meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, September 18th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 September 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OSSEC Active Response; MSFT Mac Office Patch; VMWare Patch; Secure Boot; End of Flash

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, September 18th, 2020 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich.

0:10.4

And today I'm recording from Jacksonville, Florida. And yes, today it's actually Friday. Sorry for confusing you yesterday with the wrong day.

0:22.3

In responding to security events, speed is often off the essence.

0:27.7

And of course, you also want to be repeatable.

0:30.9

Today we have a great diary by Xavier introducing the active response feature in OSEC. OSEC is mostly a tool that collects

0:42.0

logs and parses them into a standard format, but it also has the ability to run scripts whenever

0:49.7

it sees a certain log entry. So this can be used to essentially automatically, for example,

0:57.1

then disconnect systems from a network or maybe suspend a virtual machine or such if there is a

1:05.0

suspicion that this particular system is compromised. And as usual, you'll find more details in Xavier's post from today.

1:16.6

And Microsoft this week also released updates for Office for the Mac.

1:22.6

These updates were not released as part of the regular patch Tuesday.

1:26.6

There are total of five vulnerabilities being

1:29.7

patched in this update, one for Excel, two for Word, and two for the office suite. Now,

1:37.9

these vulnerabilities are identical to vulnerabilities that were patched as part of Patch Tuesday.

1:44.0

This is just now the Mac version of these patches.

1:49.6

Not sure why this wasn't released at Patch Tuesday,

1:52.8

but this has happened before that the Mac patches were released a little bit delayed.

1:59.7

And VMware did release this week a new version of VMware Fusion version 12, which

2:06.1

fixes an important privilege escalation vulnerability.

2:10.9

Now, VMware 11 also suffers from that exact vulnerability, but there is at this point no patch available.

2:20.9

And patch should be coming out soon.

2:24.0

The Mvarez says it's pending and did not note a specific release date.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.