meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 16th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 16 October 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Adobe Updates; Symantec BSDO; OSX Shlayer/Tarmac; Fake iOS Jailbreak

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, October 16th, 2019 edition of the Sandsenet Storms,

0:06.2

and its Stormcast, my name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.5

Well, looks like Adobe's patch Tuesday came a week late, and today we got four different Adobe bulletins to talk about.

0:23.6

Brought the most important of the updates affects Adobe Acrobat and Raider. A total of 68 vulnerabilities

0:31.6

are being fixed here and 45 of them are rated as critical and allow arbitrary code execution.

0:40.9

In addition to this, we got an update for the Adobe Download Manager.

0:44.5

This fixes DLL hijacking vulnerability.

0:50.1

Then we got an update for Adobe Experience Manager forms.

0:55.0

This also fixes a single vulnerability, a cross-site scripting issue.

1:00.5

And finally, we do have an update for the Adobe Experience Manager that fixes 12 different

1:07.2

vulnerabilities.

1:08.6

So really the Adobe Acrobat and reader vulnerabilities are probably

1:13.0

the big one here that you should address quickly. Now we've got nothing for Flash here and

1:19.7

Flash of course is the important one when it comes to synchronizing the Adobe Patch Tuesday

1:25.4

with Microsoft's Patch Tuesday because it is integrated into browsers.

1:31.3

So the reason that these updates are arriving not in sync with Microsoft's Patch Tuesday

1:37.3

is not an indication that these are super critical.

1:41.3

Actually, the priority as Adobe calls it, is pretty much two for all of these vulnerabilities,

1:48.6

meaning that there is no exploit expected to be imminent.

1:55.3

And users of Symantex endpoint protection client reported on various forums, a blue screen of death,

2:03.8

yesterday. Turns out that Symantec apparently did release a bad update on Monday. The affected version

2:12.6

is the intrusion prevention signature, 1014, R61.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.