• bitcoinBitcoin(BTC)$83,959.00-0.33%
  • ethereumEthereum(ETH)$2,690.130.05%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$774.47-0.55%
  • rippleXRP(XRP)$1.572.60%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$121.533.95%
  • tronTRON(TRX)$0.337483-0.87%
  • zcashZcash(ZEC)$1,550.810.27%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.83%
  • HyperliquidHyperliquid(HYPE)$91.47-2.91%
  • dogecoinDogecoin(DOGE)$0.0981212.21%
  • moneroMonero(XMR)$559.681.07%
  • chainlinkChainlink(LINK)$13.885.35%
  • whitebitWhiteBIT Coin(WBT)$83.87-0.58%
  • USDSUSDS(USDS)$1.000.00%
  • cardanoCardano(ADA)$0.2550922.95%
  • RainRain(RAIN)$0.0121550.57%
  • leo-tokenLEO Token(LEO)$8.82-1.33%
  • stellarStellar(XLM)$0.2196853.48%
  • bitcoin-cashBitcoin Cash(BCH)$340.621.46%
  • nearNEAR Protocol(NEAR)$5.066.68%
  • uniswapUniswap(UNI)$9.613.45%
  • litecoinLitecoin(LTC)$71.04-0.31%
  • CantonCanton(CC)$0.12934013.41%
  • Ethena USDeEthena USDe(USDE)$1.000.01%
  • suiSui(SUI)$1.1512.49%
  • avalanche-2Avalanche(AVAX)$10.491.06%
  • daiDai(DAI)$1.000.01%
  • USD1USD1(USD1)$1.000.02%
  • hedera-hashgraphHedera(HBAR)$0.0945121.97%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.430.67%
  • BittensorBittensor(TAO)$308.473.92%
  • BitwayBitway(BTW)$1.2921.50%
  • shiba-inuShiba Inu(SHIB)$0.0000061.35%
  • crypto-com-chainCronos(CRO)$0.0656884.05%
  • Global DollarGlobal Dollar(USDG)$1.000.01%
  • MemeCoreMemeCore(M)$1.19-2.10%
  • paypal-usdPayPal USD(PYUSD)$1.000.01%
  • tether-goldTether Gold(XAUT)$4,290.460.59%
  • OndoOndo(ONDO)$0.556.60%
  • EthenaEthena(ENA)$0.26091717.08%
  • okbOKB(OKB)$120.570.91%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • Circle USYCCircle USYC(USYC)$1.140.03%
  • aaveAave(AAVE)$152.894.90%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.15-0.05%
  • mantleMantle(MNT)$0.67-2.25%
  • polkadotPolkadot(DOT)$1.192.32%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Echo raises $35M to secure the enterprise cloud’s base layer — container images — with autonomous AI agents

December 16, 2025
in AI & Technology
Reading Time: 4 mins read
A A
Echo raises M to secure the enterprise cloud’s base layer — container images — with autonomous AI agents
ShareShareShareShareShare

As enterprises accelerate the deployment of LLMs and agentic workflows, they are hitting a critical infrastructure bottleneck: the container base images powering these applications are riddled with inherited security debt.

YOU MAY ALSO LIKE

Apple’s HomePod Mini 2 Will Reportedly Come In New Colors, But Feature A Similar Design

Aikido Security Releases Altar-1: An Open-Weight Security Model Pruned From GLM-5.3 to 328 GB

Echo, an Israeli startup, is announcing a $35 million in Series A funding today (bringing its to-date total to $50 million in funding) to fix this by fundamentally reimagining how cloud infrastructure is built.

The round was led by N47, with participation from Notable Capital, Hyperwise Ventures, and SentinelOne. But the real story isn’t the capital—it’s the company’s ambitious goal to replace the chaotic open-source supply chain with a managed, “secure-by-design” operating system.

The Hidden Operating System of the Cloud

To understand why Echo matters, you first have to understand the invisible foundation of the modern internet: container base images.

Think of a “container” like a shipping box for software. It holds the application code (what the developers write) and everything that code needs to run (the “base image”). For a non-technical audience, the best way to understand a base image is to compare it to a brand-new laptop. When you buy a computer, it comes with an Operating System (OS) like Windows or macOS pre-installed to handle the basics—talking to the hard drive, connecting to Wi-Fi, and running programs. Without it, the computer is useless.

In the cloud, the base image is that Operating System. Whether a company like Netflix or Uber is building a simple web app or a complex network of autonomous AI agents, they rely on these pre-built layers (like Alpine, Python, or Node.js) to define the underlying runtimes and dependencies.

Here is where the risk begins. Unlike Windows or macOS, which are maintained by tech giants, most base images are open-source and created by communities of volunteers. Because they are designed to be useful to everyone, they are often packed with “bloat”—hundreds of extra tools and settings that most companies don’t actually need.

Eylam Milner, Echo’s CTO, uses a stark analogy to explain why this is dangerous: “Taking software just from the open source world, it’s like taking a computer found on the sidewalk and plugging it into your [network].”

Traditionally, companies try to fix this by downloading the image, scanning it for bugs, and attempting to “patch” the holes. But it is a losing battle. Echo’s research indicates that official Docker images often contain over 1,000 known vulnerabilities (CVEs) the moment they are downloaded. For enterprise security teams, this creates an impossible game of “whac-a-mole,” inheriting infrastructure debt before their engineers write a single line of code.

The “Enterprise Linux” Moment for AI

For Eilon Elhadad, Echo’s co-founder and CEO, the industry is repeating history. “Exactly what’s happened in the past… everybody run with Linux, and then they move to Enterprise Linux,” Elhadad told VentureBeat. Just as Red Hat professionalized open-source Linux for the corporate world, Echo aims to be the “enterprise AI native OS”—a hardened, curated foundation for the AI era.

“We see ourselves in the AI native era, the foundation of everything,” says Elhadad.

The Tech: A “Software Compilation Factory”

Echo is not a scanning tool. It does not look for vulnerabilities after the fact. Instead, it operates as a “software compilation factory” that rebuilds images from scratch.

According to Milner, Echo’s approach to eliminating vulnerabilities relies on a rigorous, two-step engineering process for every workload:

  1. Compilation from Source: Echo starts with an empty canvas. It does not patch existing bloated images; it compiles binaries and libraries directly from source code. This ensures that only essential components are included, drastically reducing the attack surface.

  2. Hardening & Provenance (SLSA Level 3): The resulting images are hardened with aggressive security configurations to make exploitation difficult. Crucially, the build pipeline adheres to SLSA Level 3 standards (Supply-chain Levels for Software Artifacts), ensuring that every artifact is signed, tested, and verifiable.

The result is a “drop-in replacement.” A developer simply changes one line in their Dockerfile to point to Echo’s registry. The application runs identically, but the underlying OS layer is mathematically cleaner and free of known CVEs.

AI Defending Against AI

The need for this level of hygiene is being driven by the “AI vs. AI” security arms race. Bad actors are increasingly using AI to compress exploit windows from weeks down to days. Simultaneously, “coding agents”—AI tools that autonomously write software—are becoming the number one generators of code, often statistically selecting outdated or vulnerable libraries from open source.

To counter this, Echo has built a proprietary infrastructure of AI agents that autonomously manage vulnerability research.

  • Continuous Monitoring: Echo’s agents monitor the 4,000+ new CVEs added to the National Vulnerability Database (NVD) monthly.

  • Unstructured Research: Beyond official databases, these agents scour unstructured sources like GitHub comments and developer forums to identify patches before they are widely published.

  • Self-Healing: When a vulnerability is confirmed, the agents identify affected images, apply the fix, run compatibility tests, and generate a pull request for human review.

This automation allows Echo’s engineering team to maintain over 600 secure images—a scale that would traditionally require hundreds of security researchers.

Why It Matters to the CISO

For technical decision-makers, Echo represents a shift from “mean time to remediation” to “zero vulnerabilities by default.”

Dan Garcia, CISO of EDB, noted in a press release that the platform “saves at least 235 developer hours per release” by eliminating the need for engineers to investigate false positives or patch base images manually.

Echo is already securing production workloads for major enterprises like UiPath, EDB, and Varonis. As enterprises move from containers to agentic workflows, the ability to trust the underlying infrastructure—without managing it—may be the defining characteristic of the next generation of DevSecOps.

Pricing for Echo’s solution is not publicly listed, but the company says on its website it prices “based on image consumption, to ensure it scales with how you actually build and ship software.”

Credit: Source link

ShareTweetSendSharePin

Related Posts

Apple’s HomePod Mini 2 Will Reportedly Come In New Colors, But Feature A Similar Design
AI & Technology

Apple’s HomePod Mini 2 Will Reportedly Come In New Colors, But Feature A Similar Design

September 25, 2026
Aikido Security Releases Altar-1: An Open-Weight Security Model Pruned From GLM-5.3 to 328 GB
AI & Technology

Aikido Security Releases Altar-1: An Open-Weight Security Model Pruned From GLM-5.3 to 328 GB

September 25, 2026
Perplexity Trains Its Computer Agent on Real Mistakes With Hint-Guided Self-Distillation
AI & Technology

Perplexity Trains Its Computer Agent on Real Mistakes With Hint-Guided Self-Distillation

September 25, 2026
Microsoft’s Copilot App Adds Office, Natural Coding And Automation
AI & Technology

Microsoft’s Copilot App Adds Office, Natural Coding And Automation

September 25, 2026
Next Post
Suspected gunmen in Australia seen on bridge in Bondi Beach

Suspected gunmen in Australia seen on bridge in Bondi Beach

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Vanderbilt recovers fumble with 1 second left to stun NC State – ESPN

Vanderbilt recovers fumble with 1 second left to stun NC State – ESPN

September 19, 2026
D4vd abruptly parts ways with legal team in murder case

D4vd abruptly parts ways with legal team in murder case

September 20, 2026
Investors warn Anthropic could struggle to sustain revenues post-IPO – Financial Times

Investors warn Anthropic could struggle to sustain revenues post-IPO – Financial Times

September 19, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!