Pressure Zone Podcast Series - Episode 4

What happens when an open-source library buried deep in your cloud architecture goes rogue and the solo maintainer holds the patch for ransom? Step into the hot seat with Chief Strategy Officer Caroline Wong as she navigates an ethical supply chain strike, boardroom pressure to alter security metrics, and a critical unpatched RCE vulnerability with the clock ticking. 

Presented by Hack The Box

PZ-Ep-4-Caroline-Thumbnail

Pressure Zone - Episode 4

The Zero-Day Squeeze

  • Listen on demand
  • Video & Audio Available
  • Available on Spotify, Apple Podcasts & YouTube

Overview

An unauthenticated Remote Code Execution (RCE) vulnerability hits a deep open-source dependency inside your production microservices. The solo maintainer drops a proof-of-concept exploit and refuses to release a patch until corporate users pool a $600,000 sustainability fund.  

In the fourth episode of Pressure Zone, host Christine Bartlett puts Chief Strategy Officer Caroline Wong into the executive hot seat. What begins as an ethical open-source strike quickly spirals into a high-pressure crisis involving SEC disclosure dilemmas, boardroom pressure to alter risk dashboards, an internal developer mutiny, and active internet scanning.  

Faced with brutal trade-offs, Caroline must choose whether to risk database corruption with an experimental memory patch, pull rank on exhausted engineers, or aggressively amputate application features to save core database records.

What Would You Do?

Ready to test your decision-making against an open-source ransom demand? Watch the episode to see how Caroline managed the blast radius, then see if you have what it takes to survive the zone.