Issue 245: Delinea patches API vulnerability, API vulnerability in Palo Alto devices
Brief
This week, we have two vulnerabilities: an API vulnerability in the Delinea platform and a remote command execution (RCE) affecting Palo Alto PAN-OS devices. We also have articles on how to fix API design, seven ways to better manage supply chain risk, and whether OpenBanking will transform the future of finance. Finally, we have Dana Epp on how to use “naughty strings” to break APIs.
Vulnerability: Delinea patches API vulnerability
This week’s first vulnerability comes courtesy of SC Media , who report that Delinea, privileged access management (PAM) provider, confirmed a critical vulnerability in its Delinea Platform and Secret Server Cloud products on April 15, 2024.
The vulnerability, identified as a flaw in the SOAP API, could allow attackers to bypass authentication, gain administrative access, and extract sensitive information if left unpatched.
