Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

1/29/2019
01:00 PM
50%
50%

Symantec Rolls Out New Endpoint Security Tools, Updates

Today's releases include more advanced EDR tools, a new managed EDR service, and protection and hardening for Symantec's endpoint portfolio.

Symantec is ramping up its endpoint defense offerings with myriad updates to its endpoint security portfolio and a new Managed Endpoint Detection and Response (MEDR) service that leverages its new EDR 4.0 to improve on incident response, threat hunting, and forensics.

MEDR is made up of Symantec EDR 4.0, the SOC technology platform, and the Global Intelligence Network. Its capabilities, which include industry- and region-specific analysts across six global SOCs and managed threat hunting, are intended to help decrease the burden on security teams as endpoint threats grow in size, number, and complexity. EDR 4.0 pulls threat research from Symantec's telemetry to detect new attack patterns and zero-day threats.

"With a critical shortage of skilled investigators available, security teams need smart tools and services that can help them deal with the scale and speed of the modern threat environment, making it easier to identify and fix impacted endpoints," said ESG senior principal analyst Jon Oltsik, in a statement on today's releases.

Both Symantec MEDR and EDR 4.0 are now available on any device before or after an attack, for detection and response. Also available today are multiple endpoint security updates to its Integrated Cyber Defense Platform, which address application, cloud, and Active Directory.

Security portfolio updates include endpoint application control, which only allows known and good applications to run; endpoint application isolation, which ensures applications are limited to authorized behavior; endpoint cloud connect defense, which uses a policy-based smart VPN to defend against risky networks; and endpoint threat defense for Active Directory, which helps ensure attackers on domain-connected endpoints can't exploit AD to view critical assets.

Read more details here and here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-20949
PUBLISHED: 2021-01-20
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vul...
CVE-2020-25683
PUBLISHED: 2021-01-20
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a heap-allocated memory. T...
CVE-2020-25684
PUBLISHED: 2021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query,...
CVE-2020-25685
PUBLISHED: 2021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSS...
CVE-2020-35271
PUBLISHED: 2021-01-20
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.