4.9 • 696 Ratings
🗓️ 25 January 2023
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, January 25th, 2023 edition of the Sands and its Stormsendors Stormcast. |
0:09.4 | My name is Johannes Ulrich and I am recording from Jacksonville, Florida. |
0:15.5 | I summarized yesterday's Apple patches. |
0:18.6 | So if you're interested in how much overlap there is between |
0:22.8 | different Apple operating systems, you may find this helpful. As usual, there's quite a bit |
0:27.9 | of overlap here because these operating systems between iPad OS, iOS, MacOS, and so on, |
0:35.0 | are sharing quite a bit of code. |
0:41.9 | Also somewhat noteworthy that TVOS did not get an update. |
0:45.6 | I suspect this will come later this week. |
0:47.5 | Well, maybe next week. |
0:51.2 | Again, there should be quite a bit of overlap here in particular when it comes to things like WebKit or some of the kernel issues. |
0:56.3 | We've got a couple products here where it starts to get difficult to figure out if a vulnerability is |
1:01.6 | actually new or if it's just sort of something new about an existing vulnerability. |
1:07.8 | First product here is Manage Engine, in particular CVE 2022-47966. This is actually |
1:16.2 | a vulnerability in the Apache Sun to Arori product or Sun to R Rio product. That product is used to |
1:25.4 | implement the SAML single sign-on in Manage Engine. |
1:29.7 | It fixed a vulnerability in October. |
1:33.4 | However, it took a while for Manage Engine actually to patch its product and sort of one of those typical dependency supply chain issues where there was a delay. |
1:44.0 | This vulnerability was patched in |
1:46.1 | Manage Engine on January 10th. On January 18th, which was late last week, and I think I covered |
1:54.4 | this, Horizon 3 AI, did then come out with a proof of concept. |
2:06.6 | This vulnerability is now officially considered exploited in the wild, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.