We patched for a CVE last week that a malicious usb sound card device could be use the gain root.
On a Vm? Is that something we really need to worry about??
We patched for a CVE last week that a malicious usb sound card device could be use the gain root.
On a Vm? Is that something we really need to worry about??
They do not care if the issue is in a piece of code that is never executed and would require full access to the machine. It is there and tool X reports it.
Even security audits are terrible, when they don't find anything major they start reporting stuff that few percent of companies have implemented just to stuff their reports, it is ridiculous.
Then companies started hiring paper pushers into security roles and discretion no longer mattered, it just became a game of "Check the box" with no regard for what is actually running in prod, or whether you're actually vulnerable.
Same shit with auditors. I deal with PCI and it's a fight to explain why the "compensating controls" work to a non technical auditor. If it doesn't check the box exactly, good luck.