meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, August 27th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 27 August 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. iOS/macOS Patch; Pulse Secure VPN Scans; Emotet

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, August 27, 2019 edition of the Sansandot Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich.

0:09.4

And I'm recording from Jacksonville, Florida.

0:14.1

Apple today released an update for iOS, MacOS Mojave, as well as for TV OS. And while this looks initially like the typical

0:24.1

Apple patches, everything sort of release, this is a little bit different. First of all, no update,

0:30.3

at least nothing from the security side for watchOS. The other sort of interesting part is

0:36.1

it's only one vulnerability that's being fixed

0:39.4

across these three operating systems. This vulnerability is notably an issue that was reintroduced

0:47.7

in 12.4, iOS 12.4. I mentioned this in this podcast in 12.3 Apple patched a vulnerability that led to a jail break in

1:01.9

iOS in 12.4. They reintroduced this vulnerability. And of course, the jail break community jumped on

1:10.0

this and released a jail break for iOS 12.4.

1:14.6

This vulnerability is now being patched again in iOS 1241.

1:19.6

Due to similarities in the different kernels, this also affects Mac OS and TVOS.

1:26.6

That's why we do have patches for these other

1:31.5

operating systems as well. But again, only one vulnerability is being patched and this is

1:38.4

CVE 2019-8605. You may think, hey, for MacOS,, jailbreaking isn't really an issue, but what this comes down

1:47.8

to is that this really approach escalation vulnerability.

1:52.3

And in order to do a jail break on iOS, you need to execute arbitrary code with system

1:58.0

privileges, and this is what this vulnerability allows across all these

2:03.4

operating systems and back in April Pulse Secure released a patch for the Pulse

2:11.2

Connect secure VPN server the patch affixed arbitrary file read vulnerability that can be used to read well arbitrary files

2:20.6

from the VPN server including keys and other secrets.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.