DEF CON 33  - Breaking into thousands of cloud based VPNs with 1 bug -David Cash, Rich Warren

DEF CON 33 - Breaking into thousands of cloud based VPNs with 1 bug -David Cash, Rich Warren

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:51

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This talk reveals critical vulnerabilities in major Zero Trust Network Access (ZTNA) products, demonstrating they fail to deliver true "zero trust" security 0:42.

Key Takeaways:
• Multiple ZTNA vendors including Checkpoint, Zcaler, and Netscope had authentication bypasses allowing unauthorized access 2:45, 8:53, 15:31
• Device tokens could be extracted and reused to impersonate users, bypassing steering policies 10:45
• Privilege escalation vulnerabilities exist in all examined products via insecure inter-process communication 24:20
• Hardware IDs and posture checks can be spoofed, undermining device verification claims 28:02, 30:01

The presenters conclude that ZTNA is more accurately described as "always trust, never verify" rather than the promised zero trust principle 38:30.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Good afternoon, Defcon. Uh, our next talk is up zero trust total bust. Please give a big welcome to our next speakers, Dave and Rich. [Applause] Hey everyone, thanks for coming to our talk uh about zero trust network access. Um, I'm Dave, this is Rich. Uh we both work at Amberwolf which is a UK based consultancy specializ in red teaming and and bone research. We're covering a lot of bugs in this 45 minutes. Uh but all of the technical details will be on our blog uh within the next few weeks, some of them straight after this talk. So everyone's heard of zero trust. The theory is that no user device or request is inherently trusted. Everything must be continuously evaluated against a set of access controllers. So even if you've got valid creds, you won't get access unless all the criteria ar…