meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, July 1st 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 1 July 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Special Windows Patch (Code Exec Vuln); MacOS Ransomware; VPN Priv Escalation; DNSSEC Phish

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, July 1st, 2020 edition of the Sansanet Storm Center's

0:06.2

Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:13.3

Microsoft today released two updates for Windows Codecone vulnerabilities that do affect Windows 10 as well as Windows Server 2019.

0:27.6

Now of course no big surprise that Windows 10 and Server 2019 are both affected.

0:33.6

They're similar enough and share a lot of libraries. These codec libraries affected by these two vulnerabilities are processing images.

0:43.9

So in order to exploit the vulnerability, a victim would have to look at a malicious

0:49.3

image that is then able to execute arbitrary code.

0:53.7

It's a little bit odd that Microsoft came up with this patch sort of out of order.

1:02.3

There is no current exploit known for it, and this vulnerability was found by Abdu Lassiz Harari,

1:12.8

who was actually part of the Trent Micro-Cyrid initiative

1:14.8

so it was reported to Microsoft

1:17.3

via the Serrida initiative.

1:20.2

Microsoft does state that this update

1:22.7

should be applied automatically via

1:24.5

the Microsoft Store.

1:26.6

You could theoretically trigger it manually if you don't want to wait

1:31.1

for the automatic patch to kick off. But well, a lot of malware these days, of course,

1:38.8

doesn't really rely on any vulnerabilities like this in order to execute code. It just tricks the user into doing so.

1:48.1

And that, of course, is operating system independent. And yes, I do have some new Mac malware

1:55.6

to talk about. Malverbytes wrote this up. And the reason you may be infected with this latest Mac Malver

2:03.5

is if you installed Little Snitch, very popular and very good firewall software for MacOS from Torrent.

2:15.0

So the trick here is that the attacker is trying to trick you into

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.