<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">BleepingComputer was alerted to a new malware campaign where attackers are using Steam Forum posts asking for help solving problems to distribute โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/AcrsthZ5HcyJs8_tkVnZ8wfOIZQA6MJHDqGiJGvBXnM=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/UxBfXCElu6-zz5b1NxNz4CeqC-kB9Z9QeGgJpJxkUm4=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=3f6c5858-8995-11f1-a2c3-bfa00a9a34dc%26pt=campaign%26t=1785157698%26s=eb60beb5a391888ffeaaf37d795d74cb3999413830491e153e3bcc1d7ad4417e/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/sv5NXBRpDwjaGfP7Rz-tEKu-3eMGmsvAEr1aOsraxeg=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-27</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Fr2ZQ3d/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/R7wwIkL_eV1-NWOkNdg28WoapT7PRV6ggtRwqiSPIBs=452">
<span>
<strong>Steam Forum ClickFix Attack Infects Gamers With XMRig Cryptominers (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
BleepingComputer was alerted to a new malware campaign where attackers are using Steam Forum posts asking for help solving problems to distribute malware using ClickFix attacks, suggesting users run PowerShell commands that will fix their issue. The command downloads and runs a fake Windows Optimization tool that claims to run several PC tuneup tasks but actually installs the XMRig malware. The tool also kills existing XMRig processes, installs itself as a scheduled task that runs at startup, and adds Windows Defender exceptions for it
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FZKcwbv/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/2xSR8MOx-UNShnGqj_d9kaxCTeCpENeSEiDpm_05MGY=452">
<span>
<strong>Data Breach Confirmed After Australian Energy Giant Origin Is Hacked (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Origin Energy has confirmed unauthorized access to customer data after a hacker claims to have stolen records on 2 million people, including contact details and partial payment information. The company is still determining how many customers are affected and has engaged external cybersecurity firms. It has notified Australian law enforcement and regulators. The attacker is threatening to leak the data unless Origin pays a ransom.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fgolden-chickens-resurfaces-with-four.html%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/gEki2UjkDW9ixH-8QtmmugVmAkmS7JKIdOXFc1Iydsg=452">
<span>
<strong>Golden Chickens Resurfaces With Four New Malware Families and Modular Implants (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Golden Chickens (TAG-195) is back with four tools: TinyEgg for initial access, ChonkyChicken as the main implant, a modular ChonkyChicken variant with 14 on-demand modules, and ChromEggscalator for Chrome credential theft. TAG-127 uses ClickFix lures to deploy TinyEgg, which hands off to ChonkyChicken for persistence, live Chrome session control, data theft, and surveillance over WebSocket-based C2.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐ง </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fspecterops.io%2Fblog%2F2026%2F06%2F29%2Fllm-jailbreak-testing-with-jailbreaker%2F%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/GK4k8BsGotYblwjRgEPap3XeMdUnoAwVV2aLNwt3Mqw=452">
<span>
<strong>Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat (12 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
LLM jailbreak testing is typically a very manual process that involves copying and pasting prompts into a target and attempting to record the technique used by the prompt and results. Jailbreaker provides a streamlined platform to record experiments and catalog a technique repository. Users can run tests of a single prompt, a family of techniques, or the full technique repository, and automatically record intent and results.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdepthfirst.com%2Fresearch%2Fgoing-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/eSlFcrlE504QTWcodo36VF-myjeAF1vS6H1DfcgmhMo=452">
<span>
<strong>Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities (17 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An authenticated GitLab user with push access could chain two memory-safety bugs in the Oj JSON parser, an unchecked nesting-stack write and an unsafe 16-bit key-length truncation, by committing a crafted Jupyter notebook and viewing its rendered diff, since GitLab's in-tree ipynbdiff gem feeds repository-controlled bytes into Oj::Parser.usual.parse inside the Puma worker. The write primitive was amplified through a jemalloc allocator handoff and Ruby Array heap overlap to seize a parser callback pointer, while the key-length bug leaked a heap address through the rendered diff to defeat ASLR and pivot to system() via libruby/libc gadgets, executing commands as the git user. DepthFirst reported the bugs on June 5, and GitLab shipped fixed Oj 3.17.3 in its June 10 releases. The same audit surfaced nine further Oj CVEs across its dump, loader, and document APIs. Self-managed operators should upgrade to a current supported GitLab patch release and confirm their deployment bundles Oj 3.17.3 or later, since versions 15.2 through 18.9 outside GitLab's security-maintained patch trains received no dedicated backport.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.praetorian.com%2Fblog%2Fknossos-decoy-environments%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/YZHjQ5VO0ZkwBr8qOhNnmxobeG5p4pFgiw78C0ZPTj0=452">
<span>
<strong>Knossos: Procedurally Generated Decoy Environments (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Knossos is a deception engine that mines a customer's real cloud footprint for naming grammars, tag vocabularies, CIDR allocation habits, and instance family preferences, then procedurally generates a decoy AWS account whose VPCs, IAM roles, RDS instances, and Secrets Manager entries are assembled around backward-chained attack paths terminating in lure resources. Generation runs through seven deterministic stages, including a history pass that backdates synthetic audit entries to the organization's observed peak hours, three isolation layers of deny-all NACLs, permission boundaries, and a customer-applied SCP that contain the blast radius, and every lure touch emits an EventBridge event recording which breadcrumb was followed and how long the attacker dwelled at each step. The underlying techniques of pattern-derived naming, camouflage resources matched to real subnet ratios, and lure scoring as interaction rate times one minus escape rate transfer directly to homegrown honeypot builds.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐งโ๐ป</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flp.novee.security%2Fnovees-buyer-guide%2F%3Futm_campaign=439282893-Content%2520-%2520Buyers%2520Guide%26utm_source=Content%2520Syndication%26utm_medium=email%26utm_term=TLDR/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/QCVzR9qNNLIHeU3HdmcRjoeWvB2SSXBFZfZl0MM_hsE=452">
<span>
<strong>AI Pentesting: Ask These 8 Questions to Separate Fact From Fiction (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
<strong>The "AI pentesting" market is crowded with bold claims that hide LLM wrappers and repackaged scanners. This </strong><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flp.novee.security%2Fnovees-buyer-guide%2F%3Futm_campaign=439282893-Content%2520-%2520Buyers%2520Guide%26utm_source=Content%2520Syndication%26utm_medium=email%26utm_term=TLDR/2/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/YiVzc9mGaeYe_XrVMQq-k7PxTtxGRASUnMMat3f7_q0=452" rel="noopener noreferrer" target="_blank"><span><strong>definitive guide by Novee</strong></span></a> will help you cut through the noise, evaluate which platforms have genuine AI capabilities versus surface-level marketing, and determine what actually delivers results. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flp.novee.security%2Fnovees-buyer-guide%2F%3Futm_campaign=439282893-Content%2520-%2520Buyers%2520Guide%26utm_source=Content%2520Syndication%26utm_medium=email%26utm_term=TLDR/3/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/F3varT3oZbsRnZgNoOVA_Flv1iP5MVn9ZMA4YRzj3fY=452" rel="noopener noreferrer" target="_blank"><span>Get your free copy</span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fsecureagentics%2FAdrian%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/WxHQhcw1JQJ1DKYCq0M7YddjnZ9EXtphQs6LtB7zp4s=452">
<span>
<strong>Adrian (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Adrian is an open-source runtime security monitoring and control engine for AI agents.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.aegisai.ai%2F%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/lrad4quCatSQxfDSJeu_Xeo2IsdwYyZ_HSTqAQ8FGzM=452">
<span>
<strong>AegisAI (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AegisAI provides email security tools that use detection agents to scan messages for phishing, business email compromise, and other fraud, connecting via API to Microsoft 365 and Google Workspace to investigate suspicious links and attachments within minutes.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fbadchars%2Fdarknet-mcp-server%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/TDIWcJ327rReTak8Nt7_DBbcd4aRXfy3RI3qbgA4N4k=452">
<span>
<strong>darknet-mcp-server (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
darknet-mcp-server bundles 66 MCP tools across 16 threat intelligence sources into one stdio server, giving an agent HIBP breach and password lookups, ransomware.live and RansomLook victim tracking, the abuse.ch trio of ThreatFox, URLhaus, and MalwareBazaar, Hudson Rock stealer logs, Vulners exploit search, Bitcoin address tracing with ChainAbuse reports, and seven Tor tools that fetch and scrape .onion sites through a local SOCKS5 proxy using socks5h to keep DNS resolution inside Tor.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjoshuasaxe181906.substack.com%2Fp%2Fthe-openaihuggingface-incident-how%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/Tn3I1S-H5Fte8umFl0NivIwr3gu5F5yKFwwVqX24Nww=452">
<span>
<strong>The OpenAI/Huggingface Incident: How We Should Manage the Imminent Arrival of Autonomous Hacking too Cheap to Meter (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The incident of an unreleased and unguardrailed OpenAI model hacking Hugging Face may be a precursor to the level of autonomous hacking tools that attackers will soon have. While much of the current American political discourse is focused on limiting access to powerful models that can perform sophisticated attacks like this, we should instead prioritize defender adoption. The government's role should instead be to build safety organizations with true independence from frontier labs that can serve as safety observatories to guide societal-level responses to threats.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fkrebsonsecurity.com%2F2026%2F07%2Flg-to-ban-residential-proxies-from-smart-tv-apps%2F%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/cJJGW-47jlA4k763c1OaQ7m2wnga2Qqi0SmYJeD73Mc=452">
<span>
<strong>LG to Ban Residential Proxies from Smart TV Apps (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Following a report from security firm Spur that 42% of apps available to download on LG's webOS store allow unknown third parties to route traffic through a user's smart TV, LG has announced that it will no longer allow apps to contain this feature. Spur found that the majority of these apps used SDKs from the residential proxy network Bright Data. Bright Data responded that users opt in to the sharing via a consent screen and that they follow know-your-customer processes, but Spur counters that these one-time prompts are buried in the apps and insufficient.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F07%2F25%2Fthe-hacker-who-humiliated-spyware-makers-and-was-never-caught%2F%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/v3hptlK6Nufd9zhvFuuAp549EG3m8JK8OgtL75W9c90=452">
<span>
<strong>The hacker who humiliated spyware makers and was never caught (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Phineas Fisher hacked government spyware vendors FinFisher and Hacking Team, leaking internal data that exposed client operations and helped sink Hacking Team's business. They later breached a Catalan police union, Turkey's ruling party, and Cayman National Bank's Isle of Man branch, funding leftist causes and proposing a โhacktivist bug bountyโ while staying anonymous and active in private contacts.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">โก</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fknocknoc.io%2Fc%2Fprevention%2F%3Ftldr3%26utm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/WuRGsveb4LBuBsv364aWVdND2vlPhwwczu7wqPPi2h0=452">
<span>
<strong>Detection and response is dead. Prevent instead. Allowlist your networks with Knocknoc. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Stop chasing attackers. Remove your attack surface instead. Authenticated users gain just-in-time access through existing firewalls. No agents. No re-architecture. Live within hours.<p></p><p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fknocknoc.io%2Fc%2Fprevention%2F%3Ftldr3/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/zydTp7Hvqz96fhwRVVK59Y3J6t8Oj5jisGZl1CI3o04=452" rel="noopener noreferrer nofollow" target="_blank"><span><strong>Get the free licence (DIY)</strong></span></a><strong> | </strong><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fknocknoc.io%2Fc%2Fprevention%2F%3Ftldr3/2/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/TYnaO7TvpHLFclZbfmGh2PN4m7XOoE-O3zE6pSC7a6c=452" rel="noopener noreferrer nofollow" target="_blank"><span><strong>Start a free trial (SaaS)</strong></span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.hivesystems.com%2Fblog%2Fare-your-passwords-in-the-green%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/O8gUJEGr34cjzvWDO5wdgzfINpAFIPZqqhuac0oTMDc=452">
<span>
<strong>Are Your Passwords in the Green? (34 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An updated infographic on password complexity vs time to crash and an article describing Hive Systems' testing methodology.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FHjgZwH/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/pLeFAskrpOjqvOHUSgQzTF8YDI2h4AmrpNwKcbmJ6P0=452">
<span>
<strong>Vatican's Official Prayer App Leaks 700K+ Global Users' PII (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A white hat hacker found an IDOR flaw in Click to Pray that exposes names, email addresses, countries, account status, and admin roles for over 700,000 users via an unauthenticated API endpoint.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fsecurity%2F2026%2F07%2F23%2Fstadler-rail-scoffs-at-eversts-123m-extortion-attempts%2F5276922%3Futm_source=tldrinfosec/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/91-x6cZGLqIKD59JOAjWu1XVuioDpcS2Lkc438uer7k=452">
<span>
<strong>Stadler Rail scoffs at Everst's $12.3M extortion attempts (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Everest compromised a supplier's data exchange platform for Stadler Rail using stolen credentials and demanded CHF 10 million.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/hkS1JIa2sgigJkgXkqwNORDutuXxTeu-gexKDwm8Mu4=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/w9RnfSC3NiOXURpP4ezuguwJjz34Pq-cQqx0uL-SDZM=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? ๐ฐ
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/66p1WWZqrnqzy375V-Xb_zOPGwO6pVKHmsFY9AI9Kqo=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? ๐ผ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/tWfmo6nFe8NutECLsHQglUuir6MiEpoudJkgUguZS3U=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/zobXxaPRjDU2vf3p6I7YW_jtn_tQgx8Adx7FqU6wLRA=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/XRKOUqNNxu8haVliokTr2Fap0FUg3Odr4Mp4tY6DVXk=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/Lw8Eky0B3CeeXNbLb0sv-6youRcp8p6xD66VLve--ic=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/BZmH-BqmAxHPcxGulWQ3VuEY3OKHH3ZonqPnWLv7mOg=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/IFCIS9rO8sE0Hoc38OdNpKGfgG7clAO-8RQbhPvBJZQ=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/7aKZ1B_YAgIw2X-gU8_8cak0eZ-4GUFzLzCxg1fVCwM=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=3f6c5858-8995-11f1-a2c3-bfa00a9a34dc%26pt=campaign%26pv=4%26spa=1785157242%26t=1785157698%26s=51044b8f82a51e515c95aec6e6faef57b6ac5071d08e8a34e63d2a540d3a700b/1/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/f9A5792T93k-VSUIy8Q6mN3oCnSxts7F2RiKVTesskI=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fa3b0c37b-973a3cf0-ab62-4345-9632-ba43b644b241-000000/uMxQob_qjLwAy18E2JsL_vTKWKoO5iQB4Myk3XSD3Ck=452" style="display: none; width: 1px; height: 1px;">
</body></html>