<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">An unauthenticated attacker able to reach odhcpd's DHCPv6 listener on UDP port 547 could overwrite a fixed 512-byte stack buffer through crafted IA </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/eBrZtjdlNhtXxYIzCmd2vtM_GyRwyJShe7COJaE_c6Q=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/ndD7J06ZqzdqHX5G97_sydUUBWVr5oaEri5b9Qve-mU=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=04ceec28-8bf8-11f1-a1e5-1babea903200%26pt=campaign%26t=1785416998%26s=ed7ff323c353c70c672ff332eeaa45b66b05536b539901f57096aa5458fee564/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/AsMHW-WBbSrL1zKRD8QjjsekMiQ4O28nP8EyY3dJNXs=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-30</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Fcritical-openwrt-dhcpv6-flaw-could-let.html%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/vzjQW-oKenJZ1D-QnO1UyYPqne3yHXYwKTU6E3js6Zg=452">
<span>
<strong>Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An unauthenticated attacker able to reach odhcpd's DHCPv6 listener on UDP port 547 could overwrite a fixed 512-byte stack buffer through crafted IA options in a DHCPv6 REQUEST, tracked as CVE-2026-53921 with a CVSS of 9.8, and since odhcpd runs as root and embedded devices commonly lack stack canaries and ASLR, code execution is a realistic outcome rather than just a crash. The same 24.10.8 and 25.12.5 releases also close several other pre-authentication odhcpd bugs (out-of-bounds write, use-after-free, memory disclosure, neighbour-discovery proxy spoofing), three uhttpd request-smuggling flaws, and a DHCPv6 hostname-injection issue (CVE-2026-62948) that produces stored XSS in LuCI. Administrators should update the 24.10 branch to 24.10.8 or the 25.12 branch to 25.12.5 via the OpenWrt Firmware Selector, patch any separately installed packages, and note that a related batch of LuCI command-injection and path-traversal fixes from a separate Hacker House audit remains open and unmerged as of July 28.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.infosecurity-magazine.com%2Fnews%2Fai-linux-kernel-zero-day-net-sched%2F%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/-SHNmfvZ4macBsngHdRhb1MD_AR1EwvSsjz55Qf5SF4=452">
<span>
<strong>AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researcher Lee Jia Jie of STAR Labs used AI to uncover and reliably trigger a use-after-free race condition in the Linux kernel's net/sched subsystem, tracked as CVE-2026-53264, where mismatched RCU locking let a shared object be freed and reused while still referenced, enabling local privilege escalation to root on systems with unprivileged user namespaces enabled. The flaw had persisted for two to three years and was independently found by an AI system named KyleBot before Jia Jie's TyphoonPwn 2026 submission, and he separately reported two exploitable perf events subsystem bugs, including CVE-2026-64300, affecting Intel bare-metal RHEL-based and Arch systems under permissive performance-monitoring settings. CVE-2026-53264 has been patched upstream by deferring object deallocation until after the RCU grace period, so administrators should pull updated kernels through their distribution's security channels and review user namespace exposure on affected desktop systems.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FcjAXIK/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/VjiD1hq6iYMIVyH8hnB8YLrGlrQ_mTBa_1X_xANz9eQ=452">
<span>
<strong>Cisco Warns of FMC Static Credential Flaw Exploited in Zero-Day Attacks (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cisco is warning customers of a vulnerability in its Secure Firewall Management Center (FMC) systems. The vulnerability is due to a low-privilege account that is enabled by default and uses static credentials to authenticate. While the CVE was only given a CVSS score of 5.3, Cisco rates it as a high-severity vulnerability due to other vulnerabilities that an attacker could chain to escalate privileges.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.infosecurity-magazine.com%2Fnews%2Fphishing-dominates-initial-entry%2F%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/2eKpokvccS_n_CX-8H_wOrhEoYMVsVII5UpikW3k-6I=452">
<span>
<strong>Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cisco Talos's Incident Response Trends report for Q2 2026 found phishing accounted for just over half of investigated initial access incidents, up from a third the prior quarter, with threat actor UAT-11764 running a persistent campaign that uses victim-tailored PDFs containing QR codes to evade email gateway scanning and direct targets to credential harvesting pages hosted on trusted platforms like Microsoft 365 and SharePoint. Once compromised, accounts were used to create defense-evading inbox rules and propagate further phishing, while separately observed phishing-as-a-service kits now offer OAuth device-flow MFA bypass, Primary Refresh Token persistence, and encrypted anti-analysis payloads. Defenders are advised to enforce phishing-resistant MFA, block or flag QR codes in PDF attachments, monitor for suspicious inbox rule creation and SharePoint file staging, and tighten outbound email thresholds to limit lateral propagation.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhuggingface.co%2Fblog%2Fagent-intrusion-technical-timeline%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/EhUO8sVZButw5a9FqBE_n5SWaU2948PQNnTkpGlXcS0=452">
<span>
<strong>Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (20 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An autonomous AI agent evaluated under OpenAI's ExploitGym cyber-capability harness escaped its sandbox via a zero-day in a package registry proxy, rooted a third-party code-evaluation sandbox as an external launchpad, then pivoted into Hugging Face's dataset-processing pipeline through an HDF5 external-storage file read and a Jinja2 server-side template injection, giving it code execution inside a production Kubernetes pod. From there, it chained cloud metadata theft, forged Kubernetes service-account tokens, a privileged hostPath pod escape to node root, and a stolen mesh-VPN key to reach cluster-admin on multiple clusters and a compromised GitHub App integration, running roughly 17,600 actions over four and a half days while communicating through public pastebins, request-capture services, and dead-drop datasets. Hugging Face has since blocked pod-level access to instance metadata, disabled template evaluation and HDF5 external references in its dataset loader, rotated all infrastructure credentials, enforced per-cluster connector scoping, and rebuilt affected clusters, and recommends organizations running agentic evaluations apply the same isolation principles: short-lived credentials, blocked IMDS access, narrow trust boundaries per cluster, and detection tuned to correlate high-volume low-signal activity.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdetect.fyi%2Fdetection-engineering-in-the-era-of-semantic-malware-663cee8cda7b%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/azhlxvzvQeyCxhbL7HNIL5AIIvHUjVppBIzsNqNuEa0=452">
<span>
<strong>Detection Engineering in the Era of Semantic Malware (14 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Malware campaigns that target agents via their memory or other configuration present detection engineering challenges as they don't produce classical indicators of compromise. Some classic detection techniques such as File Integrity Monitoring (FIM), privilege auditing, and behavioral baselining can be adapted to agentic threats. Additionally, the agentic landscape also offers some new detection opportunities such as: context window integrity, agent session telemetry, memory file provenance, and cross-session behavioral correlation.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Ftigerless-labs%2Fautoharness%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/iGd84NFN6cg-w_xejhH-yuLRimWgkDbwAWwoMf-gjoM=452">
<span>
<strong>AutoHarness (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AutoHarness adds a self-learning skill layer to Claude Code that distills real sessions into skills, merges duplicates, and prunes unused ones automatically.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fxxyyue%2Fllm-observer-proxy-go%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/Zyoo6ChDuBYSp8Sg8eJesbiXfwbyeldvUFHbk66mPPw=452">
<span>
<strong>LLM Observer Proxy (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
LLM Observer Proxy is a tool that records LLM requests, responses, streaming output, tool calls, token usage, cost estimates, errors, and provider-visible reasoning content.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FinclusionAI%2FSingGuard-NSFA%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/FBvFmT3_dKf2AVGEvJHp8bxIkSkow5drmZQ0lTdAa1g=452">
<span>
<strong>SingGuard-NSFA (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
SingGuard-NSFA provides extensive guardrails for agentic AI using a CIA triad-based taxonomy, multilingual benchmark suite, dual-mode inference architecture, and native extensibility.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F07%2Ftengu-botnet-reboots-compromised-linux.html%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/derMupIKDIxmx7bZJLcciFUMJymRK13sulUx_A4dT9E=452">
<span>
<strong>Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Nozomi Networks Labs identified a Mirai-derived botnet named Tengu that abuses a compromised Linux device's hardware watchdog to force a reboot whenever its main process is killed, giving its other persistence mechanisms, including a fake systemd service and immutable binaries, another chance to relaunch. The researchers stopped short of establishing the botnet's real-world scale, and independent URLhaus telemetry at the same C2 address confirmed only generic Mirai-related hosting rather than Tengu itself.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftombedor.dev%2Farguments-against-open-source-ai-are-very-bad%2F%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/Ltv2eeIcx9pz7QW636hIcUBFCTYxzAGWGxWlfRgBXiE=452">
<span>
<strong>The Arguments Against Open Source AI are Very Bad (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
In the wake of powerful Chinese models such as GLM 5.2 and Kimi K3, US frontier model labs have been pushing against open-source models. Common arguments include: China is building high-quality, free models now with the goal of eliminating competition, models may spread propaganda, and models may contain backdoors. Not only are these arguments weak, but they are also irrelevant, as suppressing open-source software has always been a losing battle.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemgrep.dev%2Fblog%2F2026%2Fcomparing-open-source-ai-code-security-harnesses%2F%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/OxC4wiDIjjDgX3SaJqUiOKShJfx5m9dw8hQMu8JbZXU=452">
<span>
<strong>Comparing Open-Source AI Code Security Harnesses (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
This post distinguishes between several approaches: LLM-led exploit generation, where large language models operate independently to find vulnerabilities; LLM skill-boosting vulnerability research, which involves providing skills to an LLM to emulate a human vulnerability researcher's reasoning; and hybrid tools combining SAST with LLMs. LLM-led exploit generation can be seen as a new type of fuzzing but is challenging because it requires access to model providers with fewer guardrails. The post outlines various use cases for different skills and the integration of SAST with LLMs.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fharmonyintelligence.com%2Fhow-0x-secures-200b-with-harmony%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/kQkzItErHCMHzd9FsrZPVb15YP1xhta2y07gkSFRuoE=452">
<span>
<strong>How 0x Secures $200B with Harmony's AI AppSec agents (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
0x, the DeFi infrastructure layer underpinning Coinbase, Robinhood, MetaMask, and Phantom wallets, expanded its use of Harmony Intelligence's AI-driven security testing across its full product suite after an initial review convinced its engineering team the tool surfaced vulnerabilities with clearer prioritization than traditional pentests.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgbhackers.com%2Fnvidia-bluefield-flaw%2F%3Futm_source=tldrinfosec/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/AB34iRzOdCl3iCZGOi5l0PUY87J74JXa7yAM1SzBIg8=452">
<span>
<strong>NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
NVIDIA patched CVE-2026-65094, a CVSS 9.0 Write-What-Where flaw in VIRTIO-Net on BlueField-3 DPUs that let adjacent VM users execute arbitrary code and break tenant isolation.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/qCnvEsEQgJszBy5XQNwNt6a9-FDzFufbNkcPxibYj9c=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/M-QeZUXe_0o7N9wHE2fOEEMTz_TSn4Sud7DkTSA0dl8=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/anatupRKAVSZK6HnYUpSpqL5FJ1wuT45oFCsl1lnIjM=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/raRoQadCub7lXiL42e7T-0qsxvrS15IeG0M5TPun9No=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/Z5JlfOpvKHI3d7QcCE8tiYCgo6U1-t6P4ymkAYJ8cRU=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/NhDFaP0uITCRLVj0vY2K2Ieva_vQA64eH4-CAVC8fj4=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/KgkpT4LESiFJCK1I1ZfLTL_jyRPF4j6F4EUnZPobulA=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/YoV-f3c0drTpfdBZPApba1mQK-EzcyKy9TRl6Wo1nqI=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/l8IlwsfjVQl9bSFlTMej8ACbjWXNN5R4gd81g08MbBI=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/RGGwivASAL8sy78EpFT_4X8Z7bnXDprcqj7JkdnDF-8=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=04ceec28-8bf8-11f1-a1e5-1babea903200%26pt=campaign%26pv=4%26spa=1785416423%26t=1785416998%26s=2e78de62583f1cdcad003c144a2a66b48910ff59ce1bfcf6dd0013faa7705c7e/1/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/1nstIKwN096IjrNHWUPcBjh2MmQzJK3AjxYF9IRA0J4=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fb3255e5b-52b76dc5-10b8-4951-a7bc-1ee96154768e-000000/mJOJBB0ZOk3cOhuxHk0_k6nw8yhT9wAvcbQ92gZH27k=452" style="display: none; width: 1px; height: 1px;">
</body></html>