ISC StormCast for Wednesday, May 5th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 May 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 5th, 2021 edition of the Sansonet Stormontas Stormcast. |
| 0:07.9 | My name is Johannes Ulrich. |
| 0:09.5 | And I'm recording from Jacksonville, Florida. |
| 0:13.5 | After Apple patching everything yet again yesterday, Google today followed with its regular patch Tuesday. |
| 0:21.7 | Nothing out of the ordinary here, nothing at least labeled as being already being exploited, |
| 0:27.5 | but there are a number of critical remote code execution vulnerabilities. |
| 0:33.1 | And then again, remember if you do see May 1st as your patch level, that means that you have the May |
| 0:40.6 | patches installed. |
| 0:41.8 | If it says May 5th, then you also have prior security updates, including the May 1 installed. |
| 0:50.1 | So that's really sort of what you're going for. |
| 0:53.2 | If you're using a Google Pixel phone, then you received additional patches for various |
| 1:00.2 | kernel and Qualcomm components. |
| 1:04.5 | Keeping your firmware up to date on various devices is tricky and Dell tries to help you out here by providing some firmware |
| 1:14.3 | update drivers with all Dell computers. Sadly, Sentinel Labs figured out that these drivers |
| 1:22.6 | suffer from a privilege escalation vulnerability, providing a user with full kernel level access. |
| 1:30.8 | What makes this such a big deal is that these drivers have shipped with this particular |
| 1:37.0 | vulnerability since 2009 on all Dell desktops, laptops, and tablets. |
| 1:44.8 | So pretty much anything Dell shipped that wasn't a server is affected by this vulnerability. |
| 1:51.8 | And I think the headline here from Sentinel Labs who found this particular vulnerability |
| 1:57.9 | stating that hundreds of millions of Dell computers are at risk is |
| 2:02.4 | probably not overstating the problem here. So if you have any system with a Dell label on it, |
| 2:09.7 | you better head over to the Dell website. They have a more detailed list of what's exactly |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

