<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Hugging Face reports that an autonomous AI agent exploited its data processing pipeline via a malicious dataset, gained node-level access β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/ZBNhrTqwazTm80JWtBZSWvbFwGRkaZKvH1w1SY4K61Y=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/mjdXkVjKOxiiDzI2YSVQsvS_48wItMHwQYseMof6cU4=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=1bba0f5e-84db-11f1-9cc8-8985dc4045b9%26pt=campaign%26t=1784639429%26s=35b5fd6e7b4bd2991efdc88cb4847d7d76b059f5415c969892b330f58324ce6e/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/1vT3a6OSG4wt9Q0NvdD1htsu81WDmYhm5qTHGvP-lkE=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-21</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fworlds-largest-ai-model-repository.html%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/zxBuJvegYore7P4ADqbyABFh2MOOAms1aFEbUDTTXJY=452">
<span>
<strong>World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Hugging Face reports that an autonomous AI agent exploited its data processing pipeline via a malicious dataset, gained node-level access, stole cloud and cluster credentials, and moved through internal clusters over a weekend. The company rebuilt compromised nodes, rotated credentials, tightened cluster controls and detection, urged customers to rotate tokens, and used Z.ai's GLM 5.2 locally for forensic work because hosted models blocked analysis containing live attack commands.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FsAz1Hi/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/w_KxFoSntsnzbkOnSPdbqAg6wTtovgcTjMjuaumCBoU=452">
<span>
<strong>Ernst & Young Data Breach Affects Personal, Financial Information (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Hackers accessed a third-party service management platform Ernst & Young uses for client tax work between March 28 and April 12. They downloaded support ticket documents containing names, addresses, Social Security numbers, account numbers, card data, and other tax-related details. EY reports no known misuse so far. It has hired an external incident response firm and is offering two years of credit and identity monitoring and restoration services to affected individuals.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FJcRcno/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/Y_N-M9JGdDswfmt3zUrqRM5616HXxvJVBKMwPdvE6qg=452">
<span>
<strong>EstΓ©e Lauder Discloses Data Breach via Oracle E-Business Flaw (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cosmetics giant EstΓ©e Lauder is notifying impacted individuals of a data breach. The data was stolen by threat actors exploiting a vulnerability in the company's Oracle E-Business suite. The stolen data includes full names, email and postal addresses, dates of birth, SSNs, passport numbers, financial account numbers, health information, and payroll information.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwebflow.sysdig.com%2Fblog%2Fjadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/1Mmyehpk2y91M0dP6b-sQd-6jUPd6z9pzkQNU1XB6hU=452">
<span>
<strong>JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Sysdig's Threat Research Team tracked the agentic operator JADEPUFFER re-entering the same Langflow instance through CVE-2025-3248 (unauthenticated RCE, in CISA KEV since May 2025), then autonomously chaining credential harvest, Docker socket discovery at /var/run/docker[.]sock, and an in-session-built privileged escape container that used nsenter --target 1 to stage ENCFORGE, a compiled Go locker purpose-built to encrypt roughly 180 AI/ML extensions. The agentic signal is the tradecraft itself: when the initial binary fetch failed, the operator iterated six Python scripts over five minutes to build a procfs-based host escape, mirroring the prior campaign's fail-and-correct behavior. Defenders should patch Langflow to 1.3.0 or later, deny or socket-proxy Docker access for the Langflow user, alert on nsenter from containers and on Container/Create requests carrying Privileged plus PidMode host, monitor .locked creation on model-artifact paths, and hold offline immutable snapshots of model weights since encrypted checkpoints, unlike business data, cannot be restored.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.pillar.security%2Fblog%2Fthe-week-of-sandbox-escapes%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/Chtz-ECLOJCU_v6MZoqFwg0agGNM0aP6MWWBfsrTMMI=452">
<span>
<strong>The Week of Sandbox Escapes (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Pillar Research reproduced sandbox escapes across Cursor, Codex CLI, Gemini CLI, and Google Antigravity that share one mechanic: the agent never breaks the sandbox directly - it writes a file that a trusted, unsandboxed host component later runs, loads, or scans, so the real blast radius is everything the host trusts rather than the agent process itself. The chains cluster into four repeatable failure modes: allow-by-default denylist profiles that miss OS features, workspace config that is really executable code, name-based command allowlists that ignore dangerous invocations, and privileged local daemons reachable from the sandbox, plus a Cursor venv-interpreter write executed by the Python extension during discovery. Defenders should treat agentic IDEs as endpoint actors: enforce deny-by-default sandboxing, require explicit approval before an agent writes host-side automation, run helper execution under the same policy as the agent, model command policy at the invocation and side-effect level rather than by name, restrict access to local daemons like the Docker socket, and preserve provenance so user-created, repo-created, and agent-created files stay distinguishable.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwojciechregula.blog%2Fpost%2Fgolden-gate-appdata-protection%2F%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/OlBhxQYmpgC6gUplraXGg2QAd6Jkc0d6Hbb9NravroA=452">
<span>
<strong>Crossing the Golden Gate: macOS's New Application Support Protection (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Wojciech ReguΕa documented an undocumented macOS 27 privacy mechanism that extends the com.apple.macl xattr, which previously bound only sandboxed apps' Container folders to a code identity, to a hardcoded allowlist of non-sandboxed apps' ~/Library/Application Support folders, so a plain Terminal without Full Disk Access gets Operation not permitted on protected paths. The rules live in an embedded sandboxd XML policy mapping bundle ID plus Team ID to protected paths for Discord, Chrome, Brave, Edge, Firefox, and the Ledger Live, Exodus, and Wasabi crypto wallets, enforced by the kernel MACL under the new kTCCServiceSystemPolicyAppDataDetailed service, which blocks writes even to paths of uninstalled apps while excluding NativeMessagingHosts subdirectories so browser extensions keep working. For defenders and red-teamers, the practical takeaway is that credential-theft tradecraft reading browser profiles and wallet data straight from Application Support with only user-level access no longer works against listed apps on macOS 27, the allowlist ships live via XProtect so coverage can expand without an OS update, and everything off the list (password managers like MacPass included) remains fully readable.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.neo.ai%2F%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/wVeW7UO38-dL2C0MWD2dZdI9n9DKu3F18NLJYECFVZU=452">
<span>
<strong>Neo (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Neo provides a control layer for enterprise software that uses models and automated agents in production environments. Its platform inventories agents, models, extensions, and MCP servers, then flags risky permissions and configuration weaknesses for security teams.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fawslabs%2Fferret-scan%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/00fAd-oLXMB11nnOj9ZKWU1fisemTVfp5_WSG-Xb178=452">
<span>
<strong>Ferret Scan (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Find and redact sensitive data before it leaks. A single-binary Go CLI (plus embedded web UI and Go library) that detects PII, secrets, and IP markers in your files and streams β then redacts them in place, format-preserving, with context-aware confidence scoring. No runtime dependencies.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cloudflare.com%2Finternal-dns%2F%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/ToVxEgjjrDCzvpLac1jz8sA5CpmXJy5HdY0fxV4fDzU=452">
<span>
<strong>Cloudflare Internal DNS is now generally available (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cloudflare has made Internal DNS generally available, unifying public and private DNS on a single control plane through two components: a Gateway Resolver that handles recursive resolution and policy evaluation atop 1.1.1.1, and Internal Authoritative DNS serving private zones, with split-horizon handled as DNS Views over shared zones and resolver policies extending Zero Trust to name resolution. Changes propagate through one DNS Records API path (dashboard, Terraform, or direct call) and invalidate cached entries in seconds rather than waiting on TTL, and the feature ships to Enterprise Gateway customers at no additional charge.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fsecurity%2F2026%2F07%2F20%2Fmicrosoft-365-calendars-become-spy-drop-boxes-in-hollowgraph-campaign%2F5274982%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/kZ4lH21ZBygBEcfVnB9b9dQzpBInNzUzCql-eI0A0Js=452">
<span>
<strong>Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
HOLLOWGRAPH hides commands in Microsoft 365 calendar events dated May 13, 2050, stores stolen files in appointments, and refreshes Entra ID credentials through DNS tunneling. Group-IB linked it to the Cavern framework, found 12 infected systems, and traced the command mailbox to an Israeli organization.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Frussian-intelligence-hacks-ip-cameras.html%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/CpG2Y4X1EFS7qFyynXBCuYpOBCXZ5GEtl8ynE-xo9Vk=452">
<span>
<strong>Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A July 10 advisory from the Netherlands' AIVD and MIVD services describes at least one Russian intelligence service systematically hijacking internet-exposed IP cameras across the EU, NATO states, and Ukraine to watch military transport routes and weapons shipments, with camera access in Ukraine used in attempts to target military personnel. The tradecraft needs no zero-day: operators scan for exposed cameras, fingerprint them by brand, walk into ones left on default credentials and obsolete firmware, then run image recognition to find military vehicles and cargo automatically. The strategic point is how ordinary both halves are, since a default login turns a roadside camera into a targeting aid and hands an adversary a live read on physical operations without any deeper network breach.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhackread.com%2Fhidden-risk-enterprise-ai-agents-ungoverned-context%2F%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/2MxpPyaovUignXCaw5zvMzFK5gK6ACRwtWDrjDyc-_E=452">
<span>
<strong>The Hidden Risk in Enterprise AI Agents: Ungoverned Context (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Enterprises are granting AI agents real access to customer records, financial systems, and internal tools, but an agent pointed at sensitive data without governed context becomes a security risk because it acts confidently on unchecked assumptions, surfacing stale metrics, restricted records, or cross-boundary figures a human would never expose. The failure modes are structural rather than model-level: fragmented definitions with no single source of truth, context that carries no notion of who may see what, auto-drafted definitions that ship unreviewed, and human-built systems fed through brittle workarounds that bypass existing controls. For teams deploying agents near sensitive data, the defensible pattern is to treat context as governed infrastructure, auditing where definitions live and who owns them, then enforcing role-based access and SSO so agents inherit permissions, audit trails that trace answers to approved definitions, expert review workflows, and real-time sync to prevent silent staleness.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F07%2F20%2Fhackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies%2F%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/J7w1jIc_n3N7kGHexwM-hY5EFDmkPBo2aKV75HYL_yA=452">
<span>
<strong>Hackers stole 'significant' amount of data from tech firm relied on by thousands of US hospitals and pharmacies (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Craneware said hackers stole a significant volume of customer data from its systems and pushed them out.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.tomshardware.com%2Ftech-industry%2Ftaiwan-inducts-ex-tsmc-manager-for-allegedly-stealing-chip-secrets-for-china%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/GcIDstIx6I0AcwizYQn011r_Rl7ozVro6cf9tIScuZk=452">
<span>
<strong>Taiwan indicts ex-TSMC manager for allegedly stealing chip secrets for China β first case of its kind links managers to Chinese semiconductor materials analysis company (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Taiwan indicted a former TSMC deputy manager for allegedly copying 21 confidential documents to build a Chinese semiconductor materials firm tied to an alleged CCP military-linked recruitment network.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhackread.com%2Ffbi-arrests-florida-man-steam-crypto-theft-case%2F%3Futm_source=tldrinfosec/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/TzABmnc2fmbQy2wy_Cve4hDpVZv9v6al_SL63dOryRU=452">
<span>
<strong>FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The FBI arrested 21-year-old Zyaire Wilkins of North Lauderdale on July 14 for allegedly financing and promoting malware-laced Steam games that infected roughly 8,000 devices.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/IZSSTnYqB2zt_XTbyM6aqspUYeZrlZ4yz9dBxXAWLd0=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/O_LbeeOLDT5Avc5h3gnFHJ4y9PrdyY9CH0H4D76ilG4=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/I7maLGQWGGcaus15rHjaTZilyL-skRCJTBf6t50fV2I=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/g_2miK6ikYZmlGG3F6qeCnQ2NVBhuwTW364yj3IFnhU=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/C4ShRcOdNqCDjuTWfegstxOk2t-O4fOTAEZSvTWfzx8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/CvFZR0bZpK2e1hUMXBh5sWfIlRsJglofiWf8XaOYUb8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/R_xLGwz_QFN41Yqp_iwn1CwHiKpvaH2JGfZmIFHqjNg=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/2TB5PUNUmLhMnfl2wFq_8jfXezv_B_bIk6RVoLn4fgA=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/Mp7QiU-512AAI9astJYL1tjW70xrxAQxwJJSu7f7rCY=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/kLbg14nGxzvLs1qCatlLeA1cK5AjYHWFvidk16A2M04=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=1bba0f5e-84db-11f1-9cc8-8985dc4045b9%26pt=campaign%26pv=4%26spa=1784638823%26t=1784639429%26s=c3cd6025e065e98e83efa0fd57b91ab8b43626304def7bfd4198b7666978e013/1/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/Jm0oa3tufgLQ3ezGI27jAUnSxfdDVW4697fSewxmEWA=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019f84cc9b10-2304d5cb-3d9c-4542-9caa-11d33b1d7e0f-000000/9XEiRswNqznFb7-r1edN94h-Zq3bmeCcovYsbLTURao=452" style="display: none; width: 1px; height: 1px;">
</body></html>