meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 6th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 June 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Android Updates; Chrome Updates; Bing Injecting Mac Malware @AiroSecurity @Akamai

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 6, 2019 edition of the Sansanet Storm Centers, Stormcast.

0:07.1

My name is Johannes Ulrich.

0:08.8

And I'm recording from Jacksonville, Florida.

0:13.4

Google came out with its monthly update for Android.

0:17.0

We got a total of 22 vulnerabilities being fixed here, eight of which are critical.

0:24.0

Now out of these eight critical vulnerabilities, three are again in the media framework.

0:30.0

What's sort of interesting about these three vulnerabilities, that two of them only exist

0:34.1

in Android 9, while the third one only exists in older versions of Android.

0:41.6

Now, the fourth vulnerability in the framework, which is only rated as high, it's a per-age

0:46.7

elevation vulnerability. This one goes all the way back to Android 7 and also appears

0:53.9

to affect the newer versions.

0:56.5

Chrome also received an update with a number of security fixes, nothing really too spectacular

1:03.0

here and Chrome should update itself anyway.

1:08.0

But we also got some little bit new and different Mac malware to talk about.

1:14.0

This particular sample was dissected by Arrow Security.

1:18.8

Now the initial install vector is the old and tried fake Flash player install.

1:25.5

Have seen this for years now with Macs and must be probably

1:29.7

the number one way how Malva ends up on the Mac. Now, once it runs, it actually runs a little

1:36.3

bash script that will install an HTTP and HTTP proxy on the system. It will add a trusted certificate authority to the system to properly

1:47.5

provide signed certificates. And then the end goal and moneymaker appears to be the injection

1:53.9

of ads into the browser sessions. Interestingly, they're actually using Bing ads here, which is a little bit ironic all over

2:04.6

here for Mac malware, but I guess that's where they're actually able to make a little bit

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.