As DevOps teams continue to ‘shift security left’ and build container security into the pipeline, integrated toolchains for managing security risk early in the software development lifecycle (SDLC) are becoming critical. The Sonatype Nexus Lifecycle integration with NeuVector enables developers and DevOps teams to manage software vulnerabilities throughout the entire SDLC and even into the production environment. The security risks …
Use Cloud-Native Tools OPA and CRD to Protect Applications from Pipeline to Production
By Gary Duan Application owners and IT administrators have been looking for tools that can help them secure their application pipeline, from the development stage to deployment and production. How to do this reliably and efficiently without slowing down development processes remains a big challenge. This is where Open Policy Agent (OPA) and Kubernetes Custom Resource Definitions (CRD) can help. …
NeuVector Releases New Vulnerability Management Tools That Strengthen and Automate End-to-End Container Security
Now part of the NeuVector platform, enterprise DevOps and security teams get the Vulnerability and Compliance Explorer, a high-performance scanner, and enhanced host protection San Jose, CA – April 14, 2020 – NeuVector, the leader in Full Lifecyle Container Security, today announced the NeuVector platform includes new features – purpose-built for enterprise DevOps and security teams – focused on …
End-to-End Vulnerability Management for Images, Containers and Kubernetes
NeuVector 3.2 Release Adds a Vulnerability & Compliance ‘Explorer,’ High Performance Scanner, and Host Process Protection The ‘Shift-Left’ movement to build security into the CI/CD pipeline continues to grow. Vulnerability management is a critical component of this, and organizations must ‘Shift-Left, then Shift-Right‘ in order to fully protect critical assets and sensitive data throughout the entire container lifecycle. NeuVector …
How to Mitigate the SACK Panic DDoS Attack
By Gary Duan On June 17, 2019, security researchers at Netflix released a series of vulnerabilities they discovered in the Linux and FreeBSD kernel. By sending crafted SACK packets to the vulnerable server, attackers are able to slow down the server’s TCP stack, incur excessive resource usage, and in the worst case scenario, cause a kernel panic. The main vulnerability, …