Evento di Lancio: Smart AI Security. Controllo Totale dei Dati. Prenota il tuo posto

chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
          Experience Netskope
          Prova direttamente la piattaforma Netskope
          Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
            Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
            Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
            2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
            Una piattaforma unificata costruita per il tuo percorso
              Securing Generative AI for Dummies
              Securing Generative AI for Dummies
              Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
                eBook sulla Modern Data Loss Prevention (DLP) for Dummies
                Modern Data Loss Prevention (DLP) for Dummies
                Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
                  Modern SD-WAN for SASE Dummies Book
                  Modern SD-WAN for SASE Dummies
                  Smettila di inseguire la tua architettura di rete
                    Comprendere dove risiede il rischio
                    Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
                        Supporto tecnico Netskope
                        Supporto tecnico Netskope
                        I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
                          Video Netskope
                          Formazione Netskope
                          La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

                            Heartbleed Remediation Status for Enterprise Cloud Apps

                            May 01 2014
                            Tags
                            Cloud Best Practices
                            Cloud Security
                            Netskope Announcements
                            Netskope Threat Research Labs
                            Tools and Tips
                            Vulnerability Advisory

                            Researchers discovered a vulnerability (CVE-2014-0160) in OpenSSL, an open source library for secure data transport used by most websites, including the enterprise cloud apps that we use for work. This vulnerability, which enables TLS “heartbeat” data packets to be passed without authentication with the server, allows hackers to steal information located in the memory of each server, which can include passwords and private encryption keys.

                            We at Netskope maintain a database of enterprise cloud apps, including ones that use SSL in order to help organizations manage their cloud app security risk. We have begun a countdown process of apps that are susceptible to this vulnerability and have not yet patched their servers. We started with the more than 4,500 enterprise cloud apps in our database, identified which ones are vulnerable, looked at the IP addresses of their SSL servers, and scanned those servers to determine whether they have been patched. We looked across the publicly-facing domains of each of the enterprise cloud apps and arrived at our count.

                            In an effort to release this information as quickly as possible, we have assumed that patches applied to publicly facing domains for an app have also been applied to non-publicly facing domains or subdomains. This is a good faith assumption we have made and we will update the community via this blog should we find information to the contrary. Note that this process did not result in Netskope collecting any of the data exposed by this vulnerability.

                            Here’s what app vendors can do to remediate their systems, if they haven’t already:

                            • Upgrade to OpenSSL version 1.0.1g or patch their system using a version of OpenSSL configured with -DOPENSSL_NO_HEARTBEATS.
                            • Revoke and reissue all certificates. Ensure new certificates use new keys.
                            • Alert users of the vulnerability and remediation steps.
                            • Have users change their passwords after the above steps have been completed.

                            At Netskope we also underwent the above process and have notified and published a KB article to our customers.

                            Learn more. Netskope Researcher, Ravi Balupari, has recorded a Netskope Movie Line Monday (we made an exception and published it on a Thursday!) about the Heartbleed bug and what it means to you. Watch it here.

                            Enterprise Cloud Apps That Remain Vulnerable to Heartbleed

                            Netskope-Heartbleed-Bug-Update-May-2

                            We will periodically review the list of remaining vulnerable apps, but since we’re doing so less frequently, we will no longer publish the list to this blog. If you’d like a copy of the updated list, please reach out to us at [email protected].

                            We’ll be updating this status as major developments occur. Please check back with us or reach out to us at [email protected] if you have a specific question about Heartbleed or any cloud security topic.

                            ** April 11 update **
                            The list has dropped from 100 to 72. The list has been updated to reflect this new total.

                            ** April 12 update **
                            The list has dropped from 72 to 62. The list has been updated to reflect this new total.

                            ** April 13 update **
                            The list has dropped from 62 to 51. The list has been updated to reflect this new total.

                            ** April 14 update **
                            The list has dropped from 51 to 48. The list has been updated to reflect this new total.

                            ** April 15 update **
                            The list has dropped from 48 to 42. The list has been updated to reflect this new total.

                            ** April 16 update **
                            The list has dropped from 42 to 40. The list has been updated to reflect this new total.

                            ** April 17 update **
                            The list has dropped from 40 to 35. The list has been updated to reflect this new total. Read additional analysis about The Tie Between Cloud App Enterprise-Readiness and Remediation here.

                            Due to slowing of remediation efforts we have changed to a weekly update frequency for this blog. Our next update will come on April 24.

                            ** April 24 update **
                            The list has dropped from 35 to 26 over the course of 1 week. The list has been updated to reflect this new total.

                            **May 2 update**
                            This is our last blog update on the Heartbleed bug. The list of remaining vulnerable apps has dropped from 26 last week to 22.

                            If you have remaining questions, please reach out to us at [email protected].

                            author image
                            Krishna Narayanaswamy
                            A highly regarded and awarded researcher in security, behavioral anomaly detection, and deep packet inspection, Krishna Narayanaswamy brings two decades of technical and thought leadership as founder and chief technology officer at Netskope.
                            A highly regarded and awarded researcher in security, behavioral anomaly detection, and deep packet inspection, Krishna Narayanaswamy brings two decades of technical and thought leadership as founder and chief technology officer at Netskope.
                            Connettiti con Netskope

                            Iscriviti al blog di Netskope

                            Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.