Showing posts with label virtual machine. Show all posts
Showing posts with label virtual machine. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


CloudJumper launches distribution agreement with Crayon to improve access to cloud workspace for Azure

CloudJumper announces alliance with Crayon that combines the power of CloudJumper’s Cloud Workspace Management Suite (CWMS) for VDI and RDS workloads with the expertise of Crayon’s managed services and independent 'cloud economics' consulting practice.

CloudJumper and Crayon’s partnership bring new possibilities for customers and MSPs who want the flexibility of choice for management, security options and the ability to build their own value-add services suite leveraging WVD. 


Microsoft’s Windows Virtual Desktop (WVD) brings new choices for customers who want more control of the managed services running on top of desktop and application virtualization solutions. Legacy VDI providers have historically served as a gatekeepers controlling the workstation management plane. CloudJumper brings to Azure WVD what the legacy vendors will not – the flexibility of controlling managed services on top of managed desktops.

The utility of Windows Virtual Desktop (WVD) is further enhanced through CloudJumper's Cloud Workspace Management Suite (CWMS). CWMS is an automation, orchestration workflow and policy solution to deploy, configure and manage WVD in real-time and at cloud scale. CWMS will instantly, and continually, optimize the customer’s Azure investment.


WVD is a complex collection of Azure services. CloudJumper simply funnels the hundreds of WVD setup options into a few key questions and then orchestrates and deploys a customized environment. With CloudJumper, the customer is just minutes away from deploying thousands of new WVD VMs– something that is not available in a native Azure user interface (UI).

To provide additional support for this distribution partnership, CloudJumper's product development team has been working closely with Microsoft's WVD product team for over two years. As a result, CloudJumper is proud to be recognized as a Microsoft Preferred Solution Provider for WVD.

Microsoft Azure WVD provides customers with unique licensing options and operating system flexibility for Windows 10 and Windows 7 desktop virtualization. Windows 7 desktops can now be migrated to Azure WVD and receive up to three years extended security updates at no additional costs. 

New Windows 10 multi-session OS options are only offered in Azure. These OS choices along with the many complementary Azure PaaS management and security offerings can be securely delivered directly into the Azure tenant. Native Azure Management, supported by CWMS, means no redirection and no third party vendor lock-in. This allows customers to leverage current Microsoft licensing instead of buying overlapping third party tools.

The partnership with Crayon combines the strengths and expertise of CloudJumper and Crayon to deliver the next generation of cloud DaaS and WaaS VDI and RDS desktop and application virtualization solutions.


Headquartered in Oslo, Norway, Crayon is in over 35 countries, providing more than 8,000 customers with strategic advice, consulting and managed services, and support with complex IT estates. Crayon has been the preeminent IT infrastructure consulting business in the Nordic region for more than 12 years, and has expanded its footprint in the US in the last two years.

“Crayon’s deep experience in all aspects of the digitalization journey helps ensure the success of the new partnership. We are pleased to combine CloudJumper’s advanced platform with Crayon’s unique SAM to Cloud Consultancy Services as companies take the next step in digital transformation with their move to Windows Virtual Desktop,” said Alex Picchietti, global director of cloud services for Crayon. “The wealth of expertise from both companies will support organizations making this important move to improve productivity and operational efficiency.”

“The advent of WVD and the partnership with a respected industry leader like Crayon extends the reach of our combined solutions globally,” said JD Helms, president of CloudJumper. “Customers are demanding choice and flexibility in their managed workspace providers and CloudJumper is uniquely positioned to do just that.”

Wednesday, December 11, 2019

McAfee releases CASB-integrated cloud security platform for container-based applications

McAfee announced McAfee MVISION Cloud for Containers that integrates container security with its Cloud Access Security Broker (CASB) and Cloud Security Posture Management (CSPM) security solution. 

Leveraging NanoSec’s zero trust application visibility and control capabilities for container-based deployments in cloud environments, the solution provides customers with the ability to speed up application delivery, while enhancing the governance, compliance and security of their container workloads.




The acquisition of NanoSec will strengthen the container security capabilities of McAfee MVISION Cloud and MVISION Server Protection products, giving its customers the ability to speed up application delivery while enhancing governance, compliance and security of their hybrid, multi-cloud deployments. 

NanoSec’s security capabilities will be applied to applications and workloads deployed in containers and Kubernetes and will be integrated into McAfee MVISION Cloud and MVISION Server Protection offerings. These capabilities include continuous configuration compliance and vulnerability assessment as well as runtime application-level segmentation for detecting and preventing lateral movement of threats.


Container security has long been treated as separate from other Infrastructure as a Service (IaaS) security solutions, requiring evaluation, investment and management of multiple, niche products thus increasing total cost of ownership and complexity and reducing security. 

McAfee MVISION Cloud for Containers integrates Cloud Security Posture Management (CSPM) and Vulnerability Scanning for container workloads into the existing McAfee MVISION Cloud platform to give customers a unified cloud security solution where consistent security policies can be implemented across all forms of cloud IaaS workloads.

McAfee MVISION Cloud integrates with DevOps tools, helps users “shift-left” to pre-emptively improve compliance and secure container workloads by running security audits in the DevOps pipeline and providing security incident data directly back to the development teams. 

Additionally, McAfee MVISION Cloud also continuously monitors the production deployments of these container workloads to ensure configuration drift does not compromise the security of the applications.


Currently available, McAfee MVISION Cloud for Containers provides CSPM that integrates Configuration Audit checks for containerized workloads to ensure the container platforms run in accordance with CIS and other best practice compliance standards. This is designed to ensure security checks for the complete container stack including the configuration of the virtual machine the container runs on, as well as the storage, network and other Platform as a Service (PaaS) services the container may be accessing.

The offering also adds vulnerability scanning of container images that helps to identify and prevent the use of weak or exploitable components of the container images. This reduces the overall risk profile of the application by minimizing the attack vectors. With Shift Left DevOps integration, users can perform CSPM and Vulnerability Scanning checks earlier in the application development lifecycle. This helps identify risk and provide meaningful feedback to developers within the build process. Additionally, continuously monitor and prevent configuration drift on production deployments of the container workloads.

Sunday, December 8, 2019

Microsoft validates Lenovo ThinkSystem SE350 edge server for Azure Stack HCI

Microsoft and Lenovo have teamed up to validate the Lenovo ThinkSystem SE350 for Microsoft's Azure Stack HCI program. The ThinkSystem SE350 was designed and built with the unique requirements of edge servers in mind. It is versatile enough to stretch the limitations of server locations, providing a variety of connectivity and security options and can be easily managed with Lenovo XClarity Controller. 

The ThinkSystem SE350 solution has a focus on smart connectivity, business security, and manageability for the harsh environment.


The ThinkSystem SE350 is the latest workhorse for the edge. Designed and built with the unique requirements for edge servers in mind, it is versatile enough to stretch the limitations of server locations, providing a variety of connectivity and security options and is easily managed with Lenovo XClarity Controller. 

The ThinkSystem SE350 is a rugged compact-sized edge solution with a focus on smart connectivity, business security, and manageability for the harsh environment.

The ThinkSystem SE350 is an Intel Xeon D processor-based server, with a 1U height, half-width and short depth case that can go anywhere. Mount it on a wall, stack it on a shelf, or install it in a rack. This rugged edge server can handle anything from 0-55°C as well as full performance in high dust and vibration environments.

Information availability is another challenging issue for users at the edge, who require insight into their operations at all times to ensure they are making the right decisions. The ThinkSystem SE350 is designed to provide several connectivity options with wired and secure wireless Wi-Fi and LTE connection ability. This purpose-built compact server is reliable for a wide variety of edge and IoT workloads.

Azure Stack HCI solutions bring together highly virtualized compute, storage, and networking on industry-standard x86 servers and components. Combining resources in the same cluster makes it easier to deploy, manage, and scale, while managing command-line automation or Windows Admin Center.

Consumers can achieve virtual machine (VM) performance for server applications with Hyper-V, the foundational hypervisor technology of the Microsoft cloud, and Storage Spaces Direct technology with built-in support for non-volatile memory express (NVMe), persistent memory, and remote direct memory access (RDMA) networking.

Friday, December 6, 2019

University of Lausanne adopts Cohesity data management platform to boost time and cost savings, backup flexibility, scalability

Cohesity announced this week implementation of a comprehensive data backup solution for the University of Lausanne, located in Switzerland. Working in tandem with local partner Infoniqa, the solution deployed by the university is significantly faster and more automated and scalable than systems previously used. 

A complete backup of the Microsoft Exchange database now only takes eight hours instead of 29 and the incremental backup can be completed in just under two hours instead of the previous 7.5 hours.



With the new solution, the University of Lausanne is realizing simple, fast backup and disaster recovery on a single platform; easier management through integration with VMware and Avamar; significant time and cost savings in data backup and recovery; and compliance according to DSGVO by encryption of critical data.

With over 15,000 students, 5,000 employees, and two million documents, the university manages around 22 PB of logical data. For this purpose, a second backup solution was set up at the Neuchâtel site. 

As the licences for the existing system expired, the university was looking for a state-of-the-art solution that would meet a number of key requirements: secure critical data in encrypted form, high scalability, efficient recovery of mass data, compatibility with EMC NetWorker and the option of a hybrid cloud solution.

“Cohesity and Infoniqa take a modern and holistic approach to data management,” explains Michel Ruffieux, storage backup manager, University of Lausanne. “It was the only solution that met our requirement to secure critical data in encrypted form using a multi-tenant solution with private keys managed on a KMS server using the KMIP protocol.”


Cohesity and Infoniqa were able to combine the old and new backup systems at the University of Lausanne to cover the entire virtualized environment. Infoniqa enabled the platform to be deployed according to the customer’s requirements. Cohesity supplied four appliances, and additional servers can be added to this space-saving cluster in the future. This appliance group can also be used for storage with the same cluster concept.

With the Cohesity’s SnapTree technology, the university can now access the data in a maximum of three steps. Login takes less than five minutes and full flash recovery takes 11.5 hours. In addition, a web interface facilitates the recovery of a Windows or Linux virtual machine with granular files. This approach to using, managing and backing up secondary and primary data is one of Cohesity’s strengths.

Wednesday, November 27, 2019

Cohesity debuts new offerings to protect cloud databases and enhance data archiving

Cohesity announced that it will showcase new integrations at AWS re:Invent 2019 in Las Vegas that extend its enterprise-class backup and data protection to database as a service and platform as a service offerings on AWS, making it easier for customers to protect valuable cloud workloads without adding to their cloud footprint. 


In addition, Cohesity will showcase new enhancements for archiving data to AWS, making it even more cost-effective to build hybrid cloud environments.


Cohesity’s new integrations with AWS include Cohesity Cloud Snapshot Manager for Amazon RDS and Amazon EC2 with its new lightweight solution that protects Amazon database and virtual machine workloads remotely from on-premises environments. Cohesity also extended enterprise-class backup capabilities for SAP HANA in-memory databases that run on AWS.


The Cohesity CloudArchive Direct capability allows customers to archive file data from Networked Attached Storage (NAS) devices directly to cloud reducing primary storage footprint and costs. 


Cohesity is also adding support for Glacier Deep Archive, the lowest cost cloud storage class from AWS, enabling customers to further reduce their long term cloud storage costs.

Wednesday, November 20, 2019

Rancher Labs takes Kubernetes to the edge and beyond, as it strengthens its product line

Rancher Labs announced general availability of K3s, its lightweight, certified Kubernetes distribution purpose built for small footprint workloads, along with the beta release of Rio, their new application deployment engine for Kubernetes that delivers a fully integrated deployment experience from operations to pipeline.


Although many enterprises now include Kubernetes in their strategic edge initiatives, Kubernetes in its upstream form is too heavy and operationally challenging for edge use-cases. Rancher Labs originally created K3s as a lightweight Kubernetes distribution designed for use in edge production environments and has been working with Arm to optimize for these workloads. 

Rio is targeted squarely at addressing the inherent complexity of building, deploying, and managing containerized applications. Designed for use by developers and DevOps teams, Rio makes it fast and easy to build, test, deploy, scale, and version stateless apps in any Kubernetes cluster. 


Capabilities of Rio include lightweight, cloud-native platform that delivers a fully integrated deployment experience from operations to pipeline without taking over the cluster; and easily installed using Rancher’s App Catalog and also runs on any Kubernetes cluster anywhere, even on a laptop, handling all wiring for common services like Istio, Knative, and Prometheus.

It also comes with Rancher’s built-in security capabilities around cluster performance, multitenancy and encryption allow applications to launch with the most secure network configuration possible.

Because of its lightweight design and simple operation, K3s is also being adopted for use cases beyond the edge. 

“Kubernetes has established itself as the de facto standard for container orchestration,” stated Sheng Liang, co-founder and CEO, of Rancher Labs. With our investments in K3s and Rio, and our recently announced Rancher v2.3, we are completing our Kubernetes-as-a-service solution stack for ITOps and DevOps teams.”


Civo, a cloud solutions provider, who has created the initial K3s-powered, managed Kubernetes service. 

“Our #KUBE100 K3s platform is a learning playground where those new to containers can test the water, risk and cost-free,” said Andy Jeffries, CTO at Civo. “K3s is so lightweight we can install it in under two minutes - a fraction of the time it takes to launch a regular Kubernetes cluster. With K3s, developers can spin up new clusters, deploy apps and test easily - at speed.”

Monday, November 18, 2019

HPE Container Platform boosts application development for bare-metal and edge to cloud deployments

Hewlett Packard Enterprise (HPE) announced on Monday its HPE Container Platform, an enterprise-grade Kubernetes-based container platform designed for both cloud-native applications and monolithic applications with persistent storage. With the HPE Container Platform, enterprise customers can accelerate application development for new and existing apps – running on bare-metal or virtualized infrastructure, on any public cloud, and at the edge.


The HPE Container Platform is built on proven innovations from HPE’s acquisitions of BlueData and MapR, together with 100 percent open source Kubernetes. This next-generation solution dramatically reduces cost and complexity by running containers on bare-metal – while providing the flexibility to deploy on virtual machines and cloud instances. 


Customers benefit from greater efficiency, higher utilization, and improved performance by “collapsing the stack” and eliminating the need for virtualization.


The platform addresses the requirements for large-scale enterprise Kubernetes deployments across a wide range of use cases, from machine learning and edge analytics to CI/CD pipelines and application modernization. 


IT teams can manage multiple Kubernetes clusters with multi-tenant container isolation and pre-integrated persistent storage. Developers have secure on-demand access to their environments so they can develop apps and release code faster, with the portability of containers to build once and deploy anywhere.


The HPE Container Platform modernizes non cloud-native monolithic applications without re-architecting them, elevating the experience to modern cloud standards; provides the ability to build applications once and run them anywhere, bridging the gap between on-premises, public clouds and the edge; and improves productivity for developers and delivers new code releases faster, with simplified Kubernetes deployment and multi-cluster management.


It also ensures enterprise-class security, performance, and reliability at lower cost, with bare-metal containers and data persistence. 



This new solution complements existing HPE services to assist customers with container strategies, application modernization, and hybrid cloud deployments. HPE Pointnext provides advisory and consulting services built upon experience from over one thousand hybrid cloud engagements, with expertise and best practices from the acquisitions of Cloud Technology Partners and RedPixie.


HPE Container Platform software will be orderable in early next year along with advisory, consulting, deployment, and support services from HPE.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...