ISC StormCast for Thursday, October 26th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 October 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, October 26, 2023 edition of the Sandsenet Storm Center's Stormcast. |
| 0:09.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.9 | Well, and a day late, at least according to mine and others' expectation, we today got updates from Apple for pretty much anything. |
| 0:25.6 | iOS, iPadOS, MacOS, TVOS, and watchOS. |
| 0:30.6 | For the big operating systems here, MacOS, iOS, iPadOS, |
| 0:33.9 | we actually got updates three versions back. |
| 0:37.7 | Across the different operating systems, I believe we got 53 vulnerabilities patched. |
| 0:44.5 | Probably the one that's sort of the most interesting is CVE 2020-23-3-4-34-4. |
| 0:51.9 | This is the already exploited vulnerability. We have received patches for the more recent operating systems. Well, today we now got a patch for iOS 15. That brings us up to iOS 15.8. And Apple states and stated that before, that it has seen exploitation of this |
| 1:13.5 | vulnerability for iOS prior to 15.7. And this is also the only iOS 15 patch that was in |
| 1:24.7 | today's update. The remainder of the vulnerabilities are sort of your usual mix, |
| 1:30.7 | bunch of WebKit vulnerabilities that are always interesting |
| 1:33.9 | that allow for code execution if you're visiting a malicious web page, |
| 1:39.3 | some approach escalation vulnerabilities to go with this, |
| 1:42.4 | and then also sort of a crop of privacy issues, |
| 1:46.6 | for example, where your Mac address may be sent when it's not supposed to be sent, |
| 1:52.7 | or where, for example, hidden photo albums and such may be viewed without off the occasion. |
| 1:59.6 | Certainly an update that you don't want to miss, I would suggest that at least sort of |
| 2:05.7 | by the coming weekend you probably should apply these updates across your different Apple devices. |
| 2:14.1 | And beginning of October at Lashin did release an update for CVE 2020-2515, patching a vulnerability |
| 2:24.8 | in their Confluence server and data center product. The problem here was an off-occation |
| 2:32.4 | bypass that pretty much allows anybody with a simple request to add new admin users to your system. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

