share_log

Seal Security Is Now a CVE Numbering Authority (CNA)

Seal Security Is Now a CVE Numbering Authority (CNA)

Seal Security現在是CVE編號機構(CNA)
PR Newswire ·  09/10 16:15

TEL AVIV, Israel, Sept. 10, 2024 /PRNewswire/ -- Seal Security, a leading provider of open source vulnerability and patch management solutions, has been authorized by the Common Vulnerabilities and Exposures (CVE) Program as a CVE Numbering Authority (CNA).

以色列特拉維夫,2024年9月10日/PRNewswire/--領先的開源漏洞和補丁管理解決方案提供商Seal Security已獲授權成爲Common Vulnerabilities and Exposures(CVE)計劃的CVE編號管理機構(CNA)。

As a CNA, Seal Security will collaborate closely with open source communities to enhance security awareness by responsibly vetting, documenting, and disclosing vulnerabilities through the creation and assignment of CVE Records. These records are then published to the CVE List, a centralized database that serves as a critical resource for cybersecurity professionals worldwide.

作爲CNA,Seal Security將與開源社區密切合作,通過負責任的審查、記錄和披露漏洞,以創建並指派CVE記錄,提升安全意識。這些記錄隨後會發布到CVE列表,作爲全球網絡安全專業人士的重要資源。

By leveraging CVE Records, security teams can quickly identify, assess, and mitigate potential threats, thereby strengthening their organizations' overall security posture against emerging cyber risks.

通過利用CVE記錄,安全團隊可以快速識別、評估和消除潛在威脅,從而加強組織對新興網絡風險的整體安全態勢。

"Becoming an authorized CVE Numbering Authority reinforces Seal Security's commitment to helping organizations maintain robust security," said Itamar Sher, CEO of Seal Security. "Beyond publishing CVE Records to provide consistent descriptions of vulnerabilities, we aim to help organizations secure these open source vulnerabilities, positively impact the open source security community, and ultimately keep our customers safe, secure, and productive."

Seal Security的首席執行官Itamar Sher表示:「成爲授權的CVE編號管理機構,強化了Seal Security幫助組織維護強大安全性的承諾。」他說:「除了發佈CVE記錄以提供漏洞的一致描述外,我們的目標是幫助組織保護這些開源漏洞,積極影響開源安全社區,從而保護我們的客戶的安全和效率。」

In addition to creating and assigning CVE Records, Seal Security proactively leverages the CVE List to identify and remediate open source vulnerabilities. By providing standalone security patches, we ensure seamless and predictable fixes for vulnerabilities in both application code and images.

除了創建和指派CVE記錄,Seal Security還積極利用CVE列表來識別和修復開源漏洞。通過提供獨立的安全補丁,我們確保在應用程序代碼和映像中修復漏洞時,修復工作順利可預測。

Currently, Seal Security's repository offers over 300 cryptographically signed, sealed packages with 2,500+ unique patches across seven programming languages: Python, Go, C# (.Net), JavaScript, Java, C, and C++. The solution also supports patching base container and virtual machine images based on RHEL, CentOS, and Fedora.

目前,Seal Security的軟件庫提供超過300個使用七種編程語言(Python,Go,C#(.Net),JavaScript,Java,C,C++)的加密簽名、密封包和2500多個獨特的補丁。該解決方案還支持修復基於RHEL、CentOS和Fedora的基礎容器和虛擬機映像。

About the CVE Program
The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program. Partners publish CVE Records to communicate consistent descriptions of vulnerabilities. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.

關於CVE計劃
CVE計劃的使命是識別、定義和編目公開披露的網絡安全漏洞。目錄中每個漏洞都有一個CVE記錄。這些漏洞是由與CVE計劃合作的世界各地的組織發現、指派和發佈的。合作伙伴發佈CVE記錄以傳達漏洞的一致描述。信息技術和網絡安全專業人員使用CVE記錄確保他們對同一個問題進行討論,並協調他們的工作以優先處理和解決漏洞。

About Seal Security
Seal Security is redefining open source vulnerability remediation by providing standalone security patches that ensure seamless and predictable fixes for vulnerabilities in both application code and images. By backporting security fixes and creating fully compatible versions of open source packages, Seal enables security teams to apply patches independently of R&D involvement. This approach decouples security fixes from feature upgrades, centralizes the replacement of all vulnerable package instances across all CI pipelines, and automates and scales the vulnerability remediation processes.

關於Seal Security
Seal Security通過提供獨立的安全補丁來重新定義開源漏洞修復,確保在應用程序代碼和鏡像中對漏洞進行無縫且可預測的修復。通過後向移植安全補丁並創建完全兼容的開源軟件包版本,Seal使安全團隊能夠獨立應用補丁,無需R&D的參與。這種方法將安全修復與功能升級解耦,集中替換所有CI流水線中的所有易受攻擊軟件包實例,並自動化和擴展漏洞修復流程。

Our solution is trusted by several organizations, including Fortune 100 companies and some of the largest software vendors. To learn more visit seal.security

我們的解決方案得到了多家組織的信任,包括財富100強公司和一些最大的軟件供應商。要了解更多信息,請訪問seal.security

Contacts
Judith Wahnon
[email protected]

聯繫方式
朱迪斯·瓦農
[email protected]

SOURCE Seal Security

資源:Seal Security

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論