meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, June 4th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 4 June 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Zoom CIS Benchmark @boeke; BIG-IP Vuln; WE.LOCK Vuln; 2xWordpress Plugin Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, June 4th, 2021 edition of the Sands and the Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.0

Well, if you're running Zoom, which probably means everybody listening to this podcast, you probably are familiar with various ways to secure Zoom and

0:24.2

to configure it to be less open in particular to Zoom bombing.

0:29.3

The Center for Internet Security has recently released a benchmark with about a hundred or so

0:36.0

different issues that you may want to check your Zoom configuration

0:41.6

for.

0:42.7

And while I'm still not able to receive the emails that I need to click on in order to actually

0:48.2

obtain a copy of the benchmarks from the Center for Internet Security, there is now a nice script available that automates

0:57.8

verification of this benchmark. So all you have to do is run the script, give it your account

1:04.8

credentials so it can check your configuration, and it'll spit out a nicely formatted report detailing what you may want to

1:15.5

adjust in your Zoom configuration. So if you got some time today, this may be a nice exercise

1:21.0

to run to see if you are in compliance with the benchmark. As usual with these benchmarks, you may not necessarily

1:28.8

find all of the items that they're looking for applicable for your environment.

1:35.8

And F5 released, an update for the Big IP Edge Client for Windows. It fixes memory corruption vulnerability CVE 2020-5897 that could be

1:49.9

triggered to execute arbitrary code. In order to execute the code, the victim would have to visit

1:58.4

a malicious website using the Internet Explorer browser.

2:04.2

The vulnerable component is actually the active X component for a big IPH client.

2:11.7

So other browsers are not affected.

2:16.5

And yes, and then we got another smart lock vulnerability.

2:19.6

Now, there are different types of smart locks.

2:21.4

Some of them, for example, allow local access via, for example, Bluetooth low energy, sometimes

2:28.2

RFID, or in some cases there is also an HTTP API involved in order to remotely lock or unlock

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.