Loading...
Loading...
Browse all stories on DeepNewz
VisitWhich major ISP will first announce mitigation for BlastRADIUS vulnerability by September 30, 2024?
Comcast • 25%
AT&T • 25%
Verizon • 25%
Other • 25%
Official announcements from ISPs
Cloudflare Discloses Critical BlastRADIUS Vulnerability in RADIUS Protocol Allowing MitM Attacks
Jul 9, 2024, 01:25 PM
Cloudflare and a team of researchers have disclosed a critical vulnerability in the RADIUS protocol, which is widely used to control administrative access to networking equipment. The vulnerability, known as BlastRADIUS, exploits the outdated use of the MD5 hash function, allowing attackers to perform Man-in-the-Middle (MitM) attacks by modifying Access-Request packets undetected and forcing user authentication. This flaw, which involves a novel chosen-prefix collision attack, can lead to unauthorized network access, compromised integrity checks, and forging authentication messages. Internet Service Providers (ISPs) and organizations are advised to update their RADIUS servers, use TLS/IPSec, and avoid PAP/CHAP methods to mitigate the risk.
View original story
Comcast • 25%
AT&T • 25%
Verizon • 25%
Other • 25%
Comcast • 25%
AT&T • 25%
Verizon • 25%
Other • 25%
Apple • 25%
Microsoft • 25%
Third-party cybersecurity firm • 25%
No patch released • 25%
Issuing patches and advisories • 33%
Collaborating with affected parties • 33%
Taking legal action against Funnull • 33%
Verizon • 25%
AT&T • 25%
T-Mobile • 25%
Other • 25%
AT&T • 25%
Verizon • 25%
T-Mobile • 25%
Other • 25%
Yes • 50%
No • 50%
Microsoft • 25%
Google • 25%
Amazon • 25%
Other • 25%
Yes • 50%
No • 50%
Vertex Protocol • 25%
Steer Protocol • 25%
Gnosis Multisig • 25%
Other • 25%
No • 50%
Yes • 50%
Yes • 50%
No • 50%
No • 50%
Yes • 50%
Using TLS/IPSec • 25%
Other • 25%
Updating RADIUS servers • 25%
Avoiding PAP/CHAP methods • 25%