We just wrapped up a big week at VMworld Europe, where among daily activities we were featured as part of VMware CEO Pat Gelsinger’s main stage keynote address, announcing the latest milestone in our integration with VMware.
Read Samantha Madrid’s discussion of our new Palo Alto Networks VM-Series release here. And have a look at scenes from the VMworld Europe exhibit hall and throughout the conference below and in this gallery on our Facebook page.
Palo Alto Networks announced this week that we have extended our enterprise security platform to bring next-generation security right to the public cloud – all while preserving speed and efficiency. Find out more.
Sebastian Goodwin with Palo Alto Networks is at Black Hat Europe in Amsterdam and wanted to share his experience at a great hands-on workshop at the conference, “PDF Attack: A Journey From the Exploit Kit to the Shellcode,” hosted by Jose Miguel Esparza.
This week three Google researchers revealed details around the latest attack on SSLv3, code named POODLE. The POODLE (Padding Oracle On Downgraded Legacy Encryption) attack allows an attacker who is already in the network path between the client and server to decrypt portions of the SSL session, including HTTP cookie data used for authentication. Unit 42 further examines this attack.
Brian Tokuyoshi highlights security risks of devices connected to the Internet of Things (IoT) and how to secure them against unauthorized network access.
Join us on next Wednesday, October 22 for a webinar hosted by David Guretz, a Palo Alto Networks engineer and IT security expert to learn more about the hot topic of network segmentation in financial services. Register.
Pamela Warren attended and spoke at AFCEA TechNet Europe last week in Paris. She participated in a panel delving into Modern Cyber Defence and whether it requires “built-in security.” Find out her key takeaways from the event.
Last week we brought our top partners from Europe, the Middle East and Africa to Barcelona for our 6th Annual NextWave Partner Conference. Watch this video to hear from our executives and partners about what propelled growth behind our Enterprise Security Platform in 2014 — and what will keep EMEA on an upswing throughout the next 12 months.
We invite you to view a webcast featuring ISA99 Managing Director Joe Weiss and Palo Alto Networks SCADA Product Marketing Manager Del Rodillas, who will discuss cybersecurity for SCADA and ICS with an Oil & Gas SCADA security practitioner and explain real world use cases and cyber incidents.
Here are upcoming events around the world that you should know about:
1999 was a pretty interesting year for the Internet and security. To jog your memory, here are just a few of the major events from the ultimate (or penultimate, depending on your point of view) year of the last millennium.
The Melissa Virus was infecting millions of hosts using malicious e-mails.
Both Napster and MySpace made their first public appearances.
Internet Explorer 5.0 was released for Windows 3.1, 95 and 98.
The TLSv1 specification was published to replace SSLv3 to improve security of Internet communications.
In the 15 years since TLS was introduced it has been widely adopted, but in many ways SSLv3 has hung on. The two specifications are very similar, but not interoperable and applications that implement TLS are often capable of falling back to SSL to support legacy servers. Cryptologists have slowly chipped away at the security of SSL over the last decade, discovering ways to reveal larger and larger pieces of information from encrypted sessions.
This week three Google researchers announced the latest attack on SSLv3 (named POODLE), which may prove to be the deathblow for this protocol. The POODLE (Padding Oracle On Downgraded Legacy Encryption) attack allows an attacker who is already in the network path between the client and server to decrypt portions of the SSL session, including HTTP cookie data used for authentication.
As all modern browsers and most servers support TLS, this attack should only apply to a small number of connections, but that is not the case. When most browsers fail to connect using TLS, they assume the server must be expecting SSL and downgrade their connections to the vulnerable protocol. This means that even two TLS-capable systems can be forced into using SSLv3 by an attacker who controls the network path. That attacker can then decrypt parts of the encrypted channel without the server or client’s knowledge.
The only permanent fix for POODLE is disabling the SSLv3 protocol completely. This can be done either from the server side or the client side depending on the applications. To address this issue, our IPS team issued an emergency update this morning, which contains a signature that alerts on any SSLv3 connection.
Hits on this signature do not indicate an attack is underway, but any SSLv3 session should be considered vulnerable to POODLE and potentially compromised.
Palo Alto Networks recently won Mobile Security Solution of the Year at the 2014 Computing Security Awards in London, honoring GlobalProtect.
Many thanks to everyone who voted. Check out photos from this year’s gala here — including our own Alex Raistrick and Steve Gerrard accepting the award!
Palo Alto Networks WildFire was also runner up for Anti Malware Solution of the Year.
Learn more
For more on GlobalProtect, check out our resources page here.
Santa Clara, Calif., October 14, 2014 – Palo Alto Networks® (NYSE: PANW), the leader in enterprise security, today extended its leadership in security services for private, hybrid and public cloud with the latest release of its virtual firewall series (VM-Series).Enterprises are keen to take advantage of the agility, scalability and cost benefits of cloud-based virtual data centers (VDCs) by building their own private cloud, purchasing public cloud services from providers, or adopting a hybrid cloud approach. Most enterprises are ultimately aiming for the portability of both the application and security policies, regardless of where the application is deployed.However, when it comes to security, most public cloud environments are based on inconsistent network architectures common in traditional data centers and still rely on legacy security technologies – such as stateful inspection and port-based firewalls – that aren’t capable of securing public cloud or hosted VDCs against sophisticated cyber threats.The latest Palo Alto Networks VM-Series release gives organizations the ability to realize the full agility and flexibility promises of cloud; to detect and prevent known and unknown cyber threats before they compromise their VDCs; and to choose the public, private or hybrid deployment architecture without compromising security.Palo Alto Networks also is working with VMware to extend the companies’ unique, integrated security and network virtualization capabilities to hybrid cloud environments, enabling customers to apply the same rich security policies across their private and public infrastructure with a consistent approach to security whether the application is virtual, physical, on-premise or off-premise. Today, Palo Alto Networks and VMware are delivering a solution that includes the Palo Alto Networks VM-1000-HV designed specifically for VMware NSX™ interoperability. Customers also can deploy the Palo Alto Networks VM-series with their instances of VMware vCloud® Air™, an enterprise-grade public cloud service.In 2015, Palo Alto Networks and VMware expect to deliver new multi-tenant next-generation firewall as-a-service capabilities in VMware vCloud Air based on the Palo Alto Networks VM-1000-HV integration with VMware NSX.
QUOTES
“VMware and Palo Alto Networks are delivering on the vision of hybrid cloud, which is to design applications once, secure once, and deploy anywhere without compromise. Through our partnership, we are combining best-in-class security with the software-defined data center architecture to meet customers’ business requirements for improved security and advanced threat protection.”
— Scott Collison, Vice President, Common Platforms, vCloud Air, VMware
“The latest release of our VM-Series was specifically designed with the cloud in mind. It provides consistent automated protection for cloud computing environments so organizations can take advantage of the productivity and cost benefits provided by the cloud without compromising security. It delivers the freedom to deploy new applications and virtual machines and remain confident their VDCs are protected by next-generation firewall and threat prevention technology.”
— Lee Klarich, senior vice president of Product Management, Palo Alto Networks
The new release of the Palo Alto Networks VM-Series also gives organizations the flexibility to maintain next-generation security across a number of cloud service providers with support for cloud infrastructure providers like Amazon Web Services (AWS), and support for Kernel-based Virtual machine (KVM), a popular open source hypervisor used in public cloud computing environments.
Availability
The latest release of the Palo Alto Networks VM-Series is expected to be available by the end of October including support for AWS and KVM. Palo Alto Networks customers with active maintenance agreements can obtain the software by accessing the support portal. The Palo Alto Networks VM-1000-HV is expected to be available in vCloud Air in the first half of calendar year 2015.
For more information about the Palo Alto Networks VM-Series, please visit:
Palo Alto Networks is leading a new era in cybersecurity by protecting thousands of enterprise, government, and service provider networks from cyber threats. Unlike fragmented legacy products, our security platform safely enables business operations and delivers protection based on what matters most in today’s dynamic computing environments: applications, users, and content. Find out more atwww.paloaltonetworks.com.
Palo Alto Networks and the Palo Alto Networks Logo are trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. VMware, VMware NSX and VMware vCloud Air are registered trademarks or trademarks of VMware, Inc. in the United States and other jurisdictions. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners. The use of the word “partner” or “partnership” does not imply a legal partnership relationship between VMware and any other company.
Media Contacts:
Jennifer Jasper Smith
Head of Corporate Communications
Palo Alto Networks
408-638-3280 jjsmith@paloaltonetworks.com