ISC StormCast for Friday, June 23rd, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 June 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, June 23rd, 2003 edition of the Sands and at Storm Center's |
| 0:07.0 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Stockholm, Germany. |
| 0:14.2 | I told you this week, I'll be in actually next week, too, I'll be a little bit off with respect to the recordings here because of the |
| 0:21.7 | time zone difference. So yesterday, just as I finished recording, I did learn that, well, |
| 0:28.4 | Apple released updates for all of its operating systems, fixing three vulnerabilities that are |
| 0:36.4 | already actively being exploited. |
| 0:40.1 | Kasperski reported these vulnerabilities to Apple, which indicates that these |
| 0:45.8 | vulnerabilities are likely related to a compromise of devices at Kasperski, which |
| 0:52.7 | they reported about a week or so ago. |
| 0:56.8 | I think they called it Operation Triangle. |
| 1:00.8 | Two of the vulnerabilities are affecting WebKit. |
| 1:03.9 | WebKit, of course, is the engine behind Apple's browsers, |
| 1:08.5 | so Safari and pretty much anything else that parses HTML and such in Safari, visiting |
| 1:15.9 | malicious website can execute arbitrary code. |
| 1:21.2 | This will typically only give you code execution privileges within the web browser's sandbox. |
| 1:28.3 | And this is where the third vulnerability comes in. |
| 1:31.6 | That third vulnerability does actually allow approach escalation and does allow |
| 1:37.6 | executing arbitrary code with kernel privileges. |
| 1:41.2 | So these vulnerabilities have to be chained together to lead to a complete system |
| 1:46.9 | compromise the way Kraski described to Malver that they observed. Now, in the reporting by Kraski, |
| 1:53.9 | I've seen they only noted older operating systems being affected, but these vulnerabilities are |
| 2:00.5 | being patched in all current operating systems up to iOS 16.5. Now we have 16.5.1 as well as a macOS Ventura or 13.4, which now is up to 13.4.1. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

