SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Stormcast, Jan 23, 2025: PFSync Protocol; Oracle CPU; Korean VPN Supply Chain Attack; Ivanti Guidance

5 snips
Jan 22, 2025
Discover the intricacies of the PFSync protocol, crucial for synchronizing firewall states during failover scenarios. Delve into Oracle's latest critical patch release that targets multiple vulnerabilities. Uncover a sophisticated supply chain attack on a Korean VPN service, revealing significant security implications. Explore the challenges of VPN configuration and the urgent need for enhanced security measures regarding Ivanti. Stay informed with effective strategies to protect critical infrastructure from emerging threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

PFSync Security Advice

  • Isolate PFSync traffic to a dedicated link between firewalls.
  • This prevents data leaks and mitigates potential performance impact due to substantial traffic volume.
INSIGHT

PFSync Protocol Insights

  • PFSync, used for firewall failover, isn't a standard protocol and lacks an RFC.
  • It uses protocol number 240, considered unused by IANA, making analysis with tools like Wireshark or tcpdump difficult.
INSIGHT

Oracle CPU January 2025 Key Points

  • Oracle's January 2025 Critical Patch Update addresses 318 vulnerabilities.
  • Key fixes target MySQL, WebLogic, and Oracle Financial Services, including critical Kerberos and Diameter Signaling Router flaws.
Get the Snipd Podcast app to discover more snips from this episode
Get the app