{"id":26126,"date":"2025-11-13T14:50:58","date_gmt":"2025-11-13T14:50:58","guid":{"rendered":"http:\/\/localhost\/?p=26126"},"modified":"2025-11-13T14:50:58","modified_gmt":"2025-11-13T14:50:58","slug":"viasat-and-the-terrible-horrible-no-good-very-bad-day","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=26126","title":{"rendered":"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-13T20:05:07&#8243;,&#8221;description&#8221;:&#8221;![Viasat and the terrible, horrible, no good, very bad day](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/11\/threat-source-newsletter-1.jpg)\\n\\nWelcome to this week&#8217;s edition of the Threat Source newsletter.\\n\\nA year ago, fresh off a layoff, I never would have guessed I&#8217;d be spending Halloween weekend bouncing between conversations about space policy, satellite hacking, and wedding plans. That&#8217;s exactly what happened when my space analyst friend came to stay with us for a few days. Between coffee runs, getting sneak peeks of his upcoming book, and painting on skull makeup for a party, we found ourselves deep in discussions about putting data centers in space and, inevitably, the world of satellite cybersecurity.\\n\\nSomewhere within all of that, I realized I was on deck for the newsletter intro soon, and I did what any cyber newbie would do: I asked the nearest expert if there had ever been a well-known cyberattack on satellites. My friend didn&#8217;t even blink before answering, \\&#8221;KA-SAT.\\&#8221;\\n\\nSome light research and a few Webex messages later, I was speaking with our own Joe Marshall &#8212; who, lucky for me, might be the only person at Cisco who&#8217;s been to satellite hacking training.\\n\\nJoe walked me through how on Feb. 24, 2022, just hours before Russia&#8217;s invasion of Ukraine, a cyber attack targeted Viasat&#8217;s KA-SAT satellite network. The attackers exploited a vulnerability in a VPN appliance, gaining access to the network&#8217;s management systems. They then deployed a wiper malware called AcidRain, which was designed to erase data on modems and routers across Europe.\\n\\nSatellite communications were disrupted for thousands of users in Ukraine, but surprisingly, beyond Ukraine&#8217;s borders, approximately 5,800 Enercon wind turbines in Germany lost connectivity for remote monitoring and control.\\n\\nOne surprise from the conversation was the overlap between the AcidRain wiper and  _VPNFilter_, which you may remember from  _Joe &#8216;s September newsletter_. AcidRain may be VPNFilter&#8217;s successor. Take a look:\\n\\n![Viasat and the terrible, horrible, no good, very bad day](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/11\/Screenshot-2025-11-07-at-2.41.26&#8212;PM-1.png)Figure 1. Section headers strings tables for VPNFilter (left) and AcidRain (right). Credit: SentinelOne.\\n\\nIdentical, hinting at a shared compiler and other technical links, as  _SentinelOne &#8216;s_  _blog_ details.\\n\\nWhat followed this summary was a LOT of questions on my part. What  _was_ the VPN vulnerability? How did the wiper work, exactly? What are the pros and cons of replacing vs. fixing the modems, and what about the logistics of the winning decision? Ultimately, while the AcidRain attack was destructive, it was, in the context of what else was happening to Ukraine&#8217;s infrastructure, a blip.\\n\\nAs a newcomer to both cybersecurity and Talos, I keep discovering that there are always gaps in the story. I didn&#8217;t get all my questions answered because companies guard details, official statements leave out key information, and sometimes, even years later, we&#8217;re still piecing things together. Being okay with that is a tall order for people who scour logs looking for a needle in a stack of needles. But when attacks are raining down, customers aren&#8217;t asking you to send a flawless analysis. They want to know what you&#8217;redoing to keep them safe.\\n\\nSo, as I write this, still with more questions than answers about AcidRain and the KA-SAT attacks, I&#8217;m learning to find peace in knowing that curiosity is the foundation for future expertise. Keep acquiring knowledge, asking questions (both basic and complex), and being okay with some uncertainty.\\n\\n## The one big thing\\n\\nCisco Talos _published a new blog today_ on the Kraken ransomware group. Linked to HelloKitty, they double-extort organizations globally with cross-platform attacks and use advanced techniques like encryption benchmarking and anti-analysis. Kraken has also launched a new underground forum to strengthen ties within the cybercrime community.\\n\\n### Why do I care?\\n\\nKraken&#8217;s advanced, cross-platform techniques &#8212; including encryption benchmarking and evasion methods &#8212; raise the threat level for organizations of all sizes, and may inspire similar advancements in future ransomware. Plus, their new secure underground forum may accelerate collaboration between threat actors, making robust, layered defenses and intelligence sharing among defenders even more critical.\\n\\n### So now what?\\n\\nPrioritize patching known vulnerabilities (especially SMB), strengthen credential management, and implement comprehensive endpoint, network, and access security solutions. Continuous monitoring, incident response planning, and user awareness training are crucial to detect and contain threats early.\\n\\n## Top security headlines of the week\\n\\n**SAP fixes serious security issues &#8211; here &#8216;s how to stay safe**   \\nA patch is now publicly available, and while SAP&#8217;s users were previously notified, the researchers are once again urging everyone to apply it as soon as possible since the risk is only going to get bigger going forward. (_TechRadar_)\\n\\n**Phishing tool uses smart redirects to bypass detection**   \\nA new phishing tool targeting Microsoft 365 users called Quantum Route Redirect simplifies what was once a technically complex campaign flow, as well as offers a uniquely evasive redirect feature that can bypass even robust email protections. (_Dark Reading_)\\n\\n**Cisco finds open-weight AI models easy to exploit in long chats**   \\nThe report, titled Death by a Thousand Prompts: Open Model Vulnerability Analysis, analyzed eight leading open-weight language models and found that multi-turn attacks, where an attacker engages the model across multiple conversational steps, were up to ten times more effective than one-shot attempts. (_HackRead_)\\n\\n**Nearly 30 alleged victims of Oracle EBS hack named on Cl0p ransomware site**   \\nThe Cl0p website lists major organizations such as Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ Corporation, and Copeland. (_SecurityWeek_)\\n\\n**Kimsuky APT takes over South Korean Androids, abuses KakaoTalk**   \\nOne of North Korea&#8217;s formidable advanced persistent threat (APT) groups is targeting Android users in South Korea with a remote reset attack that exploits a feature in Google aimed at helping users find their devices. (_Dark Reading_)\\n\\n## Can&#8217;t get enough Talos?\\n\\n**The TTP: How Talos built an AI model into one of the internet &#8216;s most abused layers**  \\nHazel talks with Talos researcher David Rodriguez about how adversaries use DNS tunneling to sneak data out of networks, why it&#8217;s so difficult to spot in real time, and how Talos built an AI model to detect it without breaking anything important (like the internet).\\n\\n**_The 2026 Snort Calendar is now available_**   \\nSnorty will pose as a new mythical creature each month. To get your copy, fill out our short survey. Calendars will begin shipping in December 2025. U.S. shipping only, available while supplies last.\\n\\n** _Talos Takes: How attackers use your own tools against you_**   \\nFrom a wave of Toolshell events, to a rise in post-exploitation phishing, and the misuse of legitimate tools like Velociraptor, this quarter&#8217;s cases all point to a theme: attackers are getting very good at living off what&#8217;s already in your environment.\\n\\n**_Do robots dream of secure networking?_**   \\nThis blog demonstrates a proof of concept using LangChain and OpenAI, integrated with Cisco Umbrella API, to provide AI agents with real-time threat intelligence for evaluating domain dispositions.\\n\\n## Upcoming events where you can find Talos\\n\\n  *  _DeepSec IDSC_ (Nov. 18 &#8211; 21) Vienna, Austria\\n  *  _AVAR_ (Dec. 3 &#8211; 5) Kuala Lumpur, Malaysia\\n\\n\\n\\n## Most prevalent malware files from Talos telemetry over the past week\\n\\n**SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507**   \\nMD5: 2915b3f8b703eb744fc54c81f4a9c67f    \\nTalos Rep: _https:\/\/talosintelligence.com\/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507_   \\nExample Filename: e74d9994a37b2b4c693a76a580c3e8fe_1_Exe.exe    \\nDetection Name: Win.Worm.Coinminer::1201\\n\\n**SHA256: 41f14d86bcaf8e949160ee2731802523e0c76fea87adf00ee7fe9567c3cec610**   \\nMD5: 85bbddc502f7b10871621fd460243fbc    \\nTalos Rep: _https:\/\/talosintelligence.com\/talos_file_reputation?s=41f14d86bcaf8e949160ee2731802523e0c76fea87adf00ee7fe9567c3cec610_   \\nExample Filename: 85bbddc502f7b10871621fd460243fbc.exe    \\nDetection Name: W32.41F14D86BC-100.SBX.TG\\n\\n**SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974**   \\nMD5: aac3165ece2959f39ff98334618d10d9    \\nTalos Rep: _https:\/\/talosintelligence.com\/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974_   \\nExample Filename: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974.exe    \\nDetection Name: W32.Injector:Gen.21ie.1201\\n\\n**SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91**   \\nMD5: 7bdbd180c081fa63ca94f9c22c457376    \\nTalos Rep: _https:\/\/talosintelligence.com\/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91_   \\nExample Filename: e74d9994a37b2b4c693a76a580c3e8fe_3_Exe.exe    \\nDetection Name: Win.Dropper.Miner::95.sbx.tg\\n\\n**SHA256: d933ec4aaf7cfe2f459d64ea4af346e69177e150df1cd23aad1904f5fd41f44a**   \\nMD5: 1f7e01a3355b52cbc92c908a61abf643    \\nTalos Rep: _https:\/\/talosintelligence.com\/talos_file_reputation?s=d933ec4aaf7cfe2f459d64ea4af346e69177e150df1cd23aad1904f5fd41f44a_   \\nExample Filename: cleanup.bat    \\nDetection Name: W32.D933EC4AAF-90.SBX.TG\\n\\n**SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe**   \\nMD5: bf9672ec85283fdf002d83662f0b08b7   \\nTalos Rep: _https:\/\/talosintelligence.com\/talos_file_reputation?s=c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe_   \\nExample Filename: f_003b6c.html    \\nDetection Name: W32.C0AD494457-95.SBX.TG&#8221;,&#8221;published&#8221;:&#8221;2025-11-13T19:00:14&#8243;,&#8221;modified&#8221;:&#8221;2025-11-13T19:00:14&#8243;,&#8221;type&#8221;:&#8221;talosblog&#8221;,&#8221;title&#8221;:&#8221;Viasat and the terrible, horrible, no good, very bad day&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/blog.talosintelligence.com\/viasat-and-the-terrible-horrible-no-good-very-bad-day\/&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-13T20:05:07&#8243;,&#8221;description&#8221;:&#8221;![Viasat and the terrible, horrible, no good, very bad day](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/11\/threat-source-newsletter-1.jpg)\\n\\nWelcome to this week&#8217;s edition of the Threat Source newsletter.\\n\\nA year ago, fresh off a layoff,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,7,69,11,5],"class_list":["post-26126","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-security","tag-talosblog","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=26126\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-13T20:05:07&#8243;,&#8221;description&#8221;:&#8221;![Viasat and the terrible, horrible, no good, very bad day](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/11\/threat-source-newsletter-1.jpg)nnWelcome to this week&#8217;s edition of the Threat Source newsletter.nnA year ago, fresh off a layoff,...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=26126\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-13T14:50:58+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2\",\"datePublished\":\"2025-11-13T14:50:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126\"},\"wordCount\":1786,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"Security\",\"talosblog\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=26126#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126\",\"name\":\"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-13T14:50:58+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=26126\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=26126#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=26126","og_locale":"en_US","og_type":"article","og_title":"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-13T20:05:07&#8243;,&#8221;description&#8221;:&#8221;![Viasat and the terrible, horrible, no good, very bad day](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/11\/threat-source-newsletter-1.jpg)nnWelcome to this week&#8217;s edition of the Threat Source newsletter.nnA year ago, fresh off a layoff,...","og_url":"https:\/\/zero.redgem.net\/?p=26126","og_site_name":"zero redgem","article_published_time":"2025-11-13T14:50:58+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=26126#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=26126"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2","datePublished":"2025-11-13T14:50:58+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=26126"},"wordCount":1786,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","Security","talosblog","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=26126#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=26126","url":"https:\/\/zero.redgem.net\/?p=26126","name":"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-13T14:50:58+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=26126#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=26126"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=26126#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Viasat and the terrible, horrible, no good, very bad day_TALOSBLOG:2B7C070BB0BE7343A7C0C134DDA5C6D2"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/26126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26126"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/26126\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}