meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, September 14th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 14 September 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple Updates; Gooble Chrome Patches; WooCommerce Currency Conv. Flaw;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, September 14th, 2021 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.7

And today I'm recording from Jacksonville, Florida, but virtually teaching this week in Reston, Virginia.

0:17.9

Apple today released updates for Safari, for macOS Catalina,

0:22.9

MacOS Bixer, Apple Watch, iOS, iPad OS,

0:27.8

and these updates are fixing two critical vulnerabilities

0:32.0

that have already been exploited in the wild.

0:37.0

Now, Safari, for example, only is affected by one of these vulnerabilities, the WebKit

0:41.3

vulnerability.

0:42.3

The other products are affected by both vulnerabilities.

0:46.3

First vulnerability in core graphics may lead to arbitrary code execution if a crafted

0:53.3

PDF is processed.

0:55.3

The second, the WebKit vulnerability is triggered by visiting a malicious web page.

1:03.6

Now, the WebKit vulnerability CVE 2021 30858 is attributed to an anonymous researcher.

1:11.4

The Core Graphics Vulnerability CVE 2021-806-0 is attributed to the Citizen Lab.

1:20.1

The Citizen Lab, of course, has been sort of breaking these stories about the NSO Group and its Pegasus tool. This vulnerability is apparently

1:31.3

related and the Citizen Lab has published a blog post with additional details about the malicious

1:38.8

PDFs that they have seen attack a phone owned by a Saudi activist.

1:46.0

Use of this vulnerability has first been spotted by Citizen Lab in March.

1:51.0

Now, Citizen Lab has collaborated with Apple in fixing this vulnerability,

1:57.0

and now of course with Apple releasing the update.

2:00.0

We do get more details from

2:02.9

Citizen Lab about this particular event. So how critical is it that you are updating your devices?

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.