meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, July 17th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 July 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Zoom Patches; Boarding Pass Hack; Android File Jacking

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, July 17th, 2019 edition of the Sansomit Stormeners Stormcast. My name is

0:07.9

Johannes Ulrich. And today I'm recording from Svindon, England. We got another follow-up to the

0:15.4

Zoom vulnerability on Mac OS. Last week, Zoom and Apple released patches to address serious vulnerability in this video conferencing

0:26.2

software, mostly centered around the web server that was installed by Zoom and opened up

0:34.3

the system to vulnerabilities.

0:37.4

Apple even went as far as to label the Zoom web server as malware, which caused it to be removed

0:46.3

automatically.

0:47.3

Now, in addition to the main Zoom video conference software, there are also co-branded versions of the software

0:55.5

published by Ring Central and Sumu. These versions of the software had the same

1:01.4

problem but weren't covered by the initial set of patches and by Apple's malware

1:07.8

removal tool. Apple now added additional signatures to its tool, so these particular partner apps, as

1:16.1

Zoom calls them, should also be cleaned up.

1:19.6

Remember, just uninstalling Zoom is not going to uninstall the web server, so you have to remove that web server separately if you're

1:30.2

trying to clean up this particular mess by hand.

1:35.6

And Lenovo patched a critical vulnerability in the IOMega network storage devices.

1:42.8

If you have one of those IOM Omega branded devices, which are now sold

1:48.0

via Lenovo, please check for the update on Lenovo's website. The problem here is an API. Both

1:58.8

White Hat security and vertical structures reported as vulnerability to Lenovo

2:04.6

and essentially this API allows unrestricted, unauthenticated access to all files stored on the device.

2:14.6

So while you need to log in if you use the normal web interface, this API

2:19.5

allows direct access bypassing any authentication. If you ever sort of looked a little bit at

2:28.1

the back end of a lot of airline reservation systems, you may have come across the name

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.