TLDR

TLDR Information Security 2026-05-27

600K Lithuanian Records Leaked πŸ‡±πŸ‡Ή, KnowledgeDeliver 0-Day RCE πŸ’₯, Google Family Link Hijack πŸ“±

How Veriff achieves 99.6% IDV accuracy (Sponsor)

πŸ”“

Attacks & Vulnerabilities

Charter Confirms Data Breach After ShinyHunters Extortion Threat (2 minute read)

Lithuania Suspects Foreign Involvement in Data Leak of Over 600k National Register Entries (2 minute read)

Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer (3 minute read)

🧠

Strategies & Tactics

How my minimal, memory-safe Go rsync steers clear of vulnerabilities (10 minute read)

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability (4 minute read)

πŸ§‘β€πŸ’»

Launches & Tools

Threat Modeling MCP Server (GitHub Repo)

iron-proxy (GitHub Repo)

IDA Pro MCP (GitHub Repo)

🎁

Miscellaneous

Google APIs Keys Keep Working After You Delete Them (6 minute read)

Paved With Intent: ROADtools and Nation-State Tactics in the Cloud (5 minute read)

⚑️

Quick Links

Microsoft Copilot Cowork Exfiltrates Files (1 minute read)

Google Family Link exploit that locks out victims permanently (2 minute read)

Curated news πŸ“°, research πŸ§‘β€πŸ”¬, and tools πŸ”’ for information security professionals

Join 410,000 readers for one daily email