Cybersecurity News: Palo Alto PAN-OS Vulnerability & Sisense Security Incidents

  Рет қаралды 229

risk3sixty

risk3sixty

Күн бұрын

Join Cory in today's quick 10-minute InfoSec Exec BLUF as he breaks down the recent critical vulnerability in Palo Alto's PAN-OS and the security incident involving Sisense.
Stay informed on the latest cybersecurity threats and updates in just minutes every week! Plus, don't forget to access premium content on penetration testing with our exclusive ROI calculator: risk3sixty.com/whitepaper/pen...
Palo Alto PAN-OS Critical Vulnerability
Executive Summary:
A critical command injection vulnerability was discovered in Palo Alto Networks PAN-OS software that affects firewalls running PAN-OS versions 10.2, 11.0, and 11.1. An unauthenticated attacker can exploit this vulnerability to execute arbitrary code with root privileges on the firewall, providing control over the device.
The impact of a successful exploit of this issue can be rated as ‘Critical’. Palo Alto Networks has released hotfixes to address CVE-2024-3400 for version 11.1 of PAN-OS. However, patches are not yet available for versions 10.2 or 11.0. It is recommended to update the PAN-OS device to version 11.1 if possible. In the meantime, there are a few steps that can be taken to mitigate the risk of exploitation - Specific threat signatures related to this issue should be enabled and device telemetry should be disabled.
Additional Reading:
www.bleepingcomputer.com/news...
www.bleepingcomputer.com/news...
Sisense Security Incident
Executive Summary:
In April 2024, data analytics platform provider Sisense suffered a security breach. The exact nature of the breach is still under investigation, but it is believed that attackers gained access to a Sisense GitLab code repository and used stolen credentials to compromise cloud servers storing customer data.
The full extent of the Sisense breach is unknown, but affected organizations should immediately perform password and credential resets on all assets connected to the Sisense platform including user and database passwords, revocation of certificates used for authentication, API keys, and to invalidate any Access Tokens.
Additional Reading:
krebsonsecurity.com/2024/04/w...
www.cisa.gov/news-events/aler...

Пікірлер
The CISO Paradox
28:01
Dr Eric Cole
Рет қаралды 830
PCI DSS Basics: Everything You Need to Get PCI DSS Certified
33:37
Comfortable 🤣 #comedy #funny
00:34
Micky Makeover
Рет қаралды 12 МЛН
A little girl was shy at her first ballet lesson #shorts
00:35
Fabiosa Animated
Рет қаралды 17 МЛН
IQ Level: 10000
00:10
Younes Zarou
Рет қаралды 12 МЛН
why are more people not talking about this?
5:24
Low Level Learning
Рет қаралды 117 М.
NIST Cybersecurity History with Dr. Ron Ross
30:05
GRC Academy
Рет қаралды 718
Cybersecurity Architecture: Application Security
16:36
IBM Technology
Рет қаралды 58 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 468 М.
Stop, Intel’s Already Dead! - AMD Ryzen 9600X & 9700X Review
13:47
Linus Tech Tips
Рет қаралды 1 МЛН
Fortinet | ZTNA - Better Secure Access to Applications for All Users
58:35
Switchshop - Network Specialists
Рет қаралды 18 М.
Common Types Of Network Security Vulnerabilities | PurpleSec
21:24
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Dave's Garage
Рет қаралды 2,1 МЛН
Сколько реально стоит ПК Величайшего?
0:37
Rate This Smartphone Cooler Set-up ⭐
0:10
Shakeuptech
Рет қаралды 7 МЛН
Частая ошибка геймеров? 😐 Dareu A710X
1:00
Вэйми
Рет қаралды 5 МЛН
Лучший браузер!
0:27
Honey Montana
Рет қаралды 1,1 МЛН
Это - iPhone 16!
16:29
Rozetked
Рет қаралды 453 М.