meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, August 16th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 August 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Realtek Vuln Followup; MacOS Priv Escalatio; Zoom; Vuln Bootloaders; HPE ILO

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, August 16th, 2020 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.1

Just a quick follow-up on the Real Tech ECOS SDK vulnerability. Luckily, no big news and no widespread exploitation in the wild. As of now,

0:25.3

I just checked before I started recording. I added a presentation to the diary to help you

0:31.1

inform management as needed. Feel free to use the PowerPoint slides as you see fit and well,

0:37.3

modify them, put them in your own

0:39.3

templates, whatever.

0:40.6

Hopefully they will help.

0:42.5

I also added a snort signature to the post.

0:47.1

The snort signature is in the works for me state of quality control and feedback is welcome.

0:54.8

And thanks to those who noted the bad link in the show notes should be fixed now and I hope

1:00.3

I will get it right today.

1:04.2

Zoom published a security update for Mac users.

1:07.8

This privilege escalation vulnerability doesn't really sound like a huge deal, but

1:12.1

shouldn't really be overlooked.

1:14.2

It does allow attackers to bypass a lot of Apple's built-in security controls, not just escalate

1:21.7

privileges to root.

1:25.2

Now you wonder why, and that gets me to a blog post by Sector 7 outlining how Apple's

1:32.4

different security layers can be bypassed.

1:35.5

This includes system integrity protection or short SIP, which is sometimes also referred

1:41.6

to as rootless because even root does not have permission to alter certain files on the system,

1:49.4

and processes are also somewhat isolated from each other and don't sort of automatically inherit all the privileges of the user running it.

1:59.2

What a particular process is allowed to do is now regulated by entitlements that are assigned

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.