NeuVector Releases New Vulnerability Management Tools
April 14, 2020

NeuVector announced the NeuVector platform includes new features – purpose-built for enterprise DevOpps and security teams – focused on automated end-to-end vulnerabilitty management and protection, expanded registry scanning, and host protection in production environments.

The platform additions include the new Vulnerability and Compliance Explorer for quickly investigating, prioritizing, reporting, and mitigating potentially damaging vulnerability and compliance issues. High performance large-registry scanning and enhanced host (node) security processes have also been added.

NeuVector's new Vulnerability and Compliance Explorer enables DevOps and security teams to:

- Assess the current state of container security by identifying assets, scanning registries, and receiving comprehensive reports.

- Prioritize which images, nodes, or containers are most in need of attention.

- Respond to and mitigate any areas with security and compliance risk.

- Improve ongoing security procedures (and rescan to confirm improvements).

Importantly, the Explorer adds virtual patching as part of its response mechanism. This critical security feature gives DevOps teams the ability to virtually patch vulnerabilities in production containers or hosts without needing to actually patch or remediate that vulnerability in a library or package. Doing so gives enterprises confidence deploying containers in production environments that have vulnerabilities without a current fix available. NeuVector is able to do this by whitelisting all authorized application container behavior – such as network connections, processes, and file activity – either through NeuVector's behavioral learning processes or automatically via security policy as code. Any attempted exploit on a workload or host protected by NeuVector is then detected, alerted, and blocked (depending on user settings). In addition to virtually patching vulnerabilities, these same run-time security capabilities also protect enterprises against embedded malware, zero-day attacks, and insider or phishing attacks.

The platform release also introduces high performance scanning for images in large registries. DevOps teams can deploy additional scanners to run in parallel, quickly scanning registries with thousands or even tens of thousands of images. This new capability builds on NeuVector's market-leading scanner performance that easily handles enterprise requirements.

Additionally, the release strengthens host (node) protection in production environments. Now, just as NeuVector automatically baselines and whitelists container processes to detect suspicious activity, host processes are baselined and hosts can be put into an alert-or-block mode. This enhances existing host protections that include detecting privilege escalations as well as known suspicious processes (such as reverse shells, port scanning, and tunnels). Hosts are automatically scanned for vulnerabilities and run Docker and Kubernetes standards-based or customized compliance checks.

"Today's additions to the NeuVector platform make it even easier for DevOps and security teams to achieve end-to-end vulnerability insight and protection – helping them get in front of any issues and ensure their security compliance," said Gary Duan, CTO, NeuVector. "Alongside our new high-performance parallel scanning and reinforced host process protections, we're proud to make these key platform additions available to our customers. There's no easier or more thorough way to automate container security across the entire lifecycle."

Share this

Industry News

April 03, 2025

StackGen has partnered with Google Cloud Platform (GCP) to bring its platform to the Google Cloud Marketplace.

April 03, 2025

Tricentis announced its spring release of new cloud capabilities for the company’s AI-powered, model-based test automation solution, Tricentis Tosca.

April 03, 2025

Lucid Software has acquired airfocus, an AI-powered product management and roadmapping platform designed to help teams prioritize and build the right products faster.

April 03, 2025

AutonomyAI announced its launch from stealth with $4 million in pre-seed funding.

April 02, 2025

Kong announced the launch of the latest version of Kong AI Gateway, which introduces new features to provide the AI security and governance guardrails needed to make GenAI and Agentic AI production-ready.

April 02, 2025

Traefik Labs announced significant enhancements to its AI Gateway platform along with new developer tools designed to streamline enterprise AI adoption and API development.

April 02, 2025

Zencoder released its next-generation AI coding and unit testing agents, designed to accelerate software development for professional engineers.

April 02, 2025

Windsurf (formerly Codeium) and Netlify announced a new technology partnership that brings seamless, one-click deployment directly into the developer's integrated development environment (IDE.)

April 02, 2025

Opsera raised $20M in Series B funding.

April 02, 2025

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, is making significant updates to its certification offerings.

April 01, 2025

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the Golden Kubestronaut program, a distinguished recognition for professionals who have demonstrated the highest level of expertise in Kubernetes, cloud native technologies, and Linux administration.

April 01, 2025

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade internal developer portal based on the Backstage project.

April 01, 2025

Platform9 announced that Private Cloud Director Community Edition is generally available.

March 31, 2025

Sonatype expanded support for software development in Rust via the Cargo registry to the entire Sonatype product suite.

March 31, 2025

CloudBolt Software announced its acquisition of StormForge, a provider of machine learning-powered Kubernetes resource optimization.