Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
ISC StormCast for Thursday, September 24th 2015
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/4669.mp3
SANS Daily Network Security Podcast (Stormcast) for Thursday, September 24th 2015
00:00
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
Cisco IOS and IOS XE Semiannual Software Security Advisory
http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep15.html
Apple iOS 9.0.1 Release (currently no security content posted, but if any is included, it should be listed at the URL below)
https://support.apple.com/en-us/HT201222
Partial iOS 9 Lock Screen Bypass
https://twitter.com/presentservices/status/646730290790969344?ref_src=twsrc%5Etfw
Over 4,000 Apps Affected by XCodeGhost
https://www.fireeye.com/blog/executive-perspective/2015/09/protecting_our_custo.html
Kaspersky Patches Security Vulnerabilities in AV product
http://googleprojectzero.blogspot.co.uk/2015/09/kaspersky-mo-unpackers-mo-problems.html
OPM Breach Update: 5.6 Million Fingerprints Stolen
https://www.opm.gov/news/releases/2015/09/cyber-statement-923/
http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep15.html
Apple iOS 9.0.1 Release (currently no security content posted, but if any is included, it should be listed at the URL below)
https://support.apple.com/en-us/HT201222
Partial iOS 9 Lock Screen Bypass
https://twitter.com/presentservices/status/646730290790969344?ref_src=twsrc%5Etfw
Over 4,000 Apps Affected by XCodeGhost
https://www.fireeye.com/blog/executive-perspective/2015/09/protecting_our_custo.html
Kaspersky Patches Security Vulnerabilities in AV product
http://googleprojectzero.blogspot.co.uk/2015/09/kaspersky-mo-unpackers-mo-problems.html
OPM Breach Update: 5.6 Million Fingerprints Stolen
https://www.opm.gov/news/releases/2015/09/cyber-statement-923/
Discussion
The lockscreen bypass was obviously a backdoor implanted on purpose, as no real code could accidentally cause such behaviour. It is strange how people continue trusting closed hardware and software produced in the US. Quoting Linus Torvald's father to Microsoft: "You have bug-backdoors".
Posted by Enos on Wed Sep 30 2015, 05:55
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Network Monitoring and Threat Detection In-Depth | Baltimore | Mar 3rd - Mar 8th 2025 |
Application Security: Securing Web Apps, APIs, and Microservices | Orlando | Apr 13th - Apr 18th 2025 |