meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 1 July 2026

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, July 1st, 2026 edition of the Sands Internet Storm Center's Stormcast.

0:12.9

My name is Johannes Ulrich, recorded day from Riyadh, Saudi Arabia.

0:18.2

And this episode is brought you by the sands.edu,

0:21.6

graduate certificate program in industrial control system security.

0:26.9

Well, Apple did release updates this weekend with that security patches for iOS, iPadOS,

0:33.9

MacOS, and Safari. So this lineup is a little bit different of what we usually see from

0:39.3

apple apple typically updates all of its operating systems and also well we don't really have the

0:45.1

same number of vulnerabilities being addressed as usual but a smaller number 28 vulnerabilities total

0:51.8

most of these vulnerabilities are web kit, and that also explains the focus on iOS and Mac OS.

1:00.9

The other operands like WatchOS and such, of course, are less exposed to WebKit.

1:07.5

There are a couple of kernel vulnerabilities that are also being addressed here, and these vulnerabilities will potentially also affect the other operating systems like watchOS, Vision OS, and TV OS.

1:21.5

So I expect that there will be an update for the other operating systems relatively shortly.

1:29.3

Part of the reasoning behind this update was also that some of these vulnerabilities had already been addressed in

1:34.3

beta versions of the next major release of iOS, iPad OS and MacOS. An MDR company Blackpoint did release a blog post outlining a recent intrusion that they have

1:49.1

observed against Simple Help.

1:51.6

Simple Help is one of those remote tech support platforms, so enterprises use it to basically

1:57.7

be able to reach out and support systems across their network.

2:02.6

And it suffered, well, not even two weeks ago from an open ID connect bypass.

2:08.6

So that essentially allowed an authentication bypass and an attacker is able to authenticate as a technician,

2:15.6

and with that able to then reach out to remote systems

2:20.0

that are connected to this particular simple help instance.

2:24.4

What Blackpoint observed is that the attacker did deploy a fairly obfuscated JavaScript file.

...

Transcript will be available on the free plan in 1 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.