meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 September 2025

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, September 30th, 20th,

0:07.9

2000, 5th edition of the Sands and at Storm Center's Stormcast.

0:12.9

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:18.1

And this episode is brought you by the sands.edu master's degree program in

0:23.2

information security engineering. Today we got a little bit of surprise update from Apple for

0:30.9

iOS, iPad OS and macOS 26. No, it's not a surprise that there is an update shortly after there is a

0:39.2

major update like this because that usually fixes some of the bugs and such that came out

0:46.0

after the product was sort of released to the masses. But this time it also fixes an single

0:53.8

vulnerability. It's a font parser vulnerability that but this time it also fixes a single warnability.

0:55.2

It's a font parser vulnerability that can lead to unexpected app termination or corrupt process memory.

1:03.6

The second part could hint to possible code execution, even though that's not stated like this in the advisory.

1:12.1

There is no indication from Apple that this particular vulnerability has already been

1:16.9

exploited. Often Microsoft does release sort of these one vulnerability updates for actively

1:23.4

exploited vulnerabilities. But I think here it's just that this was sort of one of the

1:27.1

issues that came up after 26 was released and now is being patched as a security patch with the

1:35.3

functional patches released with this update. They also released it for a couple older versions

1:41.5

of macOS as well as for the last version before 26 for iOS and iPad OS.

1:50.3

Doesn't affect TVOS, doesn't affect watchOS, so the updates released today for those operating systems are just functional.

1:59.8

And our honeypots are seeing an increase in scans for a little bit

2:04.7

an older Palo Alto Global Protect Warnability. That's Palo Alto's VPN solution. It exploits CVE

2:13.0

24, 3,400. This vulnerability is very easy to exploit and has already been widely exploited.

2:21.8

I see this a little bit sort of as a cleaning up kind of scan, looking if there are any unexploited

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.