meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 19th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 February 2024

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SolarWinds Patch; Chrome CORS Extension; Biometrics Theft

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, February 19th, 2020, 4 edition of the Sandsenet Storm Center's Stormcast.

0:09.0

My name is Johannes Ulrich and then I'm recording from Jacksonville, Florida.

0:14.9

Let's start today with a couple of vulnerabilities.

0:18.3

First one is in solar winds, in particular in the Access Rights Manager,

0:24.6

abbreviated Arm, and here Arm of course is not used for the CPU architecture. There are a total of

0:32.6

five different vulnerabilities being patched in SolarWinds arm and three of them are rated critical.

0:41.3

One is your classic deseralization vulnerability.

0:45.3

Of course, that's one where there are already exploits, kind of an exploit patterns available.

0:51.1

And then there are two directory traversal remote code execution vulnerabilities in this

0:58.8

product. The deseratural vulnerability does require authentication. The directory traversal

1:05.8

vulnerabilities do not require authentication to exploit the vulnerability. Oddly enough, I don't see the

1:13.9

vulnerabilities listed in SolarWinds' global secured advisory page, but they are listed as part of

1:22.3

the release notes for Arm-2020.2.3.

1:30.2

And I'll link to that in the show notes.

1:32.9

These vulnerabilities were reported by Trent Micro's third initiative

1:34.6

and no indication here whether or not

1:37.4

they have already been exploited.

1:41.0

And as of the upcoming version

1:43.7

1-2-3 of Google Chrome, which should show up sometime in March,

1:50.3

Google Chrome is planning on making some changes to how Course works for their browser.

1:58.3

Course, the Cross Origin Resource resource sharing describes how JavaScript being loaded

2:03.4

from one webpage is able to access JavaScript on another web page. Typically, there are sort of

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.