ISC StormCast for Wednesday, January 24th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 24 January 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, January 24th, 2018 edition of the Santern Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. Apple today had one of its usual surprise patch days that affect all of its operating systems. We got patches for watchOS, iOS, |
| 0:23.6 | macOS or OS10, and TVOS. For some older versions of OS10, there's also a separate Safari |
| 0:32.6 | update. Out of the total of 19 vulnerabilities being addressed here, and I think that's actually a little |
| 0:38.1 | bit on the smaller side as far as Apple patches go. |
| 0:42.7 | Ten of the vulnerabilities do apply to all of the different products. |
| 0:48.3 | Now of note here is probably that there is another patch for the meltdown vulnerability. |
| 0:55.0 | Originally, Apple released an update for High Sierra on January 8th. |
| 1:01.8 | Now, this update did not cover the older version of the operating systems that are still |
| 1:06.8 | being supported like Sierra and El Capitan. |
| 1:09.8 | Well, with today's update, you will also get the meltdown patch for these older operating |
| 1:16.6 | systems. |
| 1:17.6 | Another interesting vulnerabilities being addressed here is what Apple calls the link presentation |
| 1:22.6 | vulnerability. |
| 1:23.6 | This vulnerability has already been exploited. |
| 1:26.6 | I mentioned it here before. In order to exploit |
| 1:29.6 | a vulnerability, an attacker would send you a link via iMessage that then leads to a web page |
| 1:36.3 | that includes a malicious open craft hack. Now, you don't actually have to click on the link, |
| 1:41.6 | just the preview within iMessage will cause |
| 1:45.5 | the system to lock up. However, the vulnerable is it. I'm sort of most worried about are three |
| 1:51.5 | vulnerabilities in WebKit. WebKit, of course, is the rendering engine behind Safari and |
| 1:57.9 | could easily be exploited by a malicious web page. These particular vulnerabilities do allow |
| 2:04.1 | arbitrary code execution. So this is a classic vulnerability that would be exploited by |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

