4.9 • 696 Ratings
🗓️ 28 October 2021
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, October 28, 2021 edition of the Sansonet Storms and Stormcast. |
0:08.5 | My name is Johannes Ulrich, and today I'm recording from Al-Kobar, Saudi Arabia. |
0:14.3 | Beijing went hunting for fishing pages and came across an interesting one that likely was meant to impersonate an outlook web access |
0:24.1 | site from engineering underwriting firm Mirabalus Africa. Now, the interesting part here is also |
0:32.6 | the host name used to host a fishing site, auth.internal. |
0:38.3 | . |
0:39.3 | We know what site is likely supposed to impersonate based on comments in the code. |
0:46.3 | Also, apparently the author of the fishing site had a foresight to actually run the site through a spell checker |
0:53.3 | because there is a comment |
0:55.1 | left over from Grammaly. Outlook Web Access as well as Outlook 365 is one of the favorite |
1:03.1 | targets for fishing and one of the follow-ups is often than business email compromise. |
1:11.1 | And we now got details from Apple regarding the vulnerabilities fixed in this week's |
1:17.5 | update of note here is CVE 2021 30883. This is yet another I.O. Mobile frame buffer |
1:27.3 | vulnerability that has already been exploited |
1:31.3 | in the wild and may lead to arbitrary code execution with kernel privileges. In addition, |
1:39.3 | there are a number of other mostly approach escalation vulnerabilities that are being addressed in iOS and |
1:46.3 | macOS. And then remember, you don't have to go all the way to the latest and greatest MacOS |
1:53.1 | Monterey. There are specific security updates for older versions of MacOS. So it can still get the security benefits of these updates |
2:03.0 | without having to run into functionality issues. |
2:08.3 | And one thing, of course, people attending Sands class |
2:11.3 | and such are always worried about is VMBer Fusion on Macs. |
2:16.1 | As long as you have an Intel Mac, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.