CVEs ARE DYING - ThreatWire

Поділитися
Вставка
  • Опубліковано 31 тра 2024
  • ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
    Support ThreatWire → / threatwire
    @endingwithali →
    Twitch: / endingwithali
    Twitter: / endingwithali
    Everywhere else: links.ali.dev
    [❗] ThreatWire Patreon has moved to → / threatwire
    0:00 Intro
    0:12 - The NVD is MIA
    2:09 - Linux Foundation CVE Reporting Changed
    4:16 - Cisco Acquires Splunk
    4:20 - It’s Literally Black Market Extortion
    6:06 - Is the AT&T Leak Real?
    7:02 - OUTRO
    LINKS
    🔗 Story 1: The NVD is MIA
    blog.morphisec.com/national-v...
    anchore.com/blog/national-vul...
    nvd.nist.gov/
    www.hackread.com/nist-nvd-hal...
    🔗 Story 2: Linux Foundation CVE Reporting Changed
    github.com/torvalds/linux/blo...
    community.synopsys.com/s/ques...
    lwn.net/ml/linux-kernel/20240...
    lwn.net/Articles/961961/
    openssf.org/blog/2024/02/14/l...
    This story had help with sourcing by Karl and Lacey! Thank you for the help!
    🔗 Story 3: Cisco Acquires Splunk
    www.cisco.com/site/us/en/abou...
    🔗 Story 4: It’s Literally Black Market Extortion
    grahamcluley.com/incognito-ma...
    krebsonsecurity.com/2024/03/i...
    🔗 Story 5: Is the AT&T Leak Real?
    www.scmagazine.com/brief/att-...
    www.bleepingcomputer.com/news...
    www.theregister.com/2024/03/1...
    www.nextgov.com/cybersecurity...
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • Наука та технологія

КОМЕНТАРІ • 97

  • @ViolentOrchid
    @ViolentOrchid 2 місяці тому +50

    The CVEs not being reported until they are fixed means vulnerabilities will exist without that information being provided to parties that need to deal with it until a fix is available.

    • @dingokidneys
      @dingokidneys 2 місяці тому +7

      The kernel team IS the party that needs to deal with it.

    • @arandomnamegoeshere
      @arandomnamegoeshere 2 місяці тому +2

      @@dingokidneys....and if one were to have a Linux kernel deployed somewhere... no deal?

    • @dingokidneys
      @dingokidneys 2 місяці тому +2

      @@arandomnamegoeshere Say there's a use after free error in the ICH9 driver affecting kernels newer than 5.6 to pull an example out of the air. What will you do with that knowledge in the absence of a kernel patch? There's nothing you can do to prevent processes running on the system from accessing that driver that would allow you to continue to use the machine the kernel is running on. It's literally keep on running and hope that you don't pick up anything that exploits that bug or power the machine down until the kernel patch comes out.

    • @lmaoroflcopter
      @lmaoroflcopter 2 місяці тому +4

      ​@dingokidneys add it to the risk register. Increase monitoring on hosts affected by the vulnerability. Enact further segregation to minimise exposures. Increase the priority on our project to isolate identified servers from the internet. Further restrict access to particular servers. Change hardware. Bring forward the migration project to move towards SaaS for our systems pushing the risk ownership to our cloud vendor.
      Not every mitigation must be a patch. Without knowledge of vulnerabilities and their impact we have no knowledge of how to spend our limited budget, effort and time to best secure our estate.
      To assume only kernel devs should be aware is exceedingly myopic.

    • @justinburris4077
      @justinburris4077 Місяць тому

      that may be so, but the damage is already dealt to the customer base. most of the times companies report vulnarablities 6 months or more after finding the compromise. a company i used to worked for, waited a year, shut down its server, reloaded the information, made everyone change their password, offered life lock. they did so without warning, the sad part is, it is an PC company and they specialize in this type of protection. not to mention that lifelock has also been targeted by vulnerabilities manytimes before. I don't think anyone or anything is really safe from these issues. Somtimes they are not fixed at all and to reduce panic they just say they have done something. after all individual people are more often to get fired and the company is less likely to be found at fault and shut down. this is probably why when the great att outage of 2024 that took out an entire cell network was a result of a "bad update" and not a "hack attack"

  • @andrewtaylor76
    @andrewtaylor76 Місяць тому +1

    We had an IT recruiter come in to our college class and he basically said stop trying to beautify your resumes. Put the important things that qualify you for the job and your contact info at the top, and leave the work history and what not towards the bottom/ next page.

  • @mytechnotalent
    @mytechnotalent 2 місяці тому +21

    This is a fantastic episode pointing to the fact that so many of these CVE's were at scale in years past. Today the level of sophistication of threats and a legitimate capability to keep up and categorize and process them in this model simply does not scale. Regardless of what happens a change to the model must take place.

  • @TFKAT
    @TFKAT 2 місяці тому +11

    Incognito was a textbook exit-scam. This just as Nemesis market got blasted by the German FEDS.
    ShinyHunters back at it again, AT&T malding and balding.

    • @lowwastehighmelanin
      @lowwastehighmelanin 2 місяці тому +1

      Why are you calling them feds when it's Bundestag? Don't use English words. That one isn't that hard to spell. It makes it more difficult for other people to look up who did what.

  • @c1ph3rpunk
    @c1ph3rpunk 2 місяці тому +9

    We held a funeral for Splunk this week.

  • @robgandy4550
    @robgandy4550 2 місяці тому +4

    amazing the amount of CVEs that have no fixes. I use them for work all the time. Gonna suck when they get rid of some of them.

  • @Rico34
    @Rico34 23 дні тому

    👀 Appreciate your honesty about never being on the DW. You’re not missing much. Best to stay away from black holes….

  • @afterglow5285
    @afterglow5285 2 місяці тому +5

    yup, i felt for the clickbait

  • @jpo3811
    @jpo3811 2 місяці тому +7

    Somebody tell Linux patched CVEs are remediations not vulns. Duh.

  • @tonysolar284
    @tonysolar284 2 місяці тому +4

    Incognito tried to extort me but they couldn't find my history.

  • @ewasteredux
    @ewasteredux 2 місяці тому +15

    Ally should interview @LaurieWired on camera. That would be an interview to remember.

    • @denic6861
      @denic6861 2 місяці тому +3

      Got to see her do a talk at the Spokane Cyber Cup on February 10th and she’s a great speaker. +1 this

    • @apIthletIcc
      @apIthletIcc 2 місяці тому +2

      Just seeing them interact would be great, i feel like their sense of humor would match up in a badass way.

  • @papa_sweep7335
    @papa_sweep7335 2 місяці тому +6

    SORRY FOR BEING HOT AND SMART LMFAO GET EM!!

  • @cloudshock_io
    @cloudshock_io 2 місяці тому +2

    Good info. Do you think automated scanners like SonarQube will incorporate these new CVE feeds?

  • @jamess1787
    @jamess1787 2 місяці тому +1

    Manager:
    I look for a conpetant individual that is a criticsl thinker. Enough paper pushers and people who cant think for themselves, sick of printing silly meme-worthy motivational posters, just need people that dont need their hands to be held (at least not for more then a 2-3 weeks until they figure out where they fit in).

  • @justinburris4077
    @justinburris4077 Місяць тому +1

    they have already found all vulnerabilities in Windows, now they are going to completely find all the ones for linux. they know some cannot be fixed, and some can, but they are all aware all windows vulnerabilities, including future ones. this does not mean that they will stop their dedication to finding them. now that more people are using Linux including the great gamer migration and because of proton implementation within steam, the CVE's are now going up due to a shift in users on linux. steam os is based around linux, android is linux based, bluestacks, and they have had even more time to prepare now that windows has linux for windows. with the world turning more to Open source products it will be getting much worse. this is why you macs are going to see more CVE's also.

  • @petesakes1985
    @petesakes1985 2 місяці тому +2

    Thanks for sharing !

  • @thefrub
    @thefrub 2 місяці тому +6

    Great job on the video! As CVEs continue to get more common with more and more bug bounty hunters out there every day, I really hope that the reporting structure continues to evolve. Hi Twitch Chat! Ali what does that pink sign behind you say? Also DRIP CHECK time Ali pog

  • @jamespifher
    @jamespifher 2 місяці тому +1

    Great follow up shirt, after last week ❤

  • @akashsrivastava279
    @akashsrivastava279 2 місяці тому +2

    watching their video still feels like early 2000s

  • @DNETREAPER
    @DNETREAPER 2 місяці тому +4

    Love LoVe Love the shirt!!!!

  • @user-zu4ft8yw9e
    @user-zu4ft8yw9e 2 місяці тому

    The stages of problem-solving for addressing the vulnerability problem, specifically in regards to the decline of CVEs, typically involve:
    1. Identifying vulnerabilities
    2. Evaluating vulnerabilities
    3. Treating vulnerabilities
    4. Reporting vulnerabilities
    These stages are crucial in the vulnerability management process to effectively assess and mitigate security risks in IT infrastructure.

  • @anounTT
    @anounTT 2 місяці тому +2

    Where can we get the shirt ?

  • @wilgarcia1
    @wilgarcia1 2 місяці тому +10

    Love the shirt =D

  • @atajahangiri5861
    @atajahangiri5861 2 місяці тому

    Happy Nourouz
    VERY very GOOD video

  • @ksea4350
    @ksea4350 2 місяці тому +3

    You Convince me, I like subscribe. And comment

  • @Ms.Robot.
    @Ms.Robot. 2 місяці тому +1

    Thanks sueety🎉❤😊😊😊 Just ignore cowbell tee-shirt commenters.

  • @keithbull5261
    @keithbull5261 2 місяці тому +2

    Accurate shirt 😂

  • @David_998
    @David_998 2 місяці тому +2

    Love the shirt 🥵❤️‍🔥

  • @Jerhyn7
    @Jerhyn7 2 місяці тому

    Seven words that make algorithms love You.

  • @aleckane99
    @aleckane99 2 місяці тому +1

    That blooper though haha

  • @Bsmashington
    @Bsmashington 2 місяці тому +16

    that shirt is funny

  • @Dr_Larken
    @Dr_Larken 2 місяці тому +1

    Free cookies!

  • @herauthon
    @herauthon 2 місяці тому

    where can i ask a SECQ without unfolding a POC ?

  • @isaacadams5570
    @isaacadams5570 Місяць тому

    Love the T

  • @lossless4129
    @lossless4129 2 місяці тому

    I feel like this shirt is in direct response to some dude whining about hak5 “catering you younger crowds” back on one of Ali’s first videos haha!

  • @hiamealhilwa6684
    @hiamealhilwa6684 2 місяці тому +1

    No, you're not sorry

  • @user-td4pf6rr2t
    @user-td4pf6rr2t 2 місяці тому

    I blame chatgpt

  • @carsonjamesiv2512
    @carsonjamesiv2512 2 місяці тому

    😬

  • @aliebada
    @aliebada 2 місяці тому

    !idk, apology for being so hot and smart :) J.K

  • @ksea4350
    @ksea4350 2 місяці тому

    I like the shrit 🤣😂😴

  • @sinistergeek
    @sinistergeek 2 місяці тому

    nah

  • @slugnasty2395
    @slugnasty2395 2 місяці тому

    Dyer.

  • @thj9760
    @thj9760 2 місяці тому

    עליה? לא הבנתי, היא משלנו?

  • @JhonsonFam
    @JhonsonFam 2 місяці тому +1

    Do u know what necklace she's wearing

    • @drnoone3596
      @drnoone3596 2 місяці тому +1

      Her name in Hebrew I presume Aliche

    • @RyanBarnes
      @RyanBarnes 2 місяці тому

      Looks like a Hebrew name as already mentioned, lol!

    • @endingwithali
      @endingwithali 2 місяці тому +6

      its my hebrew name :)

    • @JhonsonFam
      @JhonsonFam 2 місяці тому +1

      עלית זה שם יפה…

  • @endingwithali
    @endingwithali 2 місяці тому +4

    linux LINUX L I N U X

  • @carpentb17
    @carpentb17 2 місяці тому +4

    You should read mean tweets. I love those bits

    • @endingwithali
      @endingwithali 2 місяці тому

      i actually dont get that many mean tweets or comments tbh 🤷‍♀

  • @danielgx83
    @danielgx83 2 місяці тому

    עליח או שרשום אלירז ? קשה לראות

  • @NovaZero
    @NovaZero 2 місяці тому

    Gdi

  • @arjunsinhchudasama72
    @arjunsinhchudasama72 2 місяці тому +3

    The 👕 is 🔥

  • @Linuxfy
    @Linuxfy 2 місяці тому

    I was confused at first but its funny you fool me

  • @AnonMedic
    @AnonMedic 2 місяці тому +5

    That's shirt lol 😂😂😂

  • @petesakes1985
    @petesakes1985 2 місяці тому +2

    Click bait LOL 😅😂

  • @JNET_Reloaded
    @JNET_Reloaded 2 місяці тому

    the word is patch not fix! its never fixed!

  • @ac9206
    @ac9206 2 місяці тому

    This channel still alive? Lololol

  • @LORDJPXX3
    @LORDJPXX3 2 місяці тому +2

    good girl.

  • @soko45
    @soko45 2 місяці тому +1

    and thats the unsub

  • @MoreBollocks-ui2zs
    @MoreBollocks-ui2zs 2 місяці тому +1

    Same Sh*t, different T-shirt.

  • @ChuckNorris-lf6vo
    @ChuckNorris-lf6vo 2 місяці тому +1

    Ali I am not convinced you get sufficient viewer feedback about what the viewers of infosec want? Also you look like a sales person much more rather than like a hacker?

    • @endingwithali
      @endingwithali 2 місяці тому +1

      what does a hacker even look like lmao

    • @ChuckNorris-lf6vo
      @ChuckNorris-lf6vo 2 місяці тому

      Good morning hand had my coffee yet let me think a bit I think in infosec to deliver valueable information such as news, or curiosities, you have to understand the business world big picture, top down, the IT world inside-out, the software development, and the people who work with this stuff, to heart. To understand and respect all the sentiment to be able to prioritize what is important news and what less important. Personal independence. And some pain from working long hours. Or street smarts. Trust. More male energy than female energy or a different balance of the energies than presented. I don't know it all depends what you want to do exactly. My comment is that if you want to deliver the infosec news you can pay attention to what infosec public really wants to hear and how, and if you want to have a IT related career you are not at all limited to infosec because of your energy that you bring forward. At least in these few videos. Also it's a more dangerous world infosec. But actually I remember you are backend engineer so keep doing that I guess it pays well for sure so youll be just fine. Much love.@@endingwithali

    • @ChuckNorris-lf6vo
      @ChuckNorris-lf6vo 2 місяці тому

      you are awesome you got this@@endingwithali

    • @ChuckNorris-lf6vo
      @ChuckNorris-lf6vo 2 місяці тому

      lmao i dont know @@endingwithali

  • @poppafuze
    @poppafuze 2 місяці тому

    side scrolling is painful please stop

  • @whyme8068
    @whyme8068 2 місяці тому +3

    No need to apologize for being hot and smart. We're the ones with the problem who can't take our eyes off your beauty 😍😊🌹

  • @johnsmith1953x
    @johnsmith1953x 2 місяці тому +7

    *"Sorry for being so hot and smart..."*
    Uhm...You need a need T-shirt. Why?
    You're neither hot nor smart.

    • @volvo09
      @volvo09 2 місяці тому

      It's a joke...
      Ever wonder where the old "dumb broad" saying comes from?
      (If you don't get it, people assume a decent looking woman is only where she is for everything but her brain).

    • @francescocommisso5352
      @francescocommisso5352 2 місяці тому +3

      LOL

  • @davethetech
    @davethetech 2 місяці тому

    Nice, I was 666th. ;P Thanks ThreatWire staff and @Hak5 for doing the world a service :)

  • @UncleBoobs
    @UncleBoobs 2 місяці тому +6

    i accept your apology 😩

  • @heyguesswhat_69
    @heyguesswhat_69 2 місяці тому

    Are you a hiring manager? Cuz I'm about to get fired. 😂