<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Wiz Research bypassed Cosmos DB's Gremlin sandbox by abusing .NET reflection to achieve arbitrary code execution on the DB Gateway </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/A3_CCbi1JA-0WZRSMuwv-P34D7cNDipxpVRMAIj4_ww=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/fTjH9TehTHmBppxALiVRZQBvTWqW0skxfilwQMUj3IU=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=19c7d590-8cc0-11f1-840c-c9e22a0b7a34%26pt=campaign%26t=1785503333%26s=90a1e33b6067e577cc688d28958aae8ab1919d427545cc3a2c8fbe818cbf229f/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/cm2zWw_4kvWN_npy5AZKKbwU0dAgrA_TWPcCB0NJvIA=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-07-31</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.wiz.io%2Fblog%2Fcosmosescape-taking-over-every-database-in-azure-cosmos-db%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/-EQDqlGSmbrubyP6jvBelXnNa6ROsfQlU-2jsSkP31g=452">
<span>
<strong>CosmosEscape: Taking Over Every Database in Azure Cosmos DB (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Wiz Research bypassed Cosmos DB's Gremlin sandbox by abusing .NET reflection to achieve arbitrary code execution on the DB Gateway, then extracted a platform-wide "Cosmos Master Key" capable of retrieving any account's primary key and enumerating every database on the service by tenant or subscription ID, including Microsoft's own internal Cosmos DB-backed services like Entra ID, Teams, and Copilot. The flaw affected private and network-isolated accounts as well, since the DB Gateway itself enforced isolation and was the component compromised. Microsoft deployed a hotfix within 48 hours of disclosure, eliminated the master key entirely, and completed a hardened architecture rollout by July. There was no evidence of exploitation beyond Wiz's own testing.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.rapid7.com%2Fblog%2Fpost%2Fetr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails%2F%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/YgDKJNrgS5j-6FEfBbx4H8gk2EXjOnjLjptdxvysUvU=452">
<span>
<strong>KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CVE-2026-66066 (CVSSv4 9.5) lets an unauthenticated attacker abuse unfuzzed libvips operations during Active Storage image processing to read files accessible to the Rails process, potentially exposing secrets that enable RCE. Only the default Vips variant processor is affected, not Magick. Fixed in Rails 7.2.3.2, 8.0.5.1, and 8.1.3.1 alongside libvips 8.13+ and ruby-vips 2.2.1+, with no in-the-wild exploitation reported as of July 30. Rapid7 urges rotating secret_key_base and other exposed credentials, patching outside normal cycles, and applying Vips.block_untrusted(true) as an interim workaround where upgrading isn't immediately possible.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwts.dev%2Fposts%2Fsandbox-spawnattrs-escape%2F%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/IjLvi9idjvwIVorNBuj31tqIRhNn_CxMOth1qzar1zw=452">
<span>
<strong>Escaping the Apple Sandbox by Spawning an Executable (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CVE-2026-20628 let a sandboxed macOS process spawn a child with the posix_spawnattr_setmacpolicyinfo_np API specifying a more permissive built-in profile like no-network, which grants home directory access, then chain that into a shell config modification and Terminal launch to fully escape the sandbox. Researcher Noah Gregory reported the bug, which Apple patched in version 26.3 by blanket-denying built-in profile assignment for already-sandboxed processes unless they carry the com.apple.private.security.sandbox-spawnattrs entitlement. Defenders should ensure affected Apple devices are updated to 26.3 or later, as no more granular policy comparison was implemented.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.philvenables.com%2Fpost%2Fcontrol-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/RaVB0PT93xFHpn_izm0RIo8w2vz5rzf-_jNITmGi92o=452">
<span>
<strong>Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Most breaches stem not from novel attacker capability but from security controls that were believed operational yet were actually broken, misconfigured, or never fully implemented, proposing Control Reliability Engineering (CRE) as a direct port of Google's Site Reliability Engineering discipline onto security controls. CRE treats a "Control Incident" (a failed defense, regardless of whether it led to a breach) with the same severity as an actual security incident, applying SLIs/SLOs, error budgets, controls-as-code, continuous control monitoring, and synthetic event injection to catch controls that silently "read zero" while broken. Security teams should build a control ontology/catalog, adopt Control Readiness Reviews before production onboarding, and formalize blameless postmortems for control failures to shift from reactive ticket-based response to engineered, metric-driven control health.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fddosier-disects.medium.com%2Fthe-one-chokepoint-to-rule-them-all-why-i-deleted-50-clickfix-detection-rules-and-replaced-them-7c532206d32d%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/9f3-fiz912vWXvIinnResX4F21WeoOJXF1vzCeUwg1k=452">
<span>
<strong>The One Chokepoint to Rule Them All: Why I Deleted 50 ClickFix Detection Rules and Replaced Them With One (11 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
ClickFix attacks are a growing class of attacks that trick a user into executing a malicious command by prompting them to fix or otherwise diagnose a bogus issue. At the behavioral level, a ClickFix attack boils down to a browser process losing focus, followed by a native shell gaining focus, followed by a command containing a network call being executed within 60 seconds. The post contains this behavioral detection in several languages and a demonstration of it working against several variants.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fclaude.com%2Fblog%2Fciso-guide-to-agentic-ai%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/8NnPHinkgPeAk4CUiWqOXoQ5iDSh0lnGh_aVtTKbsOE=452">
<span>
<strong>Zero Risk Isn't the Job: a CISO's Guide to Agentic AI (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
This post outlines how Anthropic assesses risk for internal agentic workloads. To understand the risk associated with an agent, Anthropic asks what untrusted content an agent will ingest, what actions the agent can take, what the blast radius is in the case of misalignment, and what observability is available. Anthropic also defines an identity access model spectrum where agents may run as a self-contained, single-purpose, least-privilege identity that does one thing for the business with no human identity on one end and human credential agents where employees use an agent such as a chatbot or Claude Cowork directly on the other end.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fmanishrawat21%2FCisa-KEV-Threat-Intel-Orchestrator%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/VflLcYIXn9E3f0X3ABBkBDC0Wg6pTwhAyMvwQySbo2s=452">
<span>
<strong>Cisa-KEV-Threat-Intel-Orchestrator (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An n8n workflow that pulls newly weaponized CVEs from the CISA KEV catalog every Monday and uses Google Gemini to auto-generate Sigma detection rules with Sysmon EventIDs and MITRE ATT&CK mappings, logging each CVE to Google Sheets for compliance and emailing analysts a weekly briefing.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2F7h3kn0w3r%2FDedupInspector%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/fUGbTZzcwdbpLd9S2cAPes3KwmvZMW6XjlqWGZY3PlA=452">
<span>
<strong>DedupInspector (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
DedupInspector is a lightweight, portable, offline forensic utility for recovering files from Windows Data Deduplication volumes.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fchvancooten%2Fcode-needle%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/LjX-cNVNhP_MvC_Wjm7XrBUBicaSVsw7vtByWobU08M=452">
<span>
<strong>CodeNeedle (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CodeNeedle is a VS Code extension that silently exposes JavaScript code execution over a local HTTP endpoint. Once loaded into a target's VS Code instance, the extension listens on localhost for incoming JSON-RPC requests, evaluates arbitrary JavaScript code, and returns results to the caller.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgbhackers.com%2Flinux-xmrig-botnet%2F%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/ZaIK6wKpbbLPaz-BPGyVSnlyoWZ821l97CrISTPxGHY=452">
<span>
<strong>Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A V25 (Generation 26) cryptomining campaign gained initial access through a trusted third-party relationship, then weaponized Linux PAM's pam_rootok policy to move password-lessly from root into ordinary user accounts, fragmenting malicious activity across shadowed identities in a "hydra-like" persistence model. The customized XMRig 6.25.0 build self-unlinked its own binary after execution, running fileless from memory while suppressing authentication logs and masquerading its process listings and network traffic. The operation reflects a broader trend in Linux cryptomining tradecraft, where supply chain compromise, identity-layer abuse, and anti-forensic design are converging to outpace file-based and DNS-centric detection models.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cryptographyengineering.com%2F2026%2F07%2F29%2Fsome-notes-about-anthropics-new-results%2F%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/lRHebeWLNCOk6EM_BI8Igz8GCe4uuOQAoEVWfBufVVo=452">
<span>
<strong>Some Thoughts About Anthropic's New Cryptanalysis Results (10 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Anthropic recently announced that its unreleased Mythos model discovered two novel attacks against the post-quantum cryptography hashing candidate HAWK and a reduced-round AES variant. The HAWK attack was in fact novel, but it only effectively reduced the strength of the cipher by halving the bits, whereas the AES attack was a slight speed-up of a theoretical attack from 2013. The model was able to develop the attacks with a naive prompt, and from that perspective, the results are still meaningful.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.helpnetsecurity.com%2F2026%2F07%2F30%2Fcisa-sbom-guidance-updated%2F%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/2j6WnEAj_BPNsDlwiEt59auBrVpNRVMNqrl8IY2xBC8=452">
<span>
<strong>CISA Sets a New SBOM Baseline (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The CISA has released the 2026 Minimum Elements of a Software Bill of Materials (SBOM) to replace the NTIA's 2021 version. The new version introduces new elements including component hash algorithms, component licenses, the name of the tool that generated the SBOM, and the generation context. CISA highlights cloud software, AI, SBOM validation, and linking an SBOM to security alerts as future areas of development.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftherecord.media%2Fnorth-korea-hackers-ransomware%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/ZJrJ3yKwmmFqHFjDmXNXSadQzKQHHOp4oyp7X4vU2bU=452">
<span>
<strong>North Korea's Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AhnLab's "Operation Double Barrel" report found Lazarus and the Gunra ransomware group exploiting identical vulnerabilities in mandatory Korean financial security software, sharing malware filenames, C2 servers, and SSH key fingerprints while running parallel espionage (72+ organizations breached) and extortion campaigns across South Korea from 2025 into 2026.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.wired.com%2Fstory%2Fchrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now%2F%3Futm_source=tldrinfosec/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/qIBpMMcBmQaspo6V7e4qqAk384eNk0ezUUEFIsDgBYQ=452">
<span>
<strong>Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Google's Chrome security team fixed 1,072 bugs across June's two major releases, more than the prior 23 releases combined, driven largely by AI-assisted vulnerability discovery.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/sVb5KjfQBX5qvkZ-17fYCK7UJQdF8OdjftPkpIjLDzA=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/8TChYR8mBLqvsT85oW_NjMogSRqlK3nyZAABHQhhbCc=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/oxswZ01-CwztdHb2U64RLxodBFaCrRtvJFbmIZDgDqA=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/uBYt6eBgBtVqdQT2ls1eJJasEjFsDggnbuWGlhdKX1I=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/L4iw_9UdhHLlgor1pZhJd8Bn7dMg0h_4xPnhJEbPkZY=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/7WWHbN_E-NJsY1O96UyA8QkoVxOKld_BFLIxcaDNQoc=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/hu5kOd-XnS0V2LFuGvF5SSgDHDOXkJlAYfrcopAJ8KY=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/JfIU14omHLkNPszDFQK-d9dEYwgO_lM02fffeeySL20=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/SmRU4iDR5Elfb6vvCBlWfPWqICufwgGOVvpfS_0YYKA=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/7TrRxJ3YPYarkuy4FxvfrlVlpVKB9ZNLg6no2FMrKq0=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=19c7d590-8cc0-11f1-840c-c9e22a0b7a34%26pt=campaign%26pv=4%26spa=1785502822%26t=1785503333%26s=f55df72e234d4e667caf839d567b58f69b00e213d314cea86393ba4dacaf7510/1/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/7s2F_W5M8pZ6svf2nepOF5AqFGKpWqe3qbL0KWjP9q4=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fb84abbef-565d7830-de26-44f9-be0e-1ccd89090055-000000/CODLFdmT23id4RigTXOfmWqGfeZ1EU7Kh0l0A7MhaZI=452" style="display: none; width: 1px; height: 1px;">
</body></html>