Light

Episode #1071 Quiz

Bucketsquatting
Date: 2026-03-24 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

This episode investigates H&R Block’s tax software installing a long-lived root CA with its private key exposed, enabling global TLS man-in-the-middle attacks and code-signing spoofing.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What critical security flaw did H&R Block's 2026 tax preparation software introduce by installing a root CA certificate named "WK ATX ServerHost 2024" on users' machines?
Question 2: What is the main operational reason H&R Block's tax software included a private key to the root CA locally on the user's machine?
Question 3: What vulnerability does the "bucketsquatting" issue with Amazon S3 buckets exploit?
Question 4: How did Amazon's introduction of "account regional namespaces" aim to mitigate the bucketsquatting problem going forward?
Question 5: According to Amazon Threat Intelligence's findings about the Cisco Secure Firewall Management Center vulnerability CVE-2026-20131, what was a key factor that allowed the Interlock ransomware to exploit it before disclosure?
Cancel