ISC StormCast for Friday, May 19th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 May 2017
⏱️ 13 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, May 19th, 2017 edition of the Sands and Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich, and I'm recording from San Diego, California. |
| 0:13.4 | Last weekend showed how important it is to keep your systems patched, |
| 0:18.5 | but the challenge is to stay oppressed of what patches are available |
| 0:23.8 | for your organization's systems. Xavier put together a little Python script to help you with |
| 0:31.5 | just that. The script will monitor the CVE database for vulnerabilities that match your selected profile, so you can select |
| 0:41.0 | operating systems and software that you are interested in, and then it will send you an email |
| 0:48.1 | whenever it finds a new vulnerability. |
| 0:50.9 | It's pretty easy to use, and in particular, for smaller organizations, maybe a nice supplement to regular vulnerability scans. |
| 1:00.8 | One Agrii, of course, incited a discussion about the duty of government organizations and other researchers to disclose vulnerabilities. |
| 1:10.6 | They discover. |
| 1:12.6 | One argument that is sometimes used is that if one entity is able to discover the vulnerability, |
| 1:19.6 | then others will probably do so as well. |
| 1:23.6 | As a result, these other entities may as well then use this vulnerability against you. |
| 1:30.5 | So it's in your best interest to disclose them to the vendor and have a patch available for your own networks as well. |
| 1:40.5 | And what happens as more and more researchers, of course, discover certain vulnerabilities. |
| 1:46.0 | The risk and the probability of these vulnerabilities being disclosed, of course, increases. |
| 1:53.0 | So far, there wasn't really any good data about sort of the rediscovery rate of vulnerabilities, |
| 1:59.0 | but in March, a paper by Trey Herr actually looked into |
| 2:04.5 | this question a little bit more systematic. He had a number of different data sets to look at. |
| 2:11.0 | One of the more recent ones was a database of Android vulnerabilities discovered between 2015 and 2016. |
| 2:20.3 | And essentially he looked at how many of these vulnerabilities were reported multiple times. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

