AVLEONOV Podcast: Recent Episodes

Alexander V. Leonov

Vulnerability assessment, IT compliance management, security automation and other beautiful stuff.

View Details

Hello everyone! This month I decided NOT to make an episode completely dedicated to Microsoft Patch Tuesday. Instead, this episode will be an answer to the question of how my Vulnerability Management month went. A retrospection of some kind. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for July 2023, including vulnerabilities that were added between June and July Patch Tuesdays. As usual, I use my open source Vulristics project to analyse and prioritize vulnerabilities. I optimized the detection of the vulnerable product and the type of vulnerability based on the description. Now processing already downloaded data (with option –rewrite-flag "False") takes a few seconds. For example, only ~3 seconds for 100 MS Patch Tuesday vulnerabilities. It used to take a few minutes. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for June 2023, including vulnerabilities that were added between May and June Patch Tuesdays. This time there were only 3 vulnerabilities used in attacks or with a public exploit. And only one of them is more or less relevant. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for November 2022, including vulnerabilities that were added between October and November Patch Tuesdays. As usual, I use my open source Vulristics project to create the report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for October 2022, including vulnerabilities that were added between September and October Patch Tuesdays. As usual, I use my open source Vulristics project to create the report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about the new hot twenty vulnerabilities from CISA, NSA and FBI, Joint cybersecurity advisory (CSA) AA22-279A, and how I analyzed these vulnerabilities using my open source project Vulristics. Americans can't just release a list of "20 vulnerabilities most commonly exploited in attacks on American organizations." They like to add geopolitics and point the finger at some country. Therefore, I leave the attack attribution mentioned in the advisory title without comment. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Five years ago I wrote a blogpost about OpenSCAP. But it was only about the SCAP Workbench GUI application and how to use it to detect security misconfigurations. This time, I will install the OpenSCAP command line tool on Ubuntu and use it to check for vulnerabilities on my local host. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Let’s take a look at Microsoft’s September Patch Tuesday. This time it is quite compact. There were 63 CVEs released on Patch Tuesday day. If we add the vulnerabilities released between August and September Patch Tuesdays (as usual, they were in Microsoft Edge), the final number is 90. Much less than usual. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This video was recorded for the VMconf 22 Vulnerability Management conference, vmconf.pw. I will be talking about my open source project Scanvus. This project is already a year old and I use it almost every day. Scanvus (Simple Credentialed Authenticated Network VUlnerability Scanner) is a vulnerability scanner for Linux. Currently for Ubuntu, Debian, CentOS, RedHat, Oracle Linux and Alpine distributions. But in general for any Linux distribution supported by the Vulners Linux API. The purpose of this utility is to get a list of packages and Linux distribution version from some source, make a request to an external vulnerabililty detection API (only Vulners Linux API is currently supported), and show the vulnerability report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, let’s take a look at the Microsoft Patch Tuesday August 2022 vulnerabilities. I use my Vulristics vulnerability prioritization tool as usual. I take comments for vulnerabilities from Tenable, Qualys, Rapid7, ZDI and Kaspersky blog posts. Also, as usual, I take into account the vulnerabilities added between the July and August Patch Tuesdays. There were 147 vulnerabilities. Urgent: 1, Critical: 0, High: 36, Medium: 108, Low: 2. There was a lot of great stuff this Patch Tuesday. There was a critical exploited in the wild MSDT DogWalk vulnerability, 3 critical Exchange vulnerabilities that could be easily missed in prioritization, 13 potentially dangerous vulnerabilities, 2 funny vulnerabilities and 3 mysterious ones. Let’s take a closer look. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This is the second episode of Vulnerability Management news and publications. In fact, This is the second episode of Vulnerability Management news and publications. In fact, this is a collection of my posts from the https://t.me/avleonovcom and https://t.me/avleonovrus telegram channels. Therefore, if you want to read them earlier, subscribe to these channels. The main idea of ​​this episode. Microsoft is a biased company. In fact, they should now be perceived as another US agency. Does this mean that we need to forget about Microsoft and stop tracking what they do? No, it doesn’t. They do a lot of interesting things that can at least be researched and copied. Does this mean that we need to stop using Microsoft products? In some locations (you know which ones) for sure, in some we can continue to use such products if it is reasonable, but it’s necessary to have a plan B. And this does not only apply to Microsoft. So, it’s time for a flexible approaches. Here we do it this way, there we do it differently. It seems that rather severe fragmentation of the IT market is a long-term trend and it’s necessary to adapt to it. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Microsoft has been acting weird lately. I mean the recent publication of a propaganda report about evil Russians and how Microsoft is involved in the conflict between countries. It wouldn't be unusual for a US government agency, NSA or CIA to publish such a report. But when a global IT vendor, which, in theory, should be more or less neutral, does this… This is a clear signal. It's not about business anymore. I'll take a closer look at this report in the next episode of the Vulnerability Management news, but for now let's take a look at Microsoft July Patch Tuesday. Yes, the vendor is behaving strangely, but Microsoft products need to be patched. Right? At least for now. And tracking vulnerabilities is always a good thing. 🙂 Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I will try to revive Security News with a focus on Vulnerability Management. On the one hand, creating such reviews requires free time, which could be spent more wisely, for example, on open source projects or original research. On the other hand, there are arguments in favor of news reviews. Keeping track of the news is part of our job as vulnerability and security specialists. And preferably not only headlines. I usually follow the news using my automated telegram channel @avleonovnews. And it looks like this: I see something interesting in the channel, I copy it to Saved Messages so that I can read it later. Do I read it later? Well, usually not. Therefore, the creation of news reviews motivates to read and clear Saved Messages. Just like doing Microsoft Patch Tuesday reviews motivates me to watch what’s going on there. In general, it seems it makes sense to make a new attempt. Share in the comments what you think about it. Well, if you want to participate in the selection of news, I will be glad too. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This will be an episode about the Microsoft vulnerabilities that were released on June Patch Tuesday and also between May and June Patch Tuesdays. On June Patch Tuesday, June 14, 56 vulnerabilities were released. Between May and June Patch Tuesdays, 38 vulnerabilities were released. This gives us 94 vulnerabilities in the report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this short episode, I want to talk about the new feature in Vulners Linux API. Linux security bulletin publication dates are now included in scan results. Why is it useful? Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I want to talk about the Positive Hack Days 11 conference, which took place on May 18 and 19 in Moscow. As usual, I want to express my personal opinion about this event. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about the AM Live Vulnerability Management online conference. I participated in it on May 17th. The event lasted 2 hours. Repeating everything that has been said is difficult and makes little sense. Those who want can watch the full video or read the article about the event (both in Russian). Here I would like to share my impressions, compare this event with last year's and express my position. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for May 2022. Sorry for the delay, this month has been quite intense. As usual, I’m using my Vulristics project and going through not only the vulnerabilities that were presented on May 10th, but all the MS vulnerabilities presented by Microsoft since the previous Patch Tuesday, April 12th. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I want to talk about the latest updates to my open source vulnerability prioritization project Vulristics. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This video was recorded for the VMconf 22 Vulnerability Management conference, vmconf.pw. I will be talking about malicious open source and the cost of using someone else's code. We must start with the fact that this year is fundamentally different. We now live in The New Reality of Information Security (TNRoIS). It has become quite clear that Open Source tools and code can harm your organization, because project maintainers can easily inject malicious features into their projects. Now they are actually doing it! Hypothetical threats have become quite real! Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for April 2022 and new improvements in my Vulristics project. I decided to add more comment sources. Because it's not just Tenable, Qualys, Rapid7 and ZDI make Microsoft Patch Tuesday reviews, but also other security companies and bloggers. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! After a two-year break, I took part in Moscow CISO Forum 2022 with a small talk "Malicious open source: the cost of using someone else's code". CISO Forum is the first major Russian conference since the beginning of The New Reality of Information Security (TNRoIS). My presentation was just on this topic. How malicious commits in open source projects change development and operations processes. I will make a separate video about this. In this episode, I would like to tell you a little about the conference itself. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, let’s take a look at the latest vulnerabilities in Gitlab. On March 31, the Critical Security Release for GitLab Community Edition (CE) and Enterprise Edition (EE) was released. GitLab recommends that all installations running a version affected by the issues described in the bulletin are upgraded to the latest version as soon as possible. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about last week's high-profile vulnerabilities in Spring. Let's figure out what happened. Of course, it's amazing how fragmented the software development world has become. Now there are so many technologies, programming languages, libraries and frameworks! It becomes very difficult to keep them all in sight. Especially if it's not the stack you use every day. Entropy keeps growing every year. Programmers are relying more and more on off-the-shelf libraries and frameworks, even where it may not be fully justified. And vulnerabilities in these off-the-shelf components lead to huge problems. So it was in the case of a very critical Log4Shell vulnerability, so it may be in the case of Spring vulnerabilities. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I would like to talk about Github and how to remove sensitive information that was accidentally uploaded there. This is a fairly common problem. When publishing the project code on Github, developers forget to remove credentials: logins, passwords, tokens. What to do if this becomes known? Well, of course, these credentials must be urgently changed. What was publicly available on the Internet cannot be completely removed. This data is indexed and copied by some systems. But wiping it from github.com is real. Why is it not enough to just delete the file in the Github repository? The problem is that the history of changes for the file will remain and everything will be visible there. Surprisingly, there is still no tool in the Github web interface to remove the history for a file. You have to use third-party utilities, one of them is git-filter-repo. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! I am glad to greet you from the most sanctioned country in the world. Despite all the difficulties, we carry on. I even have some time to release new episodes. This time it will be about Microsoft Patch Tuesday for March 2022. I do the analysis as usual with my open source tool Vulristics. You can still download it on github. I hope that github won’t block Russian repositories and accounts, but for now it looks possible. Most likely, I will just start hosting the sources of my projects on avleonov.com in this case. Or on another domain, if it gets even tougher. Stay tuned. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for February 2022. I release it pretty late, because of the my previous big episode about the blindspots in the Knowledge Bases of Vulnerability Scanners. Please take a look if you haven’t seen it. Well, if you are even slightly interested in the world news, you can imagine that the end of February 2022 in Eastern Europe is not the best time to create new content on Vulnerability Management. Let’s hope that peace and tranquility will be restored soon. And also that geopolitical confrontation between the largest nuclear powers will de-escalate somehow. But let’s get back to information security. While working on Microsoft Patch Tuesday report for February 2022, I made a lot of improvements to my open source project for vulnerability prioritization Vulristics. I want to start with them. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This video was recorded for the VMconf22 Vulnerability Management conference. I want to talk about the blind spots in the knowledge bases of Vulnerability Scanners and Vulnerability Management products. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! As you probably know, CentOS Linux, the main Enterprise-level Linux server distribution, will soon disappear. It wasn’t hard to predict when RedHat acquired CentOS in 2014, and now it is actually happening. End of life of CentOS Linux 8 was 31.12.2021. There won’t be CentOS Linux as downstream for RedHat anymore. Only CentOS Stream, that will be upstream for RedHat, more or less a testing distro like Fedora. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about Microsoft Patch Tuesday for January 2022. Traditionally, I will use my open source Vulristics tool for analysis. This time I didn’t make any changes to how connectors work. The report generation worked correctly on the first try. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I want to talk about VMconf 22. It was an experiment from the beginning. Is it possible to host a Vulnerability Management event with little effort and budget? Looks like no. So I would like to talk about why the original idea failed and the future of VMconf. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! I decided to make a separate episode about Log4Shell. Of course, there have already been many reviews of this vulnerability. But I do it primarily for myself. It seems to me that serious problems with Log4j and similar libraries will be with us for a long time. Therefore, it would be interesting to document how it all began. So what is the root cause of Log4Shell? Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! It’s even strange to talk about other vulnerabilities, while everyone is so focused on vulnerabilities in log4j. But life doesn’t stop. Other vulnerabilities appear every day. And of course, there are many critical ones among them that require immediate patching. This episode will be about Microsoft Patch Tuesday for December 2021. I will traditionally use my open source Vulristics tool for analysis. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I want to talk about vulnerabilities, news and hype. The easiest way to get timely information on the most important vulnerabilities is to just read the news regularly, right? Well, I will try to reflect on this using two examples from last week. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode is about Qualys Security Day 2021 Las Vegas, Qualys VMDR, VMDR Training and exam. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode I want to highlight the latest changes in my Vulristics project. For those who don’t know, this is a utility for prioritizing CVE vulnerabilities based on data from various sources.. Currently Microsoft, NVD, Vulners, AttackerKB. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about the VMconf 22 Vulnerability Management conference. CFP started on November 1, which will last a month and a half. So please submit your talk or share this video with someone who might be interested. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This episode will be about relatively recent critical vulnerabilities. Let’s start with Microsoft Patch Tuesday for October 2021. Specifically, with the vulnerability that I expected there, but it didn’t get there. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Last week I gave a "Career Navigator" talk for the students of the IT Hub College in Moscow. By the way, this college has a very interesting practical information security program. If it is relevant for you, check it out. I’ve never talked so much about myself in public. It was like giving advises to yourself from the past. An interesting experience. It took about an hour and a half. And now I will try to mention the main points. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This time, let’s talk about recent vulnerabilities. I’ll start with Microsoft Patch Tuesday for September 2021. I created a report using my Vulristics tool. A link to the full report in the blogpost. The most interesting thing about the September Patch Tuesday is that the top 3 VM vendors ignored almost all RCEs in their reviews. However, there were interesting RCEs in the Office products. And what is most unforgivable is that they did not mention CVE-2021-38647 RCE in OMI – Open Management Infrastructure. Only ZDI wrote about this. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

In a previous episode on Microsoft Defender for Endpoint, I described how to get a list of antivirus engine and signatures versions for the hosts in your infrastructure using the Microsoft Graph API. But the problem remains. You know the versions that are currently installed on the hosts. But where can you get the latest versions that should be installed there? Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! This is a new episode with my comments on the latest Information Security news. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Yet another news episode. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! In this episode, I would like to tell you how I tried to get automatically antivirus-related data (current status, engine and signature version, last full scan date) from Microsoft Defender for Endpoint using Microsoft Intune and the Graph API. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Last Week’s Security News, August 1 – August 8. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Last Week’s Security News, July 26 – August 1. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

If you are using Nessus to scan Linux hosts and authenticate by key, you may encounter this problem. You have generated the keys correctly, placed the public key on a remote server. You can connect to this server using the private key. But when scanning with Nessus, you get weird errors in the various plugin outputs. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

So, the last week, July 19 – July 25. In my opinion, the most interesting news was the scandal related to the iPhone Pegasus spyware and two Elevations of Privileges: SeriousSAM for Windows and Sequoia for Linux. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! I decided to share my thoughts on the latest Gartner vulnerability assessment report. Not so bad text after all, but it could be better. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello guys! The fourth episode of Last Week’s Security news, July 12 – July 18. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! For the past 9 months, I’ve been doing Microsoft Patch Tuesday reviews quarterly. Now I think it would be better to review the July Patch Tuesday while the topic is still fresh. And that will save us some time in the next Last Week’s Security news episode. So, July Patch Tuesday, 116 vulnerabilities. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello guys! The third episode of Last Week’s Security news, July 5 – July 11. There was a lot of news last week. Most of them was again about PrintNightmare and Kaseya. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! Let’s now talk about Microsoft Patch Tuesday vulnerabilities for the second quarter of 2021. April, May and June. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello guys! The second episode of Last Week’s Security news from June 28 to July 4. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hi guys! I was on vacation this week. So I had time to work on my Vulristics project. For those who don’t know, this is a framework for prioritizing known CVE vulnerabilities. I was mainly grooming the HTML report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello, today I want to experiment with a new format. I will be reading last week’s news from my @avleonovnews channel, which I found the most interesting. I do this mostly for myself, but if you like it too, then that would be great. Please subscribe to my YouTube channel and my Telegram @avleonovcom. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Today I will talk about the Positive Hack Days conference, which took place on May 20 and May 21 in Moscow. I can say that this was and remains the main event for Information Security Practitioners in Russia. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Today I want to talk about Microsoft Intune Mobile Device Management platform. The task I needed to solve was how to get the timestamp of the last activity for all hosts in Microsoft Intune using the official API. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello all! It is the second part about AM Live Vulnerability Management conference. In the first part I made the timecodes for the 2 hours video in Russian. Here I have combined all my lines into one text. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Hello everyone! It has been 3 months since my last review of Microsoft vulnerabilities for Q4 2020. In this episode I want to review the Microsoft vulnerabilities for the first quarter of 2021. There will be 4 parts: January, February, March and the vulnerabilities that were released between the Patch Tuesdays. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I have completed a major refactoring of Vulristics. Now it can create beautiful reports not only for Microsoft Patch Tuesdays, but for any set of CVEs! Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I recently tried Microsoft Defender for Endpoint. Not that free antivirus built into Windows, but an enterprise product. The thing is very promising. Even from the Vulnerability Management side. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

This episode will be about Vulners Linux Audit API, which allows you to detect vulnerabilities on a Linux host knowing only the OS version and installed packages. I had a similar post about this 4 years ago, but some details have changed, so I came back to this topic. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

In this episode I would like to make a status update of my Vulristics project. For those who don’t know, in this project I retrieve publicly available vulnerability data and analyze it to better understand the severity of these vulnerabilities and better prioritize them. Currently, it is mainly about Microsoft Patch Tuesday vulnerabilities, but I have plans to go further. Also in this episode I want to demonstrate the new Vulristics features on Microsoft Patch Tuesday reports for October, November and December 2020. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

In this episode, I would like to share my thoughts about the new Vulnerability Management product by Positive Technologies – MaxPatrol VM. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

In this episode, I would like to talk about Nessus Essentials and, in particular, how to register and update it without direct internet access. Nothing complicated, but there are a couple of pitfalls that I would like to share. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I would like to start this episode by talking about Microsoft vulnerabilities, which recently turned out to be much more serious than it seemed at first glance. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

This time I would like to review not only the vulnerabilities that were published in the last August Microsoft Patch Tuesday, but also the CVEs that were published on other, not Patch Tuesday, days. Of course, if there are any. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I am doing this episode about July vulnerabilities already in August. Sorry for delay. I talk here about my new open source project Vulristics and review the PatchTruesday report. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

This episode is based on posts from my Telegram channel avleonovcom, published in the last 2 weeks. So, if you use Telegram, please subscribe. I update it frequently. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

This time, Microsoft addressed 129 vulnerabilities: 11 critical and 118 important. It's rather interesting month, but the focus is still mainly on SMB RCE vulnerabilities and the possible use of these vulnerabilities in malware attacks. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I have been a Splunk guy for quite some time, 4 years or so. I have made several blog posts describing how to work with Splunk in automated manner. But after their decision to stop their business in Russia last year, including customer support and selling software and services, it was just a matter of time for me to start working with other dashboarding tools. For me, Grafana has become such a tool. In this post I want to describe the basic API operations with Grafana dashboards, which are necessary if you need to create and update dozens and hundreds of dashboards. Doing all this in the GUI will be painful. Grafana has a pretty logical and well-documented API. The only tricky moments I had were getting a list of all dashboard and editing an existing dashboard. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

It will be an off-topic, but I really wanted to share this with you. Adding your own tools in Notepad++ makes it much more fun!😊 I have to say, I spend a lot of time daily in Notepad++ text editor for Windows. I keep my “logbook” there. I record what I am doing now and what needs to be done. This allows me not to keep everything in my head and switch the context more efficiently. I can recommend this to everyone. And it is especially useful to note when you started working on a task and when you finished. This gives an understanding of what actually takes your time. I’m not a fan of very strict and formal techniques such as pomodoro, but using some form of time management is good. Recording timestamps manually is inconvenient. It would be much easier to press a key combination and automatically insert the current timestamp into the document. It turned out that this is possible, and even more – you can get the results of any Python script this way! Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Last time I complained that different VM vendors release completely different reports for Microsoft Patch Tuesday. This time I decided that it’s not a bug, but a feature. I upgraded my script to not only show vulnerabilities, but also show how these vulnerabilities were mentioned in the reports of various VM vendors (Tenable, Qualys, Rapid7 and ZDI). In my opinion, it seems pretty useful. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

This time I want to write about the service of my friends from Antiphish. They call it “security awareness and employee behaviour management platform”. Simply put, they teach company employees how to detect and avoid phishing attacks. How can you protect your organization from phishing attacks? Educate people and constantly provoke them using emulated phishing attacks (some of these Antiphish attacks are amazing, I show them in the video). Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Making the reviews of Microsoft Patch Tuesday vulnerabilities should be an easy task. All vulnerability data is publicly available. Even better, dozens of reviews have already been written. Just read them, combine and post. Right? Not really. In fact it is quite boring and annoying. That's why I created a script that takes Patch Tuesday CVE data from microsoft.com and visualizes it giving me helicopter view on what can be interesting there. With nice grouping by vulnerability type and product, with custom icons for vulnerability types, coloring based on severity, etc. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

Without a doubt, the hottest Microsoft vulnerability in March 2020 is the "Wormable" Remote Code Execution in SMB v3 CVE-2020-0796. The most commonly used names for this vulnerability are EternalDarkness, SMBGhost and CoronaBlue. There was a strange story of how it was disclosed. It seems like Microsoft accidentally mentioned it in their blog. Than they somehow found out that the patch for this vulnerability will not be released in the March Patch Tuesday. So, they removed the reference to this vulnerability from the blogpost as quickly as they could. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

This will be an update to my post from 2017. In that post, I presented a small python script that parses Nessus XML reports and returns a dictionary with all the data. It worked pretty well for me until the most recent moment when I needed to get compliance data from Nessus scan reports, and it failed. So I researched how this information is stored in a file, changed my script a bit, and now I want to share it with you. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I recently read Forrester's 20-page report "The Total Economic Impact™ Of Rapid7 InsightVM". It is about the Cost Savings And Business Benefits that Vulnerability Management solution can bring to the organizations. In short, I didn't like everything related to money. It seems like juggling with numbers, useless and boring. But I really liked the quotes from customers who criticized existing Vulnerability Management solutions, especially the low quality of the remediation data. These are the real pain points of Vulnerability Management process. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

View Details

I’ve just read a nice article about Vulnerability Management in the Acribia blog (in Russian). Here is an extract with my comments. In the most cases Vulnerability Management is not about Vulnerabilities, but about Management. Just filtering the most critical vulnerabilities is not enough. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.