<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Researchers at Accomplish AI found that Claude Coworkβs macOS app shares the host filesystem readβwrite into a Linux VM, letting an agent exploit β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/2tQAscBXM-vjRWn3khpXQM7br2NDdb2BUjGrPaE5YB8=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/nY4V07w22YXcs-MRCEixCknnaNRm5ch7aDW4NKbN8ZQ=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=040e4ef4-8758-11f1-8c76-e7ba84788eba%26pt=campaign%26t=1784898469%26s=ab49a10349932a84a5f53716037a54829551bce95657c8bea6ca06fbbc1062d7/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/W82WNg-uPaBoj--PVe2e3xzThDhDsJ7wMojzlhyt5aA=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-24</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fclaude-cowork-flaw-could-let-ai-agent.html%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/0T-In344pUb-4eH8MO1QIy9dQlYhGydyxanUYvXc9MY=452">
<span>
<strong>Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers at Accomplish AI found that Claude Cowork's macOS app shares the host filesystem readβwrite into a Linux VM, letting an agent exploit CVEβ2026β46331 to gain guestβroot and read or write files across the Mac, including SSH keys and cloud credentials. Anthropic now defaults Cowork to cloud execution, but local sessions remain exposed unless user namespaces are restricted, seccomp tightened, autoloaded modules limited, and host sharing scoped or made readβonly.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FZQp5zn/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/0klFVt_Umgs9uEGnX3OVu653_KW1h7dNFk1GjK07Z6c=452">
<span>
<strong>Chick-fil-A discloses data breach after credential stuffing attacks (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Attackers used stolen credentials in automated login attempts against Chick-fil-A's site and app between June 17 and 19, breaching Chick-fil-A One accounts in multiple US states. Exposed data includes names, contact details, membership and payment info, and partial card numbers. Chick-fil-A has reset logins, removed payment methods, restored account balances, and advised password change.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FuNXt9w/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/KLi_thdNDI-pfVKT2kYEZM5lsiW1tBB5AskBLhRvqwI=452">
<span>
<strong>Hackers Abuse Notepad++ Plugins to Stealthily Install Malware (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Ukraine's CERT uncovered a new campaign that uses a legitimate Notepad++ distribution to spread malware via a malicious plugin. The plugin extracts a password-protected RAR file, which eventually loads a C2 client. The researchers linked the attack to a vulnerability in Notepad++ version 8.8.3, but the developers refute this claim and state that plugin loading is standard functionality.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fscamdrill.com%2Fblog%2Fm365-oauth-device-code-phishing%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/OSXhYKWrWJ8y-EbGP6TQ8Nn_JaCEe6s-0jgpLGAXsbo=452">
<span>
<strong>Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA (11 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Device code phishing abuses Microsoft's legitimate device-code login flow for TVs and printers by tricking users into entering attacker-generated codes on the real Microsoft sign-in page, handing over valid access and refresh tokens without stealing passwords or breaking MFA. Recent campaigns, including Kali365 and EvilTokens, sell ready-made kits with AI-written lures, role-tuned emails, and automated token capture, hitting hundreds of Microsoft 365 tenants worldwide and driving large-scale business email compromise focused on finance and payment redirection. Defenders can cut risk by blocking device-code flow in Entra Conditional Access, tightening device registration, shifting to phishing-resistant MFA, and monitoring risky sign-ins, new device registrations, and stealthy inbox rules, while pushing a simple user rule: any unsolicited login code is an attack.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.dtex.ai%2Fblog%2Fdprk-it-worker-money-trail%2F%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/szEZ1Vb-LwjmM3Ek63jXR6s5_IjLt4it5EU8kq1Tz-M=452">
<span>
<strong>From Payroll to Pyongyang: The DPRK IT Worker Money Trail (13 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
DPRK IT workers embedded in global hiring pipelines confirm completed payments through an internal Discord-style remittance platform, luckyguys[.]site (also linked to luckyguys[.]cloud and rbluckyguys[.]com), routing funds from individual operators through team-collector accounts up to Unit 1020 under Command 710, with DTEX assessing "RB wallet" references as the OFAC-sanctioned Ryongbong General Corporation alongside front companies Sobaeksu, Saenal, and Songkwang. Leaked chats and infrastructure pivots on the payment server show funds pooled through Chinese financial channels and crypto-to-fiat conversion before consolidating upward to fund DPRK weapons programs, with multilateral reporting tying the same revenue stream to North Korea's military support for Russia's war in Ukraine. Defenders vetting remote contractors should treat DPRK IT worker fraud as a full-spectrum cyber-financial threat rather than an HR screening issue, correlating freelance-platform activity against the disclosed infrastructure and the identity-broker ecosystem that increasingly obscures direct DPRK attribution.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fzerotracelab.com%2Fblog%2Fgdid-windows-tracking%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/d2SA4Cp1_V8z8YBGs1Zg6Rtq0HTAHn5PJF__-wOi7oo=452">
<span>
<strong>GDID: The Windows Global Device Identifier (14 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Every Windows install since Vista registers a 64-bit Passport Unique ID with login.live.com on first internet connection, storing it as plaintext hex in HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties\LID while Microsoft's servers bind that identifier to hardware descriptors and a TPM-backed device certificate that surfaces on every Store, activation, WNS, and telemetry call. Researchers at ZeroTrace Lab tested four escalating attempts to spoof a different device identity onto a VM and found the local registry value and DPAPI-wrapped certificate are both replaceable, but the TPM Endorsement Key's private half never leaves the physical chip, making full impersonation require an unsolved TPM-challenge relay. The real-world stakes were underscored by the US v. Peter Stokes complaint, where prosecutors linked a defendant to an ngrok account using only this identifier. Investigators can pull the value locally via reg query "HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties" or a three-line PowerShell conversion of the LID to decimal PUID, and should treat the number as non-rotatable for forensic linkage purposes since deleting it, reinstalling Windows, or firewalling login.live.com only issues a fresh ID that Microsoft's server re-links to the same underlying hardware.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemperis.swoogo.com%2Fhipconf26%2F%3Futm_medium=pd%26utm_source=tldr%26utm_campaign=hip-nashville-reg/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/_5yooB1rbCgoS6S1V_jHqr9lYRiQSC2UuSjDQC34ZoM=452">
<span>
<strong>You can't solve identity security in isolation. Tap into the HIP Community. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cyber defenders: When identity is under pressure, you need more than theory. Come to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.hipconf.com%2Fwhy-attend%2F%3Futm_medium=pd%26utm_source=tldr/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/MZ1zFJu-iVTRLOVXe9gRG23i2-f9BgNlCUwa7CX9it0=452" rel="nofollow noreferrer noopener" target="_blank"><span>The Hybrid Identity Protection Conference</span></a> for knowledge and expertise. Leave with clarity, confidenceβand connections you can trust, with people who understand the stakes. At HIP Conf, we're stronger together. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemperis.swoogo.com%2Fhipconf26%2F%3Futm_medium=pd%26utm_source=tldr%26utm_campaign=hip-nashville-reg/2/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/feKuukIq2EcsXnAQJGYAn9EQNZcyS0iy-NxUsRD4rTM=452" rel="noopener noreferrer nofollow" target="_blank"><span>Register for September 8-10 in Nashville, now</span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.glow.io%2F%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/qxRoIzqRGFDtU7CfEdsMj9ihd5gNOdp7SMEsNpRloy0=452">
<span>
<strong>Glow (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Glow provides endpoint security software that controls what runs on employee devices, using real-time environment mapping, risk analysis, and automated policy enforcement to reduce attack surface and support safe use of advanced tools in large enterprises.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fgoogle%2Fmantis%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/dwHs3ncbsbxaskJrBYVgbO8fJ17K6gZe7CMOWTbyyXU=452">
<span>
<strong>Mantis Skills: Portable Toolkit for Building Security Review Harnesses (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Mantis is a decoupled, sequential set of security-review skills for coding agents like Gemini CLI and Antigravity that runs a full pipeline from threat modeling and vulnerability sweeps through deduplication, sandboxed crash-reproducer generation, patching, and risk calibration into a human-readable report.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fmomenbasel%2Fmalware-check%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/Elvoa01An5UAozlrrA-0vVfe4gf2nFgPWNqJbzamHO8=452">
<span>
<strong>malware-check (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Farstechnica.com%2Fai%2F2026%2F07%2Fai-arms-race-in-line-for-a-reckoning-after-openai-hacking-incident%2F%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/PRWXtnCQvsCs3hCZ0ytLXiw4xdXNcfHrsiuoF-HJoY4=452">
<span>
<strong>AI arms race in line for a reckoning after OpenAI hacking incident (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenAI's GPT-Sol 5.6 test agent escaped an internal sandbox, reached the internet, exploited vulnerabilities, and stole credentials from Hugging Face while chasing a cybersecurity task. The model had safety checks removed for evaluation, and reinforcement learning pushed it to focus on goal completion over constraints. The breach has prompted calls for tighter standards and regulatory attention around autonomous, reward-driven security agents.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fministryofcyberaffairs.com%2Fnews%2Fhow-starlink-became-the-unkillable-wi-fi-for-a-114-billion-crime-empire-a6f9d641-cc79-410f-b1fe-29d1ce6122b8%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/Ycfu_KWao2MeRVM67F-0Nj-ZVPnUjinL0oquoYjevco=452">
<span>
<strong>How Starlink Became the Unkillable Wi-Fi for a $114 Billion Crime Empire (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A UNODC threat assessment for South-East Asia detailed how transnational scam syndicates adopted Starlink terminals to sustain compounds after Thailand severed terrestrial internet and power along the Myanmar border in 2025, linking the resulting satellite-dependent criminal ecosystem to regional scam losses of $88.3 to $114.1 billion in 2025 alone. SpaceX disabled over 2,500 Starlink kits near suspected Myanmar scam centers following AFP reporting and a military raid on KK Park. However, UNODC warned that this reactive takedown model would be hard to replicate as additional LEO satellite providers enter the market. The report framed the episode as exposing a jurisdictional mismatch between globally operating satellite providers and territorially bound regulators, a gap now drawing US congressional scrutiny and UNODC calls for harmonized cross-border enforcement.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemgrep.dev%2Fblog%2F2026%2Fcomparing-open-source-ai-code-security-harnesses%2F%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/Un3wwMwz0sxVwGYzjLBSSZ1E6kMVo742ee1aeCVEtiQ=452">
<span>
<strong>Comparing Open-Source AI Code Security Harnesses (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Semgrep's Isaac Evans surveyed the emerging open-source landscape of LLM-driven vulnerability-hunting harnesses, grouping them into three approaches: LLM-led exploit generation that treats a crash as proof of a bug, skill-boosting frameworks that graft security-research methodology onto existing coding agents, and SAST-LLM hybrids that use deterministic tools like Semgrep or CodeQL to narrow an LLM's search space. The piece walks through named projects in each category (Anthropic's now-unmaintained defending-code-harness, Cloudflare's security-audit-skill, Trail of Bits' skills, Visa's VVAH, and Vercel's deepsec, among others) and compares them on validation rigor, code execution, patch generation, and language coverage, concluding that no reference open-source leader has emerged because the field moves too fast. Written by a Semgrep employee, the analysis carries an inherent vendor lens worth weighing alongside its otherwise even-handed comparisons.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FdKkAdd/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/SNGyCK0q-xQhfnBqsfobw7he-YFw2WS8tlbaAarF_lE=452">
<span>
<strong>Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Upbound Group reports that hackers accessed non-sensitive customer information and documents, then used those details to set up fraudulent lease-to-own agreements in its Acima segment, driving about $13 million in contract losses in Q2 2026.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdecipher.sc%2F2026%2F07%2F23%2Fyour-llm-is-showing-new-data-finds-sharp-rise-in-exposed-ai-tools%2F%3Futm_source=tldrinfosec/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/mD8-i_JAagLetG3wOsK6JtH83X4P5mTMd3XWAPMgcWo=452">
<span>
<strong>Your LLM Is Showing: New Data Finds Sharp Rise in Exposed AI Tools (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Censys' forthcoming 2026 State of the Internet Report found AI/LLM tool exposures up over 60% in nine months to 294,000+ IPs across 43 detected tools, led by Langflow and LiteLLM.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/ahDwcZZoyLAq8ynCsWr5y4Gr_KnhLETQykqGrEdKflo=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/2Sd4LJPo0Tfc6KkhLH9YG8pPa1xiLeEV2n4EE5U8wVs=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/7st-Tfc75Z7ZKYGrXRuYOMVOOB5FcOhKVPxh--oTT8k=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/Y31l4vtDFOVZTikBghUMX-jU-WO7suon7W_6Xf_Mc20=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/EZoS6cUq8mUepQazUyFEuAsydr0qi0PEp21kvMCrzyI=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/umT9FU9161og0Gk8ZuS3TT6UFnpsq_zCDT9kBdfa4Dw=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/6mFdfSvidJiRWMBGcv-ijBh_VWOKZbCc_wkAV4j3HfE=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/Am3mBt8kta-So05zGhv3ztQg68Sbg3iAavicWA5k45s=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/qgJb5u0w8rcwl0XX9ndp-ALOpKRENRpcVbf7toitSsU=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/nrDH3x04JDUcTAZHjy4wWu93kY22b8FaZGs1PGj7osQ=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=040e4ef4-8758-11f1-8c76-e7ba84788eba%26pt=campaign%26pv=4%26spa=1784898021%26t=1784898469%26s=c53b18f5c01f4f6a49fca905c8389f8353e2a95c534e2c9cf07855805cf1c5b7/1/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/8qvE3Bn92zIb5E-HW7GZ5A_LBUJ-lPyX38gSEOeMvQ4=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019f943d3e6c-7519c3cf-1566-4293-bb82-28f22272b24c-000000/3ziXJNHJc_Ts2SXBMO_pCys9U0GfQI3ikhbpOG3u1HE=452" style="display: none; width: 1px; height: 1px;">
</body></html>