4.9 • 696 Ratings
🗓️ 6 December 2018
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 6th, 2018 edition of the Sansonet Stormsendos Stormcast. |
| 0:07.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.3 | And we got familiar news from Adobe today. |
| 0:16.4 | Adobe released an update for Flash. |
| 0:19.6 | That's the second out-of-order sort of update that they are |
| 0:23.7 | releasing in a row. The last one was two weeks ago. This update fixes two vulnerabilities, |
| 0:30.4 | one of which is already exploited in the wild in targeted attacks. So nothing really to be |
| 0:37.0 | too excited or concerned about. There is no |
| 0:40.3 | widely available exploit available for this vulnerability. It's used in some limited targeted |
| 0:47.3 | attacks. So you probably have a couple weeks to either patch or finally uninstall flash. |
| 0:53.3 | But as usual, if you do run Chrome, if you do run |
| 0:57.4 | Microsoft Edge and in Explorer 11, then of course flash is included in the browser and you |
| 1:05.0 | have to update the browser in order to protect yourself. If you have one of these |
| 1:10.7 | browsers at the very least set them up so they will ask for permission |
| 1:14.7 | to run any flash content and not just run it automatically. |
| 1:20.8 | And Apple today released updates for its entire product portfolio. |
| 1:26.1 | The one missing item here was actually watchOS. |
| 1:29.4 | No update for a watch OS today, but everything else was updated, including iCloud for Windows. |
| 1:37.3 | As usual, a lot of overlap here between these different updates for different operating systems, |
| 1:43.3 | WebKit vulnerabilities, they're typically |
| 1:45.3 | exploited via the browser on these various platforms, also a number of approach escalation |
| 1:52.9 | vulnerabilities. I did see a patch for one Specter variant pop-up for macOS and os 10. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.