meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 13th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 October 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Adobe Patches; Fortinet Details and New Patches; iOS and Android VPN Issues; Aruba Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, October 13th, 22 edition of the Sands and Storm Center's Stormcast.

0:09.7

My name is Johannes Orich, and I'm recording from Riyadh, Saudi Arabia.

0:15.9

After recording yesterday's podcast, Adobe, of course, did release some patched Tuesday updates. After

0:22.3

all, the updates are addressing vulnerabilities in Acrobat Reader, Colfusion, Commerce, and Dimension.

0:30.7

For Coldfusion, four of the vulnerabilities that they are patching here, have a CVSS score of 9.8.

0:39.3

Now, Adobe Commerce and Magento, there is a cross-site scripting vulnerability with a perfect CVSS score of 10.0.

0:50.3

Apply the patches soon, but Adobe does not consider an exploit for any of the patches likely soon.

1:00.6

Horizon 3 published some details assisting 48 customers with the detection of CVE 22-4684 exploit attempts.

1:10.7

Now, this is the vulnerability that was patched on Friday after

1:14.2

Fortigate detected the vulnerability being exploited in the wild. Make sure that you are updating.

1:23.2

Horizon 3 has not yet included details how to exploit this vulnerability, but they did promise

1:30.8

proof-of-concept exploit for later this week in a separate blog post, so it's certainly coming.

1:38.4

There are additional vulnerabilities that Fortigate patched today, they include some authenticated

1:47.2

code execution flaws in the patch for a weakness in the authentication of brute force detection.

1:54.3

Nothing quite as critical as the one released on Friday, but keep your 48 devices updated.

2:03.6

And VPN service Mulvad VPN published blog post outlining how some traffic does escape

2:11.6

a VPN connection on Android, even if the block connections without VPN feature is selected.

2:18.9

The issue here appears to be a little bit more of a documentation issue

2:22.4

where maybe that setting should be clarified a bit,

2:26.0

but the traffic that's not using the VPN, for example, is connectivity checks.

2:32.0

This tends to be a little bit tricky with devices in particular, like

2:36.8

myself, for example, I know at a hotel. There is often sort of a portal that I have to log in

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.