Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
7 Hot Security Terms (and Buzzwords) to Know
Newest First  |  Oldest First  |  Threaded View
tcritchley07
tcritchley07,
User Rank: Moderator
3/8/2017 | 3:30:56 PM
Re: Cyber Terms
No, just trying to get temrmnology straight in my mind in the context of security. Thanks. 
T Sweeney
T Sweeney,
User Rank: Moderator
3/8/2017 | 1:29:02 PM
Re: Cyber Terms
Correct, @tcritchkley07... I used firewalls as just one example of compartmentalization. But the term could also apply to the bucketize slide or the micro-services slide as well, which both try to create similar boundaries in the name of better security.

Was there a specific application of compartmentalization you were thinking of?
tcritchley07
tcritchley07,
User Rank: Moderator
3/8/2017 | 12:16:25 PM
Cyber Terms
Isn't compartmentalization the same as the more modern 'segmentation' of various entities, not just firewall traffic?
T Sweeney
T Sweeney,
User Rank: Moderator
3/7/2017 | 1:55:44 PM
Re: To Buzzword #7 - Compartmentalization
Thanks, stormrunner2... what Fortinet's doing seems to track closely with this intelligent segmentation trend we're seeing from various vendors and startups.
storrmrunner2
storrmrunner2,
User Rank: Apprentice
3/6/2017 | 7:13:32 PM
To Buzzword #7 - Compartmentalization
Have you looked at companies like Fortinet and ISFW (Internal Segmentation Firewall) solution?  They have been running at 100Gb speeds for a couple of years now.  And announced a 1Tb throughput firewall in Jan-2017 (https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2017/the-worlds-first-terabit-firewall-appliance-ngfw.html).

Does this not solve the usability issue of mantaining LAN speeds with Layer-7 inspection services?


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Promise and Reality of Cloud Security
Cloud security has been part of the cybersecurity conversation for years but has been on the sidelines for most enterprises. The shift to remote work during the COVID-19 pandemic and digital transformation projects have moved cloud infrastructure front-and-center as enterprises address the associated security risks. This report - a compilation of cutting-edge Black Hat research, in-depth Omdia analysis, and comprehensive Dark Reading reporting - explores how cloud security is rapidly evolving.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-24157
PUBLISHED: 2023-02-03
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2023-24151
PUBLISHED: 2023-02-03
A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2023-24152
PUBLISHED: 2023-02-03
A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2023-24153
PUBLISHED: 2023-02-03
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
CVE-2023-24154
PUBLISHED: 2023-02-03
TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.