Light

Episode #805 Quiz

SCADA Scandal
Date: 2021-02-09 | Length: 2 hrs | Episode page at twit.tv

About this episode

Chrome’s Great Suspender was removed after a suspected malicious ownership transfer and remote code execution in extension updates. Google patched an exploited V8 heap overflow; North Korean actors used fake research personas, malware-laced Visual Studio projects, and Chrome sync for command-and-control. WordPress NextGEN Gallery CSRF bugs enabled RCE.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: Why did Google remove The Great Suspender from the Chrome Web Store and push it off installed browsers?
Question 2: What was the exploit mechanism behind the Chrome zero-day that Google patched on February 4th?
Question 3: How was the malicious Chrome extension abusing Chrome sync to bypass local defenses?
Question 4: What did Microsoft say happened with the Windows Defender ATP detection on the freshly patched Chrome release?
Question 5: What was the key design problem with the Oldsmar water plant incident?
Cancel