Zero Day Bug Found in Popular Firewalls

  Рет қаралды 61,830

Mental Outlaw

Mental Outlaw

Күн бұрын

Пікірлер: 234
@EmM-ko7mu
@EmM-ko7mu 8 ай бұрын
whats with all the vulnerabilities being found this month
@symbioticparasite6268
@symbioticparasite6268 8 ай бұрын
Jacky be hacky
@archimedesbird3439
@archimedesbird3439 8 ай бұрын
@@johnsmith8981 Stop deifying AI, it's a tech bubble fed by illegally scraped data and nothing more.
@vigilantmug5028
@vigilantmug5028 8 ай бұрын
Better than feds and other "cyber security specialists" exploiting them as zero days under the radar
@dogyX3
@dogyX3 8 ай бұрын
The XZ exploit sparked everyone to check their defences again.
@MaxiTimmi
@MaxiTimmi 8 ай бұрын
@@johnsmith8981 I am sure cyber security companies would be able to use AI as well for their systems so it's unlikely that would happen
@jonahkrompart
@jonahkrompart 8 ай бұрын
It’s hilarious that this takes place over the device telemetry channel, AKA the spyware that Palo Alto highly encourages you to not opt out of
@JacobyB
@JacobyB 8 ай бұрын
because it collects errors 🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯
@LailSidgar
@LailSidgar 8 ай бұрын
@@JacobyB It collects errors. Good thing bugs are features and not errors.
@ARCNSPUDS
@ARCNSPUDS 8 ай бұрын
It doesn’t matter if telemetry is on or not
@jonahkrompart
@jonahkrompart 8 ай бұрын
@@ARCNSPUDS Palo specifically recommended in their advisory that you disable telemetry to mitigate the issue, I’m sure you know better than them
@kilosandkeyboards
@kilosandkeyboards 8 ай бұрын
@@jonahkrompart Nah, there was an update from PANW which states that telemetry does not need to be enabled for this CVE to be exploited.
@Jango1989
@Jango1989 8 ай бұрын
That feeling when the firewall glows brighter than the fire...
@deef0
@deef0 8 ай бұрын
I work in cybersec, got this one on my desk under NDA very late march. Patch was out when they announced it to the rest
@adrianfisher3349
@adrianfisher3349 8 ай бұрын
I wanted an enterprise grade firewall for my home network so I could gain work experience with it. I couldn't afford any of them I saw and then loads of flaws in them were announced. I then bought a workstation/server and installed OpenBSD on it and love it.
@adrianfisher3349
@adrianfisher3349 8 ай бұрын
@GhOs7-Operator WiFi isn't very good under OBSD but I used an old Asus router for that, which is connected to my firewall though and Ethernet cable and I have no problems there either. I put 16GB ECC RAM in (this was 2015) which I know is much more than would be needed but it let me setup part of it as a RAM disk so the SSD drive is almost only used during boot ups and software updates to help it last longer.
@UnlimitedPepsi
@UnlimitedPepsi 8 ай бұрын
State sponsored threat actors seething hard rn.
@Immortal-market
@Immortal-market 8 ай бұрын
This
@TheSuperBoyProject
@TheSuperBoyProject 8 ай бұрын
No, I am fine
@spacemeter3001
@spacemeter3001 8 ай бұрын
​@@TheSuperBoyProjectBeing on unemployment benefits doesn't count as "state sponsored"
@UnlimitedPepsi
@UnlimitedPepsi 8 ай бұрын
@@spacemeter3001 topkek
@jakedhale
@jakedhale 8 ай бұрын
@@spacemeter3001 lmao gg
@jonahhekmatyar
@jonahhekmatyar 8 ай бұрын
NSA must be seething this month
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 8 ай бұрын
Lol
@JosephValentine-o5w
@JosephValentine-o5w 8 ай бұрын
Seeding***
@hvher
@hvher 8 ай бұрын
Month of vulnurabs
@Alfred-Neuman
@Alfred-Neuman 8 ай бұрын
Yeah wtf is happening?
@juho1882
@juho1882 8 ай бұрын
​@@Alfred-Neumanthese are found all the time. people have just been making more videos of them lately
@zaremol2779
@zaremol2779 8 ай бұрын
This isn't a 0-day, this is an alphabet soup agency backdoor
@ruthlessadmin
@ruthlessadmin 8 ай бұрын
I'm responsible for a pair of Fortigate appliances. We've had to patch out vulnerabilities before but we generally stay on top of it. While we are attacked relentlessly and constantly, we've so far never had a breech (at least not that we know of yet). What's frustrating, is I can't get upper management to take anything seriously, so we have a weak backup policy and no budget to do anything.
@spacemeter3001
@spacemeter3001 8 ай бұрын
They'll learn once they get compromised
@chimagamer4157
@chimagamer4157 8 ай бұрын
Maybe sell it to them like an insurance policy, you rather pay some money in order not to become bankrupt, incase it does go bad Because this would be the worst possible outcome.
@dracula7779
@dracula7779 8 ай бұрын
@@spacemeter3001 hopefully, but some still don't
@Silentguy_
@Silentguy_ 8 ай бұрын
I manage one at work and a personal one at home. We’ve closed off as much as we can and enabled 2FA on basically everything but with how bad exploits have gotten over the past few years, I take a zero tolerance policy towards updating. If a new update drops, I send out a email saying internet will be offline for about 5 minutes at the end of the day and the only one that can tell me any different is my boss’s boss.
@YaySyu
@YaySyu 8 ай бұрын
Don't worry, my firewall has a firewall.
@Exigentable
@Exigentable 8 ай бұрын
good luck pal i'm 7 firewalls deep
@marconiandcheese7258
@marconiandcheese7258 8 ай бұрын
Yo dawg I heard you liked firewalls so I got your firewall a firewall
@necktwister666
@necktwister666 8 ай бұрын
firewall²
@nitproject5193
@nitproject5193 8 ай бұрын
it doesn't matter if they are on a same network and one of them can be compromized
@elpsykongr00
@elpsykongr00 8 ай бұрын
Firecube
@Daniel-sj2mu
@Daniel-sj2mu 8 ай бұрын
It was over for Palo Alto once Professor Messer stopped working there
@fiverZ
@fiverZ 8 ай бұрын
Context?
@hakawatis
@hakawatis 8 ай бұрын
in 2016 we were only discovering maybe 10K-30K CVE's a year. in 2022 we were discovering 100,000 CVEs a year. in 2024 we're discovering 4x the amount of CVEs a year. goodluck blue team. this year is gonna be hell for you. 😭😭
@rohanofelvenpower5566
@rohanofelvenpower5566 8 ай бұрын
get out of infosec, its an overworked industry and it will only get worse. bad career choice. like videogaming industry.
@syedibrahimkhalil786
@syedibrahimkhalil786 8 ай бұрын
@@rohanofelvenpower5566 lol with that mindset, I wonder what insecure world would we live in then. This actually give a survival bias, where in actual there is 'more' need of infosec than running out of it.
@markmonster3315
@markmonster3315 8 ай бұрын
@@rohanofelvenpower5566 Isn't that exactly the reason to get into it?
@rj7250a
@rj7250a 8 ай бұрын
​@@markmonster3315if you enjoy regular overtime, 10 hours shifts, sometimes and earning 5x less than some dude typing SQL commands at a bank for 10 hours a week, sure. That is basically game dev industry, that is why i always say to new programmers to not do game dev. I do not know about cybersec industry, maybe it is not as bad, since it is more boring than game dev. The pay and working conditions of a programming job is proportional to how boring it is. - me, 2024
@lokeshchandak3660
@lokeshchandak3660 8 ай бұрын
​@@rj7250aso the more boring something is, the better the pay and the better the work conditions? I have a feeling you meant to say inversely proportional...
@sampatton146
@sampatton146 8 ай бұрын
Back door insisted by the glowies
@jer1776
@jer1776 8 ай бұрын
TLDR: Your firewall should have a firewall
@imjonkatz
@imjonkatz 8 ай бұрын
When you wonder if it's a bug or a feature...
@JacobyB
@JacobyB 8 ай бұрын
???
@gandalfdaking
@gandalfdaking 8 ай бұрын
Schizo moment
@cunjoz
@cunjoz 8 ай бұрын
@@gandalfdaking glowie moment
@deadshxll
@deadshxll 8 ай бұрын
funnily enough, the Security+ certificate which is considered fundamental cert, provided by CompTIA, actually calls out that security controls themselves have the possibility to be vulnerable and open to attack vectors.
@chubbycatfish4573
@chubbycatfish4573 8 ай бұрын
It's always something, isn't it?
@_ruddegar
@_ruddegar 8 ай бұрын
Keeps me employed!
@dinguscollective1872
@dinguscollective1872 8 ай бұрын
@@_ruddegar pretty much why this shit is happening lmao. more jobs I guess
@_ruddegar
@_ruddegar 8 ай бұрын
@dinguscollective1872 lol you might be on to something.
@ditrypand8273
@ditrypand8273 8 ай бұрын
oh that swag "Won't fix" still gives me chuckle
@BJ-sq1si
@BJ-sq1si 8 ай бұрын
Your security vulnerability discovery videos are my favorite
@isbestlizard
@isbestlizard 8 ай бұрын
Oh another RCE/hard coded credentials vulnerability? Gee Palo Alto you sure do suck tonight.
@caine_inu
@caine_inu 8 ай бұрын
It's funny how I was looking at this in the morning & now you published a video about it.
@isbestlizard
@isbestlizard 8 ай бұрын
Make a t-shirt with Monero-chan looking cute and I will buy one
@susguy446
@susguy446 8 ай бұрын
💀
@spacemeter3001
@spacemeter3001 8 ай бұрын
He should make one where her bare feet and them toes are visible 😛🦶👡
@gamtax
@gamtax 8 ай бұрын
I thought he made a bunch long time ago...
@13thravenpurple94
@13thravenpurple94 8 ай бұрын
Excellent video 👍 Thank you 💜
@itswilliamanimate
@itswilliamanimate 8 ай бұрын
government agencies stash of exploits getting discovered this month, huh... linux exploit giving ring 0 xz poorly escaped strings in windows this
@awesomecronk7183
@awesomecronk7183 8 ай бұрын
the windows one has been known of for a long time, getting a 10/10 CVE tagged on rust got it very famous very fast
@islantay5795
@islantay5795 8 ай бұрын
Someone please tell me where did 0:21 came from. I have to know that 😭😭😭
@bradbeckett
@bradbeckett 7 ай бұрын
It’s very obvious all these remote root backdoors are not simply accidents anymore.
@denerlkonig277
@denerlkonig277 8 ай бұрын
Thank you for the video
@andljoy
@andljoy 8 ай бұрын
We are on an older panos so we are fine :).
@lukeskywalker2116
@lukeskywalker2116 8 ай бұрын
Nice walkthrough. Thank you.
@raumfahreturschutze
@raumfahreturschutze 7 ай бұрын
The number of bugs in our systems is TOO DAMN HIGH!
@evccyr
@evccyr 8 ай бұрын
Vulnerabilities playing April fools the entire month
@codemiesterbeats
@codemiesterbeats 8 ай бұрын
Im too easily amused "please like and share it" Nice little animation around the like button... Who knows how long this has been a thing but neato
@tommy_salami108
@tommy_salami108 8 ай бұрын
It’s not exactly clear which name corresponds to which colors on the tor t shirts. Specifically confused about moondance and royal.
@Gbennett1425
@Gbennett1425 8 ай бұрын
I wonder if this is how my university I go to got hacked into. Whoever it was critically damaged or wiped all the virtual machines and had access to tons of private information.
@alphaomega154
@alphaomega154 8 ай бұрын
so then the exploit guard needed for this is something that can watch out the use of any commands on CSS file creation, or watching out the vailidity of the CSS creation itself.
@Max-mj4sp
@Max-mj4sp 8 ай бұрын
How is that gonna affect Stock Prices of palo. How big of a deal are we talking about.
@HailScreaM77
@HailScreaM77 8 ай бұрын
LOL i have worked in a bank that uses Palo alto Firewall, i wonder if they have telemetry on
@jvav
@jvav 8 ай бұрын
couple months ago there was fortinet that had a vulnerability
@ENNEN420
@ENNEN420 8 ай бұрын
"D-disable telemetry to g-get it to stop? John you're smart, will the breach or disabling telemetry lose us more money? "Sir, the telemetry is for just the employees" "Then it's more valuable!!!" "..."
@asmod4n
@asmod4n 8 ай бұрын
Wait, their WEB UI is running on a Read/Write File System? Thats just asking for trouble.
@dimasskarabas
@dimasskarabas 8 ай бұрын
Hacking into someone’s router is the equivalent of “I’m in your walls”
@abiram3394
@abiram3394 8 ай бұрын
i blame Obama for these bugs
@Kabodanki
@Kabodanki 8 ай бұрын
yes obama and the hackers are for sure russians
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 8 ай бұрын
Aaajhhhhh BuGs 😢
@pajeetsingh
@pajeetsingh 8 ай бұрын
What's up with series of critical bugs in the last month? Are they making cyber false flag for force some laws? What's happening?
@ImZaDi-love
@ImZaDi-love 8 ай бұрын
That hacker in the beginning wearing the mask looks like he was mixing and spinning some vinyl.
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 8 ай бұрын
Looooool
@MinuteBracelet
@MinuteBracelet 8 ай бұрын
Critical RCE Theory
@Amipotsophspond
@Amipotsophspond 8 ай бұрын
I wonder if you could build a toaster with out it being a smart appliance, do we have the technology or is it just a unattainable dream?
@eointhomas2914
@eointhomas2914 8 ай бұрын
Any hospital or med facility I go too all have Palo Alto’s 😂
@JoeDueterte
@JoeDueterte 8 ай бұрын
More of these videos would be appreciated
@GmodFreak555
@GmodFreak555 8 ай бұрын
putty also has a vulnerability discovered where private keys can be exposed
@crimsonlion100
@crimsonlion100 8 ай бұрын
The only thing keeping Java from being destroyed as it deserves is Minecraft. I tell ya, if I never have to use, or see Java again, I will feel true happiness.
@zyriab5797
@zyriab5797 8 ай бұрын
Isn't the bedrock edition just Minecraft in C++ because of all the problems the Java edition caused? (Shitty GC, etc) You can still find nice MC clones written in other languages as well
@crimsonlion100
@crimsonlion100 8 ай бұрын
@@zyriab5797 No, I will never play that facsimile of what Minecraft is. The thing that made Minecraft great was BECAUSE it was written in a language like Java. Java is EASILY reverse engineered, and easily modded. That must stay in place for me to even consider it. Classicube comes CLOSE, but the fact that they restrict themselves to classic is very very unfortunate. Beta 1.7.3 is and has always been the best version of Minecraft. and things like Glowstone are so incomplete it isnt even worth it.
@Archbtw_
@Archbtw_ 8 ай бұрын
tf is up with all these vulnerabilities recently?
@rwxzig
@rwxzig 8 ай бұрын
That picture of Biden was epic :D
@koensampers5505
@koensampers5505 8 ай бұрын
Quite hilarious that I received multiple alerts at work from this incident lmao
@User-o5l2w
@User-o5l2w 8 ай бұрын
Can you do a video on kicksecure? Please 🙏
@crazy_dummie5240
@crazy_dummie5240 8 ай бұрын
microsoft SSH man is the harambe of the NSA
@QuantumKurator
@QuantumKurator 8 ай бұрын
Vulns in all things held sacred - Linux, Rust, Palo...
@a_spe_ct
@a_spe_ct 8 ай бұрын
WEF sponsored code
@saltypureblood8987
@saltypureblood8987 8 ай бұрын
First you fix zee bugs, then you eat zee bugs.
@kameronbriggs235
@kameronbriggs235 8 ай бұрын
Once this stuff is used and smarter people integrate into an existing tools with more persistence, good luck.
@froozynoobfan
@froozynoobfan 8 ай бұрын
please correct the video, they updated the page, disabeling telemetry does not mitigate the vulnerability!!!
@kanshank
@kanshank 8 ай бұрын
Again ? Are we doing good those days or bad ? not sure.
@Not_cee
@Not_cee 8 ай бұрын
Does firewalls stop ddos
@kawalier1
@kawalier1 8 ай бұрын
Which cloud?
@PiotrPavel
@PiotrPavel 7 ай бұрын
not only Rust, also GO or c# was recomended
@andreassa
@andreassa 8 ай бұрын
Yo Kenny, why the hell does Google say you are a “Musical Artist”? Drop the beats, homie.
@asddw4998
@asddw4998 8 ай бұрын
GOOD MORNING SIRS PLEASE REMIND TO DO THE NEEDFUL AND SFC /SCANNOW
@jeonghutamilim2259
@jeonghutamilim2259 8 ай бұрын
"Security" products are bigger target than browsers...
@signal65
@signal65 8 ай бұрын
💥💥💥💥
@doublesushi5990
@doublesushi5990 8 ай бұрын
*1:44*
@Leo_Aqua
@Leo_Aqua 8 ай бұрын
We have a LOT of 10/10 Critical CVEs these days
@zyriab5797
@zyriab5797 8 ай бұрын
CSS confirmed to be evil
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 8 ай бұрын
Yes 😅
@tetttettamilli6761
@tetttettamilli6761 8 ай бұрын
@MO - "Gay Agenda"
@DeltaNrOne
@DeltaNrOne 8 ай бұрын
Firewall you had 1 job!
@nasimfaheemalquadir
@nasimfaheemalquadir 8 ай бұрын
I don't even use a firewall on any of my GNU systems.
@b6yg
@b6yg 8 ай бұрын
Can you make a don't mess with taxes shirt? on your store?
@abe-danger
@abe-danger 8 ай бұрын
third major bug this month, woo!
@PoposteriousExe-ph5em
@PoposteriousExe-ph5em 8 ай бұрын
WOOOOOOO!!! 5 MILLION LEFT!!!
@hombre356
@hombre356 8 ай бұрын
This is going to keep the cybersecurity team at my company pulling their hair out as we use global protect. Glad I am not them.
@zachalam2232
@zachalam2232 8 ай бұрын
Not really… just disable telemetry, apply threat content updates, or upgrade the OS
@n6ra
@n6ra 8 ай бұрын
The cursed month
@yesyesyesgrill-ir2ur
@yesyesyesgrill-ir2ur 8 ай бұрын
bro what is going on rn with all the exploits
@Nik-rx9rj
@Nik-rx9rj 8 ай бұрын
Yooooooo, another one?!?!?!
@JabbaTiure
@JabbaTiure 8 ай бұрын
Build your own Opnsense firewall. Problem sidestepped.
@zdrux
@zdrux 8 ай бұрын
My employer uses PaloAlto and GlobalProtect for our VPN lol
@realhumanbeingyesyesveryreal
@realhumanbeingyesyesveryreal 8 ай бұрын
Chat, are we fucked?
@OleksandrSe
@OleksandrSe 8 ай бұрын
Oh boy)
@lightfox11
@lightfox11 8 ай бұрын
This video is a based win
@___gg421
@___gg421 8 ай бұрын
just assume all your software has vulnerabilities
@lordbarron3352
@lordbarron3352 8 ай бұрын
Tldr: It's because they didn't install McAfee
@levigeorge9140
@levigeorge9140 7 ай бұрын
See, the firewall vulnerabilities only affect you if you actually use a firewall. There is only one solution here.
@IQof2
@IQof2 8 ай бұрын
I think Palo Alto is losing control of their code base maintainability.
@thetransferaccount4586
@thetransferaccount4586 8 ай бұрын
nice one there
@linuxguy1199
@linuxguy1199 8 ай бұрын
Everybody is getting on the hype train for Rust thinking it's the magic bullet to all their problems. Just like Java was the magic bullet back in the 2010s. It's idiotic to suggest a programming language can be the goto solution for solving security problems in software that is fundamentally not secure.
@haythamkenway1561
@haythamkenway1561 8 ай бұрын
you really need to take care of your comment section. full of bots and spammers.
@Heisenberg355
@Heisenberg355 8 ай бұрын
When you say the letter "s" its really loud and sharp. You need a pop filter or edit it in post, its unbearable at loud volume
@wichu7131
@wichu7131 8 ай бұрын
wsg
@ASaltyAcc
@ASaltyAcc 8 ай бұрын
Welp lets see this shit
@ads-baisgreenock9737
@ads-baisgreenock9737 4 ай бұрын
I dont use a firewall ..i dont use AV my password is the same across all my devices and has been since i was online.. i just hope haxxors see my pathetic shit and move on to somwone more interesting. Is rather be hacked by BH oe RH than have an active attack from NSA or whatever tho.
@ads-baisgreenock9737
@ads-baisgreenock9737 4 ай бұрын
Dont use firewalls AV bs ....people they dont need your phone keyboard , mic , camera as intel now ....remote neural monitoring is here
@Mr.Beauregarde
@Mr.Beauregarde 8 ай бұрын
Hevking first
@DUMBDUDEGAMER
@DUMBDUDEGAMER 8 ай бұрын
So... this is extremely similar to the Solar Winds Orion supply chain attack, with even telemetry being a key part of the attack.
@immameme
@immameme 8 ай бұрын
Firewall situation and Imma1st Don't take my comments seriously. It's only a meme
Windows Has a Critical Command Injection Bug
11:25
Mental Outlaw
Рет қаралды 109 М.
researchers find unfixable bug in apple computers
8:32
Low Level
Рет қаралды 718 М.
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19
Try this prank with your friends 😂 @karina-kola
00:18
Andrey Grechka
Рет қаралды 9 МЛН
Coomer PSYOPS - The New Weapon of War
9:24
Mental Outlaw
Рет қаралды 228 М.
Host Your Own Encrypted DNS Server
24:21
Mental Outlaw
Рет қаралды 135 М.
why are more people not talking about this?
5:24
Low Level
Рет қаралды 118 М.
Google Has Been Lying About Their Search Results
11:51
Mental Outlaw
Рет қаралды 400 М.
if you view this image, YOU GET HACKED.
8:40
Low Level
Рет қаралды 391 М.
The Biggest Piracy Bust in History
8:16
Mental Outlaw
Рет қаралды 310 М.
Wubuntu - An Illegal Windows Like Distro
16:56
Mental Outlaw
Рет қаралды 394 М.
Stop Using Tor With VPNs
11:41
Mental Outlaw
Рет қаралды 974 М.
How to Smuggle Data out of the Network with Ping
16:54
Plaintext Packets
Рет қаралды 119 М.