_-min.jpg)
Datagram Transport Layer Security
Internet protocolWikipedia
40
MENTIONS
17
EPISODES
15
PODCASTS
Search complete. 40 mentions across 17 episodes found for "Datagram Transport Layer Security".
Oct 9, 2026
Ingela Andin on the TLS Stack Running Under Every BEAM App
I
17:16Ingela AndinGUEST
So, uh, so that you could, like, have a malicious server fool the client.
I
17:21Ingela AndinGUEST
And some of them are against the DTLS, which in short is, uh, TLS over UDP, and that means that application data may be lost.
I
17:32Ingela AndinGUEST
Um, and, uh, this is a requirement area where we put less effort.
I
17:39Ingela AndinGUEST
It was, uh, somebody that, uh, wanted it, but then they dropped requirement.
SNMP: The 40-Year-Old Stopgap Running Your Rack
H
5:35Herman PoppleberryHOST
The manager receives traps and informs on port 162.
H
5:39Herman PoppleberryHOST
And with TLS or DTLS wrapping it, ports 161 and W62.
C
5:45CornHOST
Why UDP? That's a real choice.
H
5:48Herman PoppleberryHOST
Because it's cheap.
Citrix Under Attack + AI Agents Accelerate Cybersecurity
M
0:50Martin ReynoldsHOST
So the first is an, uh, an authenticated, uh, RCE flaw, uh, that hits nearly every version of NetScaler, even default deployments.
M
1:01Martin ReynoldsHOST
And the second is a memory overflow that also leads to RCE, and DTLS is on default on VPN, uh, virtual servers.
M
1:10Martin ReynoldsHOST
So almost all of them are in scope.
S
1:13Starr BrownGUEST
Yeah.
Microsoft' Digital Defense Report - The 443 Podcast - Episode 390
M
5:46Marc LaliberteHOST
Never forget.
M
5:48Marc LaliberteHOST
So anyways, the vulnerability itself takes place in how the Citrix NetScaler appliance handles DTLS fragmentation.
M
5:56Marc LaliberteHOST
So DTLS, it's the way to add encryption to UDP packets.
M
6:01Marc LaliberteHOST
There's a bit of a handshake that's kind of different than how you would do it over a TCP-based connection.
M
6:07Marc LaliberteHOST
But it supports fragmenting packets, meaning you can send a larger piece of data over multiple smaller packets.
Hacking Without Boundaries - Michael Jenkins - PSW #946
P
45:10Paul AsadoorianHOST
We can hit these really quick.
P
45:12Paul AsadoorianHOST
Watchtower analyzed that pre-auth DTLS memory overflow.
P
45:17Paul AsadoorianHOST
Turns out DTLS is TLS over UDP.
P
45:20Paul AsadoorianHOST
Weird.
P
45:21Paul AsadoorianHOST
Okay.
7 MINS LATER
P
52:20Paul AsadoorianHOST
So like if you're running that version, you're vulnerable.
P
52:23Paul AsadoorianHOST
And the rest of them require that a feature be enabled.
P
52:26Paul AsadoorianHOST
The DTLS is actually enabled if you're using the VPN functionality on it.
Hacking Without Boundaries - Michael Jenkins - PSW #946
P
45:10Paul AsadoorianHOST
We can hit these really quick.
P
45:12Paul AsadoorianHOST
Watchtower analyzed that pre-auth DTLS memory overflow.
P
45:17Paul AsadoorianHOST
Turns out DTLS is TLS over UDP.
P
45:20Paul AsadoorianHOST
Weird.
P
45:21Paul AsadoorianHOST
Okay.
7 MINS LATER
P
52:20Paul AsadoorianHOST
So like if you're running that version, you're vulnerable.
P
52:23Paul AsadoorianHOST
And the rest of them require that a feature be enabled.
P
52:26Paul AsadoorianHOST
The DTLS is actually enabled if you're using the VPN functionality on it.
Hacking Without Boundaries - Michael Jenkins - PSW #946
P
45:10Paul AsadoorianHOST
We can hit these really quick.
P
45:12Paul AsadoorianHOST
Watchtower analyzed that pre-auth DTLS memory overflow.
P
45:17Paul AsadoorianHOST
Turns out DTLS is TLS over UDP.
P
45:20Paul AsadoorianHOST
Weird.
P
45:21Paul AsadoorianHOST
Okay.
7 MINS LATER
P
52:20Paul AsadoorianHOST
So like if you're running that version, you're vulnerable.
P
52:23Paul AsadoorianHOST
And the rest of them require that a feature be enabled.
P
52:26Paul AsadoorianHOST
The DTLS is actually enabled if you're using the VPN functionality on it.
Cyber Daily News for September 30th, 2026
S
0:59speaker_0HOST
It fires during the first handshake before any login and hands over route.
S
1:03speaker_0HOST
DTLS is on by default for gateway VPNs, so patch now and hunt for the Blipshot and Sloughchip web shells.
S
1:10speaker_0HOST
Two flaws in Amazon Bedrock Agent Core's Python kit led a crafted package named smuggle-shell-commands into its code interpreter sandbox, exposing the sandbox's temporary AWS credentials.
S
1:21speaker_0HOST
The awkward part? AWS's first fix was bypassed too.
Cyber Mornings Daily - September 30th, 2026
S
2:45speaker_0HOST
This is the engine that handles incoming data.
S
2:48speaker_0HOST
And specifically, they're exploiting how this engine parses the Datagram Transport Layer Security Protocol or DTLS.
S
2:56speaker_1HOST
DTLS, right, which is heavily used for streaming and VPN connections, I think.
S
3:00speaker_0HOST
Exactly, because it relies on UDP.
S
3:03speaker_0HOST
So it doesn't require that strict back and forth acknowledgement that a standard TCP connection does.
S
3:09speaker_0HOST
It's built for speed.
S
3:10speaker_1HOST
OK, so the engine is expecting this really fast streaming DTLS traffic.
S
3:14speaker_1HOST
How do the attackers break it?
Remote access at risk as Citrix gateways face active attacks
S
0:19speaker_0NARRATOR
One weakness allows unauthenticated code execution in default deployments.
S
0:24speaker_0NARRATOR
The other affects systems with DTLS enabled.
S
0:28speaker_0NARRATOR
CISA added both to its known exploited vulnerabilities catalog, and more than 20,000 internet-exposed instances were reported as potentially at risk.
S
0:39speaker_0NARRATOR
Confirmed compromises were not described as widespread.
7 more episodes mention Datagram Transport Layer Security.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.