Alexander V. Leonov

AVLEONOV Podcast

Vulnerability assessment, IT compliance management, security automation and other beautiful stuff.

Author

Alexander V. Leonov

Category

Technology

Podcast website

avleonov.com

Latest episode

Mar 5, 2024

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ep.69 - Microsoft Patch Tuesday July 2022: propaganda report, CSRSS EoP, RPC RCE, Edge, Azure Site Recovery 23.07.2022

Hello everyone! Microsoft has been acting weird lately. I mean the recent publication of a propaganda report about evil Russians and how Microsoft is involved in the conflict between countries. It wouldn't be unusual for a US government agency, NSA or CIA to publish such a report. But when a global IT vendor, which, in theory, should be more or less neutral, does this… This is a clear signal. It's...

Ep.68 - Vulnerability Management news and publications #1 06.07.2022

Hello everyone! In this episode, I will try to revive Security News with a focus on Vulnerability Management. On the one hand, creating such reviews requires free time, which could be spent more wisely, for example, on open source projects or original research. On the other hand, there are arguments in favor of news reviews. Keeping track of the news is part of our job as vulnerability and securit...

Ep.67 - Microsoft Patch Tuesday June 2022: Follina RCE, NFSV4.1 RCE, LDAP RCEs and bad patches 25.06.2022

Hello everyone! This will be an episode about the Microsoft vulnerabilities that were released on June Patch Tuesday and also between May and June Patch Tuesdays. On June Patch Tuesday, June 14, 56 vulnerabilities were released. Between May and June Patch Tuesdays, 38 vulnerabilities were released. This gives us 94 vulnerabilities in the report. Watch the video version of this episode on my YouTub...

Ep.66 - Vulners Linux Audit API: Security Bulletin Publication Dates in Results 13.06.2022

Hello everyone! In this short episode, I want to talk about the new feature in Vulners Linux API. Linux security bulletin publication dates are now included in scan results. Why is it useful? Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

Ep.65 - PHDays 11: towards the Independence Era 11.06.2022

Hello everyone! In this episode, I want to talk about the Positive Hack Days 11 conference, which took place on May 18 and 19 in Moscow. As usual, I want to express my personal opinion about this event. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

Ep.64 - AM Live Vulnerability Management Conference 2022: my impressions and position 04.06.2022

Hello everyone! This episode will be about the AM Live Vulnerability Management online conference. I participated in it on May 17th. The event lasted 2 hours. Repeating everything that has been said is difficult and makes little sense. Those who want can watch the full video or read the article about the event (both in Russian). Here I would like to share my impressions, compare this event with la...

Ep.63 - Microsoft Patch Tuesday May 2022: Edge RCE, PetitPotam LSA Spoofing, bad patches 27.05.2022

Hello everyone! This episode will be about Microsoft Patch Tuesday for May 2022. Sorry for the delay, this month has been quite intense. As usual, I’m using my Vulristics project and going through not only the vulnerabilities that were presented on May 10th, but all the MS vulnerabilities presented by Microsoft since the previous Patch Tuesday, April 12th. Watch the video version of this episode o...

Ep.62 - Vulristics May 2022 Update: CVSS redefinitions and bulk adding Microsoft products from MS CVE data 23.05.2022

Hello everyone! In this episode, I want to talk about the latest updates to my open source vulnerability prioritization project Vulristics. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

Ep.61 - Malicious Open Source: the cost of using someone else’s code 11.05.2022

Hello everyone! This video was recorded for the VMconf 22 Vulnerability Management conference, vmconf.pw. I will be talking about malicious open source and the cost of using someone else's code. We must start with the fact that this year is fundamentally different. We now live in The New Reality of Information Security (TNRoIS). It has become quite clear that Open Source tools and code can harm yo...

Ep.60 - Microsoft Patch Tuesday April 2022 and custom CVE comments sources in Vulristics 23.04.2022

Hello everyone! This episode will be about Microsoft Patch Tuesday for April 2022 and new improvements in my Vulristics project. I decided to add more comment sources. Because it's not just Tenable, Qualys, Rapid7 and ZDI make Microsoft Patch Tuesday reviews, but also other security companies and bloggers. Watch the video version of this episode on my YouTube channel. Read the full text of this ep...

Ep.59 - CISO Forum 2022: the first major Russian security conference in the New Reality 17.04.2022

Hello everyone! After a two-year break, I took part in Moscow CISO Forum 2022 with a small talk "Malicious open source: the cost of using someone else's code". CISO Forum is the first major Russian conference since the beginning of The New Reality of Information Security (TNRoIS). My presentation was just on this topic. How malicious commits in open source projects change development and operation...

Ep.58 - Gitlab OmniAuth Static Passwords and stored XSS 04.04.2022

Hello everyone! In this episode, let’s take a look at the latest vulnerabilities in Gitlab. On March 31, the Critical Security Release for GitLab Community Edition (CE) and Enterprise Edition (EE) was released. GitLab recommends that all installations running a version affected by the issues described in the bulletin are upgraded to the latest version as soon as possible. Watch the video version o...

Ep.57 - Spring4Shell, Spring Cloud Function RCE and Spring Cloud Gateway Code Injection 03.04.2022

Hello everyone! This episode will be about last week's high-profile vulnerabilities in Spring. Let's figure out what happened. Of course, it's amazing how fragmented the software development world has become. Now there are so many technologies, programming languages, libraries and frameworks! It becomes very difficult to keep them all in sight. Especially if it's not the stack you use every day. E...

Ep.56 - How to remove sensitive information from a Github repository 27.03.2022

Hello everyone! In this episode, I would like to talk about Github and how to remove sensitive information that was accidentally uploaded there. This is a fairly common problem. When publishing the project code on Github, developers forget to remove credentials: logins, passwords, tokens. What to do if this becomes known? Well, of course, these credentials must be urgently changed. What was public...

Ep.55 - Microsoft Patch Tuesday March 2022 14.03.2022

Hello everyone! I am glad to greet you from the most sanctioned country in the world. Despite all the difficulties, we carry on. I even have some time to release new episodes. This time it will be about Microsoft Patch Tuesday for March 2022. I do the analysis as usual with my open source tool Vulristics. You can still download it on github. I hope that github won’t block Russian repositories and...

Ep.54 - Microsoft Patch Tuesday February 2022 28.02.2022

Hello everyone! This episode will be about Microsoft Patch Tuesday for February 2022. I release it pretty late, because of the my previous big episode about the blindspots in the Knowledge Bases of Vulnerability Scanners. Please take a look if you haven’t seen it. Well, if you are even slightly interested in the world news, you can imagine that the end of February 2022 in Eastern Europe is not the...

Ep.53 - VMconf 22: Blindspots in the Knowledge Bases of Vulnerability Scanners 18.02.2022

Hello everyone! This video was recorded for the VMconf22 Vulnerability Management conference. I want to talk about the blind spots in the knowledge bases of Vulnerability Scanners and Vulnerability Management products. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

Ep.52 - End of CentOS Linux. Where to migrate? 21.01.2022

Hello everyone! As you probably know, CentOS Linux, the main Enterprise-level Linux server distribution, will soon disappear. It wasn’t hard to predict when RedHat acquired CentOS in 2014, and now it is actually happening. End of life of CentOS Linux 8 was 31.12.2021. There won’t be CentOS Linux as downstream for RedHat anymore. Only CentOS Stream, that will be upstream for RedHat, more or less a...

Ep.51 - Microsoft Patch Tuesday January 2022 16.01.2022

Hello everyone! This episode will be about Microsoft Patch Tuesday for January 2022. Traditionally, I will use my open source Vulristics tool for analysis. This time I didn’t make any changes to how connectors work. The report generation worked correctly on the first try. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.co...

Ep.50 - VMconf 22: Why Didn't It Work As Planned and What's Next? 08.01.2022

Hello everyone! In this episode, I want to talk about VMconf 22. It was an experiment from the beginning. Is it possible to host a Vulnerability Management event with little effort and budget? Looks like no. So I would like to talk about why the original idea failed and the future of VMconf. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all...

Ep.49 - Log4j 'Log4Shell' RCE explained (CVE-2021-44228) 27.12.2021

Hello everyone! I decided to make a separate episode about Log4Shell. Of course, there have already been many reviews of this vulnerability. But I do it primarily for myself. It seems to me that serious problems with Log4j and similar libraries will be with us for a long time. Therefore, it would be interesting to document how it all began. So what is the root cause of Log4Shell? Watch the video v...

Ep.48 - Microsoft Patch Tuesday December 2021 16.12.2021

Hello everyone! It’s even strange to talk about other vulnerabilities, while everyone is so focused on vulnerabilities in log4j. But life doesn’t stop. Other vulnerabilities appear every day. And of course, there are many critical ones among them that require immediate patching. This episode will be about Microsoft Patch Tuesday for December 2021. I will traditionally use my open source Vulristics...

Ep.47 - Vulnerability Intelligence based on media hype. It works? Grafana LFI and Log4j "Log4Shell" RCE 13.12.2021

Hello everyone! In this episode, I want to talk about vulnerabilities, news and hype. The easiest way to get timely information on the most important vulnerabilities is to just read the news regularly, right? Well, I will try to reflect on this using two examples from last week. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avle...

Ep.46 - QSC21, VMDR Training and Exam 06.12.2021

Hello everyone! This episode is about Qualys Security Day 2021 Las Vegas, Qualys VMDR, VMDR Training and exam. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

Ep.45 - Vulristics Command Line Interface, improved Product / Vuln. Type Detections and Microsoft Patch Tuesday November 2021 30.11.2021

Hello everyone! In this episode I want to highlight the latest changes in my Vulristics project. For those who don’t know, this is a utility for prioritizing CVE vulnerabilities based on data from various sources.. Currently Microsoft, NVD, Vulners, AttackerKB. Watch the video version of this episode on my YouTube channel. Read the full text of this episode with all links on avleonov.com blog.

Listen to the AVLEONOV Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.