Security News

Arista expands CloudVision for both on-premises and cloud-service deployment
2020-08-19 01:45

Arista's new CloudVision as-a-Service product is now available as a fully managed software service that automates multi-domain networks spanning across the client to cloud to help customers achieve faster time-to-value, elastic scaling, and continuous network assurance. "With CloudVision cognitive NetDB, we extended our unique state-sharing architecture from individual switches into the cloud, creating a unified network data platform. On top of this platform, we built CloudVision as a SaaS-based product, the next step towards network reliability with advanced network assurance services," said Ken Duda, Founder, Chief Technology Officer and Senior Vice President, Software Engineering at Arista.

Saviynt converges PAM, IGA, and cloud security technologies in a single platform
2020-08-19 01:00

The latest release includes considerable security improvements to their Cloud PAM application, bolstering one of the only solutions to converge Identity Governance, Application Governance-Risk Management-and Compliance, and Privileged Access Management into a unified Identity Platform built for the cloud. The latest release of Saviynt's Cloud PAM provides improved governance, analytics, and access to privileged assets across enterprise applications and platforms including Google Cloud Platform.

VMware’s  updated portfolio helps provision, optimize and govern hybrid and multi-cloud environments
2020-08-19 00:15

Uniquely available both on-premises and as SaaS, VMware vRealize provides customers with the agility and efficiency of cloud infrastructure at scale, leveraging artificial intelligence, machine learning, and DevOps principles such as Infrastructure as Code and GitOps to provision, orchestrate, optimize and govern hybrid and multi-cloud environments. VMware vRealize Log Insight 8.2 and vRealize Log Insight Cloud will also introduce enhanced Kubernetes support, deeper integration with VMware Cloud on AWS, and overall usability enhancements.

Styra now enables highly regulated industries to take advantage of cloud-native authorization policy
2020-08-18 23:30

Styra announced that Styra Essentials now includes Long Term Support for Open Policy Agent, enabling companies in highly regulated industries to take advantage of cloud-native authorization policy. Highly regulated industries typically limit how often companies can update their software in order to reduce new risks.

AWS Cryptojacking Worm Spreads Through the Cloud
2020-08-18 14:14

A cryptomining worm from the group known as TeamTNT is spreading through the Amazon Web Services cloud and collecting credentials. Attacking AWS. The attack starts with targeting the way that AWS stores credentials in an unencrypted file at ~/.aws/credentials, and additional configuration details in a file at ~/.aws/config.

Terrascan open source software helps developers build secure cloud infrastructure
2020-08-18 04:30

Accurics unveiled a major upgrade to Terrascan, the open source static code analyzer that enables developers to build secure infrastructure as code. The new Terrascan architecture leverages the Open Policy Agent engine from CNCF, which dramatically simplifies policy definition for developers that want to create custom policies as well as provides over 500 out-of-the-box policies for the CIS Benchmark.

Red Hat OpenShift 4.5: Breaking down app barriers between traditional and cloud-native infrastructure
2020-08-18 00:00

Red Hat OpenShift 4.5, which includes the general availability of OpenShift Virtualization, is designed to help organizations break down application barriers between traditional and cloud-native infrastructure and extend control over distributed resources. Red Hat OpenShift now includes OpenShift Virtualization, a new platform feature that enables IT organizations to bring standard VM-based workloads to Kubernetes, helping eliminate the workflow and development silos that typically exist between traditional and cloud-native application stacks.

How AppTrana Managed Cloud WAF Tackles Evolving Attacking Techniques
2020-08-17 10:20

How does AppTrana handle evasions Real-world attacks often include multiple steps, including reconnaissance and a combination of attacks, so behavior profiling, anomaly scoring provide automated mitigation, and security experts, like the Indusface security research team, can quickly see if the attack is new or unique and take appropriate action. How to evaluate WAF Any security solution should be regularly evaluated in terms of blocking attacks, FPs, and performance.

How AppTrana Managed Cloud WAF Tackles Evolving Attacking Techniques
2020-08-17 03:20

How does AppTrana handle evasions Real-world attacks often include multiple steps, including reconnaissance and a combination of attacks, so behavior profiling, anomaly scoring provide automated mitigation, and security experts, like the Indusface security research team, can quickly see if the attack is new or unique and take appropriate action. How to evaluate WAF Any security solution should be regularly evaluated in terms of blocking attacks, FPs, and performance.

Trend Micro integrates with AWS to enhance agility and automation in cloud security
2020-08-14 00:00

Trend Micro has demonstrated the strength of its collaboration with AWS since 2012 with a deep understanding of customer use cases and by integrating with leading AWS security services at launch. Most recently, Trend Micro Cloud One offerings have been natively integrated with AWS Control Tower and AWS Systems Manager Distributor.