Showing posts with label developer. Show all posts
Showing posts with label developer. Show all posts

Tuesday, December 31, 2019

VMware completes acquisition of Pivotal, connects infrastructure and application owners to boost software delivery, business outcomes

VMware announced Monday that it has completed the acquisition of Pivotal Software. With the completion of the acquisition, Pivotal’s Class A common stock was removed from listing on the New York Stock Exchange with trading suspended prior to the open of the market today, and Pivotal will now operate as a wholly owned subsidiary of VMware. The transaction represented an enterprise value for Pivotal of approximately $2.7 billion.


Under the terms of the transaction, Pivotal’s Class A common stockholders are entitled to receive $15.00 per share cash for each share held (without interest and less applicable tax withholdings), and Pivotal’s Class B common stockholder, Dell Technologies, received approximately 7.2 million shares of VMware Class B common stock, at an exchange ratio of 0.0550 shares of VMware Class B common stock for each share of Pivotal Class B common stock.

Pivotal’s offerings will be core to the VMware Tanzu portfolio of products and services designed to help customers transform the way they build, run and manage their most important applications, with Kubernetes as the common infrastructure substrate. 


The combination of Pivotal’s developer-centric offerings with VMware’s upstream Kubernetes run-time infrastructure and management tools will deliver a comprehensive enterprise solution that enables dramatic improvements in developer productivity in the creation of modern applications. VMware is able to offer product building blocks and integrated solutions that are tested and proven with technical expertise that customers need to accelerate software delivery across data center, cloud and edge environments.

“It's my pleasure to announce Ray O'Farrell as the leader of VMware’s new Modern Applications Platform business unit—uniting the Pivotal and VMware Cloud Native Applications teams,” said Pat Gelsinger, CEO, VMware. “And as Pivotal is now part of VMware, I want to thank the Pivotal leadership team for building a great company. Together, we’re poised to be the leading enabler of Kubernetes with a deep understanding of both operators and developers.”

“Digital transformation and the applications that drive it should not be restricted only to cloud and software giants,” said Ray O’Farrell, executive vice president and general manager, Modern Applications Platform Business Unit, VMware. “We believe that modern application development solutions and practices need to be easily accessible to everyday enterprises across the globe. With Pivotal’s developer capabilities as the foundation, we’ll focus on delivering consumable, enterprise-ready cloud native offerings to customers to help them achieve better business outcomes.”  


“Pivotal has fundamentally changed how the world’s biggest brands build and manage software with a focus on developer productivity through platform abstractions and development techniques as well as connecting the business with the developer,” said Edward Hieatt, senior vice president, customer success, Pivotal. “The combination of Pivotal and VMware offers the most comprehensive application platform in the industry and is a win for our customers, a win for Pivotal, and a win for VMware. We’re excited to team up with VMware to help more enterprises become like modern software companies by adopting DevOps and Lean techniques developed by internet giants and the startup community.”


Numerous mutual customers including Raytheon have reacted positively to the news of the acquisition. “By working with both Pivotal and VMware, we’ve been able to completely transform how we write software for our military and government customers,” said Todd Probert, vice president for C2, Space and Intelligence at Raytheon. “Combining these companies under a single umbrella is going to make it possible for my team to get code to our customers even faster and easier.”

Wednesday, December 11, 2019

McAfee releases CASB-integrated cloud security platform for container-based applications

McAfee announced McAfee MVISION Cloud for Containers that integrates container security with its Cloud Access Security Broker (CASB) and Cloud Security Posture Management (CSPM) security solution. 

Leveraging NanoSec’s zero trust application visibility and control capabilities for container-based deployments in cloud environments, the solution provides customers with the ability to speed up application delivery, while enhancing the governance, compliance and security of their container workloads.




The acquisition of NanoSec will strengthen the container security capabilities of McAfee MVISION Cloud and MVISION Server Protection products, giving its customers the ability to speed up application delivery while enhancing governance, compliance and security of their hybrid, multi-cloud deployments. 

NanoSec’s security capabilities will be applied to applications and workloads deployed in containers and Kubernetes and will be integrated into McAfee MVISION Cloud and MVISION Server Protection offerings. These capabilities include continuous configuration compliance and vulnerability assessment as well as runtime application-level segmentation for detecting and preventing lateral movement of threats.


Container security has long been treated as separate from other Infrastructure as a Service (IaaS) security solutions, requiring evaluation, investment and management of multiple, niche products thus increasing total cost of ownership and complexity and reducing security. 

McAfee MVISION Cloud for Containers integrates Cloud Security Posture Management (CSPM) and Vulnerability Scanning for container workloads into the existing McAfee MVISION Cloud platform to give customers a unified cloud security solution where consistent security policies can be implemented across all forms of cloud IaaS workloads.

McAfee MVISION Cloud integrates with DevOps tools, helps users “shift-left” to pre-emptively improve compliance and secure container workloads by running security audits in the DevOps pipeline and providing security incident data directly back to the development teams. 

Additionally, McAfee MVISION Cloud also continuously monitors the production deployments of these container workloads to ensure configuration drift does not compromise the security of the applications.


Currently available, McAfee MVISION Cloud for Containers provides CSPM that integrates Configuration Audit checks for containerized workloads to ensure the container platforms run in accordance with CIS and other best practice compliance standards. This is designed to ensure security checks for the complete container stack including the configuration of the virtual machine the container runs on, as well as the storage, network and other Platform as a Service (PaaS) services the container may be accessing.

The offering also adds vulnerability scanning of container images that helps to identify and prevent the use of weak or exploitable components of the container images. This reduces the overall risk profile of the application by minimizing the attack vectors. With Shift Left DevOps integration, users can perform CSPM and Vulnerability Scanning checks earlier in the application development lifecycle. This helps identify risk and provide meaningful feedback to developers within the build process. Additionally, continuously monitor and prevent configuration drift on production deployments of the container workloads.

Sunday, December 8, 2019

Google extends its Android TLS adoption program; covers 80% apps by default

Google announced this week that 80 percent of Android apps are encrypting traffic by default. The percentage is even greater for apps targeting Android 9 and higher, with 90 percent of them encrypting traffic by default.

Android is committed to keeping users, their devices, and their data safe. One of the ways that Google is keeping data safe is by protecting network traffic that enters or leaves an Android device with Transport Layer Security (TLS). 


Android 7 (API level 24) introduced the Network Security Configuration in 2016, allowing app developers to configure the network security policy for their app through a declarative configuration file. To ensure apps are safe, apps targeting Android 9 (API level 28) or higher automatically have a policy set by default that prevents unencrypted traffic for every domain.

The Network Security Configuration feature lets apps customize their network security settings in a safe, declarative configuration file without modifying app code. These settings can be configured for specific domains and for a specific app. 


This feature can customize which Certificate Authorities (CA) are trusted for an app's secure connections. For example, trusting particular self-signed certificates or restricting the set of public CAs that the app trusts. It also safely debugs secure connections in an app without added risk to the installed base; protects apps from accidental usage of cleartext traffic; and restricts an app's secure connection to particular certificates.

Since Nov. 1 2019, all app (updates as well as all new apps on Google Play) must target at least Android 9. As a result, we expect these numbers to continue improving. Network traffic from these apps is secure by default and any use of unencrypted connections is the result of an explicit choice by the developer.


The latest releases of Android Studio and Google Play’s pre-launch report warn developers when their app includes a potentially insecure Network Security Configuration (for example, when they allow unencrypted traffic for all domains or when they accept user provided certificates outside of debug mode). 

This encourages the adoption of HTTPS across the Android ecosystem and ensures that developers are aware of their security configuration.

Wednesday, December 4, 2019

New HPE GreenLake Central delivers cloud experience everywhere with next-generation as-a-Service platform

Hewlett Packard Enterprise (HPE) will now deliver its entire edge-to-cloud portfolio as-a-Service, with the launch of HPE GreenLake Central, an advanced software platform that provides customers with a consistent cloud experience for all their applications and data, through an operational console that runs, manages and optimizes their entire hybrid IT estate. HPE unveiled HPE GreenLake Central in a keynote address by Antonio Neri, President and CEO, at HPE Discover More Munich.



Building on the momentum of HPE GreenLake, HPE’s IT as-a-Service offering, HPE GreenLake Central gives customers a simple, unified, digital experience across public and private clouds, the data center and edge workloads. This platform accelerates business outcomes for customers by lowering costs and risks and providing greater choice and control.


Despite the promise of the cloud to speed delivery of new applications, organizations’ digital transformation efforts have become more complex, costly, and slow-moving. 


To add to these challenges, the vast majority of applications and data remain in the data center, and are growing exponentially at the edge. As a result, organizations have been dealing with a siloed, inconsistent experience across their hybrid estate, and lack control and visibility into the costs and risks across their enterprise.



HPE GreenLake Central allows customers to break through these challenges by delivering a single, integrated management control plane for their entire hybrid IT estate, and one operational console from which to direct and drive their digital transformation initiatives – all delivered as-a-Service. The platform gives customers the freedom to choose which tools they want to use to build applications, where and how to place their workloads and data, and only pay for what they consume.


HPE GreenLake Central helps CIOs regain control of their organization’s hybrid IT estate through a unified dashboard and operational console that positions them as service brokers to the rest of the business. CIOs can monitor and take action on a range of KPIs, including security, capacity, cost, compliance, and resource utilization. 



HPE GreenLake Central brings the self-service experience to the on-premises environment, and gives CIOs unmatched visibility and control, so they can focus on innovation and strategy, and transition from reacting to running hybrid IT.


It enables developers to gain access to a simple “point, click, get” pay-per-use platform that allows developers to write, release, and deploy code quickly, without having to worry about underlying infrastructure. Developers can access a wide array of tools and services from HPE and partners through a marketplace, giving them one “workbench” from which to design and create applications at high speed.


It allows CFO to obtain a real-time view of technology spend across the hybrid IT estate, to understand spend by users, teams, and business units, and within public and private cloud, data center and edge environments. HPE GreenLake Central provides finance with visibility to control costs and ensure projects remain on budget.


It also delivers legal, compliance and security capability to gain a single, integrated view into the governance and security status of an organization’s hybrid IT estate. Users can identify risks through a KPI dashboard and take action by leveraging over 1,000 controls to ensure compliance with company and industry regulations. Risks and failures are easy to identify and address, and comprehensive reports offer significant reduction in the time it takes to perform audits.

“HPE GreenLake Central is a transformative platform that changes the game in hybrid IT,” said Antonio Neri, president and CEO, HPE. “With this offering, every user in a company gains access to a unique console from which to run their organization and achieve powerful business outcomes. Now the CIO can operate as a strategic service broker, and everyone benefits from a consistent cloud experience, resulting in lower costs and risks, and greater choice, control, simplicity, and speed.”


HPE GreenLake is one of the quick growing businesses in HPE, with more than 740 customers worldwide, including 160 new customer logo wins this year. Additionally, HPE has enabled its global partner community to deliver the offering – in 2019 the channel generated over 200 percent order growth for HPE GreenLake.


HPE GreenLake Central is in trial with customers now, and will be generally available to HPE GreenLake clients by the end of HPE first quarter next year. 

Thursday, November 28, 2019

Apple expands Everyone Can Code curriculum to bring more coding resources to teachers and students

Apple unveiled completely redesigned Everyone Can Code curriculum to help introduce more elementary and middle school students to the world of coding. Now available, the new curriculum includes even more resources for teachers, a brand new guide for students and updated Swift Coding Club materials. 



Currently millions of students in more than 5,000 schools worldwide already use Everyone Can Code curriculum to bring their ideas to life and develop important skills including creativity, collaboration and problem solving. Additionally, learners around the world can register for thousands of free Today at Apple coding sessions taking place in December at Apple Stores to learn to write their first lines of code to celebrate Computer Science Education Week.


The Everyone Can Code curriculum builds on existing interactive puzzles, guides and activities to make learning to code even more approachable and connected to students’ everyday lives. Everyone Can Code Puzzles is an all-new student guide to Swift Playgrounds where each chapter helps students build on what they already know, experiment with new coding concepts and creatively communicate how coding impacts their lives. 



A companion teacher guide supports educators in bringing coding into their classrooms with helpful ways to facilitate, deepen and assess student learning. Designed to support all students, the new Everyone Can Code curriculum is optimized for VoiceOver and includes closed-captioned videos and audio descriptions as well as videos in American Sign Language.


The Everyone Can Code curriculum integrates Apple’s Everyone Can Create project guides to help students express what they learn through drawing, music, video and photos. Designed to help unleash kids’ creativity throughout their school day, Everyone Can Create gives teachers fun and meaningful tools to easily fold creativity skills into their existing lesson plans in any subject from coding to chemistry.


From Dec. 1 to Dec. 15, Apple Stores will increase Today at Apple coding sessions to offer thousands of opportunities to celebrate Computer Science Education Week. The free interactive sessions provide opportunities for participants at a variety of skill levels to get started with coding. Sessions help aspiring coders explore block-based coding with robots, while those with more experience can get started using Swift Playgrounds to learn coding concepts or code an augmented reality experience.


Select stores will also offer special sessions for coders of all ages. Preschool-age kids can try creative pre-coding activities in the new Coding Lab with the Helpsters, a team of vibrant monsters who love to solve problems and are featured in the new live-action preschool series, available now on Apple TV+, from the makers of “Sesame Street.” 



Participants of all ages can also learn from Apple Distinguished Educators, Apple Entrepreneur Camp innovators, developers and artists. Customers can register for Code with Apple sessions starting today.
For the seventh year, Apple will also support Hour of Code with a new Hour of Code Facilitator Guide to help educators and parents host sessions using Swift Playgrounds and some of the more than 200,000 educational apps available from the App Store.


For more advanced learners, including high school and college students preparing for the workforce, the Develop in Swift curriculum continues to give students the practical tools and techniques they need to qualify for high-demand and high-skill jobs. 


Develop in Swift is great for students new to coding as well as advancing those with previous experience — and even helps prepare them for a career in programming with a free AP Computer Science Principles course and the opportunity to earn industry recognized certification.

Wednesday, November 27, 2019

Google Security expands its Android Security rewards program

Google is expanding its Android Security Rewards (ASR) program and increasing reward amounts, by introducing a top prize of US$1 million for a full chain remote code execution exploit with persistence which compromises the Titan M secure element on Pixel devices. Additionally, the search engine giant will release a specific program offering a 50 percent bonus for exploits found on specific developer preview versions of Android, offering a top prize of $1.5 million.


The rewards program was created in 2015 to reward researchers who find and report security issues to help keep the Android ecosystem safe. Over the past 4 years, Google has awarded over 1,800 reports, and paid out over four million dollars.

The Android Security Rewards program recognizes the contributions of security researchers who invest their time and effort in helping Google make Android more secure. The reward level is based on the bug severity and increases for complete reports that include reproduction code, test cases, and patches.

Android Security Rewards covers bugs in code that runs on eligible devices and isn't already covered by other reward programs at Google. Eligible bugs include those in AOSP code, OEM code (libraries and drivers), the kernel, the Secure Element code, and the TrustZone OS and modules. Vulnerabilities in other non-Android code, such as the code that runs in chipset firmware, may be eligible if they impact the security of the Android OS.


Earlier this year, Gartner rated the Pixel 3 with Titan M as having the most “strong” ratings in the built-in security section out of all devices evaluated. Due to this, Google has created a dedicated prize to reward researchers for exploits found to circumvent the secure elements protections.

In addition to exploits involving Pixel Titan M, Google has added other categories of exploits to the rewards program, such as those involving data exfiltration and lockscreen bypass. These rewards go up to $500,000 depending on the exploit category. 

During this year, Google made total payouts over the last 12 months to the tune of over $1.5 million. Over 100 participating researchers have received an average reward amount of over $3,800 per finding (46 percent increase from last year), and the top reward that was paid out this year was $161,337.

The highest reward paid out to a member of the research community was for a report from Guang Gong (@oldfresher) of Alpha Lab, Qihoo 360. This report detailed the first reported 1-click remote code execution exploit chain on the Pixel 3 device. 

Guang Gong was awarded $161,337 from the Android Security Rewards program and $40,000 by Chrome Rewards program for a total of $201,337. The $201,337 combined reward is also the highest reward for a single exploit chain across all Google VRP programs. The Chrome vulnerabilities leveraged in this report were fixed in Chrome 77.0.3865.75 and released in September, protecting users against this exploit chain.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...