Nexus: A Claroty Podcast

Sharon Brizinov on Hacking and Securing PLCs


Listen Later

In this episode of the Aperture podcast, Claroty Team82 vulnerability research lead Sharon Brizinov covers a presentation he’s giving at the S4x22 conference in Miami that explains a unique attack against Siemens SIMATIC 1200 and 1500 PLCs that enabled native code execution on the device. 
Also, Brizinov explains his participation in the Pwn2Own contest. S4 hosts the only ICS-focused version of Pwn2Own, and this year there are four categories of targets in scope: control servers, OPC UA servers, data gateways, and HMIs.
“The goal in most cases is to achieve remote code execution, not only to find a vulnerability but achieve exploitation,” Brizinov said. “Usually we are able to find at least one vulnerability, but the real challenge is to exploit those vulnerabilities. Usually the difficulty around this is to bypass the different security mitigations that both the software, hardware, or operating system present.”



...more
View all episodesView all episodes
Download on the App Store

Nexus: A Claroty PodcastBy Claroty

  • 5
  • 5
  • 5
  • 5
  • 5

5

16 ratings


More shows like Nexus: A Claroty Podcast

View all
Risky Business by Patrick Gray

Risky Business

361 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,007 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,877 Listeners

Conan O’Brien Needs A Friend by Team Coco & Earwolf

Conan O’Brien Needs A Friend

59,406 Listeners

@BEERISAC: OT/ICS Security Podcast Playlist by Anton Shipulin / Listen Notes

@BEERISAC: OT/ICS Security Podcast Playlist

7 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

Industrial Cybersecurity Insider by Industrial Cybersecurity Insider

Industrial Cybersecurity Insider

0 Listeners

PrOTect It All by Aaron Crow

PrOTect It All

7 Listeners