meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 19th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 December 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ASUS/Gigabyte Vulns; Apple Phishing; Kibana Exploit; SANS Holiday Hack Challenge #kringlecon

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 19th, 2018 edition of the Sands and at Storm Center's Stormcast.

0:09.1

My name is Johannes Ulrich, and today I'm recording from Washington, D.C.

0:14.6

Today, let's start with an sort of interesting vulnerability in AIS drivers.

0:20.1

This affects some of the higher-end AIS

0:24.3

motherboards that are targeting particular gamers and tech enthusiasts that come with the AIS

0:31.7

Sync applications. You typically use AIS Sync in order to, for example, control LED strips and the like that are often added to these sort of higher-end gaming PCs.

0:43.9

In exploiting, this vulnerability attacker is able to elevate privileges, and there is currently no patch available from ASAS.

0:54.6

So your only real option is to just uninstall this software.

1:00.0

Now, ASIS isn't the only company that is having issues.

1:03.4

The company that discovered the vulnerability secure off found similar problems with equipment

1:10.1

made by a gigabyte.

1:12.0

It affects gigabyte motherboards and graphics cards again can lead to privilege escalation and no patch is available.

1:23.1

Now apparently in both cases, Secureoth wasn't really able to communicate with the vendor in order

1:29.8

to disclose the vulnerability, which is why they now went public. However, they also went public

1:35.5

with proof of concept, exploit code, which of course makes exploitation of these vulnerabilities

1:41.8

quite a bit more likely.

1:51.8

Now during the holidays, there's always sort of a chance that the bad guys try to take advantage of the increase in online shopping and such by launching various campaigns

1:58.1

that target online merchants.

2:01.3

One example that bleeping computers reporting about is Apple's App Store.

2:06.8

Now, that's always a favorite fishing target, of course.

2:10.6

This latest wave arrives as an email with a PDF as an attachment,

2:14.7

where the PDF is actually in itself not really malicious, not using

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.