ISC StormCast for Tuesday, April 16th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 April 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, April 16, 2024 edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and today I'm recording from Washington, D.C. |
| 0:14.2 | As mentioned in the early Special Monday episode, Palo Alto Networks notified users of a critical already exploited |
| 0:23.0 | vulnerability affecting its global protect product. As promised, Palo Alto released a hot fix |
| 0:31.2 | on Sunday. As usual, test the hot fix. It was released just before midnight, at least here, East Coast |
| 0:41.3 | Time. |
| 0:42.4 | Effected systems should also display a warning in their management console, notifying users |
| 0:47.5 | of the vulnerability and of the availability of a patch. |
| 0:52.5 | Now, one of our readers, Mark, shared that they saw actual attempts on Saturday that attempt |
| 1:00.2 | to exploit this vulnerability. |
| 1:02.7 | They have a number of different global protect instances across their infrastructure. |
| 1:07.4 | Pretty much all of them were attacked. |
| 1:10.0 | A couple that were not attacked were fairly new. |
| 1:12.6 | So one assumption here is that they're working off not the very latest list of vulnerable devices. |
| 1:20.6 | Could be something like Shodan or such, which of course is not always quite that up to date. |
| 1:25.6 | Haven't heard anything from others, so there's a single observation |
| 1:29.5 | at this point. I published a quick update with also the IP addresses that Mark observed attacking |
| 1:37.9 | them. The attack was not successful in this case, and these devices also had telemetry turned off, which is the recommended |
| 1:46.8 | workaround and appears to be working so far. |
| 1:51.7 | Now, pretty much at the same time where Palo Alto released its issues, there was another |
| 1:58.5 | vulnerability that I want to mention that meant a little bit under |
| 2:01.8 | the radar and that's an authentication bypass vulnerability in the Delinea secret server. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

