Mondoo
All Posts

DevSecOps

Integrating security into development workflows

9 articles

Five Key Takeaways from ESG Report ‘Automating Risk Reduction in the AI Era’
6 min read

Five Key Takeaways from ESG Report ‘Automating Risk Reduction in the AI Era’

The cybersecurity landscape is undergoing one of its most significant shifts in years, driven by the emergence of AI and more recently Agentic AI. Agentic AI not only analyzes and recommends, but also acts autonomously to detect, respond, and remediate threats and vulnerabilities and threats. A recent report published by leading industry analyst Enterprise Strategy Group, now part of Omdia, and sponsored by Mondoo, reveals how fast organizations are moving from experimentation to real-world deployment, and what’s holding some of them back.

Deborah Galea
Deborah Galea · Oct 31, 2025
Introducing MCP for Mondoo: Unlocking AI to Fix CVEs faster
5 min read

Introducing MCP for Mondoo: Unlocking AI to Fix CVEs faster

We're excited to launch the Model Context Protocol (MCP) Server for Mondoo, available for private preview for Mondoo customers. MCP was created by Anthropic and has been rapidly adopted by OpenAI, Microsoft and Google. By adopting MCP, Mondoo removes integration costs and efforts to integrate into enterprise AI applications, allowing them to deliver value to customers faster. With Mondoo’s MCP server, AI models have immediate access to Mondoo’s exposure assessment data as additional context. Real-time security answers help companies to fix prioritized vulnerabilities and security findings faster.

Christoph HartmannDominik Richter
Christoph Hartmann, Dominik Richter · Apr 29, 2025
Bridging DevOps and Security with Better Tools
2 min read

Bridging DevOps and Security with Better Tools

As you take a step back to view your organization's infrastructure landscape, you might notice a pronounced rift between your build and runtime. This gap often signifies an age-old challenge – one that many organizations grapple with – the disconnect between DevOps and security.

Timon Lanzendörfer
Timon Lanzendörfer · Sep 5, 2023
Chef Infra Server CVE-2023-28864 Impact and Remediation
3 min read

Chef Infra Server CVE-2023-28864 Impact and Remediation

On June 14th, Progress Software announced the release of Chef Infra Server 15.7. The release includes additional platform support and resolves several OpenJDK CVEs by bundling a new release of OpenJDK. However, a minor yet significant detail might have been overlooked – the resolution of CVE-2023-28864.

Tim Smith
Tim Smith · Jul 17, 2023
Security Automation Takes Center Stage at HashiConf 2022
7 min read

Security Automation Takes Center Stage at HashiConf 2022

HashiConf Global 2022 wrapped up the first week of October in sunny Los Angeles, CA. We were there in person to catch all of the latest news from HashiCorp, and to celebrate the arrival of Mondoo on stage with the HashiCorp team. Here’s our recap from that event.

Scott Ford
Scott Ford · Oct 19, 2022
Mondoo’s Packer Plugin Earns Verified Status with HashiCorp
2 min read

Mondoo’s Packer Plugin Earns Verified Status with HashiCorp

The Mondoo team has two exciting announcements: We’re now a member of the HashiCorp Technology Partnership Program and our Packer provisioner has earned HashiCorp verification.

Scott Ford
Scott Ford · Sep 21, 2022
Straight to the Source - Eliminate Security Threats Before They Hit Production
5 min read

Straight to the Source - Eliminate Security Threats Before They Hit Production

For many people working in DevOps, security is starting to become a bigger part of their daily work lives. With this new reality come new challenges

Alex Miller
Alex Miller · Jul 11, 2022
Announcing Packer Plugin Mondoo
3 min read

Announcing Packer Plugin Mondoo

The Mondoo team is excited to announce the release of the Mondoo plugin for HashiCorp Packer, a powerful tool for securing and validating machine images.

Scott Ford
Scott Ford · Jun 24, 2022
Why Infrastructure as Code Is Setting You up to Make Bad Things Faster
7 min read

Why Infrastructure as Code Is Setting You up to Make Bad Things Faster

Information security is a changed game. Traditional security practices can’t keep up with the rapid acceleration of both infrastructure as code and cybercrime. It’s time for a new approach: continuous security testing throughout your development cycle.

Yvo van DoornLetha Dunn
Yvo van Doorn, Letha Dunn · Apr 27, 2022

Ready to Transform Your Security?

See how Mondoo can help you find and fix vulnerabilities faster.