SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Stormcast, Jan 16, 2025: Critical Vulnerabilities and Cybersecurity Updates You Need to Know

11 snips
Jan 16, 2025
A long-neglected vulnerability in Netgear routers is back in the spotlight, with attackers exploiting it to deploy crypto miners. There's a critical flaw in Google's OAuth that threatens sensitive data through defunct domains. Rsync also faces urgent security issues that require immediate patching. Meanwhile, Fortinet's advisory nudges the importance of updating firmware to secure defenses. Explore these pressing concerns and fortify your cybersecurity today!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

12-Year-Old Netgear Vulnerability Exploited

  • Attackers are exploiting a 12-year-old Netgear router vulnerability to install Monero miners.
  • This vulnerability was discovered in 2013 but only received a CVE last year.
INSIGHT

OAuth/OpenID Connect Domain Reuse Issue

  • OAuth, used for features like "login with Google," has a weakness where defunct domain accounts can be exploited.
  • A proposed solution is to include a workspace ID in addition to the email address.
ADVICE

Mitigating Domain Reuse Issues

  • Consider the implications of domain reuse when integrating third-party authentication services.
  • Ensure your implementation can detect re-registered accounts with the same email but different users.
Get the Snipd Podcast app to discover more snips from this episode
Get the app