Channels gone downhill

The problem is that information can be hard to come by because these companies don’t generally do a good job of putting that information out there. It takes research and reading though posts from security researchers notes (provided they even post about it) to dig into that.

For example the Sonicwall incident that lead to the to the losing peoples configuration backup was first downplayed by Sonicwall by claiming it was less than 5% of their customers but later revised to be all customers that used their config backup. We also learned they did not encrypt the backups which is what what made the issue so much worse.

I have covered Fortinet not because they have had security issues, but because those issue reveal ed and were caused by failure to follow well known modern guidelines designed to prevent those issues.

I did bring up UniFi CVE-2025-52665 on my last live stream but because it was found and responsibly disclosed by a researcher and UniFI paid out $25K to that researcher for finding it while also getting a patch out within 2 weeks, it’s not anything to panic about. Also it was a flaw in UniFi Access that required an attacker to be on a trusted network with privileges to access the firewall.

Maybe I could make a video on the challenges of finding information about these products.

1 Like