

Defensive Security Podcast Episode 294
Jan 26, 2025
The discussion kicks off with a hidden backdoor in Juniper routers that raises serious network security alarms. PayPal’s recent data breach highlights the urgent need for better data protection strategies. The conversation then dives into older Ivanti vulnerabilities still being exploited, emphasizing timely patching. The massive PowerSchool data breach reveals the severe consequences of poor credential protection. Lastly, CISA's new software security guidelines aim to enhance protection across critical infrastructure, showcasing the ongoing battle against cyber threats.
AI Snips
Chapters
Transcript
Episode notes
Monitor Outbound Connections
- Monitor infrastructure devices for unsolicited outbound connections.
- This can help detect backdoors, even if identifying the initial compromise is difficult.
Adversary's Concerns
- The adversary is likely concerned about others co-opting their backdoor after discovery.
- They implemented additional authentication to prevent this.
Detection Recommendations
- Use specialized hunt guides for BPF-based malware detection on perimeter devices.
- Review network logs and check for common persistence mechanisms.