Skip to content
TrackPodcasts
newsDec 6, 202432:58pending

Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386

About this episode

When focused on cybersecurity through a vulnerability management lens, it's tempting to see the problem as a race between exploit development and patching speed. This is a false narrative, however. While there are hundreds of thousands of vulnerabilities, each requiring unique exploits, the number of post-exploit actions is finite. Small, even.

Although Log4j was seemingly ubiquitous and easy to exploit, we discovered the Log4Shell attack wasn't particularly useful when organizations had strong outbound filters in place.

Today, we'll discuss an often overlooked advantage defenders have: mitigating controls like traffic filtering and application control that can prevent a wide range of attack techniques.

This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

Show Notes: https://securityweekly.com/esw-386

Get every episode summarized

Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386

Enterprise Security Weekly (Video)

0:00
32:58

More episodes

More from Enterprise Security Weekly (Video)

View all episodes →