meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 4th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 4 November 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Patch Gitlab; More Exchange Action; Blackmatter Shutting Down Again; Android 0-Day Patched

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 4, 2021 edition of the Sansonet Storm Center's

0:06.8

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.7

If you're using GitLab, then please be aware that you should patch GitLab occasionally.

0:21.6

Rapid 7 took a look at a critical vulnerability in GitLab that was made public back in April.

0:30.6

This was a remote code execution vulnerability and apparently it is actively being exploited. Rapid 7 during its scanning found

0:41.2

that there apparently tens of thousands of unpatched GitLab installations still out there

0:49.3

that have not been updated and are open to attack.

0:54.2

Now, if you're using GitLab, GitLab is publishing security updates at the end of each month.

1:01.5

The last one was published last week, October 28th, so that's when you should take a look and probably update your install.

1:11.6

And according to Rapid Seven's scans,

1:15.6

21% of GitLab installs are fully patched for the issue that was released back in April,

1:23.6

and 50% of installs are not patched. Now there's another 30% where they weren't really sure

1:31.9

if it was vulnerable or not. But with 50% being definitely not patched, this is more than we

1:39.9

typically see for vulnerabilities that old and maybe related with GitLab, not necessarily

1:46.7

sort of being the software that makes the news a lot. So that's why I really want to emphasize

1:51.0

to patch it, double check that you're running it. Maybe you're not even aware that some developers

1:57.7

are so set it up in your environment. And if you need a little bit extra motivation to patch GitLab,

2:03.8

the patch released last week does also address the unicode issue

2:09.3

that made the news picktime.

2:11.3

So maybe that issue about the bidirectional characters making the news

2:17.0

may give you a little bit resource and such

2:19.6

to actually push out a patch.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.