meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 11th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 11 February 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. WebKit 0-Day Patch; Zyxel NAS Exploit; WMIC Removal; Zoom Mac Microphone; Planted Evidence

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 11th, 2020 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:13.4

Today we've got an emergency patch from Apple. This patch fixes a single vulnerability in WebKit and effects MacOS Monoray, iPadOS, iOS,

0:26.6

and then we also have a standalone update for Safari that is for MacOS, Bixer, and Catalina,

0:34.7

so for the last two versions of a macOS.

0:39.5

The individual flaw being patched here is CVE 2020, 22620.

0:46.4

Like I said, it's a web kit vulnerability that can lead to arbitrary code execution.

0:51.9

So typically this would be exploited via a malicious website that's viewed

0:57.7

in Safari. But WebKit can also be used in other components within these operating systems

1:05.5

that display HTML content. What made this patch so urgent is that it was already being exploited in the wild

1:12.9

and not sure if you're following some of discussions around NSO group and similar companies

1:18.0

that have used some of these unpublished vulnerabilities in the past. I believe part of the

1:25.4

cleanup around all of this triggered this reasons

1:29.3

that of increase in these kind of vulnerabilities and related patches.

1:34.5

I believe this is the third one now that we had within a couple months.

1:40.2

And then in more sort of run-off the mill exploits, we did see an increase in our honeypots

1:46.8

for hits that looked for a psych cell network accessible storage vulnerability.

1:54.4

The reason I kind of point this one out is not because it's really super recent.

1:58.9

It's about a year old this vulnerability, but when

2:02.8

it originally became public, it was after the exploit was already traded sort of in underground

2:10.6

forums. About half a year ago, it certainly has been seen exploited rather widely, but then again, these network-accessible storage

2:20.5

devices really are a little bit sort of a focus of mine lately, because I see so many people

2:26.7

are using them and exposing them to the internet, because that's sort of how they're advertised.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.