Check Point® Software Technologies Ltd. has been recognized as a Leader in the latest GigaOm Radar Report for Security Policy as Code.
Exiger announced the acquisition of software supply chain risk visibility platform aDolus Technology Inc.
This acquisition enhances Exiger's software supply chain visibility capabilities by integrating aDolus' ability to generate software bills of material (SBOMs) and analyze binary for software provenance. This capability extends Exiger's Ion Channel platform for SBOM analysis to binaries that have no SBOMs, as well as device firmware, operational technology (OT) and IoT.
"While the public and private sector are adopting policies and solutions to address supply chain risks in new software going forward, there's a glaring blind spot when it comes to spotting and rooting out vulnerabilities in operational or legacy technologies," said Exiger President Carrie Wibben. "When you consider that the cost of simply maintaining these legacy systems exceeds $1 trillion, you start to appreciate the scale of the gap in security across our software supply chains. Today, even our largest, most recognizable organizations are trying to bridge this gap in visibility with written vendor questionnaires. But with the acquisition and integration of aDolus, Exiger's customers can independently verify suppliers' attestations about the composition and security of their software."
"Organizations across energy, telecom, manufacturing, defense and other high assurance environments are grappling with these black swan cyber events and regulatory headwinds," said aDolus Founder and CEO Eric Byres. "Working with Exiger over the past year has made clear the enormous need in the market but also the enormous opportunity presented by combining our capabilities to generate SBOMs directly from binary files, uncover hidden third-party risk and expose the full provenance of software components even if they've been rebranded, misattributed or counterfeited."
aDolus analyzes operational technology, real-time operating systems and Windows / Linux-based IT software. Its FACT platform delivers high-precision risk analytics, provides results tuned to maximize accuracy, generates retroactive SBOMs for legacy systems and verifies and validates current supplier SBOMs.
"This acquisition allows our customers to 'trust but verify' when it comes to software visibility," said JC Herz, Exiger SVP of Cyber Supply Chain. "Firmware and OT is packed with proprietary files that don't appear in public package managers or open source data. Vulnerability scanners and DevOps tools have no coverage for these systems. But aDolus has analyzed millions of these proprietary files in industrial operations and with AI can identify their point of origin. We have already used this capability to unmask software suppliers that critical equipment manufacturers didn't know were there."
The combination of Exiger's AI, the Ion Channel platform and aDolus empowers customers to achieve full cyber supply chain visibility, even in the absence of contractual leverage.
Industry News
JFrog announced the addition of JFrog Runtime to its suite of security capabilities, empowering enterprises to seamlessly integrate security into every step of the development process, from writing source code to deploying binaries into production.
Kong unveiled its new Premium Technology Partner Program, a strategic initiative designed to deepen its engagement with technology partners and foster innovation within its cloud and developer ecosystem.
Kong announced the launch of the latest version of Kong Konnect, the API platform for the AI era.
Oracle announced new capabilities to help customers accelerate the development of applications and deployment on Oracle Cloud Infrastructure (OCI).
JFrog and GitHub unveiled new integrations.
Opsera announced its latest platform capabilities for Salesforce DevOps.
Progress announced it has entered into a definitive agreement to acquire ShareFile, a business unit of Cloud Software Group, providing SaaS-native, AI-powered, document-centric collaboration, focusing on industry segments including business and professional services, financial services, healthcare and construction.
Red Hat announced the general availability of Red Hat Enterprise Linux (RHEL) AI across the hybrid cloud.
Jitterbit announced its unified AI-infused, low-code Harmony platform.
Akuity announced the launch of KubeVision, a feature within the Akuity Platform.
Couchbase announced Capella Free Tier, a free developer environment designed to empower developers to evaluate and explore products and test new features without time constraints.
Amazon Web Services, Inc. (AWS), an Amazon.com, Inc. company, announced the general availability of AWS Parallel Computing Service, a new managed service that helps customers easily set up and manage high performance computing (HPC) clusters so they can run scientific and engineering workloads at virtually any scale on AWS.
Dell Technologies and Red Hat are bringing Red Hat Enterprise Linux AI (RHEL AI), a foundation model platform built on an AI-optimized operating system that enables users to more seamlessly develop, test and deploy artificial intelligence (AI) and generative AI (gen AI) models, to Dell PowerEdge servers.