ISC StormCast for Tuesday, July 11th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 July 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, July 11, 2023 edition of the Sands and its Storm Center's |
| 0:07.0 | Stormcast. My name is Johannes Ulrich. And today I'm recording from Washington, D.C., here at |
| 0:14.4 | Sands Fire. Well, Apple today had a surprise for us. This is in the form of a rapid security update. |
| 0:23.8 | These are these smaller but urgent updates that Apple publishes |
| 0:27.4 | that do not require a system reboot, |
| 0:30.7 | but that patch currently exploited vulnerabilities. |
| 0:35.3 | Apple published a total of three different vulnerabilities. Two of them |
| 0:40.7 | are WebKit remote code execution vulnerabilities, so visiting a malicious web page may |
| 0:46.7 | be triggering these vulnerabilities. This, of course, again, gives you access to the Safari |
| 0:53.5 | Sandbox. The third one then is the typical privilege-esque. again gives you access to the Safari sandbox. |
| 0:55.0 | The third one then is the typical privilege escalation vulnerability that allows you to break out of the sandbox. |
| 1:03.0 | One of the two code execution vulnerabilities is only being exploited against iOS released before iOS 15.7. As a result, it's also |
| 1:16.4 | only patched for 15.7. The other remote code execution vulnerability is patched for current |
| 1:24.7 | versions of iOS, the older version of iOS, as well as MacOS Ventura. |
| 1:30.8 | Older versions of MacOS do not receive this patch. |
| 1:34.2 | Not clear if that's because they're not vulnerable. |
| 1:37.1 | The privilege escalation vulnerability, it is patched across all the operating systems, including watchOS. |
| 1:45.0 | So the remote code execution vulnerabilities, well, their web kit, they don't affect watchOS, |
| 1:51.0 | only the kernel part that's actually the bridge escalation vulnerability. |
| 1:57.0 | So given that these vulnerabilities are actively being exploited, the patch is relatively easy to install. |
| 2:03.9 | I would recommend, well, do it now if you haven't already installed these updates. |
| 2:10.8 | If you are using ubiquitous edge router or AirCube, you want to double check your firmware version on June 29th, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

