whats with all the vulnerabilities being found this month
@symbioticparasite62688 ай бұрын
Jacky be hacky
@archimedesbird34398 ай бұрын
@@johnsmith8981 Stop deifying AI, it's a tech bubble fed by illegally scraped data and nothing more.
@vigilantmug50288 ай бұрын
Better than feds and other "cyber security specialists" exploiting them as zero days under the radar
@dogyX38 ай бұрын
The XZ exploit sparked everyone to check their defences again.
@MaxiTimmi8 ай бұрын
@@johnsmith8981 I am sure cyber security companies would be able to use AI as well for their systems so it's unlikely that would happen
@jonahkrompart8 ай бұрын
It’s hilarious that this takes place over the device telemetry channel, AKA the spyware that Palo Alto highly encourages you to not opt out of
@JacobyB8 ай бұрын
because it collects errors 🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯🤯
@LailSidgar8 ай бұрын
@@JacobyB It collects errors. Good thing bugs are features and not errors.
@ARCNSPUDS8 ай бұрын
It doesn’t matter if telemetry is on or not
@jonahkrompart8 ай бұрын
@@ARCNSPUDS Palo specifically recommended in their advisory that you disable telemetry to mitigate the issue, I’m sure you know better than them
@kilosandkeyboards8 ай бұрын
@@jonahkrompart Nah, there was an update from PANW which states that telemetry does not need to be enabled for this CVE to be exploited.
@Jango19898 ай бұрын
That feeling when the firewall glows brighter than the fire...
@deef08 ай бұрын
I work in cybersec, got this one on my desk under NDA very late march. Patch was out when they announced it to the rest
@adrianfisher33498 ай бұрын
I wanted an enterprise grade firewall for my home network so I could gain work experience with it. I couldn't afford any of them I saw and then loads of flaws in them were announced. I then bought a workstation/server and installed OpenBSD on it and love it.
@adrianfisher33498 ай бұрын
@GhOs7-Operator WiFi isn't very good under OBSD but I used an old Asus router for that, which is connected to my firewall though and Ethernet cable and I have no problems there either. I put 16GB ECC RAM in (this was 2015) which I know is much more than would be needed but it let me setup part of it as a RAM disk so the SSD drive is almost only used during boot ups and software updates to help it last longer.
@UnlimitedPepsi8 ай бұрын
State sponsored threat actors seething hard rn.
@Immortal-market8 ай бұрын
This
@TheSuperBoyProject8 ай бұрын
No, I am fine
@spacemeter30018 ай бұрын
@@TheSuperBoyProjectBeing on unemployment benefits doesn't count as "state sponsored"
@UnlimitedPepsi8 ай бұрын
@@spacemeter3001 topkek
@jakedhale8 ай бұрын
@@spacemeter3001 lmao gg
@jonahhekmatyar8 ай бұрын
NSA must be seething this month
@PoposteriousExe-ph5em8 ай бұрын
Lol
@JosephValentine-o5w8 ай бұрын
Seeding***
@hvher8 ай бұрын
Month of vulnurabs
@Alfred-Neuman8 ай бұрын
Yeah wtf is happening?
@juho18828 ай бұрын
@@Alfred-Neumanthese are found all the time. people have just been making more videos of them lately
@zaremol27798 ай бұрын
This isn't a 0-day, this is an alphabet soup agency backdoor
@ruthlessadmin8 ай бұрын
I'm responsible for a pair of Fortigate appliances. We've had to patch out vulnerabilities before but we generally stay on top of it. While we are attacked relentlessly and constantly, we've so far never had a breech (at least not that we know of yet). What's frustrating, is I can't get upper management to take anything seriously, so we have a weak backup policy and no budget to do anything.
@spacemeter30018 ай бұрын
They'll learn once they get compromised
@chimagamer41578 ай бұрын
Maybe sell it to them like an insurance policy, you rather pay some money in order not to become bankrupt, incase it does go bad Because this would be the worst possible outcome.
@dracula77798 ай бұрын
@@spacemeter3001 hopefully, but some still don't
@Silentguy_8 ай бұрын
I manage one at work and a personal one at home. We’ve closed off as much as we can and enabled 2FA on basically everything but with how bad exploits have gotten over the past few years, I take a zero tolerance policy towards updating. If a new update drops, I send out a email saying internet will be offline for about 5 minutes at the end of the day and the only one that can tell me any different is my boss’s boss.
@YaySyu8 ай бұрын
Don't worry, my firewall has a firewall.
@Exigentable8 ай бұрын
good luck pal i'm 7 firewalls deep
@marconiandcheese72588 ай бұрын
Yo dawg I heard you liked firewalls so I got your firewall a firewall
@necktwister6668 ай бұрын
firewall²
@nitproject51938 ай бұрын
it doesn't matter if they are on a same network and one of them can be compromized
@elpsykongr008 ай бұрын
Firecube
@Daniel-sj2mu8 ай бұрын
It was over for Palo Alto once Professor Messer stopped working there
@fiverZ8 ай бұрын
Context?
@hakawatis8 ай бұрын
in 2016 we were only discovering maybe 10K-30K CVE's a year. in 2022 we were discovering 100,000 CVEs a year. in 2024 we're discovering 4x the amount of CVEs a year. goodluck blue team. this year is gonna be hell for you. 😭😭
@rohanofelvenpower55668 ай бұрын
get out of infosec, its an overworked industry and it will only get worse. bad career choice. like videogaming industry.
@syedibrahimkhalil7868 ай бұрын
@@rohanofelvenpower5566 lol with that mindset, I wonder what insecure world would we live in then. This actually give a survival bias, where in actual there is 'more' need of infosec than running out of it.
@markmonster33158 ай бұрын
@@rohanofelvenpower5566 Isn't that exactly the reason to get into it?
@rj7250a8 ай бұрын
@@markmonster3315if you enjoy regular overtime, 10 hours shifts, sometimes and earning 5x less than some dude typing SQL commands at a bank for 10 hours a week, sure. That is basically game dev industry, that is why i always say to new programmers to not do game dev. I do not know about cybersec industry, maybe it is not as bad, since it is more boring than game dev. The pay and working conditions of a programming job is proportional to how boring it is. - me, 2024
@lokeshchandak36608 ай бұрын
@@rj7250aso the more boring something is, the better the pay and the better the work conditions? I have a feeling you meant to say inversely proportional...
@sampatton1468 ай бұрын
Back door insisted by the glowies
@jer17768 ай бұрын
TLDR: Your firewall should have a firewall
@imjonkatz8 ай бұрын
When you wonder if it's a bug or a feature...
@JacobyB8 ай бұрын
???
@gandalfdaking8 ай бұрын
Schizo moment
@cunjoz8 ай бұрын
@@gandalfdaking glowie moment
@deadshxll8 ай бұрын
funnily enough, the Security+ certificate which is considered fundamental cert, provided by CompTIA, actually calls out that security controls themselves have the possibility to be vulnerable and open to attack vectors.
@chubbycatfish45738 ай бұрын
It's always something, isn't it?
@_ruddegar8 ай бұрын
Keeps me employed!
@dinguscollective18728 ай бұрын
@@_ruddegar pretty much why this shit is happening lmao. more jobs I guess
@_ruddegar8 ай бұрын
@dinguscollective1872 lol you might be on to something.
@ditrypand82738 ай бұрын
oh that swag "Won't fix" still gives me chuckle
@BJ-sq1si8 ай бұрын
Your security vulnerability discovery videos are my favorite
@isbestlizard8 ай бұрын
Oh another RCE/hard coded credentials vulnerability? Gee Palo Alto you sure do suck tonight.
@caine_inu8 ай бұрын
It's funny how I was looking at this in the morning & now you published a video about it.
@isbestlizard8 ай бұрын
Make a t-shirt with Monero-chan looking cute and I will buy one
@susguy4468 ай бұрын
💀
@spacemeter30018 ай бұрын
He should make one where her bare feet and them toes are visible 😛🦶👡
@gamtax8 ай бұрын
I thought he made a bunch long time ago...
@13thravenpurple948 ай бұрын
Excellent video 👍 Thank you 💜
@itswilliamanimate8 ай бұрын
government agencies stash of exploits getting discovered this month, huh... linux exploit giving ring 0 xz poorly escaped strings in windows this
@awesomecronk71838 ай бұрын
the windows one has been known of for a long time, getting a 10/10 CVE tagged on rust got it very famous very fast
@islantay57958 ай бұрын
Someone please tell me where did 0:21 came from. I have to know that 😭😭😭
@bradbeckett7 ай бұрын
It’s very obvious all these remote root backdoors are not simply accidents anymore.
@denerlkonig2778 ай бұрын
Thank you for the video
@andljoy8 ай бұрын
We are on an older panos so we are fine :).
@lukeskywalker21168 ай бұрын
Nice walkthrough. Thank you.
@raumfahreturschutze7 ай бұрын
The number of bugs in our systems is TOO DAMN HIGH!
@evccyr8 ай бұрын
Vulnerabilities playing April fools the entire month
@codemiesterbeats8 ай бұрын
Im too easily amused "please like and share it" Nice little animation around the like button... Who knows how long this has been a thing but neato
@tommy_salami1088 ай бұрын
It’s not exactly clear which name corresponds to which colors on the tor t shirts. Specifically confused about moondance and royal.
@Gbennett14258 ай бұрын
I wonder if this is how my university I go to got hacked into. Whoever it was critically damaged or wiped all the virtual machines and had access to tons of private information.
@alphaomega1548 ай бұрын
so then the exploit guard needed for this is something that can watch out the use of any commands on CSS file creation, or watching out the vailidity of the CSS creation itself.
@Max-mj4sp8 ай бұрын
How is that gonna affect Stock Prices of palo. How big of a deal are we talking about.
@HailScreaM778 ай бұрын
LOL i have worked in a bank that uses Palo alto Firewall, i wonder if they have telemetry on
@jvav8 ай бұрын
couple months ago there was fortinet that had a vulnerability
@ENNEN4208 ай бұрын
"D-disable telemetry to g-get it to stop? John you're smart, will the breach or disabling telemetry lose us more money? "Sir, the telemetry is for just the employees" "Then it's more valuable!!!" "..."
@asmod4n8 ай бұрын
Wait, their WEB UI is running on a Read/Write File System? Thats just asking for trouble.
@dimasskarabas8 ай бұрын
Hacking into someone’s router is the equivalent of “I’m in your walls”
@abiram33948 ай бұрын
i blame Obama for these bugs
@Kabodanki8 ай бұрын
yes obama and the hackers are for sure russians
@PoposteriousExe-ph5em8 ай бұрын
Aaajhhhhh BuGs 😢
@pajeetsingh8 ай бұрын
What's up with series of critical bugs in the last month? Are they making cyber false flag for force some laws? What's happening?
@ImZaDi-love8 ай бұрын
That hacker in the beginning wearing the mask looks like he was mixing and spinning some vinyl.
@PoposteriousExe-ph5em8 ай бұрын
Looooool
@MinuteBracelet8 ай бұрын
Critical RCE Theory
@Amipotsophspond8 ай бұрын
I wonder if you could build a toaster with out it being a smart appliance, do we have the technology or is it just a unattainable dream?
@eointhomas29148 ай бұрын
Any hospital or med facility I go too all have Palo Alto’s 😂
@JoeDueterte8 ай бұрын
More of these videos would be appreciated
@GmodFreak5558 ай бұрын
putty also has a vulnerability discovered where private keys can be exposed
@crimsonlion1008 ай бұрын
The only thing keeping Java from being destroyed as it deserves is Minecraft. I tell ya, if I never have to use, or see Java again, I will feel true happiness.
@zyriab57978 ай бұрын
Isn't the bedrock edition just Minecraft in C++ because of all the problems the Java edition caused? (Shitty GC, etc) You can still find nice MC clones written in other languages as well
@crimsonlion1008 ай бұрын
@@zyriab5797 No, I will never play that facsimile of what Minecraft is. The thing that made Minecraft great was BECAUSE it was written in a language like Java. Java is EASILY reverse engineered, and easily modded. That must stay in place for me to even consider it. Classicube comes CLOSE, but the fact that they restrict themselves to classic is very very unfortunate. Beta 1.7.3 is and has always been the best version of Minecraft. and things like Glowstone are so incomplete it isnt even worth it.
@Archbtw_8 ай бұрын
tf is up with all these vulnerabilities recently?
@rwxzig8 ай бұрын
That picture of Biden was epic :D
@koensampers55058 ай бұрын
Quite hilarious that I received multiple alerts at work from this incident lmao
@User-o5l2w8 ай бұрын
Can you do a video on kicksecure? Please 🙏
@crazy_dummie52408 ай бұрын
microsoft SSH man is the harambe of the NSA
@QuantumKurator8 ай бұрын
Vulns in all things held sacred - Linux, Rust, Palo...
@a_spe_ct8 ай бұрын
WEF sponsored code
@saltypureblood89878 ай бұрын
First you fix zee bugs, then you eat zee bugs.
@kameronbriggs2358 ай бұрын
Once this stuff is used and smarter people integrate into an existing tools with more persistence, good luck.
@froozynoobfan8 ай бұрын
please correct the video, they updated the page, disabeling telemetry does not mitigate the vulnerability!!!
@kanshank8 ай бұрын
Again ? Are we doing good those days or bad ? not sure.
@Not_cee8 ай бұрын
Does firewalls stop ddos
@kawalier18 ай бұрын
Which cloud?
@PiotrPavel7 ай бұрын
not only Rust, also GO or c# was recomended
@andreassa8 ай бұрын
Yo Kenny, why the hell does Google say you are a “Musical Artist”? Drop the beats, homie.
@asddw49988 ай бұрын
GOOD MORNING SIRS PLEASE REMIND TO DO THE NEEDFUL AND SFC /SCANNOW
@jeonghutamilim22598 ай бұрын
"Security" products are bigger target than browsers...
@signal658 ай бұрын
💥💥💥💥
@doublesushi59908 ай бұрын
*1:44*
@Leo_Aqua8 ай бұрын
We have a LOT of 10/10 Critical CVEs these days
@zyriab57978 ай бұрын
CSS confirmed to be evil
@PoposteriousExe-ph5em8 ай бұрын
Yes 😅
@tetttettamilli67618 ай бұрын
@MO - "Gay Agenda"
@DeltaNrOne8 ай бұрын
Firewall you had 1 job!
@nasimfaheemalquadir8 ай бұрын
I don't even use a firewall on any of my GNU systems.
@b6yg8 ай бұрын
Can you make a don't mess with taxes shirt? on your store?
@abe-danger8 ай бұрын
third major bug this month, woo!
@PoposteriousExe-ph5em8 ай бұрын
WOOOOOOO!!! 5 MILLION LEFT!!!
@hombre3568 ай бұрын
This is going to keep the cybersecurity team at my company pulling their hair out as we use global protect. Glad I am not them.
@zachalam22328 ай бұрын
Not really… just disable telemetry, apply threat content updates, or upgrade the OS
@n6ra8 ай бұрын
The cursed month
@yesyesyesgrill-ir2ur8 ай бұрын
bro what is going on rn with all the exploits
@Nik-rx9rj8 ай бұрын
Yooooooo, another one?!?!?!
@JabbaTiure8 ай бұрын
Build your own Opnsense firewall. Problem sidestepped.
@zdrux8 ай бұрын
My employer uses PaloAlto and GlobalProtect for our VPN lol
@realhumanbeingyesyesveryreal8 ай бұрын
Chat, are we fucked?
@OleksandrSe8 ай бұрын
Oh boy)
@lightfox118 ай бұрын
This video is a based win
@___gg4218 ай бұрын
just assume all your software has vulnerabilities
@lordbarron33528 ай бұрын
Tldr: It's because they didn't install McAfee
@levigeorge91407 ай бұрын
See, the firewall vulnerabilities only affect you if you actually use a firewall. There is only one solution here.
@IQof28 ай бұрын
I think Palo Alto is losing control of their code base maintainability.
@thetransferaccount45868 ай бұрын
nice one there
@linuxguy11998 ай бұрын
Everybody is getting on the hype train for Rust thinking it's the magic bullet to all their problems. Just like Java was the magic bullet back in the 2010s. It's idiotic to suggest a programming language can be the goto solution for solving security problems in software that is fundamentally not secure.
@haythamkenway15618 ай бұрын
you really need to take care of your comment section. full of bots and spammers.
@Heisenberg3558 ай бұрын
When you say the letter "s" its really loud and sharp. You need a pop filter or edit it in post, its unbearable at loud volume
@wichu71318 ай бұрын
wsg
@ASaltyAcc8 ай бұрын
Welp lets see this shit
@ads-baisgreenock97374 ай бұрын
I dont use a firewall ..i dont use AV my password is the same across all my devices and has been since i was online.. i just hope haxxors see my pathetic shit and move on to somwone more interesting. Is rather be hacked by BH oe RH than have an active attack from NSA or whatever tho.
@ads-baisgreenock97374 ай бұрын
Dont use firewalls AV bs ....people they dont need your phone keyboard , mic , camera as intel now ....remote neural monitoring is here
@Mr.Beauregarde8 ай бұрын
Hevking first
@DUMBDUDEGAMER8 ай бұрын
So... this is extremely similar to the Solar Winds Orion supply chain attack, with even telemetry being a key part of the attack.
@immameme8 ай бұрын
Firewall situation and Imma1st Don't take my comments seriously. It's only a meme