Header image

Session 2.8f Tutorial: Project Hummingbird: Zero CVEs for Zero Cost

Tracks
Wednesday, November 18, 2026
4:00 PM - 5:00 PM
Swan Room

Presentation Outline

Frontier AI models have fundamentally changed the vulnerability exploitation landscape. What once required skilled threat actors and significant time investment - reverse-engineering patches, crafting exploits, and chaining vulnerabilities - can now be accomplished rapidly using generative AI. We typically define threats as needing both capability and intent; highly capable frontier AI models place capability in the hands of threat actors with intent. How do we protect environments against these highly capable, AI-enabled threat actors? Project Hummingbird is an open source project providing minimal, hardened container base images with near-zero CVEs. These images strip away unnecessary packages, binaries, and libraries, removing the attack surface, and rapidly delivering fixes from upstream projects. Red Hat makes these images available at zero cost, built via Konflux and signed using verifiable signing keys. Instead of accepting hundreds of vulnerabilities across container fleets and building complex deferral workflows, organisations can start from a near-zero baseline. Fewer CVEs means fewer waivers, less toil, and reduced risk — directly supporting compliance with frameworks like the Australian Information Security Manual (ISM). In an environment where AI-accelerated exploitation is shrinking response timelines, the most effective mitigation is ensuring there's nothing to exploit in the first place. Project Hummingbird images are available for Defence teams, and In this tutorial, we will take a closer look at the image catalog, how container images are built and distributed, and how to get started using Project Hummingbird container images today.


Speaker

Agenda Item Image
Mr Shane Boulden
Solution Architect
Red Hat

Biography

Shane Boulden is a solution architect at Red Hat, supporting Fortune 500 companies and government organisations across Australia and the region to adopt open source technologies. He has contributed to security-focused open source projects like 'Compliance as Code', StackRox, and Keycloak, and is a contributing author to the second edition of "The Kubernetes Bible". Shane specialises in Red Hat OpenShift and Red Hat Enterprise Linux security and compliance, and his recent focus has been helping organisations adopt distroless base images with Red Hat Hardened Images.
loading