meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 27th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 27 January 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Citrix ADC Updates; Windows Fix Breaks Printer; GE Medical Devices

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 27th, 2020 edition of the Sands and its Stormsendors Stormcast.

0:07.8

My name is Johannes Ulrich, and the day I'm recording from Augusta, Georgia.

0:13.2

On Friday, Citrix made available the last patches for the Citrix ADC and Citrix Gateway Vulnerability, CVE 2019, 19781.

0:26.6

The last patch released was for version 10.5, and with this patch, you have now patches available

0:34.6

for all currently still supported versions of Citrix ADC, Cirrix Gateway,

0:41.0

and Citrix SD-WAN.

0:43.7

Of course, the big question everybody's mind is, are you already compromised?

0:48.3

The quick answer is, well, that depends.

0:52.3

If you apply the workaround before Christmas, then you're probably okay.

0:59.0

If you waited with the workaround until after about January 6th, then chances are that you have been compromised.

1:08.0

Now, I mentioned on Friday that Citrix and Fire Eye came up with a scanner to check

1:15.1

if your system has been compromised. This scanner is not perfect. If you have a system that is

1:23.6

vulnerable, it's exposed, and you didn't apply any workaround, you're just applying the patch

1:29.3

now, then I would say it's pretty certain that that system has gotten compromised.

1:36.3

Now the Fire Eye tool is certainly a useful tool. I don't want to diminish its value here,

1:42.3

but be aware if it shows you that the system was compromised,

1:47.0

then please do not just remove the artifacts that it finds.

1:52.0

Likely, you got compromised by several exploits.

1:56.0

Some of them may be detected by the tool, some of them will not. The only way I would use this Fire Eye tool

2:03.2

is if it shows that you are compromised,

2:06.5

rebuild the system from scratch.

2:09.7

The first way you could possibly use the Fire Eye tool

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.