Light

Episode #864 Quiz

Targeted Exploitation
Date: 2022-03-29 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome’s second 2022 zero-day was a V8 type-confusion bug enabling out-of-bounds memory access; Google patched it after in-the-wild exploitation and urged Enhanced Safe Browsing and updates. The episode also covered Ukraine ISP resilience, npm typosquatting against @azure packages, fixed-code Honda key replay attacks, and FCC restrictions on Kaspersky and Chinese telecoms.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific condition did JFrog say made the npm attack particularly effective against Azure developers who were not careful about package names?
Question 2: What did Google’s TAG team say the initial Chrome exploit kit did before delivering the Chrome RCE in the North Korean campaigns?
Question 3: How did the attackers constrain delivery of the Chrome exploit stages to make analysis and reuse difficult?
Question 4: What was the key security flaw identified in the 2016–2020 Honda Civic key system discussed in the episode?
Question 5: What did the episode say about the likely duration of active exploitation of Chrome’s first zero-day of the year before it was spotted and patched?
Cancel