Light

Episode #919 Quiz

Forced Entry
Date: 2023-04-18 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Microsoft patched 97 vulnerabilities, including an exploited Windows Common Log File System elevation-of-privilege zero-day, critical MSMQ and DHCP remote code execution flaws, and multiple RCE, info-disclosure, DoS, spoofing, and feature-bypass issues. Google launched free Assured OSS, providing vetted Java and Python packages, SBOMs, tamper-evident provenance, scanning, fuzzing, and upstream fixes.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the episode’s discussion of Microsoft’s April 2023 Patch Tuesday, what made the Windows Common Log File System Driver zero-day especially dangerous from an operational standpoint?
Question 2: According to the episode, what was the key feature Google highlighted in Assured Open Source Software that distinguished it from a generic package mirror?
Question 3: What mechanism did WhatsApp’s new Device Verification feature use to detect that the same account was being accessed from a physically separate client?
Question 4: What did WhatsApp’s Automatic Security Codes feature add to contact verification, according to the episode?
Question 5: In the ForcedEntry deep dive, what sequence allowed a malicious file disguised as a GIF to become code execution on iPhone?
Cancel