Get a Pentest and security assessment of your IT network.

News

Attacking SSL VPN – Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case Study!

This is the last part of Attacking SSL VPN series. We have found 7 vulnerabilities in total, including a stack-based overflow on the management interface. Pulse Secure has been in our research queue for a long time because it was a critical infrastructure of Google, which is one of our long-term targets. Google applies the Zero Trust security model, and therefore the VPN is removed now. An intelligence also points out that there is already a China APT group exploiting this bug. So, if you havent updated your Palo Alto, Fortinet or Pulse Secure SSL VPN, please update it ASAP!”]

Source: https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months