Aggregator
CVE-2024-8321 | Ivanti Endpoint Manager 2024/up to 2022 SU5 missing authentication
CVE-2024-8320 | Ivanti Endpoint Manager 2024/up to 2022 SU5 missing authentication
CVE-2024-8190 | Ivanti CSA up to 4.6 Patch 518 os command injection
How AI and zero trust are transforming resilience strategies
In this Help Net Security interview, John Hernandez, President and General Manager at Quest Software, shares practical advice for enhancing cybersecurity resilience against advanced threats. He underscores the need to focus on on-premises and cloud environments, adapt to new regulations, and address supply chain vulnerabilities. Hernandez also discusses how AI and zero-trust architecture are becoming key elements in future cybersecurity strategies. What practical steps can organizations take to improve their cybersecurity resilience in response to … More →
The post How AI and zero trust are transforming resilience strategies appeared first on Help Net Security.
Commerce Unveils 'Scale' Tool to Tackle Supply Chain Risks
Commerce Secretary Gina Raimondo unveiled a new data tool Tuesday called Scale. It assesses a wide range of factors affecting supply chains to provide a detailed analysis of potential risks and challenges, from labor shortages to climate challenges and geopolitical tensions.
UK ICO and NCA to Collaborate on Cyber Incident Preparedness
The British data protection authority and national law enforcement agency signed onto a cyber risk information-swapping agreement. The National Crime Agency and the Information Commissioner's Office will share cyberthreat assessments and information about incidents.
RAM Signals Expose Air-Gapped Networks to Attacks
A novel side-channel attack exploits radio signals emitted by random access memory in air-gapped computers, presenting a new threat to highly secure networks. One of the most effective ways to mitigate the risk is to cover sensitive machines with Faraday shielding.
Polish Government Disrupts Russian and Belarusian Hacks
The Polish government said Monday it faces an onslaught of cyberattacks from Russian and Belarusian security agencies intent on cyberespionage and blackmail. Poland is in the midst of a "de facto cyberwar," said Deputy Prime Minister Krzysztof Gawkowski.
Defending the Cloud: Essential Strategies for Cyber Resilience
Commerce Unveils 'Scale' Tool to Tackle Supply Chain Risks
Commerce Secretary Gina Raimondo unveiled a new data tool Tuesday called Scale. It assesses a wide range of factors affecting supply chains to provide a detailed analysis of potential risks and challenges, from labor shortages to climate challenges and geopolitical tensions.
UK ICO and NCA to Collaborate on Cyber Incident Preparedness
The British data protection authority and national law enforcement agency signed onto a cyber risk information-swapping agreement. The National Crime Agency and the Information Commissioner's Office will share cyberthreat assessments and information about incidents.
RAM Signals Expose Air-Gapped Networks to Attacks
A novel side-channel attack exploits radio signals emitted by random access memory in air-gapped computers, presenting a new threat to highly secure networks. One of the most effective ways to mitigate the risk is to cover sensitive machines with Faraday shielding.
Polish Government Disrupts Russian and Belarusian Hacks
The Polish government said Monday it faces an onslaught of cyberattacks from Russian and Belarusian security agencies intent on cyberespionage and blackmail. Poland is in the midst of a "de facto cyberwar," said Deputy Prime Minister Krzysztof Gawkowski.
丈八网安获5000万元B轮融资 加速网络仿真技术创新及应用实践
2024年9月11日,北京丈八网络安全科技有限公司(以下简称“丈八网安”)宣布正式完成人民币5000万元的B轮融资。本轮融资由广州白云金融控股集团有限公司(简称白云金控)和泓沣北京私募基金管理有限公司(简称泓沣资本)共同投资。白云金控作为本轮新增的直接投资股东,高度认可丈八网安过往发展取得的骄人成绩,并继续看好公司广阔的发展前景。泓沣资本作为公司首轮融资的独家投资人持续加码,不但用实际行动体现老股东对公司的支持和鼓励,更极大地提振了市场对丈八网安业务和技术创新的信心。此次融资所得资金,丈八网安将继续用于加强技术人才的吸纳和网络仿真技术的研发,旨在进一步拓宽产品方向、丰富应用场景,有效推动网络仿真的普适化发展进程。
丈八网安成立于2021年,专注尖端网络仿真技术创新及产品研发,基于网络仿真技术推出了一系列创新产品,围绕特种、工控、金融、教育、电力等关基重点领域,在仿真网络攻防训练、竞赛、演习、应急响应预演、测试评估、策略验证、沙盘推演等多种场景中发挥重要作用。
丈八网络靶场平台——国内首个基于“网络仿真操作系统”的解耦式弹性平台
网络靶场是丈八网安推出的首款产品,区别于市面上传统网络靶场,丈八网安选择自主研发纯国产化的、仿真专用底层,开创性的采用了虚拟化技术(VMs & SDN)+数字建模仿真技术(Meta Computing)双栈引擎,来支撑其实现强大的网络仿真功能。
为了确保网络靶场可用、易用、实用,丈八网安对产品的整体架构进行革新,将承载仿真能力的底层进行独立开发,推出国内首个“网络仿真操作系统”(ZBOS),将网络靶场的典型功能场景:授课教学、考试评测、攻防演练、实战演练、测试床、CTF、AWD等以“应用”的形式开发并组合插装在系统上,实现快速部署、即插即用,在自有知识库的海量资源支撑下,形成多元化解决方案的交付。此外,平台内置的“应用中心”同时面向第三方开发者开放,使之成为行业内唯一可以进行网络仿真生态建设的靶场产品,推动了网络仿真技术在更多行业和场景落地应用。
丈八沙盘推演系统——国内唯一网络攻防专用沙盘推演产品
沙盘推演系统是丈八网安依托ZBOS推出的网络攻防专用沙盘推演产品。与网络靶场平台侧重个人开展技能训练和技术研究不同,丈八沙盘推演系统主要面向决策者或高层管理者,通过对大规模连续网络安全事件的模拟仿真,开展网络攻防技术推演、安全架构效能评估。
丈八沙盘推演系统的最大技术亮点在于其充分运用了数字建模仿真技术(Meta Computing),实现了以低资源占用模拟宏大且复杂的网络环境,对网络空间攻防所涉及的全域要素进行了精准建模。此外,该系统还借助AIGC智能体技术辅助和替代决策,实现了“人在环内”与“人在环外”的双模式推演。
目前,凭借产品及技术的创新性与稀缺性,丈八网络靶场平台在仿真能力、产品架构、用户体验等维度上形成了跨越式的领先优势,迅速跻身垂直行业市场的前列;同时,丈八沙盘推演系统有效填补了网络沙盘推演领域存在的巨大市场空白,成为极具发展潜力和想象空间的新业务增长点。凭借以上优势,丈八网安在今年资本市场普遍趋于谨慎的大背景下,仍然能够持续获得资本青睐,充分展现了其卓越的市场竞争力和深厚的投资价值。
投资方白云金控是广州白云区政府成立的区属国有产业金融平台,白云金控董事长湛珊表示:“新一代信息技术属于白云金控重点投资方向,网络安全作为新一代信息技术细分领域,丈八网安在其深耕的专业领域内,凭借卓越的技术实力和产业化落地能力,坚定地守护着国家的网络空间安全。我们看到了该公司所蕴含的高科技价值、巨大的发展潜力以及广阔的市场前景。我们期待丈八网安落地白云区,希望丈八网安能够继续发挥其核心竞争力,不断创新突破,为我国网络安全事业的发展贡献重要力量,为国家构建更加安全、稳定、繁荣的数字未来。”
投资方泓沣资本专注于新兴科技、智能安防、军民融合等行业的深度产业投资和布局,重点关注具有长期增长潜力和核心竞争力的企业。泓沣资本CEO吕俊峰表示:“丈八网安在网络仿真领域展现出的卓越创新与突破能力,每一次产品的更新都体现了团队严谨的逻辑思维和对细节的精益求精。这种对技术的执着追求和对产品的极致打磨,以及超预期的业绩表现,让我们深信丈八网安具备成长为一家伟大企业的潜力。因此,我们愿意与丈八网安携手并进,共同完成使命,共创辉煌未来。”
丈八网安CEO王珩表示:“公司将以此次融资为契机,坚定不移地走技术创新引领发展的国产化道路,在网络建模仿真技术、网络攻防大模型技术、SaaS化产品方向上持续加大研发投入。丈八网安所专注的网络靶场与沙盘推演产品,虽身处网络安全行业的特定细分领域,却是保障国家网络安全、强化安全防御机制、培育网络安全专业人才、推动网络安全技术创新与发展的重要基石。我们目前已经是这一领域的新生代佼佼者,正在以技术为刃,勇破陈规,引领着行业变革。我坚信,在不久的将来,丈八网安必将在更广阔的网络安全市场中占据举足轻重的地位,为国家网络安全事业书写全新篇章。”
据悉,随着公司产品的不断创新迭代,业务的不断发展,团队的快速成长和壮大,本轮融资的顺利完成使公司资本化之路快速迈入新的阶段。