<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Searchlight Cyber disclosed a pre-authentication RCE in WordPress Core exploitable by an anonymous attacker on a stock install with no plugins β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/ER85QY0Ql5aCad8Hme7ZlqjHgwtsjZtReTNLICHijP4=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/UWOxYAeLP8iaWIN-DCc856cBX3_xP0L-CiZVX-9_F70=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=84e8c218-842c-11f1-8f53-ebf2d3968bb2%26pt=campaign%26t=1784552967%26s=0fe16e62171c22b0f958e2138ce880c11c625f78a366cab97882c8e2c116c3c1/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/ewnjqqWrdtCw3B7QSjRF28Pc5OZhFPMlohvBNgCHhLA=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-20</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fslcyber.io%2Fresearch-center%2Fwp2shell-pre-authentication-rce-in-wordpress-core%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/ll8iveAYFgBA28_i4s5giLUWbC92yv_TzenkesJP4aA=452">
<span>
<strong>WP2Shell: Pre-Authentication RCE in WordPress Core (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Searchlight Cyber disclosed a pre-authentication RCE in WordPress Core exploitable by an anonymous attacker on a stock install with no plugins, affecting roughly 500 million sites on versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The researchers withheld technical details to give defenders time to patch, but released wp2shell[.]com as a public checker tool. Admins should update to WordPress 7.0.2 (or 6.9.5 on the 6.9 branch) immediately, or as a temporary measure, block anonymous access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF level.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fopenssl-hollowbyte-flaw-could-freeze.html%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/VGKjYkUIgmSlY95L3hjso40oNrP8q4fLSzWDMQQ6v-E=452">
<span>
<strong>OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
HollowByte allows an attacker to send tiny TLS handshakes that cause OpenSSL to allocate up to 131 KB per connection, leaving that memory stranded on glibc systems until a restart. OpenSSL silently fixed it on June 9 across multiple branches without a CVE, so scanners miss it, and downstream backports are hard to track. Okta reported NGINX servers losing hundreds of megabytes to fragmented heaps.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FIzf0sm/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/W4E0g9-8mOwB0z_9-nni_04qDVRb5gDhIoCoahRg6QU=452">
<span>
<strong>Abbott probes two cyber incidents amid extortion claims (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Abbott confirmed unauthorized access to legacy Exact Sciences systems after ShinyHunters listed the Cancer Diagnostics unit on its leak site, with the group claiming a vishing attack compromised a Microsoft Entra SSO account in mid-June and led to theft of over 30 million rows of customer PII, including a million-plus Social Security numbers, plus tens of millions of medical records and client notes. A separate threat actor, ShadowByt3$, claimed to have breached Abbott's LabCentral customer portal on July 4 using stolen credentials and exfiltrated business documents, though Abbott disputed that any of the data in that environment was sensitive. Neither actor has publicly released stolen data, and Abbott says it has activated incident response, engaged outside cybersecurity experts, and notified law enforcement in both cases.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fneurowinter.com%2Fsecurity%2F2026%2F07%2F16%2Fforging-the-government-lottery%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/ISPy4NerqkWX_azBb6hkDbLYOaWbChCYlJ8rKoN7PKQ=452">
<span>
<strong>Forging the government's lottery: China's civic apps run on a shared reward backend with no real secret (22 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Chinese local government and stateβmedia apps rely on shared βinteractive marketingβ SaaS platforms where tenants are separated mainly by a client_id, but the signing scheme meant to protect reward campaigns uses a public salt and an HMAC key served openly via an init endpoint, making points, quizzes, and lottery draws forgeable at scale. Farmers automate civic app actions such as article reading, quizzes, and sweepstakes using plaintext scripts, solve CAPTCHAs with ddddocr, and cash out rewards to Alipay, while some scripts target Beijing municipal socialβservices quizzes and answer them automatically with Xunfei Spark, creating fake engagement and lottery entries tied to citizen accounts.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.bitdefender.com%2Fen-us%2Fblog%2Fbusinessinsights%2Fbind-link-abuses-windows-feature-edr-evasion-technique%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/sp_bu6_2B5roJvxQWt3P0K9SqHUwl-Fshf1bTD-iLbU=452">
<span>
<strong>Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (20 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Bitdefender Labs documented three escalating post-compromise techniques abusing the bindflt.sys minifilter driver: File-Binding hijacks trusted DLL and artifact paths (defeating AMSI, EDR sensors, and forensic tools), Process-Binding redirects a trusted executable to a different backing image, and Silo-Binding scopes bind links to a Windows container silo so malicious code runs inside while AppLocker, Windows Firewall, and Sysmon see a clean file outside it, letting Invoke-Mimikatz run undetected in testing. The chain requires local administrator access, mirrors BYOVD in threat model, and maps to MITRE ATT&CK T1562.001, T1574.001/002, T1036.005, T1055-adjacent behavior, T1070.001, and T1003.002, plus a novel Docker Desktop docker-users-to-SYSTEM escalation path. Defenders should stop trusting image paths from process-creation callbacks, resolve the real backing file via IoGetShadowFileInformation or PsReferenceProcessFilePointer, re-resolve identity on every delayed re-open, enumerate active bind-link mappings, and confirm with their EDR/AV vendor whether bind-link resolution is validated rather than relying solely on Windows 24H2's partial veto protection.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Facademy.bluraven.io%2Fblog%2Fdetecting-cobalt-strike-https-beacons-with-simple-method%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/uetrSKZ5qEnrLOWrn05JKDeSPnJAifLOJm2iTUIAqX4=452">
<span>
<strong>Detecting Cobalt Strike HTTP(S) Beacons with a Simple Method (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cobalt Strike's malleable C2 profiles let operators define multiple URIs for http-get and http-post blocks, but each beacon actually communicates using only one static GET URI and one static POST URI, which can even be identical. This fixed selection creates a detection chokepoint: defenders hunting through web proxy logs for internal hosts talking to low-prevalence domains or IPs that use only one or two unique URIs can surface potential Cobalt Strike beacon traffic. The piece is light on hardening specifics, so treat this as a starting heuristic for hunting rather than a full detection rule, and pair it with tuning to reduce false positives against legitimate low-traffic services.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FzYfPsx%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/6Lml3BXXYH2Djdu18vbNUTDjhbvqflzO2jQO7LXQTnI=452">
<span>
<strong>Are pentests obsolete in the AI era? (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
You can now get the depth of a pentest at the frequency of a scan. Does that mean pentests are dead? This <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FzYfPsx/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/Yiz7fZKWgI83kMoTxFgbySPXZH7YpcAmzmCBPVGbgbs=452" rel="noopener noreferrer nofollow" target="_blank"><span>Intruder blog</span></a> lays out the short-term, mid-term, and long-term implications of AI-driven pentesting. See what the economics, frontier AI developments, and threat landscape are all pointing to. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FzYfPsx/2/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/16S1SszBNVKSNK81T7MYbKYWgFIm9oCXt-UDk3bY-mg=452" rel="noopener noreferrer nofollow" target="_blank"><span>Read the blog</span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FamElnagdy%2Fguard-skills%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/fyW1c3B4RZx79gsmts2Al__2AOPLP100s79pzOmBtcs=452">
<span>
<strong>guard-skills (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
guard-skills packages five focused guard skills - clean-code-guard, test-guard, docs-guard, wp-guard, and woo-guard - that run as second-pass review gates on AI-generated code, tests, and docs rather than as upfront coding assistants.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FCorgea%2FSighthound%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/Lm7xNhG2zx59QthOc867T3tJmtfI6LBCQr6W8B9ExLg=452">
<span>
<strong>Sighthound (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A fast open-source source-code vulnerability scanner built in Rust. Tree-sitter parsing and RON rules β command injection, SQL injection, XSS, and more with every rule included.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fbeacon.security%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/m7ZBfyvoUjx4da2-5OqN_Vj2b48LbOI6LMdQUuqiVFc=452">
<span>
<strong>Beacon Security (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Beacon Security provides a security data platform that merges telemetry from multiple sources into a single context layer for defenders. It supports automated and human-led threat detection, investigations, and response workflows, including detecting attacks on AI systems and emerging cyber techniques.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fai-and-ml%2F2026%2F07%2F16%2Fresearcher-poisons-open-weight-ai-model-for-under-100%2F5273880%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/8blSS33L91yF-qosRHvI4q1nNRDHw_FVXfSQgSGRlT8=452">
<span>
<strong>Researcher poisons open-weight AI model for under $100 (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Katie Paxton-Fear shows how cheaply and quickly an open-weight coding model can be fine-tuned into a backdoored system that emits remote-code-execution bugs on demand, with only ten training examples. Another test model quietly exfiltrates data via a send_email tool when used in drug discovery workflows, turning model weights into a persistent insider with almost no observability or effective verification.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdaniel.haxx.se%2Fblog%2F2026%2F05%2F26%2Fthe-pressure%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/_0caW83-oN1RMvpv2mLjokSCf_4JmaLAcI0X9eNI8j4=452">
<span>
<strong>The Pressure (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The curl project has been swarmed by a deluge of LLM-generated bug reports in recent years, with 2026 showing a 4x increase in submissions over 2024 and double the number of submissions as 2025. While finding more bugs is good, it negatively impacted the team's work-life balance and mental health. The curl project will weather this storm. Few of the companies that rely on the project contribute to it.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Fwyf0Ks/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/BDzkyWUlO4P-lNkIUqTB3CJRzF3dGf-GyTT5wTqMZRM=452">
<span>
<strong>Files Related to India's Largest Power Plant Exposed in Data Breach (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The World Leaks Ransomware group has claimed a hack that included files from the Kundankulam nuclear power plant. One of the plant's contractors states that there was a partial data breach via a third-party cloud services provider. The files do not include data on the nuclear plant's core systems, but they do contain blueprints, information on cooling systems, and insurance documents.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F07%2F16%2Fcoca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/NZ2arClGKExTmqGNyonad9W2M2EC3upMqmUuX8Vs_qQ=452">
<span>
<strong>Coca-Cola suspended production at its Fairlife dairy after a ransomware attack (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Coca-Cola has reported a ransomware attack on its Fairlife dairy unit that hit production systems and forced a temporary shutdown of US operations.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcryptoslate.com%2Fmetamask-code-was-open-to-a-north-korea-linked-contractor-for-a-month-before-consensys-halted-releases%2F%3Futm_source=tldrinfosec/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/YHtWIR6xPpTbAlLHiXEr1XZ3SwP-Ra2FI-0CYpEiQGc=452">
<span>
<strong>MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A third-party contractor later linked to North Korea contributed to MetaMask code from March 9 until Consensys terminated access and paused releases in April.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/5kteOtfIX3bX60Ch3vFwuHZsCddhqc05Sd8CQsWi8t0=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/M0IJ59sf3Tn-BJBtx_w7AHO3vlLK6AduP3Jc1Ul_wDM=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/H6wNJV1ezg55kW-c_Fbkv2GUKVr1tsq4sAdEl13Q81g=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/tTeuYlzT6iUZlyX3rXq570IzXt4RQKv5ypAOSokOmq8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/kexqqrZoVT-e1SyYV4myty_EC-Hu2kmf0TBndRJ_Qtk=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/Em9F8PIKwWsLP_zlklLeiBb3SpSCI1oxp5uTPX5CZ8w=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/e-gif9atsCC1sAMrytryyB1NbJqt3x4XTbTmgytWhhE=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/w_0JWhA6MYqmosgbAaTybtU10va1O_EvO36xMqgZZAQ=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/BhQesIpGUc6a_hS5EyLtLohYO4fqoWj2WQqE1p9Ya2I=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/5kX2EzzWPA_OEGngHAz7CoJj9cE5uBH5-m-ryPS9UDY=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=84e8c218-842c-11f1-8f53-ebf2d3968bb2%26pt=campaign%26pv=4%26spa=1784552511%26t=1784552967%26s=940a0b8c0a9581be1132deaecc5a520220c0c40fb959a632704cb1206d8c6e36/1/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/mb2BGoqHkT8w9s2cBWg4Uye_6h4dggQYtZDSCxoqMss=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019f7fa54d3d-9fca4e0e-7e5d-4770-9184-69e56bc7250b-000000/OeFRRcGi7gWR7tMyWV4cMne1KnRkOUz9U83e_-yaxsc=452" style="display: none; width: 1px; height: 1px;">
</body></html>