671 - Mais de 2000 firewalls da Palo Alto já foram atacados com novos zero-days
Description
[Referências do Episódio]
Post da Fundação Shadowserver sobre a exploração das falhas no PAN-OS - https://bsky.app/profile/shadowserver.bsky.social/post/3lbh6k7p7pc27
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) - https://security.paloaltonetworks.com/CVE-2024-0012
CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface - https://security.paloaltonetworks.com/CVE-2024-9474
Forti-fied? Logging blind spot revealed in FortiClient VPN - https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/
Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine - https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/
Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY - https://www.recordedfuture.com/research/russia-aligned-tag-110-targets-asia-and-europe
Unveiling the Past and Present of APT-K-47 Weapon: Asyncshell - https://medium.com/@knownsec404team/unveiling-the-past-and-present-of-apt-k-47-weapon-asyncshell-5a98f75c2d68
DPRK IT Workers | A Network of Active Front Companies and Their Links to China - https://www.sentinelone.com/labs/dprk-it-workers-a-network-of-active-front-companies-and-their-links-to-china/
Microsoft disrupts ONNX phishing-as-a-service infrastructure - https://www.bleepingcomputer.com/news/security/microsoft-disrupts-onnx-phishing-as-a-service-infrastructure/
Roteiro e apresentação: Carlos Cabral e Bianca Oliveira
Edição de áudio: Paulo Arruzzo
Narração de encerramento: Bianca Garcia