DiscoverAppSec NowLatest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates
Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates

Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates

Update: 2025-03-18
Share

Description

Welcome to the latest episode of AppSec Now, a DevCentral podcast dedicated to the ever-evolving world of application security. In this episode, Chase takes the reins while Aubrey is away, joined by Malcolm Heath, a principal researcher at F5 Labs, and the illustrious MegaZone, a principal security engineer on the SIRT team.

We dive deep into the recent Apache Camel remote code execution vulnerability, discussing the initial panic and the eventual revelation that it was a medium-severity CVE with narrow impact. We also explore the ongoing debate on government backdoors in end-to-end encryption, with insights on the recent stances of Signal and Apple. Finally, we shed light on the recent DDoS attack on X (formerly Twitter), attributed to Dark Storm, and discuss the complexities of attributing such attacks. Stay informed and up-to-date with the latest trends and threats in the AppSec world!

References: https://community.f5.com/kb/security-insights/appsec-camels-typhoons-and-backdoors/340217

00:00 Introduction

00:59 Apache Camel RCE

10:09 Silk Typhoon

16:11 Government Encryption Backdoors

25:51 X (Twitter) DDoS

30:25 VulnCon Comin' Up!

32:16 Outro

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates

Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates

DevCentral