Search/netapp
Vendor

netapp

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
cloud backup
Connections
280 relationships
Cybersecurity jobs available right now: August 18, 2026
Cybersecurity jobs available right now: August 18, 2026 CISO ADI Global Distribution | USA | Hybrid – View job details As a CISO, you will develop and lead ADI’s global security strategy to protect information assets, digital platforms, critical operations, and AI-enabled environments. Advise executives and the Board on cyber risk, resilience, regulatory compliance, and security posture while leading incident response, threat and vulnerability management, supply chain risk, and M&A security. Cybersecurity Analyst Schneider Electric | India | Hybrid – View job details As a Cybersecurity Analyst, you will monitor, triage, and investigate security alerts across SIEM, network, and OT/ICS security platforms in a 24×7 SOC environment. Analyze and enrich security events, manage incidents and escalations, maintain accurate case documentation, and support detection tuning, reporting, and SIEM operations. Cybersecurity Architect L’Oréal | France | On-site – View job details As a Cybersecurity Architect, you will design and implement secure enterprise architectures, services, and reusable security solutions. Advise project teams on security design, drive risk management, third-party security, and vulnerability remediation, and ensure security standards are embedded across the technology lifecycle. Get weekly updates on new cybersecurity job openings. Subscribe here! Cybersecurity Engineer GovCIO | USA | On-site – View job details As a Cybersecurity Engineer, you will support the RMF process and ATO readiness by developing and maintaining SSPs, SARs, POA&Ms, and eMASS documentation. Perform security testing, vulnerability scanning, patching, and control validation while managing remediation activities and supporting secure hardware deployments. Cyber Security Engineer Neros Technologies | USA | On-site – View job details As a Cyber Security Engineer, you will build and operationalize the enterprise cybersecurity program across security architecture, detection and response, governance, and automation. Manage the security technology stack, lead incident response, conduct vulnerability assessments and security testing, implement NIST 800-171 and ITAR-aligned controls, automate security workflows and detections, and establish security baselines, change controls, and awareness programs. Director of Information Security Panthalassa | USA | On-site – View job details As a Director of Information Security, you will define secure-by-default architecture and guardrails, strengthen identity and access management, harden critical systems, lead vulnerability management and incident response, conduct security architecture and risk reviews, and partner across the organization to drive remediation, audit readiness, and practical security standards. Head of Security Chamelio | Israel | On-site – View job details As a Head of Security, you will own Chamelio’s security strategy across product, engineering, cloud, corporate IT, and compliance. Embed security into the product and codebase, establish standards for AI and LLM features, strengthen access and endpoint security, and lead incident readiness, audits, vendor risk, and customer-facing security engagements. Founding Security Engineer Asymptote Labs | USA | On-site – View job details As a Founding Security Engineer, you will build the AI detection and response platform to secure complex agent environments. Engineer scalable telemetry, behavioral detections, investigation and response capabilities across AI agents, developer tooling, CI/CD, cloud, and enterprise infrastructure. Head of Cyber Security East Sussex County Council | United Kingdom | Hybrid – View job details As a Head of Cyber Security, you will provide strategic leadership across cybersecurity, information governance, and risk management to protect resilient public services. Partner with senior leaders, elected members, and external organizations to embed security into service design and transformation, enable informed risk decisions, and support secure information sharing across the Council and its partners. Information Security Support Engineer Landmark Group | UAE | On-site – View job details As a Information Security Support Engineer, you will secure and maintain company endpoints by ensuring required security tools, patches, and controls are properly deployed and compliant. Troubleshoot endpoint security issues, support incident and vulnerability remediation, maintain audit and compliance evidence, and partner with IT and business teams to address security risks. Network Security Engineer Kargo | USA | On-site – View job details As a Network Security Engineer, you will design and secure network architectures across cloud, on-premise, and IoT/edge environments. Implement firewalls, VPNs, segmentation, secure access, and edge connectivity while leading network monitoring, incident response, vulnerability remediation, and infrastructure hardening. Head of Cyber Security LION | Australia | On-site – View job details As a Head of Cyber Security, you will define and execute Lion’s cyber strategy across enterprise IT, OT, cloud, AI, and emerging technologies. Strengthen security capabilities across people, processes, and platforms, lead the cyber team and strategic partners, and advise senior leaders on cyber risk and investment. Principal Product Manager – Identity Threat Detection and Response Elastic | Canada | Remote – View job details As a Principal Product Manager – Identity Threat Detection and Response, you will define and own the vision, strategy, and roadmap for Elastic Security’s ITDR capabilities, including human, non-human, and AI agent identities. Partner with engineering, threat research, customers, and security teams to advance identity threat detection, investigation, and automated response, integrate identity signals across SIEM and XDR, and differentiate Elastic’s identity security capabilities in the market. Senior Cybersecurity Engineer Huntington National Bank | USA | On-site – View job details As a Senior Cybersecurity Engineer, you will manage and enhance internet proxy and filtering technologies to ensure secure, reliable internet access. Maintain configurations, support users, implement new security features and tools, integrate automation and monitoring systems, and partner with cybersecurity teams to improve security operations and automation. Senior Network Systems Engineer NetApp | Ireland | On-site – View job details As a Senior Network Systems Engineer, you will bridge network operations and NetDevOps by automating and managing global network, security, and hybrid data center infrastructure. Drive infrastructure as code, observability, and automated remediation across enterprise LAN, NAC, firewalls, and secure access platforms while improving reliability and uptime. Staff Cybersecurity Engineer Abbott | USA | Remote – View job details As a Staff Cybersecurity Engineer, you will drive AI-enabled cybersecurity workflows and product security strategy to reduce vulnerability risk and scale security decision-making. Lead release security readiness, vulnerability triage and remediation, validate security controls and fixes, and implement preventive measures across applications and platforms.
helpnetsecurity.comAug 18, 2026extracted
Nvidia and Tech Giants Launch AI Security Alliance
Nvidia and a large group of technology, cybersecurity, and enterprise software companies announced on Monday the launch of the Open Secure AI Alliance, a new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. The effort builds on existing work from the Linux Foundation’s recently launched Akrites initiative and the OpenSSF community. Inaugural partners of the Open Secure AI Alliance also include Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, Naver, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI. Nvidia’s contribution to the project includes open models, weights, data, and agent harness research, including a newly released open source project called NOOA, designed to help harnesses make agent behavior easier to trace, test, and audit. HPE is contributing to SPIFFE/SPIRE, a zero-trust identity framework for cryptographically verifying AI agents and services, while Hugging Face is donating its Safetensors model weight storage format to the PyTorch Foundation. IBM and Red Hat are extending open source supply chain security through the Lightwell project, which is designed to deliver automated vulnerability remediation at scale. Microsoft is contributing MDASH, a multi-model agentic scanning harness that coordinates AI agents to find, debate, and validate exploitable software bugs. SpaceXAI is open-sourcing its Grok Build terminal-based AI coding agent, with plans to eventually open-source the weights of the Grok model line. The new alliance argues that open models, harnesses, and security tooling should be treated as defensive assets rather than liabilities, and warns policymakers and regulators that broad restrictions on open frontier AI could weaken collective cyber defense capacity. Nvidia points to the recent security incident involving OpenAI and Hugging Face, noting that when closed AI tools could not differentiate between attackers and defenders and blocked forensic work, Hugging Face used the open-weight GLM 5.2 model on its own systems to review over 17,000 actions and contain the breach. “The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies,” Nvidia said. “Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them,” it added. Related: Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative Related: OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider Related: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
securityweek.comJul 27, 2026extracted
Factoring RSA Keys with Many Zeros
Factoring RSA Keys with Many Zeros Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, we uncovered a large number of keys in the wild with the patterns in Figure 1. Both patterns include several regularly spaced blocks of all zeros interleaved with seemingly random data. Pattern 1 appears in CT logs for certificates issued to several large organizations, including Yahoo and Verizon, and on some devices running NetApp software. Fortunately, these certificates have already expired, but we still shared our findings with these companies. We wanted to learn more about which product could be responsible for generating these keys, but we did not hear back. Pattern 2 appears on SSH hosts running the CompleteFTP software from EnterpriseDT. The underlying vulnerability affects RSA keys generated using versions 10.0.012.0.0 (Dec 2016Mar 2019) and DSA keys generated with v10.0.023.0.4 (Dec 2016Dec 2023). These vulnerabilities affect a small minority of hosts on the internet, but the more interesting takeaway is that independent cryptographic implementations failed in similar ways. More implementations may include the same bugs, and so it’s worth tailoring cryptanalytic algorithms for this particular type of failure. The article doesn’t speculate, but I will. This could be a deliberately designed backdoor, of the sort I wrote about back in 2013. I could imagine some government agency figuring out how to break this class of RSA keys, and then convincing different providers to hand them out to users.
schneier.comJun 29, 2026extracted
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a zero-day the entire time. The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10. It needs no login and no user interaction, just network access over HTTP, to take over the server. If you run PeopleSoft with the Environment Management Hub reachable from outside, that is your exposure, and the immediate move is to lock those endpoints down. The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB). Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too. It credits researchers from TrendAI Zero Day Initiative and TrendAI Research for the report. Mandiant CTO Charles Carmakal confirmed the bug is being exploited in the wild; Oracle has not said whether it has seen exploitation. Its advisory points to a patch availability document behind a support login, and whether a full fix is broadly available is unclear. For now, the guidance centers on mitigation. The operational detail became public because the attackers left their own gear exposed. Researcher @nahamike01 publicly flagged the open directories. Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888. Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script. The agents called home to a command-and-control server at azurenetfiles.net, a domain picked to look like Azure NetApp Files. The script, named [victim]_fanout.sh, spreads over SSH by spraying a hardcoded list of usernames and passwords against internal hosts pulled from /etc/hosts, then drops a marker file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into PeopleSoft directories. The command history shows the data compressed with zstd and an outbound SSH connection to the server hosting the public mirror of the ShinyHunters leak site. Mandiant notified more than 100 organizations whose IP addresses matched vulnerable endpoints. Sixty-eight percent were in higher education, most of them in the United States. Some blocked the activity; others were compromised and had data posted to the leak site. The University of Nottingham is one of the first confirmed victims. Have I Been Pwned has counted about 455,000 unique email addresses in the leaked set, covering current students and alumni, with names, addresses, phone numbers, passport numbers, and details on ethnicity and disabilities. The university has confirmed the breach. Oracle's guidance is to disable the Environment Management Hub service on multi-server setups, or remove the PSEMHUB application outright on single-server setups. If you cannot do either, block external access to /PSEMHUB/* (especially /PSEMHUB/hub) and /PSIGW/HttpListeningConnector at the perimeter. Mandiant warns that WAF body-inspection rules alone are not enough, since they can be bypassed. Restricting these endpoints does not break normal user sessions. Then hunt for signs of an existing compromise: WebLogic access logs showing external POST requests to /PSEMHUB/hub or /PSIGW/HttpListeningConnector. Unexpected .jsp files under the PSEMHUB.war web application directory, or odd folders named logs, persistantstorage, or scratchpad under the PSEMHUB paths. Recently changed .xml files under the web doc root's envmetadata/data/environment, which can be abused for XMLDecoder persistence that fires on the next restart. Outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations, which the exploit chain may use to capture machine-account NetNTLM hashes. Apply Oracle's update for your PeopleTools version once you confirm it is available in My Oracle Support. ShinyHunters says victim outreach has only just started, and it has not posted most of the organizations it claims, so more names are likely. The method is the bigger tell. ShinyHunters has lately leaned on vishing, stolen tokens, and weak access controls to steal data from SaaS and education platforms, from Salesforce customers to Canvas. A server-side zero-day in on-premises ERP software is a step up from that, aimed at the same data-rich targets. The open question is whether this was a one-off borrowed zero-day or the start of ShinyHunters moving into ERP exploitation.
thehackernews.comJun 11, 2026extracted
Upwind Raises $250 Million at $1.5 Billion Valuation
Cloud security company Upwind today announced raising $250 million in a Series B funding round that brings the total raised by the company to $430 million and its valuation to $1.5 billion. The new investment round was led by Bessemer Venture Partners, with additional support from Salesforce Ventures and Picture Capital. The startup is also backed by Alta Park, Cerca Partners, Craft Ventures, Cyberstarts, Greylock, Leaders Fund, Penny Jar Capital, Swish Ventures, and TCV. Upwind offers a runtime-native cloud security platform that provides organizations with increased visibility into networks, APIs, and data flows. According to Upwind, amid a massive surge in agentic workflows, its solution can reduce noise and prioritize real risk, without impacting business speed. The new investment allows the startup to accelerate product and go-to-market initiatives, scaling its runtime-first cloud security platform across data, AI and code. It will continue to advance the core AI security capabilities of the platform, while expanding the runtime-first approach to help developers eliminate misconfigurations before production. Since its Series A funding round in December 2024, Upwind has doubled its workforce and deepened its presence across the US, UK, and Israel, while expanding to Australia, India, Singapore and Japan. Headquartered in San Francisco, California, Upwind was founded in 2022 by Amiram Shachar, who previously founded Spot.io, a company acquired by NetApp for $450 million. “Cloud infrastructure has changed faster than the security models designed to protect it,” said Shachar, who serves as Upwind’s CEO. “The next era of cloud security requires a fundamentally different approach, centered in realtime signals. That’s actually the only way to protect the cloud in the new era of AI. We built Upwind for where the cloud is going, not where it has been,” Shachar added. Related: AiStrike Raises $7 Million in Seed Funding Related: Claroty Raises $150 Million in Series F Funding Related: Furl Raises $10 Million for Autonomous Vulnerability Remediation Related: Monnai Raises $12 Million for Identity and Risk Data Infrastructure
securityweek.comJan 26, 2026extracted
New infosec products of the week: December 12, 2025
New infosec products of the week: December 12, 2025 Here’s a look at the most interesting products from the past week, featuring releases from Apptega, Backslash Security, BigID, Black Kite, Bugcrowd, NinjaOne, Nudge Security, and Veza. Apptega Policy Manager streamlines policy creation and compliance oversight Apptega revealed its Policy Manager module, expanding the company’s platform to automate the creation, review, and oversight of custom business policies. With this enhancement, Apptega enables partners and in-house security and compliance teams to maintain auditable policies with minimal manual effort. Backslash secures MCP servers from data leakage, prompt injection, and privilege abuse Backslash Security announced the launch of its end-to-end solution for the secure use of Model Context Protocol (MCP) servers across software development environments. As organizations increasingly adopt AI-native coding agents and integrated development environments (IDEs), the Backslash platform is designed to protect the new AI-powered development stack end-to-end. BigID Activity Explorer enhances visibility for insider risk investigation BigID announced Activity Explorer, a new capability that delivers auditability and granular activity investigation to strengthen insider risk detection and response. With Activity Explorer, organizations can review, search, and analyze activity across cloud and on-prem environments, including AWS S3, SharePoint, OneDrive, Google Drive, and NetApp, all within a unified interface for user accounts, service accounts, and AI agents. New Black Kite module offers product-level insight into software supply chain vulnerabilities Black Kite released its new Product Analysis module, which allows security teams to evaluate the risks of third-party software products at a granular level. As the first TPRM platform to offer this capability, Black Kite provides a more detailed view of exposure and supports better decision-making around specific products and vendor outreach. The new module delivers intelligence on software supply chain risk through deep downloadable software analysis (CPE), SaaS subdomain analysis, and SBOM analysis. Bugcrowd unveils AI tools to accelerate triage and strengthen preemptive security Bugcrowd has launched new platform functionality, Bugcrowd AI Triage Assistant and Bugcrowd AI Analytics, to bring speed and intelligence and insights to the process of building security resilience. Combined with the general availability of AI Connect, these new capabilities enable security teams to make smarter, faster decisions that help preempt emerging threats, not just react to them after the fact. NinjaOne rolls out secure, compliant remote access for IT teams NinjaOne announced NinjaOne Remote, a remote access solution natively integrated into the NinjaOne Platform. NinjaOne Remote was built from the ground up for businesses, not consumers, with security in mind, and gives IT teams and MSPs fast, reliable, and secure control over endpoints, wherever they are. Nudge Security expands platform with new AI governance capabilities Nudge Security announced an expansion of its platform to address the need for organizations to mitigate AI data security risks while supporting workforce AI use. Veza brings unified visibility and control to AI agents across the enterprise Veza has launched AI Agent Security, a purpose-built product to help organizations secure and govern AI agents at enterprise scale. As businesses accelerate AI adoption, Veza is defining a new foundation for AI SPM by giving security and governance teams the visibility and control they need to protect data and enforce trust across human-AI interactions.
helpnetsecurity.comDec 12, 2025extracted
BigID Activity Explorer enhances visibility for insider risk investigation
BigID Activity Explorer enhances visibility for insider risk investigation BigID announced Activity Explorer, a new capability that delivers auditability and granular activity investigation to strengthen insider risk detection and response. With Activity Explorer, organizations can review, search, and analyze activity across cloud and on-prem environments, including AWS S3, SharePoint, OneDrive, Google Drive, and NetApp, all within a unified interface for user accounts, service accounts, and AI agents. Organizations manage massive volumes of sensitive data across distributed environments. Yet when incidents occur, a deleted file, unauthorized access, suspicious downloads, security teams often lack the visibility to answer the most critical questions: who or what accessed the data, when, and how. Traditional audit logs are fragmented, incomplete, or unavailable, slowing response and increasing both insider risk and AI-driven exposure. Activity Explorer solves this challenge by centralizing activity events, from human user and service accounts, to automated or AI-based processes, into a searchable, filterable experience that gives analysts and investigators immediate clarity. Teams can rapidly trace behavior, validate suspicious actions, review historical events, and support compliance audits with complete, trustworthy activity records. Key highlights: Unified activity auditing across hybrid environments: Access consolidated user activity logs across AWS S3, SharePoint, OneDrive, Google Drive, and NetApp, eliminating blind spots across cloud, SaaS, and on-prem data stores. Visibility across all identity types: Track activity across users, service accounts, and AI agents – ensuring complete oversight of all identities that access or move sensitive data. Activity investigation: Search and filter user events by date, user, operation, resource, or any combination, helping teams quickly answer questions like “Who deleted this file?” or “What did this user access yesterday?” Audit history: Maintain a comprehensive record of activity across sensitive data to support forensic investigations, incident response, and required audit logging for regulations like HIPAA, GLBA, and GDPR. Breach investigation & blast-radius analysis: Identify data touched by a compromised account during a breach window, helping teams determine exposure scope and accelerate containment. Accelerated insider risk detection: Surface patterns tied to unauthorized access, mass downloads, suspicious deletions, or unusual identity behavior, helping teams detect risky actions early. Better context for data security teams: Combine activity logs with BigID’s sensitivity classification and data context to understand not just what happened, but what type of data was involved and how risky it was. “Organizations can’t protect what they can’t see – and they can’t investigate what they can’t trace,” said Nimrod Vax, Chief Product Officer at BigID. “With Activity Explorer, we’re giving security teams unified visibility into user, service account, and automated activity across their hybrid environment, helping them investigate insider risks, support compliance, and strengthen their data security posture.”
helpnetsecurity.comDec 10, 2025extracted
Trend Vision One AI Security Package delivers proactive protection for AI environments
Trend Vision One AI Security Package delivers proactive protection for AI environments Trend Micro will launch the Trend Vision One AI Security Package in December. The package delivers centralized exposure management with analytics for AI-driven environments. It protects the AI application stack from model development to runtime and extends security across every stage of AI deployment. It will also launch alongside additional AI security capabilities. “Innovation without oversight is a risk businesses cannot afford. Our goal is to provide the foundation for AI safety and guardrails to align AI transformation with security and trust. By building with these principles from the start, organizations can move forward with confidence as AI becomes central to their growth,” said Rachel Jin, Chief Platform and Business Officer at Trend Micro. Organizations are building AI systems at speed, but most lack visibility into how those systems process data, make decisions, or could be exploited by threat actors. Traditional security tools serving endpoints, network, and cloud were not built to understand model behaviors or AI-specific risks like prompt injection, data poisoning, or output manipulation. This leaves organizations exposed to errors and blind spots that existing tools were never designed to address. This is where Trend Vision One changes the game, offering a comprehensive way to detect risks in AI models and automatically protect them through intelligent AI guardrails. With AI Application Security, the AI Scanner continuously monitors models to uncover vulnerabilities and applies AI guardrails to defend against threats—creating a seamless, proactive, closed-loop system for AI risk management. Despite growing awareness of AI risks, most organizations still deploy systems without adequate security checks. According to the World Economic Forum (2025), only 37% of organizations assess AI security before rollout, even as the average cost for a data breach surpasses $4.4 million. To address emerging threats and simplify security management, Trend has several integrated security tools designed to deliver proactive, AI-powered protection across cloud-native environments, including: AI Security Blueprint and Risk Insights: Establishes auditable AI governance with a unified risk posture visualization, delivering actionable insights to enforce compliance and protect proprietary models across the development pipeline and enterprise. Cloud Risk Management (CRM) – Project View: Breaks dev-security silos with real-time monitoring, instant threat alerts, and full-stack risk visibility across supply chain pipelines. Agentless vulnerability detection across multi-cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), provides zero-impact deployment with 24-hour updated asset visibility. Container & Code Security: Delivers shift-left security by moving vulnerability evaluation earlier in development, reducing manual overhead through automation, and ensuring consistent policy application. New File Integrity Monitoring (FIM) for critical system files with Kubernetes and eBPF support enhances runtime protection. File Security with NetApp Storage Support (FSx): Provides real-time malware and ransomware protection for cloud storage with a security-first design—files never leave the environment, and scanning happens locally with only metadata sent to Trend. Kubernetes-based architecture enables automatic scaling with unified Trend Vision One visibility. Agentic SIEM with AWS Native Logs Integration: AI-native cloud detection and response combining real-time observability, IOC sweeping with threat intelligence, and automated security playbooks. Supports rapid ingestion of new cloud application logs within hours for correlation with Trend threat intelligence. Zero Trust Secure Access – AI Secure Access: Extends zero trust to generative AI tools, enabling granular policy enforcement to control employee interaction, prevent sensitive data exposure, and mitigate critical shadow IT risks. “As organizations race to gain advantage through the use of AI throughout their operating environment, most face significant risks across the many facets of AI security and governance,” said Dave Gruber, Principal Analyst at Omdia. “Mitigating these risks requires comprehensive visibility and governance throughout model and application development, deployment, and utilization.”
helpnetsecurity.comNov 24, 2025extracted
NetApp strengthens its enterprise data platform with new AI-focused innovations
NetApp strengthens its enterprise data platform with new AI-focused innovations NetApp unveiled new products, strengthening its enterprise-grade data platform for AI innovation. The new NetApp AFX decouples performance and capacity with a disaggregated NetApp ONTAP that runs on the new NetApp AFX 1K storage system. NetApp AI Data Engine is a secure, unified extension of ONTAP integrated with the NVIDIA AI Data Platform reference design that helps organizations simplify and secure the entire AI data pipeline, and managed via single, unified control plane. Together, these capabilities unify high-performance storage and intelligent data services into a single, secure, and scalable offering that accelerates enterprise AI retrieval augmented generation (RAG) and inference across hybrid and multicloud environments. With NetApp AFX and the NetApp AI Data Engine, the NetApp data platform is able to ensure that all applicable data is ready for AI. “With the new NetApp AFX systems, customers now have a trusted, proven choice in on-premises enterprise storage built on a comprehensive data platform to rapidly propel AI innovation forward,” said Syam Nair, Chief Product Officer at NetApp. “NetApp AI Data Engine enables customers to seamlessly connect their entire data estate across hybrid multicloud environments to build a unified data foundation. Enterprises can then accelerate their AI data pipelines by collapsing multiple data preparation and management steps into the integrated NetApp AI Data Engine, built with NVIDIA accelerated computing and NVIDIA AI Enterprise software complete with semantic search, data vectorization and data guardrails. The combination of NetApp AFX with AI Data Engine provides the enterprise resilience and performance, built and proven over decades by NetApp ONTAP, now in a disaggregated storage architecture, and all still built on the most secure storage on the planet,” Nair continued. To accelerate AI workloads, NetApp introduced new capabilities including: NetApp AFX NetApp AFX is an enterprise-grade disaggregated all-flash storage system built for demanding AI workloads. NetApp AFX is a powerhouse data foundation for AI factories. It is certified storage for NVIDIA DGX SuperPOD supercomputing and powered by NetApp ONTAP, the storage operating system trusted by tens of thousands of enterprise customers across industries to manage exabytes of data. AFX delivers the same data management and built-in cyber resilience that NetApp is known for, along with secure multi-tenancy and seamless integration across on-premises and cloud environments. AFX is designed for linear performance scaling up to 128 nodes with TBs per second of bandwidth, exabyte-scale capacity, and independent scaling of performance and capacity. Optional DX50 data compute nodes enable a global metadata engine for a real-time catalog of enterprise data and leverage NVIDIA accelerated computing. NetApp AI Data Engine (AIDE) NetApp AIDE is a comprehensive AI data service designed to make AI simple, affordable, and secure. From data ingestion and preparation to serving GenAI applications, AIDE offers a global, up-to-date view of a customer’s entire NetApp data estate for fast searching and curation while seamlessly connecting their data to any model or tool across on-premises and public cloud. It automates data change detection and data synchronization, eliminating redundant copies and ensuring data is always current. Built-in guardrails follow data throughout its AI lifecycle, ensuring security and privacy. AIDE leverages the NVIDIA AI Data Platform reference design, featuring NVIDIA accelerated computing and NVIDIA AI Enterprise software, including NVIDIA NIM microservices, for vectorization and retrieval, which joins advanced compression, fast semantic discovery, and secure, policy-driven workflows. By bringing AI to data in an integrated system, AIDE provides the efficiency, data clarity, and governance needed for enterprises to confidently adopt AI. NetApp AIDE will run natively within the AFX cluster on top of the DX50 data compute nodes. Future ecosystem support includes the integration of NVIDIA RTX PRO Servers featuring RTX PRO 6000 Blackwell Server Edition GPUs. NetApp AIDE accelerates customers’ AI journeys with simplicity, security, and efficiency. Object API for seamless access to Azure Data & AI Services Customers can now access their Azure NetApp Files data through an Object REST API, available in public preview. This new capability means customers no longer need to move or copy file data into a separate object store to use it with Azure services. Instead, NFS and SMB datasets can be connected directly to Microsoft Fabric, Azure OpenAI, Azure Databricks, Azure Synapse, Azure AI Search, Azure Machine Learning, and more. Customers can analyze data, train AI models, enable intelligent search, and build applications on their existing ANF datasets, while continuing to rely on the enterprise performance and reliability of Azure NetApp Files. Enhanced unified global namespace in Microsoft Azure Enterprises can now seamlessly unify their global data estate across cloud and on-premises into Microsoft Azure with new FlexCache capabilities in Azure NetApp Files. The same capability can also extend their on-premises workloads, such as Electronic Design Automation. This allows for data stored in other ONTAP-based storage in customer data centers or across multiple clouds to be instantly made visible and writeable in an ANF environment, but with data transferred granularly only when requested. This allows for a customer’s entire hybrid cloud data estate to be seamlessly accessed in Microsoft Azure. Additionally, enterprises can migrate data and snapshots effortlessly between environments using SnapMirror, supporting hybrid use cases such as continuous backup, automated disaster recovery, and workload balancing across environments. “Enterprises are looking for a trusted, high-performance data foundation to turn massive volumes of information into real intelligence that powers their AI journey,” said Justin Boitano, VP, Enterprise AI Products at NVIDIA. “NetApp’s data platform has transformed into an AI-native storage platform by integrating NVIDIA accelerated computing and software, including leading AI models. With this new platform, organizations can index and search vast amounts of unstructured data across their enterprise to drive innovation and deliver real business impact,” Boitano concluded.
helpnetsecurity.comOct 14, 2025extracted
NetApp StorageGRID 12.0 powers AI and data-intensive workloads
NetApp StorageGRID 12.0 powers AI and data-intensive workloads NetApp has released NetApp StorageGRID 12.0, a scalable, software-defined object storage solution designed for unstructured data. This latest version of StorageGRID introduces new capabilities designed to enhance AI initiatives, improve data security, and modernize organizations’ data infrastructure. Whether businesses are in the early stages of modernizing their data lakes or experimenting with advanced AI applications, they need to manage and store exploding volumes of unstructured data such as text, video, machine and sensor data, server logs, and more. Businesses that want to tap into this growing ocean of data need a secure, cost-effective, and scalable solution, making object storage an essential component of their primary storage environment. “As the proven industry leader in on-premises object storage, NetApp StorageGRID provides the scalability, cost-effectiveness, and performance needed to feed modern workloads like AI,” said Sandeep Singh, SVP and GM of Enterprise Storage at NetApp. “Our latest updates enable customers to grow their object-based data estates more securely and accelerate workloads so they can focus on putting their data to work.” NetApp StorageGRID 12.0 introduces new features designed to strengthen object storage in customers’ intelligent data infrastructure, including: Improved scaling for AI workloads: StorageGRID 12.0 includes new capabilities for advanced caching that improve the efficiency and scalability for AI training and other HPC workloads, boosting performance with up to 20x more throughput than before. Additionally, it supports versioning AI datasets with bucket branches. Customers can more easily iterate AI projects at scale, facilitate testing and development workflows, and make their data stores more resilient. This new feature enables users to create space-efficient clones of their object storage buckets to use in their workflows and enable faster recovery in the face of disruption. Simplified management: StorageGRID 12.0 includes numerous enhancements ranging from better drive firmware upgrades to improved log archiving abilities that are designed to simplify the administrator experience. Administrators can automate drive firmware updates across all nodes, reducing manual labor spent on maintenance tasks. Enhanced cyber resiliency and security features: StorageGRID 12.0 includes updates that increase the security of object storage environments. The solution now supports enhanced encryption standards with AES GCM encryption add integrity checking, stronger on-disk encryption, and default blocking for SSH ports. Customers also more easily support immutable datasets for AI by leveraging the new support for object lock in cross-grid replication.
helpnetsecurity.comSep 9, 2025extracted