Jon Calalang is a Solutions Architect at F5, covering Cloud and Automation solutions. He has previously appear on Buu's Hour: Cloud Edition to discuss the Top 3 Automation Tools to Learn in 2020 - https://youtu.be/JBktLySSnf4
He will join Daryl and Buu on the Monday live stream to go through the traditional guest Q&A!
This Week:IMPORTANT – RCE VULNERABILITY – CVE-2020-5902Weekly Update with Jon Calalang, Cloud and Automation Solutions Architect, F5Reminder: You can listen to this!This newsletter is going monthly, how to get the weekly version and win prizesBuu’s Hour Live Streams for the WeekF5 Technical UpdatesIMPORTANT – F5 TMUI RCE VULNERABILITY CVE-2020-5902A couple days ago, a vulnerability was disclosed for RCE to the TMUI. Patches have been released as well as a temporary mitigation if you cannot patch right away.Further details can be found in K52145254: TMUI RCE vulnerability CVE-2020-5902I created a quick video to show the temporary mitigation: https://www.youtube.com/watch?v=jzoEBwHpLN8
Live StreamsBuilding a Home Lab to Further Your CareerAlex Dow, Co-founder - Mirai SecurityJuly 8th, 3pmhttps://www.youtube.com/watch?v=JpPmtDkOBQo
Building Organizations That Do GoodDavid Wood, Founder – Kina Social Ventures, Founder, WirefireJuly 10th, 1pmhttps://www.youtube.com/watch?v=emdKcX2Ck8k
F5 Technical UpdatesF5 UpdatesTMOS ReleasesWith K52145254: TMUI RCE vulnerability CVE-2020-5902 there have been TMOS releases for:15.1.0.414.1.2.613.1.3.412.1.5.211.6.5.2Updates to BIG-IP VE Supported Platforms Matrixhttps://clouddocs.f5.com/cloud/public/v1/matrix.htmlAttack Signature Updates for ASM and AWAFObtain these at https://downloads.f5.comHow to Setup Shape Log Analysis in Fastlyhttps://devcentral.f5.com/s/articles/How-to-Setup-Shape-Log-Analysis-in-Fastly?page=1If you use Fastly CDN, you can use Shape Log Analysis to analyze HTTP and application logs to look at possible attacks to your applicationsNGINX Controller 3.6 was releasedhttps://docs.nginx.com/nginx-controller/releases/See release notes for the latest features added including:Beta features for:Active Directory integrationMetrics forwarding to SplunkNGINX App Protect 1.2 was releasedhttps://docs.nginx.com/nginx-app-protect/releases/Threat Campaigns has been added!Cloud ResourcesAS3 Best Practiceshttps://devcentral.f5.com/s/articles/AS3-Best-PracticeAS3 is a very powerful declarative interface and you will see it more and more with configuring BIG-IP3 Ways to use F5 BIG-IP with OpenShift 4https://devcentral.f5.com/s/articles/3-Ways-to-use-F5-BIG-IP-with-OpenShift-4Outlines use cases around using BIG-IP for OCP core services, OpenShift Router and for securityLori MacVittie – The Third Wave of Cloud is Crestinghttps://www.f5.com/company/blog/the-third-wave-of-cloud-is-crestingInteresting observations on workload repatriation to on-premisesIndustry ArticlesTechRepublic – How to use NGINX as a reverse proxyhttps://www.techrepublic.com/article/how-to-use-nginx-as-a-reverse-proxy/e-Commerce Site Hackers Now Hiding Credit Card Stealer Inside Image Metadatahttps://thehackernews.com/2020/06/image-credit-card-skimmers.htmlSubscribe to our YouTube channel! - https://www.youtube.com/darylandbuu?sub_confirmation=1
Daryl Montgomery and Buu Lam are the F5 Account Team based in Vancouver, British Columbia covering valued clients across British Columbia, Northwest Territories, Yukon and Nunavut. This weekly show covers recent topics in the world of F5 and information technology in Vancouver. Please consider Subscribing and enabling Notifications. These weekly shows will be live streamed at the beginning of each week. Buu's Hour Live Streams are released throughout the week.
Podcast format on Apple Podcast, Google Play Podcast and SpotifyInstagram - https://www.instagram.com/buushour/LinkedIn -https://www.linkedin.com/in/daryl-montgomery-8876752/https://www.linkedin.com/in/buulam/Buu's Hour B Roll Channel - https://www.youtube.com/channel/UCRSFdUbMRvX925MU7_knxSwWebsite / News