Patchless patching, IPv6-enabled RCE, room searches at DEF CON, and Moon GPS – ESW #372
Adrian Sanabria
- ACQUISITIONS: Fortinet Strengthens Its Top-Tier Unified SASE Solution with Acquisition of Enterprise Data Security Company Next DLP
- ACQUISITIONS: OPSWAT Acquires InQuest, Strengthening Federal Go-to-Market Strategy, Network Detection, and Threat Intelligence Capabilities – OPSWAT
- ACQUISITIONS: EQT to acquire a majority stake in Acronis, Acronis continues to expand its platform for MSPs
- ACQUISITION RUMORS: Trend Micro explores sale, sources say
This would be momentous. Trend Micro is one of the last remaining big OG security vendors started in the 1980s, along with F-Secure (now WithSecure). The Japanese market seems to be hurting them pretty bad right now though (they used to be on the NASDAQ, but are now public in Tokyo)
- ACQUISITION RUMORS: CrowdStrike eyes Action1 for $1B amid fallout from Falcon update mishap
- NEW FEATURES: “Patchless Patching” for Zero Days: Qualys Advances Vulnerability Management
Darwin has some thoughts on this one, I think.
Adrian's question: how is this different from virtual patching, which was a thing 20+ years ago! Also, I've been using 0Patch for years (inserts virtual patches into running processes). Other approaches (like Cyvera, acquired by PANW in 2014) block known exploit attempts rather than creating virtual patches that need to be exploit/vuln-specific.
- ESSAYS: BlackHat Innovators & Investors Quick Hits
- ESSAYS: Let’s get real: there is no such thing as “gatekeeping” in cybersecurity
A very controversial-sounding title that ends up not being all that controversial once he qualifies the statement with "with regards to entry-level folks trying to find their first job in cybersecurity."
- ESSAYS: Software’s Iron Triangle: Cheap, Fast and Good – Pick Two
From Chris Hughes
At Black Hat, Jen Easterly dropped a few instantly iconic quotes.
“We don’t have a cybersecurity problem. We have a software quality problem.”
I mean, of course this is an oversimplification of cybersecurity's problems, but I think it's even worse than that. I think this applies to a subset of IT and most third party vendors, but even if you have no in-house dev team, you still have some pretty serious cybersecurity concerns. I think our software quality problem is just a small part of our system-level design and engineering problem.
She also said,
“We have a multi-billion dollar cybersecurity industry because for decades, technology vendors have been allowed to create defective, insecure, flawed software.”
Which I think is fair.
- STANDARDS: NIST Releases First 3 Finalized Post-Quantum Encryption Standards
We interviewed Vadim Lyubashevsky, one of the authors of these quantum safe algorithms, back in episode 315, check it out here!
- VULNERABILITIES: Windows TCP/IP Remote Code Execution Vulnerability
A critical vulnerability that is RCE and exploitable via IPv6. The only options seem to be to disable IPv6 or patch! This one could get VERY spicy in the near future if exploits emerge.
- VULNERABILITIES: Microsoft Azure AI Health Bot Infected With Critical Vulnerabilities
- DUMPSTER FIRES: Here are the Hacker Tools a DEF CON Hotel is Hunting For
- DUMPSTER FIRES: Azure outages should spark new urgency for a multi-cloud approach
- LAYOFFS: Cisco to lay off thousands more in second job cut this year, sources say
Also heard that Dell is laying off over 10,000 employees, yikes!!!
- STUNT HACKING: Watch How a Hacker’s Infrared Laser Can Spy on Your Laptop’s Keystrokes
Just because it's stunt hacking doesn't mean it's not fun!
- HOT TAKES: Pramod Gosavi on LinkedIn: Gartner cancels SOAR, calling it obsolete…
- SQUIRREL: What Time Is It on the Moon?
Devo Launches New Capabilities & Revolutionizing Cyber Resilience – Rakesh Nair, Rekha Shenoy – ESW #372
Rakesh Nair is the Senior Vice President of Engineering and Product at Devo, where he oversees the company’s research and development efforts. With over 25 years of experience in cybersecurity, Rakesh brings a wealth of expertise to his role. He was the co-founder and CEO of Kognos, an autonomous cyber threat hunting platform that Devo acquired in 2022.
With over 25 years in B2B tech, Rekha has led product and go-to-market strategies at top companies like Belden, Tripwire, and BMC Software. She is excited to lead the strong team at BackBox and recognizes network automation’s transformative power. Her expertise has consistently driven innovation and growth and will position the company for continued success in this evolving space.
Operational Resilience in Healthcare & Zscaler Uncovers Record-Breaking Ransom – Marty Momdjian, Brett Stone-Gross – ESW #372
As General Manager for Ready1 and EVP of Services, Marty Momdjian brings more than 15 years’ strategic and tactical leadership in cyber resilience and incident response (IR) to Semperis. His expertise in identity security, particularly in applied controls and ease of use, was forged while leading IR and recovery teams during some of the most well-known cyber breaches in the healthcare industry.
At Semperis, Marty’s focus is on breach preparedness and mitigating the impact to clinical and business operations during cyber events.
Dr. Brett Stone-Gross is the Senior Director of Threat Intelligence at Zscaler. He holds a Ph.D. in computer science from the University of California, Santa Barbara and has over 20 years of experience in malware analysis and reverse engineering. Brett has authored more than a dozen publications and presented his work at top cybersecurity conferences. He specializes in advanced technical research focused on sophisticated cyber threats.


















