Light

Episode #1063 Quiz

Mongo's Too Easy
Date: 2026-02-03 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

This Security Now! episode discusses a widespread supply chain attack on eScan antivirus where malware replaced a legitimate update executable, persisted through scheduled tasks, and disabled updates by modifying the hosts file, highlighting the risks of third-party AV kernel-level privileges.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the primary factor allowing the malware distributed via the eScan antivirus update server breach to prevent the antivirus from updating itself further?
Question 2: What key reason did the cURL project give for discontinuing its bug bounty program at the start of 2026?
Question 3: Regarding the AI-driven cybersecurity company AISLE's contributions, what is notable about their discovery of OpenSSL vulnerabilities in 2025?
Question 4: What is the typical attack pattern used by script kiddies exploiting unsecured MongoDB instances, as described in the episode?
Question 5: What is a major limitation in applying AI-based solutions like AISLE to fix software security issues, according to the episode's final analysis?
Cancel