meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 10th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 9 May 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. MSFT Patch Tuesday; Cisco CMP-Telnet Patch; WolfSSL Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, May 10th, 2017 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich,

0:08.5

and today I'm recording from Jacksonville, Florida. Microsoft Patch Tuesday today, of course, a little bit

0:15.0

difficult to compare to past Patch Tuesdays given the new format, but I would guess that today's Patch Tuesdays probably

0:23.6

would have been one of the smaller ones based on the number of bulletins, maybe five or six

0:30.6

bulletins, I think. We do have updates for In The Explorer and Microsoft Edge.

0:36.6

Aside from fixing a number of vulnerabilities, this

0:40.4

also turns off Shah 1 support in these two browsers. This change will however

0:46.9

not affect Enterprise certificates so if you have your own certificate authority

0:52.6

then you can still use Shah 1 certificates. That's a nice option if you have your own certificate authority, then you can still use SHA-1 certificates.

0:56.3

That's a nice option if you, for example, have things like cameras.

1:01.3

For example, I ran into that that only support Sha-1, so you can still use your own certificate

1:07.5

authority for these devices.

1:10.5

And then there are patches for a number of

1:13.5

dot net core or a sp.net core packages. The vulnerabilities being addressed here can lead to

1:20.4

privilege escalation. The tricky part is that these are essentially libraries that you're

1:25.3

including in your dot net project.

1:28.3

So in order to really apply these patches, you not only have to update the libraries,

1:35.3

you also have to include the updated libraries in your project.

1:39.3

There is a configuration file that essentially specifies which versions of these libraries you include

1:47.1

and you have to update these configuration files.

1:50.6

The vulnerability is really exposed by applications written using these libraries.

1:56.9

And then there's an interesting Windows Update vulnerability in Windows 10 and Server 2016 that's being patched here.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.