meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 15th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 June 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple iOS 12.5.4; NIST.gov DNS issues; Akkadian Bugs; Exchange Online MFA Bypass

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 15th,

0:02.8

2021 edition of the Sandler, Storm Center's Stormcast.

0:07.6

My name is Johannes Ulrich,

0:09.1

and then I'm recording from Jacksonville, Florida,

0:12.0

and again virtually teaching this week in Paris, France.

0:18.2

Apple today released iOS 12.5.4. The most recent version of iOS, of course, is iOS 14.6. However, some older devices going back to the iPhone 5 and iPhone 6 are not supporting newer iOS versions, and that's why Apple is still releasing security updates

0:41.1

for iOS 12. This particular update fixes three war-warrant abilities. One is a vulnerability

0:49.9

in how certificates are parsed, and it may lead to arbitrary code execution.

0:56.0

And then we have two WebKit vulnerabilities that also may lead to memory corruption or code execution.

1:04.0

And apparently these vulnerabilities are already actively being exploited.

1:15.6

So if you're still running one of these older devices, make sure you update.

1:25.0

And apparently nist.gov at the National Institute for Standard and Technologies domain suffered an outage earlier today. I was able to see this myself early this morning,

1:32.5

and there were a couple of reports on Twitter as well as on the outage's mailing list.

1:39.1

One of the effects was that the website, of course, that serves many security standards and

1:43.8

such, was not reachable. Also

1:46.7

affected was apparently the NIST time service because some of the host names of these NIST

1:54.4

time servers were not resolvable and some organizations are using them as their time standards. For less critical

2:04.5

NTP services, of course, you may want to just sync with pool.nTP.org or go or run your own

2:14.2

little NTP server that is synchronized, for example, via GPS.

2:19.5

It's not quite clear what the root cause of the outage was,

2:22.6

but apparently it was DNS-related, of course,

2:26.0

and it may have been caused by a denial-of-service attack,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.