Light

Episode #868 Quiz

The Zero-Day Explosion
Date: 2022-04-26 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

CISA’s exploited-vulnerability catalog now includes older flaws, reflecting long patch tails. Lenovo UEFI drivers left in production firmware let privileged code disable SPI flash protections and Secure Boot, enabling bootkits. A browser-based wallet exposed private keys via a constant nonce and six-digit PIN brute force. Java ECDSA flaws let attackers forge signatures.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the critical flaw in the Everscale/Ever Surf web wallet that made the browser version fundamentally unsafe?
Question 2: What was the specific problem ESET found in the Lenovo UEFI firmware that let an attacker with privileges disable protections and plant bootkit-style malware?
Question 3: Which combination of Lenovo vulnerabilities and effects was reported by ESET and confirmed by Lenovo in the episode?
Question 4: What exploitability threshold did the episode highlight for the Java flaw affecting versions 15 through 18?
Question 5: What did Mandiant report about zero-day activity in 2021 compared with prior years?
Cancel