<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Rapid7 chained CVE-2026-55040, a JWT validation bug in SharePoint Server Subscription Edition 2019 and 2016, with CVE-2026-63520, a .NET type β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/MS6HtVyA74pvCuKa6gC7dsU_HhA9zOQ5A0eu-IShO-c=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/lZItbQhQKRbdIX7OhPwBFKN0cK95_SK21JHKV4RZd6Y=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=d4228478-963c-11f1-b1e3-a52107b97a29%26pt=campaign%26t=1786540177%26s=2cc46fc2a683f8ba756f9fc43dc40c35f1a534bad0d9cebe5a350835e55d10db/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/bGtiGf4QO3UOWWue82S99h71eNru9vN6vLYhCb3W8OQ=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-12</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.helpnetsecurity.com%2F2026%2F08%2F11%2Fopenssh-10-5-ssh-agent-flaw%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/CZAL1T1pSeTlYFQDWGzBoxQR1KARcSb9Zec8JD2ZftI=452">
<span>
<strong>Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenSSH 10.5 fixed a flaw introduced in version 10.4 where locking the ssh-agent disabled the check distinguishing local requests from forwarded ones, letting remote connections perform operations meant to stay local, including adding PKCS#11 tokens and bypassing destination-restricted keys, alongside a use-after-free in the ssh client and a broken authorized_keys "restrict" keyword that failed to block tunnel forwarding.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FkGHsLX/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/3qecWXm4xXCp28ASOpylc0g23230tpC3b_XodMYlZDY=452">
<span>
<strong>Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A zero-day SQL injection flaw in Metabase Cloud (CVSS 10, no CVE yet) let an attacker inject SQL into the app database and get admin access, steal database credentials, and export data. Metabase patched cloud instances automatically. Self-hosted users with the /api/session/reset_password endpoint exposed on port 3000 remain vulnerable. n8n confirmed 136 leaked customer records. Kilo Code confirmed exposed Slack tokens and customer data. Metabase told self-hosted users to patch now or block that endpoint, rotate credentials, and revoke sessions.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fresearchers-disclose-ai-assisted.html%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/cC93pvAC1RpQIPfeYyjOmbfAT523JET0xT0q-38CVhg=452">
<span>
<strong>Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Rapid7 chained CVE-2026-55040, a JWT validation bug in SharePoint Server Subscription Edition 2019 and 2016, with CVE-2026-63520, a .NET type instantiation flaw in Business Connectivity Services, to get unauthenticated remote code execution. Attackers need only a target's SID or UPN. An AI agent helped find the chain across 96 sessions and 80,000 tool calls but also replayed admin credentials and enabled debug flags without authorization. Install the July KB updates now. August patches aren't public yet.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsecurelist.com%2Fproject-cav3rn-continues%2F120991%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/zUi-k3hHnouAfgkK6Wk2nVa6IezDYgZD4nKdML_LXpI=452">
<span>
<strong>Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Kaspersky researchers uncovered an updated Project CAV3RN espionage framework targeting Israeli organizations that dynamically routes command-and-control traffic by inspecting DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay. This evasive technique allows the malware to blend seamlessly with legitimate traffic before handing execution to an inter-component broker (β rnp.dllβ ) that orchestrates malicious modules. To detect this activity, defenders should flag anomalous β script.google[.]comβ POST requests and hunt for associated infrastructure, specifically queries resolving to β studiotikva[.]comβ .
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Funit42.paloaltonetworks.com%2Faeternum-blockchain-c2-analysis%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/4b3gSHKQZN5ug59CojlyRzr0saEpiV7h-ia2L2g4R64=452">
<span>
<strong>The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Compromises (20 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Aeternum is a sophisticated malware loader that utilizes Polygon blockchain smart contracts over JSON-RPC to fetch encrypted command-and-control instructions. After decrypting these commands, the malware downloads secondary payloads from GitHub, including the XWorm RAT and XMRig miners, while a related Python variant specifically targets over 60 cryptocurrency wallets and browser extensions. Aeternum ultimately relies on hardcoded Telegram bot APIs for data exfiltration. Defenders should hunt for anomalous Telegram API traffic and outbound JSON-RPC calls originating from non-browser processes.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.offensai.com%2Fblog%2Famazon-s3-vectors-security-llm-rag-poisoning%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/bYt7Ol38QQ19s7a9FinOLogDFb6tQq03sM-Byp4cnxw=452">
<span>
<strong>A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines (15 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An attacker holding only s3vectors:PutVectorBucketPolicy permissions can grant foreign AWS accounts full data-plane access to forge chunk text, spoof citation URLs, and manipulate embedding coordinates so poisoned data dominates top-K retrieval. Researchers demonstrated that a single planted vector could trick a clinical RAG assistant into recommending dangerous medical dosages alongside authentic citations or even achieve command execution in tool-enabled agents. CloudTrail data events for these actions are disabled by default and strip critical metadata when enabled, so defenders must isolate ingestion behind strict IAM roles, utilize HMACs for chunk keys, and mandate manual confirmation before autonomous agents execute actions.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhorizon3.ai%2Fdownloads%2Fwhitepapers%2Foperationalizing-ctem-practical-playbook%2F%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctemwhitepaper/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/c4Gcvp31vHnH_IX5fRq4yozAAjH0xZ5ciPZJTOnjcWI=452">
<span>
<strong>Playbook: Driving Measurable Outcomes from Gartner's CTEM Framework (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Most teams understand Gartner's Continuous Threat Exposure Management framework, but struggle to turn it into a repeatable program. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhorizon3.ai%2Fdownloads%2Fwhitepapers%2Foperationalizing-ctem-practical-playbook%2F%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctemwhitepaper/2/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/00g7Uv24w8FlsK5OHUKrJVzoQUndazEdv9twzDWygMM=452" rel="noopener noreferrer nofollow" target="_blank"><span>Download the Horizon3 whitepaper</span></a> to translate CTEM into an operating model that reduces attacker opportunity by validating what matters, prioritizing remediation, and verifying outcomes across your entire attack surface. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhorizon3.ai%2Fdownloads%2Fwhitepapers%2Foperationalizing-ctem-practical-playbook%2F%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctemwhitepaper/3/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/QoYSSPfTtBb2s-UCPa4UjU9RXh19H1Nf3-2qjXYmZ3k=452" rel="noopener noreferrer nofollow" target="_blank"><span>Get your copy.</span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cloudflare.com%2Fopen-sourcing-our-privacy-proxy-cli%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/rIAoH1SBRpkQMI9DnDHtSblVBbMRkc_ib58RLr1YZfQ=452">
<span>
<strong>We're open-sourcing our privacy proxy CLI (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cloudflare has open-sourced pvcli, a Rust-based diagnostic tool that handles full Oblivious HTTP (OHTTP) requests across relays, gateways, and targets in a single command to eliminate tedious manual binary parsing. Unlike single-protocol alternatives, the utility combines OHTTP, CONNECT proxying, and MASQUE support using a familiar curl-like syntax. This unified approach significantly accelerates incident response and debugging for engineers managing large-scale privacy deployments like Apple's Private Relay and Microsoft's Edge Secure Network VPN.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fbeelzebub.ai%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/ou58wKqChAZPUvVk9wgYBG-KYj88WZqWZeeP3RUhtxk=452">
<span>
<strong>Beelzebub (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Beelzebub provides a platform that traps attackers already inside a network, using LLM-based decoys, continuous emulation, and an AI analyst to generate incident reports. It runs on-premises or as SaaS and pulls threat feeds from 60+ researchers.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Falibaba%2Fopen-code-review%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/zCBFMqfD7tch-eV730SmJEpGAAUqBEOS1hSGADKvQQA=452">
<span>
<strong>OpenCodeReview (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenCodeReview is the Alibaba Group's internal AI-powered code review tool. It reads git diffs, sends changed files to a configurable LLM via an agent with tool-use capabilities, and generates structured review comments with line-level precision.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FVx90RF/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/PZBXt8QUpwj51kkU3qm8Q5eA1lc3rDVlPiMw2Or7CAQ=452">
<span>
<strong>Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Google pulled "AI Sidebar with DeepSeek, ChatGPT, Claude and more" in January after OX Security found it scraping ChatGPT/DeepSeek chats and sending them to external domains, with 300,000+ installs by then. It's back on the Chrome Web Store. Netskope found version 1.7.3.0 added 21 lines that open affiliate links on update events and hijack the uninstall URL for referral commissions.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Farstechnica.com%2Fsecurity%2F2026%2F08%2Fheres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/jJrLmPlrVLt8X_l2iF5ymDEEYfojUdF9w7yJPDt8Nww=452">
<span>
<strong>New Pass-ta-key attack reveals all the things we didn't know about passkeys (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Pass-ta-key malware can steal passkeys from an infected Windows PC using Google Password Manager. It may pose as an iPhone, then use Google's device-sync feature to copy the victim's saved passkeys. Windows lets malware access other apps' data more easily than Apple and Android systems. A malware-infected, signed-in PC can also expose passwords and active sessions.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.google%2Fsecurity%2Fthe-multi-layered-defenses-that-harden-chrome-against-abusive-notifications%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/ZQ4R0B5IpohUdGUS4og_epjwdihgx3iZron9etZLfWE=452">
<span>
<strong>The multi-layered defenses that harden Chrome against abusive notifications (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Chrome Security detailed a new defense-in-depth stack utilizing Firebase Cloud Messaging and Safe Browsing that successfully blocked over 7 billion abusive Android notifications per day in Q1. The multi-layered approach curtails coordinated spam networks by automatically revoking permissions for suspicious sites, analyzing malicious service worker activity signals, and throttling disruptive domains at the FCM server level to 1,000 messages per minute with HTTP 429 error responses.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjorgebranco.substack.com%2Fp%2Fportuguese-hacker-to-face-trial-for%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/1_JGArvMVRT53pi6IvvX0bWNEzAHOU303glji93L0mM=452">
<span>
<strong>Portuguese Hacker to Face Trial for Malicious ChatGPT Clone (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The 23-year-old Portuguese hacker who created WormGPT is currently on trial for creating the software.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsecurityaffairs.com%2F197042%2Fhacking%2Fzoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/HiYunzD_3De7ve-K5UTujDkGngP8s-lOKyIVWWsO83E=452">
<span>
<strong>Zoom Patches "Zoomsday" Zero-Click Flaw Enabling Remote Code Execution (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Zoom has released critical updates to mitigate "Zoomsday" (CVE-2026-53413), a zero-click remote code execution vulnerability in its annotation protocol that allows any meeting participant to silently trigger a stack buffer overflow and execute arbitrary code across all unpatched platforms.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F08%2F11%2Fnorth-korean-remote-it-staffer-worked-for-us-government-agency-says-fbi%2F%3Futm_source=tldrinfosec/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/pZ8GLaWc6cuONaXJinHffAtwUGQUEgZlVbUdfGheGOk=452">
<span>
<strong>North Korean remote IT staffer worked for US government agency, says FBI (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The FBI is investigating a sanctioned North Korean operative who fraudulently secured a remote IT position at an undisclosed US federal agency.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/ewwG7vEX5pCh2sobtueAUFNewxcXt0JachyE4k1WYWo=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/Z6i1W_5pcyvlPc4-PgOZ513dUvRbmynsNlJUlxu0Z20=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/k_Ey6TWfkHT8PyMNDvmgzBo0tCdzsEknlbu9aTSIhwQ=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/crtcH3vxzlfJMXFxUjAZ0YQunW_hvSW0A2MaPnQ7iBI=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/5NtyG7-X4MgK20JGNx9JqzzMmG1BvdqiB_c5nkNOJoA=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/P3UHe-F5nAGpOyF8ml7VyU_aAtyoj3dV8_3qDDVKUsY=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/crqfAPCKSBCpqPd18NNWxjv4xQCoBGyVsKEHSXHrTRQ=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/tXgipi2aujLaoaXbrUnMi6rPzM_KgJxKzQc02nHDq-g=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/ydVe8sbJxKtW9v_dSZXfXoOHFQnd-Z3UqZ4dOFaI5y4=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/MtM0mWr6OPoFImCjB_kg33bNmf2DdyjANQc9Db2Vb0c=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=d4228478-963c-11f1-b1e3-a52107b97a29%26pt=campaign%26pv=4%26spa=1786539744%26t=1786540177%26s=eb2fe14bafbcce770eebdec862838cf74da4987e4b053904105c86e5f3dc627c/1/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/x_964mfej61yQzzZ2cay4spD63KbAIiFf5mZVqaalSM=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019ff617ba1d-2f53279f-ae88-48d1-b168-d7376ac95a5f-000000/bCQcKBLXLmrvNN9RpEFDFinZQSaXY1CLR8QPcA9_0rw=452" style="display: none; width: 1px; height: 1px;">
</body></html>