Showing posts with label VM. Show all posts
Showing posts with label VM. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


CloudJumper launches distribution agreement with Crayon to improve access to cloud workspace for Azure

CloudJumper announces alliance with Crayon that combines the power of CloudJumper’s Cloud Workspace Management Suite (CWMS) for VDI and RDS workloads with the expertise of Crayon’s managed services and independent 'cloud economics' consulting practice.

CloudJumper and Crayon’s partnership bring new possibilities for customers and MSPs who want the flexibility of choice for management, security options and the ability to build their own value-add services suite leveraging WVD. 


Microsoft’s Windows Virtual Desktop (WVD) brings new choices for customers who want more control of the managed services running on top of desktop and application virtualization solutions. Legacy VDI providers have historically served as a gatekeepers controlling the workstation management plane. CloudJumper brings to Azure WVD what the legacy vendors will not – the flexibility of controlling managed services on top of managed desktops.

The utility of Windows Virtual Desktop (WVD) is further enhanced through CloudJumper's Cloud Workspace Management Suite (CWMS). CWMS is an automation, orchestration workflow and policy solution to deploy, configure and manage WVD in real-time and at cloud scale. CWMS will instantly, and continually, optimize the customer’s Azure investment.


WVD is a complex collection of Azure services. CloudJumper simply funnels the hundreds of WVD setup options into a few key questions and then orchestrates and deploys a customized environment. With CloudJumper, the customer is just minutes away from deploying thousands of new WVD VMs– something that is not available in a native Azure user interface (UI).

To provide additional support for this distribution partnership, CloudJumper's product development team has been working closely with Microsoft's WVD product team for over two years. As a result, CloudJumper is proud to be recognized as a Microsoft Preferred Solution Provider for WVD.

Microsoft Azure WVD provides customers with unique licensing options and operating system flexibility for Windows 10 and Windows 7 desktop virtualization. Windows 7 desktops can now be migrated to Azure WVD and receive up to three years extended security updates at no additional costs. 

New Windows 10 multi-session OS options are only offered in Azure. These OS choices along with the many complementary Azure PaaS management and security offerings can be securely delivered directly into the Azure tenant. Native Azure Management, supported by CWMS, means no redirection and no third party vendor lock-in. This allows customers to leverage current Microsoft licensing instead of buying overlapping third party tools.

The partnership with Crayon combines the strengths and expertise of CloudJumper and Crayon to deliver the next generation of cloud DaaS and WaaS VDI and RDS desktop and application virtualization solutions.


Headquartered in Oslo, Norway, Crayon is in over 35 countries, providing more than 8,000 customers with strategic advice, consulting and managed services, and support with complex IT estates. Crayon has been the preeminent IT infrastructure consulting business in the Nordic region for more than 12 years, and has expanded its footprint in the US in the last two years.

“Crayon’s deep experience in all aspects of the digitalization journey helps ensure the success of the new partnership. We are pleased to combine CloudJumper’s advanced platform with Crayon’s unique SAM to Cloud Consultancy Services as companies take the next step in digital transformation with their move to Windows Virtual Desktop,” said Alex Picchietti, global director of cloud services for Crayon. “The wealth of expertise from both companies will support organizations making this important move to improve productivity and operational efficiency.”

“The advent of WVD and the partnership with a respected industry leader like Crayon extends the reach of our combined solutions globally,” said JD Helms, president of CloudJumper. “Customers are demanding choice and flexibility in their managed workspace providers and CloudJumper is uniquely positioned to do just that.”

Tuesday, December 17, 2019

Oracle makes it to DISA Impact Level 5 provisional authorization for Oracle Cloud Infrastructure

Following closely on the heels of Oracle achieving FedRAMP authorization, Oracle announces Tuesday three new government regions: Ashburn, Virginia; Phoenix, Arizona; and Chicago, Illinois. These regions have achieved DISA Impact Level 5 provisional authorization (IL5 PATO), providing a cloud environment where U.S. Department of Defense (DoD) and other federal customers can harness the power of Oracle Cloud to unlock innovation, improve mission performance, and enhance service delivery.  

This is an important milestone in Oracle’s journey to deliver innovative cloud services with consistent high performance and exceptional security to the entire U.S. government. In 2020, Oracle plans to bring additional full-scale Gen 2 Cloud Regions online to support the classified missions of the US Government.



“U.S. DoD and other Federal customers are continually looking for new, secure ways to improve citizen services and keep our nation safe,” said Don Johnson, executive vice president, Oracle Cloud Infrastructure. “Oracle’s Generation 2 Cloud was engineered to deliver highly secure, high-performance, cost effective infrastructure that helps government organizations address the needs of the nation today and tomorrow.” 

Oracle has been a key technology partner of the U.S. government. Currently, more than 500 government organizations take advantage of Oracle’s technologies and superior performance. State, local and federal government customers using Oracle to modernize their technology include Defense Manpower Data Center (DMDC) and the U.S. Air Force.

The Department of Defense recently awarded a contract to Oracle for its Oracle Cloud Infrastructure to support a large portion of the enterprise human resource portfolio. The award modernizes existing infrastructure and will assist the Defense Manpower Data Center in providing necessary human resource services and capabilities to its military members, veterans and their families.

With Oracle Cloud Infrastructure, customers benefit from best-in-class security, consistent high performance, simple predictable pricing, and the tools and expertise needed to bring enterprise workloads to cloud quickly and efficiently. In addition, Oracle now provides organizations with a complete set of solutions for any high performance computing (HPC) workload, enabling businesses to capitalize on the benefits of modern cloud computing while enjoying performance comparable to on-premises at a lower cost.

Oracle Cloud Infrastructure has achieved certifications and attestations for key security standards and compliance mandates. These independent third-party assurance programs demonstrate Oracle’s commitment to security and to meeting the needs of the public sector. These IL5 PATO government regions will launch with initial Oracle services including VM and bare metal compute (CPU and GPU), storage (including archive, block, and object storage), database, identity and access management, key management service, load balancer, and Exadata cloud service.


“Oracle Cloud Infrastructure brings incredible performance, flexibility, security, and cost-savings benefits to our federal civilian, commercial and higher education customers,” said Paul Seifert, federal sector president, Mythics. “Mythics’ DoD customers will now be able to leverage Oracle Cloud to better serve the unique requirements of the DoD at home and abroad.”

“We’re excited to see the Oracle Cloud Infrastructure achieve DISA Impact Level 5 provisional authorization, as it provides additional options that our federal government clients—especially those seeking to migrate large and complex Oracle-based solutions to the cloud—can leverage,” said Anthony Flake, managing director of Accenture Federal Services’ Oracle practice.

McAfee joins with Google Cloud to integrate McAfee Security offerings with GCP for Linux and Windows workloads, containers

McAfee and Google Cloud entered into an alliance to integrate key McAfee solutions for endpoint and container security within Google Cloud. Under this new partnership, McAfee will tightly integrate its endpoint security solutions for Linux and Windows workloads, as well as its MVISION Cloud solution for container security, on Google Cloud infrastructure.

Several enterprise customers leverage virtual machines (VMs) running in the cloud to handle key Linux and Windows workloads. Ensuring security of these workloads is critical. With this new integration, customers will be able to deploy McAfee’s advanced endpoint security solutions across these key workloads and VMs via Google Cloud Marketplace.


McAfee’s workload security technology uses advanced machine learning and cloud analytics to help protect against file-based, fileless, and script-based threats at scale for workloads deployed on Google Cloud.

Google Cloud provides organizations with critical infrastructure, platform capabilities and solutions, along with expertise, to reinvent their business with data-powered innovation on modern computing infrastructure. The Mountain View, California-based company delivers enterprise-grade cloud solutions that leverage Google technology to help companies operate more efficiently, modernize for growth and innovate for the future. Customers in more than 150 countries turn to Google Cloud as their trusted partner to solve critical business problems.  

McAfee is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates business and consumer solutions that make the world a safer place. 


McAfee MVISION Cloud for Containers service extends data security, threat prevention, governance, and compliance capabilities of the MVISION Cloud platform to provide additional security for container-based workloads on Google Cloud. Organizations can also leverage MVISION to integrate security into DevOps processes and toolsets to discover and address security issues before applications are deployed.

“Increasingly, customers are choosing to move critical workloads and applications to the cloud because of the strong security protections it can provide,” said Anand Ramanathan, vice president of product and marketing at McAfee. “As more of these enterprises choose to leverage Google Cloud’s hyperscale capabilities, we’re excited to integrate our core capabilities in VM and container security to ensure Google Cloud customers can benefit from the highest levels of data protection and threat prevention.”

“We’re excited to partner with McAfee to bring their proven, trusted security capabilities to enterprise customers,” said Kevin Ichhpurani, corporate vice president, Global Ecosystem at Google Cloud. “Integrating McAfee’s solutions into Google Cloud means customers will have even more tools to ensure the highest levels of data security and protections as they migrate mission-critical workloads to the cloud.”

Wednesday, December 11, 2019

McAfee releases CASB-integrated cloud security platform for container-based applications

McAfee announced McAfee MVISION Cloud for Containers that integrates container security with its Cloud Access Security Broker (CASB) and Cloud Security Posture Management (CSPM) security solution. 

Leveraging NanoSec’s zero trust application visibility and control capabilities for container-based deployments in cloud environments, the solution provides customers with the ability to speed up application delivery, while enhancing the governance, compliance and security of their container workloads.




The acquisition of NanoSec will strengthen the container security capabilities of McAfee MVISION Cloud and MVISION Server Protection products, giving its customers the ability to speed up application delivery while enhancing governance, compliance and security of their hybrid, multi-cloud deployments. 

NanoSec’s security capabilities will be applied to applications and workloads deployed in containers and Kubernetes and will be integrated into McAfee MVISION Cloud and MVISION Server Protection offerings. These capabilities include continuous configuration compliance and vulnerability assessment as well as runtime application-level segmentation for detecting and preventing lateral movement of threats.


Container security has long been treated as separate from other Infrastructure as a Service (IaaS) security solutions, requiring evaluation, investment and management of multiple, niche products thus increasing total cost of ownership and complexity and reducing security. 

McAfee MVISION Cloud for Containers integrates Cloud Security Posture Management (CSPM) and Vulnerability Scanning for container workloads into the existing McAfee MVISION Cloud platform to give customers a unified cloud security solution where consistent security policies can be implemented across all forms of cloud IaaS workloads.

McAfee MVISION Cloud integrates with DevOps tools, helps users “shift-left” to pre-emptively improve compliance and secure container workloads by running security audits in the DevOps pipeline and providing security incident data directly back to the development teams. 

Additionally, McAfee MVISION Cloud also continuously monitors the production deployments of these container workloads to ensure configuration drift does not compromise the security of the applications.


Currently available, McAfee MVISION Cloud for Containers provides CSPM that integrates Configuration Audit checks for containerized workloads to ensure the container platforms run in accordance with CIS and other best practice compliance standards. This is designed to ensure security checks for the complete container stack including the configuration of the virtual machine the container runs on, as well as the storage, network and other Platform as a Service (PaaS) services the container may be accessing.

The offering also adds vulnerability scanning of container images that helps to identify and prevent the use of weak or exploitable components of the container images. This reduces the overall risk profile of the application by minimizing the attack vectors. With Shift Left DevOps integration, users can perform CSPM and Vulnerability Scanning checks earlier in the application development lifecycle. This helps identify risk and provide meaningful feedback to developers within the build process. Additionally, continuously monitor and prevent configuration drift on production deployments of the container workloads.

Sunday, December 8, 2019

Microsoft validates Lenovo ThinkSystem SE350 edge server for Azure Stack HCI

Microsoft and Lenovo have teamed up to validate the Lenovo ThinkSystem SE350 for Microsoft's Azure Stack HCI program. The ThinkSystem SE350 was designed and built with the unique requirements of edge servers in mind. It is versatile enough to stretch the limitations of server locations, providing a variety of connectivity and security options and can be easily managed with Lenovo XClarity Controller. 

The ThinkSystem SE350 solution has a focus on smart connectivity, business security, and manageability for the harsh environment.


The ThinkSystem SE350 is the latest workhorse for the edge. Designed and built with the unique requirements for edge servers in mind, it is versatile enough to stretch the limitations of server locations, providing a variety of connectivity and security options and is easily managed with Lenovo XClarity Controller. 

The ThinkSystem SE350 is a rugged compact-sized edge solution with a focus on smart connectivity, business security, and manageability for the harsh environment.

The ThinkSystem SE350 is an Intel Xeon D processor-based server, with a 1U height, half-width and short depth case that can go anywhere. Mount it on a wall, stack it on a shelf, or install it in a rack. This rugged edge server can handle anything from 0-55°C as well as full performance in high dust and vibration environments.

Information availability is another challenging issue for users at the edge, who require insight into their operations at all times to ensure they are making the right decisions. The ThinkSystem SE350 is designed to provide several connectivity options with wired and secure wireless Wi-Fi and LTE connection ability. This purpose-built compact server is reliable for a wide variety of edge and IoT workloads.

Azure Stack HCI solutions bring together highly virtualized compute, storage, and networking on industry-standard x86 servers and components. Combining resources in the same cluster makes it easier to deploy, manage, and scale, while managing command-line automation or Windows Admin Center.

Consumers can achieve virtual machine (VM) performance for server applications with Hyper-V, the foundational hypervisor technology of the Microsoft cloud, and Storage Spaces Direct technology with built-in support for non-volatile memory express (NVMe), persistent memory, and remote direct memory access (RDMA) networking.

Friday, December 6, 2019

University of Lausanne adopts Cohesity data management platform to boost time and cost savings, backup flexibility, scalability

Cohesity announced this week implementation of a comprehensive data backup solution for the University of Lausanne, located in Switzerland. Working in tandem with local partner Infoniqa, the solution deployed by the university is significantly faster and more automated and scalable than systems previously used. 

A complete backup of the Microsoft Exchange database now only takes eight hours instead of 29 and the incremental backup can be completed in just under two hours instead of the previous 7.5 hours.



With the new solution, the University of Lausanne is realizing simple, fast backup and disaster recovery on a single platform; easier management through integration with VMware and Avamar; significant time and cost savings in data backup and recovery; and compliance according to DSGVO by encryption of critical data.

With over 15,000 students, 5,000 employees, and two million documents, the university manages around 22 PB of logical data. For this purpose, a second backup solution was set up at the Neuchâtel site. 

As the licences for the existing system expired, the university was looking for a state-of-the-art solution that would meet a number of key requirements: secure critical data in encrypted form, high scalability, efficient recovery of mass data, compatibility with EMC NetWorker and the option of a hybrid cloud solution.

“Cohesity and Infoniqa take a modern and holistic approach to data management,” explains Michel Ruffieux, storage backup manager, University of Lausanne. “It was the only solution that met our requirement to secure critical data in encrypted form using a multi-tenant solution with private keys managed on a KMS server using the KMIP protocol.”


Cohesity and Infoniqa were able to combine the old and new backup systems at the University of Lausanne to cover the entire virtualized environment. Infoniqa enabled the platform to be deployed according to the customer’s requirements. Cohesity supplied four appliances, and additional servers can be added to this space-saving cluster in the future. This appliance group can also be used for storage with the same cluster concept.

With the Cohesity’s SnapTree technology, the university can now access the data in a maximum of three steps. Login takes less than five minutes and full flash recovery takes 11.5 hours. In addition, a web interface facilitates the recovery of a Windows or Linux virtual machine with granular files. This approach to using, managing and backing up secondary and primary data is one of Cohesity’s strengths.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...