CTO's Blog

Proactive DLP is here

July 09, 2019 by Taeil Goh
DLP which stands for "data loss prevention" or "data leakage prevention" refers to technical solutions and processes employed by organizations to prevent exposing or sharing sensitive data with unauthorized users. Implementing...

26 new file types support including Video, Email and more

April 03, 2019 by Vinh Lam
Overview We are excited to announce a major release, v5.4, of Data Sanitization (also known as CDR). With this release, we address two new use cases. The first protects isolated networks from threats borne by email messages on...

Data Sanitization againsts Remote Code Execution via Macro/Event execution in LibreOffice (CVE-2018-16858)

February 25, 2019 by Vinh Lam
Overview LibreOffice is widely used because of their effectiveness and free! However, several vulnerabilities were discovered in the past, from 2017 the number of CVEs increased significantly. In 2017, OPSWAT started...

データ無害化5.3リリース

December 27, 2018 by Taeil Goh
ハイライト Microsoft Office 2007ドキュメントに再帰的に埋め込まれたドキュメントを無害化カレンダーデータファイルの無害化: iCalendar (.ics), vCalender v1.0...

Proof of Concept (PoC) Attack Leverages Microsoft Office and YouTube to Deliver Malware

November 26, 2018 by Vinh Lam
Researchers at Cymulate have discovered a way to deliver and execute malware through the Online Video feature in Microsoft Office Word (https://blog.cymulate.com/abusing-microsoft-office-online-video). Here we outline a brief summary of...

How to Protect Against Software Supply Chain Attacks

October 04, 2018 by Taeil Goh
What protections do you have in place to ensure that your software builds are virus-free before releasing to the public? With software supply chain attacks on the rise, it is more important than ever to ensure that your software build is...