ISC StormCast for Thursday, January 9th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 January 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, January 9th, 2020 edition of the Santernut Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:13.0 | And just the day after Mozilla released Firefox 72, Mozilla found it necessary to release yet another update for Firefox 72.0.1. |
| 0:26.4 | This update fixes a single critical flaw. |
| 0:30.4 | It's a type confusion in the Ein Monkey Just in Time compiler. |
| 0:35.3 | These Just in Time compilers have had a lot of issues quite complex, |
| 0:39.3 | but they're trying to accomplish here. And the reason they sort of pushed out this update so quickly |
| 0:45.3 | it was that this vulnerability is already exploited in targeted attacks in the wild. |
| 0:52.3 | So that's why you may see this minor update for Firefox updating |
| 0:58.0 | to 72.0.1. Trend Micro found three applications in the Google Play Store that took advantage of CVE 2019-2215. |
| 1:14.5 | This was a vulnerability in Binder, the inter-processed communication on Android and allowed |
| 1:21.9 | for privilege escalation. |
| 1:23.7 | It was fixed by Google in October, but these applications actually started showing up in the Google Play Store as far back as March, according to Trend Micro. |
| 1:36.1 | This vulnerability has been exploited in some targeted attacks. |
| 1:41.4 | So kind of interesting to have applications in the Play Store exploiting this |
| 1:48.0 | vulnerability a few months ahead of it, actually sort of being publicly known and patched. |
| 1:53.9 | This vulnerability has been used by the NSO group, which is also known sort of as the Sidewinder, APT in some circles. |
| 2:04.5 | So Trent Micro suggests that NSO Group was the one or one of their customers. |
| 2:09.8 | NSO Group heavily sells Malware as well, has placed these applications in the Google Play Store in order to infect targets. |
| 2:21.3 | The applications themselves are not really all that terribly remarkable. |
| 2:25.3 | They appear to be functional. |
| 2:27.4 | One is called Camero, which is sort of a camera application. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

