Red Hat adds deep OS security for AI agents
Red Hat has updated its OpenShift AI platform with new deep security for AI agents—essentially, bots that can browse the web or run code for you. The new 'OpenShell' feature creates hard OS-level boundaries that even clever agents can’t talk their way around. Red Hat is starting with this kernel-enforced sandbox as a preview, aiming to make this level of security standard.
- 77% of organizations now use AI agents in production
- AI agent security incidents cost over $670,000 extra on average
- OpenShell sandbox uses three Linux kernel isolation layers
- Guardrails enforced by OS, not by the agent itself
- Now available as a Developer Preview in OpenShift AI 3.5
Sources covering this
In this story
More in Enterprise
Red Hat adds NVIDIA BlueField to OpenShift
Red Hat OpenShift will now support NVIDIA BlueField hardware, aiming to make data centers faster by letting specialized cards take on tasks usually handled by main processors. By moving network traffic management and security enforcement off CPUs and onto BlueField, businesses can free up computing power for core applications and AI tasks. Red Hat says this helps cut operational costs and makes network security more robust.
Databricks launches Consort for database test branching
Databricks unveiled a new tool called Consort that lets developers create isolated branches of a real database for testing—just like code. Instead of using unreliable mock databases, you can now quickly spin up a copy, run tests (even destructive ones), and throw away the branch when done. This means code changes and database changes can be tested and shipped together, and risky updates get caught before reaching production.
Red Hat launches post-quantum certificate platform
Red Hat has released Certificate System 11, a platform designed to manage quantum-resistant digital certificates. The company says the system helps organizations identify and replace legacy cryptographic certificates, addressing new government mandates for post-quantum security. US agencies and others have begun classifying traditional encryption as a vulnerability requiring replacement, and the new tool aims to streamline migration to quantum-safe security standards.
SAP addresses critical security flaw in core software
SAP has released a patch for a maximum severity vulnerability, tracked as CVE-2026-44756, affecting the SAP kernel. Security researchers at Onapsis say over 10,000 internet-exposed SAP systems could be at risk. The flaw allows unauthenticated attackers to send crafted network requests that could let them execute arbitrary operating system commands with administrative privileges. There are currently no reports of active exploitation, but experts recommend immediate patching.