meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, July 24th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 24 July 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TLS Configuration; #Apple Updates; #QNAP/#Synology Advice; New #Bluekeep Writeup @0xeb-bp

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, July 24, 2019 edition of the Sansonet Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich.

0:09.3

And I'm recording from Jacksonville, Florida.

0:12.9

Today in Diaries, we got a post from Boyan regarding how to test your TLS configuration.

0:19.7

Of course, that always has been sort of some of these

0:24.6

canaries. I think if your TLS configuration isn't sort of close to up to date, then probably

0:32.4

you're doing a bunch of other things wrong. Now, Boyan also has a nice webcast coming. In this webcast,

0:39.7

he'll actually demonstrate some of these poodle vulnerabilities, for example, and that's, I think,

0:45.8

something that's often missing here, where we're talking about these vulnerabilities. We're

0:50.4

claiming that they're severe, but hardly anybody sort of ever has gone through an actual

0:56.3

exploit of one of these vulnerabilities.

1:00.2

And over the last two days, Apple again pretty much updated everything starting on Monday

1:06.1

with their operating systems, MacOS, Apple TV OS, WatchOS, and iOS, and on Tuesday with updates

1:15.8

for some Windows software like ICloud for Windows and iTunes. Probably the highest profile vulnerability

1:23.6

being addressed here was an issue in the walkie-talkie feature in the Apple Watch,

1:30.0

and that's actually something that Apple even disabled prior to this update being released.

1:37.6

Now, in this update in the security notes, there is a brief description of this

1:42.7

that says a logic issue existed in the answering of phone calls.

1:48.0

The issue was addressed with improved state management.

1:52.0

So apparently if someone called you and also did initiate a walkie-talkie connection at the same time,

2:00.0

they may be able to eavesdrop on you without you realizing that this walkie-talkie connection

2:06.7

was established.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.