meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, October 28th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 October 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OpenSSL Versions; Apple Updates; 1Tbps Fodcha Botnet;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, October 28, 2022 edition of the Sands and its Storm Center's

0:08.5

Stormcast. My name is Johannes Ulrich and I'm recording from Augusta, Georgia.

0:15.3

I mentioned yesterday that OpenSSSL announced a critical patch for this coming Tuesday.

0:22.1

The patch will affect OpenSL version 3.0.

0:26.6

So today I started a diary with a list of different Linux distributions and what OpenSL

0:33.3

versions they include by default.

0:36.6

As a rule of thumb, you will likely find OpenSSL on Linux

0:41.2

distributions released over the last two years. So for example, Ubuntu 2004 still has OpenSL

0:51.0

1.1.1.1, but the latest Ubuntu 22.04, that one has OpenSL 3.0. But note that copies of

1:03.5

OpenSSL may also be installed later as additional updates or as part of other software.

1:10.8

MacOS is a little bit tricky here.

1:12.7

It comes by default with Libre SSL, so not with OpenSSSL, but OpenSL may then be installed

1:20.8

via Mac ports or HomePro, or again, will be included in other software that you may be installing.

1:28.2

I will keep things updated and the list sort of should expand a little bit over the weekend.

1:34.8

If you find any omissions, please send them to me.

1:38.3

And Apple today released updates for iOS and iPad OS 15.

1:46.2

Remember, the latest version is 16 and the latest version did receive updates earlier this

1:52.6

week that included a fix for a seraday vulnerability.

1:57.4

These updates for iPad OS and iOS 15 are now including these same security fixes, including the fix for CVE 2022-22827, which is the vulnerability that's already being exploited.

2:16.5

360 NetLab reports about the Fajah botnet as they call it and that it now reached a complete

2:25.3

firepower of one terabit per second.

2:30.3

This botnet is being used to launch distributed denial of service attacks, and 360 NetLab has first seen this botnet around April, but since then it sort of has observed it being upgraded and the botnet itself growing.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.