It’s interesting to me that Netscaler has this vast footprint (>50k devices) and the exploitation activity has allowed entry into orgs including the UN and the US government, bypassing MFA, straight into remote access to internal networks - and it’s had zero mainstream coverage.
SharePoint vuln, a product most orgs stopped running themselves a decade ago - all over media.
Eddie.
in reply to Kevin Beaumont • • •JA
in reply to Kevin Beaumont • • •Popio
in reply to Kevin Beaumont • • •Eddie.
Unknown parent • • •fuzzyfuzzyfungus
in reply to Kevin Beaumont • • •I suspect that it's mostly public familiarity; not sure if there's anyone from the tech-business-but-not-really-technical side who is interested because it's another case where o365 sharepoint and exchange are unaffected(or at least were mitigated a lot more quickly and quietly); but on-prem gets to live dangerously.
Relative familiarity seems more likely.
Jess👾
in reply to Kevin Beaumont • • •CShanahan
in reply to Kevin Beaumont • • •meriksson
in reply to Kevin Beaumont • • •But it’s RCE, man!
Network access can’t be as dangerous as an RCE, right?
I mean we have passwords, right?!
Scary truth, most (yeah, weird I know) dont understand the attack vektor.
Which is, disturbing.
Eddie.
Unknown parent • • •WinterKnight
in reply to Kevin Beaumont • • •Jay
in reply to Kevin Beaumont • • •VessOnSecurity
in reply to Kevin Beaumont • • •Snoop
in reply to Kevin Beaumont • • •Ciarán McNally
in reply to Kevin Beaumont • • •