Microsoft OneNote Malware, TPM 2.0 Flaws, The Good & Bad in Cybersecurity | Cyber Threat Briefing

Опубликовано: 29 Июль 2026
на канале: SureCloud
131
1

Every month, our experts Nick, Hugh and Arron will highlight the current and emerging cyber threats you need to know about right now, giving you great insights to help protect your organization.

March's Cyber Threat Briefing covers:

💡 Microsoft OneNote used to spread malware across networks
💡 TPM 2.0 flaws leave cryptographic keys vulnerable
💡 The line between good and bad in cybersecurity

💻 Register for our next episode here: https://www.surecloud.com/resources/w...

👉 Learn more: https://www.surecloud.com/cyber-secur...

👂 Questions? Email: 𝗯𝗿𝗶𝗲𝗳𝗶𝗻𝗴@𝘀𝘂𝗿𝗲𝗰𝗹𝗼𝘂𝗱.𝗰𝗼𝗺

👉 Nick Hayes' LinkedIn:   / nickjhayes  
👉 Hugh Raynor's LinkedIn:   / hughraynor  
👉 Arron Dowdeswell's LinkedIn:   / dowdeswell  

Timestamps

00:13 Intro
𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗢𝗻𝗲𝗡𝗼𝘁𝗲: 𝘂𝘀𝗲𝗱 𝘁𝗼 𝘀𝗽𝗿𝗲𝗮𝗱 𝗺𝗮𝗹𝘄𝗮𝗿𝗲 𝗮𝗰𝗿𝗼𝘀𝘀 𝗻𝗲𝘁𝘄𝗼𝗿𝗸𝘀.
01:34 - New mechanism for delivering malicious payloads to users since around December time
02:16 - A quick history of email-based phishing and difficulties surrounding that these days
04:30 - What is it specific to things like Excel and Word based-attacks previously? What has changed now that means we have to find new ways?
07:22 - How can organizations remediate this kind of attack?
𝗧𝗣𝗠 𝟮.𝟬 𝗳𝗹𝗮𝘄𝘀 𝗹𝗲𝗮𝘃𝗲 𝗰𝗿𝘆𝗽𝘁𝗼𝗴𝗿𝗮𝗽𝗵𝗶𝗰 𝗸𝗲𝘆𝘀 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗹𝗲.
09:15 - What is TPM (Trusted Platform Module)?
10:47 - Who maintains and defines what a TPM chip does?
11:39: What's the future of TPM?
13:18 - Is TPM secure? What vulnerabilities have been found? How can these be exploited? What vectors need to exist?
17:42 - What are the recommendations here to mitigate these vulnerabilities?
19:50- What is the level of awareness security leaders should have on TPM?
𝗘𝘁𝗵𝗶𝗰𝘀: 𝘁𝗿𝗲𝗮𝗱𝗶𝗻𝗴 𝘁𝗵𝗲 𝗹𝗶𝗻𝗲 𝗯𝗲𝘁𝘄𝗲𝗲𝗻 𝗴𝗼𝗼𝗱 𝗮𝗻𝗱 𝗯𝗮𝗱 𝗶𝗻 𝗰𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆.
21:26 - What can be done to prevent people from doing malicious things?
25:35 - What happens when the "ethical" guys are also criminals?
28:55 - Is hacking worth it?
31:06 - From a CISO's perspective, how can bad conduct in cybersecurity be mitigated?
34:41 - Conclusion

#Cybersecurity #Malware #Microsoft