4.9 • 696 Ratings
🗓️ 27 October 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, October 27, 2021 edition of the Sandcent Storm Center's Stormcast. |
0:09.2 | My name is Johannes Ulrich and I'm recording from Alcobar, Saudi Arabia. |
0:16.1 | Apple released its new operating system, Monoray, and with that we got a number of security updates. |
0:23.3 | Sad part is we don't really know what security vulnerabilities are being fixed. |
0:29.4 | It states on Apple's security updates page that there will be details released shortly, |
0:36.4 | so maybe by tomorrow we do have some more details. |
0:42.0 | This also affects iOS, watchOS, TVOS, and iPad OS. |
0:47.1 | All of these operating systems have been updated, and there was also a security update for macOS bixer but then again no details available at this point |
0:59.6 | it's also noteworthy that if you received a new mac this week that had a macOS monoray |
1:06.1 | pre-installed there is also an update for you mac macOS Monoray 1201, which is the version that was |
1:15.1 | then released for download, does include additional security updates. And according to a blog post |
1:23.4 | by researchers from Inky, it looks like Craigslist, maybe subject to some form of breach |
1:31.5 | that allowed an attacker to send email on Craigslist's behalf. |
1:36.5 | The emails in question are only sent to active Craigslist users, and they originated from |
1:43.7 | an IP address that is actually associated with |
1:47.9 | Craigslist and did pass SPF and decim checks. I haven't seen anything from Craigslist about |
1:55.2 | this incident. Of course, there's always a chance that they may have just abused the internal |
2:00.3 | messaging function |
2:01.2 | or something like this. |
2:02.7 | The emails themselves claimed that the recipient had listed an item that was inappropriate for Craigslist, |
2:10.8 | provided a link to remedy the issue, and that link then led to, well, possibly malware. |
2:19.3 | The InQ researchers were not able to retrieve the last step here because the link was |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.