

Risky Business #771 -- Palo Alto's firewall 0days are very, very stupid
Nov 20, 2024
Andrew Morris, the founder of GreyNoise, dives into the world of cybersecurity, highlighting alarming vulnerabilities in edge devices. He reveals a new zero-day discovered by their AI system, emphasizing that the threat landscape is even worse than commonly perceived. The conversation also tackles the ineffectiveness of phishing training and underscores the critical security flaws in high-security IP cameras. As always, the episode blends humor with serious insights, making it both engaging and informative.
AI Snips
Chapters
Transcript
Episode notes
Microsoft Security Enhancements
- Microsoft is introducing a remote recovery feature and user-mode security software options.
- These aim to improve system resilience and reduce kernel-mode vulnerabilities.
Machine-Readable Vulnerability Data
- Microsoft will publish machine-readable vulnerability data in JSON format.
- This simplifies vulnerability data consumption for security tools.
Palo Alto Networks Vulnerabilities
- Palo Alto Networks suffered two sets of bugs: one in a customer migration tool and another in their firewall's management interface.
- The latter included an auth bypass and command injection vulnerability, exploitable by sending specific HTTP headers.