<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">The Rails framework for Ruby disclosed a new vulnerability in Active Storage that could enable arbitrary reads. The vulnerability is exploitable </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/lUmxg2g_x8LM4lXXRJgn2mdm-DCztNTmbQznoLJFciM=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/RKptaVA8gmf82C2owOtjrUlKrp5-P1tuAmkwbO4A7qM=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=014e4cb8-8f2e-11f1-a941-2ba36a083637%26pt=campaign%26t=1785762474%26s=43a7edd08f3d20c5214fb30471885bf244c32bdc361d5897ced299784302956d/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/aFHovX1kEqNKMTFmAicSCSMkc8Nh6pCIgBP_9RFEUzI=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.hipconf.com%2Fwhy-attend%2F%3Futm_source=tldr%26utm_medium=pd%26utm_campaign=2026-08-03_Primary_Semperis%2BTechnologies%2BInc%26utm_content=header_identity_security_heart/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/6AKb8RvW3DGNKHvM4ikQPi863Ov6ASa_H8aMb35Dt_U=452"><img src="https://images.tldr.tech/semper.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="Semperis"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-03</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.hipconf.com%2Fwhy-attend%2F%3Futm_source=tldr%26utm_medium=pd%26utm_campaign=2026-08-03_Primary_Semperis%2BTechnologies%2BInc%26utm_content=header_identity_security_heart/2/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/F-Dx2JvxtSfLXVHCUKYx3jndppR5HHqVFtlHij1bGgQ=452">
<span>
<strong>Identity security is at the heart of cyber defense. Meet with the people that get it (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
You don't need to solve identity security on your own.<p></p><p>The <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemperis.swoogo.com%2Fhipconf26%2F%3Futm_source=tldr%26utm_medium=pd%26utm_campaign=hip-nashville-reg%26utm_content=body_intro_hybrid_identity_protection_conference/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/C_3S-V48lnsafQz_Xh_9_S_Q3NoFJD00Q2ZUzZHYu9I=452" rel="noopener noreferrer nofollow" target="_blank"><span>Hybrid Identity Protection Conference</span></a> puts you in the room with experts, practitioners, and leaders who understand the stakes and are ready to share what works. </p>
<p><em>“HIP is the only place you can find this many people who can dive this deep into identity management and identity protection.” —</em>David Rowe, Active Directory Security Engineer, Harvard University</p>
<p>HIP Conf 26 is <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.hipconf.com%2Fwhy-attend%2F%3Futm_source=tldr%26utm_medium=pd%26utm_campaign=2026-08-03_Primary_Semperis%2BTechnologies%2BInc%26utm_content=body_outro_where_identity_security_community/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/3a0PBHU1LCz-Jf1CVowkSJyN-TUT-yuUhmjszvJrr-A=452" rel="noopener noreferrer nofollow" target="_blank"><span>where the identity security community connects</span></a>.</p>
<p>Join us for masterclasses, cutting-edge security research, and the sorts of hallway conversations that spark lasting relationships. September 8-10, Nashville. </p>
<p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemperis.swoogo.com%2Fhipconf26%2F%3Futm_source=tldr%26utm_medium=pd%26utm_campaign=hip-nashville-reg%26utm_content=cta_register/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/kb92Nc4ckdQ6CH35aJsmUwSZaJFa0VBq_UVc1HmD88U=452" rel="noopener noreferrer nofollow" target="_blank"><span>Register now.</span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theguardian.com%2Ftechnology%2F2026%2Fjul%2F29%2Fdepartment-for-education-police-hackers-cybercrime%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/s5S_2MvYvP1XVkGj75V3rN-h8kiVrRubzUtSr32c1Jc=452">
<span>
<strong>Hackers Steal Sensitive Data from UK Department for Education and Police (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The UK's Department for Education (DfE) and a police database were hacked by a new ransomware gang which stole 740k lines of data. The DfE's data was stolen from a help-desk portal and includes full names, email addresses, phone numbers, and job titles for staff and parents. The police database that was compromised provides legal assistance to UK police forces and includes names, the force or organization they're assigned to, and work email addresses.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FEHCxix/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/j2fjKMY1znwa4d7o4gWG5R1WulhsLK6xPZWSITvGJLE=452">
<span>
<strong>Rails Patches Critical Active Storage Flaw with RCE Potential (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Rails framework for Ruby disclosed a new vulnerability in Active Storage that could enable arbitrary reads. The vulnerability is exploitable when libvips is used, and the server allows for image uploads from untrusted users. Security researchers highlighted that this vulnerability could be exploited to read the Rails master key, which could compromise all cryptographic operations and lead to RCE.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FKg8z24/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/3YLeq-2aFL8P5bh_ayMX1TtKL_ks4C0qFXHMY_e-jZc=452">
<span>
<strong>Amgen Says Cloud Data Breach Exposed Patient Health, Proprietary Info (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Pharmaceutical company Amgen stated that it suffered a data breach after attackers stole data via a third-party cloud provider. Amgen stated that the stolen data includes proprietary information and patient PHI, but they have not yet determined whether additional data was stolen.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fback.engineering%2Fblog%2F31%2F07%2F2026%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/GLCEa6KE0CsLHJ8tARlMOa1z9SycJrBDx9Pw4crd1Uk=452">
<span>
<strong>Static Devirtualization of Tencent VM (10 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Back Engineering Labs published a technical devirtualization of Tencent's ACE anti-cheat VM obfuscation, detailing how the .tvm dispatcher preserves CET shadow-stack and SEH/unwind semantics via boxed native instructions, RDSSPQ/INCSSPQ balancing, and phantom unwind info, and how guided symbolic execution recompiles virtualized functions back to native code. The team reported 815 of 865 virtualized functions (94.2%) recovered across four ACE kernel drivers, offered a third party for independent validation, and flagged ranged for-loops as a known limitation causing infinite-loop mis-lifts.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.huntress.com%2Fblog%2Fmacsync-stealer-rat-reverse-engineering%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/_iRLdAcI0nrNeE1M87rMtiOvS4_IOkSdTqwfe5uGfcQ=452">
<span>
<strong>Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker's Servers (35 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Huntress traced a malvertising chain that walked a victim from a poisoned Google ad through a weaponized claude.ai/share page into a curl|zsh loader, unfolding into a six-stage macOS kill chain that phished Full Disk Access and a confirmed account password, then dropped a native Mach-O RAT, a signed Screen Recording helper, and trojanized Ledger/Trezor wallet apps rewritten in place to phish BIP39 recovery phrases. The tradecraft resembles the AMOS/Atomic Stealer lineage based on shared techniques and Russian-language code comments, which Huntress frames as a family resemblance rather than named-actor attribution. Defenders should hunt behaviorally for curl -k piped into zsh, a com.apple.* LaunchAgent paired with a ~/.local/.mpwd file, and ad-hoc-signed apps whose ElectronAsarIntegrity hash doesn't match the shipped app.asar.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fveganmosfet.codeberg.page%2Fposts%2F2026-07-27-opus5%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/AD6oWDgma253kXgZculMgD-t3-FTYUbEPFpBVtfcNr0=452">
<span>
<strong>From /init to Code Execution - Prompt Injection Experiments with Opus-5 in Claude Code (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The author of this post ran an experiment in which they had Claude Code running Opus 5 in yolo mode analyze a hit repo which contained an image file with a hidden message that led the model to a Star Trek-themed challenge. The challenge is a web server that features six challenges, with the final two requiring the model to download and execute a remote Python script which contains an encoded malicious command. Opus 5 determined that it shouldn't directly run the script but extracted and ran the malicious command, believing that it contained the solution to the challenge.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.hackingarticles.in%2Fimpacket-for-pentester-atexec%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/Ydrz7U-NPMwCIU0p7-SgOPAwt2epApSDqX_a_-zWGQQ=452">
<span>
<strong>Impacket for Pentester: atexec (12 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
This walkthrough walks through Impacket's atexec module across the full Windows Task Scheduler (ATSVC/TSCH) abuse chain over SMB, demonstrating plaintext, Pass-the-Hash, Pass-the-Ticket, and Pass-the-Key execution against a Server 2019 DC before weaponizing a Base64 PowerShell payload with -silentcommand into a full interactive reverse shell. It's a solid operational reference rather than new tooling, no repo to evaluate, though the closing detection notes add real blue-team value.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fgoogleprojectzero%2Fsandbox-attacksurface-analysis-tools%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/oqapF0vNODxu8JAx42EJVHl9IKbNQIFvrCVzHNPx9Pg=452">
<span>
<strong>sandbox-attacksurface-analysis-tools (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A collection of tools from Google Project Zero to analyze Windows sandboxes for exposed attack surface
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FMatheuZSecurity%2FFurtex%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/4QmRD-NCAURChczR2PD8cGBCq5nPmFj-dNovJwal1RA=452">
<span>
<strong>Furtex (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Furtex is a post-exploitation and evasion research toolkit for Linux, built around io_uring and eBPF.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="mailto:infosec@tldr.tech?utm_source=tldrinfosec">
<span>
<strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F0xdbgman.github.io%2Fposts%2Finside-the-falcon-how-crowdstrike-catches-you%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/oW1Hs549OgLTa40XNt14nGBEV5qWhSchMa3m9CHNiTI=452">
<span>
<strong>Inside the Falcon: How CrowdStrike Catches You (21 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A reverse-engineering teardown mapped csagent.sys's full detection surface: six kernel callback sources (process, thread, image, object, registry, and file), a firewall-grade WFP network engine capable of injecting TCP resets to kill C2 flows, an FLTMGR minifilter hooking 12 IRP majors, and the cspcm4 "pinned" broker module. The dissection traced verdicts to a single vtable call into g_DetectionEngine, a detection object loaded at runtime from cloud-pushed channel files rather than compiled into the driver, and documented seams including a user-mode-only trust boundary on Object/Registry callbacks, hash-or-signature resolution failures that skip full rule matching, and a 10,000-flow WFP tracking cap. The author tied this same swappable cloud-content architecture to the July 2024 CrowdStrike outage, attributing that crash to a bad channel-file object rather than a code defect in the sensor binary.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftrufflesecurity.com%2Fblog%2Fscanning-7-6-petabytes-of-ai-training-data-for-secrets%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/BrtPxc__AQh6kYdmh5FJcFv84pENhsvqLhlPq62zzS8=452">
<span>
<strong>Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets (12 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Truffle Security scanned all 7.6 petabytes of public Hugging Face datasets (187 million files) with TruffleHog and found 221,303 live, unique credentials across 6,003 datasets, including 349 GitHub PATs with repo-write/CI/admin:org scope, 318 Docker Hub push tokens, 8,557 live GCP service-account keys, 8,594 working database logins, and 742 OpenAI plus 26 Anthropic keys carrying a conservative $920K/year inference-abuse floor. Leaks compounded through scrape corpora like The Stack and Common Crawl, with 44% of unique secrets appearing in more than one dataset and one AWS key, pasted into a chatbot, mirrored across 1,131 datasets. Hugging Face was notified pre-publication and contributed native storage-bucket scanning to TruffleHog. The company withheld all names, dataset paths, and key material, and recommends scanning corpora before publishing or training and treating any publicly exposed key as burned.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fpostquantum.com%2Fsecurity-pqc%2Fdigicert-quantum-readiness-outlook-2026%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/KAUIm-hTS_99VKkDqkl7AJ3G3CbTqN_XoG86F5GVB4E=452">
<span>
<strong>87% of Organizations Are Pursuing PQC. Only 7% Have Deployed It (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
DigiCert's second annual Quantum Readiness Outlook, which surveyed 1,001 IT and security decision-makers across the US, UK, and Australia, found 87% of organizations are planning, testing, or implementing PQC, yet only 7% have deployed quantum-safe or hybrid certificates at scale, up less than two points from 5% a year earlier. The analysis argues the barrier data (legacy complexity, performance, and budget) shows this has shifted from an awareness problem to an execution problem, and flags that the certificate-only metric masks progress elsewhere while saying nothing about the arguably more urgent Trust Now, Forge Later signature-forgery threat.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgbhackers.com%2Farch-linux-suspends-aur-package-adoptions%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/IMFHiA2yXMe2mRIL0GfrAb9FxMu6bv9mGrHX8vuopgQ=452">
<span>
<strong>Arch Linux Suspends AUR Package Adoptions to Block Ongoing Malicious Commit Campaign (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Arch Linux's DevOps team disabled AUR package adoptions platform-wide on July 30 after attackers began systematically adopting orphaned/unmaintained packages and pushing malicious PKGBUILD commits that execute payloads via makepkg.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.crowdfundinsider.com%2F2026%2F08%2F294588-singapore-launches-ai-cyber-risk-taskforce-to-bolster-financial-sector-resilience%2F%3Futm_source=tldrinfosec/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/bkIMNCqhOiLRe0WqBT8UBw-tuaDvJBfd9t4BXpbaU5E=452">
<span>
<strong>Singapore Launches AI Cyber Risk Taskforce to Bolster Financial Sector Resilience (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
MAS and the Association of Banks in Singapore launched the AI-Driven Cyber and Technology Risk Taskforce (ACT), uniting DBS, OCBC, UOB, SGX, NETS, and BCS since May to share AI threat intelligence, run proof-of-concept trials of AI-enabled defense tools, and develop sector guidance against frontier AI-driven attacks.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/Vi58wq6x0qM75gbxGMrcofFGSlS8Zt8lEiwurVxFN_0=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/xMbf7CxBc3vxKv5XH77tFi9iSJ8NriM7la5RJHAhI6M=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/lcTJ-d3O9G5HfZJlxRsQfav1GenRedKkhrUeg0UwawU=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/Kn7L_gnmUbUTfJ1SSVKtPzeWk4DGpulC-U7kOV3lr8s=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/Em0uMK277C9dCAHpJbxpY0ilbpANB0BCP74d_TcQu3k=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/mcw3HA-V2vDQkp93q-cIeGSgFmVvNYO6VOwSWrUjBAQ=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/cblWtilL4G6pz_qewQMA05dGCoP_MUzJ23_JO1kMkAc=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/NTue0J3dMEx_zeJIaE9TRi2PyJ-XKF8bH3uUMAEzHWQ=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/gMZcU6P3nrSuVikirP-ahLw3oDQH7N4Jq-hhdt8t1oA=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/Fxwrcpr5_6bsyHNQmfA0aBkUTVQEvKgGBr6Z_pfD0gA=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=014e4cb8-8f2e-11f1-a941-2ba36a083637%26pt=campaign%26pv=4%26spa=1785762033%26t=1785762474%26s=2486d25888ffc9a676e6e0c5d7288a261f05808c51807b62234ffa1b42779cd0/1/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/h2Ox6KOPXFWdZw7403Z-JxiipuW8T6bRNDIlkCQixk4=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fc7bceb6f-b8cde0c0-ff95-4a0b-9c32-f209709eac48-000000/ihEphrXxEdD-8GIZhUNqXApOIsijNc_bdxSNTWa49XE=452" style="display: none; width: 1px; height: 1px;">
</body></html>