惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
Hacker News: Ask HN
Hacker News: Ask HN
T
Threatpost
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
P
Palo Alto Networks Blog
S
SegmentFault 最新的问题
月光博客
月光博客
Latest news
Latest news
博客园 - Franky
T
Threat Research - Cisco Blogs
有赞技术团队
有赞技术团队
博客园_首页
T
The Exploit Database - CXSecurity.com
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
Simon Willison's Weblog
Simon Willison's Weblog
爱范儿
爱范儿
Security Latest
Security Latest
Scott Helme
Scott Helme
博客园 - 聂微东
T
Tor Project blog
美团技术团队
IT之家
IT之家
Stack Overflow Blog
Stack Overflow Blog
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
Jina AI
Jina AI
Vercel News
Vercel News
小众软件
小众软件
T
Tenable Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Forbes - Security
Forbes - Security
aimingoo的专栏
aimingoo的专栏
O
OpenAI News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Last Watchdog
The Last Watchdog
Cloudbric
Cloudbric
AI
AI

SECURITY.COM

3 Ways to Defend Against LOTL Attacks Now Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For Your DLP Incident Backlog Owes You Closure 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Locking Down the Server Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 5 Ways To Keep AI in Check DLP Made Easier on the Teams Running It Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? For Financial Services, a Wake-Up Call for Reclaiming IAM Control How Cloud-Managed DLP Lowers the Barrier to Entry As Identity Takes Control, Telecom Needs Repatriated IAM Capable of Keeping Up Post-Quantum Security Starts at the Edge The Public Sector Case for Repatriating IAM in the Age of AI The Data Sovereignty Paradox The Unseen Wall: How Billions of Attacks Were Blocked in 2025 The “Zero-Blindness” Roadmap: Achieving Maturity in the DLP Endpoint Workspace IAM Has a Fix for the Modern Identity Crisis Identity is the Control Plane, and AI Just Changed the Game
4 Application Control Updates That Help Teams Move Faster
About the Author · 2026-07-22 · via SECURITY.COM
  • Too often, organizations are forced to make an impossible choice between control and productivity. 
  • When security tools can’t keep up with Linux updates or administrator workflows, teams face delays, increased risk, and frustrated users. 
  • Carbon Black App Control’s latest updates help organizations extend application control protections to more ARM-powered devices, adopt Linux kernel updates faster, secure access with TOP-based 2FA, and simplify secure sign-ins, streamlining both security and daily operations. 

As threats evolve, modern security demands a steady balancing act between protection and user experience. There’s no debate: Security teams need robust application control that reduces risk and prevents unauthorized software from running. But not at the cost of slower patching, heavier maintenance, or clunky operations. 

That much-needed balance isn’t getting any easier to achieve. When systems, like Linux, require frequent updates for stability, and users—administrators and executives alike—need secure access from anywhere, security teams can’t afford to delay essential updates or waive a two-factor authentication (2FA). Now, these competing priorities, more often than not, stem from technology limitations. Not a lack of security strategy.

When security tools can’t keep up with the very environments they’re designed to protect, they become yet another obstacle for already overextended security teams. And from it, two main challenges arise. 

When security itself becomes the bottleneck

Application control is designed to strengthen security, not slow it down. Yet two common operational challenges continue to create unnecessary friction at the intersection between security and IT.  

Challenge #1: System maintenance 

When security agents depend on full upgrades to support new operating system releases, critical Linux kernel updates can get delayed. That increases maintenance overhead, slows vulnerability remediation and leaves organizations exposed for longer than necessary. But security and operation teams want to deploy kernel updates as quickly as possible, especially when addressing critical security fixes. Unfortunately, lengthy agent upgrade cycles often get in the way. 

Challenge #2: Administrative access 

On one hand password-only authentication leaves privileged accounts wide open to phishing, credential theft, password reuse, and account compromise. On the other, overly complex authentication processes can frustrate administrators and disrupt workflows. Administrators need flexible sign-in options that improve security while maintaining a seamless user experience, like passkeys that eliminate the need to remember complex passwords. 

When security controls lag behind operating system updates or cause undesired friction, organizations are left to choose between delaying critical maintenance or weakening their security controls to keep operations moving. Neither approach is sustainable.

4 updates, one common goal

The latest Carbon Black App Control enhancements—specifically Carbon Black App Control Windows Agent 8.12.0, Carbon Black App Control Server 8.13, and Linux Agent 8.9.0—deliver help address these very challenges with four capabilities designed to improve operational agility, bolster security, and simplify management: 

  • Support for ARM64-based Windows 11 devices
  • Independent Kernel Module (MOD) updates for faster Linux kernel adoption
  • Time-Based One-Time (TOTP) two-factor authentication (2FA) for stronger access protection
  • Passkey support for simpler, passwordless authentication

Together, these updates strike the perfect balance, helping organizations stay protected without slowing down day-to-day operations. 

1. Safeguard more endpoints with ARM-based device support

IT environments can be diverse, and even organizations that standardize on, say, x86-based hardware will find a few ARM64-based devices in the mix. Thanks to a collaboration with Qualcomm and Microsoft, Carbon Black App Control now supports those ARM-based Windows 11 endpoints. 

This means security admins can apply the same trusted application control policies across both traditional x86- and ARM–based Windows devices. This helps ensure consistent endpoint protection regardless of hardware platform. 

2. Keep Linux environments current with independent KMOD updates 

Linux environments evolve quickly, which means they need regular updates to maintain security, stability, and performance. Independent KMOD updates decouple kernel module support from full agent releases, allowing organizations to adopt supported Linux kernel updates faster without waiting for a complete agent upgrade. 

By separating kernel module updates from the agent lifecycle, organizations can reduce maintenance complexity, accelerate vulnerability remediation and minimize any disruptions during kernel update rollouts—all while preserving the control security teams rely on. 

3. Protect privileged access with TOTP-based 2FA

Every analyst knows administrative accounts are one of the most valuable targets for an attacker. Even strong passwords can be compromised through phishing or password reuse. By adding TOTP-based 2FA, Carbon Black App Control strengthens access to privileged accounts with an additional layer of verification that’s familiar, reliable, and most importantly, easy to deploy. Security teams can keep access under lock, while admins go about their day undisturbed. 

4. Simplify secure sign-ins with passkeys 

Strong authentication shouldn’t come at an expense. Passkey support enables passwordless authentication using capabilities already built into user’s devices, including fingerprint recognition, facial recognition, and device PINs. 

Built on industry-standard cryptographic authentication, these passkeys provide protection against phishing and credential theft while eliminating the need to remember complex passwords. Thus, admins can spend less time at sign-ins and organizations reduce the plethora of risks associated with compromised credentials. 

Security that moves at the speed of operations

Application control is at its strongest when it evolves alongside the environments it protects. At Carbon Black, we’re focused on helping organizations reduce operational friction without asking them to compromise on their security. With the latest Carbon Black App Control updates, Linux teams can adopt kernel updates faster and administrators can keep business operations moving forward, even as they protect more devices—all while security teams spend less time managing access and more time reducing risk. 

Because true enterprise-grade security should help organizations move faster, not hold them back. 

Want more? Read about the latest updates in detail, or contact your in-region expert to learn how Carbon Black App Control can add speed and resilience to your security strategy. 

Common questions about application control

What is application control?

Application control is a security approach that helps prevent unauthorized or untrusted software from running on a device or server. Instead of trying to detect malicious applications after they're installed, it allows organizations to define which applications are trusted, helping reduce the risk of malware, ransomware, and other unauthorized software.

What is a Linux kernel update, and why is it important?

A Linux kernel update improves the core software that manages a system's hardware, security, and performance. These updates often include important security fixes and stability improvements, so organizations typically want to deploy them as quickly as possible. Security tools that delay kernel updates can slow vulnerability remediation and make things a lot harder on teams. 

What should organizations look for in a modern application control solution?

Organizations should look for capabilities that strengthen security while making ongoing management easier. That includes support for both x86- and ARM-based Windows devices, faster updates, stronger protection for privileged accounts through methods like TOTP-based two-factor authentication, and passwordless authentication with passkeys. 

You might also enjoy

4 Application Control Updates That Help Teams Move Faster

Larry Howarth

Larry Howarth

Principal Product Manager, Enterprise Security Group, Broadcom