Risky Business

Risky Business #777 -- It's SonicWall's turn

16 snips
Jan 29, 2025
Luke Jennings, a security researcher at Push Security, dives into the pitfalls of federated authentication, emphasizing how attackers exploit unexpected identity providers. He highlights alarming vulnerabilities in SonicWall devices and a comical DNS mishap involving MasterCard. The discussion also touches upon the risks of using personal Google accounts for corporate access and the complexities of managing multiple identity providers. With an eye on emerging threats, Jennings provides insights into securing user authentication in today's digital landscape.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

TikTok Correction

  • Patrick Gray incorrectly stated that TikTok was still available in app stores.
  • It was actually removed but kept functional by Akamai and Oracle.
INSIGHT

SonicWall Vulnerability

  • A CVSS 9.8 vulnerability in SonicWall devices allows for remote code execution.
  • This likely signals Chinese APT groups building botnets.
ANECDOTE

MasterCard DNS Typo

  • MasterCard had a typo in their DNS records, pointing a nameserver to an unregistered Nigerian domain.
  • Someone registered it, intercepting traffic but getting a low bug bounty.
Get the Snipd Podcast app to discover more snips from this episode
Get the app