meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 25th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 25 May 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Patches 0-Days; Bluetooth Vulnerabilities; NAGIOS Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 25th, 2021 edition of the Sansanet Stormers Stormcast.

0:08.0

My name is Johannes Ulrich, recording again from Jacksonville, Florida, but teaching virtually

0:14.5

in London, England this week.

0:18.4

Well, big news today from Apple. Apple again, released updates for pretty much anything.

0:23.8

And well, of course, the big focus here is new functionality.

0:27.9

With these updates come also important security patches.

0:32.0

So on the desktop, I guess you would call it, operating system side,

0:37.5

the got updates for macOS bix Pixar, Mojave, as well as Catalina.

0:43.5

So two versions back here.

0:46.1

Then we got updates for iPadOS, iOS, TVOS, and watchOS.

0:51.2

Of note is that there are three vulnerabilities being addressed here. Actually, even in TVOS. Of note is that there are three vulnerabilities being addressed here, actually even in

0:57.5

TVOS, that are currently already being exploited. And probably the most interesting one of

1:05.6

these vulnerabilities is CVE 2021-3713.

1:11.6

This impacts macOS Bixer,

1:14.6

and it is a bypass of the transparency, consent,

1:18.6

and controller TCC framework,

1:21.6

which is used to give permissions to software

1:25.6

to do sensitive things, like like for example, taking screenshots.

1:31.0

And with the release of the patch today, there's also a blog post by YAMF, the maker of enterprise

1:36.6

management software for Apple devices.

1:39.9

They have details about how a recent version of the XCS set malware took advantage of this vulnerability.

1:48.0

Now, XCS set has been around at least since August last year.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.