Cloud

11/13/2017
04:00 PM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail

Emerging IT Security Technologies: 13 Categories, 26 Vendors

A rundown of some of the hottest security product areas, and vendors helping to shape them.
11 of 14

DevSecOps

Tools for integrating security controls and processes into the DevOps pipeline. 
Vendor: ShiftLeft

Fully automated security-as-a-service for detecting and mitigating security vulnerabilities in cloud apps and microservices during build-time and runtime.
	
Factors to Watch

- Offered on a Try-and-Buy basis
- Combines code intelligence from build-time and runtime
- Exited stealth mode in Sept. 2017 with $9.3 million in Series A funding



Key Executives: Founder and CEO Manish Gupta was formerly the chief product and strategy officer for FireEye.

Founded: 2016

Vendor: Threat Stack

Enabling security and operations to work together with tools for automating critical manual processes.
	
Factors to Watch

- Single platform for monitoring cloud, hybrid cloud, and containerized environment
- Integrates into existing workflows
- Raised $45 million in Series C funding September 2017 bring total raised to $70 million



Key Executives: Brian Ahern took over as Chairman and CEO in May 2015. He is the founder of Industrial Defender Inc., a company that Lockheed Martin acquired in 2014.

Founded: 2012

Image Source: REDPIXEL.PL via Shutterstock

DevSecOps

Tools for integrating security controls and processes into the DevOps pipeline.

Vendor: ShiftLeft

Fully automated security-as-a-service for detecting and mitigating security vulnerabilities in cloud apps and microservices during build-time and runtime.

Factors to Watch

  • Offered on a Try-and-Buy basis
  • Combines code intelligence from build-time and runtime
  • Exited stealth mode in Sept. 2017 with $9.3 million in Series A funding

Key Executives: Founder and CEO Manish Gupta was formerly the chief product and strategy officer for FireEye.

Founded: 2016

Vendor: Threat Stack

Enabling security and operations to work together with tools for automating critical manual processes.

Factors to Watch

  • Single platform for monitoring cloud, hybrid cloud, and containerized environment
  • Integrates into existing workflows
  • Raised $45 million in Series C funding September 2017 bring total raised to $70 million

Key Executives: Brian Ahern took over as Chairman and CEO in May 2015. He is the founder of Industrial Defender Inc., a company that Lockheed Martin acquired in 2014.

Founded: 2012

Image Source: REDPIXEL.PL via Shutterstock

11 of 14
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
MarkS94105
100%
0%
MarkS94105,
User Rank: Apprentice
12/8/2017 | 2:28:08 PM
Story -> Potentially Valuable; Site -> Problematic Viewing and Printing
This topic and story is presented as a white paper.  To read the story, we must click the next arrow 13 times to see all 14 pages.  This is time consuming as the site loads so many advertisements.  There is no simple way to print the story, as the print function show only 1 of 14, 2 of 14, etc.  This may be by design, but I find it a serious barrier and will seek other sources for this material.  
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19790
PUBLISHED: 2018-12-18
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restricti...
CVE-2018-19829
PUBLISHED: 2018-12-18
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.
CVE-2018-16884
PUBLISHED: 2018-12-18
A flaw was found in the Linux kernel in the NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel id and cause a use-after-free. Thus a malicious container user can cause a host kernel memory corruption and a system ...
CVE-2018-17777
PUBLISHED: 2018-12-18
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. The attacker will have acc...
CVE-2018-18921
PUBLISHED: 2018-12-18
PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.