live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
newsSECURITY

RHEL 10 gains automated scanning and remediation for DISA STIG V1R2

SCAP Security Guide 0.1.82 aligns the RHEL 10 profile with the official benchmark and makes it usable across OpenSCAP, Satellite and Red Hat Lightspeed.

RHEL 10 STIG automation versus manual remediation.
Side by side: what changed
By The News Desk· Sep 26, 2026the quick take — two AI hosts go live when you do

Red Hat has released an automated compliance profile for Red Hat Enterprise Linux 10 that follows the official Defense Information Systems Agency Security Technical Implementation Guide, replacing the earlier vendor profile with content aligned to RHEL 10 DISA STIG Benchmark V1R2.

The profile ships in scap-security-guide 0.1.82. Red Hat’s release notes say the update brings the RHEL 10 profile into line with the official benchmark; the same release also updates the RHEL 8 and RHEL 9 DISA profiles to V2R8 and V2R9, respectively.

What administrators can automate

According to Red Hat’s announcement, administrators can use the stig or stig_gui profile to evaluate and remediate RHEL 10 systems through OpenSCAP’s oscap command, Red Hat Satellite or Red Hat Lightspeed. Red Hat also points to an official RHEL 10 STIG Ansible role for applying the controls.

The same content can be used earlier in the system lifecycle. Red Hat says organizations can apply STIG hardening through Kickstart, RHEL image builder and RHEL image mode rather than treating compliance as a post-install cleanup task. For platform teams, that creates a path to put the benchmark into repeatable image pipelines and provisioning workflows.

Version 0.1.82 also improves RHEL 10 remediation scripts so that newly created files and directories receive explicit owners and permissions, and adds rationale to the rule requiring the SSSD package, according to the SCAP Security Guide notes.

Automation is not certification

The new profile automates technical checks and remediations; it does not certify a deployed environment. Red Hat explicitly says administrators and security officers still need to review findings in the context of their operational environment to establish compliance.

That distinction matters for teams pursuing an Authority to Operate. The profile can make assessment, remediation and evidence collection more repeatable, but organizations remain responsible for interpreting results, documenting exceptions and satisfying controls that cannot be reduced to host configuration.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.