logo
episode-header-image
Oct 2
35m 54s

Zero Day, Zero Warning: Inside the Disco...

SHI
About this episode

Twelve years. That's how long a vulnerability sat in sudo—the command powering every Linux system—waiting for the wrong hands. When Stratascale researchers Rich Mirch and Quentin Rhoads-Herrera discovered not one, but two zero-day vulnerabilities in sudo, millions of systems worldwide were at risk. 

Go behind the scenes of a discovery that could have changed everything—but didn't, thanks to ethical research and responsible disclosure. Learn how a 12-year-old vulnerability went undetected in one of the world's most scrutinized open-source projects, why human curiosity still outpaces automated security tools, and the methodology behind discovering critical flaws in mature, battle-tested software.

Guests: Rich Mirch, Principal Security Researcher, Stratascale; Quentin Rhoads-Herrera, VP of Security Services, Stratascale

Stratascale is a wholly owned subsidiary of SHI International, delivering cutting-edge cybersecurity research and managed security services.

Show Notes & Resources

Read our blog announcing the vulnerabilities: https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host CVE Details: • CVE-2025-32462 - The 12-year sudo vulnerability • CVE-2025-32463 - The more severe chroot vulnerability

Key Timestamps: • [02:07] - Rich's discovery approach: assuming vulnerabilities exist • [08:03] - Quinton's validation process and initial disbelief • [13:31] - The "double take" moment of confirming the discovery • [21:21] - Dynamic vs. static testing methodology • [29:03] - Why offensive security research matters • [34:44] - Career advice for aspiring cybersecurity professionals

Learn More: When you need expert guidance on cybersecurity solutions and frameworks, trust SHI's Field CISOs and security experts. We help identify critical gaps, consolidate security platforms, and integrate AI into your cybersecurity practices. Learn more at https://www.shi.com/solutions/cybersecurity

Up next
Sep 18
The Last Swimmer in the Pool: Deaflympian Brooke Thompson on Adaptive Tech
More than 80% of disabilities are invisible, yet too often technology and workplace systems overlook these needs. In this episode, Rutgers swimmer and Deaflympian Brooke Thompson shares her inspiring journey—from Michigan lakes to the global stage—powered by adaptive technology a ... Show More
31m 18s
Sep 16
Innovation Heroes – Season 7: Real Voices, Real Risks, Real Answers
SHI's Innovation Heroes is back. After hitting #1 on the Apple Technology charts, Season 7 brings twelve no-fluff episodes on the real risks and real answers facing IT leaders today—from cybercrime that runs like a Fortune 500 to the power of accessibility in tech. It's a new sea ... Show More
1m 29s
Apr 2025
The New Rules of Virtualization: Insights for Navigating Change
What should you really do about your VMware environment? Since Broadcom’s acquisition, virtualization strategy has become a hot topic on the minds of CIOs and infrastructure leaders. In this episode, we sit down with Cody Hosterman, Senior Director of Product Management – Cloud a ... Show More
24m 56s
Recommended Episodes
Jan 2025
Sam Altman on AI Superintelligence, U.S. Buys Record Nuclear Power, and Nvidia's Personal AI Supercomputer
We're experimenting and would love to hear from you!In this episode of Discover Daily, we explore groundbreaking developments in AI and energy sectors that are reshaping our technological landscape. OpenAI's dramatic shift towards superintelligence development, following ... Show More
9m 52s
Apr 2021
Making Quantum Computers a Commercial Reality
IonQ is the first company solely focused on quantum computing to go public, with its quantum computers accessible via the cloud today. The company’s co-founder/chief scientist Chris Monroe and president/CEO Peter Chapman join Azeem Azhar to explore how they turned cutting-edge re ... Show More
49m 17s
Feb 2024
When brains and computers meet
Are cyborgs now reality? Elon Musk certainly thinks so. His company, Neuralink, has successfully implanted one of its wireless brain chips in a human. Although billed as a breakthrough, they’re not the first to do it. In fact, similar devices have already been implanted, all with ... Show More
27m 12s
Jan 2022
“The Most Important Things Are Invisible”
Each individual server stacked high inside a data center is powerful in its own right. But without a way of linking them together, they aren't much use to anyone. It takes a vast collection of switches, cables, and software control systems to create a well-functioning global netw ... Show More
14m 59s
Sep 2024
Quantum computers aren't what you think — they're cooler | Hartmut Neven
Quantum computers obtain superpowers by tapping into parallel universes, says Hartmut Neven, the founder and lead of Google Quantum AI. He explains how this emerging tech can far surpass traditional computers by relying on quantum physics rather than binary logic, and shares a ro ... Show More
12m 18s
Jun 2024
Do we have enough energy to power AI?
Artificial Intelligence is something that’s all around us in our daily lives. And even if we do use it, whether that’s to search for a recipe online, make a funny photo, or ask it to help with our homework, every task that AI does uses power. That power is electricity. Around the ... Show More
22m 59s
Nov 2024
How AI is changing national security w/ Kathleen Fisher
We’ve had conversations about AI’s online influence on politics, from deepfakes to misinformation. But AI can also have profound effects on hardware – especially when it comes to national security and military capabilities like weapons and stealth technologies. Kathleen Fisher is ... Show More
55m 1s
Jan 2024
Better Satellite World: Deep Diving from Space, Episode 3 - Satellites & Cities
In this Better Satellite World podcast series, we explore the exciting developments in space-based data analytics and the absolutely game-changing nature of this relatively new part of the industry. The third episode features a conversation with Raimundo Rodulfo, Director of Inno ... Show More
44m 52s