Analytics
1/9/2014
01:35 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Tripwire Announces Technology Partnership With CORE Security

Partnership provides threat and vulnerability risk management to mutual customers

PORTLAND, OREGON -- January 9, 2013 -- Tripwire, Inc., a leading global provider of risk-based security and compliance management solutions, and CORE Security, a leading provider of predictive security intelligence solutions, today announced a technology partnership and integration that provides comprehensive threat and vulnerability risk management to mutual customers. The integration unites vulnerability information with network topology from firewalls and routers, and then validates the vulnerability information and potential attack paths in live or simulated penetration tests. The collaboration is part of Tripwire's Technology Alliance Partner (TAP) program, designed to allow a wide variety of vendors to collaborate with Tripwire to deliver innovative security solutions.

"We are looking forward to building on our relationship with CORE Security," said Rod Murchison, vice president of product management and technology alliances for Tripwire. "Our integration with CORE Insight Enterprise makes it possible for enterprises to go beyond finding and fixing vulnerabilities to operating their vulnerability management programs at peak efficiency."

Large enterprises need to gather, analyze and prioritize an overwhelming amount of vulnerability and network topography data and combine it with cyberattack domain expertise in order to gain a comprehensive understanding of the security risks facing their most critical assets. To decrease the cost and complexity of risk-based security management, enterprises need the ability to effectively prioritize threats in the context of business, regulatory compliance and operational metrics.

The integration combines vulnerability information from Tripwire® IP360&trade with detailed exploit and network topology data from CORE Insight to model threat scenarios and enable vulnerability validation and proactive remediation. With this integration, mutual customers gain the ability to:

· Discover complex attack paths that expose vulnerability risks to other areas of the business.

· Validate vulnerability findings with directed simulation and/or live tests of exploitable conditions.

· Model the impact of remediation actions on the security posture of the business.

"The most common mistake organizations make is to take a reactive posture to imminent security threats to critical assets. Enterprises must go on the offensive by thinking like an attacker, and then they can preempt attacks rather than wait to deal with their consequences," said Eric Cowperthwaite, vice president of advanced security and strategy at CORE Security. "We are very pleased to partner with Tripwire and help organizations of all sizes better protect themselves against outside attacks through the use of our combined technologies and processes, providing an even stronger solution to this problem."

For more information about the integration between CORE Security and Tripwire IP360, please visit: http://www.tripwire.com/register/tripwire-ip360-and-core-insight-enabling-predictive-security-intelligence/.

About CORE Security

CORE Security is the leading provider of predictive security intelligence solutions for enterprises and government organizations. We help more than 1,400 customers worldwide preempt critical security threats throughout their IT environments, and communicate the risk the threats pose to the business. Our patented, proven, award-winning enterprise solutions are backed by more than 15 years of applied expertise from CoreLabs, the company's innovative security research center. For more information, visit www.coresecurity.com.

About Tripwire

Tripwire is a leading global provider of risk-based security and compliance management solutions, enabling enterprises, government agencies and service providers to effectively connect security to their business. Tripwire provides the broadest set of foundational security controls including security configuration management, vulnerability management, file integrity monitoring, log and event management. Tripwire solutions deliver unprecedented visibility, business context and security business intelligence allowing extended enterprises to protect sensitive data from breaches, vulnerabilities, and threats. Learn more at www.tripwire.com, get security news, trends and insights at http://www.tripwire.com/state-of-security/ or follow us on Twitter @TripwireInc.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7896
Published: 2015-03-03
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before ...

CVE-2014-9283
Published: 2015-03-03
The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

CVE-2014-9683
Published: 2015-03-03
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.

CVE-2015-0656
Published: 2015-03-03
Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCum81269.

CVE-2015-0890
Published: 2015-03-03
The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.