meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 22nd 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 May 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Spectre NG Patches; New TheMoon(Mirai?) Variants; Extracing Keys from ssh-agent in Windows

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 22nd, 2018 edition of the Zanzanet Storms and its Stormcast. My name is Johannes Ulrich,

0:08.9

and I'm recording from Reston, Virginia. Yesterday I talked about two different hardware-related flaws,

0:15.9

one of the older specter flaws and how it can be used to exploit system management mode. Also new exploits

0:24.4

over the network for Rohhammer. Well, we are not done yet with these hardware flaws.

0:31.7

Today on Monday we have a new news about new variants of the Specter flaw. These are these Specter and G flaws

0:40.3

that sort of have been rumored now for a couple of weeks. We didn't have any details about

0:46.3

them, but today Intel, Microsoft and Redhead have released advisories regarding these flaws.

1:00.1

There are two distinct flaws that have been released as part of Spectre NG.

1:06.2

One is a variant of the Spector variant 3, which we already have seen,

1:10.3

and then there's also a new variant Spectre variant 4. Intel now has released some bios updates and microcode

1:14.6

updates to OEMs in beta forms, so they're probably not yet out by the time you listen to this.

1:22.3

However, Microsoft and Redhead also released patches of their own to protect yourself from these vulnerabilities.

1:30.4

One of the more dangerous exploits, of course, against Specter was always the use of

1:36.3

JavaScript and the browser in order to take advantage of these vulnerabilities. According to

1:41.5

Intel, the browser protection mechanisms that have been put in place for Spector

1:46.7

1 should also be effective for these newer versions of Spector.

1:52.9

So now, what should you do as an end user?

1:54.8

Well, what do you usually do?

1:56.3

Apply patches.

1:57.3

I wouldn't really rate these patches as super critical, so give them some time to actually

2:02.3

make sure that they're not causing any issues.

2:05.2

Remember, we had issues with some of these specter patches in the past, so don't rush it,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.