meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 13th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 13 May 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Get-WebRequest Fails; HP BIOS Patch; INTEL BIOS Patch; Zyxel RCE;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 13, 2020 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.7

We do have a quick follow-up by Rob today to a diary that he wrote a few days ago about how to figure out what

0:22.8

the latest patches are that Microsoft has to offer in order to check if your systems are

0:30.9

completely patched.

0:32.8

Now, this involved PowerShell and the connection to the Microsoft Update Catalog in order to retrieve

0:40.5

current available updates, but when Rob moved this script to production, well, it failed.

0:48.0

And apparently the problem here was that the client systems had a rather tightly configured TLS configuration.

0:57.0

It's unusual but still a good idea for clients to limit, for example, the TLS ciphers that they're supporting,

1:07.0

and sadly, the Microsoft Update Catalog does not yet support TLS 1.3 which would have

1:16.4

been an option here. Probably not a huge surprise here from Microsoft's and given that

1:22.4

Microsoft server is a little bit behind here when it comes to TLS 1.3 support.

1:30.4

And I believe only the latest version Windows server 2022 officially supports TLS 1.3 out of the box.

1:41.7

And a little bit lost this week in Microsoft another updates is an update by HP for its

1:49.2

PC bias. This is the May 2020 update released on May 10th and it fixes two vulnerabilities,

1:57.9

both with a base score of 8.8, and both with the possibility of arbitrary

2:05.3

code execution. HP did not include a lot of detail with its advisory, but a long list of

2:13.9

affected systems, including notebooks, desktops, point-of-sales PCs, desktop workstations,

2:20.3

and also thinclined PCs.

2:23.3

But it's not just HP sneaking in some bias updates. We also got some from Intel.

2:30.3

That's the 2022.1 IPU bias advisory. It fixes, I believe it was 11 vulnerabilities,

2:38.0

and the highest CVS score here is 8.2,

2:42.0

which was assigned to four of the vulnerabilities.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.