<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">A new Shai-Hulud worm variant has compromised over 1,280 npm packages, including the well-known Keyv library, by injecting malicious commits </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/ASufFqYYlRbwU2g0qgbNddXpFRjtG6nS-iOwyAOgBGQ=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/IN6Bq2F0Q6TfylwvYSg7W_tN_6x6uEjyED02BlTyC5Y=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=88091d48-915c-11f1-ba4a-7d4984454734%26pt=campaign%26t=1786021743%26s=aff725556c35ef07cc420653740ec138c47676af40b198e0a8809a631198925e/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/0NxBElHSzWwg5zkxPDqB4ViDxZYvobsRRkVMSWBX5F4=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.tines.com%2Faccess%2Fguide%2Fthe-it-and-security-field-guide-to-ai-adoption%2F%3Futm_source=TLDR%26utm_medium=paid_media%26utm_campaign=2026-08-06_Primary_Tines%26utm_content=newsletter-primary-0608_header_before_you_invest/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/v5XrN9bVZpPR84sKLUrZA_X-YeqrYrMMXftS3kaiTTc=452"><img src="https://images.tldr.tech/tines50.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="Tines"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-06</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.tines.com%2Faccess%2Fguide%2Fthe-it-and-security-field-guide-to-ai-adoption%2F%3Futm_source=TLDR%26utm_medium=paid_media%26utm_campaign=2026-08-06_Primary_Tines%26utm_content=newsletter-primary-0608_header_before_you_invest/2/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/3cOAbzF3fWOUBh3nERjiELh1HWlcoj8usB88TVGLORY=452">
<span>
<strong>Read this before you invest in AI tools (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AI is everywhere right now. But for many teams, the reality hasn't matched the promise.<p></p><p>So what's <em>actually</em> working?</p><p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.tines.com%2Faccess%2Fguide%2Fthe-it-and-security-field-guide-to-ai-adoption%2F%3Futm_source=TLDR%26utm_medium=paid_media%26utm_campaign=2026-08-06_Primary_Tines%26utm_content=newsletter-primary-0608_cta_tines_recently_released/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/FP8_pK-UaZ_yxG_N6Er4octjX-dzYxWilz8clKigw_A=452" rel="noopener noreferrer nofollow" target="_blank"><span>Tines recently released a guide</span></a> that takes a more practical look at AI adoption for security and IT teams. Inside, you'll find:</p>
<ul>
<li>A framework for <strong>evaluating tools beyond the demo</strong></li>
<li>A step-by-step approach to selecting tools that <strong>hold up in production</strong></li>
<li><strong>Questions to ask</strong> before committing to a vendor</li>
<li>Best practices for <strong>keeping humans in the loop</strong></li>
</ul>
<p>If you're thinking about AI beyond experimentation, this is a useful place to start.
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhackread.com%2Fshai-hulud-npm-worm-poisoning-1280-packages%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/gWSJEnWGCmOP_sj3CQxDvjIQkUprTnJmgoZsB6r-Hro=452">
<span>
<strong>Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A new Shai-Hulud worm variant has compromised over 1,280 npm packages, including the well-known Keyv library, by injecting malicious commits via hijacked GitHub Actions pipelines. The worm employs a preinstall hook to download Bun and run an obfuscated payload that aggressively extracts developer and cloud credentials such as AWS, Kubernetes, and Vault, which it then uses to spread further. Organizations that have installed affected versions should assume an immediate breach, requiring them to rotate all secrets immediately and perform manual log reviews, rather than waiting for scheduled vulnerability scans.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Fzfyf2M/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/-35DKTj7iStH0P3fBePtQK9qLi1NoTEJEmJKmxfABTU=452">
<span>
<strong>77 Open VSX extensions found harvesting developer info (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Manifold Security uncovered an "evil twin" campaign on the Open VSX registry involving 77 malicious extensions that impersonated legitimate packages to harvest developer environment data. While claiming to only collect anonymous metrics, the most aggressive variants actively exfiltrated OS usernames, workspace paths, Git commit hashes, and CI/CD infrastructure details to mangorbit[.]com, utilizing DNS TXT lookups for C2 resilience. Although Open VSX removed the packages on August 3, security teams should block the C2 domain and manually audit developer environments for the malicious extension IDs.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.bbc.com%2Fnews%2Farticles%2Fcr7km34z112o%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/keyHahK25bvoDTTve4q09Cs2CCXWtow02sHUhusEVWY=452">
<span>
<strong>English National Ballet Suffers Supply Chain Attack (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
English National Ballet (ENB) disclosed that customer information was stolen via a breach of its customer relationship management (CRM) system. ENB stated that no password or financial information was stolen and advised customers to be vigilant of phishing emails.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frotcee.github.io%2Fposts%2Fanalyzing-the-mersusys-mb115-4g-router%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/ywk-K0oZUUl-mF5_BTgrDbQlfphYBT0dRendUUQE1IQ=452">
<span>
<strong>Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router (16 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researcher Rotce rooted the Mercusys MB115-4G, Amazon Spain's best-selling router, via UART and traced a pre-auth path in /usr/bin/httpd where http_gdpr_decrypt copied up to 2048 bytes of AES-decrypted, attacker-controlled data into a 512-byte caller buffer with no bounds check, tracked as CVE-2026-12495. The bug was surfaced through disciplined static analysis rather than a working exploit, following the routing table into the login handler in Ghidra and confirming with Ghidriff that the flaw persisted unpatched from v1.7.0 through v1.9.0. Mercusys' own validation reproduced the crash and shipped a fix in v1.11.0 that added the missing bounds check, moved the login decrypt path from RSA to ECC, and introduced HMAC verification.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FHDJZE2/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/W3U2tiPKeVKTxYdliChM2HBnhIWfFkogZmenx310E7g=452">
<span>
<strong>Phishing service spoofs RingCentral to steal Microsoft 365 accounts (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Greatness phishing platform recently bypassed email filters by spoofing RingCentral voicemail alerts to target organizations that had blanket-whitelisted the domain, despite the lures failing standard SPF, DKIM, and DMARC checks. Once clicked, the attack routed victims through an adversary-in-the-middle (AiTM) flow to steal MFA-approved tokens, allowing attackers to replay them from remote VPNs and stealthily siphon Microsoft 365 data for weeks. To mitigate this threat, defenders must immediately replace broad safe-sender exclusions with strict authentication requirements, hunt for anomalous MFA sign-ins originating from hosting providers, and comprehensively revoke access tokens if a compromise is suspected.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cauchy.org%2Fblog%2Fincident-response-notebooks%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/N1mgBIlyBf-j5-VFx6IZiZFbZSZOwIsn9l9f-M42GcE=452">
<span>
<strong>Agentic Incident Response Notebooks (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The DNB Cyber Defense Center's incident response team used marimo to build out incident response workflows as modular notebooks. The team developed a custom SDK for cross-platform query translation across Splunk, Defender, and SQL interfaces while utilizing marimo's native cell dependencies and caching capabilities. The marimo-pair agentic interface also allows agents to create and execute the same notebooks as human responders.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_medium=referral%26utm_source=tldr/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/ntdA05cCLYdB4A7a68EfDhNzJ540iIsIpvZArqNGrx0=452">
<span>
<strong>6,000+ "guardrail-free" AI models. One download away. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AI-powered cybercrime is no longer just a future risk. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/Fe4pyDwd0AedL6lVTZR_gIbStCcopy3lPM6BXW_Axdo=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown's </span></a>new research found it's already here, hiding in plain sight on infrastructure organizations already trust. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F/2/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/q9dZmxwX07t5mWbKu7wu5BQSwgx5ug1ES2ZMMeyQx7k=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown</span></a> researchers assess that AI capable of exploiting vulnerabilities at scale could reach criminal marketplaces within roughly six months. Read the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_medium=referral%26utm_source=tldr/2/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/QfIFgekaLOftFYo19R5w0qF0aVaU2Uh__3B6pIEejuY=452" rel="noopener noreferrer nofollow" target="_blank"><span><em>Cybercrime in the age of AI</em></span></a> report.
<p></p>
<p>
</p>
</span></span></div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhackread.com%2Fairlock-digital-unveils-agentic-ai-control-governance-to-extend-preventative-endpoint-security%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/EDdq4gHcnWBpU_M8A8O8YRFexWPN13KDvBdC94-gbAQ=452">
<span>
<strong>Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Airlock Digital extended its application control platform with Agentic AI Control & Governance, adding command- and session-level visibility into trusted AI agent behavior plus real-time policy enforcement that communicates decisions back to supported agents rather than simply blocking them, targeting Q3 2026 general availability.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fadithyan-ak%2Fagenthound%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/SCgZ9FiEmCZC2nKMJhh690CHE4MBQdMlM1g6PMV4tAs=452">
<span>
<strong>AgentHound (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AgentHound is an open-source offensive security framework for AI agent infrastructure that can perform recon, fingerprinting, credential looting, system prompt inventorying, model inversion, tool and instruction poisoning, and config-implant persistence and exports results to a Neo4j graph.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fsliverarmory%2Fbeignet%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/O0eijirHw-u8M6WW7V6A7hmzTFE9mdmUJg63O6Rq-7Q=452">
<span>
<strong>Beignet (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Beignet is a tool to convert .dylib files into macOS PIC shellcode.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;"> <div class="text-block"><span><a href="mailto:infosec@tldr.tech"><span><strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong></span></a><br><br><span style="font-family: ;">Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!</span></span></div> </td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsibouzitoun.tech%2Flabs%2Ffrom-stack-overflows-to-modern-pool-grooming%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/UC5eVtGwf-DpHqbLok3aZwtAPuDcgN4x0f3uMGRrT6w=452">
<span>
<strong>HEVD: From Stack Overflows to Modern Pool Grooming (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
This four-part series traced the arc of Windows kernel exploitation on a deliberately vulnerable driver, moving from classic stack corruption and SMEP-bypassing ROP chains through arbitrary-write primitives into pure Data-Only attacks. The later stages reflected how modern Windows 11 mitigations, which strip kernel pointer leaks and harden execution hijacking, have pushed offensive research toward kernel pool grooming and named-pipe-based heap manipulation instead. The progression illustrated a broader industry shift: privilege escalation research increasingly abandons control-flow hijacking in favor of data-only techniques that sidestep control-flow integrity protections entirely.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Fo8FRQj/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/ILF1dbpW28iEmOh48Rq0xUYkfxtO37vF_bePynddn9k=452">
<span>
<strong>New Pass-Ta-Key Attacks Let Malware Hijack Google-Synced Passkeys (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Palo Alto Networks' Unit 42 has released details of three new attack techniques, which it calls Pass-ta-key, that an attacker with access to a TPM-equipped Windows device can use to abuse Google Password Manager's synced passkeys to steal passkeys. The first technique allows the attacker to impersonate a trusted device and request a valid authentication response for one of the victim's passkeys. If a site checks the User Verified flag of the response, the authentication can fail. The other two attack techniques go further by allowing the attacker to register their own user-verification key or even obtain the master key, which is used to encrypt all passkeys synced through the victim's Google Password Manager.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdatabreaches.net%2F2026%2F08%2F05%2Fcanadian-man-pleads-guilty-to-hacking-u-s-cloud-storage-provider-and-extorting-its-customers-for-millions%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/bpY9M6aW_YNIfI1wepwyk0bd1e3cOYF2vSThSvm0pfU=452">
<span>
<strong>Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider and Extorting Its Customers for Millions (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Connor Riley Moucka pleaded guilty to multiple federal charges after using stolen credentials to breach over 165 SaaS customers between February and October 2024. The campaign compromised billions of records across more than 100 million individuals and caused roughly $9.5 million in corporate damages. Moucka successfully extorted over $2.5 million from his victims and now faces up to 30 years in federal prison at his upcoming October sentencing.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcyberscoop.com%2Ftrump-ai-executive-order-open-source-strategy-sean-cairncross%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/vvRZaAcAL_pbWaLSaarDMRQTsIVpB5havCSCjnnbI-E=452">
<span>
<strong>National cyber director lays out White House plans to secure AI without writing new rules (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
National Cyber Director Sean Cairncross announced at Black Hat 2026 that the administration will bypass new AI regulations in favor of voluntary industry-government information-sharing, a deregulatory stance facing renewed scrutiny after OpenAI models reportedly escaped a test environment to hack Hugging Face last month.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinuxiac.com%2Ftails-7-10-1-emergency-release-fixes-critical-kernel-and-expat-flaws%2F%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/1imi7BEFMGVRHCGp3x2ncX_daQmd_X6kFo09a7OsdB8=452">
<span>
<strong>Tails 7.10.1 Emergency Release Fixes Critical Kernel and Expat Flaws (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Tails issued an emergency 7.10.1 update to patch a critical Linux kernel vulnerability (CVE-2026-64560) that could allow a malicious website to escalate privileges and completely deanonymize Tor Browser users, alongside secondary security fixes for the Expat XML library.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fopenai-disrupts-poipet-scam-network.html%3Futm_source=tldrinfosec/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/QyxwFSucLb5pN5VJBEmMjTkMNBNGSt09dGQVIwYjBvY=452">
<span>
<strong>OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenAI and WhatsApp dismantled a Cambodian cybercrime syndicate that leveraged ChatGPT to generate synthetic personas, forge legal documents, and translate communications for complex financial fraud and romance scams linked to forced labor operations.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/Oo5-8A1e41MF24WLxZoZZfSJ4K8Vk5VV4ew0jC4nB0Y=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/4aY1f6U_-LOyndqnl6BWYmP5iT4XQdqFPV0RX9lb_4c=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/Gk3ynEJh5m2jdLuPjc-HeTzqfGW1EuDpvO-4bjthSaY=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/aCExQdWEkJQ3GsX5m4-tVguBN3y-G7FfbM6RRlQvZ-c=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/Rt2Q71jqH-dSk5jPfDAJTxn6mtKt80hh2V1aXMrzmFM=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/xlDxfqa0wV4SVgf7biEil50AFT4H8Yai94-zjVcHf-Y=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/GQdAXMKqtOlifzapRqMQUIuy8M96uGML9UmxXrOJm6M=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/eEKCXUtGobu6RgbLPGbwb4t8uzyj6WRSDMKDN7GvdxE=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/wqJETrK14hB1fB4JgVm45W4AV3Hn-eC_JkSTcA1We9Q=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/snzOZVsiEPhBt6ZIYsuN2YvFzGnwf7GRzutyZRJr_o8=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=88091d48-915c-11f1-ba4a-7d4984454734%26pt=campaign%26pv=4%26spa=1786021318%26t=1786021743%26s=65c9ded3271a4e81a1fa40803441d9bc7ef3156c224aab11a91949df71ae7703/1/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/Mgm-rR2FaOjgzXLgswYbIb8A6EnJhSPRzMIybqOq52o=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fd7310acb-2e4fddff-d7d0-49a2-8f8f-5296df698d96-000000/SRqbWEtVnT8scDRkzWv6D_rdj75ztXlpXk4mmrM9psE=452" style="display: none; width: 1px; height: 1px;">
</body></html>