Palo Alto Networks confirms mystery zero day now exploited: No patch, no CVE (www.thestack.technology)
from Joker@sh.itjust.works to technology@lemmy.world on 16 Nov 16:02
https://sh.itjust.works/post/28184962

#technology

threaded - newest

thejml@lemm.ee on 16 Nov 17:19 next collapse

with the US-based security vendor on November 11 urging customers to pull their management interfaces off the public internet or restrict them to known IP addresses.

Why would you EVER put management interfaces on the public internet? What terrible decisions led them down that path? VPN is so quick and easy at a minimum.

Evotech@lemmy.world on 16 Nov 17:46 next collapse

I know right, 99% of these caves are against management interfaces too

AmidFuror@fedia.io on 16 Nov 19:25 collapse

Paleo Alto?

corsicanguppy@lemmy.ca on 16 Nov 19:42 collapse

Saw the writing on the wall, there.

qjkxbmwvz@startrek.website on 16 Nov 19:43 next collapse

The network gear I manage is only accessible via VPN, or from a trusted internal network…

…and by the gear I manage, I mean my home network (a router and a few managed switches and access points). If a doofus like me can set it up for my home, I’d think that actual companies would be able to figure it out, too.

catloaf@lemm.ee on 16 Nov 22:00 next collapse

Management interfaces shouldn’t even be accessible from the general LAN.

jdeath@lemm.ee on 16 Nov 22:54 collapse

zero trust?

lnxtx@feddit.nl on 16 Nov 17:19 collapse

www.paloaltonetworks.comLeader in Cybersecurity Protection & Software for the Modern Enterprises - Palo Alto Networks

Thanks, I will avoid them.

VonReposti@feddit.dk on 16 Nov 18:04 collapse

They’re spamming all web logs too with an advertisement for their services in the user agent. I decided to ban them from all my websites because the logs took up too much space.

TheKMAP@lemmynsfw.com on 16 Nov 22:12 collapse

lmao that’s not an ad, dude.

VonReposti@feddit.dk on 17 Nov 05:49 collapse

They’re saying who they are, what they do, and are linking to their website and sometimes sends hundreds of requests in a minute. It might not say "For only €49.99 you can get your very own thing!”, but that does not mean they aren’t throwing their name up in every website owner’s arse whether they like it or not.

TheKMAP@lemmynsfw.com on 17 Nov 06:41 collapse

It’s so you know who is scanning you.

VonReposti@feddit.dk on 17 Nov 07:39 collapse

That could have been done by just having a single entry called GoogleBot or BingBot, not an entire sentence explaining their product offering let alone hundreds of times a minute.