meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 2nd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 2 June 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Patches Unc0ver; Office 365 Details; Security Researchers

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 2nd, 2020 edition of the Sandtonet Storm Center's Stormcast.

0:07.3

My name is Johannes Ulrich.

0:08.9

And I'm recording from Jacksonville, Florida.

0:13.8

It's less than a week ago that Apple did release updates for macOS and about two weeks since we got the last ios update still

0:22.9

apple today released a security update for all of its operating systems now this update fixes

0:30.2

one single vulnerability cve 2020 9859 and And this is a privilege escalation vulnerability that did allow for the recently released

0:44.5

uncover jailbreak exploit.

0:48.0

So jailbreaking on iOS devices does require that you as a user are able to execute code with kernel privileges,

0:57.9

and that's exactly what is being fixed here.

1:02.2

The big impact here, of course, is for iOS and iPadOS, because there you have all these

1:09.0

restrictions trying to limit what a user could possibly execute.

1:14.4

For macOS, this is still a dangerous privilege escalation flaw that should be addressed, of course.

1:20.9

MacOS, at least in its normal configuration, is a little bit more open.

1:26.3

Now, of course, once you upgrade to iOS 13.5.1, which is this

1:32.0

latest version that was just released today, the uncover jailbreak exploit will no longer work,

1:39.1

so you will no longer be able to jail break your phone. For most users, jailbreaking tends to be a bad idea

1:47.7

because you are essentially disabling a good part of the secure infrastructure in iOS.

1:55.4

If you are a researcher or such that would like to look at some of the internals of iOS, then of course

2:02.8

jailbreaking, maybe something that you would like to do to your devices, and in this case,

2:08.9

don't upgrade to 13.5.1. And aside from fixing this single vulnerability, Apple apparently didn't make any changes to any of the

2:21.3

operating systems. Now, anti-maliver sometimes can sort of be this black box and you really don't

2:28.5

know why it considers a particular email attachment, for example, as malicious.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.