Bharat Jogi, Qualys | Qualys QSC22
Bharat Jogi, the director of vulnerability threat research at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to give an overview of Microsoft Patch Tuesdays, as well as share the most jarring CVEs released and provide an update on ProxyNotShell.
Transcript
This is texturong TV. Hi everyone. We're back here live in Vegas for the qualis QSC show at the Venetian wrapping up day two.
I think we have just one or two more people to come on. Here we but don't stick around for him. I think you'll enjoy what we're going to talk about, right?
Excuse me. My next guest is Barat Jodie Bratz been with us at previous qsc's and so forth and we're happy to have them back for out. First of all, welcome.
Thank you Ellen. Thank you before we jump in. Why don't we give people a little bit of kind of your background and what you do in qualis shut so I've been with qualis for 13 plus years and I had the vulnerability and threat research at call list.
So my team we have a global team of security researchers. We look at the threat landscape new vulnerabilities that get released on a daily basis. Try to build count and measures detections for them.
You also do our own in-house zero day research some of the vulnerabilities like we have fairly good luck finding like very critical vulnerabilities like Pawn kid Barons and my dad written of wizards. Most of these vulnerabilities are exploited in the wild. So yeah, you know what they say about luck 80% prosperation 20% inspiration.
Yes, exactly. And yeah, it's it's a never-ending game, right? You know, we have to constitute vulnerabilities are not stopping hackers are exploiting new breaches.
So it's it's a wild ride but it's a good one. You know what I know. Sometimes it could feel like are we ever making progress right?
Because as fast as we find them that's how many more you know for everyone we find two more come out, but the fact is we are making progress. Yes, right, we and we have been and we continue to so thank you for all that you and your team do You know, we interviewed someone earlier. There's a announcement here at QSC about the true.
Yeah team. Yeah, just Don't you know a to let people know about true again? Yes, but what's the relationship there with your team and true?
Yeah, so we have a Global Security research team. And we have been producing some very quality research. And the quality has been doing this for last 20 plus years.
So we decided to you know, basically give the research team a name like, you know, we have like Top Class researchers on the team and we wanted this reaches researchers to have their own identity. So all our research on vulnerability threats policy compliance external attacks surface, all of these come together as a part of one unit. We are calling it as quality threat Research Unit in short qualis true.
And that is something that we you know, really stand by like if you look at qualis research that we have produced, right? There are a lot of companies out there who do a lot of you know. scary stories figurines like and we that is not something that we want to get ourselves associated with we want to give our customers and the industry like real insights that matter and that is why the true name really stuck, you know, and that was something that we all as a research team like this is something that we can stand by we will provide real insights how it affects you and what are the actions that you can take in order to reduce service.
So that is how the qualis true the threat Research Unit came into being got it. Excellent. All right.
Let's focus in we were gonna talk a little bit about patch Tuesdays. Okay, and I thought we would start with this most recent Patch Tuesday, and then we'll we'll look at patch Tuesdays in general and sort of where we going with them. Yeah.
so that's Tuesday's always interesting for me. I have been doing that for last 14 years. And every month it's like, you know.
It's like, you know some of those like I have a daughter two and a half. we have subscribed her with a monthly subscription where we basically get new toys So sort of Microsoft pass Tuesday has become something like that like every month. You don't know what surprise are we going to receive.
and this month's past using no different keeping in terms of the number of vulnerabilities just by the Numbers Microsoft fixed like 68 vulnerabilities 11 of them were rated critical. That's actually look. Yeah.
Yeah exactly like this year. Microsoft is averaging like hundred plus volunteers they already fixed like 1300 cve's just in 2020. So 100 hundred and ten average right compared to that.
We are at 69. however, the interesting part is that Microsoft fixed six zero day vulnerabilities with this patch Tuesday. now that that number is quite High generally it would be around one to Max.
I have seen around four but six in one month is quite High. So yeah, I mean in terms of number of zero days cost by Microsoft in this one is really high six good thing. They released patch for proxy not shell was a zero days that were being exploited were used for targeted attacks against Microsoft Exchange.
And there are some other critical vulnerabilities that also Microsoft fixed. Yeah, I feel obligated that I got to mention to our audience. Microsoft Patch Tuesday, so these are only Microsoft.
Vulnerabilities, it doesn't mean that Microsoft is inherently not secure or less secure than than Apple or Linux or any of these others. Yeah. It just means that, you know Microsoft for the last Oh, I don't know.
It's got to be 15 14 years. Yeah has been releasing every month on time Patch Tuesday where they address vulnerabilities within the windows. Well, yeah, well the whole microgreens system.
That's just what it does. So I I just want to say that we're not here banging Microsoft. They're trying to say they're in war insecure.
Than other systems, that's not it at all. Secondly again, our audience is pretty technical right if you get six zero days coming out in a month. That's because they were probably yeah six in the wild.
Yes. Yes exploits out there for you zero. Yes, and they had to be fixed immediately.
Yeah, so, you know just another reason why we need to do a better job. Of automating remediation obviously, right? Yeah that I don't think you know.
so early I think yesterday at USC sales was doing his presentation and if you look at just Microsoft. for this year the patches their release are more than 45,000. Wow, 45,000 patches that you need to apply in order to fix all those Microsoft vulnerabilities.
So I mean and with the rapid digital transformation, I mean there is no way do you get up on it? No, exactly. There's no no way and Today, you know when Travis announced are through one of the insights that he provided was.
The time to weaponize the vulnerabilities from the time the vulnerabilities out to the time attackers have used that vulnerability and weaponized exploits are available that is down to less than 16 days. So if you don't have an Automation in place to patch your vulnerabilities, you are giving attackers a quite wide window to you know, attack your infrastructure. So automation is the key.
I don't think there is anyone would deny that automation is not good. There is no way like the how many vulnerabilities constantly on the rise. We are what 21,000 CVS just this year.
We are not at the end of the year. So number of vulnerabilities are on the rise vulnerabilities like log4j spring for Shell tax for Shell. They are on the rice and yet you know, there's going to be more we just don't know where anywhere exactly and you know, perfect like this is the time of the year when you know, usually don't get something right around the holidays.
Yes. So it's a little early next month. Yes.
Yeah after Thanksgiving to Christmas is when you see all our wings lock 4G everything happened around that time. So why? You know automation is the key.
There is there is no way we need to. com as I thought to myself there has to be a better way. Yeah.
And so the whole what what's become known as shift left? Yes, right. My thought my Hope was that.
As more companies adopt that into their software development process. We would develop software. That would be more secure by Design.
Yeah, which would therefore I mean we'd have less patching to do. Yes. after deployment Do you think maybe 2023 we start seeing we reap the rewards of that or yeah, we're getting ourselves.
Yeah, I think organizations have realized that. Once something is in production. Once something is live.
It becomes very difficult. And after that it's basically you are doing a you know. You are just trying to catch up.
So as much as you can fix things before they are in production, right? You have all the time, right? You don't have to worry about dependencies your it becomes easier.
So the more we fix vulnerabilities, you know it developer side. It's shift left side of things. You know it the better.
Absolutely. Yeah. But why do you think we'll see it in the numbers?
So I think obviously in 2023-24 probably I think organizations would you know will soon realize especially? You know, there is a lot of push in industry for s-born, right? And that's very supply chain.
That's Palm. Yeah all the race so vendors when they are trying to You know, you're working with vendors, you know beforehand when you are procuring something that this is the S form it transparently lays out all the if you if you know that a vendor is telling you a product which already has out of dated, you know, dependencies Etc. Probably are not going to deploy that in the environment.
So this is going to you know, basically put a lot of pressure on vendors as well that they are inherently shipping you a secure product. So I I am very hopeful I think Jonathan mentioned about that at you know, we had a see so panel disco. Yeah, so and and I think as bomb was something that you know, absolutely look we have High Hopes through anyway Barat this nice talking.
Thank you. Hey, we're wrapping up but you have one or two more to coming at you here live from Vegas. We're gonna take a break.
We'll be back in just a minute.





