Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


04:01 PM
Dark Reading
Dark Reading
Products and Releases

CORE Security Announces CORE Insight Enterprise 2.0

With version 2.0, CORE Insight now offers a comprehensive set of vulnerability management capabilities

Infosecurity Europe, London, U.K. – April 24, 2012 – CORE Security®, a leading provider of predictive security intelligence solutions, today announced a major enhancement to CORE Insight™ Enterprise that provides IT security professionals and leaders with the ability to identify critical exposures to their infrastructure and – for the first time – link them to the actual risk to the business. A real-time security intelligence platform, CORE Insight provides unified threat validation and prioritization while feeding key analytics to the security ecosystem. Additionally, CORE Insight enables organizations to improve IT security, optimize budgets, increase efficiency of security operations, and predict threats without disrupting operations.

“Security experts are constantly looking for ways to streamline and automate as many processes as possible to stay on top of a difficult threat landscape. Right now there is too much disparate data for these security experts to process and analyze”, said Charles Kolodgy, research vice president, Secure Products, IDC. “By offering scanning, simulation, reporting and vulnerability remediation in Insight 2.0, CORE Security has taken a major step in delivering a single platform that provides actionable intelligence. As important, the solution allows for the communication of security risk in a language the business understands.”

With version 2.0, CORE Insight now offers a comprehensive set of vulnerability management capabilities – including integrated network and web application vulnerability scanning; attack planning and simulation; threat replication; dashboards and reporting; and vulnerability remediation – on a single platform. CORE Insight 2.0 offers customers access to bundled network and web vulnerability scanners, including nCircle and NT OBJECTives (NTO), in addition to the ability to import and interact with data from other leading scanning solutions. Users now have the capability to schedule and manage scans directly from within CORE Insight.

Leveraging imported scan data, CORE Insight combines patented artificial intelligence developed by CORE Labs with proactive security assessment capabilities to:

· Reveal attack paths that leverage vulnerabilities identified by network and web application scans

· Simulate and/or replicate attacks targeting the vulnerabilities across network, web and endpoint vectors

· Proactively identify critical threats in need of remediation

· Deliver security data in business context, enabling clearer risk understanding and prioritization

· Provide remediation information and track the efficacy of remediation efforts

New enhancements that address customer challenges, streamline vulnerability management processes, reduce associated costs, and improve overall security

· Integrated network and web vulnerability scanning

o Challenge addressed: Disparate, underutilized and disconnected vulnerability management tools

o Benefit delivered: Time savings and reduced costs via vulnerability consolidation and validation through a single vulnerability management interface

· Streamlined workflow for vulnerability management processes

o Challenge addressed: Time- and resource-intensive vulnerability management data correlation and validation

o Benefit delivered: Actionable data to inform better decision making for increased efficiency and effectiveness – and the ability to customize security intelligence efforts to including scanning, simulation, testing, remediation, tracking and reporting

· Multi-vector threat analysis

o Challenge addressed: Significant time wasted in manually consolidating, analyzing and interpreting siloed, vector-specific vulnerability data

o Benefit delivered: Deep understanding of an organization’s total risk profile based on how criminals would exploit and traverse paths of vulnerabilities across web applications, network systems and client-side infrastructure

· Grouping of users, targets and campaigns

o Challenge addressed: Inaccurate or non-existent reporting of security metrics to business leaders resulting from lengthy gaps between vulnerability identification and threat remediation

o Benefit delivered: A standardized platform for communication with other business units; more efficient security resource delegation and decision making; and the ability to efficiently assess risks to critical business assets

· Enhanced simulation capabilities

o Challenge addressed: Environments that do not permit exploit-based security testing to validate vulnerabilities and trace attack paths

o Benefit delivered: The ability to model attack paths and determine business risk without affecting production systems

In addition, CORE Insight has been enhanced with a new graphical user interface (GUI) to improve the user experience and allow for more concise views.

“The bottom line for the head of IT security in any organization is to be able to effectively communicate overall security risk to senior management based upon specific risks to the business while being able to protect the IT infrastructure and focus proper amounts of time and resources,” said Milan Shah, senior vice president of products and engineering at CORE Security. “We are answering their call by providing an advanced, unified vulnerability management platform to streamline, automate, and intelligently predict and subsequently prevent outside attackers from connecting vulnerabilities across multiple threat vectors to breach critical assets.”

About CORE Insight Enterprise

CORE Insight Enterprise is the first security intelligence solution that enables organizations to continuously and proactively assess their business risks. CORE Insight empowers executives to make informed choices for improving security, optimizing budgets, and increasing operational efficiency. The Insight solution integrates seamlessly with existing IT environments, pinpointing imminent risks without disrupting business processes. By combining advanced simulation with real-world testing, CORE Insight provides actionable information otherwise overlooked amidst volumes of security data. Customers gain unprecedented intelligence regarding their organization’s real-time security posture, while connecting real risks to specific operational and business goals.

About CORE Security

CORE Security is the leading provider of predictive security intelligence solutions for enterprises and government organizations. We help more than 1,400 customers worldwide preempt critical security threats throughout their IT environments, and communicate the risk the threats pose to the business. Our patented, proven, award-winning enterprise solutions are backed by more than 15 years of applied expertise from CORE Labs, the company’s innovative security research center. For more information, visit www.coresecurity.com.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-01-28
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
PUBLISHED: 2021-01-28
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker co...
PUBLISHED: 2021-01-28
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can...
PUBLISHED: 2021-01-28
Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
PUBLISHED: 2021-01-28
Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.