ISC StormCast for Wednesday, June 9th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 June 2021
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 9th, 2021 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich. |
| 0:09.3 | And I'm recording from Jacksonville, Florida. |
| 0:13.4 | Well, of course, today, Microsoft's patched Tuesday, we got patches for 50 vulnerabilities, five of which are critical. Two had a privacy been disclosed, |
| 0:24.8 | and six of these vulnerabilities were already being exploited. Kasperski actually has a blog post |
| 0:32.6 | about an attack that led them to two of these already being exploited vulnerabilities. They call it |
| 0:40.6 | a puzzle maker. The attack used three vulnerabilities in total, one remote code execution |
| 0:47.6 | vulnerability against Google Chrome, and then two of these vulnerabilities that Microsoft |
| 0:52.6 | patched today that are privilege escalation vulnerabilities. |
| 0:57.6 | Also interesting, the Google Chrome vulnerability was first found or disclosed as part of the |
| 1:03.4 | Pohn to Own program mid-April. A day later, proof-of-concept exploit was released without any sort of sandbox escape mechanism |
| 1:15.0 | and the attack that Kerspersky found just happened then another day later so April 14th, |
| 1:23.2 | April 15th is when Kerspersky did see the fully weaponized exploit chain being used in the while. |
| 1:31.5 | Google actually released an update to Google Chrome about a day before on April 13th. |
| 1:37.2 | So definitely, you know, make sure you keep those browsers up to date. |
| 1:40.7 | Those vulnerabilities are exploited pretty quickly after they become known. |
| 1:46.4 | And now, of course, we do get the fixes from Microsoft for these privilege escalation |
| 1:52.8 | vulnerabilities that were used as part of this puzzle maker attack. |
| 1:57.9 | Additional noteworthy vulnerabilities being patched by Microsoft this month is an off-occasion |
| 2:05.6 | bypass vulnerability in the Kerberus app container. It got a CVSS score of 9.4. There is also a remote |
| 2:14.9 | code execution vulnerability affecting Windows Defender. |
| 2:19.8 | And Microsoft rates the complexity of potential attack as low. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

