We're sunsetting PodQuest on 2025-07-28. Thank you for your support!
Export Podcast Subscriptions
cover of episode Stopping 0day Exploits Doesn't Require AI or Superhuman Speed  - Rob Allen - ESW #386

Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386

2024/12/6
logo of podcast Security Weekly Podcast Network (Video)

Security Weekly Podcast Network (Video)

Shownotes Transcript

When focused on cybersecurity through a vulnerability management lens, it's tempting to see the problem as a race between exploit development and patching speed. This is a false narrative, however. While there are hundreds of thousands of vulnerabilities, each requiring unique exploits, the number of post-exploit actions is finite. Small, even.

Although Log4j was seemingly ubiquitous and easy to exploit, we discovered the Log4Shell attack wasn't particularly useful when organizations had strong outbound filters in place.

Today, we'll discuss an often overlooked advantage defenders have: mitigating controls like traffic filtering and application control that can prevent a wide range of attack techniques.

This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker) to learn more about them!

Show Notes: https://securityweekly.com/esw-386)