Monday, August 27, 2018

Jamf Pro now integrated with Cisco Security Connector

Cisco Security Connector 1.2.0 Released

Cisco Security Connector is now integrated with Jamf Pro (formerly known as the Casper Suite). Designed to automate device management for the administrative team, while driving end-user productivity and creativity, Jamf Pro is a leading Enterprise Mobility Management (EMM) tool focused on delivering on the promise of unified endpoint management for Apple devices.

Jamf is committed to enabling IT to empower end users and bring the legendary Apple experience to businesses, education and government organizations via its Jamf Pro and Jamf Now products, and the 60,000+ member Jamf Nation. Today, over 15,000 global customers rely on Jamf to manage more than 10 million Apple devices.

Features of Jamf Pro include:

  • App Management
  • Deployment
  • Device Management
  • Inventory
  • Security, including integration with Cisco Security Connector and Cisco Identity Services Engine
  • Self Service apps / updating

Integration with Cisco Security Connector is supported for both Jamf Pro Cloud and On-premises. The configuration and deployment guide can be found here.

Requirements:

  • Jamf Pro 10.2.0 or later
  • Supervised devices with iOS 11.3 or later
  • Cisco Security Connector 1.2.0 recommended

Figure 1 – Downloading Jamf Configuration from AMP ConsoleFigure 2 – Downloading the Jamf Configuration from Umbrella Dashboard

Cisco Security Connector 1.2.0

New in Cisco Security Connector 1.2.0 is the ability to turn on malicious detection notification on the iOS device. Clarity will display an alert on the device when a malicious network connection is detected or blocked, if this is turned on via Connector policy.



from Cisco Blog » Security https://ift.tt/2wnkTLM

How to get VPN protection for your laptop while using a smartphone Wi-Fi hotspot

IBM Security Bulletin: Multiple vulnerabilities in Node.js affect IBM Rational Application Developer for WebSphere Software (CVE-2018-1000168, CVE-2018-7161)

Multiple Node.js vulnerabilities were disclosed by the Node.js project. Node.js is used by the Cordova tools in IBM Rational Application Developer for WebSphere Software. IBM Rational Application Developer for WebSphere Software has addressed the applicable CVEs.

CVE(s): CVE-2018-1000168, CVE-2018-7161

Affected product(s) and affected version(s):

Rational Application Developer 9.6.1.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10728705
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141584
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144736

The post IBM Security Bulletin: Multiple vulnerabilities in Node.js affect IBM Rational Application Developer for WebSphere Software (CVE-2018-1000168, CVE-2018-7161) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2PHZQMQ

IBM Security Bulletin: Arbitrary File Reads (CVE-2018-1705) affects IBM Platform Symphony, IBM Spectrum Symphony

Arbitrary File Reads (CVE-2018-1705) affects IBM Platform Symphony, IBM Spectrum Symphony

CVE(s): CVE-2018-1705

Affected product(s) and affected version(s):

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1

IBM Spectrum Symphony 7.1.2 and 7.2.0.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10719665
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146340

The post IBM Security Bulletin: Arbitrary File Reads (CVE-2018-1705) affects IBM Platform Symphony, IBM Spectrum Symphony appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2NnMcwX

IBM Security Bulletin: Vulnerability in Apache Tomcat affects IBM Platform Symphony

This interim fix provides instructions on upgrading Apache Tomcat from v5.5.36 to v7.0.90 in IBM Platform Symphony 6.1.1 and from v6.0.43 to v8.5.32 in IBM Platform Symphony 7.1 Fix Pack 1 in order to address security vulnerability CVE-2018-8014 in Tomcat.

CVE(s): CVE-2018-8014

Affected product(s) and affected version(s):

Platform Symphony 6.1.1
Platform Symphony 7.1 Fix Pack 1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10718917
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/143411

The post IBM Security Bulletin: Vulnerability in Apache Tomcat affects IBM Platform Symphony appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2LtDYkY

California’s CCPA Brings EU Data Privacy to the US

By Rich Campagna, Chief Marketing Officer, Bitglass

California state flagOver the summer a new data privacy law, the California Consumer Privacy Act of 2018 (CCPA), was passed. Assembly Bill 375 is scheduled to go into effect on Jan 1, 2020, which means there will likely be a lot of change before we see the final, enforced version of the bill.

The net for now?

The US’s most stringent data privacy law, CCPA, looks a lot like GDPR, and will likely have impact far beyond the State of California. It also means that companies in all industries are now what we used to refer to as “regulated.” That means more focus on data protection tools like data leakage prevention, cloud access security brokers (CASB), encryption, and more.

CCPA: The US’s most stringent data privacy law

According to the Bill, the following will be covered by the CCPA:

  • Grants consumers the right to request a business to disclose the categories and specific pieces of personal information that it collects about the consumer, the categories of sources from which that information is collected, the business purposes for collecting or selling the information, and the categories of third parties with which the information is shared.
  • Requires businesses to make disclosures about the information and the purposes for which it is used.
  • Grants consumers the right to request deletion of personal information and would require the business to delete upon receipt of a verified request, as specified.
  • Grants consumers the right to request that a business that sells the consumer’s personal information, or discloses it for a business purpose, disclose the categories of information that it collects and categories of information and the identity of 3rd parties to which the information was sold or disclosed.
  • Requires businesses to provide this information in response to a verifiable consumer request.
  • Authorizes consumers to opt out of the sale of personal information by a business and would prohibit the business from discriminating against the consumer for exercising this right, including by charging the consumer who opts out a different price or providing the consumer a different quality of goods or services, except if the difference is reasonably related to value provided by the consumer’s data.
  • Authorize businesses to offer financial incentives for collection of personal information.
  • Prohibits businesses from selling the personal information of a consumer under 16 years of age, unless affirmatively authorized, as specified, to be referred to as the right to “opt in.”

The first half of the list reads very similar to similar provisions in the EU GDPR. The second half includes some interesting new twists.

GDPR … with a twist

The prohibition on discriminating against consumers that exercise their right to privacy, unless “the difference is reasonably related to value provided by the consumer’s data,” is a departure from GDPR regulations. That said, this clause seems far too vague to make it through to 2020 in its current form and will likely be heavily debated by lawmakers and lobbyists alike over the next 18 months.

Additionally, the authorization to offer financial incentives for collection of personal information is quite interesting as well, and it will be interesting to see how businesses make use of this. How does, “free 2-day shipping if we can sell your personal data to a third party” sound?

The cost of non-compliance? “Not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is greater.” To put that into context, last year’s Equifax breach of 340 million records would have amounted in a fine somewhere between $34 billion and $255 billion. Yikes!

All told, the scope of CCPA’s protections look very similar to EU GDPR. For organizations that have applied GDPR globally, that’ll make the path to CCPA compliance much easier. And keep in mind that, like the GDPR, CCPA applies to any business handling California resident data, so even if you don’t have a physical presence in California, doing business in CA is enough to make you subject to the law.

Now what other states (and countries) do with their own privacy laws is a totally different story. It’s wishful thinking to think that others will follow California and the EU without changes of their own. The result will be either amazingly complicated enforcement, or the restriction of services in markets that aren’t nearly as large as California and the EU. If Congress were to step up and enact a national data privacy law it could go a long way towards simplifying this grim future picture. Bueller?



from Cloud Security Alliance Blog https://ift.tt/2PIkEnA

How hackers managed to steal $13.5 million in Cosmos bank heist