Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
IBM Launches New Tools for Container Security
Newest First  |  Oldest First  |  Threaded View
RyanSepe
RyanSepe,
User Rank: Ninja
9/14/2017 | 8:44:05 AM
Re: IBM and trust
"...decimating cloud support staff" hard to envision Cloud gaining traction QUICKLY with statements such as these.
REISEN1955
REISEN1955,
User Rank: Ninja
9/13/2017 | 8:25:56 AM
IBM and trust
Good question about the backend ---- and knowing that IBM is decimating cloud support staff and some elements of Watson (health care hit hard), i would not trust any advertisement of good stuff from old Big Blue.  Ginny has wrecked the company and it is a shell of what remains now.  Disclosure - i was with a business partner during the John Akers meltdown years.    So the BETTER question is WHO is supporting what is behind the backend?  
RyanSepe
RyanSepe,
User Rank: Ninja
9/13/2017 | 7:22:13 AM
Container Security
This is interesting but how does hosting the application in "Docker" elevate security? IE: what is occuring on the backend?


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Developing and Testing an Effective Breach Response Plan
Whether or not a data breach is a disaster for the organization depends on the security team's response and that is based on how the team developed a breach response plan beforehand and if it was thoroughly tested. Inside this report, experts share how to: -understand the technical environment, -determine what types of incidents would trigger the plan, -know which stakeholders need to be notified and how to do so, -develop steps to contain the breach, collect evidence, and initiate recovery.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-46826
PUBLISHED: 2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
CVE-2022-46827
PUBLISHED: 2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVE-2022-46828
PUBLISHED: 2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVE-2022-46829
PUBLISHED: 2022-12-08
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
CVE-2022-46830
PUBLISHED: 2022-12-08
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.