meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, September 28th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 28 September 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Trend Micro ServerProtct Auth Bypass; Let's Encrypt Root Expiration; ERMAC Android Malware; QNAP Vulns;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, September 28, 2021 edition of the Santernet Storm Center's Stormcast.

0:08.3

My name is Johannes Ulrich.

0:09.7

And then I'm recording from Jacksonville, Florida.

0:13.6

And here, the Saturday initiative, Yudomeida from Cyber Defense Institute,

0:19.2

release details regarding a vulnerability in Trent

0:23.7

Micro's server protect. CVSS score is 9.8 and the vulnerability is an authentication

0:32.0

bypass vulnerability. To exploit the vulnerability and hacker would have to have access to the server

0:39.5

protect console because that's where the vulnerability is located and Trent Micro has already

0:47.7

released updates for this product. Well it's time to talk in a little bit more detail again about a problem

0:57.0

with let's encrypt certificates that I have mentioned in the past, and that's that one of the

1:03.1

root certificate authority certificates being used to validate let's encrypt certificates

1:09.6

is going to expire at the end of the month.

1:13.3

Of course, Let's Encrypt has been aware of this and has been taking measures to lessen the impact

1:20.5

by cross-signing their certificates with a second route certificate.

1:25.4

That's the ISRG Route X-1 certificate. But of course, there are old

1:31.0

operating systems that do not trust this newer certificate authority because, well, at the time

1:37.6

when the operating system was released, this authority wasn't around yet, and these operating

1:43.7

systems have not received the necessary

1:46.6

updates to their route certificates.

1:50.2

Now, we're talking very old operating systems here.

1:54.3

For example, Android devices, as for a bag as 236, according to Let's Encrypt, will continue to work.

2:02.5

Browsers like Firefox also got their own updates, and pretty much any operating system

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.