DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch
SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch

SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch

Update: 2025-02-18
Share

Description



My Very Personal Guidance and Strategies to Protect Network Edge Devices

A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable.

https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660

PostgreSQL SQL Injection

A followup to yesterday's segment about the PostgreSQL vulnerability. Rapid7 released a Metasploit module to exploit the vulnerability.

https://github.com/rapid7/metasploit-framework/pull/19877

Ivanti Connect Secure Exploited

The Japanese CERT observed exploitation of January's Connect Secure vulnerability

https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html

WinZip Vulnerability

WinZip patched a buffer overflow vulenrability that may be triggered by malicious 7Z files

https://www.zerodayinitiative.com/advisories/ZDI-25-047/

Xerox Printer Patch

Xerox patched two vulnerabililites in its enterprise multifunction printers that may be exploited for lateral movement.

https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch

SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch

Dr. Johannes B. Ullrich