TLDR

TLDR Information Security 2024-07-26

KnowBe4 hires North Korean Hacker πŸ‘¨β€πŸ’», PKFail undermine secure boot πŸ—οΈ, LetsEncrypt deprecates OCSP ⚑

Tines is the secure way to introduce LLM-powered automation to your security workflows (Sponsor)

πŸ”“
Attacks & Vulnerabilities

Michigan Medicine notifies nearly 57K patients after health information potentially exposed in cyberattack (2 minute read)

KnowBe4 Discovers Remote Worker is Really a North Korean Hacker (3 minute read)

PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem (6 minute read)

🧠
Strategies & Tactics

Unfashionably secure: why we use isolated VMs (12 minute read)

A Hard Look at GuardDuty Shortcomings (7 minute read)

How We Securely Generate Sensitive Secrets (8 minute read)

πŸ§‘β€πŸ’»
Launches & Tools

FlowAnalyzer (GitHub Repo)

Lakera (Product Launch)

GPT4-Captcha-bypass (GitHub Repo)

SEC Materiality framework (Sponsor)

🎁
Miscellaneous

Forget security – Google's reCAPTCHA v2 is exploiting users for profit (7 minute read)

Invisible Ghost: Alarming Vulnerability in GitHub Copilot (8 minute read)

Cloudflare Reports that Nearly 7% of Internet Traffic is Malicious (4 minute read)

⚑️
Quick Links

Double Dipping Cheat Developer Gets Caught Red-Handed (7 minute read)

Anyone can Access Deleted and Private Repository Data on GitHub (6 minute read)

Moving to a more privacy-respecting and efficient method of checking certificate revocation (2 minute read)

Curated news πŸ“°, research πŸ§‘β€πŸ”¬, and tools πŸ”’ for information security professionals
Join 280,000 readers for one daily email