<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">The popular 7-Zip Windows archive tool released an update to fix a heap-based buffer overflow vulnerability that could be exploited by attackers β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/1lnFnT5A8rxhWrf09vyM-3_cEcXkdoXBAafHjXwFTQ4=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/P9KWGrCoabuhnl_TZQTiiIP8-5EEGxS1WXzbfNa32i0=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=e7423c10-85a7-11f1-9940-2d167be82918%26pt=campaign%26t=1784725754%26s=a4b4dbbdae274db4a1fbf295563ebebea0e174144feefefc83a55eb8b72f08ea/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/XvSoneuIcxgthBR-qT1KA39tSAAVZjDreS4y0shtJFY=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_source=TLDR%26utm_medium=Sponsored_Content%26utm_campaign=EDU_Masters%26utm_content=7.22.26_primary_header_you_cybersecurity_masters%26utm_goal=Leads%26utm_rdetail=NA%26utm_type=College/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/oIsJHcLH4RQfOGaIE7GoWz5UVQyrSLkREcmpDkfG7n8=452"><img src="https://images.tldr.tech/sans2.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="SANS Institute"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-22</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_source=TLDR%26utm_medium=Sponsored_Content%26utm_campaign=EDU_Masters%26utm_content=7.22.26_primary_header_you_cybersecurity_masters%26utm_goal=Leads%26utm_rdetail=NA%26utm_type=College/2/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/Dq-Df6iyrEvI-4_WMBAq3jGPG3fEqRtxMIeRtyXY3SU=452">
<span>
<strong>Would you get a Cybersecurity Master's Degree if your boss paid for it? (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Many organizations offer tuition assistance benefits that employees never fully use. Is yours one of them? <p></p><p>The SANS Technology Institute's <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_source=TLDR%26utm_medium=Sponsored_Content%26utm_campaign=EDU_Masters%26utm_content=7.22.26_primary_body_intro_master_science_information_security%26utm_goal=Leads%26utm_rdetail=NA%26utm_type=College/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/Qw7Wdk-nMqa-OmXuIlowm77N3-3DohKq0dbCeygDdFI=452" rel="noopener noreferrer nofollow" target="_blank"><span>Master of Science in Information Security Engineering (MSISE)</span></a> helps working professionals build advanced technical skills while earning 9 GIAC certifications respected across the cybersecurity industry. </p>
<p>β Eligible for most <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_source=TLDR%26utm_medium=Sponsored_Content%26utm_campaign=EDU_Masters%26utm_content=7.22.26_primary_body_outro_employer_tuition_benefit_programs%26utm_goal=Leads%26utm_rdetail=NA%26utm_type=College/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/KmzPAF54rWmv0319KlyLb9BGWBSIORRIzptsX5IVzf0=452" rel="noopener noreferrer nofollow" target="_blank"><span>employer tuition benefit programs</span></a> </p>
<p>β Online and designed for working professionals </p>
<p>β Developed and taught by top cybersecurity practitioners, not career academics</p>
<p>β‘οΈ<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_source=TLDR%26utm_medium=Sponsored_Content%26utm_campaign=EDU_Masters%26utm_content=7.22.26_primary_cta_session%26utm_goal=Leads%26utm_rdetail=NA%26utm_type=College/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/rkMBdMz9Z1hwcuvUhhITIw93OfE73WaZJbCbTepyyrc=452" rel="noopener noreferrer nofollow" target="_blank"><span> Join a free info session</span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FdqdTlm/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/nBE46KS1scGuDH_8IAAImH1jYXqeIEDC0tD5SyZNyQc=452">
<span>
<strong>7-Zip Fixes RCE Flaw Exploitable With Malicious Archives (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The popular 7-Zip Windows archive tool released an update to fix a heap-based buffer overflow vulnerability that could be exploited by attackers to achieve arbitrary code execution. The vulnerability exists in 7-Zip's processing of XZ-compressed data. 7-Zip does not have automatic update functionality, so users will need to manually download the new version to update.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F70ZeiQ/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/TZVqdRI9ANELLCromgcdSKuYiP4py9_9fmKsrZegxBQ=452">
<span>
<strong>Critical ServiceNow Code Execution Flaw Now Exploited in Attacks (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Threat Intelligence platform Defused reported that they have observed a recently disclosed vulnerability in the ServiceNow AI Platform being actively exploited. The vulnerability could allow unauthenticated attackers to escape the sandbox and execute code remotely within the ServiceNow platform. ServiceNow has denied that the vulnerability is being actively exploited.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F07%2F21%2Fai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned%2F%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/DRBdHNu0jdujiu6OCQNPIXPKsojcHSDh9hL7kP2TYXo=452">
<span>
<strong>AI music generator Suno breach affects 55M users, per Have I Been Pwned (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A hacker stole data on about 55.3 million Suno users, including names, postal and email addresses, phone numbers, purchase records, and partial card numbers from Stripe with expiry dates. The breach also exposed Suno source code showing largeβscale scraping of music and lyrics from major platforms and occurred in November 2025. Suno has yet to notify affected users or clearly disclose the incident.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fworkos.com%2Fblog%2Foauth-mix-up-attacks-rfc-9207%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/XWrbFhXpm6Li97U4AQlV34GkQbGLOf-7m80TJRY5o0g=452">
<span>
<strong>OAuth mix-up attacks and RFC 9207: The issuer check that never made it to token exchange (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
WorkOS traces the OAuth mix-up attack (a client talking to multiple authorization servers gets confused about which server sent a response and routes a code or token to the wrong one) and how RFC 9207's 2022 fix, an iss parameter the client must compare against the expected issuer and reject when absent, only covers redirect flows and never extended to back-channel grants. That gap is what CVE-2026-59208 exploited in n8n's token exchange: the endpoint confirmed a subject_token's signature matched a trusted key but never confirmed the key belonged to the issuer named in the token's iss claim, so a token from one tenant resolved to a same-named account in another because signature validation and account-namespace scoping were treated as separate questions. Defenders should enforce RFC 9207 client-side (reject a missing iss when the server supports it), partition trusted signing keys per issuer rather than pooling them flat across RFC 8693/7523/7522 grants, and scope sub account lookups to the confirmed issuer's namespace, the single check that would have stopped the CVE, treating this as first-class in MCP and agent architectures where multi-issuer topologies are becoming default.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.elastic.co%2Fsecurity-labs%2Fcontagious-interview-malware-svg-steganography%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/_YN7H5l499cJLaELMn104BW6B6qLkHKi7LEeOFNIA_Y=452">
<span>
<strong>New North Korean campaign uses fake coding interviews to steal developer credentials (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Elastic Security Labs tracked a Contagious Interview campaign (REF9403) in which DPRK-aligned actors posted fake job offers in developer Slack channels, moved targets to DMs, and delivered trojanized e-commerce "coding challenge" repos that reassembled Base64 payload chunks hidden in SVG flag images via steganography, then executed them with eval() on every server start. The four-stage OTTERCOOKIE-aligned payload combined a browser credential and crypto wallet stealer, a recursive file stealer, a Socket.IO RAT, and a clipboard stealer, exfiltrating to rightwidth[.]dev subdomains and IPs 195.26.248[.]212 and 188.40.64[.]61, with zero AV detections at the time of writing. Defenders should treat unsolicited take-home coding tests as hostile, run them only in isolated VMs, hunt for node.exe spawning cmd.exe/powershell.exe with Get-Clipboard, and block the listed C2 domains. MITRE techniques include T1027.003 (Steganography), Clipboard Data, and Credentials from Password Stores.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fslcyber.io%2Fresearch-center%2Fexploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6%2F%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/-kVu1B90_bhxvZhrPyPL70_DggJepSQGlwwBhpeOBxA=452">
<span>
<strong>Exploit Brokers Pay $500,000 For A Wordpress Rce. I Found One With Gpt5.6 Sol Ultra And $25 (18 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A researcher used GPT5.6 Sol Ultra to find a pre-auth SQL injection in WordPress's batch API, abusing a validation desync and an unsafe author filter to gain database access. By chaining cache poisoning, embed handling, and customize_changeset posts, the attack escalates from SQLi to temporary admin privileges. It then abuses WordPress hooks, especially parse_request, to replay the batch request as admin and create a new administrator account, enabling plugin-based RCE on default WordPress installs.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_medium=Sponsored_Content%26utm_source=TLDR%26utm_content=7.22.26_secondary%26utm_campaign=EDU_Masters%26utm_rdetail=NA%26utm_goal=Leads%26utm_type=College/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/37s5zTKy_RFY8sfZhTBT4bSPz5mAaudjbtU_q2k7Sns=452">
<span>
<strong>Your shortcut from technical expert to cyber leader (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
97% of SANS Technology Institute's master's alumni agree the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_medium=Sponsored_Content%26utm_source=TLDR%26utm_content=7.22.26_secondary%26utm_campaign=EDU_Masters%26utm_rdetail=NA%26utm_goal=Leads%26utm_type=College/2/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/mvViaj-Lc8ousLCC-LctQD8wNDN6u7SOmARzfRmRSKM=452" rel="noopener noreferrer nofollow" target="_blank"><span>MSISE program</span></a> prepared them for cybersecurity leadership roles. Earn 9 GIAC certifications, build your foundation of expertise, and gain the technical & organizational skills you need for higher-impact cybersecurity positions. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sans.edu%2Fmasters-degree%3Futm_medium=Sponsored_Content%26utm_source=TLDR%26utm_content=7.22.26_secondary%26utm_campaign=EDU_Masters%26utm_rdetail=NA%26utm_goal=Leads%26utm_type=College/3/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/H0lKNVYmLWTQCiC_hX6wRAMeh6B7n0dqh2Dn6h8zca4=452" rel="noopener noreferrer nofollow" target="_blank"><span><strong>Next application deadlines: August 1 and November 1</strong></span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Finstavm%2Ftarit%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/-WD_wDwCI-cYE1MPdBvHZ102GfcSA52rYYN-0TxdV7g=452">
<span>
<strong>Tarit (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Tarit is a Rust/rust-vmm-based microVM platform that boots hardware-virtualized, kernel-isolated sandboxes in milliseconds for AI agent and RL workloads, pairing a minimal one-process-per-VM hypervisor with a multi-node orchestrator offering warm pools, live snapshots, suspend/restore, per-VM egress allowlisting, and PTY access.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fmicrosoft%2FEventLogExpert%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/X1cd-UPKA_v84DMScYbLV5_QYKw02410DNbuNLz7m60=452">
<span>
<strong>EventLogExpert (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
EventLogExpert is a Windows Event Log viewer built by Microsoft that provides a Wireshark-like interface for viewing evtx files.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fpenberg%2Fchimera%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/b0A0SDBQs__-oMHx27QdZPswFfQrDTivo-nLXs8219o=452">
<span>
<strong>Chimera (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Chimera is a userspace sandbox for running untrusted code that doesn't require a VM, container, or kernel features.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.aikido.dev%2Fblog%2Fbenchmarking-ai-models-known-cves%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/ifTOuY2xtX0NJ-z5SP1FxjSCaaVnqFeuRm1szbYbfNU=452">
<span>
<strong>Benchmarking 13 AI models on rediscovering known CVEs (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Aikido ran 13 models from OpenAI, Anthropic, xAI, Google, and open-weight vendors against 26 known GitHub-advisory CVEs inside its production AI Code Analysis harness (pass@3, model pointed at the vulnerable snippet), and found that GPT-5.6 topped recall at 23/26 (88.5%) with Kimi K3 tying it, grok-4.5 at 20, and the Claude Opus models at 15 to 18. The operationally useful finding is variance: single runs miss bugs other runs catch, so pooling three passes of a cheap model beats one pass of a flagship, with three gpt-5.4-nano runs reaching 18/26 for roughly $170 against a flagship single pass, and claude-haiku-4-5 swinging from 7 to 13 on the same task. The capability ceiling is reasoning, not sinks: every model found both critical bugs and obvious injection/deserialization flaws, but only GPT-5.5 and the strongest GPT-5.6 variants traced an indirect SQL injection through an unescaped ORM column alias, so defenders should pool multiple cheaper runs and treat the harness, not raw model tier, as the variable that aims reasoning at the right code.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Farstechnica.com%2Fgoogle%2F2026%2F07%2Fgoogle-reveals-faster-and-cheaper-gemini-3-6-flash-says-3-5-pro-is-still-in-testing%2F%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/XRd3CIluzMWcIAZevfG1UC2bvsfvnU_a61tDT7GgAKk=452">
<span>
<strong>Google announces Gemini 3.6 Flash and cybersecurity AI, teases 3.5 Pro and Gemini 4 (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Google is replacing Gemini 3.5 Flash with 3.6 Flash, which improves DeepSWE coding scores, adds builtβin computer use, cuts token use by about 17 percent, and lowers output token pricing. Gemini 3.5 Flash Lite powers faster search and app responses, while the new 3.5 Flash Cyber model runs inside DeepMind's CodeMender agent for vetted partners and governments to find and fix vulnerabilities, staying out of broad public release.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fsecurity%2F2026%2F07%2F21%2Fgerman-authorities-lead-takedown-of-kratos-phishing-platform%2F5275666%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/CXVsdqgVipL0VY97x2_p5edUDAybM5ePxk3_PLuXGFQ=452">
<span>
<strong>Kratos phishing-as-a-service kit loses its battle with international law enforcement (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
German and US-backed investigators shut down more than 200 servers tied to the Kratos phishing kit and arrested its alleged developer in Indonesia. Kratos helped low-skill attackers steal Microsoft 365 credentials and bypass MFA, enabling large campaigns across the US and Europe.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.thestar.com.my%2Ftech%2Ftech-news%2F2026%2F07%2F20%2Fiphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/enzKea5u2llTpyTpsS-FyAQ7WCjlKBO4gaJnd8cjPXE=452">
<span>
<strong>iPhone hacking firm sues ex-worker over alleged theft of secrets (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Magnet Forensics sued former iOS exploit engineer Mario Del Gaudio and rival Paradigm Shift Technology in Georgia federal court, alleging Del Gaudio helped disclose a zero-day in Apple's A12 and A13 chips (which Magnet sold to government customers to unlock iPhones) on Paradigm's blog, destroying its value by alerting Apple to a potential fix.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FSPpXE0/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/HMWDz5RktuWzkvUwhMsnIhhMRQegwg_EVTcHwZ72JAA=452">
<span>
<strong>Clover Health Investments Discloses Data Breach (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Hackers used social engineering to take over three nonβmanagerial Clover Health employee accounts tied to visit scheduling and brokerβfacing sales functions, giving them access to personally identifiable and protected health information, but not financial or claims systems.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.techradar.com%2Fpro%2Fsecurity%2Festee-lauder-says-it-was-hit-by-data-breach-caused-by-oracle-e-business-issue%3Futm_source=tldrinfosec/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/P2j6XYydcUOXA1ac9XJygwNB4CERWWb6Mohto7hTh0M=452">
<span>
<strong>EstΓ©e Lauder says it was hit by data breach caused by Oracle E-Business issue (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
EstΓ©e Lauder identified that an attacker accessed its Oracle EβBusiness Suite HR system around August 2025.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/PCU5aPtSwdzb56e_z-ajCRDgU7bEwn19WkOetcSgP9o=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/yW_iScjc8axGfM83ks0EODWOv2AFUc9n45XHoNIX26Y=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/S8Lepury-L_760_ZB61Z9vTPxQglLDb79GWqMPWS0KE=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/Gsi19MMUDD_rY-qqY47K45qVlHIHfXLVUQCGa9vO_Cs=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/alAbIAj9HmKx9TB5hVtqwJ9xMkCDN2yOSmZ3MTeXLy4=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/LpoPK_wEK30EIYDkcNo0GMiDIeMidwCw35Mq59OgILE=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/iDCoY_v-qRkYNS-ce_-Jgakz1h8-qglb9nwoy2RQT2I=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/yYp43O14flOAY1AJMfGYMHKUZrTqz7eahwxt9cs6GcU=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/gzWD2UTpm0_2WAF7uypWQessIx6egsTBMbEgqRX6y6s=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/Rj4Gybv2BrL9PYVJPz3FTKxozhNe9icX2-Upbq4Mcio=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=e7423c10-85a7-11f1-9940-2d167be82918%26pt=campaign%26pv=4%26spa=1784725308%26t=1784725754%26s=becca97e723532c868be7265039bde001dda2aede91faa3413c5f0b464875179/1/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/PKgnp7Yj6zeUUPR2bo91zaI5RwZWTHtLlEXCEu6i84E=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019f89f1d0c2-8e080cec-b471-4fba-ab86-903febcbc0a1-000000/1nIwKYLENTuPJz3TMWDXk5i2T3BFnoLQMqzs70mXA1s=452" style="display: none; width: 1px; height: 1px;">
</body></html>