Light

Episode #826 Quiz

The Kaseya Saga
Date: 2021-07-06 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

PrintNightmare exploited Windows Print Spooler RPC authentication bypasses to install malicious print drivers, enabling local privilege escalation and remote code execution; Microsoft’s initial patch was incomplete, so disabling the spooler or applying out-of-band updates was advised. Separately, REvil leveraged Kaseya VSA zero-days and antimalware exclusions to push ransomware through MSP supply chains.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What did the Chinese researcher from NSFOCUS say Microsoft had done when they patched CVE-2021-1675 in the June Patch Tuesday fix?
Question 2: What control did Western Digital say was missing from the My Book Live refactor that introduced the unauthenticated factory reset flaw?
Question 3: According to the episode, what two changes made Kaseya VSA especially effective as a ransomware delivery channel once the server was compromised?
Question 4: What immediate operational response did the DIVD help coordinate once the Kaseya attack was underway?
Question 5: What did REvil publicly offer for $70 million in bitcoin in its 'Happy Blog' post about the Kaseya attack?
Cancel