SANS Stormcast Friday April 24rd, 2026: Apple Update; Bitwarden Compromise; ASP.NET Core Patch
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 24 April 2026
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, April 24th, 2006 edition of the Sands Internet Stormsanders Stormcast. |
| 0:12.0 | My name is Johannes Ulrich, recorded today from Amsterdam, Netherlands. |
| 0:17.0 | And this episode is brought you by the sands.edu graduate certificate program in incident response. |
| 0:24.9 | Today I wrote a quick diary about a patch that Apple released yesterday. This patch fixes a single |
| 0:33.0 | vulnerability in iOS and iPad OS. And while it's not unusual for Apple to release these sort of single vulnerability updates, |
| 0:43.5 | these updates are usually reserved for currently exploited vulnerabilities. |
| 0:49.3 | And Apple's description of the vulnerability does not actually note that it's already exploited. On the other |
| 0:56.0 | hand, well, the nature of the vulnerability, it does describe it as a vulnerability in the notification |
| 1:02.8 | center where notifications that are marked for deletion are not actually deleted. And exactly |
| 1:09.4 | this particular vulnerability was noted in a press description of a recent criminal |
| 1:18.9 | case in which the FBI was able to recover at least partial signal messages by looking at |
| 1:26.5 | these notifications that were not deleted. |
| 1:29.8 | So and so far it is certainly already an exploited vulnerability and also not a terribly |
| 1:34.6 | difficult to exploit vulnerability. |
| 1:37.3 | It's a common problem with secure messengers that if they are using sort of these built-in |
| 1:43.4 | operating system messaging components, |
| 1:45.9 | that these components may, well, at a very least, not encrypt the messages to the same standard |
| 1:51.7 | as the originating application, but also that artifacts of sending messages or receiving messages |
| 1:59.8 | may often be retained in these additional operating system components, |
| 2:04.8 | as they're usually not designed for these threat models that these end-to-end encrypted messengers are often designed for. |
| 2:14.0 | So this isn't fundamentally new, and in Signal, you had the option to disable |
| 2:20.1 | notifications, but now Apple also fixed the bug slash vulnerability that the notification artifacts |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

