Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Palo Alto Networks to Buy CloudGenix for $420M
Oldest First  |  Newest First  |  Threaded View
tdsan
tdsan,
User Rank: Ninja
4/23/2020 | 9:59:36 AM
Goodbye to CloudGenics and hello to PaloAlto's Network Automation Platform
I do think this is the way to go, PaloAlto has created a network they intend to utilize  which offers services ranging from network creation, management, and network control. They are looking to control the highway to create a clean environment the same way Google is.

I have been a proponent of PaloAlto Networks since their inception using AppID and controlling the application, I think this goes right inline with the ability to create networks (as long as the network is consistent - good data in, good data out, this is where CloudGenix comes into play, they use YAML files to create automated SDNs and Physical networks).

I do think with PaloAlto's R&D team, they could improve this CloudGenix process because it looks like it is not polished, more from a DevOps perspective. I did see from the video (CloudGenix, the admin where the admin had to make changes and create variables in the YAML file "type: {switch}"; the application should have done this,  hopefully they can move this process to the next level.

SD-WAN: Secure, High-Performance, Simple | PaloGuard.com

It is an interesting time.

Todd


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Creating an Effective Incident Response Plan
Security teams are realizing their organizations will experience a cyber incident at some point. An effective incident response plan that takes into account their specific requirements and has been tested is critical. This issue of Tech Insights also includes: -a look at the newly signed cyber-incident law, -how organizations can apply behavioral psychology to incident response, -and an overview of the Open Cybersecurity Schema Framework.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-24999
PUBLISHED: 2022-11-26
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query strin...
CVE-2022-45909
PUBLISHED: 2022-11-26
drachtio-server 0.8.18 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
CVE-2022-45907
PUBLISHED: 2022-11-26
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-45908
PUBLISHED: 2022-11-26
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
CVE-2022-44843
PUBLISHED: 2022-11-25
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.