meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 29th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 29 October 2024

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Updates; HTML File Phishing via Telegram; ChatGTP-4o Encoding Evasion

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, October 29th, 2024 edition of the Sands and its Storms on a stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. Apple today released its usual updates for pretty much everything. Their updates for MacOS, iOS, VisionOS, WatchOS,

0:23.6

as well as TVOS. Some of these updates are available for older versions of the operating

0:30.4

systems with MacOS. It goes back, two versions back to MacOS Ventura 13 and 14 are being covered in addition to the current

0:39.6

version 15 iOS is going back one version to iOS 17 this update of course is also a big

0:48.4

feature update for iOS 18 and macOS 15 it adds the new AI feature set that was sort of highlighted for these

0:58.5

recent versions of the operating system. There is no security patch only release for iOS 18 and

1:08.0

macOS 15. However, the updates for the older operating system versions, they are

1:14.5

just security updates and they will not get you any of the newer features. I counted a total of

1:20.9

67 vulnerabilities being patched here across the different operating systems. None of them

1:26.2

is currently being exploited.

1:28.4

I didn't really see any sort of patch now style vulnerability.

1:32.9

A lot of the vulnerabilities are actually a lock screen vulnerabilities.

1:36.5

I think there was about half a dozen or so of them, which I thought was a little bit

1:40.8

interesting.

1:42.1

And what this often comes down to is that if you're enabling certain features to be available

1:46.9

on the lock screen, they are not properly access control.

1:52.0

It's usually best practice to limit what you are exposing on the lock screen.

1:57.0

And then, of course, keeping your devices under your physical control is always preferred.

2:03.4

Also a number of vulnerabilities that essentially come down to one application being able to

2:10.0

see another application's data. iOS in particular is supposed to sandbox all of these

2:16.2

applications. That has often failed in the past and still fails occasionally.

2:21.3

Here, my recommendation is, well, be careful what applications you're installing.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.