Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Palo Alto Networks confirms mystery zero day now exploited

⁨160⁩ ⁨likes⁩

Submitted ⁨⁨5⁩ ⁨months⁩ ago⁩ by ⁨Joker@sh.itjust.works⁩ to ⁨technology@lemmy.world⁩

https://www.thestack.technology/palo-alto-networks-zero-day-exploited/

source

Comments

Sort:hotnewtop
  • thejml@lemm.ee ⁨5⁩ ⁨months⁩ ago

    with the US-based security vendor on November 11 urging customers to pull their management interfaces off the public internet or restrict them to known IP addresses.

    Why would you EVER put management interfaces on the public internet? What terrible decisions led them down that path? VPN is so quick and easy at a minimum.

    source
    • qjkxbmwvz@startrek.website ⁨5⁩ ⁨months⁩ ago

      The network gear I manage is only accessible via VPN, or from a trusted internal network…

      …and by “my network” I mean my home network (a router and a few managed switches and access points). If a doofus like me can set it up for my home, I’d think that actual companies would be able to figure it out, too.

      source
    • catloaf@lemm.ee ⁨5⁩ ⁨months⁩ ago

      Management interfaces shouldn’t even be accessible from the general LAN.

      source
    • Evotech@lemmy.world ⁨5⁩ ⁨months⁩ ago

      I know right, 99% of these caves are against management interfaces too

      source
    • cyberpunk007@lemmy.ca ⁨5⁩ ⁨months⁩ ago

      Once I read this I just stopped lol. You almost deserve to be explored if you do this, this is like security 101.

      source
    • jdeath@lemm.ee ⁨5⁩ ⁨months⁩ ago

      zero trust?

      source
  • lnxtx@feddit.nl ⁨5⁩ ⁨months⁩ ago

    www.paloaltonetworks.com → Leader in Cybersecurity Protection & Software for the Modern Enterprises - Palo Alto Networks

    Thanks, I will avoid them.

    source
    • VonReposti@feddit.dk ⁨5⁩ ⁨months⁩ ago

      They’re spamming all web logs too with an advertisement for their services in the user agent. I decided to ban them from all my websites because the logs took up too much space.

      source
      • TheKMAP@lemmynsfw.com ⁨5⁩ ⁨months⁩ ago

        lmao that’s not an ad, dude.

        source
        • -> View More Comments
      • mostlikelyaperson@lemmy.world ⁨5⁩ ⁨months⁩ ago

        Yeah fuck them.

        source
    • cyberpunk007@lemmy.ca ⁨5⁩ ⁨months⁩ ago

      “urging customers to pull their management interfaces off the public internet or restrict them to known IP addresses.”

      Sounds more like pebkac and less of a big deal. Management interface should be in your management VLAN, plus I don’t know another vendor that can touch them in terms of security features.

      source