

























As threats evolve, modern security demands a steady balancing act between protection and user experience. There’s no debate: Security teams need robust application control that reduces risk and prevents unauthorized software from running. But not at the cost of slower patching, heavier maintenance, or clunky operations.
That much-needed balance isn’t getting any easier to achieve. When systems, like Linux, require frequent updates for stability, and users—administrators and executives alike—need secure access from anywhere, security teams can’t afford to delay essential updates or waive a two-factor authentication (2FA). Now, these competing priorities, more often than not, stem from technology limitations. Not a lack of security strategy.
When security tools can’t keep up with the very environments they’re designed to protect, they become yet another obstacle for already overextended security teams. And from it, two main challenges arise.
Application control is designed to strengthen security, not slow it down. Yet two common operational challenges continue to create unnecessary friction at the intersection between security and IT.
When security agents depend on full upgrades to support new operating system releases, critical Linux kernel updates can get delayed. That increases maintenance overhead, slows vulnerability remediation and leaves organizations exposed for longer than necessary. But security and operation teams want to deploy kernel updates as quickly as possible, especially when addressing critical security fixes. Unfortunately, lengthy agent upgrade cycles often get in the way.
On one hand password-only authentication leaves privileged accounts wide open to phishing, credential theft, password reuse, and account compromise. On the other, overly complex authentication processes can frustrate administrators and disrupt workflows. Administrators need flexible sign-in options that improve security while maintaining a seamless user experience, like passkeys that eliminate the need to remember complex passwords.
When security controls lag behind operating system updates or cause undesired friction, organizations are left to choose between delaying critical maintenance or weakening their security controls to keep operations moving. Neither approach is sustainable.
The latest Carbon Black App Control enhancements—specifically Carbon Black App Control Windows Agent 8.12.0, Carbon Black App Control Server 8.13, and Linux Agent 8.9.0—deliver help address these very challenges with four capabilities designed to improve operational agility, bolster security, and simplify management:
Together, these updates strike the perfect balance, helping organizations stay protected without slowing down day-to-day operations.
IT environments can be diverse, and even organizations that standardize on, say, x86-based hardware will find a few ARM64-based devices in the mix. Thanks to a collaboration with Qualcomm and Microsoft, Carbon Black App Control now supports those ARM-based Windows 11 endpoints.
This means security admins can apply the same trusted application control policies across both traditional x86- and ARM–based Windows devices. This helps ensure consistent endpoint protection regardless of hardware platform.
Linux environments evolve quickly, which means they need regular updates to maintain security, stability, and performance. Independent KMOD updates decouple kernel module support from full agent releases, allowing organizations to adopt supported Linux kernel updates faster without waiting for a complete agent upgrade.
By separating kernel module updates from the agent lifecycle, organizations can reduce maintenance complexity, accelerate vulnerability remediation and minimize any disruptions during kernel update rollouts—all while preserving the control security teams rely on.
Every analyst knows administrative accounts are one of the most valuable targets for an attacker. Even strong passwords can be compromised through phishing or password reuse. By adding TOTP-based 2FA, Carbon Black App Control strengthens access to privileged accounts with an additional layer of verification that’s familiar, reliable, and most importantly, easy to deploy. Security teams can keep access under lock, while admins go about their day undisturbed.
Strong authentication shouldn’t come at an expense. Passkey support enables passwordless authentication using capabilities already built into user’s devices, including fingerprint recognition, facial recognition, and device PINs.
Built on industry-standard cryptographic authentication, these passkeys provide protection against phishing and credential theft while eliminating the need to remember complex passwords. Thus, admins can spend less time at sign-ins and organizations reduce the plethora of risks associated with compromised credentials.
Application control is at its strongest when it evolves alongside the environments it protects. At Carbon Black, we’re focused on helping organizations reduce operational friction without asking them to compromise on their security. With the latest Carbon Black App Control updates, Linux teams can adopt kernel updates faster and administrators can keep business operations moving forward, even as they protect more devices—all while security teams spend less time managing access and more time reducing risk.
Because true enterprise-grade security should help organizations move faster, not hold them back.
Want more? Read about the latest updates in detail, or contact your in-region expert to learn how Carbon Black App Control can add speed and resilience to your security strategy.
Application control is a security approach that helps prevent unauthorized or untrusted software from running on a device or server. Instead of trying to detect malicious applications after they're installed, it allows organizations to define which applications are trusted, helping reduce the risk of malware, ransomware, and other unauthorized software.
A Linux kernel update improves the core software that manages a system's hardware, security, and performance. These updates often include important security fixes and stability improvements, so organizations typically want to deploy them as quickly as possible. Security tools that delay kernel updates can slow vulnerability remediation and make things a lot harder on teams.
Organizations should look for capabilities that strengthen security while making ongoing management easier. That includes support for both x86- and ARM-based Windows devices, faster updates, stronger protection for privileged accounts through methods like TOTP-based two-factor authentication, and passwordless authentication with passkeys.

Larry Howarth
Principal Product Manager, Enterprise Security Group, Broadcom
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。