Welcome to the weekly highlights and analysis of the blueteamsec subreddit (and my wider reading). Not everything makes it in, but the best bits do.
Operationally this week you will see below there is a lot going on. The callout is likely the data from the MSI breach being released. (a PC OEM and motherboard maker). This release of data included Firmware Image Signing Keys for 57 products and Intel BootGuard BPM/KM Keys for 166 products. That is the root of trust gone for devices with those products in (more below).
In the high-level this week:
Rob Joyce (Director of Cyber Security for NSA) features in this podcast (starts at 19:40) discussing co-operation/collaboration with industry via the NSA’s Cyber Collaboration Centre etc. and the epiphanies they’ve had along the way - I also like think the UK’s i100 has inspired a little.
Related - Partnerships Power Cyber Readiness - how the DoD CIO, NSA Director and Defense Information Systems Agency Director collaborate daily - at 7am I may a…

