Light

Episode #1076 Quiz

FAST16.SYS
Date: 2026-04-28 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

Security Now! #1076 details a sophisticated mid-2000s Windows malware framework involving a kernel driver, fast16.sys, which stealthily intercepts executable loading to patch binaries in-memory with 101 precise rules, notably injecting floating-point code to subtly corrupt scientific computations.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the primary method used by the supply-chain malware in the compromised Bitwarden CLI package to exfiltrate stolen credentials?
Question 2: What is the significance of the PDB path found inside svcmgmt.exe in the context of the fast16.sys investigation?
Question 3: How did the fast16.sys kernel driver modify executable files during its operation?
Question 4: What specific types of software were identified as likely targets of the precision sabotage caused by fast16.sys?
Question 5: Which feature of svcmgmt.exe indicated that the fast16 framework was designed for modularity and adaptability?
Cancel