Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

10/2/2018
04:45 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Mimecast Announces Web Security

75% Of Organizations Lack Complete Confidence That Their Security Defenses Will Stop Targeted Spear-Phishing With Malicious Web Links

IP Expo, London – Mimecast Limited today announced the general availability its new web security service. The cloud-based service is designed to guard against malicious activity initiated by user action or malware while blocking access to websites deemed unsafe or inappropriate based on each organization’s policies.

Mimecast Web Security is engineered to be managed with the same administration console that customers use to manage Mimecast's existing email services. This offers an easy-to-deploy and manage defense against advanced phishing and malware attacks being delivered to employees by both email, web, instant messaging systems, social network sites, and ad networks.

During the early adopter program, customers around the world tested the service which is now immediately available globally.

Jamie Fernandes, director of product management for web security at Mimecast, said: "Commonalities between email and web threat intelligence and detective analytics help improve the security defenses against both vectors whether used by attackers separately or together. The new web security service is designed to allow customers to broaden and improve their protection from attacks occurring via email and the web, using a single integrated service. We're excited about our ability to significantly expand our customers’ defense systems by extending the power of our Mime|OS threat detection technologies and the global grid powered by 30,000+ customers we’re protecting around the globe."

Vanson Bourne research* found 32% of organizations were not confident that their employees could spot and defend against malware or ransomware attacks via direct web downloads. Only 25% were completely confident their security defenses would stop targeted spear-phishing with malicious links.

Ascend Learning, a network of K-12 public charter schools serving 4,800 students in 12 schools across Brooklyn, were a member of the customer early adopter program. Emeka Ibekweh, managing director of technology at Ascend, commented: "It’s critical to our primary educational objectives that our staff and students are protected from malicious email attacks and web sites or inappropriate web content."

Scott Crawford, research director of Information Security, 451 Research, commented: "Organizations often struggle to enforce security for two of the most common attack vectors: email and the web. Many security professionals seek to consolidate and use integrated cloud services that make management and operation simpler and more effective. Mimecast's move to expand outside of its core email focus mirrors the growing need for a more integrated defense to combat advanced attacks."

The combined cyber resilience offering is also supported by the Mimecast Security Operations Center (MSOC) team and is enriched with all the global threat intelligence, analytics, and infrastructure that supports Mimecast’s current services.   

Mimecast's CEO, Peter Bauer, added: "We can now protect our customers with a more complete threat detection offering that will work the way organizations do—anytime and anywhere, doing business through the email and web at global scale. Our homegrown research and development into the high-growth web security market is designed to apply our recent acquisitions of Solebit for advanced malware detection and Ataata for a new approach to employee risk scoring, training and awareness. Together, these strategic investments are helping us move toward our vision of providing an integrated super-category of cyber resilience solutions from a global, cloud-based service."

The service is available for a free 30-day trial for existing Mimecast customers.

*Research was conducted in March 2018 by Vanson Bourne on behalf of Mimecast. Respondents were IT decision makers at 800 organizations around the world with more than 250 employees.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
5 Common Errors That Allow Attackers to Go Undetected
Matt Middleton-Leal, General Manager and Chief Security Strategist, Netwrix,  2/12/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20477
PUBLISHED: 2020-02-19
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
CVE-2019-20478
PUBLISHED: 2020-02-19
In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.
CVE-2011-2054
PUBLISHED: 2020-02-19
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper in...
CVE-2015-0749
PUBLISHED: 2020-02-19
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker ...
CVE-2015-9543
PUBLISHED: 2020-02-19
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is rel...