meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, December 13th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 13 December 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. #iOS, #tvos, #watchOS Patches; #McAfee AV Scan Vulnerabilities; Ransomware Snowball Marketing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, December 13th, 2016 edition of the Sands and a Storm Center's Stormcast.

0:07.6

My name is Johannes Ulrich, and the day I'm recording from Washington, D.C.

0:11.9

Well, ahead of Microsoft's patched Tuesday, we got updates from Apple.

0:17.8

Apple fixed 12 vulnerabilities in iOS, one in TV OS, and two in watch OS. One vulnerability is

0:26.6

actually affecting all three operating systems and it does get triggered by installing a malicious

0:33.8

profile. Now profiles that you install in iOS or these other operating systems

0:39.1

are really certificates that can then be used in order to sign settings and the like. Well,

0:45.7

if you are importing a malicious certificate, code execution may happen and this is fixed in this

0:53.9

update.

0:55.0

Now for iOS, again, we have a total of 12 vulnerabilities.

0:59.3

Some of the more interesting ones are there are a number of lock screen issues that are being

1:04.1

fixed here either bypassing the lock screen or preventing the lock screen from actually

1:09.6

taking effect.

1:11.4

There's also an issue that I found sort of interesting in that you can no longer speak passwords

1:17.8

because apparently passwords that are being spoken, yes, they can be overheard by people

1:25.3

in your proximity.

1:26.7

I wouldn't call any of these vulnerabilities extra critical,

1:30.6

so apply the patch as it becomes available, but no need to rush it at this point unless we are

1:37.6

seeing some exploits being published. Apparently a recent update to Windows 8 and Windows 10 is causing these

1:46.3

systems to have a hard time getting a DHCP lease from very selective

1:52.4

routers. Not really clear what the issue is but appears to be affecting

1:58.0

certain ISPs that use these routers.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.