-

RapidFort Launches Industry’s First End-to-End Continuous Threat Elimination by Extending Leading Software Supply Chain Security Into Live Production Environments

Unveiled at Black Hat USA 2026, RapidFort Runtime Uniquely Delivers End-to-End Continuous Monitoring of Live Environments to Detect and Address CVEs Emerging After Software Deployment

LAS VEGAS--(BUSINESS WIRE)--(Black Hat USA 2026 Booth #5704) -- RapidFort, the leader in Software Supply Chain Security (SSCS) with the largest distribution of curated truly open-source software, today at Black Hat USA 2026 launched RapidFort Runtime, a real-time-based security solution that extends RapidFort’s leading SSCS functionalities into live production environments, creating the industry’s first genuinely end-to-end continuous threat elimination solution – from curated, independently malware-scanned open-source software before deployment to continuous CVE monitoring and tamper detection in live production environments.

Unveiled in Black Hat booth No. 5704, RapidFort Runtime operates inside an organization’s production environment continuously monitoring deployed software, detecting unauthorized or unexpected changes, and proactively tracking newly discovered CVEs.

Share

Unveiled in Black Hat booth No. 5704 and demonstrated publicly for the first time, RapidFort Runtime operates inside an organization’s production environment continuously monitoring deployed software, detecting unauthorized or unexpected changes, and proactively tracking newly discovered CVEs. It notifies administrators and developers of relevant security impacts and provides actionable mitigation recommendations. This industry-first capability delivers top-level visibility that distinguishes between first-party and third-party software, generates a precise Runtime Bill of Materials (RBOM®), and provides evidence of the software and processes executing in production. It integrates into existing CI/CD pipelines without requiring code changes, effectively bridging the gap between pre-production security and live runtime protection.

Together with RapidFort curated open-source software catalog and hardened images validated through ReversingLabs deep-binary malware analysis, RapidFort Runtime enables organizations to verify both what enters production and whether deployed software remains intact once it is running.

“Maintaining an accurate, real-time inventory of what is actually executing in production has been a consistent audit and compliance hurdle,” said Sangram Dash, CISO and VP of IT, Sisense. “RapidFort Runtime’s ability to generate a precise, dynamic RBOM provides us with undeniable evidence of our software’s state. We can now verify integrity and confirm our compliance in real-time, which is a total game-changer for our security operations.”

RapidFort Runtime differentiating new capabilities include:

  • End-to-End Continuous Monitoring: Monitors live production environments to detect and address CVEs that emerge after software deployment, solving the “production obsolescence” problem where software is often “born outdated” and immediately vulnerable when it hits production due to new CVE disclosures.
  • Agent-Based Runtime Profiling: Uses BPF/ptrace instrumentation to map system calls, network/memory usage, and process execution, providing cryptographic evidence of what is truly running.
  • Proactive Mitigation Recommendations: Beyond just detection, the platform notifies administrators of new relevant security impacts and offers actionable mitigation recommendations to fix them in live environments.
  • Automated Runtime Bills of Materials Generation: Continuously produces dynamic RBOMs for audit-ready compliance.
  • Curated, Independently Malware-Scanned Software: Integrates with the RapidFort extensive catalog of curated open-source libraries and hardened container images, validated through ReversingLabs deep-binary malware analysis, to reduce the risk of compromised or unverified software reaching production.
  • Runtime Tamper Detection and Integrity Monitoring: Establishes a verifiable baseline of approved software and continuously detects changes to packages, binaries, libraries, processes, and runtime behavior, providing evidence of what changed and where the change occurred.

“While most software supply chain security tools stop at build-time or deployment, RapidFort continuously monitors live production environments for newly disclosed CVEs that impact deployed software,” said Rajeev Thakur, CTO of RapidFort. “By automatically correlating new vulnerabilities with running workloads, RapidFort eliminates the manual effort of tracking CVEs and determining real production exposure, enabling organizations to respond faster and with greater confidence.”

RapidFort Runtime leverages lightweight agents that utilize BPF and ptrace technology to continuously monitor the software running in live production environments where threats and anomalies are most critical. Only RapidFort uses BPF/ptrace to deliver true runtime intelligence and actual evidence of execution, which drastically reduces false positives and vulnerability noise over relying solely on static analysis or scanning.

Unlike competitors that force migration to proprietary package managers or “distroless” images, RapidFort provides zero-overhead integration with drop-in replacement that supports standard package managers (pip, npm, apk). It is fully aligned with BSI TR-03183 Part 2, NIS2 (enforcement Dec 2025), and EU Cyber Resilience Act (CRA) requirements; and supports CIS Benchmarks and STIG validation, ensuring suitability for defense and mission-critical cloud-native deployments.

Availability

RapidFort Runtime is currently generally available. For more information visit https://www.rapidfort.com/platform/runtime.

About RapidFort

RapidFort leads the Software Supply Chain Security market with the largest distribution of curated, genuinely open-source software. Its platform enables organizations to eliminate risk at scale through hardened near-zero CVE container images, runtime profiling, attack surface management, and the industry's first independently malware-scanned open-source images – cutting CVE exposure by up to 99.9% without code changes or platform migration. RapidFort is recognized in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security, named a Gartner® Cool Vendor™, and honored as a Nutanix .Next Partner of the Year. The company is backed by Blue Cloud Ventures and Forgepoint Capital and headquartered in Sunnyvale, Calif. Visit www.RapidFort.com.

RapidFort, RAPIDFORT, and RBOM are registered trademarks of RapidFort, Inc. All other marks and names mentioned herein may be trademarks of their respective companies.

Contacts

Dan Spalding
dan.spalding@rapidfort.com
(408) 960-9297

RapidFort


Release Summary
RapidFort launches end-to-end continuous threat elimination by extending leading software supply chain security into live production environments.
Release Versions

Contacts

Dan Spalding
dan.spalding@rapidfort.com
(408) 960-9297

More News From RapidFort

RapidFort Recognized as a 2026 Top InfoSec Innovator for Software Supply Chain Security

SUNNYVALE, Calif.--(BUSINESS WIRE)--RapidFort is recognized as a Top InfoSec Innovator in 2026 for Software Supply Chain Security....

RapidFort and ReversingLabs Launch Industry’s First Independently Validated Open-Source Dependency Libraries Delivering Safe Package Catalogs

SAN JOSE, Calif.--(BUSINESS WIRE)--RapidFort and ReversingLabs launch industry’s first independently validated open-source dependency libraries delivering safe package catalogs....

RapidFort Recognized in 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security for Delivering Mandatory Features for SSCS Market

SUNNYVALE, Calif.--(BUSINESS WIRE)--RapidFort recognized in 2026 Gartner Magic Quadrant for Software Supply Chain Security report for delivering mandatory features for the SSCS market....
Back to Newsroom