Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Saturday, December 28, 2019

Greenliant SATA 2.5-inch EnduroSLC industrial enterprise SSDs deliver SLC data storage that provide ultra high endurance

Greenliant is currently sampling its SATA 2.5-inch EnduroSLC Industrial Enterprise EX Series solid state drives (SSDs) for primary storage applications that require ultra high endurance under extreme temperature conditions. 

Designed with Greenliant’s EnduroSLC technology, SATA 2.5-inch Industrial Enterprise EX Series SSDs provide ultra robust data retention and ultra high system-level lifetime endurance of 30 drive writes per day (DWPD) for 5 years. EnduroSLC is a proprietary 3D NAND management technology that delivers high reliability applications requiring superior data retention and endurance in extreme temperature, high stress environments. 



With advanced hardware ECC capabilities and NAND flash management algorithms, EnduroSLC Technology significantly extends the write endurance of 1-bit-per-cell (SLC) SSDs reaching industry leading 250K+ program-erase (P/E) cycles. EnduroSLC enabled products meet robust data retention requirements under complex temperature conditions and support wide cross-temperature ranges between data programming and reading. Further, due to its substantially lower bit error rate, an EnduroSLC SSD provides better consistency in read/write performance throughout product lifetime. 

The SATA 2.5-inch EnduroSLC industrial enterprise SSDs with 1-bit-per-cell (SLC) NAND include ultra high endurance that reaches 30 DWPD for five years; high capacity offered from 800 gigabytes to 1.92 terabytes; on-chip adaptive RAID that improves SSD reliability; power interrupt data protection that helps prevent data corruption during power failures; industrial temperature that operates between -40 and +85 degrees Celsius; and data security supports AES 256-bit encryption and crypto erase.

By leveraging over 25 years of solid state storage design expertise, Greenliant is dedicated to developing durable, reliable and secure storage solutions for embedded systems and enterprise data centers. The company is headquartered in Silicon Valley with product development centers in Santa Clara, Beijing, Shanghai, Xiamen and Hsinchu.


“Greenliant has brought its SLC NAND expertise to the enterprise with its new line of EnduroSLC Industrial Enterprise EX Series SSDs,” said Xuanhui Li, vice president of business development for datacenter products, Greenliant. “With high reliability and outstanding quality of service, Greenliant’s industrial enterprise storage products are ideal for mission critical, I/O intensive applications in aerospace, defense, transportation, energy and power, communications and industrial control.”

The SATA 2.5-inch Industrial Enterprise EX Series expands the EnduroSLC product family, which also includes SATA M.2 2242/2280, mSATA, SATA 2.5-inch and CFast ArmourDrive, and SATA 6Gb/s NANDrive and 100-ball/153-ball eMMC NANDrive ball grid array (BGA) SSDs.

Greenliant is sampling its new G3200 Industrial Enterprise EX Series SSDs to customers now, and expects to start shipping in volume production by end of this year. Greenliant is also shipping its 3-bit-per-cell (3D TLC NAND) G3100 Enterprise PX Series SSDs in capacities from 480 GB to 3.84 TB. 

Tuesday, December 24, 2019

Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

Saturday, December 21, 2019

Symantec releases its Holiday Wishlist, with key cyber safety tools making it to the Holiday Shopping listing

As consumers head into the end-of-year holiday celebrations, they are expected to go shopping. But as they trek to the malls or go online, shoppers need to consider the security implications of the vast array of cool, connected devices now on the market.

After a hacker accessed a security camera and harassed an 8-year-old, the chilling recording of the encounter sends a clear warning to shoppers this holiday season. This could happen with anyone using smart-home devices can potentially be hacked or modified to lock out. General device privacy and security concerns apply here to protect users from the misuse of their data.


Consumers must make purchases from reputable manufacturers, and make sure to change the default passwords that these devices come with and don’t forget to use security software to help prevent malware from infecting devices on home network. 

Smart watches and activity trackers are soaring in popularity with nearly 85 million people around the world last quarter discovering the convenience of having the power of the internet within reach. But these accessories don't stand alone. Rather, they serve as extensions of smartphones and collect personal information. So, carefully read the privacy policies regarding the information that the user intends to share, including reviewing geographical location settings.


Increasingly, smart watches are gaining access to certain functions in smart homes, such as the ability to remotely unlock the front door. That sounds great until the device gets lost or stolen. If it does, review all passwords to make sure they’re protected with two-factor authentication. Even though some accessories include security settings that ought to help protect users in case of loss or theft, be sure to understand the tradeoffs of convenience.

Any internet-connected, voice-enabled TV has the capability to track what you are searching and watching. What’s more concerning is attackers can hack into smart TV webcams for spying or capitalize on software vulnerabilities to insert malware that can move through  connected devices. Also, when shopping for a unit, don’t forget to ask whether it has a camera. Also, does it come with a physical cover or is there one that can be added?

It’s worth researching whether the brand has a good or bad reputation when it comes to privacy and data collection. Once the user brings it home, think about whether they want to be tracked for advertising purposes. Most smart TVs do come with an option for users to turn off such tracking, but it may not be the default setting. So, check the fine print before turning on or turning off features on the smart TV.


A general rule with Smart TV software (and any computing device), to keep the software up to date or turn on automatic updates if there’s such an option.

Another great convenience of the last few years, robot vacuum cleaners have become a must-have appliance for many. Independent research finds that the devices enjoy off-the-chart loyalty with 89 percent of people who own robot cleaners saying they would recommend them to friends and family.

But don’t ignore the privacy implications. Many robot cleaners have cameras to map the house floor layout and optimize operation. This poses potential areas of concern if the robot is connected to the internet. Ensure the manufacturer is protecting the mapped layout data and that it is not shared. Also ensure the cameras are not capturing additional data from within the home.


Another point to consider is that unlike most other devices users may own around the house, this is a machine that physically moves inside the home. As such, a compromised vacuum potentially can enable other types of creepy activity.

So again, ask whether the user trust the manufacturer and whether the company not only can build a vacuum, but also safeguard data. If the answer to that question is yes, also inquire how they go about doing it. Don’t take “why, of course we protect you” as the final answer. Do the research and focus on reputable manufacturers. 

NPR and Edison Research estimates that there are now about 120 million smart speakers in U.S. homes, representing 78 percent year-over-year growth. But most of these devices have “always on” speech listening and recognition features so that they can identify the “wake word” — even while they are standing by?

It’s no longer exceptional to read about people complaining that their private conversations somehow triggered the device’s wake word to start eavesdropping. So, before buying a smart speaker for the home, ask whether they are comfortable with this?


Many of users see this as a small price to pay for the convenience being offered. But always-on listening means that such devices can not only listen to what the user says (and potentially use it — for advertising, for instance), but they can also capture ambient noise that reveals a lot of other things about the user.

The electronic/computing system of a car controls most of its operation and is far more vulnerable than, say, a gas-guzzling station wagon from yesteryear. Increasingly, our cars are turning into the equivalent of iPads on four wheels as vehicles incorporate more and more electronic gadgetry each year to add customer convenience.

But as with any technology device, it’s wise to take precautions that mitigate security risks. For instance, in this case the USB ports in certain newer cars might be manipulated to read files on the cell phone or install malware on the device. This is the latest practice known as Juice Jacking, where malware gets installed onto a device or information and can be stolen via the USB charging port.

Also, hackers may be able to launch attacks against audio systems in a bid to control the vehicle remotely. Similar vulnerabilities have also been found with key fobs and certain apps that get used to communicate with the cars. Users must take basic precautions, and be extremely careful with car port dongles that are plugged into the car control port. As with any other computing devices, it is vital to apply software updates in a timely manner and fix any potentially relevant recalls. Don’t make an attacker’s job any easier for them.

Every year more devices become part of the Internet of Things, and that includes children’s toys. But now that digital toys and devices come with built-in cameras and GPS trackers, users need to consider benefits with the potential security risks. Some toys may interact with smart speakers, which introduces a new category of threats.


Like other connected digital devices, they are potentially vulnerable to hacks and any data they collect may not be private — or secure. The threat is not theoretical. Symantec has seen instances in which companies neglected to protect their online storage system and hundreds of thousands of records, including childrens’ names, ages and voice recordings, got exposed.

That puts the onus on parents to use complicated passwords for every connected toy they buy for their kids. Also, never let children access the internet from an unsecure Bluetooth or Wi-Fi connection.

Many wireless headphones now come with integrated voice assistants and involve security issues with which users are familiar. Also, if users can connect over Bluetooth, there’s always the risk it may not be secure, especially outdated versions of the protocol which likely have unpatched security holes. One easy precaution: Just turn off Bluetooth when the users are not using it, or near anyone who do not trust.

Saturday, December 14, 2019

Kaspersky research finds 174 municipal institutions targeted with ransomware in 2019

According to Kaspersky security experts, 2019 has seen a significant spike of ransomware attacks on municipalities. This conclusion comes after the company’s researchers observed at least 174 municipal institutions with more than 3,000 subset organizations have been targeted by ransomware throughout the last year. This represents a 60 percent increase from the same figure in 2018.


Ransomware is notorious in the corporate sector for financial devastation and has affected businesses around the world for several years. This year has seen rapid development of an earlier trend where malware distributors have targeted municipal organizations. 

Researchers note that while these targets might be less capable of paying a large ransom, they are more likely to agree to cybercriminals’ demands. Blocking any municipal services directly affects the welfare of citizens in financial losses as well as other significant and sensitive consequences.

When considering publicly available information, ransom amounts have varied greatly with highs reaching up to $5,300,000 and $1,032,460 on average. Researchers note that these figures do not accurately represent the final costs of an attack, as the long-term consequences are far more devastating.

The malware that was most often observed were varied, yet three families were named as the most notorious by Kaspersky researchers: Ryuk, Purga and Stop. Ryuk appeared on the threat landscape more than a year ago and has since been active all over the world in public and in the private sector. Its distribution model usually involves delivery via backdoor malware which spreads by the means of phishing with a malicious attachment disguised as a financial document. 


Purga malware has been recognized since 2016, yet only recently municipalities have been discovered to fall victims to this Trojan having various attack vectors from phishing to brute force attacks. Stop cryptor is relatively new as it is only a year old. It propagates by hiding inside software installers. This malware continues to be prevalent, ranking at number seven in the top 10 most popular cryptors ranking of the third quarter this year.

“One must always keep in mind that paying extortionists is a short-term solution which only encourages criminals and keeps them funded to quite possibly repeat the same acts,” said Fedor Sinitsyn, a security researcher at Kaspersky. “In addition, once a city has been attacked, the whole infrastructure is compromised and requires an incident investigation and a thorough audit. This inevitably results in costs that are in addition to the ransom requested. Based on our observations, cities might be inclined to pay because they usually cover the cyber risks with help of insurance and allocating budgets for incident response. The better approach would be to invest in proactive measures like proven security and backup solutions as well as regular security audit. While the trend of attacks on municipalities is only growing, it can be stifled by adjusting the approach to cybersecurity and what is more important by the refusal to pay ransoms and broadcasting this decision as an official statement.”

Friday, December 13, 2019

Kaspersky reports that malware variety grew by 13.7 percent this year, driven by surge in web skimmers

The number of unique malicious objects detected by Kaspersky’s web antivirus solution rose by 13.7 percent this year, compared to last year, reaching 24,610,126. The growth was mainly influenced by a 187 percent rise in web skimmer files. 

Other threats, such as backdoors and banking Trojans detected in-lab, also grew, while the presence of miners dropped by more than half. These trends demonstrated a shift in the type of threats used by attackers on the web, who search for more effective ways to target users, according to the new Kaspersky Security Bulletin: Statistics of the Year report.


In 2018, unique malicious objects (including scripts, exploits and executable files) detected by Kaspersky’s web antivirus solution totaled 21,643,946, rising to 24,610,126 this year. The growth reflects an increase in the number and variety of HTML pages and scripts with hidden data loading – usually used by unscrupulous advertisers. Yet, most notably, the growth was also partially caused by online skimmers, sometimes referred to as sniffers, where scripts are embedded by attackers in online stores and used to steal users’ credit card data from websites.

The growth of online skimmers’ unique files (scripts and HTML) detected by Kaspersky web antivirus equaled 187 percent, reaching 510,000. At the same time, the number of threats detected by web antivirus has risen five-fold (by 523 percent), totaling 2,660,000 in 2019. 

Web skimmers also entered the top 20 malicious objects detected online, taking 10th place in the overall ranking. The share of new backdoors and banking Trojan files, among all types of threats detected in-lab, also grew by 134 percent and 61 percent to reach 7,644,402 and 739,551 respectively.

Nevertheless, the number of unique malicious URLs detected by Kaspersky web antivirus fell by half (50.5 percent) in comparison to 2018, from 554,159,621 to 273,782,113. This shift was largely caused by significant decrease of hidden web miners, even though several detections related to them (including Trojan.Script.Miner.gen, Trojan.BAT.Miner.gen, Trojan.JS.Miner.m), can still be seen in the top 20 web malware threats.


The presence of programs that secretly generate cryptocurrency on users’ computers (called ‘local’ miners) has also been steadily declining over the year. The number of users’ computers affected by attempts to install miners dropped by 59 percent, from 5,638,828 to 2,259,038.

Eighty-five percent of web threats were detected as malicious URL. This detection name is used to identify links from Kaspersky’s black list. It includes links to web pages containing redirects to exploits, sites with exploits and other malicious programs, botnet command and control centers, extortion websites, and others.

“The volume of online attacks has been growing for years, but in 2019 we saw a clear shift from certain types of attacks that are becoming ineffective, to the ones focused on gaining clear profit from users,” said Vyacheslav Zakorzhevsky, head of anti-malware research at Kaspersky. “This is partly due to users becoming more aware of the threats and how to avoid them, and organizations steadily becoming more responsible. A good example is miners, which have lost their popularity due to lower profitability and cryptocurrencies’ fight against covert mining. This year we also witnessed growth in zero-day exploits, showing products remain vulnerable and are used by attackers for sophisticated attacks, and this trend is likely to continue in the future.”

Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...