DiscoverEnterprise Security Weekly (Video)Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386
Stopping 0day Exploits Doesn't Require AI or Superhuman Speed  - Rob Allen - ESW #386

Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386

Update: 2024-12-06
Share

Description

When focused on cybersecurity through a vulnerability management lens, it's tempting to see the problem as a race between exploit development and patching speed. This is a false narrative, however. While there are hundreds of thousands of vulnerabilities, each requiring unique exploits, the number of post-exploit actions is finite. Small, even.

Although Log4j was seemingly ubiquitous and easy to exploit, we discovered the Log4Shell attack wasn't particularly useful when organizations had strong outbound filters in place.

Today, we'll discuss an often overlooked advantage defenders have: mitigating controls like traffic filtering and application control that can prevent a wide range of attack techniques.

This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

Show Notes: https://securityweekly.com/esw-386

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Stopping 0day Exploits Doesn't Require AI or Superhuman Speed  - Rob Allen - ESW #386

Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386