Light

Episode #1083 Quiz

Patch Tuesday à la AI
Date: 2026-06-16 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

Security Now! #1083 details a severe supply-chain compromise involving over 400 ArchLinux User Repository packages infected with a Rust-implemented Linux ELF rootkit and infostealer, exploiting npm lifecycle preinstall hooks to harvest developer and collaboration app credentials. Anthropic’s AI models Mythos 5 and Fable 5 were suspended by US government export controls to prevent jailbreak abuses.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the ArchLinux User Repository (AUR) compromise described in Security Now! #1083, how did the attacker ensure execution of the malicious malware on developer machines?
Question 2: What capability does the malware’s eBPF rootkit component provide, as described in the Security Now! #1083 episode?
Question 3: According to Security Now! #1083, what are the four binary decision points used in CISA’s Binding Operational Directive 26-04 to prioritize patching timelines?
Question 4: What is the main concern raised in Security Now! #1083 about NPM’s plan to disable automatic execution of install scripts by default in version 12.0?
Question 5: In the June 2026 Microsoft Patch Tuesday overview from Security Now! #1083, which vulnerability was fixed by introducing a new "MaxHeadersCount" registry setting?
Cancel