KDSys Launches runZero 5.0, an Exposure Management Platform for Defend…
페이지 정보
- Date : 26-07-09 10:09
- View : 22
관련링크
본문
KDSys, a data protection and operational technology (OT) security company led by CEO Seungyong Kim, announced on July 8 that runZero, a provider of Cyber Asset Attack Surface Management (CAASM) and cyber asset visibility solutions, has released the latest version of its platform, runZero 5.0.
The key feature of runZero 5.0 is its ability to integrate the entire exposure management process—from asset discovery and risk prioritization to verified remediation—into a single automated workflow.
This enables organizations to respond effectively to a threat landscape in which AI is automating attackers’ reconnaissance activities, dramatically reducing the time between vulnerability exposure and actual exploitation from days to just minutes.
runZero maps IT, OT, IoT, cloud, and mobile environments without requiring agents or credentials, and identifies even the devices hidden behind OT gateways using protocols such as Modbus and BACnet.
A key enhancement in runZero 5.0 is the new Exposure Management Dashboard, which prioritizes the exposures most likely to lead to security incidents.
The dashboard automatically highlights issues requiring immediate attention—such as emerging threats, newly discovered exposures, multi-homed devices, and environmental changes—enabling security teams to quickly identify where remediation efforts should begin.
In addition, runZero 5.0 goes beyond simply listing vulnerabilities (CVEs) by providing an Attack Path visualization feature that maps the potential routes attackers could exploit to move laterally across an environment. In particular, runZero 5.0 automatically identifies multi-homed devices that could bypass network segmentation and visualizes the path of least resistance from those devices to vulnerable assets.
runZero 5.0 also expands its vulnerability detection capabilities. The new release broadens end-of-life (EOL) coverage for network devices and introduces out-of-band testing to identify blind vulnerabilities without requiring a dedicated callback infrastructure.
In addition, asset-specific information is correlated with security advisories and consolidated under a "Missing Patches" category, providing both impact assessments and remediation recommendations to help reduce unnecessary alerts.
runZero 5.0 also introduces enhanced remediation validation capabilities. Without leaving the runZero platform, users can directly send high-risk exposures to ticketing systems such as Jira for remediation tracking, with expanded integrations—including ServiceNow—planned for future releases.
The platform also verifies whether vulnerabilities have actually been remediated by comparing tickets marked as "Closed" in external systems with the latest scan results. If a vulnerability is detected again, the corresponding ticket is automatically reopened.
This ensures that a closed ticket truly represents a resolved security risk, rather than merely an administrative status.
The platform also verifies whether vulnerabilities have actually been remediated by comparing tickets marked as "Closed" in external systems with the latest scan results. If a vulnerability is detected again, the corresponding ticket is automatically reopened.
A new External Scheduled Reports feature has also been introduced, enabling dashboards and risk assessment results to be delivered regularly via email to executives and other stakeholders who do not have runZero login accounts. Recipients can view the reports without logging in and download the data in CSV or JSON format, helping reduce the burden of compliance and executive reporting.
The new features in runZero 5.0 are available immediately to existing customers and users of the Community Edition.
Seungyong Kim, CEO of KDSys, said, "As AI automates attackers' reconnaissance, defenders need more than just additional data—they need clear insight into what to prioritize for remediation. With runZero 5.0, organizations can go beyond gaining asset visibility to verifying that remediation has actually been completed. We believe this will significantly enhance exposure management for hospitals, manufacturers, and public-sector organizations operating converged IT/OT environments in Korea."
Meanwhile, KDSys, the official runZero partner in Korea, provides consulting, deployment, technical support, and maintenance services for the platform.
The key feature of runZero 5.0 is its ability to integrate the entire exposure management process—from asset discovery and risk prioritization to verified remediation—into a single automated workflow.
This enables organizations to respond effectively to a threat landscape in which AI is automating attackers’ reconnaissance activities, dramatically reducing the time between vulnerability exposure and actual exploitation from days to just minutes.
runZero maps IT, OT, IoT, cloud, and mobile environments without requiring agents or credentials, and identifies even the devices hidden behind OT gateways using protocols such as Modbus and BACnet.
A key enhancement in runZero 5.0 is the new Exposure Management Dashboard, which prioritizes the exposures most likely to lead to security incidents.
The dashboard automatically highlights issues requiring immediate attention—such as emerging threats, newly discovered exposures, multi-homed devices, and environmental changes—enabling security teams to quickly identify where remediation efforts should begin.
In addition, runZero 5.0 goes beyond simply listing vulnerabilities (CVEs) by providing an Attack Path visualization feature that maps the potential routes attackers could exploit to move laterally across an environment. In particular, runZero 5.0 automatically identifies multi-homed devices that could bypass network segmentation and visualizes the path of least resistance from those devices to vulnerable assets.
runZero 5.0 also expands its vulnerability detection capabilities. The new release broadens end-of-life (EOL) coverage for network devices and introduces out-of-band testing to identify blind vulnerabilities without requiring a dedicated callback infrastructure.
In addition, asset-specific information is correlated with security advisories and consolidated under a "Missing Patches" category, providing both impact assessments and remediation recommendations to help reduce unnecessary alerts.
runZero 5.0 also introduces enhanced remediation validation capabilities. Without leaving the runZero platform, users can directly send high-risk exposures to ticketing systems such as Jira for remediation tracking, with expanded integrations—including ServiceNow—planned for future releases.
The platform also verifies whether vulnerabilities have actually been remediated by comparing tickets marked as "Closed" in external systems with the latest scan results. If a vulnerability is detected again, the corresponding ticket is automatically reopened.
This ensures that a closed ticket truly represents a resolved security risk, rather than merely an administrative status.
The platform also verifies whether vulnerabilities have actually been remediated by comparing tickets marked as "Closed" in external systems with the latest scan results. If a vulnerability is detected again, the corresponding ticket is automatically reopened.
A new External Scheduled Reports feature has also been introduced, enabling dashboards and risk assessment results to be delivered regularly via email to executives and other stakeholders who do not have runZero login accounts. Recipients can view the reports without logging in and download the data in CSV or JSON format, helping reduce the burden of compliance and executive reporting.
The new features in runZero 5.0 are available immediately to existing customers and users of the Community Edition.
Seungyong Kim, CEO of KDSys, said, "As AI automates attackers' reconnaissance, defenders need more than just additional data—they need clear insight into what to prioritize for remediation. With runZero 5.0, organizations can go beyond gaining asset visibility to verifying that remediation has actually been completed. We believe this will significantly enhance exposure management for hospitals, manufacturers, and public-sector organizations operating converged IT/OT environments in Korea."
Meanwhile, KDSys, the official runZero partner in Korea, provides consulting, deployment, technical support, and maintenance services for the platform.