Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Tuesday, December 17, 2019

McAfee joins with Google Cloud to integrate McAfee Security offerings with GCP for Linux and Windows workloads, containers

McAfee and Google Cloud entered into an alliance to integrate key McAfee solutions for endpoint and container security within Google Cloud. Under this new partnership, McAfee will tightly integrate its endpoint security solutions for Linux and Windows workloads, as well as its MVISION Cloud solution for container security, on Google Cloud infrastructure.

Several enterprise customers leverage virtual machines (VMs) running in the cloud to handle key Linux and Windows workloads. Ensuring security of these workloads is critical. With this new integration, customers will be able to deploy McAfee’s advanced endpoint security solutions across these key workloads and VMs via Google Cloud Marketplace.


McAfee’s workload security technology uses advanced machine learning and cloud analytics to help protect against file-based, fileless, and script-based threats at scale for workloads deployed on Google Cloud.

Google Cloud provides organizations with critical infrastructure, platform capabilities and solutions, along with expertise, to reinvent their business with data-powered innovation on modern computing infrastructure. The Mountain View, California-based company delivers enterprise-grade cloud solutions that leverage Google technology to help companies operate more efficiently, modernize for growth and innovate for the future. Customers in more than 150 countries turn to Google Cloud as their trusted partner to solve critical business problems.  

McAfee is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates business and consumer solutions that make the world a safer place. 


McAfee MVISION Cloud for Containers service extends data security, threat prevention, governance, and compliance capabilities of the MVISION Cloud platform to provide additional security for container-based workloads on Google Cloud. Organizations can also leverage MVISION to integrate security into DevOps processes and toolsets to discover and address security issues before applications are deployed.

“Increasingly, customers are choosing to move critical workloads and applications to the cloud because of the strong security protections it can provide,” said Anand Ramanathan, vice president of product and marketing at McAfee. “As more of these enterprises choose to leverage Google Cloud’s hyperscale capabilities, we’re excited to integrate our core capabilities in VM and container security to ensure Google Cloud customers can benefit from the highest levels of data protection and threat prevention.”

“We’re excited to partner with McAfee to bring their proven, trusted security capabilities to enterprise customers,” said Kevin Ichhpurani, corporate vice president, Global Ecosystem at Google Cloud. “Integrating McAfee’s solutions into Google Cloud means customers will have even more tools to ensure the highest levels of data security and protections as they migrate mission-critical workloads to the cloud.”

Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Saturday, December 7, 2019

Trend Micro reveals that Magecart group sets sights on Smith & Wesson, other high-profile stores

Trend Micro announced this week that the infamous credit card-skimming group Magecart has struck again. After incidents in the past few months that saw the threat actor go after customers of online shops and hotel chains, the group has set its sights on a new set of targets: high-profile stores, including firearms vendor Smith & Wesson (S&W).


According to security researcher, Willem de Groot of Sanguine Security, threat actors took advantage of the Black Friday rush by injecting credit card skimmers into the sites of a number of high-profile stores such as S&W. The group behind the attack injected the skimmer into S&W’s website on Nov. 27 — a couple of days before Black Friday, most likely in anticipation of the high volume of traffic going to the website. Note that the skimmer has been removed from the S&W store as of the time of writing.

The skimmer features an impressive list of capabilities, such as reverse engineering, a three-stage loader, and multiple layers of JavaScript obfuscation to hide its tracks. When a user visits the compromised website, the command-and-control (C&C) server initially sends harmless code — up until the actual payment process, when the skimmer begins its malicious routine. 


To make the skimming attack look more legitimate, a fake payment confirmation code is presented to the user. Behind the scenes, however, malicious code is already running, sneakily exfiltrating customer data such as payment information to the C&C server.

Sanguine Security notes that these attacks only worked for users which met various criteria, including using U.S.-based IP addresses, using non-Linux-based browsers, and not using the AWS platform.

The rise of Magecart highlights the need for vendors and other organizations to properly secure their websites and applications. Data theft via an attack such as the ones regularly performed by Magecart can mean monetary losses, not only for customers but also for the company whose website or application was compromised, especially given the potentially steep fines meted out to violators of data privacy laws such as the General Data Protection Regulation (GDPR).  


Organizations can minimize the chances of compromise by consistently applying the newest patches and updates to the software they use and by shoring up the authentication mechanisms provided to customers. Furthermore, it is recommended that IT and security teams proactively monitor their websites for any sign of malicious activities, such as unauthorized access or data exfiltration.

Friday, December 6, 2019

University of Lausanne adopts Cohesity data management platform to boost time and cost savings, backup flexibility, scalability

Cohesity announced this week implementation of a comprehensive data backup solution for the University of Lausanne, located in Switzerland. Working in tandem with local partner Infoniqa, the solution deployed by the university is significantly faster and more automated and scalable than systems previously used. 

A complete backup of the Microsoft Exchange database now only takes eight hours instead of 29 and the incremental backup can be completed in just under two hours instead of the previous 7.5 hours.



With the new solution, the University of Lausanne is realizing simple, fast backup and disaster recovery on a single platform; easier management through integration with VMware and Avamar; significant time and cost savings in data backup and recovery; and compliance according to DSGVO by encryption of critical data.

With over 15,000 students, 5,000 employees, and two million documents, the university manages around 22 PB of logical data. For this purpose, a second backup solution was set up at the Neuchâtel site. 

As the licences for the existing system expired, the university was looking for a state-of-the-art solution that would meet a number of key requirements: secure critical data in encrypted form, high scalability, efficient recovery of mass data, compatibility with EMC NetWorker and the option of a hybrid cloud solution.

“Cohesity and Infoniqa take a modern and holistic approach to data management,” explains Michel Ruffieux, storage backup manager, University of Lausanne. “It was the only solution that met our requirement to secure critical data in encrypted form using a multi-tenant solution with private keys managed on a KMS server using the KMIP protocol.”


Cohesity and Infoniqa were able to combine the old and new backup systems at the University of Lausanne to cover the entire virtualized environment. Infoniqa enabled the platform to be deployed according to the customer’s requirements. Cohesity supplied four appliances, and additional servers can be added to this space-saving cluster in the future. This appliance group can also be used for storage with the same cluster concept.

With the Cohesity’s SnapTree technology, the university can now access the data in a maximum of three steps. Login takes less than five minutes and full flash recovery takes 11.5 hours. In addition, a web interface facilitates the recovery of a Windows or Linux virtual machine with granular files. This approach to using, managing and backing up secondary and primary data is one of Cohesity’s strengths.

Saturday, November 16, 2019

EXTEN Technologies and AIC to deliver NVMe-oF storage offerings optimized for supercomputing

AIC and EXTEN Technologies have partnered to provide a dense and scalable, software-defined NVMe-oF solution with record breaking performance, advanced management, provisioning, and RAID data protection services. This disaggregated storage based on the AIC Shark server provides industry leading price performance for HPC, analytics and ML/AI applications.

The AIC Shark server is ideal for dense computation, networking, and storage scalability. Four AMD EPYC processors manage storage processing for up to 24 local NVMe drives in its 2U enclosure. The AIC Shark server is an ideal scale-up (add JBOFs) and scale-out (add servers) platform for high-bandwidth shared storage applications that have a variety of data processing requirements.


The EXTEN HyperDynamic datapath running on Shark nodes creates a powerful data processing system with less than one microsecond of software overhead. This enables blistering performance with the lowest latency available. With simple striping, the 2U system achieves bandwidth of over 80GB/s. EXTEN supports both RDMA and TCP in parallel for maximum flexibility.

The EXTEN HyperDynamic software management suite offers a single REST interface to manage a cluster of NVMe-oF targets. This allows administrators to provision and manage the AIC Shark with the simplicity of a single machine, while maintaining the shared-nothing, linear scalability of NVMe-oF block storage performance. The EXTEN management framework is standards-based which ensures future-proof compatibility. Together, EXTEN software and the AIC Shark provide a perfect framework for implementing any reconfigurable, software-defined NVMe-oF solution.

Utilizing standard MPIO and Linux drivers, the Shark solution provides a robust storage platform built on standard tools that provides fault tolerance at both the target and drive level. EXTEN software ensures high performance resilience features including mirroring and dual parity RAID within each Shark node and volume replication across nodes without using client-side resources such as CPU, memory and I/O bandwidth.

Tuesday, November 12, 2019

StoneFly storage OS software now delivers WORM, deduplication and ransomware protection

StoneFly released a newer version of their patented storage Operating System (OS): StoneFusion and SCVM. The storage software also facilitates cloud integration with StoneFly appliances and other servers. Supported cloud repositories include Azure, Amazon S3, other S3 compatible cloud and StoneFly private cloud.

SCVM is also available as a standalone product compatible with VMware, Hyper-V, KVM, and Citrix (formerly XenServer) hypervisors facilitating data center consolidation, VM migration, VM snapshots, DR, and other similar use-cases.

The latest version (8.0.4) of the enterprise storage software includes WORM (Write-Once, Read-Many) storage provisioning; anti-virus, malware and ransomware detection and removal; deduplication for NAS volumes (in addition to iSCSI SAN workloads); and GUI (Graphical User Interface) update that offers real-time performance reporting of provisioned NAS, SAN and unified storage resources.


StoneFly patented storage OS, StoneFusion and SCVM, enables users to provision NAS, SAN and unified (NAS + SAN) volumes on bare-metal, Windows and Linux servers. The enterprise storage OS comes pre-configured in all StoneFly storage and backup and disaster recovery (DR) appliances.

StoneFusion is also available as a standalone software. The storage OS can be installed on bare-metal servers and mainstream enterprise storage appliances such as Dell EMC, HPE, among several others.
Besides storage provisioning, the storage OS facilitates integration of several enterprise-grade features such as delta-based snapshots, synchronous and asynchronous replication, volume encryption, automated storage tiering, and others.

The SCVM storage OS can be installed on mainstream hypervisors such as VMware, Hyper-V, KVM, and Citrix (formerly XenServers) to provision virtual NAS, virtual SAN, virtual unified (NAS + SAN) storage repositories and/or to integrate desired cloud repositories to build a hybrid HCI storage solution. With SCVM, users can run VMs in their preferred cloud, create snapshots in the cloud, replicate to the cloud, and more.

StoneFly also recently introduced StoneFusion MSP edition, the storage OS version that facilitates MSPs and large organizations to provision virtual, purpose-built, multi-tenant and noise-less storage repositories on on-premises, remote or cloud-based servers. 

Commenting on the new update the CEO and founder of StoneFly Mo Tahmasebi said, “Our culture is driven by customer feedback. We listen to our enterprise customers and develop our solutions accordingly to enhance their experience. The latest version of our storage OS is developed to help with concerns such as high impact ransomware attacks, compliance and data center consolidation. It’s an eighth generation product, which is truly one-of-a-kind in the context that it facilitates NAS, SAN, unified and hyperconverged workloads. Not many storage OS in the market can do that”

StoneFusion comes pre-configured in all StoneFly NAS, SAN and Unified (NAS + SAN) appliances. It’s also available as a standalone product for bare-metal, Windows and Linux-based servers.

SCVM is the built-in virtual storage appliance in StoneFly HCI appliances including Unified Server and Storage (USS) appliances, the DR365, DR365V and DR365U backup and DR appliances.

BittWare expands line with multiple capabilities on FPGA acceleration products to address growing industry technology demands

BittWare, a Molex company, expanded on Tuesday its offerings and solutions to further address the growing need for computing technology. These BittWare offerings provide high-end, integrated solutions for memory bandwidth and advanced cooling, enabling customers to go to market faster.

BittWare’s broad range of compute-focused accelerator cards includes HBM2-enabled FPGAs from both Intel and Xilinx yielding up to 4Tbps of bandwidth. These Stratix-10 MX and Virtex UltraScale+ based products are now shipping with a choice of abstracted toolflows, including OpenCL. 

A new alternative to high-bandwidth memory implementation, on display at SC19, will be BittWare’s new S7t accelerator card developed in conjunction with Achronix Semiconductor. 



This product features the newly announced Achronix 7nm Speedster 7t FPGA, which offers a range of capabilities, including low-cost and highly flexible GDDR6 memories that deliver HBM-class memory bandwidth without the HBM, as well as a revolutionary 2D Network-on-Chip (NoC) for high bandwidth and energy-efficient data movement.

As customers push computing technology to new limits, there is a need to consider more advanced cooling options – even for energy-efficient accelerators such as FPGAs. At Supercomputing 2019, BittWare will present Achronix, Intel and Xilinx based FPGA accelerator cards featuring Direct Liquid Cooling (DLC) technology from CoolIT System

Data center managers are increasingly turning to liquid cooling as the most reliable and efficient cooling method. In comparison to air, liquid cooling is 2-10 times more effective in transporting heat away from a source to a secondary cooling surface.

BittWare’s range of certified TeraBox server platforms, targeting networking and HPC clusters feature the latest FPGA accelerators enabling customers to develop and deploy quicker, while reducing risk and total cost. This product range will be further extended with the introduction of the TeraBox 1400DN. 

This ultra-high density 1U server based on the DELL C4140 PowerEdge server features four double-width PCIe cards with front-panel access and dual Xeon Scalable CPUs. Customers can order the server with a choice of Achronix, Intel or Xilinx FPGA accelerators supporting a high density of network ports: four 400GbE, up to 128 10/25GbE or up to 32 100GbE.

BittWare, in conjunction with Eideticom, will be displaying the world’s first FPGA-based computational storage processor (CSP). This solution, based on the BittWare 250-U2 accelerator, adheres to the industry standard U.2 form factor allowing it to be front-servicable in standard rackmount chassis. 


When programmed with Eideticom’s NoLoad IP, each Computational Storage Service executed on the 250-U2 is presented to the host operating system as a regular NVMe Controller and binds to the standard NVMe driver. This avoids the need for customers to develop or use proprietary drivers or software stacks. Instead, customers can continue using their preferred Linux, Windows or VMWare operating systems and host-based applications.

“With FPGA-based acceleration achieving wider adoption, it is essential that there is a supplier who can deliver and support higher-quality volume deployments,” said Craig Petrie, vice president of marketing for BittWare. “Traditionally, FPGA card vendors have provided cutting-edge technology primarily to innovators and early adopters; it is quite a different challenge to implement the extensive qualification, validation, life cycle management and support required by the newer enterprise-class customers. BittWare, as a part of Molex, is in the unique position to drive technology advancements while simultaneously delivering enterprise-class product consistently at high run-rates. This powerful combination allows our customers to adopt the latest and greatest FPGAs at the card and server-level with reduced risk and cost.”

Thursday, November 7, 2019

Red Hat Enterprise Linux 8.1 adds developer tools and security certifications; expands automation capabilities

Red Hat has announced general availability of Red Hat Enterprise Linux 8.1, the latest version of its enterprise Linux platform. The first minor release of the Red Hat Enterprise Linux 8 platform, Red Hat Enterprise Linux 8.1 enhances the manageability, security and performance of the operating system underpinning the open hybrid cloud, while also adding new capabilities to drive developer innovation.

Red Hat Enterprise Linux is the foundation of Red Hat’s open hybrid cloud portfolio, providing the underlying engine that allows complex workloads to be developed and deployed across physical, virtual, private and public cloud environments with greater confidence and control. 



As the backbone of the hybrid cloud, the enterprise Linux platform provides a consistent user experience across on premise deployments and all major public cloud infrastructures. At the same time, it supports key production workloads like Microsoft SQL Server and SAP HANA while also enabling new workloads like artificial intelligence (AI) and machine-learning (ML).

Red Hat Enterprise Linux 8.1 is the first Red Hat Enterprise Linux release to follow the predictable release cadence announced at Red Hat Summit 2019, with minor releases available every six months. This schedule provides Red Hat’s customers and partners with the capacity to more deliberately prepare for new releases, while minimizing unplanned outages and downtime of critical systems. 


The predictable release cycle also enables Red Hat partners, from software providers to hardware vendors, to build and deliver the next generation of their innovative offerings with a clear timetable of when a new Red Hat Enterprise Linux 8 release will be available.

All supported Red Hat Enterprise Linux subscriptions now include access to Red Hat Insights, Red Hat’s proactive analytics offering. Intended to help address configuration and other system issues before they impact production, Red Hat Insights has more than 1,000 rules for operating Red Hat Enterprise Linux on-premises or on public clouds such as AWS and Microsoft Azure. 
  

These rules support analytics for workloads such as SAP HANA and Microsoft SQL Server and help IT administrators to more quickly address performance, security, availability and stability risks to keep operations running smoothly.  

Red Hat Enterprise Linux 8.1 also adds new Red Hat Enterprise Linux System Roles, streamlining the process for setting up Red Hat Enterprise Linux subsystems to handle specific functions, such as storage, networking, time synchronization, kdump and SElinux. This expands the existing collection of Ansible system roles for Red Hat Enterprise Linux 8, better supplementing configuration automation across various versions of Red Hat Enterprise Linux deployed as the backbone of enterprise IT infrastructure.

Red Hat Enterprise Linux 8.1 is also the initial Red Hat Enterprise Linux release in the new Red Hat Enterprise Linux development lifecycle, which includes communities, projects and programs  to meet specific developer needs.


Fedora provides an opportunity for developers to engage with the future of the Linux kernel and encourages participation to shape the leading-edge of the operating system. CentOS Stream provides ecosystem developers with a "rolling preview" of what’s next in Red Hat Enterprise Linux, helping them build production applications with the future in mind.

The Red Hat Universal Base Image, based on Red Hat Enterprise Linux 8, offers a cost-free, redistributable image for creating cloud-native applications based on Red Hat Enterprise Linux. This provides a clear path for developers to more easily create applications that are ready for certification and production across Red Hat’s open hybrid cloud portfolio.

The Red Hat Enterprise Linux Developer Subscription, a no-cost, self-supported subscription that provides a dev/test environment for applications that are meant to be deployed into production on the enterprise Linux platform.

As global organizations seek to gain a competitive edge or simply serve their end users better, they often look to transform through digital technologies like Linux containers, microservices, Kubernetes or hybrid cloud services. All of this innovation, however, requires the same level of security and compliance scrutiny of traditional software and hardware deployments. 

Red Hat Enterprise Linux 8.1 continues Red Hat’s commitment to delivering open innovation paired with the software security advancements required to protect sensitive data and workloads.

Red Hat Enterprise Linux 8.1 adds full support for live kernel patching to help IT operations teams keep pace with a shifting threat landscape without incurring excessive system downtime. Kernel updates can now be applied to remediate Critical or Important Common Vulnerabilities and Exposures (CVEs), while reducing the need for a system reboot, helping to keep critical workloads running more securely. 

Additional security enhancements include enhanced CVE remediation, kernel-level memory protection and application whitelisting technologies. 


Container-centric SELinux profiles are included in Red Hat Enterprise Linux 8.1, making it possible to create more tailored security policies to control how containerized services access host system resources. This makes it easier to harden production systems against security threats targeting cloud-native applications and provides a more streamlined way to maintain regulatory compliance by reducing the risk of running privileged containers.

Red Hat Enterprise Linux 8.1 is now available for active Red Hat Enterprise Linux subscriptions via the Red Hat Customer Portal. Members of the Red Hat Developer program may also obtain the latest releases of Red Hat Enterprise Linux at no-cost.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...