Light

Episode #1047 Quiz

RediShell's CVSS 10.0
Date: 2025-10-14 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

Security Now! Episode 1047 reveals RediShell, a critical CVSS 10.0 remote code execution vulnerability in Redis affecting 330,000 exposed servers worldwide. It exploits a 13-year-old Use-After-Free bug in Redis's Lua interpreter, allowing attackers to escape the sandbox and execute arbitrary host code post-authentication, urging immediate patching to prevent cloud environment compromises.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What specific technical flaw underlies the 'RediShell' vulnerability discovered in Redis servers, and why does it result in a CVSS score of 10.0?
Question 2: According to the episode, what critical security practice is repeatedly violated by many Redis deployments, increasing their risk of exploitation?
Question 3: What limitation in Microsoft's Internet Explorer (IE) Mode within Edge has led them to change its accessibility to users?
Question 4: What are the key requirements imposed by the Texas Senate Bill SB2420 on app stores and apps regarding minor users?
Question 5: What operational risks do the attack techniques used by Scattered LAPSUS$ Hunters to breach Salesforce customers highlight about enterprise API usage?
Cancel