4.9 • 696 Ratings
🗓️ 20 April 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, April 20th, 2020, |
0:04.1 | 23 edition of the Sansonet Stormer's Stormcast. |
0:08.0 | My name is Johannes Ulrich, and today I'm recording from Augusta, Georgia. |
0:15.0 | Well, we got yet another already exploited vulnerability in Google Chrome that has been patched by Google. |
0:23.4 | Google will release the new version of Google Chrome that fixes a total of eight warnabilities. |
0:29.3 | One of these vulnerabilities, CVE 2023-2136, it's an integer overflow in the Skiya is already being exploited. |
0:39.3 | This particular vulnerability could allow a breakout from the Google Chrome sandbox. |
0:46.6 | I just want to reiterate that we probably should stop asking people to update Google Chrome. |
0:53.7 | There has been a lot of talk about fake update notices on different websites. |
0:59.7 | Typically, the only thing you really need to do in order to update Google Chrome is just |
1:04.2 | completely exit Google Chrome and restart it, which if you make that a daily habit, you |
1:10.0 | should be pretty safe. And Oracle |
1:13.6 | released its quarterly critical patch update. This one fixes 433 different vulnerabilities. Overall, |
1:22.4 | this is not unusual given the wide range of products being covered here, and this is only being released every quarter. |
1:30.5 | There are a couple of sort of noteworthy critical vulnerabilities in commerce, also communication application, and Golden Gate that can be exploited without authentication. |
1:41.1 | There are also a few sort of healthcare-related applications being affected by these |
1:46.9 | vulnerabilities. |
1:48.4 | Given all the focus sort of in recent years on attacks against healthcare, certainly |
1:53.1 | something that you should pay attention to. |
1:57.5 | And then a couple of updates from GitHub to make open source software a bit more secure, at least more transparent. |
2:04.6 | One thing is a GitHub option now that if you're building NPM packages will include provenance information. |
2:13.6 | What this means is it will include information about how the particular package was built, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.