Analytics

10/31/2018
03:36 PM
50%
50%

Qualys Snaps Up Container Firm

Plans to use Layered Insight's technology to add runtime capabilities and automated enforcement to its container security tool.

Security firm Qualys has agreed to acquire Layered Insight in a move intended to build on the capabilities of its current container security tool, the companies confirmed today.

Layered Insight, founded in 2015 and based in Pleasanton, Calif., aims to bring together DevOps and SecOps by providing visibility across containerized applications. Qualys plans to use its technology to add more visibility and runtime app protection to its Container Security platform.

More specifically, Layered Insight can map runtime behavior to provide a deeper understanding of containerized applications. Its system can also detect and prevent breaches during runtime and gives admins the option to set alerts for anomalies and automate enforcement. Qualys anticipates Layered Insight will be integrated into its cloud platform by the second half of 2019.

Co-founders Asif Awan and John Kinsella will be joining Qualys as CTO of container security and vice president of engineering, container security, respectively.

This is the latest purchase in Qualys' startup shopping spree. It most recently announced its intent to buy Second Front Systems in June 2018; in April, it acquired the software assets of 1Mobility. In Nov. 2017 it purchased NetWatcher assets for cloud-based threat intelligence, a few months after it bought assets of Nevis Networks to improve on network traffic analysis.

Read more details here.

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Why We Need a 'Cleaner Internet'
Darren Anstee, Chief Technology Officer at Arbor Networks,  4/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11537
PUBLISHED: 2019-04-25
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclu...
CVE-2019-9669
PUBLISHED: 2019-04-25
The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector.
CVE-2018-12244
PUBLISHED: 2019-04-25
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.
CVE-2018-18286
PUBLISHED: 2019-04-25
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive information from the database...
CVE-2019-9137
PUBLISHED: 2019-04-25
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.