<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">India's state-run Bank of Baroda disclosed that customer data was stolen via a breach of an employee's email. The bank has stated that no core โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/KxEA4EQ0OdIeAu49_OhCJ4CZYzqF2edMh_tr_iw1fbI=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/u5J4mwp9h_omto0urUsGakzUZIiTw0ohYc-A7_M08Go=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=51dbfb24-8b16-11f1-98dc-67da35eba588%26pt=campaign%26t=1785330588%26s=9ce8910ec54d4eadc6fd89d46ac7e5be050077fff23414081004631ff91a39cd/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/nBvndpodtnbWePbIAyHsomdteZpQ6zYXmi2JmZnf-Kg=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F1password.com%2Fproduct%2Fprivileged-access%3Futm_source=tldr%26utm_medium=paid_newsletter%26utm_campaign=2026q3_blackhat_lp_privileged-access_sa%26utm_content=newsletter_infosec_072926_header_standing_access_doesnt/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/vp3E1JpgRJQgMUdiwwRMkjYsk4zL0xQfLwBfFn4ts4w=452"><img src="https://images.tldr.tech/1password-2.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="1Password"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-29</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F1password.com%2Fproduct%2Fprivileged-access%3Futm_source=tldr%26utm_medium=paid_newsletter%26utm_campaign=2026q3_blackhat_lp_privileged-access_sa%26utm_content=newsletter_infosec_072926_header_standing_access_doesnt/2/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/T3Uh90GtbH12ICitxt7xVAD3FtZbIjDJKaWTxlwm8NM=452">
<span>
<strong>Standing access doesn't stand a chance against 1Password Privileged Access (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
What happens after access is granted? Too many companies can't give a clear answer. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F1password.com%2Fproduct%2Fprivileged-access%3Futm_source=tldr%26utm_medium=paid_newsletter%26utm_campaign=2026q3_blackhat_lp_privileged-access_sa%26utm_content=newsletter_infosec_072926_body_1password_privileged_access/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/A4eFOh3vUt66Ourx0ki7iM5oFanb5kF42daDrDQb82o=452" rel="noopener noreferrer nofollow" target="_blank"><span>1Password Privileged Access</span></a> was built to solve that.
<p></p>
<p>Govern every identity that touches your infrastructure: human engineers, AI agents, and machine workloads.</p>
<ul>
<li>Access exists only as long as the work requires it.</li>
<li>Every access event and session is logged automatically.</li>
<li>Security teams get a complete picture of who accessed what, when, and why.</li>
</ul>
<p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F1password.com%2Fproduct%2Fprivileged-access%3Futm_source=tldr%26utm_medium=paid_newsletter%26utm_campaign=2026q3_blackhat_lp_privileged-access_sa%26utm_content=newsletter_infosec_072926_cta_how_1password_privileged/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/MBAZHyyy4GjauTR1LKt3FwBQvvQqkdLd6cRWxhx6m7k=452" rel="noopener noreferrer nofollow" target="_blank"><span>See how 1Password Privileged Access eliminates standing access.</span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FI9yQsk/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/13TW8iaRFp0rNKVapi2x_CiFQABSdnDhoKtbIA78sIU=452">
<span>
<strong>Customer Data from India's Bank of Baroda Leaked Online (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
India's state-run Bank of Baroda disclosed that customer data was stolen via a breach of an employee's email. The bank has stated that no core banking systems were accessed. The breached data includes customer details, ID numbers, loan papers, and internal audit data.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FoysHHF/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/fDp1J80VvOKsGnzCnSiA3qggUGVTmMW5yjpXw2H19Tc=452">
<span>
<strong>Australia's Origin Energy Flags Possible Data Exposure of About 900K Customers (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Australia's top electricity and gas supplier, Origin Energy, disclosed that data linked to about 900k current and former customers had been accessed in a cybersecurity incident. Origin didn't disclose the precise data accessed but stated that it could include financial data such as the last few digits of customers' credit card numbers or bank account numbers.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsocket.dev%2Fblog%2Fnpm-rat-targets-alibaba%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/URZPa5QgqhYbwX5IamfR7PrsXwYciHeHn-JGwPnsY44=452">
<span>
<strong>Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Socket uncovered a three-month stealth campaign involving 18 npm packages that split loader functions across dependencies, making malicious intent hard to detect. They used unscoped lures impersonating Alibaba's @ali scope, pulling in smart-config-manager, which depends on cloud-config-fetcher and local-config-parser to retrieve attacker rules from GitHub and escape the Node.js vm sandbox via items.constructor.constructor. The staged aone-cli payload, a cross-platform RAT, supports command execution, file transfer, screenshots, an encrypted reverse TCP proxy, and DingTalk lateral movement. It persists through a ~/.zshrc entry, a 10-minute macOS Launch Agent, a trojanized Windows app.asar, and a Linux binary in /tmp, with C2 traffic masked by spoofed headers. Affected hosts should be treated as compromised. Reset secrets from clean systems and hunt for Python files with the identifier above.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐ง </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.huntress.com%2Fblog%2Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/Vv56N2daiFffDr1tYWfelvAm3-zlHBUdOBxfqfK0wTM=452">
<span>
<strong>Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT (13 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A Bing search for "claude desktop app" returned a sponsored link pointing at a genuine claude[.]ai artifact URL, and that user-generated page redirected through claude.ai.download-app[.]us and downloading-api.it[.]com to a ClaudeDesktop.exe that was really JetBrains jcef_helper.exe sideloading a tampered libcef.dll, packed with VMProtect and pulling its next stage from an Ethereum BSC contract using the EtherHiding technique, while a second persistence path dropped a signed IBM SPSS binary as sslconf.exe alongside a malicious tempdir.dll that gated execution on DXGI adapter IDs, sub-1GB VRAM, and compute shader timing to defeat sandboxes, then decrypted its payload with a DirectX shader running a modified AES-256-CTR rather than any hookable crypto API. Huntress traced the resulting SectopRAT build to C2 at 2.24.131[.]246, tied the registrant of download-app[.]us to ten domains going back to December 2025, and matched the tradecraft to a fake Docker Desktop campaign in April that used the same libcef.dll sideloading pattern against 29 organizations between July 21 and 22. Hunt for ClaudeDesktop.exe and DockerDesktop.exe writes, scheduled tasks pointing into %APPDATA%\Roaming\Microsoft\EdgeUpdate\Install, and Defender exclusions added around software installs, block the listed C2 range and the two BSC contracts as pivot indicators, and treat vendor domains as untrusted download sources when the landing page is a user-generated artifact, since the Anthropic disclaimer that artifact content is unverified was the only signal separating this page from a real one before takedown at 7,100 views.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flavahq.io%2Fresearch%2Fbmc-exposure-alert%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/DbFuUsPAaHSo6_yJ5Db16ZCbc-V1plhEi6GrURe1izs=452">
<span>
<strong>How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability (10 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Lava researchers scanned UDP port 623 and found 36,872 internet-exposed IPMI hosts, of which 24,650 returned a password-derived HMAC-SHA1 hash during the RAKP authentication exchange before login completed due to CVE-2013-4786, letting an unauthenticated party crack passwords offline. More than half of responding devices were Supermicro systems whose post-2019 unique ten-character factory passwords (a 26^10 keyspace) could still be exhausted in about an hour on an eight-GPU rig, while HPE iLO's eight-character factory format cracked in roughly 32 seconds per captured response. The team also found a live iLO 4 interface defaced with a ransom note demanding 0.3 BTC, evidence that this exposure is already being exploited rather than theoretical, and disclosed the Supermicro password-recovery timeline to the vendor in June, who confirmed it as plausible and is reviewing longer default password formats. Operators should block UDP port 623 at the network edge, rotate factory-issued BMC credentials during provisioning, disable IPMI 1.5, cipher suite 0, and NONE authentication, and isolate BMC access behind a dedicated management VLAN, bastion host, or VPN rather than exposing IPMI or Redfish directly to the internet.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐งโ๐ป</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_medium=referral%26utm_source=tldr/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/n_hCbQUYs4ybQ0K3ewN6WBSsLtpe-6UH4Bqz1s88kD8=452">
<span>
<strong>6,000+ "guardrail-free" AI models. One download away. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AI-powered cybercrime is no longer just a future risk. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/qDRekELj39SM6QZJASIQjPN99VjLAqjWmMIjWxDynYU=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown's </span></a>new research found it's already here, hiding in plain sight on infrastructure organizations already trust. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F/2/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/ETE3KjvljzMFbxV_S9OVITPxud7LTV27qyB1OsMZUuU=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown</span></a> researchers assess that AI capable of exploiting vulnerabilities at scale could reach criminal marketplaces within roughly six months. Read the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_medium=referral%26utm_source=tldr/2/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/7BOidYDBmQ3cortCF05p49pU6xPOGA3LJMCr-z6ouZA=452" rel="noopener noreferrer nofollow" target="_blank"><span><em>Cybercrime in the age of AI</em></span></a> report.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fsupermhel%2Ffengarde%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/nQXirxDMPyUhrtkW51XLHHbL6frXDCRKRCQMDSXnEYw=452">
<span>
<strong>FENGARDE (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
FENGARDE is an open source (Apache-2.0) SIEM aimed at European industrial Mittelstand operators, normalizing 16 parsers spanning Cisco ASA, Windows Event Log, Sysmon, Kubernetes audit, CloudTrail, Modbus/TCP, OPC UA, n8n, and MCP tool-call audit logs into OCSF, running 27 correlation rules over a sliding window into OpenSearch, and rendering alerts as draft NIS2 Article 23 and ยง32 BSIG incident notifications with every entity-specific fact left as an explicit analyst placeholder rather than fabricated. Triage runs against a local Ollama instance with a documented passthrough stub, so alert data never reaches a third-party LLM API, and the whole detection path is demonstrable without Docker through a zero-infra acceptance test.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fsecdev02%2FIncantation%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/IEDWZ_Z0TQdusunH_ofB6L20WStOspGRmxI5uA0H_GE=452">
<span>
<strong>Project Incantation (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Project Incantation is a defensive security toolkit for generating adversarial honeydocuments.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcyberinsider.com%2Fprivacy-focused-search-engine-neosearch-open-sources-code-to-promote-decentralized-web-search%2F%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/uW2PL52W9XYbjETEdPolwKJ-sPG6NkI90B1b94biBi4=452">
<span>
<strong>Privacy-focused search engine NeoSearch open-sources code to promote decentralized web search (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
NeoSearch has open-sourced its codebase under the Apache License 2.0, letting anyone inspect, modify, or self-host the ad-free, no-tracking search engine, which uses AI to downrank SEO-driven and affiliate content in favor of independent and authoritative sources while grouping and rewriting result snippets through its Lenses interface.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fbindinghook.com%2Fthe-openais-agent-didnt-go-rogue-its-governance-did%2F%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/dcGyXyYN4iLMSiz6vxlVQNXb7UqEg54rbkbbXhUWBks=452">
<span>
<strong>OpenAI's Agent Didn't Go Rogue. Its Governance Did (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The recent incident where an unreleased and unguardrailed OpenAI model autonomously hacked Hugging Face is commonly portrayed as an incident of a model going rogue. This is the wrong framing. The agent stayed aligned with its objective of finding a solution to the ExploitGym benchmark but wasn't given the guardrails or governance to understand that trying to steal the solution wasn't an acceptable attack path. The situation is also complicated by the fact that frontier labs are not incentivized to reduce their models' capabilities in tests and the fact that this incident was almost an advertisement for OpenAI.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.bbc.com%2Fnews%2Farticles%2Fcly5qgjk5ywo%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/w7qooBG7uR0huTF5tHgEmTbKj2BkDxMmr5lBvb_5pCc=452">
<span>
<strong>Some People's Chats with Claude AI Found to be Publicly Available Online (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Users of claude.ai recently discovered that shared chats were indexed by search engines and could be viewed in search results. Anthropic has responded that these chats were shared publicly by users via the option to make them available to anyone with the link. Despite this, some users were surprised to find that they were indexed by search engines.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.silentsignal.eu%2F2026%2F07%2F28%2Fthe-cipher-behind-qsyrupwd-reconstructing-ibm-i-password-hashes%2F%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/PHHQB2S1ExKBz9JcHunDJgyTxhhFnI9F1i87PW1cNvU=452">
<span>
<strong>The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes (22 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Silent Signal reverse-engineered IBM i's QSYRUPWD API by tracing SCV 10 CIPHER calls through disassembly and live memory patching, mapping how the system chains SHA-1, MD5, AES-128, and Rijndael-256 operations to protect password verifiers once QPWDLVL moves past the legacy DES/SHA-1 modes. The team reconstructed the full decryption chain and confirmed it recovers crackable DES, SHA-1, and NT hash material even at QPWDLVL 4, despite the API requiring *ALLOBJ and *SECADM authority to call.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">โก</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fclaude-ai-just-cracked-post-quantum.html%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/Vph_M7WevIU9rRI-S0sBx2wAO_Nc80AUVyjJvLoN5Vg=452">
<span>
<strong>Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Anthropic said its Claude Mythos Preview model found a new lattice symmetry to fully recover HAWK-256 signature keys and cut the cost of a seven-round AES-128 meet-in-the-middle attack by 200 to 800 times, though both results stay far from threatening production HAWK-512/1024 or full ten-round AES-128.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fsecurity%2F2026%2F07%2F28%2Fdef-con-bans-meta-style-pervert-glasses%2F5279763%3Futm_source=tldrinfosec/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/uJMJgWGuatwRRmstxwEdoB6fOWC_as5SaqYQzE6WGdE=452">
<span>
<strong>DEF CON bans Meta-style 'pervert glasses' (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
DEF CON has banned Meta-style camera-equipped smart glasses ahead of its 2026 Las Vegas event, joining Monopoly Events and Scottish ferry operator CalMac in restricting discreet recording devices due to increasing privacy and consent concerns.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/zlim8u_tAgw1zxwxIydKJ8cmaIk2zu8bUzKoz2EsAm0=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/KiBEDuTYGihQ3I59wMxaz4_BQ-zemOE9l-2NcoKvXms=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? ๐ฐ
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/TSzgGzESrFEyV3lreb8Ja4J0YXXUbVS87RGK8I311f8=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? ๐ผ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/bF3p6Hb0INSedlOEJdepftH_6XzpqS2Ci5kXJlEsmfU=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/tsCjRX5cpTL_A1AS0-BBiTLrTDUlOt6D3s_iYAtF1P0=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/mDh87eddhEQFJ92xgPnvPC4qdbuiqGmiZXhmVDfBCac=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/Qlj04HXt8KC3fG1RkEL5eK_Uyge64Uw7XF1WMDCd_d8=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/TpcYbK6JG00qTFbItlJxQdjAzbioSW4QwVDn9DQcC04=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/qIgB7RqujGBeoBJfjewp9iYRWmcPytGx5rjCNq_z2oE=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/rjuSFeIJlA9Rk4XMIFKqJdksWSGVjQtHrIELwovJmOk=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=51dbfb24-8b16-11f1-98dc-67da35eba588%26pt=campaign%26pv=4%26spa=1785330069%26t=1785330588%26s=d0320c4dba2a7863787c9aacc08ecb7171ac1d7cf75a445748294f180c7b755d/1/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/imFHYh7oFz0wU0AcJoX0IJE-9hKayTnPkxIIfwM6ysQ=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fadfedbaa-4af97a2e-3ac4-453c-8449-b1dae18b6cc4-000000/j72_h3s64toDIPk_D2YNpbqWjHb14ILVuSpLazoSBWo=452" style="display: none; width: 1px; height: 1px;">
</body></html>