668 - Zero-days em Firewalls Palo Alto Networks e Fortinet seguem sob ataque
Description
[Referências do Episódio]
PAN-SA-2024-0015 Critical Security Bulletin: Ensure Access to Management Interface is Secured - https://security.paloaltonetworks.com/PAN-SA-2024-0015
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA - https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/
FG-IR-24-423 - Missing authentication in fgfmsd - https://fortiguard.fortinet.com/psirt/FG-IR-24-423
Hop-Skip-FortiJump-FortiJump-Higher - Fortinet FortiManager CVE-2024-47575 - https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/
Inside Water Barghest’s Rapid Exploit-to-Market Strategy for IoT Devices - https://www.trendmicro.com/en_us/research/24/k/water-barghest.html
Roteiro e apresentação: Carlos Cabral e Bianca Oliveira
Edição de áudio: Paulo Arruzzo
Narração de encerramento: Bianca Garcia
[Referências do Episódio]
Post da Fundação Shadowserver sobre a exploração das falhas no PAN-OS - https://bsky.app/profile/shadowserver.bsky.social/post/3lbh6k7p7pc27
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) -...
Published 11/22/24
[Referências do Episódio]
About the security content of iOS 18.1.1 and iPadOS 18.1.1
About the security content of iOS 17.7.2 and iPadOS 17.7.2
About the security content of macOS Sequoia 15.1.1
About the security content of visionOS 2.1.1
About the security content of Safari...
Published 11/21/24