ISC StormCast for Tuesday, May 14th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 May 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, May 14, 2020, |
| 0:05.0 | edition of the Santernet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, |
| 0:10.0 | and I'm recording from San Diego, California. |
| 0:14.0 | Apple today released its usual updates for everything, |
| 0:19.0 | including iOS, iPad OS, Mac OS, watchOS, and TVOS. |
| 0:24.7 | In particular, for MacOS and iOS, it goes back a couple versions. |
| 0:30.9 | 29 vulnerabilities are being addressed across the different operating systems. |
| 0:36.5 | One that's sort of interesting is one that has already been exploited. |
| 0:41.9 | CVE 2024-23296, this is a vulnerability in RT kit. |
| 0:48.1 | Now, back in March, Apple did release updates for this vulnerability |
| 0:53.1 | for more recent versions of iOS and Mac OS. |
| 0:57.0 | This particular update now does patch this vulnerability for older versions like iOS 16 and MacOS 12 Monoray. |
| 1:08.0 | If there's anything odd and interesting, then maybe the fact that there is only a single |
| 1:13.1 | web kit vulnerability being addressed in this update. Other than that, lots of privilege |
| 1:20.0 | escalation flaws. There is a slight lock screen bypass. That's, of course, always sort of interesting. Nothing I would think that suggests |
| 1:31.0 | specifically expediting this update other than the update for the older versions of iOS and |
| 1:38.7 | macOS. And then we got an interesting update from Juniper for JunoS and JunoS Evolved. |
| 1:48.6 | This update addresses multiple vulnerabilities in OpenSH. |
| 1:54.3 | Now this is a little bit a tricky update to read here, but if I do read it correctly, the problem here is JunoS uses a heavily |
| 2:04.1 | customized version of OpenSH version 2.5 patch level 1. That particular version in its default |
| 2:14.0 | open source version had a number of vulnerabilities. And of course, if you're running a |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

