
DEF CON 33 - Breaking into thousands of cloud based VPNs with 1 bug -David Cash, Rich Warren
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:51
This talk reveals critical vulnerabilities in major Zero Trust Network Access (ZTNA) products, demonstrating they fail to deliver true "zero trust" security 0:42.
Key Takeaways:
• Multiple ZTNA vendors including Checkpoint, Zcaler, and Netscope had authentication bypasses allowing unauthorized access 2:45, 8:53, 15:31
• Device tokens could be extracted and reused to impersonate users, bypassing steering policies 10:45
• Privilege escalation vulnerabilities exist in all examined products via insecure inter-process communication 24:20
• Hardware IDs and posture checks can be spoofed, undermining device verification claims 28:02, 30:01
The presenters conclude that ZTNA is more accurately described as "always trust, never verify" rather than the promised zero trust principle 38:30.
Sources:
- 0:42 Introduction to zero trust concept
- 2:45 Checkpoint Harmony vulnerabilities
- 8:53 Zcaler SAML authentication bypass
- 10:45 Zcaler device token extraction and replay
- 15:31 Netscope authentication bypass
- 24:20 Privilege escalation vulnerabilities
- 28:02 Posture check bypassing
- 30:01(https://www.youtube.com/watch?v=RN
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Good afternoon, Defcon. Uh, our next talk is up zero trust total bust. Please give a big welcome to our next speakers, Dave and Rich. [Applause] Hey everyone, thanks for coming to our talk uh about zero trust network access. Um, I'm Dave, this is Rich. Uh we both work at Amberwolf which is a UK based consultancy specializ in red teaming and and bone research. We're covering a lot of bugs in this 45 minutes. Uh but all of the technical details will be on our blog uh within the next few weeks, some of them straight after this talk. So everyone's heard of zero trust. The theory is that no user device or request is inherently trusted. Everything must be continuously evaluated against a set of access controllers. So even if you've got valid creds, you won't get access unless all the criteria ar…