meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 23rd, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 23 January 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Updates; Atlassian Confluence Exploited; Ivanti Mitigation Problems; Czech IPv4 Shutdown Date

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, January 23rd, 2024 edition of the Sands and its Storm Center's Stormcast.

0:08.9

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.7

A couple of interesting updates today.

0:16.6

First of all, we got updates from Apple.

0:20.2

Apple released updates for all of its operating systems,

0:23.4

including some older versions of operating systems, for example, for MacOS going back to

0:30.6

Monoray or 12.7, and for iOS and iPadOS going back to 15.8. The reason we see these updates for older operating

0:43.3

systems are in one part some of these older already exploited vulnerabilities, and that's in

0:50.9

particular CVE 2020-192916 and 42917.

0:57.5

These WebKit vulnerabilities have been patched for more modern versions of iOS and

1:02.8

macOS last year.

1:04.7

Now Apple is sort of catching up with some of the older operating systems.

1:09.9

But also for up-to-date operating systems, we do have an already exploited vulnerability.

1:16.2

That's being patched here, again, a web kit vulnerability, meaning that it could be exploited

1:21.9

as you visit malicious website.

1:25.0

Now, some of these older web kit vulnerabilities, we also so exploited, for example, in

1:31.7

these tickets and boarding passes and such that are displayed by Apple's wallet, because

1:39.0

that's also rendered using WebKit.

1:43.0

Overall, we have updates for 29 different vulnerabilities.

1:46.0

At least that's my count.

1:48.0

Always easy to sort of miss one or count one double here.

1:53.0

Update, there is nothing really need to select about these updates other than to apply them.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.