Home
Categories
EXPLORE
True Crime
Comedy
Business
Society & Culture
Sports
Technology
History
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/90/02/6a/90026aa8-bc23-97c7-6cc0-5e839dd233a4/mza_1106401273357841741.jpg/600x600bb.jpg
AppSec Now
DevCentral
41 episodes
3 days ago
AppSec Now is a podcast aimed at delivering the top stories from the latest (mosttly application) security news and interesting guests from the application security community.
Show more...
Technology
RSS
All content for AppSec Now is the property of DevCentral and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
AppSec Now is a podcast aimed at delivering the top stories from the latest (mosttly application) security news and interesting guests from the application security community.
Show more...
Technology
https://d3t3ozftmdmh3i.cloudfront.net/staging/podcast_uploaded_nologo/40182249/40182249-1741042271507-440312d7c26.jpg
Amazon EC2 SSRF Breach, Oracle Cloud Breach & Malicious NPM Packages Exposed
AppSec Now
35 minutes 8 seconds
6 months ago
Amazon EC2 SSRF Breach, Oracle Cloud Breach & Malicious NPM Packages Exposed

Join our AppSec experts—Merlyn, Malcolm, MegaZone, and host Chase Abbott—as they dig into some of the latest stories shaking up the cybersecurity world. This week's AppSec Now explores an active campaign targeting Amazon EC2 instance metadata via SSRF vulnerabilities, and why that's a wider-reaching problem than you might think. We discuss Oracle's controversial handling of their cloud breach and the impact of trust in the disclosure process.

Also in the mix: malicious NPM packages deployed by North Korean hackers, a sneaky Golang malware employing "click-fix" tactics for crypto theft, and a critical Apache Parquet remote code execution bug rated CVSS 10.0—but how worried should we really be?

🔗 Relevant Links Here:https://community.f5.com/kb/security-insights/oracle-hack-north-korean-hackers-critical-flaw-in-apache/340708

00:00 Introduction

04:01 F5 Labs: AWS EC2 SSRF

10:44 Oracle Cloud Breach

16:44 Verizon iOS App Exposure

20:23 BeaverTail Malware via NPM

24:43 Golang Ghost Malware

28:34 Apache Parquet RCE - CVSS 10 !!!

34:12 Outro

AppSec Now
AppSec Now is a podcast aimed at delivering the top stories from the latest (mosttly application) security news and interesting guests from the application security community.