CIQ Blog: What's New in Enterprise Linux & AI Infrastructure
We're a team of scientists, Linux geeks, technologists, pilots, designers and more with a mission to make infrastructure something you never have to think about.

Why BOD 26-04's three-day window assumes runtime kernel monitoring
Federal teams running RLC Pro Hardened detect kernel-level exploitation while a patch is still in testing. BOD 26-04's three-day clock starts when a vulnerability enters the Known Exploited…

A Fortune 500 payments company cut licensing costs without recertifying a single application
Inside the migration that cut a Fortune 500 payments company's OS licensing costs by more than 40%, without touching a single production workload Every enterprise running RHEL at scale is having some…

A global high-frequency trading firm runs its own kernel team, and still chose RLC Pro
Inside the year-long test a global high-frequency trading firm gave CIQ, and what it took to turn a one-year renewal into a three-year commitment The hardest Enterprise Linux customer to win is the…

Rocky Linux or RLC Pro Hardened: what CISA's OSS guidance means for your kernel
CISA's new Open Source Software: Security Principles and Practices guide gives federal agencies a clear set of expectations for open source software: assess it before adoption, understand who…

What PEARC26 told us about the future of research computing
PEARC wrapped its tenth year in Minneapolis this week, and the theme organizers chose, Resilient Roots + Empowered Communities, turned out to describe the week better than most conference themes…
Monthly newsletter
No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every month.
Read about our privacy policy.

NASA's Flight Sciences Lab runs its most demanding missions on Rocky Linux
Inside the Enterprise Linux environment supporting Artemis II, ISS dockings, and NASA's return to the moon At PEARC26, our booth was standing room only for one talk. Jeff Triplett, Flight Sciences Lab…

Three days to remediate: what BOD 26-04 asks of federal Linux teams
On June 10, 2026, CISA set a three-calendar-day remediation clock for the highest-risk vulnerabilities on federal systems. Binding Operational Directive (BOD) 26-04 replaces the old severity-score…

Ascender Registry: a content hub you actually own
Here is an uncomfortable question. The collections and container images your playbooks pull every time they run, where do they actually come from? For most fleets the honest answer is the public…

BOD 26-04: three days to patch, and a harder question underneath
In June 2026, the Cybersecurity and Infrastructure Security Agency (CISA) rewrote how federal agencies handle their worst vulnerabilities. The inference here is that Binding Operational Directive (BOD…

Ascender Galaxy Proxy is now open source
Ascender Galaxy Proxy is now open source. Teams that run Ansible pull their collections through it and get local-speed downloads that hold up even when the public Ansible Galaxy service is busy. CIQ…

CMMC Phase 2 is suspended. NIST 800-171 is still in force.
Defense contractors hold the same compliance baseline today that they held before July 13. NIST SP 800-171 remains the control standard in contracts covered by the Defense Federal Acquisition…