Light

Episode #863 Quiz

Use After Free
Date: 2022-03-22 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Security Now examined a new U.S. law mandating critical infrastructure breach reporting within 72 hours and ransomware payments within 24, plus CISA subpoena power. It highlighted npm supply-chain sabotage, Browser-in-the-Browser phishing, Trickbot’s MikroTik proxy abuse, an OpenSSL infinite-loop DoS in certificate parsing, Duo fail-open MFA bypasses, and use-after-free dangers.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: Under the new U.S. cybercrime reporting law discussed in the episode, which organizations are required to report a breach to CISA within 72 hours?
Question 2: What did the malicious Node-IPC update do when it detected an IP address geolocated to Russia or Belarus?
Question 3: What made the Browser-in-the-Browser phishing technique especially convincing, according to the episode?
Question 4: How did the Russian actors disable Duo MFA on the NGO's Windows environment, according to the CISA write-up discussed in the episode?
Question 5: What was the immediate effect of the OpenSSL flaw centered on BN_mod_sqrt() when triggered with a crafted certificate?
Cancel