Exchange Vulns, A Passwordless Future, SOC Stand-ups

Exchange Vulns, A Passwordless Future, SOC Stand-ups

In this episode of the HackableYou Podcast:

We look at the ex-CEO of SolarWinds blame for the hack on an intern with a weak password, the Malaysia Airlines 9 year-long data breach, and the new critical Microsoft Exchange vulnerability actively being exploited by Chinese hackers.

In Topicpic of The Week, we debate the idea that passwords are not here to stay and what the concept of Passwordless authentication means for the future.

Lastly in our exclusive segment, Secrets from the SOC we discuss the importance of daily and routine standups or huddles when working in high-performing security teams and operations centers.


Timestamps:

Cyber News: 02:34

Topic of The Week: 13:52

SFTS: 22:54


CVE Details:

CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange that allowed the attacker to send arbitrary HTTP requests and authenticate as the Exchange server.

CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.

CVE-2021-26858 is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

CVE-2021-27065 is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(44)

More LAPSUS$, Record Breaking 0days, Breach Notifications

More LAPSUS$, Record Breaking 0days, Breach Notifications

Guess who's back with a brand new ra..Podcast. Its Ed, Alex and Will! In this episode we bring you cyber news topics; LAPSUS$ hacking T-Mobile, Google/Mandiant 0day reports and Russian hackers new mon...

29 Apr 202250min

RaidForums DOWN, Global SOC Operations, Importance of Culture

RaidForums DOWN, Global SOC Operations, Importance of Culture

It's been a while, sorry about that! Join us as always with some cyber news, our topic of the week and the exclusive segment, secrets from the SOC. contact: info@hackableyou.com

18 Apr 202247min

Russia-Ukraine Threat, Zero Trust, Note Taking Tips

Russia-Ukraine Threat, Zero Trust, Note Taking Tips

WE STAND WITH UKRAINE. In today's episode, we discuss the ongoing cyber threat from Russia amid the tensions and attack on Ukraine. The Topic of The Week looks at the concept of Zero Trust and why we...

26 Feb 202244min

CNI Ransomware Warning, PUMA Hacks, QBOT Infections

CNI Ransomware Warning, PUMA Hacks, QBOT Infections

This episode certainly took a while to come together, we hope you enjoy it!

11 Feb 202228min

Death to 2021 - A Cyber Year in Review

Death to 2021 - A Cyber Year in Review

Join us on the HackableYou Podcast as we discuss the cyber events of 2021, notable lessons we have learned, and what we think 2022 has in store for all of us. A very big Happy New Year from The Hacka...

31 Des 202136min

Zero Days, Log4Shell, Christmas Special 🎅🏼

Zero Days, Log4Shell, Christmas Special 🎅🏼

Log4Shell... need we say any more? Merry Christmas from the HackableYou Team! info@hackableyou.com

16 Des 202138min

UPS XSS Phishing, GoDaddy Breach, Securing Keys and Secrets

UPS XSS Phishing, GoDaddy Breach, Securing Keys and Secrets

Check out our episode this week where we discuss the UPS Cross-Site Scripting (XSS) Phishing attack, the Tela Connected Cars outage, and the GoDaddy data breach impacting 1.2 million customers. We als...

5 Des 202127min

We're back! Cyber News and Catch-up!

We're back! Cyber News and Catch-up!

This is a overdue episode, but we are back with more content. To get started have a listen of a recording from a few weeks ago and ramp up to the next episode! We missed you, we hope you missed us...

20 Nov 202133min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
tomprat-med-gunnar-tjomlid
elektropodden
nasjonal-sikkerhetsmyndighet-nsm
hans-petter-og-co
shifter
pedagogisk-intelligens
rss-anleggspraten
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-plateprat
rss-ai-forklart
fornybaren
rss-digitaliseringspadden
rss-30-minutter-inn-i-fremtiden
rss-alt-som-gar-pa-strom
rss-heis