meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 7th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 7 November 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Google PlayStore Security; Xen and npcap Patches; TrendMicro Insider Issue; SANS Ouch Newsletter

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 7th, 2019 edition of the Sansonet Storms, Stormcast. My name's

0:07.8

Johannes Ulrich, and I'm recording from Jacksonville, Florida. It seems like there isn't a week

0:16.1

where I don't cover some kind of story about how malicious software made it into the Google Play Store,

0:23.9

despite Google's best efforts to try to prevent this from happening.

0:28.2

These malicious apps are often discovered by endpoint security product providers, of course,

0:35.5

somewhat also advertising their goods.

0:39.3

Well, Google now actually recruited three of them, ESET, Lookout and Symparium to assist them

0:46.9

in helping them secure the Play Store.

0:51.0

The idea is that Google will take technology from these companies and integrated into

0:56.3

their Google Play Protect Detection System. That's the script they're running to filter out

1:03.3

malicious applications before they're being published. One of the big differentiators between Google's

1:10.3

Play Store and Apple's App Store is that Google

1:13.6

relies pretty much on sort of automated technology, not on an actual human reviewing the application.

1:22.6

So hopefully by adding these new companies to the mix, they will have a better chance of

1:30.0

reading out some of the bad actors.

1:35.0

And the SEN project released six advisories addressing vulnerabilities in its virtualization

1:42.6

platform. Nothing too super critical here. There are a couple

1:48.0

of privilege escalation vulnerabilities that could allow code that was running in a guest to actually

1:55.0

affect the host, a couple of denial of service vulnerabilities as well. So certainly something you should address if you are running Citrix for virtualization,

2:06.5

well it's Zen based, so you should refer to the corresponding Citrix patches.

2:14.5

And remember how WireShark recently dropped the old and outdated WinP-Cab library that's no longer

2:21.0

really maintained and replaced it with NPCAP?

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.