo, Minimus, and Wiz
Best enterprise AI pentesting tools for application security in 2026
Compare the top enterprise AI pentesting tools of 2026: Aikido, XBOW, NodeZero, Pentera, Hadrian, and Cobalt.
What is CVE remediation in 2026?
CVE remediation is fixing known flaws in the software you run. Why upgrading often fails, what remediation actually involves, and how backporting fixes it.
Top enterprise SCA tools in 2026
Compare enterprise SCA tools for 2026: Aikido, Sonatype, Snyk, Endor Labs, Checkmarx, Black Duck, and Veracode on intelligence, remediation, and compliance.
Top enterprise DAST tools in 2026
Compare the top enterprise DAST tools of 2026 on authenticated coverage, API discovery, exploit validation, governance, compliance, and AI pentesting
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

