PLAY PODCASTS
Network Security News Summary for Friday October 25th, 2024

Network Security News Summary for Friday October 25th, 2024

SANS Internet Storm Center's Daily Network Security News Podcast · Johannes B. Ullrich

October 24, 20245m 14s

Audio is streamed directly from the publisher (traffic.libsyn.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Dev Features in Prod; Cisco VPN DOS and Authenticed RCE; Hard Coded Cloud Credentials Development Features Enabled in Production https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380 Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/ Cisco Secure Firewall Management Center Software Command Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7 Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Apps https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps keywords: cloud; mobile app; cisco; ssh; dos; vpn; development