<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Forescout identified over 4,400 internet-facing Rockwell PLCs worldwide, including 22 in recently attacked US water utility cities โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/1iE2Ak0cEimvnrRoDT62XHwBd5eeseEPB7B67Up0oTM=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/UvNLiRifGQoohnJQhUCnZulEB94af3s4MbHyq5VOgaQ=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=ecab1406-9227-11f1-8c86-41f97d39f1a2%26pt=campaign%26t=1786108191%26s=8883b1c39c374bd4611da4aa4445b5a2f1525de4b641ffc98c7902f359720b6d/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/q4rEvDgYjKYSwoIyjypCAATOLToietw0YJt1Soyw1mg=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=header_sase_leader_again/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/t7mGrs3yboZMzOrQTRzMj8trVmJ8IEyG4Y2GTEDcbEM=452"><img src="https://images.tldr.tech/cato2.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="Cato Networks"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-07</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=header_sase_leader_again/2/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/YBoPuL3AV76ETOddQNEZVNrYvj2dukBPtoVjuTXLjn0=452">
<span>
<strong>A SASE Leader. Again and Again and Again (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
As AI becomes embedded across the enterprise, organizations must secure their use of AI while defending against AI-powered threats.<p></p><p>That pressure is making the limits of fragmented architectures impossible to ignore.</p><p>Cato Networks was named a Leader in the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=Body_2026_gartner_magic_quadrantTM/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/m_mXl61qiWLfh1j5HoMasHshIsyoLRDZ321VKM0TfL0=452" rel="noopener noreferrer nofollow" target="_blank"><span>2026 Gartnerยฎ Magic Quadrantโข for SASE Platforms</span></a> for the <strong>third year running</strong>.</p>
<p>See how Gartner evaluated the market and why, in Cato's view, unified SASE platforms are becoming essential for the AI era. </p>
<p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=cta_2026_gartner_magic/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/fxZS5SOYkciD5usUNh0Mm3exC2AYMNxQjJNostHxDLI=452" rel="noopener noreferrer nofollow" target="_blank"><span>Get the 2026 Gartnerยฎ Magic Quadrantโข for SASE Platforms โ </span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fover-4400-rockwell-plcs-exposed-online.html%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/GuW67R4-DT7SpMSQlVJoksWYytAv58v-NHoD4JcrYT4=452">
<span>
<strong>Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Forescout identified over 4,400 internet-facing Rockwell PLCs worldwide, including 22 in recently attacked US water utility cities that were compromised via open Ethernet/IP port 44818 rather than complex exploits, prompting urgent calls for defenders to isolate controllers behind VPNs and utilize Rockwell advisory SD1790 to recover attacker-locked systems.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdecipher.sc%2F2026%2F08%2F05%2Fresearchers-find-persistent-backdoor-in-zbtlink-routers%2F%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/36mp8SkflMe55e-fvZuiRqckZY3AkxzIs4Ox35Yi6vc=452">
<span>
<strong>Researchers Find Persistent Backdoor in Zbtlink Routers (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
VulnCheck researchers discovered an intentional and unpatchable backdoor dubbed EndlessDoors in over 100,000 active Zbtlink and Wiflyer routers that initiates outbound command-and-control connections to bypass NAT, requiring defenders to monitor port 7000 for malicious beacons and physically replace the compromised hardware.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F9UEitx/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/QlNk1XCkd181LbM4UfdirKgpUtYbT42NapvaRgmajPE=452">
<span>
<strong>Swiss Government SharePoint Breach Compromised 200 Accounts (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Swiss Federal Office of Information Technology and Telecommunications (BIT) reported that hackers exploited vulnerabilities to breach its Microsoft SharePoint instances. Other than login credentials, BIT does not believe any data was stolen. BIT responded by blocking external Internet access to SharePoint, patching the vulnerabilities that were exploited, and resetting the passwords of affected accounts.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐ง </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.pointwild.com%2Fthreat-intelligence%2Fpoint-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware%2F%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/ljD4bBw8zqD1k64fBk8Rk0N8dSMX3lAZv_FvB-yjYUg=452">
<span>
<strong>Point Wild Exclusive: Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware (11 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Vanta Stealer is a highly obfuscated Python information stealer that uses PyInstaller and PyArmor to evade detection while dynamically downloading modules to harvest browser credentials, VPN configurations, and gaming platform data. The malware actively enriches stolen Discord tokens via API to identify high-value accounts before packaging the compromised data into a ZIP archive and exfiltrating it via HTTP POST. Defenders must block outbound connections to vanta[.]st and hunt for suspicious PyInstaller binaries executing unsolicited network requests to mitigate this threat.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.coinspect.com%2Fblog%2Fill-bloom-investigation%2F%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/5Px20RywEjSpzoA9NcRcvQ--ABvLeg4Fulb3wmf2IUs=452">
<span>
<strong>Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Ill Bloom is an active cryptocurrency wallet-draining campaign exploiting a legacy CryptoJS weak-randomness vulnerability in unmaintained downstream dependencies. Defenders should immediately consult the illbloom.org technical disclosure for specific IOCs and affected wallet lists to expedite fund migration.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fpulse.latio.tech%2Fp%2Fdetecting-and-preventing-the-hugging%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/asNfvgAId6besCKPpNjscsr7lOEPvQtKhyWL8mJFTQQ=452">
<span>
<strong>Detecting and Preventing the Hugging Face/OpenAI Incident (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
James Berthoty breaks down the different tools and techniques that could have helped at different stages of OpenAI's incidental breach of Hugging Face. During the initial phases of the model's escape from OpenAI, external network blocking and agentic EDRs could have been helpful. IMDS blocking and more fine-grained secrets injection could have helped Hugging Face guard against being breached by the agent. Traditional Kubernetes and CNAPP tooling could be used to detect the lateral movement from within Hugging Face.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐งโ๐ป</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fperplexityai%2Fnumbat%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/PkJnxskDiy3ATyBY8hp903FEp8Y5zPZnTae_OFh65r8=452">
<span>
<strong>numbat (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
numbat is an โAI-EDRโ built by Perplexity. It provides visibility into AI agent activity with local detection, optional pre-action blocking, and forensic reconstruction.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FluckyPipewrench%2Fagent-egress-bench%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/eoG0akdpfrtXTMA-5vp_2_EBkNO3ihvFQrhSiKKciN0=452">
<span>
<strong>agent-egress-bench (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
agent-egress-bench is a standardized test corpus for evaluating AI agent egress tools, covering secret exfiltration, prompt injection, SSRF, hostname exfiltration, MCP tool poisoning, chain detection, MCP drift, A2A protocol scanning, WebSocket DLP, encoding evasion, shell obfuscation, and cryptocurrency/financial data protection.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fgadievron%2Fgreenlight%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/G-hmagJ8_wpNh4em0eKb7GjVeNDa6vq-uUCZ9nHHi4w=452">
<span>
<strong>greenlight (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
greenlight is a skill that was created for mapping out where Claude Code's guardrails trigger exploitation-related refusals, and where they can't be relied upon. greenlight was only tested on Opus 4.7, but the methodology is generalizable.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;"> <div class="text-block"><span><a href="mailto:infosec@tldr.tech"><span><strong>TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)</strong></span></a><br><br><span style="font-family: ;">Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to <a href="mailto:infosec@tldr.tech" rel="noopener noreferrer" target="_blank"><span>infosec@tldr.tech</span></a>!</span></span></div> </td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.wiz.io%2Fblog%2Fcloud-threat-highlights-h1-2026%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/97uBoWOJsILo-_zKsqDoHE6E5_9ONWILu8kp3S3CRuU=452">
<span>
<strong>Cloud Threat Highlights: H1 2026 (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Wiz's H1 2026 threat report highlights a 60% increase in major cloud incidents, primarily driven by cascading supply chain compromises and targeted attacks against immature AI infrastructure. Threat actors are increasingly monetizing non-human identities and reselling credential access across groups, evidenced by the sprawling TeamPCP npm campaigns and North Korean package trojanizations. This evolution signals a structural shift toward self-perpetuating attack surfaces, requiring defenders to secure unauthenticated machine-to-machine integrations and exposed backend credentials to disrupt automated access brokering.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FwQomNw/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/8RTolUR1GPkIQx_DCF-0TUzsUoVhaCiY7Xh19OdtUik=452">
<span>
<strong>New TONTOU CPU Attack Bypasses Spectre v2 Fixes to Leak Linux Password Hashes (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers at MIT CSAIL discovered a new branch predictor exploit that bypasses neutralization-based mitigations for Spectre v2 attacks. These mitigations assume that an attacker cannot exploit the time between when the branch predictor is isolated and when it is used by the victim branch. However, the researchers introduced a new primitive that can re-poison the CPU's state in this gap. The researchers demonstrated that this vulnerability can be exploited by users with unprivileged code execution on commodity hardware to extract /etc/shadow at a rate of 5.46 bytes/second.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F08%2F06%2Fchina-linked-lightspy-spyware-caught-targeting-victims-in-13-countries-including-the-us%2F%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/HYhGZ0y20-lmW87f2PbDBXuO6vtGP9Dtuz418cdqUaw=452">
<span>
<strong>China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
LightSpy, originally a Chinese state-linked spyware, has evolved into a commercial platform actively targeting governments, enterprises, and NATO-affiliated routers across 13 countries. The modular toolkit now provides total network visibility from a pool of at least 117 command servers. Notably, researchers successfully traced the latest campaign to a Chinese contractor after an operator inadvertently revealed his real name and office address by placing a food delivery order directly through the spyware's admin panel.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">โก</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftherecord.media%2Fbelarus-hacker-ransomware-sentenced%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/e_ss8L8jE3ARZfMh541rVzqBNz1n2qgcnV1necp1u6Q=452">
<span>
<strong>Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Maksim Silnikau received a 16-year prison sentence for orchestrating the Ransom Cartel ransomware operation between 2021 and 2023, concluding a prolific cybercriminal career that included developing the notorious Angler exploit kit and co-creating the foundational Reveton RaaS model.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.privacyguides.org%2Fnews%2F2026%2F08%2F05%2Fapples-private-relay-leaks-your-real-ip-address-in-safari%2F%3Futm_source=tldrinfosec/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/6WdOXabM4onrEq6-dr4fwoCioefYVI9D8YNrsXB-RDU=452">
<span>
<strong>Apple's Private Relay Leaks Your Real IP Address in Safari (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Mysk researchers found three unpatched leaks- DNS prefetching, WebAuthn's Related Origin Requests, and WebTransport- that let any website bypass Apple's Private Relay and reveal a user's real IP across all WebKit-based iOS browsers, and published the findings without prior disclosure to Apple, citing a pattern of yearlong fix delays.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/_Wn6gG2kNeEYhk8rDv1beMoA3N0aRYR40UiMA9RxK-Y=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/azlxHv0Hmjci9PvkNJdQ_TP1QLWyNupA0j9xCoLxS4s=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? ๐ฐ
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/Gwt25WDqFWcc8g2ndrlPce_opZHAd5CMSGmYX5GJG_c=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? ๐ผ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/jwfWuIN1CC036UJe9CVUulZXHbHsHuu4KqeH5sUsIHk=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/xxRKhpjNGYXZuaPpGjSlWzzgHiOZyy8e-xtREO2BE7g=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/tzLleyYdQh0bYh_9TgmtfMjUWF26LDns0_81dxgYbQ8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/zjJxJGfcBYeP2CX_fmpv3NwchgIi23gd25FFeiasecI=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/bek1H1hk_ggupwZUkv77qILPjUsBAQ-hzbapr7RPCg8=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/yZ8djONon3Zbcfp6K6MzQuf7ewHr0qSMvtZ93xOhITE=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/b3ZZ4hOIG61SfEjqAbT_52KnpC778qAq8tx_7AHF0Kg=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=ecab1406-9227-11f1-8c86-41f97d39f1a2%26pt=campaign%26pv=4%26spa=1786107752%26t=1786108191%26s=f0e4a41013ae923d3bf37a8f3f7f626545c791b1487acc18084cfd5983308b20/1/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/6yx_t8FrF6FOr2hJIi5SYxgENzRXERnxGHVRYkN1vGQ=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019fdc582407-80144d5f-2a1e-4f4d-8dcf-e2cbf3eb1204-000000/SyuViCCR4xH9UEdTGAWSG5TpGkjWd6l_E_1zo7tSHg0=452" style="display: none; width: 1px; height: 1px;">
</body></html>