A free webinar series featuring industry leaders from Harbour.Space University’s faculty of practicing professionals, sharing valuable content and insiders’ knowledge that you don’t learn in traditional classrooms!
Details about new security vulnerabilities in SD-WAN solution. There is no authentication between cloud SilverPeak’s Portal on the Internet and customers’ EdgeConnect devices. EdgeConnect doesn’t authenticate Portal. Portal can execute any command on EdgeConnect via REST API.
The IPsec UDP protocol implementation in SilverPeak EdgeConnect product fails to provide the claimed perfect forward secrecy property. Additionally, the product provides interfaces and has vulnerabilities that can be used to reconstruct the traffic encryption keys for all tunnels.
New release by Kaspersky team leaded by SCADA StrangeLove fellow Gleb Gritsai "On the insecure nature of turbine control systems in power generation" as presented on Chaos Communication Congress 36C3.
In this paper, we present the results of Internet-wide security scans of publicly available AIML systems. We show that many different interfaces of AIML systems are not protected and accessible from the Internet, moreover, most of them don't even have basic security mechanisms. Also, we describe found the known vulnerabilities related to outdated software and insecure configurations.