
Three Buddy Problem
Ep8: Microsoft's zero-days and a wormable Windows TCP/IP flaw known to China
Aug 17, 2024 · 1 hr 17 min · 62.6 MB
0:00-1:17:45
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Three Buddy Problem - Episode 8: This week’s show digs into Microsoft’s in-the-wild zero-day woes, Patch Tuesday and the absence of IOCs, a wormable Windows TCP/IP flaw that the Chinese government knew about for months, Iran’s aggressive hacking US election targets, CrowdStrike v Qihoo360 and major problems with APT naming conventions.
Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)
Links:
- Episode 8 Transcript
- Six Windows Zero-Days Being Actively Exploited
- CVE-2024-38063 - Windows Ping of Death
- Wormable TCP/IP flaw known to China — Chinese researcher Xiao Wei of Cyber KunLun said he discovered the vulnerability “several months ago.”
- Google TAG: Iran steps hacking against Israel, U.S.
- Microsoft report on Iran election hacking
- Qihoo claims CrowdStrike bug exploitable
- CrowdStrike root cause analysis
- LABScon - Speakers 2024
Episode 8 Transcript
docs.google.comSix Windows Zero-Days Being Actively Exploited
securityweek.comCVE-2024-38063 - Windows Ping of Death
msrc.microsoft.comWormable TCP/IP flaw known to China
securityweek.comMicrosoft report on Iran election hacking
cdn-dynmedia-1.microsoft.comQihoo claims CrowdStrike bug exploitable
mp-weixin-qq-com.translate.googCrowdStrike root cause analysis
crowdstrike.comLABScon - Speakers 2024
labscon.io