Listen

Description

Big news this week as several government agencies and contractors may have been compromised. We also have a number of great writeups this week covering everything from a PS4 webkit exploit, MacOS, and Windows.


[00:00:25] CISA issues emergency directive for SolarWinds Orion products compromise


[00:26:53] Finding Critical Open Source Projects


[00:33:46] Vulnerabilities in McAfee ePolicy Orchestrator


[00:39:20] Chat Question: How to get good at exploit dev


[00:44:34] Novel Abuses On Wi-Fi Direct Mobile File Transfers


[00:47:55] PsExec Local Privilege Escalation


[00:52:31] Windows: WOF FSCTL_SET_REPARSE_POINT_EX Cached Signing Level SFB


[01:01:07] This is for the Pwners: Exploiting a WebKit 0-day in PlayStation 4


[01:08:51] Game On - Finding vulnerabilities in Valve’s "Steam Sockets"


[01:14:57] Apple macOS Kernel OOB Write Privilege Escalation Vulnerability [CVE-2020-27897]


[01:17:22] ABSTRACT SHIMMER: Host Networking is root-Equivalent, Again [CVE-2020-15257]


[01:24:41] Now you C me, now you don't, part two: exploiting the in-between


[01:36:04] Portable Data exFiltration: XSS for PDFs


[01:45:27] HackerOne's 12 Days of Hacky Holidays


[01:47:55] The 2020 SANS Holiday Hack Challenge

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)