meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 29th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 January 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Emotet Update; Apple Update; Zoom; Intel Cacheout; Avast Sells Data

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 29th, 2020 edition of the Sands and the Storm Center's

0:05.8

Stormcast. My name is Johannes Ulrich, and then I'm recording from Augusta, Georgia.

0:12.2

EmoTet is still a very prolific botnet being used to install various malware, and yeah,

0:18.5

you probably have seen many samples now Brad is looking at the latest

0:23.7

version of Emudhead sample that he captured on Monday and went through how it is

0:30.7

being used to install Trickbot as usual he does provide peaps of the infection

0:37.4

activity so great way to sharpen your packet analysis skills.

0:44.3

And Apple released updates across its entire product range, including some of the Windows software that Apple publishes, in particular iTunes.

0:56.2

iTunes is no longer used on MacOS Catalina, but on Windows, it's still an active product

1:02.7

and still supported by Apple.

1:06.3

Now, I skimmed through the advisories, and of course, Apple doesn't usually do like CVSS scores or such.

1:13.3

So it's something a little bit hard to tell how important some of these vulnerabilities are.

1:18.4

A lot of purge escalation vulnerabilities that are being addressed with this update.

1:23.0

Kind of interesting remote code execution vulnerability in the Bluetooth stack I saw.

1:29.1

Haven't really seen those exploited per se, but of course that is always kind of a critical

1:35.3

issue if an attacker would be able to wirelessly connect an exploit system.

1:41.7

On iOS, Apple also fixed a bug that would allow a remote user in FaceTime

1:47.3

to change the camera you are using on your mobile device. Of course, that also could have

1:53.5

privacy implications. Apple also fixed a buck that did prevent users from turning off location

2:00.4

services all the way on recent iPhone models.

2:05.0

Now, as usual, Apple also provides a standalone Safari update for older versions of Mac OS,

2:12.9

and this fixes two vulnerabilities.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.