QUOR BLOG

Security and open source:
What we're learning along the way.

Security and open source:
What we're learning along the way.

All

Product

Research

Event

EVENT

Cybersecurity Forum 2026: o que ouvimos no evento no dia 9 de março

No dia 9 de março estivemos no 5º Cybersecurity Forum, organizado pela TI Inside, um dos veículos de tecnologia mais relevantes do Brasil e que, mais uma vez, reuniu o evento com muita competência e cuidado. Do espaço às conexões que aconteceram ali, a curadoria fez diferença. Saímos de lá com conversas boas, algumas confirmações e com uma percepção ainda mais clara sobre o momento que o mercado está vivendo.

Head of Product

Camila Bedretchuk

RESEARCH

Syft - Decompression bomb vulnerability - CVE-2026-33481

Syft is one of the most widely adopted SBOM generation tools, used by Docker, Grafana, Helm, OpenTelemetry, and hundreds of other projects. Our Security Researcher, Heitor Gouvêa, identified a decompression bomb vulnerability in Syft: a malicious file of ~200KB can expand to hundreds of gigabytes during a scan, exhausting disk space and taking down entire CI/CD pipelines. The vulnerability was reported in February, confirmed by the Anchore team, and patched yesterday.

Security Researcher

Heitor Gouvêa

RESEARCH

SBOM: what is Software Bill of Materials and how to apply it in software security

The discussion about SBOM (Software Bill of Materials) has shifted from being a peripheral topic in security to becoming a central part of modern software engineering.

Security Researcher

Heitor Gouvêa

RESEARCH

Analysis of CVE-2026-24512: configuration injection in ingress-nginx

CVE-2026-24512 describes a configuration injection vulnerability in ingress-nginx, the officially reported impact includes code execution in the context of the controller and exposure of secrets accessible by it.

Security Researcher

Heitor Gouvêa

RESEARCH

How much does the CVE Management (CVE management) cost and why does it become an operational "tax"?

The "tax" of CVE management does not appear as a line in the budget. It manifests in consumed capacity, windows of change, and lost predictability. This post proposes a simple baseline and shows how Quor's calculator helps to qualify the ROI conversation.

Head of Product

Camila Bedretchuk

PRODUCT

Year-end with Quor: your engineering team’s secret friend

We imagine Quor taking his engineering team to the Secret Santa and we listed what he packed as a gift.

Head of Product

Camila Bedretchuk

PRODUCT

Quor Changelog: Auditable trail of CVEs, fixes, and digests

The demand comes with a simple audit question, usually related to SOC 2 or PCI DSS: what changed, when it changed, and in which artifact.

Head of Product

Camila Bedretchuk

PRODUCT

AI, SecOps, and Product Security: connecting the source and effect of risk with a Zero-CVE approach

AI increases the speed of software development; the SOC operates at the limit to absorb signals and decisions. The convergence between Product Security and SecOps reduces noise, risk, and exposure.

Head of Product

Camila Bedretchuk

RESEARCH

Decree No. 12,573 and E-Ciber: why it matters and what really changes

Decree No. 12,573 formalizes the National Cybersecurity Strategy. Understand the pillars of E-Cyber, its impacts on essential services, and the challenges that still remain open.

CEO

Diogo Goebel

PRODUCT

Software supply chain glossary (Kubernetes, containers, SBOM, CVEs): Quor Edition

We have gathered in a single glossary the terms that most often appear in conversations about security in Kubernetes.

Head of Product

Camila Bedretchuk

RESEARCH

runC under Attack: How CVEs 2025-31133, 52565, and 52881 Allow Container Escape

Running conditions in runC mounts lead to Container Escape and Bypass of Linux Policies

CTO

John Brito

RESEARCH

Re-exploring CVE-2021-43798 in Grafana

How to explore, detect, and block with NetworkPolicies and Admission Policies

CTO

John Brito

RESEARCH

RediShell on Redis

Why this CVE with a CVSS score of 10 deserves your attention now!

CTO

John Brito

RESEARCH

Goodbye to Public Images: the end of an era and the beginning of a new one!

The end of free public images does not mean the end of innovation. On the contrary, it represents a necessary maturity.

CTO

John Brito

EVENT

Get up at the Gartner CIO & IT Executive Conference 2025: presenting the Quor

September 2025. Getup arrived at the Gartner CIO & IT Executive Conference in São Paulo with something new to show and a good dose of anticipation about how it would be received.

Head of Product

Camila Bedretchuk

RESEARCH

Do you know what a CVE is? And what it can do to your product strategy?

Because product leaders should treat security as part of planning and not as an exception in engineering.

Head of Product

Camila Bedretchuk

RESEARCH

Shift-Left and Economics: Why Fixing Issues Early Is Cheaper?

The financial impact of a well-applied strategy.

CTO

John Brito

RESEARCH

Not All Inheritance Is Good: The Risk of Container Images

How is the security of your container images?

CTO

John Brito

RESEARCH

Who would be fired if a CVE in their container was exploited?

The increase in the use of containers and the consequent challenge of managing vulnerabilities (CVEs).

CEO

Diogo Goebel

RESEARCH

The Challenge of Vulnerability Management [CVEs]: Insights from Getup Clients

Discover how Getup is addressing the problem of vulnerabilities in containers, reducing CVEs by up to 90% and making security more efficient without impacting productivity.

CEO

Diogo Goebel

All

Product

Research

Event

EVENT

Cybersecurity Forum 2026: o que ouvimos no evento no dia 9 de março

No dia 9 de março estivemos no 5º Cybersecurity Forum, organizado pela TI Inside, um dos veículos de tecnologia mais relevantes do Brasil e que, mais uma vez, reuniu o evento com muita competência e cuidado. Do espaço às conexões que aconteceram ali, a curadoria fez diferença. Saímos de lá com conversas boas, algumas confirmações e com uma percepção ainda mais clara sobre o momento que o mercado está vivendo.

Head of Product

Camila Bedretchuk

RESEARCH

Syft - Decompression bomb vulnerability - CVE-2026-33481

Syft is one of the most widely adopted SBOM generation tools, used by Docker, Grafana, Helm, OpenTelemetry, and hundreds of other projects. Our Security Researcher, Heitor Gouvêa, identified a decompression bomb vulnerability in Syft: a malicious file of ~200KB can expand to hundreds of gigabytes during a scan, exhausting disk space and taking down entire CI/CD pipelines. The vulnerability was reported in February, confirmed by the Anchore team, and patched yesterday.

Security Researcher

Heitor Gouvêa

RESEARCH

SBOM: what is Software Bill of Materials and how to apply it in software security

The discussion about SBOM (Software Bill of Materials) has shifted from being a peripheral topic in security to becoming a central part of modern software engineering.

Security Researcher

Heitor Gouvêa

RESEARCH

Analysis of CVE-2026-24512: configuration injection in ingress-nginx

CVE-2026-24512 describes a configuration injection vulnerability in ingress-nginx, the officially reported impact includes code execution in the context of the controller and exposure of secrets accessible by it.

Security Researcher

Heitor Gouvêa

RESEARCH

How much does the CVE Management (CVE management) cost and why does it become an operational "tax"?

The "tax" of CVE management does not appear as a line in the budget. It manifests in consumed capacity, windows of change, and lost predictability. This post proposes a simple baseline and shows how Quor's calculator helps to qualify the ROI conversation.

Head of Product

Camila Bedretchuk

PRODUCT

Year-end with Quor: your engineering team’s secret friend

We imagine Quor taking his engineering team to the Secret Santa and we listed what he packed as a gift.

Head of Product

Camila Bedretchuk

PRODUCT

Quor Changelog: Auditable trail of CVEs, fixes, and digests

The demand comes with a simple audit question, usually related to SOC 2 or PCI DSS: what changed, when it changed, and in which artifact.

Head of Product

Camila Bedretchuk

PRODUCT

AI, SecOps, and Product Security: connecting the source and effect of risk with a Zero-CVE approach

AI increases the speed of software development; the SOC operates at the limit to absorb signals and decisions. The convergence between Product Security and SecOps reduces noise, risk, and exposure.

Head of Product

Camila Bedretchuk

RESEARCH

Decree No. 12,573 and E-Ciber: why it matters and what really changes

Decree No. 12,573 formalizes the National Cybersecurity Strategy. Understand the pillars of E-Cyber, its impacts on essential services, and the challenges that still remain open.

CEO

Diogo Goebel

PRODUCT

Software supply chain glossary (Kubernetes, containers, SBOM, CVEs): Quor Edition

We have gathered in a single glossary the terms that most often appear in conversations about security in Kubernetes.

Head of Product

Camila Bedretchuk

RESEARCH

runC under Attack: How CVEs 2025-31133, 52565, and 52881 Allow Container Escape

Running conditions in runC mounts lead to Container Escape and Bypass of Linux Policies

CTO

John Brito

RESEARCH

Re-exploring CVE-2021-43798 in Grafana

How to explore, detect, and block with NetworkPolicies and Admission Policies

CTO

John Brito

RESEARCH

RediShell on Redis

Why this CVE with a CVSS score of 10 deserves your attention now!

CTO

John Brito

RESEARCH

Goodbye to Public Images: the end of an era and the beginning of a new one!

The end of free public images does not mean the end of innovation. On the contrary, it represents a necessary maturity.

CTO

John Brito

EVENT

Get up at the Gartner CIO & IT Executive Conference 2025: presenting the Quor

September 2025. Getup arrived at the Gartner CIO & IT Executive Conference in São Paulo with something new to show and a good dose of anticipation about how it would be received.

Head of Product

Camila Bedretchuk

RESEARCH

Do you know what a CVE is? And what it can do to your product strategy?

Because product leaders should treat security as part of planning and not as an exception in engineering.

Head of Product

Camila Bedretchuk

RESEARCH

Shift-Left and Economics: Why Fixing Issues Early Is Cheaper?

The financial impact of a well-applied strategy.

CTO

John Brito

RESEARCH

Not All Inheritance Is Good: The Risk of Container Images

How is the security of your container images?

CTO

John Brito

RESEARCH

Who would be fired if a CVE in their container was exploited?

The increase in the use of containers and the consequent challenge of managing vulnerabilities (CVEs).

CEO

Diogo Goebel

RESEARCH

The Challenge of Vulnerability Management [CVEs]: Insights from Getup Clients

Discover how Getup is addressing the problem of vulnerabilities in containers, reducing CVEs by up to 90% and making security more efficient without impacting productivity.

CEO

Diogo Goebel

Get started now by reducing up to 90% of CVEs before production.

Reduce your attack surface and the cost of remediation.

Preventive security, applied continuously.

Powered by Getup