惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
The Blog of Author Tim Ferriss
Microsoft Azure Blog
Microsoft Azure Blog
S
SegmentFault 最新的问题
Schneier on Security
Schneier on Security
W
WeLiveSecurity
Webroot Blog
Webroot Blog
T
Threatpost
量子位
大猫的无限游戏
大猫的无限游戏
C
Cisco Blogs
腾讯CDC
N
News | PayPal Newsroom
T
Troy Hunt's Blog
T
Tailwind CSS Blog
Latest news
Latest news
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
The Register - Security
The Register - Security
Know Your Adversary
Know Your Adversary
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Engineering at Meta
Engineering at Meta
SecWiki News
SecWiki News
MyScale Blog
MyScale Blog
GbyAI
GbyAI
Application and Cybersecurity Blog
Application and Cybersecurity Blog
A
Arctic Wolf
The GitHub Blog
The GitHub Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Help Net Security
Help Net Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
有赞技术团队
有赞技术团队
NISL@THU
NISL@THU
L
LINUX DO - 最新话题
雷峰网
雷峰网
P
Privacy International News Feed
Spread Privacy
Spread Privacy
Attack and Defense Labs
Attack and Defense Labs
N
News and Events Feed by Topic
月光博客
月光博客
V
V2EX
H
Help Net Security
博客园 - 三生石上(FineUI控件)
U
Unit 42
B
Blog
PCI Perspectives
PCI Perspectives
G
GRAHAM CLULEY
Stack Overflow Blog
Stack Overflow Blog
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
Last Week in AI
Last Week in AI

The New Stack | DevOps, Open Source, and Cloud Native News

Agentic development hinges on verification. For cloud-native software, that is a runtime problem. AI agents need infrastructure: Why Europe’s regional cloud strategy matters Transform your AI coding agent into a deterministic Java Spring expert WeAreDevelopers is coming to the US to give unsung developers a bigger voice Cleaner AI training data, fewer bugs: Sonar’s SonarSweep explained Observability overload is drowning engineers Google’s DiffusionGemma is 4x faster than its other Gemma models Fable 5: Guardrails and burn rate are annoying users, who say it’s still better than Opus 4.8 The Anthropic leader who built Claude Code says he ditched prompting — now he just writes loops. AWS can now mathematically prove your VMs are isolated Microsoft pulled 73 GitHub repos after malware attack — but still won’t say who’s compromised Databricks wants to kill the “email me a file” problem for AI agent skills Ramp bets forward deployed engineers can do what off-the-shelf finance AI can’t Git real: AI agents aren’t just for solo developers anymore Anthropic launches Claude Mythos/Fable 5, but you better try it soon This AI agent startup ditched Anthropic for DeepSeek — and says it’s saving millions When your data model is the bottleneck: lessons from Medium’s feature store How long before we stop reading the code? The tokenmaxxing party is over, and Revenium is mopping up How AI is solving the memory crunch it created Microsoft’s pitch to enterprises: Ditch Azure Repos for GitHub, despite its rocky reliability record Claude Code’s biggest upgrade yet ran 5 agents at once — here’s what happened Why Anthropic just doubled Claude Cowork limits at no charge For years, Apache Cassandra handed this work to your team — 6.0 takes it back “A dangerous combination”: The 2 factors that can “corrupt” AI agent workflows With Foundry, Microsoft bets the enterprise AI battle is about reliability, not capability Microsoft unlocks Visual Studio for developers left behind by its own AI AI teams now deploy 1,000 times a month. Your pipeline wasn’t built for that. Microsoft just made the agent runtime free — and kept everything around it “Whoever builds the most joyous product wins”: The agent war begins Netlify CTO Dana Lawson: Writing code is no longer the job From Jupyter Notebook to production: How to ship AI systems that actually work OpenClaw used Gavriel Cohen’s code and exposed the AI Agent accountability problem Replit shows how vibe coding is getting its own financial stack — and a path to profit Cloudflare aqui-hires VoidZero: Did a piece of the open web just stabilize, or become more brittle? Cursor cuts prices and adds enterprise spend controls amid “tokenomics” reckoning Google Gemma 4 12B nearly matches 26B benchmarks — and runs on your laptop Snowflake thinks it knows what’s really slowing developers down Autonomous agents have met their biggest challenge yet: The database. Why agentic AI makes the ops platform the most important layer in the enterprise How to dramatically improve enterprise security alert tuning to battle cyberattacks Why the need for humans won’t disappear in the age of autonomous databases How to secure Kubernetes in the age of AI workloads Asana says its new AI “chief of staff” turns your Slack chaos into trackable work Nvidia’s best model is now live Mate Security’s Asaf Wiener made every backend engineer a model router. He’s right to. The AI cost crisis finally has a watchdog — just not the companies causing it How to get operational data off the factory floor without creating an IT breach Why CPUs still matter in the age of AI agents Rayfin: Microsoft’s answer to the gap between vibe coding and enterprise production Microsoft bets the enterprise AI race will be won on data context, not model power “A successful attack could be catastrophic”: Anthropic gives more groups access to Claude Mythos How GitHub plans to win developers back Microsoft really, really, really wants developers to love Windows again With Intelligent Terminal, Microsoft is reinventing the Windows terminal Microsoft debuts “Scout” at Build, a new personal agent for work OpenAI’s Codex adds new tools — Sites, Annotations, more plugins — for knowledge workers GitHub Copilot’s usage-based billing is live: Here’s what you need to know OpenAI, Anthropic, Google, Amazon, and xAI all fail on type of attack, study finds JetBrains open-sources Mellum2 to go where Claude Code can’t Claude Code vs. Cursor vs. Codex vs. Antigravity — six months in This coding agent doesn’t want your feedback — it ships without it “Blowing things up”: The one move vendors got wrong on AI agents At Sapphire, SAP makes the case that enterprise AI is a context problem Gavriel Cohen found his own code inside OpenClaw, so he walked away AI retrieval at scale is becoming a systems problem, not a tooling problem The DIY platform trap that’s burning out engineering teams I tested Cursor’s new Jira integration and it’s 5 stars, no notes. Here’s why. Why GPT-5.4, Claude, and Gemini can’t agree on basic, real-world facts Replit’s vibe coding platform just got a Visa-backed identity layer for AI agents — and it changes how agents spend money Opus 4.8 Made Claude Smarter. Token Discipline Got Urgent. Why Linux creator Linus Torvalds gets angry hearing “99% of code is AI” Vendor neutrality isn’t magic: A hard look at the OpenTelemetry ecosystem “The AI did it” won’t save you when EU regulators come knocking The fix for soaring AI cloud bills exists — so why won’t we trust it? AI is shipping code faster than security was built to handle Why AWS scrapped OpenSearch’s architecture to chase agent workloads Claude Opus 4.8 is here: effort controls, dynamic workflows, cheaper fast mode, better honesty, less deception Percona celebrates 20th birthday with new foundation — and a goat cake Why OpenAI and Anthropic are hiring forward deployed engineer teams Claw-style AI agents are coming to the enterprise. The governance infrastructure is still catching up. The agentic identity crisis: Why your security isn’t ready for the AI revolution Debugging the undebuggable: building observability into probabilistic AI systems Snowflake commits $6B to AWS as it pushes deeper into AI Why MotherDuck refuses to fork DuckDB Researcher “gave Claude Code ‘ADHD’… and it thinks 2x better now.” Outside experts want more proof. “There is no accountability”: AI coding agents are installing packages no one owns “Tokenmaxxing is real, expensive & it’s spreading”: AI budgets are exploding With Google’s debut, the most important AI agent feature is now the most boring one Why AI agents need a Context Lake Google ranks the best AI for building Android apps, and the winner isn’t Gemini Google pushes Pro, Ultra, and free users from open-source Gemini CLI to closed-source Antigravity CLI The reason enterprise outages almost never start where ops teams think Taming the agentic influx: a blueprint for AI business observability How the AC/DC framework helps teams govern AI coding agents GitLab 19.0 trades its string section for a full DevSecOps orchestra Who’s monitoring the agents? How Jaeger hit 8.6× compression on 10 million spans with ClickHouse What ClickHouse learned from a year of coding with AI agents OpenClaw passed 300,000 GitHub stars. Then Google launched Spark.
Azul wants to find your unpatched JVMs before AI does
Darryl K. Taft · 2026-06-25 · via The New Stack | DevOps, Open Source, and Cloud Native News

Azul Systems is offering a free Java Virtual Machine (JVM) vulnerability risk assessment designed to reveal Java runtime exposure before AI-assisted attackers can crack their systems, but the company’s threat framing leans heavily on Anthropic’s unverified Mythos model as its lead.

Azul, a Sunnyvale, California-based Java runtime vendor, is pitching the risk assessment tool to DevOps and SecOps teams that lack full visibility into their Java estates. Here’s how it works: The tool scans networks to identify JVM instances — including embedded and unmanaged runtimes that standard asset discovery tools often miss. After the scan, it returns a prioritized remediation roadmap cross-referenced against the CISA Known Exploited Vulnerability (KEV) catalog and the U.S. National Vulnerability Database, the company says.

Azul, of course, makes its own JVM and sells support for it, and the free scan is a lead-gen play that converts to Azul Core subscriptions.

This posture targets Azul’s security-only Critical Patch Updates, which the company claims is the only OpenJDK distribution to ship security fixes exclusively, with no new features or bundled bug patches — not AWS Corretto or Eclipse Temurin, Eric Costlow, Azul’s senior director of product management, tells The New Stack. The value proposition for customers is lower risk of breakage when patching long-running Java estates, he says.

“One of the reasons people haven’t updated their JVMs in a long time is they’re worried about breaking something,” Costlow says. “So they look at it and say, ‘It ain’t broke, don’t fix it.’ What Core offers is a version of Java that only contains security patches — all it does is fix security vulnerabilities. The risk of breaking your application by applying the security-only release is really low, because all it does is fix security bugs.”

That’s the differentiation pitch against Corretto, Eclipse Temurin, and other OpenJDK distributions.

“If you grab a Corretto or an Eclipse JVM, they’re very nice people,” Costlow says. “But they just include everything in their build. Everything that changes, it’s in there. Let’s say it has a 1% chance of breaking something — you update 100 apps, one of them breaks. Our breakage rate might be like 0.1% or something, because we don’t do that other stuff.”

The AI threat argument

The core security argument is that AI tooling has shortened mean time to exploit from months to days or hours, making unpatched Java estates more dangerous than they were even 18 months ago. Costlow describes it as AI had lowered the barrier to both discovery and weaponization.

“You can build crawlers that look for older Java versions because you can identify them through a lot of signatures,” he says. “And the exploits — where you used to say, ‘I have a version of an exploit that will attack a certain version of Spring, it used to only work in certain scenarios’ — the AI has made it a lot easier to generalize those exploits. The stuff’s easier to find and easier to attack. Unfortunately.”

In a blog post, Dana Crane, product marketing director for Platform Core, delivers research to back that up. A 2024 University of Illinois Urbana-Champaign study found that GPT-4, given appropriate scaffolding, could autonomously exploit 87% of known critical-severity CVEs with no human in the loop, at roughly $8.80 per successful exploit. A follow-up from the same group showed AI agent teams hitting zero-day vulnerabilities at a 53% success rate. More recently, an AI system called ARTEMIS placed second against human penetration testers on a live enterprise network of 8,000 hosts, finding valid vulnerabilities at $18 per hour versus $60 per hour for the humans it outperformed, the study shows.

What’s harder to assess is Azul’s lead claim, which leans heavily on Anthropic’s Mythos model — a frontier AI system that has not been publicly released and that Anthropic has kept gated to a small number of trusted organizations.

The Azul press release states that “Anthropic’s Claude Mythos demonstrates that AI can autonomously uncover previously unknown vulnerabilities and generate working exploit paths at scale.”

Moreover, Azul CEO Scott Sellers, in a statement says, “Anthropic’s Mythos has shown that AI can now discover and weaponize vulnerabilities on its own — including flaws that survived decades of human review.”

Azul’s FAQ goes further, noting “how quickly Mythos-class capability escaped its intended containment” as a reason to patch faster. However, when asked in the briefing whether the company had actually tested Mythos against JVM vulnerabilities, Costlow notes that he didn’t have access to the model. “That’s gated by a lot of government stuff,” he tells The New Stack. “It’s only for select organizations now.”

In other words, Azul is using a model it hasn’t tested, and that no one outside a handful of vetted organizations has used, as the key to its threat narrative.

What the assessment actually finds

The tool itself is a network scanner that Azul says runs over a few days with no performance impact. It identifies JVM versions and ages across the full stack, including app servers, serverless containers, and databases.

The output package includes a security dashboard broken down by risk tier, publisher, and Java version; KEV and CVE exposure analysis cross-referenced against real-world threat data; end-of-life runtime identification (Java 5, 6, and 7 instances in production, which Crane notes are “more common than most IT leaders assume”); and a patch currency gap report showing how far deployed instances are from current CPU baselines.

The regulatory angle targets PCI-DSS, SOX, HIPAA, DORA, NERC CIP, and FedRAMP. These frameworks require demonstrable visibility into deployed software versions and documented patch history.

“A lot of people in the PCI DSS space are supposed to be patching their JVMs, but aren’t,” Costlow says. “If you haven’t patched in eight years, it’s really built up. I refer to it as a CDE tsunami.”

Meanwhile, Crane says: “A typical assessment reveals that a small number of Java versions — often just two or three — account for the lion’s share of risk across an enterprise estate. That makes mitigation far more tractable than it initially appears.”

The assessment is available at no cost from Azul and through select partners, at azul.com/jvm-vulnerability-risk-assessment.

YOUTUBE.COM/THENEWSTACK

Tech moves fast, don't miss an episode. Subscribe to our YouTube channel to stream all our podcasts, interviews, demos, and more.

Created with Sketch.