Light

Episode #821 Quiz

Epsilon Red
Date: 2021-06-01 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome 91 fixed 32 vulnerabilities, added clipboard paste support, blocked NAT slipstreaming port 10080, and sped JavaScript via Sparkplug and short built-in calls. Google MyActivity can now be password-protected or auto-deleted. Amazon Sidewalk uses encrypted LoRa/BLE bridging. Epsilon Red ransomware used PowerShell, WMI, and scheduled tasks to disable defenses and encrypt indiscriminately.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the Chrome 91 discussion, what new protection did Google bring down to the shipping desktop release in response to NAT slipstreaming concerns?
Question 2: What did Google’s MyActivity page newly allow users to do, according to the episode?
Question 3: According to Sophos’s analysis, which PowerShell script first attempted to invoke uninstallers for security products in the Epsilon Red attack chain?
Question 4: Which combination best matches the firewall modifications that Epsilon Red’s RED.ps1 made after its one-hour wait?
Question 5: What did the Epsilon Red ransomware executable do when encrypting folders, according to the episode?
Cancel