meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 14th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 14 February 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Patches Everything; Venmo Phish via LinkedIn; Malicious Python;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, February 14th, 2020,

0:05.0

edition of the Sandin and Stormsterners Stormcast.

0:09.6

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:16.3

Well, Apple today updated pretty much everything in Apple's portfolio. We got updates for

0:23.0

Safari, iOS, iPad OS, Mac OS, TVOS, and watchOS. The trigger for this particular set of

0:32.7

updates appears to be a critical vulnerability in a web kit that is already being exploited,

0:39.5

and that may lead to remote code execution if a user visits a malicious web page.

0:47.2

This particular vulnerability, CVE 202023-29, effects at least Safari, iPad, iPad iOS as well as Mac OS.

0:58.5

Interestingly, there has been no security content published yet for TVOS and watchOS.

1:06.0

Not sure why that was delayed.

1:08.4

Usually it's only delayed if there are still some other operating systems

1:13.0

that haven't been patched yet, but with everything being patched, not really clear what

1:17.4

was special here about TVOS and watchOS. In addition to this already exploited vulnerability,

1:24.7

we also have a vulnerability that affects iPad OS, iOS, and Mac OS, CVE 20203-23-514. Now, this is more sort of a

1:37.3

privilege escalation sandbox escape vulnerability and could potentially be chained here with the first vulnerability in order

1:45.7

to get then full kernel level access to the device.

1:50.6

And then the third vulnerability, less severe.

1:54.0

It's a Mac OS issue and it only affects shortcuts and may lead to an app being able to observe some protected user data.

2:06.8

That's CVE 2020, 23, 522.

2:11.8

So recommendation here is update, update relatively quickly because this is already being exploited. However,

2:18.9

no details have been made available as far as I'm aware regarding this one already being

2:25.6

exploited vulnerability. But who needs fancy surrethes in Safari if you can just use simple fishing tricks using some old weaknesses

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.