<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Zenity Labs discovered that the ChatGPT Workspace Agent Builder would accept initialization states via URL parameters like template_name </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/cLtu2Y7tNGgj31ZTEwdnO3rdPMF26jhAKIYfZWzKe_U=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/XBGkW3gNUV5RS1iy44lRURBnNu0nrj3Q0X2YI55QM84=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=6b33ee40-8a5f-11f1-89a2-abf001eb31a1%26pt=campaign%26t=1785244120%26s=23ff8b259319929f4f7cbafbed96bd3f9f8f0516ba70fda62da53f4e6bf66181/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/7CX4BnEgj0OnnsCY8MwvgacX7GhM-cbfOPGzKPQW7xM=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.humansecurity.com%2Fforrester-wave%2F%3Futm_source=tldr_infosec%26utm_medium=newsletter%26utm_campaign=brand_agentic_trust%26utm_content=forrester_wave_2026/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/J0yS_swzY-y174Thun399H48BorU79iWO5z5nK-250M=452"><img src="https://images.tldr.tech/human.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="Human Security"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-28</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.humansecurity.com%2Fforrester-wave%2F%3Futm_source=tldr_infosec%26utm_medium=newsletter%26utm_campaign=brand_agentic_trust%26utm_content=forrester_wave_2026/2/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/isunBLcFsLvACDw_hTWjWeY8EWDlWU1Lz52cc4BXhw0=452">
<span>
<strong>Do You Really Know Who's on Your Website? (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
<strong>Humans, AI agents, trusted automation, and malicious automation all interact with your website. Without knowing who's legitimate, every downstream decision - from security to marketing - is based on incomplete data.</strong><br><br>See why HUMAN was named a<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.humansecurity.com%2Fforrester-wave%2F%3Futm_source=tldr_infosec%26utm_medium=newsletter%26utm_campaign=brand_agentic_trust%26utm_content=forrester_wave_2026/3/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/VwlbSwsV4cR4OA-eAFyeGC3i4x-icBDo0FL_YffCwNc=452" rel="noopener noreferrer nofollow" target="_blank"><span> Leader in The Forrester Wave™</span></a>: Bot and Agent Trust Management Software, Q2 2026, and discover:
<br>
<br><strong>🛡️ </strong>Why blocking bots is no longer enough
<br>🤖 How AI agents are reshaping digital trust
<br>🎯 What separates today's leaders in bot and agent trust management
<br><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.humansecurity.com%2Fforrester-wave%2F%3Futm_source=tldr_infosec%26utm_medium=newsletter%26utm_campaign=brand_agentic_trust%26utm_content=forrester_wave_2026/4/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/8bC_wc8l7jeDkoxESPJ3R8A7hntdwRpq6uo2rKKRF-4=452" rel="noopener noreferrer nofollow" target="_blank"><span><strong><br>Get the Report</strong></span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcybersecuritynews.com%2Fchatgpt-agentforger-vulnerability%2F%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/Cg5rKrvF-S_AYy9d5B7qKCFs8pkvcImB8ucUl0dmqH0=452">
<span>
<strong>ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Zenity Labs discovered that the ChatGPT Workspace Agent Builder would accept initialization states via URL parameters like template_name and initial_assistant_prompt. It would then automatically submit the prompt when the page loads. This meant that a single link sent to a logged-in user with pre-authorized connectors could silently create an agent, connect existing Outlook, Gmail, Slack, Drive, SharePoint, and Teams integrations, and change write-action permissions from 'Always ask' to 'Never ask' without prompting a new OAuth consent screen. The deployed agent would run every five minutes, checking the attacker's inbox for messages starting with TASK, and sending back results. This setup effectively allowed an insider to perform organizational mapping, exfiltrate documents, harvest credentials, and stage Business Email Compromise (BEC) attacks. Zenity reported this vulnerability via Bugcrowd on June 4, and OpenAI patched it on June 8 by removing the parameter handler, though no evidence of active exploitation was found. Current recommendations include auditing active Workspace Agents for unknown creations, reverting approval settings to 'Always ask,' and treating deep links in emails that build agents as potential phishing attempts.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.expressvpn.com%2Fblog%2Ftribeca-film-festival-data-exposed%2F%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/mHwh9fcpD-9v08bS4AzFi-nzHdoEHfgaIytBwPuPpsU=452">
<span>
<strong>A-List Directors, Actors, and Celebrities Exposed in Major Film Festival Breach (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Security researcher Jeremiah Fowler found an unencrypted, unsecured database linked to the Tribeca Film Festival. This database contained a backup with over 163,000 users, 15,000 film contacts, and 13,500 other contacts. It also included data on numerous celebrities from the entertainment industry, such as email addresses, names, Facebook locations, addresses, IP addresses, newsletter information, and bcrypt password hashes.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F9NXQwz/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/gFq230Yo9pO2C1y1Ix2tIQojuuBCYtjJKXJfqlF9mmM=452">
<span>
<strong>Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
ReliaQuest is reporting on a new phishing campaign where attackers are changing the DNS settings on hotel Wi-Fi systems to redirect Microsoft 365 logins to fake, attacker-controlled pages. The campaign uses a device code flow where users are prompted to approve the login request to bypass MFA requirements.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgbhackers.com%2Fbluenoroff-fake-meeting-kit%2F%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/WtMViTb3wyQKBwMCN0RysKEgNcM1AGIh_ss5KrRBsFI=452">
<span>
<strong>BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A victim receives a meeting link from a hijacked Telegram contact and lands on a cloned Zoom or Teams page that silently opens the webcam and fingerprints browser wallets via EIP-6963, legacy window.ethereum, and Solana enumeration. They watch a deepfake video and chat until a fake SDK update prompt exploits clipboard hijacking to run a PowerShell loader, dropping a VBScript. JUMPSEC later recovered the source, revealing a Windows Trojan named Trojan.NukeSped that persists, blocks Defender, runs WMI scans, enumerates extensions for MetaMask, and extracts Telegram session data from IndexedDB to feed future lures. The macOS version uses Mach-O droppers with LLVM obfuscation to extract credentials via the security CLI and exfiltrate through Telegram bots. Defensive actions include alerting on Defender exclusions, monitoring clipboard PowerShell, hunting processes accessing IndexedDB, flagging unknown contacts before SDK updates, and blocking 11 C2 domains.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftrustedsec.com%2Fblog%2Fthe-privileged-roles-nobody-talks-about%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/qmPh42hTxpbiDKOrXZhIsU3SY3b0lHABT85g055xJj4=452">
<span>
<strong>The Privileged Roles Nobody Talks About (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
MDM administrator roles are as important as Domain Admin, if not more so, as they can deploy arbitrary scripts, push configuration profiles, issue remote wipes, manage applications, manage certificates and authentication configurations, and modify compliance policies. Unfortunately, many organizations do not have sufficient controls in place for these roles, with lax policies such as not having dedicated accounts or workstations, no just-in-time privilege elevation or multi-admin approvals, and overly permissive Graph API access. This article includes suggestions to remediate these issues, such as fixing the above issues, locking down script and policy deployment, hardening device enrollment, and implementing additional alerting on high-risk activities.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Featon-works.com%2F2026%2F07%2F27%2Fmy-eicher-hack%2F%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/cYkagmqy8ygvyDWMu7V9Z8LfnAmSn742ZL3KPnskG5k=452">
<span>
<strong>Exploiting Volvo/Eicher's fleet management platform to gain control over all users and vehicles (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
VE Commercial Vehicles' My Eicher telematics platform for Indian truck and bus fleets exposed unauthenticated internal APIs that listed hundreds of thousands of customers, users, vehicles, and OTP codes. By walking the API path, Eaton found open endpoints that returned user records, encrypted passwords, and a full OTP history since 2021, enabling account takeover by matching mobile numbers to OTPs or resetting passwords via API. This access allowed remote control and tracking of entire fleets and exposure of around 76,000 sensitive identity documents before the core vulnerability was fixed in November 2025 after repeated disclosure attempts.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fagentfield.ai%2Fgithub%2Fsec-af%2F%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=tldr-260728%26utm_id=tldr-260728-sec-af%26utm_content=sec-af/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/ZApcvNySDJCTpL_pB1rKLyCCMU-9VISB4KLZVpyaUN0=452">
<span>
<strong>The open-source code security auditor that proves exploitability. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The open-source security auditor that proves exploitability. Point it at any repo — every finding ships a verdict, a source-to-sink trace, and the CWE, while adversarial agents disprove the false alarms. The noise never reaches you. Works with any open model. See where it lands on the DVGA benchmark.<p></p><p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fagentfield.ai%2Fgithub%2Fsec-af%2F%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=tldr-260728%26utm_id=tldr-260728-sec-af%26utm_content=sec-af/2/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/2t9FIeTcIs0bVFLMKZQ9DTSC3-OqwU9xeY1a6e5Jkic=452" rel="noopener noreferrer nofollow" target="_blank"><span>Star & Deploy</span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fraesene%2Fzeedumper%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/_LKsg8do46N1BW8N2V2aWZV6XQb6oltfTm-ju4hVLRg=452">
<span>
<strong>zeedumper (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
zeedumper connects to Kubernetes clusters using your kubeconfig files and dumps component z-pages by retrieving them through the API server proxy.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Foptimuslabs-io%2Fgrokpatrol%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/SaaXnokIpss-GZK0UItBYFxVRSl4ajRZml2GCmAm9Nw=452">
<span>
<strong>grokpatrol (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
grokpatrol is a tool to detect whether the Grok Build CLI was installed on your machine and whether it collected and queued your git repositories for upload to xAI. If so, it will notify you of any secrets that were uploaded with them.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.abstract.security%2F%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/maASuc22jUnzhgI_OXbTQJoLM6_nXT0cmbIFrB20yLI=452">
<span>
<strong>Abstract (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Abstract provides a streaming-first security operations platform that separates security data sources from storage targets, runs in-stream detections, routes data into multiple formats like OCSF and ECS, and aims to reduce SIEM storage costs.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftachyon.so%2Fblog%2Fwhat-happened-after-we-pushed-env-to-public-repo%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/jmP2JdePUvDjGHvn_VfshjM6arwiVXB41ExDXiAJf6k=452">
<span>
<strong>What happened after we pushed our .env to a public repo (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Tachyon's committed canary .env files containing AWS, Anthropic, and Postgres credentials were made public on GitHub. GitHub flagged secrets within seconds without email alerts. AWS attached AWSCompromisedKeyQuarantineV3 shortly after a push, and within about five minutes, credentials connected externally. The quarantine policy didn't revoke keys or block secret commands, allowing an attacker using TruffleHog and Boto3 to access Secrets Manager and retrieve credentials seven minutes after pushing. Other traffic came from OVH, Tor exit, and Gigahost addresses, logging into Postgres and reading decoy tables. The intrusion stopped there, as the harvested secrets remained unused during the observation. Logs don't reveal if an LLM helped triage, leaving uncertainty about whether it was an attacker or defensive scan.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.nist.gov%2Fnews-events%2Fnews%2F2026%2F07%2Fuk-aisi-caisi-preliminary-assessment-kimi-k3s-cyber-capabilities%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/8eq8CaaG77VrYSgGCNc6KFLCBRDYy-ycqM4vQYSgSTY=452">
<span>
<strong>UK AISI/CAISI Preliminary Assessment of Kimi K3's Cyber Capabilities (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
UK AISI and CAISI jointly evaluated Moonshot AI's Kimi K3, released July 16 and slated for open-weight release by July 27, and placed it well behind frontier US models while ahead of GLM-5.2, scoring 32% on Carnegie Mellon's ExploitBench against 76.2% for top US models and 24.4% for GLM-5.2, and reaching step 17 of the 32-step "The Last Ones" cyber range against 28.5 steps for the leading US models. The gap narrows unevenly because Kimi K3 matched the frontier on coverage and came close on bug reproduction but achieved arbitrary code execution on zero of 41 samples where top models managed 20, and yet it completed the full cyber range once in ten attempts, which the evaluators read as autonomous capability against small, weakly defended enterprise networks given initial access. Two framing points deserve weight, the first being that Kimi K3's safeguards did not stop it from attempting exploit development or offensive operations at all, and the second being that US closed-weight comparators ran with system-level safeguards disabled to measure maximum capability, so the published gap measures raw model ability rather than what a user encounters, a distinction that matters as open-weight releases from PRC labs keep closing the trendline.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.accomplish.ai%2Fblog%2Fsharedroot-escaping-claude-cowork-sandbox%2F%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/Vkz2s0-aZOm5fSNftmZGT3xyAtPabGLhrpzIywk1mKI=452">
<span>
<strong>SharedRoot; Escaping the Claude Cowork sandbox (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A Claude Cowork session on macOS can chain a user-namespace feature, a Linux traffic-control module, and a recent kernel bug to escalate from an unprivileged VM user to guest root and then write directly to the host filesystem via a shared / mount. The write primitive comes from CVE-2026-46331 in act_pedit, and the path persists as similar bugs appear. To harden the environment, disable unprivileged user namespaces, tighten seccomp, block unneeded autoloaded modules and helper binaries, and scope or remove the host filesystem share so guest-root cannot touch SSH keys or other sensitive data.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fruntimewire.com%2Farticle%2Fgithub-issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz%3Futm_source=tldrinfosec/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/_N8yRm7FDzJ2ydpzm0cYaSLOvRalQElKnx7yyhr_hsE=452">
<span>
<strong>GitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_ (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
GitHub paid researcher @sagitz_ a $100,000 bounty, reportedly among the largest in its Vulnerability Reward Program, for CVE-2026-3854, an unauthenticated remote code execution flaw in the handling of crafted repository URLs.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FIN8OtM/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/82X5A4GqOvCXn1-FoWDcmNw0AmO-1delIfN3E5lsDis=452">
<span>
<strong>GitHub, PyPI add time-based defenses against supply chain attacks (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Dependabot now holds version update pull requests for 72 hours by default so a malicious package flagged minutes after publication has time to be pulled before it lands in a repo.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/Ou-132wltv1KFb4f-xXrVVbVna9fuSqmC0WH1oIPYg8=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/7NkGFyAHHQtoVaBDLGSugDpp3x-1hqoRYgh4y_61Ae0=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/lwkE4WkJ320BT8A_wrDkL5bXEPCL9zyGFnT95oMwLdY=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/cPZ4LC6iXYfnDkGrdmGTB15j0ZVZaBMJOTsI6LXwTL4=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/pt9QqwKkJ8wNmA4K7sUuyGJ9EKJVT9HLlpfKYOLZTQA=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/vl8z4Xc8OZQuX4iAuNvikISWrWPodNOgXVou6TAOhUY=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/SSgEz7SnjGxJfiDI8QwfOHis5r12mYrmD132dZt8j2E=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/KRTsNUWzwMlkJ-Q2NfQa3-ecQ923SOLUJYrIQ_amQBE=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/VEO-VwdesqxbynW0r170lc-_HPst9nPPso4bfrduHZE=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/Sqv4yd546KEFPosxLnQ0Qu6GshLyFgDpb8su7afP4Lg=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=6b33ee40-8a5f-11f1-89a2-abf001eb31a1%26pt=campaign%26pv=4%26spa=1785243679%26t=1785244120%26s=0f8c070d3ea2398e19665bccd387ca4a4c14e94661df61c9d355e816d141eb55/1/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/ad4wnDu8uhuBbaQFa-DfGP8YwMCXYwWafgG0VLJP0Ew=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fa8d775f7-30306a29-6939-4a6f-9be0-c3ed84d5e485-000000/qjv3QD4QnagmQkUmBK0ZiVYt3lt2QaJkqJjQWxCXJw4=452" style="display: none; width: 1px; height: 1px;">
</body></html>