meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, September 8th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 8 September 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Patches 0-Days; iOS Scareware; Aruba and TP Link Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, September 8, 2023 edition of the Sansonet Stormontas Stormcast.

0:08.5

My name is Johannes Ulrich and today I'm recording from London, England.

0:14.5

Apple today released updates for macOS, iOS, iOS, iPad, OS, as well as watchOS, fixing two vulnerabilities, both of

0:24.2

which are already exploited in the wild. The first one, CVE 202023-41061. Interestingly, a validation

0:33.5

issue in the wallet framework. It could be exploited via a crafted attachment and lead to arbitrary

0:41.6

code execution. The second vulnerability is affecting the image I.O framework. It's a buffer

0:50.2

overflow also leading to code execution.

1:00.1

The image I.O. Warnability, according to the Apple announcement, was discovered by the Citizen Lab at the University of Toronto. The Citizen Lab has in the past discovered similar

1:06.6

vulnerabilities that were usually then linked to commercial spyware being used by governments

1:13.3

to spy on activists.

1:16.4

At this point, I don't see any details about this vulnerability on the Citizen Lab website.

1:23.8

And sticking with Apple here for another story, I ran into some, well, not sure if I should call it scareware or fleeceware earlier today.

1:32.9

The way it was advertised was by tagging users on Facebook. And then, of course, these users' friends will also see the respective messages.

1:45.5

It was a fairly deceptive message, what is sort of just clickbait, saying that, well,

1:50.4

someone has passed away.

1:53.1

The LinkedIn led to your standard scarer page, basically claiming that you are infected with malware.

2:00.7

The software itself was essentially... basically claiming that you are infected with malware.

2:08.0

The software itself was essentially a VPN product for iOS,

2:11.9

and interestingly, it was in the app store,

2:14.8

so it did pass Apple's review.

2:16.6

I did install it briefly.

2:20.6

It does appear to contain some VPN functionality. Didn't really have time to dive into it deeper. If it's just a VPN with some adverb protection,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.