ISC StormCast for Thursday, January 9th, 2025

ISC StormCast for Thursday, January 9th, 2025

Update: 2025-01-09
Share

Description

In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.

Episode Links and Topics:

More Governments Backdoors in Your Backdoors

https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/

Researchers reveal how expired domains linked to abandoned backdoors can be hijacked, exposing systems to further compromise.

Security Update: Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways

https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways

Ivanti addresses critical vulnerabilities (CVE-2025-0282, CVE-2025-0283) in their secure gateway products, with active exploitation in the wild.

CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability

https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/

A command injection vulnerability in Aviatrix Network Controllers allows unauthenticated code execution, posing severe risks to network environments.
Comments 
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

ISC StormCast for Thursday, January 9th, 2025

ISC StormCast for Thursday, January 9th, 2025

Dr. Johannes B. Ullrich