ISC StormCast for Wednesday, July 26th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 July 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, July 26, 2020, 3 edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.9 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.9 | Today, let's jump right into currently exploited vulnerabilities. |
| 0:20.1 | Imani published an advisory |
| 0:23.0 | regarding its Imani |
| 0:24.5 | endpoint endpoint manager mobile, |
| 0:26.4 | formerly known as Mobile Iron Core, |
| 0:29.4 | fixing a vulnerability CVE |
| 0:31.4 | 202023-35078 |
| 0:34.4 | with a perfect CVSS score |
| 0:37.0 | of 10.0. Apparently there's an authentication bypass vulnerability |
| 0:43.4 | that allows unauthorized users to access the device without proper authentication. The problem |
| 0:52.6 | here is that this is already being exploited. Norway released, |
| 0:57.5 | press release, saying that they had 12 of the ministries in their country compromised by |
| 1:04.9 | this vulnerability. All currently supported versions of the product are affected as well as some unsupported, |
| 1:12.9 | so end-of-life releases as well. |
| 1:15.7 | So must patch here and looks like according to Shodan that there are more than 2,900 mobile iron |
| 1:22.7 | user portals exposed online. |
| 1:26.6 | And talking about software needing patches, we also got patches from Latian for Confluence. |
| 1:34.0 | Three remote code execution vulnerabilities are being addressed here with a CVSS score |
| 1:39.3 | between 7.5 and 8.5. |
| 1:43.0 | This affects Confluence Data Center and Server, two of the vulnerabilities, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

