meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Sunday, April 14th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 April 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Palo Alto Networks GlobalProtect 0-Day Vulnerability Exploited

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, April 15th,

0:03.2

2004 edition of the Sands and at Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and today I'm recording from London, England.

0:13.7

I'm deviating from my usual schedule, and I'm recording this podcast on Saturday evening instead of Sunday evening.

0:22.9

Two particular reasons for this.

0:25.0

First of all, my travel schedule.

0:27.3

But then we also have some breaking news that I would like to dedicate this podcast to

0:33.2

and also would like to keep you in the loop in case you're able to listen to this a little bit before Monday morning.

0:41.8

The problem we have here is a new vulnerability in Palo Alto Network's Global Protect Software.

0:49.3

Some exploitation of this vulnerability has been reported by Walexity.

0:56.2

Vlexity has seen exploits as early as end of March, March 26th,

1:04.1

and has since then seen some novel backdoors being deployed using this vulnerability. It's a remote code execution

1:13.7

vulnerability. It does give the attacker full route access. And given that Global Protect is

1:22.1

typically a VPN solution, giving remote users access to internal network resources.

1:29.1

These devices are being compromised here can then be leveraged in order to pivot into an

1:34.8

organization's network.

1:37.1

Palo Alto Networks released an advisory regarding this vulnerability on Friday, which is

1:42.8

why we didn't get around to cover this for

1:45.7

the Friday podcast and stated that a patch should be available no later than Sunday. Again,

1:55.1

I'm recording this here Saturday evening in the UK, and at this point, I don't see a patch available yet, but

2:03.4

maybe released by the time you are listening to this podcast.

2:08.4

Short of applying a patch and outright disabling, a global protect, the other option you

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.