<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">A cyberattack disrupted eight Ceva Logistics warehouses, delaying or canceling orders for many customers. Bol said attackers accessed two order β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/DJcN70RIbxhMkuM10rDZQyYuBSRdMT4rs-8ItrAWcpI=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/DSMoayhKSy-lbRN-nq91NnTWZTdCIjIbao7Q8JreJ5k=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=bb7046ec-96fd-11f1-a5db-8d6630244099%26pt=campaign%26t=1786626504%26s=7c63a1058207c5431947ddb4be31052045e1acb616aec057acad6ebd330eafef/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/t2sGdUbwLrfrPKXgwuFXCoMXCNn_DC9bVd_RcnSFe0g=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-13</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgbhackers.com%2Fdocker-copyescape-vulnerability%2F%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/RQ08C7-O1w7XmTqGZaNykrAWXvIt4hzSmXwuoPg0iUE=452">
<span>
<strong>Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CopyEscape (CVE-2026-17106) is a critical race condition in the β docker cpβ command that allows a malicious container to escape its boundaries and overwrite arbitrary files on the host system. By swapping a directory for a symlink during the archive-copy workflow, attackers can force extraction to outside paths, achieving root code execution by overwriting critical host binaries like β /usr/bin/runcβ . Docker has patched the vulnerability in Engine 29.7.2 and Desktop 4.86.0, requiring defenders to upgrade immediately, halt automated root-level copy operations, and ensure untrusted containers are stopped before retrieving files.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftherecord.media%2Fceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/Z_uaoAl2cldRXgcjxLl94wxNbmCCPmJPfk-nYW8-4YY=452">
<span>
<strong>Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A cyberattack disrupted eight Ceva Logistics warehouses, delaying or canceling orders for many customers. Bol said attackers accessed two order-processing systems. Names, addresses, contact details, tracking data, purchases, and gift-card messages may be exposed. Valve is notifying affected European hardware buyers.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Fr57t3o/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/hJs9kWs0krkrm_FRZlVahUq2Y0CDdNR1HXrzISg2zSk=452">
<span>
<strong>Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
TeamPCP compromised LiteLLM after its CI pipeline automatically installed a trojanized Trivy release. LiteLLM versions 1.82.7 and 1.82.8 ran malicious code on every Python invocation. The packages were live for 40 minutes, exposing 434,000 CI/CD pipelines across 2,500 organizations. Treat LiteLLM-accessible credentials as exposed. Validate and rotate secrets, accounts, and sessions, then review logs.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Funit42.paloaltonetworks.com%2Fkimwolf-v7-botnet-malware%2F%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/tmTBYraI5GlzUBYgpzBwQ_mmG4YNjF_aK-qiRWvpwYQ=452">
<span>
<strong>Kimwolf v7: An Evolution of the Kimwolf Botnet (15 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Kimwolf v7 is an evolving IoT botnet that compromises Android TV boxes via unauthenticated ADB interfaces to launch HTTP/2 flood attacks using spoofed browser fingerprints. The malware utilizes a resilient, three-tier command-and-control architecture featuring Ethereum Name Service lookups, a hardcoded Tor hidden service fallback, and a localized proxy routing system. Defenders should restrict network ADB access, hunt for the masqueraded β netd_serviceβ process, and monitor for anomalous outbound Ethereum RPC queries directed at the operator-controlled endpoint β eth[.]rpcuniverse[.]comβ .
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsocket.dev%2Fblog%2Fchrome-vpn-extension-impersonation%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/QzaaXqx2nVtvoZMMiif4e69NrPsJragINUNf7hKqXHs=452">
<span>
<strong>737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection (19 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Socket researchers identified a massive campaign of 737 malicious Chrome VPN extensions, operated by a single threat actor branded as Muxa VPN, targeting Russian-speaking users seeking to bypass regional blocks. Once installed, these extensions abuse the β chrome.proxy.settingsβ API to silently force all browser traffic through a SOCKS5 relay on port 1082, with many utilizing DNS-over-HTTPS to evade plaintext DNS logging. While Google has removed some extensions, over 500 remain active, prompting defenders to block egress traffic on SOCKS5:1082 and VLESS-REALITY:443 and heavily scrutinize any extension requesting the β proxyβ permission.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F1password.com%2Fblog%2Fwhy-ai-generated-patches-still-require-human-review%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/TAPYE6QXHwOwZkICfytod5eunlNOLLrD5ijQIV5BTcw=452">
<span>
<strong>Why AI-Generated Vulnerability Patches Still Require Expert Human Review (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
1Password's Off-by-1 Labs tested ChatGPT-5.5 and Opus 4.8's abilities to generate patches for six recent, high-profile CVEs when running as part of the respective organizations' cyber reduced guardrails programs. The test setup involved generating 540 patches per vulnerability in batches of 20 and testing whether they fixed the vulnerability, changed application behavior, and/or introduced new vulnerabilities. 1Password found that only 26% of patches fixed the vulnerability without changing application behavior or introducing new vulnerabilities.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FJ4UzCZ/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/0t8jplEo7O48U3OOoGQR360LJj__GagrCkyDwmLR2AI=452">
<span>
<strong>Expanding Daybreak as the Cyber Defense Window Narrows (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenAI has expanded its Daybreak cybersecurity program with two new access tiers, Daybreak Blue and Daybreak Red, alongside the introduction of a specialized model named GPT-5.6-Cyber. By explicitly reducing refusals on high-risk tasks, this purpose-built model achieved a 95% completion rate on advanced exploit-chain benchmarks and recently uncovered critical zero-day vulnerabilities like a Chrome V8 heap sandbox escape (CVE-2026-15903). To mitigate the inherent risks of bypassing standard safety guardrails, OpenAI is restricting access to approved defenders and mandating hardware security keys for all accounts starting September 1.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcorma.ai%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/QOtiGLlcBO27sd5HdQ_w8VsMA2Ictd4BI0kEEvfDH64=452">
<span>
<strong>Corma (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Corma provides an AI foundation model for cybersecurity defense. It analyzes system events, audit logs, and network traffic to spot multi-stage intrusions, then deploys automated agents that work alongside security teams.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FIdov31%2FEtwSuite%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/zVgRHnj3eROBWZNHTUfbyJcQKiUkOUWtM5AIz6nBQi8=452">
<span>
<strong>EtwSuite (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering results, and inspecting ETL/JSON/CSV recordings from one desktop tool.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fuber%2FADR%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/CAd-bj6vabbk_xt4xyaa_gbKerzHwOGGUKgojqWvEPM=452">
<span>
<strong>ADR (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
ADR is Uber's production agentic AI detection and response tool. It helps organizations secure employee and customer-facing agents.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FVx90RF/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/fFJv_wWQ3TTZjvpEBAf0tzcVblVg0UYHXTlmq9spDhk=452">
<span>
<strong>Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A malicious Chrome extension named "AI Sidebar with DeepSeek ChatGPT Claude and more" has bypassed a previous Web Store ban and returned with a new fraudulent monetization scheme. Netskope Threat Labs discovered that version 1.7.3.0 contains a script that farms affiliate commissions through an AI video platform during every update and overwrites the uninstall URL to ensure even removing the extension generates a referral payout. Defenders should immediately block and remove this extension, classified as Trojan.GenericFCA.Script.37952, which falsely masquerades as an official DeepSeek AI product to deceive users.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cloudflare.com%2Fddos-threat-report-2026-h1%2F%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/rv1-FHhWJculo4kIoV2XUnjh7-5hTrHTZbc28U1u6Nw=452">
<span>
<strong>Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cloudflare's H1 2026 DDoS Threat Report highlights a massive escalation in attack volume, recording 935 incidents exceeding 1 Tbps driven by a shift toward DNS-based floods and a 580 percent quarterly surge in CLDAP reflection. Real-world geopolitical events heavily dictated targeting patterns, with Operation Epic Fury triggering a massive spike in attacks against government infrastructure and the Ankara NATO Summit pushing Turkey into the top three most-attacked countries. Furthermore, Brazil has officially overtaken the United States as the primary source of global attack traffic, while the media sector remains the most targeted industry globally.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F9132bx/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/D3pyXtCM_yFHingtezQA-fk09qGh6lfvw0Wz9cQNTYM=452">
<span>
<strong>New StormEncryptor Ransomware Used by Former Medusa Affiliate (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Microsoft Threat Intelligence is tracking a financially motivated threat actor that was previously affiliated with the Medusa ransomware operation and is currently deploying a new ransomware strain called StormEncryptor. The threat actor has been exploiting vulnerabilities in the N-Central RMM software to breach systems, followed by using AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and Mimikatz for credential dumping. The StormEncryptor ransomware is a C++ malware that appends encrypted files with the β.encryptedβ extension and drops a ransom note, which gives victims three days to negotiate with the attackers before data is leaked, in each scanned directory.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FBkXVhE/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/NnhO2H-1rrOo4Z_KjH0KAhVhFz8E8pz1zfk8zCHROT8=452">
<span>
<strong>Cisco Patches Firewall Zero-Day Exploited for DoS Attacks (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cisco released emergency hotfixes for an actively exploited zero-day (CVE-2026-20349) that allows unauthenticated attackers to crash Secure Firewall ASA and FTD appliances via crafted HTTP requests to the Remote Access SSL VPN service, prompting a CISA mandate to patch by August 14.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fzoom-annotation-flaws-could-let-meeting.html%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/2I_qpPPZlpoy-duwFTMej_cgSuMnZVLqAy058ozGZ10=452">
<span>
<strong>Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Zoom patched three annotation bugs that let meeting participants send malformed drawing data to another client.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F08%2F11%2Ffbi-says-cybercriminals-are-hacking-into-victims-online-accounts-to-steal-their-intimate-pictures%2F%3Futm_source=tldrinfosec/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/Hj1L3mY2zjYKIFXushc_jwxiU9QTevgf9uf_EK1Brds=452">
<span>
<strong>FBI says cybercriminals are hacking into victims' online accounts to steal their intimate pictures (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The FBI warns that attackers are taking over adults' and children's social accounts to steal explicit images and videos.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/lUB--g4HQDKSSjQPLMML98LaA9Xif31zVG9CbqczVcg=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/CaPrJoN07GONd3bWuSRaIuwhhu9wqxknuABPghUJLLE=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/hFRfAoAABQWNwQWOKOxqFLk64L3-mIqxdd8B13Etyk0=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/ar1J5dPMvzNeyMEX_ElvVCec0WPYl4vBBpGOpTANSfg=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/K0g-5VooyBrFxtcVEhDGE23BnMDbito4MlJDui8LYCE=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/Ay8eHaijvb_kkUne75l4Z01Hf4MSDkvma_IwYqmBMb8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/Yd71wFJ7BlGgVF_n0WSYrfPogsiTi6bVVb8Nv6KLL70=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/_pUaflHeZ_kyU7IoWYV4Xnj9QSvenhUWmCw5g9ue9XQ=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/Rp-Rms1WZwt7PxikN1pni4yUhr9CiFeWARdnJCEj-V8=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/7583PV-_pZBxuTrabQtxaJyFlV_5MBko6FkRUN9pT0o=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=bb7046ec-96fd-11f1-a5db-8d6630244099%26pt=campaign%26pv=4%26spa=1786626076%26t=1786626504%26s=e5b3ae5612a8ccf1790b41dec7f97374b31d5ac5838c61911a2333ab5e0b1b09/1/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/-Hzb0njy9euf7diRci5-5skNY5MjQjKa0dYD3X-156w=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/0100019ffb3cf5f5-f7b5bc65-d460-49d1-abeb-a120fa07d1d8-000000/7FTUXyLsY8MG_4qMzo0hBblP-4siJ8gkrMX-b70CJCw=452" style="display: none; width: 1px; height: 1px;">
</body></html>