Connect with us

Technology

Kata Containers 4.0 Cements the Project’s Role as the Open Source Standard for Sandboxing AI Agents

Published

on

A new Rust-based default runtime, expanded hardware support and a hardened supply chain give the project’s isolation model the strength agentic workloads demand

AUSTIN, Texas, July 22, 2026 /PRNewswire/ — The Kata Containers community today announced the release of Kata Containers 4.0, a milestone that reinforces the project’s growing role as the open source foundation for sandboxing AI agents. The release’s central engineering achievement, a new Rust-based runtime, becomes the project’s default implementation, delivering the memory safety and performance gains needed to isolate agents whose behavior can’t always be predicted in advance.

Kata Containers is an open source project that combines the speed of Linux containers with the isolation of lightweight virtual machines. The project is managed by the OpenInfra Foundation and is used across multi-tenant Kubernetes environments, secure CI/CD pipelines and, increasingly, AI infrastructure.

*** Download Kata Containers 4.0

Why AI Agents Need a Stronger Sandbox

AI agents carry a different risk profile than traditional microservices: their execution paths shift based on the tools they can reach, the memory they accumulate and the prompts they receive, making them harder to trust by default. Kata Containers addresses that risk by running each workload inside its own lightweight virtual machine rather than sharing the host kernel, so a compromised agent cannot see another agent’s memory or move laterally across a cluster.

Kata Containers now serves as one of the supported runtimes for Agent Sandbox, a project under the Kubernetes SIG Apps umbrella, and remains the foundation for Confidential Containers, which encrypts data in use, allowing agent workloads to process private data without exposing it to the infrastructure operator.

*** Community experts from Ant Group, Google and NVIDIA discussed these use cases in depth during the OpenInfra Live episode on agent sandboxing, summarized in this Superuser article.

Organizations already running agent workloads in production are taking notice.

“Ant Group has long been a pioneer in deploying Kata Containers at scale. We first proved its value in co-locating our offline batch and compute workloads, where latency is less critical, to maximize resource efficiency and advance Ant Group’s green computing initiatives. To further bolster our security posture, we expanded Kata’s footprint to our core online services last year, enabling real-time security auditing and immediate mitigation of malicious access. Today, Kata has naturally become the foundational secure sandbox for our AI Agents. With its outstanding isolation and ultra-fast startup performance, Kata is now an integral part of Ant Group’s Agentic Infrastructure. The architectural leap in Kata 4.0—especially the transition to the Rust runtime—directly addresses the stringent security and efficiency requirements of modern AI sandboxing. This release is a masterpiece of community collaboration, and we are proud to drive its adoption.” — Fupan Li, Kata Containers architecture committee (AC) member and head of container technology, Ant Group

“Kata Containers 4.0 brings a memory-safe Rust foundation to one of the ecosystem’s most proven sandboxing frameworks. NVIDIA’s full GPU support, carried seamlessly from the Go runtime to Rust, enables customers to adopt 4.0 without disruption — running agentic AI and confidential workloads with stronger isolation, attestation, and performance. The NVIDIA Confidential Containers Reference Architecture, built on Kata Containers, provides NVIDIA partners a validated Confidential Computing framework for Kubernetes deployments, accelerating the path from evaluation to production. NVIDIA is proud to support this milestone and remains committed to helping customers deploy confidential AI at scale.” — Erik Bohnhorst, director of product management, NVIDIA

“Kata Containers is the foundation of our confidential computing stack here at Edgeless. Our Contrast framework shields entire fleets of containers within Kubernetes and our end-to-end encrypted GenAI inference service Privatemode AI builds directly on top of that. Kata’s pod-in-VM model is what makes this possible. The project’s continued focus on confidential computing has been essential to us. We’re excited about the 4.0 release and proud to contribute to a project that so many production workloads now depend on.” — Felix Schuster, CEO, Edgeless Systems

“Kata is a key component for many of Microsoft’s container isolation workloads such as AKS’s pod sandboxing offering. Kata’s focus on confidentiality, rust-based security, and improved agentic isolation continue to make it a valuable tool to meet the demands of our customers. Microsoft is proud to contribute to this Kata release, and to continue improving the security of AI workloads for our customers.” Jim Perrin — principal program manager lead – Azure Linux, Microsoft

A Rust-Based Foundation Makes It Possible

That level of isolation is only possible because of the architectural work behind Kata Containers 4.0. With this release, runtime-rs, the Rust-based runtime, replaces the original Go implementation as the project’s default, capping a multi-year community effort to move onto a memory-safe foundation. The change improves memory safety, reduces the runtime’s footprint and lowers startup latency, the kind of performance headroom that matters when sandboxes are being spun up and torn down at agent speed. The Go runtime is now deprecated and will continue to receive bug and security fixes during a defined transition period, but the community will not remove it before Kata Containers 5.0.

“Kata Containers 4.0 marks an important evolution for the project,” said Ildiko Vancsa, director of community for the OpenInfra Foundation. “By making the Rust runtime the default, the community is strengthening the project’s safety guarantees while creating a foundation for long-term innovation in secure cloud-native infrastructure.”

*** For the full technical breakdown, including the Go runtime deprecation timeline, supported hypervisors and hardware architectures, read the Kata Containers 4.0 release notes.

Version 4.0 also brings changes beyond the runtime: formalized release acceptance criteria, expanded hardware and hypervisor support, and a hardened software supply chain with updated dependencies and stricter CI checks. Together, these changes give the project a clearer, more predictable foundation for future releases.

*** For a closer look at the community’s work on the new Rust-based runtime, read the Kata Containers 4.0 blog post.

Get Involved

Kata Containers is an open source community that welcomes contributors across runtime development, documentation, testing and ecosystem integration.

Website: https://katacontainers.io GitHub: https://github.com/kata-containers/Slack: #general

About Kata Containers

Kata Containers is an open source project that delivers the performance of standard Linux containers with the enhanced isolation of lightweight virtual machines. Built for secure multi-tenant environments, Kata Containers enables cloud-native workloads to run with stronger isolation without sacrificing speed or compatibility. Kata Containers is managed by the OpenInfra Foundation. katacontainers.io

About the OpenInfra Foundation

The OpenInfra Foundation builds communities that write open source infrastructure software running in production. Backed by more than 110,000 individuals in 187 countries, the OpenInfra Foundation hosts open source projects and communities of practice covering AI infrastructure, container-native applications, edge computing and datacenter clouds. The OpenInfra Foundation is part of the nonprofit Linux Foundation. Join the OpenInfra movement: www.openinfra.org

Media Contacts:
Robert Cathey
Cathey.co for the OpenInfra Foundation
robert@cathey.co
Allison Price
OpenInfra Foundation
allison@openinfra.org 

View original content to download multimedia:https://www.prnewswire.com/news-releases/kata-containers-4-0-cements-the-projects-role-as-the-open-source-standard-for-sandboxing-ai-agents-302832233.html

SOURCE OpenInfra Foundation

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Cambium Networks Introduces High Density Wi-Fi 7 Solution for the Enterprise

Published

on

By

New tri-band, software-definable Wi-Fi 7 solution delivers precision directive coverage with AI optimization for exhibition halls, auditoriums, warehouses, and other high-density environments.

HOFFMAN ESTATES, Ill., July 22, 2026 /PRNewswire/ — Cambium Networks, a leading global provider of networking solutions, today announced a new Wi-Fi 7 high-density access point – the X7-56X – engineered to deliver high-performance wireless connectivity in the most demanding environments. Designed to meet the needs of large public venues, exhibition halls, busy public spaces, and educational campuses, the solution combines focused RF coverage, AI-driven optimization, and cloud-managed simplicity in a high-capacity platform.

The X7-56X extends Cambium Networks’ Wi-Fi 7 portfolio with a software-definable tri-band architecture featuring 60° x 60° directive antennas designed for precision coverage and reduced co-channel interference in congested RF environments. The platform supports up to 1,280 clients per access point and up to 17.9 Gbps aggregate wireless capacity across the three Wi-Fi spectrum bands.

“The X7-56X performed very well in our ticket scanning points that have high ceilings and see significant foot traffic volume,” said Jonathan West from the National Ice Centre in Nottingham, UK. “What makes this AP practical for a venue like ours is the integrated 60×60 degree antennas that eliminate separate antennas and cabling and can add significant cost, complexity, and footprint to every mount. Engineering all of that into one unit expedites installation and improves aesthetics as well. This form factor will extend to applications in our seating bowl as well.” 

“What excites me about the X7-56X is how well its directional approach works for some of our toughest spaces, such as auditoriums at capacity or the basketball arena on game night,” said Jeremy Petticrew, Network Engineer at University of Mary Hardin-Baylor. “Precisely controlling Wi-Fi coverage has always been the hard part, and having an AP designed specifically for that, inside a platform we already trust, is a real advantage as device counts keep climbing.”

The X7-56X integrates with Cambium’s ONE Network architecture comprised of Wi-Fi, switching, security, SD-WAN, wireless backhaul, and fiber – all managed through the cloud via cnMaestro™ X. This unified approach provides centralized visibility and control across the entire network infrastructure from a single source of truth.

The new solution provides a compelling Total Cost of Ownership (TCO) proposition by reducing the amount of equipment required in typical installations. These advantages are enabled by:

Directive antennas that focus Wi-Fi coverage only where needed – a spotlight approach vs. the floodlight type of inefficiencies of omni-directional antennas

Integrated Wi-Fi controller in every AP, eliminating the need for separate appliance or VM-based controller solutions

Software-defined radios that enable flexible deployment of the 5GHz and 6GHz Wi-Fi bands matched to environment needs, reducing the number of APs required

Key capabilities of the X7-56X include:

Tri-radio, tri-band Wi-Fi 7 architecture

4×4 MU-MIMO support with ten total spatial streams

60° x 60° directive antenna for precision coverage

Air Cleaner technology for high-density RF optimization

AI-based Assurance for improved operational efficiency and problem resolution

Software-definable radios supporting flexible 5 GHz and 6 GHz migration

Built-in IoT radio supporting BLE 5.1, Zigbee, Matter, and Thread

Simplified installation with the MarketApps Installer mobile-based app and flexible mounting options

Cloud-based management through cnMaestro™

“High-performance Wi-Fi requires more than just raw throughput,” said Bruce Miller, VP Enterprise Product Management at Cambium Networks. “Intelligent RF management, flexible deployment options, and simplified operations are key to support growing device counts, IoT proliferation, and AI-powered applications. The X7-56X was purpose-built for these challenges while at the same time delivering compelling economics for enterprise IT and managed service providers.”

“The X7-56X brings together several technologies that are particularly valuable in high-density environments,” said Kevin Tolly, Founder of The Tolly Group. “The directive antenna design, Wi-Fi 7 architecture, integrated IoT capabilities, and cloud-managed operation provide organizations with a practical approach to supporting growing connectivity requirements while maintaining operational simplicity.”

View the Tolly Group preview video of the X7-56X, showcasing the access point’s ultra-high-density design, Wi-Fi 7 capabilities, deployment flexibility, and performance advantages for demanding enterprise environments.

Cambium Networks’ directional Wi-Fi 7 innovation was recently highlighted by Wi-Fi NOW in an Expert Insights article by CEO and Chairman Claus Hetting.

Watch our webinar replay, “High-Performance Wi-Fi with New Wi-Fi 7 and 6 GHz Solutions.”

About Cambium Networks

Cambium Networks enables service providers, enterprises, industrial organizations, and governments to deliver exceptional digital experiences, and device connectivity, with compelling economics. Our ONE Network platform simplifies management of Cambium Networks’ wired and wireless broadband and network edge technologies. Our customers can focus more resources on managing their business rather than the network. We make connectivity that just works.

Media Contact

pr@cambiumnetworks.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/cambium-networks-introduces-high-density-wi-fi-7-solution-for-the-enterprise-302832358.html

SOURCE Cambium Networks

Continue Reading

Technology

OCEAN Launches Portal, the First End-to-End Encrypted Pool Dashboard for Bitcoin Miners

Published

on

By

New customizable dashboard gives miners operation-wide tools without surrendering privacy or identity

MIAMI, July 22, 2026 /PRNewswire/ — Today OCEAN announced the launch of OCEAN Portal, a customizable, end-to-end encrypted dashboard that gives Bitcoin miners a complete view of their operation. PORTAL was unveiled on stage at Mining Disrupt 2026, the world’s largest Bitcoin mining expo and conference, held July 21-23 at the Miami Airport Convention Center, by OCEAN President Mark Artymko. PORTAL is available now, for free, to all miners on OCEAN at portal.ocean.xyz.

OCEAN was built permissionless from the ground up, a deliberate design choice that, like Bitcoin itself, gives miners unhindered access to their own information. Traditional pools organize miner data by storing it on their own servers. OCEAN Portal delivers that same organized, polished experience while keeping miners fully in control: a permissionless, encrypted view of your mining addresses with the look and feel of an enterprise-style dashboard. Miners can combine multiple Bitcoin addresses into a single view, organize addresses by site, and assign human-readable names to sites, workers, and teams. Portal includes site-specific statistics, worker insights, payout information in Bitcoin and fiat, robust reporting tools, and access controls that let operators share full dashboards with their teams or generate expiring read-only links for clients. No account or email is required. Miners sign in with a Bitcoin address and a password they create. The convenience of enterprise dashboards, with the security of OCEAN.

“PORTAL was built in direct response to miner feedback,” said Mark Artymko, President of OCEAN. “Some of our miners told us that a customizable dashboard was the only thing standing between their full stack of hashrate and the pool. OCEAN heard them, and built it.”

PORTAL is powered by Sub-space Locker, an application-independent encrypted storage and access-control system developed by OCEAN. Built on public-key cryptography, Sub-space Locker authenticates users, stores encrypted application data, and controls what each user can access. Encryption and decryption happen locally in the user’s browser, leaving OCEAN and other intermediaries unable to read the underlying data.

“Every mining pool dashboard on earth makes the same trade: your tooling for your identity,” said Jason Hughes, VP of Engineering at OCEAN. “PORTAL refuses that trade. Miners get pool-grade information in the most sovereign way possible. We couldn’t read their data even if we tried.”

Since launching in 2023, OCEAN has focused on returning sovereignty to Bitcoin miners through permissionless, non-custodial pooled mining, fully transparent and auditable TIDES payouts, and DATUM, which puts block template construction back in miners’ hands. PORTAL extends that mission from the pool to the mining operation itself.

OCEAN Portal is available now at portal.ocean.xyz.

About OCEAN

OCEAN is a Bitcoin mining pool built on miner sovereignty. Operated by Mummolin, Inc., OCEAN offers non-custodial payouts, transparent reward accounting, and DATUM, the only pool technology that lets individual miners construct their own block templates.

Media Contact Ian Northon media@ocean.xyz

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/ocean-launches-portal-the-first-end-to-end-encrypted-pool-dashboard-for-bitcoin-miners-302831868.html

SOURCE Mummolin Inc

Continue Reading

Technology

PlayVS and Scouting America Announce Gaming Activation at the 2026 National Jamboree

Published

on

By

New immersive gaming hub will bring structured esports competition, casual play, and digital citizenship programming to Scouts at Summit Bechtel Reserve

LOS ANGELES, July 22, 2026 /PRNewswire/ — PlayVS, North America’s leading scholastic gaming platform, today announced a partnership with Scouting America to bring a state-of-the-art gaming activation to the 2026 National Jamboree, taking place July 22–31, 2026. One of Scouting America’s premier youth gatherings, the National Jamboree at Summit Bechtel Reserve in West Virginia, brings Scouts together from across the country for adventure, fellowship, skill-building, and shared experiences.

Running throughout the National Jamboree, the PlayVS Arena will offer a rotating schedule of competitive tournaments, leaderboard challenges, casual gaming, and hands-on technology experiences. Designed for Scouts of all experience levels, the activation promotes teamwork, digital citizenship, sportsmanship, and healthy competition while creating a welcoming space for Scouts to connect over a shared passion for gaming. The arena gives Scouts the opportunity to connect with friends, test their skills, and experience organized esports in an environment designed for participation, sportsmanship, and fun.

“At PlayVS, we believe gaming can be a powerful way for young people to build confidence, practice teamwork, and develop meaningful connections,” said Andrew Barnett, Partnership Lead. “Partnering with Scouting America allows us to bring that experience to one of the country’s most iconic youth gatherings and show how structured gaming can complement the values of leadership, fellowship, and skill-building that Scouting has championed for generations.”

The gaming activation will feature a high-tech mobile gaming trailer outfitted with gaming stations, virtual reality experiences, and a professional racing simulator. A dedicated event tent located alongside the trailer will expand the experience with additional console stations for free play, spectating, and community engagement throughout the Jamboree.

PlayVS aims to deliver a memorable gaming experience that brings together the excitement of play with the values of leadership, teamwork, and community.

About PlayVS

PlayVS is North America’s leading scholastic and collegiate gaming platform, helping students unlock the educational, social, and personal benefits of competitive gaming. The company brings together students, coaches, educators, and schools through structured, education-aligned competition across K–12 and college. PlayVS is the official esports partner of the NFHS Network, the Special Olympics, and state and regional organizations across the U.S. and Canada. To learn more, visit playvs.com.

Media Contact:
press@playvs.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/playvs-and-scouting-america-announce-gaming-activation-at-the-2026-national-jamboree-302831072.html

SOURCE PlayVS

Continue Reading

Trending