
ISC StormCast for Friday, March 11th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
Anes Spectre Is Back!
russiano proposed setting up its own certiv authority, and already has a wep side set up. Video of a proof of concept exploit has been posted that does show how the hash of the route password can be accessed by an unprivileged user. Exploitation of the problem is significantly easier if unprivileged e b p f is enabled. The siponability has yet again been revived, this time in the form of a branch history inj on warn ability.
Play episode from 02:43
Transcript


