meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 15th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 February 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. #NoPatchTuesday; #Adobe & #Websphere Patch; Operation Kingphish

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 15th, 2017 edition of the Sandinand Storm Center's Stormcast.

0:07.5

My name is Johannes Ulrich, and I'm recording from San Francisco, California.

0:12.5

Microsoft had an interesting surprise for us today.

0:15.3

It was supposed to be patched Tuesday, but essentially with an hour or two to go until we expected Microsoft to release

0:24.7

this month's patches they cancelled patch Tuesday.

0:29.6

Now they stated that they discovered some issue with this month's patches and that's

0:35.2

why they are delaying them.

0:44.5

There is no new date at which we should expect these updates could be as late as March. In the past, Microsoft occasionally has not released individual patches that turned out to cause

0:51.4

some odd side effects in the last minute, but they never really

0:56.2

cancel an entire patch Tuesday. This could be a little bit of the way they're planning to do

1:03.2

things going forward, where they are releasing these large monolithic monthly patches.

1:08.6

And of course, if one of the issues they're fixing within one of these large patches does cause problems,

1:16.7

they may not be able to remove that patch quickly enough.

1:21.1

And as a result, have then liked today to cancel the entire patch Tuesday.

1:26.7

Adobe, on the other hand, did release an update for

1:30.4

Flash. Of course, the interesting part now is that you don't necessarily have the accompanying

1:37.5

update for Edge and In Explorer 11 from Microsoft. And to make up for the missing Microsoft patch Tuesday, we do have an update from IBM for

1:49.5

WebSphere.

1:50.5

It does fix a cross-site scripting vulnerability that can be used to leak credentials from

1:58.0

trusted sessions.

1:59.9

And you should not delay patching this one while it's

2:03.1

only a cross-site scripting vulnerability. Remember, cross-site scripting vulnerabilities are often

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.