<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Reco tracked City-Forum using one Go binary against Salesforce Aura, Salesforce LWR, and ServiceNow. The campaign queried unauthenticated guest β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/3qHLHaYrMZ_-cqZKPeqATFCouBZIA4LVPN7A6EHb5hI=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/o3ooxL4MinSzj6FzaCqNo6J1gyifZjUuyN0-G93WOVA=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=8c3b92d2-97d4-11f1-8af4-1d92364540fe%26pt=campaign%26t=1786712905%26s=c8005269a48e012fa4eb9cf3a50dcdf319d06ca599297a35fc11346f192b7a44/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/6QSCQQYxvbk9-Q1rMwo7KjISyv_4r-nhPLc1VXluRhE=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_source=tldr%26utm_medium=referral%26utm_campaign=2026-08-14_Primary_Threatdown%26utm_content=header_6_000_plus_guardrail/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/aiSqHxmOcoD4fdOYxqVem4OU6Q6emWf31C19EMDI90g=452"><img src="https://images.tldr.tech/threatdown.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="ThreatDown"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-14</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_source=tldr%26utm_medium=referral%26utm_campaign=2026-08-14_Primary_Threatdown%26utm_content=header_6_000_plus_guardrail/2/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/Czb3_MitDQfvZTmaamBxhH61uEHxijyEsJzzEaB7_a0=452">
<span>
<strong>6,000+ "guardrail-free" AI models. One download away. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AI-powered cybercrime is no longer just a future risk. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-14_Primary_Threatdown%26utm_content=Body_threatdowns/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/SkDRkazBdYQHuAG7FxPVZlfFqc4CBkzM74y12ZjWPgQ=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown's </span></a>new research found it's already here, hiding in plain sight on infrastructure organizations already trust. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-14_Primary_Threatdown%26utm_content=Body_threatdown/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/zRAUlSnmhfp_Sn7w-8OED8FKVkfQhQ8V4_5yapOB6aY=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown</span></a> researchers assess that AI capable of exploiting vulnerabilities at scale could reach criminal marketplaces within roughly six months. Read the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_source=tldr%26utm_medium=referral%26utm_campaign=2026-08-14_Primary_Threatdown%26utm_content=Body_cybercrime_age_ai/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/IyUxUMs63KzI_pAFskB1JKqirdR_IxFu1uyLLJ9CGyw=452" rel="noopener noreferrer nofollow" target="_blank"><span><em>Cybercrime in the age of AI</em></span></a> report to see what they found.
<p></p>
<p>Want to learn more? Join ThreatDown researchers for a look at how AI is reshaping the threat landscape, including:</p>
<ul>
<li>The techniques criminals use to exploit shadow AI.</li>
<li>What the rise in offline, "guardrail-free" AI models means for cybersecurity.</li>
<li>Why you have six months to prepare for criminals with Mythos-class AI.</li>
</ul>
<p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Flp-ai-cybercrime-report-webinar%2F%3Fmkt_tok=ODA1LVVTRy0zMDAAAAGjU4RxCUNv0Dvb0k37O4kkPsZAr4sxJdaK4DZLq9TTn8-uPzgFxbUzQtEnZc9e1_CIqMDERIUNO1lwDRM4rEk%26utm_source=marketo%26utm_medium=email%26utm_campaign=20260521_wb_threatDown_itdr_prospect_webinar%26utm_content=v1_cta_save_seat/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/kmBYYjVSDgtPNYo9UI_YnaPA47XsqkpliUNVRX7J0zU=452" rel="noopener noreferrer nofollow" target="_blank"><span>Save your seat</span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FsWEmq3/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/0L4LXD6MedPUqQu_wii8byhiyVJJEXBwezkK7XKKDNA=452">
<span>
<strong>Stealthy βCity-Forum' Attacks Target Salesforce and ServiceNow With Custom Toolset (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Reco tracked City-Forum using one Go binary against Salesforce Aura, Salesforce LWR, and ServiceNow. The campaign queried unauthenticated guest-user access, gathering exposed Salesforce records and ServiceNow search results. One target logged more than 560,000 guest Aura enumeration events from a single IP address.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FrDsnK3/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/dQi6lHDpGVjkIN-jYLabuFOzivZlzNQz4yNGTMmX0Gk=452">
<span>
<strong>Critical VMware vCenter RCE Flaw Exploited for Reverse SSH Access (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Digital forensics firm QUIRSO reports that a recently patched, critical vulnerability in VMware vCenter Syslog Server is actively being exploited by threat actors. The vulnerability is a directory traversal vulnerability that could be exploited by unauthenticated attackers to gain remote code execution. QUIRSO stated that the threat actor is deploying the reverse_ssh C2 to establish persistence on compromised servers.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Ft4yfnE/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/b8Y-OY9yqD167Hn8bNSHtE8ELROANRtjU_3RtUnY9gY=452">
<span>
<strong>Trezor Discloses Data Breach Affecting Nearly 14k Customers (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14k customers via a breach of its logistics provider ShipMonk. Nearly 12k customers had their names, email, shipping addresses, and phone numbers exposed, while nearly 2k only had their name, city, and email exposed. ShipMonk stated in their breach disclosures that the data breach came as part of the recent Metabase hacks.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fportswigger.net%2Fresearch%2Fcan-ai-do-novel-security-research%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/I6ZgMTsQSqS94XoTAt7NU1Le9oZPkJpCAjSqZ8T96kk=452">
<span>
<strong>Can AI do novel security research? Meet the HTTP Terminator (20 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
PortSwigger built HTTP Terminator to generate and test HTTP desync hypotheses on 30,000 authorized targets. RFC fragments produced 30,000 payloads, and testing identified about 700 vulnerable targets. Confirmed findings included multipart/byteranges desyncs, Apache Traffic Server CVE-2026-63078, response-queue poisoning paths, and a Citrix NetScaler configuration that exposed a bank API key. Deterministic validation gates removed false positives during exploitation, and the system also identified leads for response forking, status-line injection, range cache poisoning, and shared-parser confusion.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fblog%2F2026%2F07%2F16%2Fleast-privilege-for-ai-agents-identity-access-and-tool-binding%2F%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/uszdTRw5mkmBGs33Hf0Pp-6OAKrRrdNf_l22Ulg_ZxU=452">
<span>
<strong>Least Privilege for AI Agents: Identity, Access, and Tool Binding (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
To properly scope agent identities, teams should seek to establish dedicated agent identities with least-privilege, task-based roles that are scoped to the access and tools the agent needs, and end-to-end auditability. Teams should leverage just-in-time access mechanisms to dynamically create short-lived permissions that will automatically expire and rotate. Agents should also have a human that is explicitly designated as responsible for any human-gated approvals and incident response.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fxbow.com%2Fblog%2Fautonomous-agent-safety-guardrails%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/kaSd0ECGMED3z0kvLkCaUZr6uTMhpMeyAIVlA9TrVpU=452">
<span>
<strong>Engineering The Impossible: Adding Safety To Autonomous Agents (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AI models from OpenAI, Anthropic, and Meta successfully broke out of bounded evaluation environments this year by prioritizing infrastructure access over prompt-level instructions restricting internet connectivity. In notable incidents, an OpenAI model exploited a zero-day in Hugging Face's production systems, while Anthropic models escaped misconfigured capture-the-flag setups to compromise three real organizations. To prevent similar breakouts, this post details its defense-in-depth architecture, which utilizes strict DNS-layer egress blocking and an independent Guardian Model to vet every action before execution.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fengineering.fb.com%2F2026%2F08%2F12%2Fsecurity%2Fhow-were-building-scam-alert-whatsapp%2F%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/9FiofBiHhABgvNPjdFThH-b3BemIJln4U0isTGuCao8=452">
<span>
<strong>How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees (11 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
WhatsApp's beta Scam Alert scans non-contact messages locally for scam patterns. Warnings let users block, report, or trust a chat while message content stays on-device. Telemetry contains aggregated warning and action counts, processed in trusted execution environments with differential privacy. Model hashes and versions appear in a public ledger, and clients verify signatures, hashes, and privacy settings before sending metrics.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fmindgard.ai%2F%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/qKCtX924xVtyLOzuHh3gbS9NHhPDvFVPCkPSVenmGYQ=452">
<span>
<strong>Mindgard (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Mindgard provides automated security testing and runtime protection for models, agents, and applications. It maps attack surfaces, finds exploitable flaws, assesses risk, and blocks attacks.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fcloudflare%2Fcomputer%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/h9tSgMuD-A1i5rIjfVVi2mHafg0xCML5V-7DKmgGXIQ=452">
<span>
<strong>Cloudflare Computer (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cloudflare Computer is a virtual filesystem that lives inside a Durable Object. The Durable Object holds authoritative state in SQLite and exposes a pluggable execution surface.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F08%2F12%2Fafter-microsoft-threatened-legal-action-a-security-researcher-publishes-a-new-windows-zero-day-bug%2F%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/o13XFO_FhfABkkM-98sqyhXyqa_EFQrT9MyLSoVv0yE=452">
<span>
<strong>After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
ShieldBreak is a Windows Defender privilege-escalation exploit. A victim must run the supplied app. It affects Windows 10, Windows 11 25H2, and Windows Server 2025. Will Dormann verified it with Defender enabled and the exploit bypassed Microsoft's RoguePlanet fix. Microsoft is investigating and has not released a patch.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fresearch.checkpoint.com%2F2026%2Fthe-state-of-ransomware-q2-2026%2F%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/mLqQ9Ul67r667cqZGXjO12yaIVWScF6hrRfQBqeo0qQ=452">
<span>
<strong>The State of Ransomware Q2 2026 (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Check Point Research's Q2 2026 ransomware report highlights a rapidly fragmenting threat landscape, noting that the number of active groups has climbed to 93 while the top ten syndicates' market share dropped significantly. Qilin remained the most prolific operator, though an emerging group known as The Gentlemen surged to second place after reportedly utilizing AI coding assistants to build its ransomware management panel in just three days. Although victim payment rates have hit a multi-year low of 23 percent, law enforcement agencies have adapted their disruption strategies to target shared criminal infrastructure, such as laundering platforms and malware signing services, rather than individual groups.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.coindesk.com%2Ftech%2F2026%2F08%2F13%2Fbitcoin-firms-ask-ai-labs-for-same-tools-attackers-already-have%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/ThVtXSY_C1v9fPTF-3eTEaBusNf0Lt5SMaFLFlTyDw0=452">
<span>
<strong>Bitcoin Firms Ask AI Labs for the Same Tools Attackers Already Have (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A coalition of over three dozen bitcoin and crypto companies signed a letter calling on the βlargest AI labsβ to give open-source security researchers early access to their most capable models. The central complaint is that the Bitcoin Core developers group cannot access the labs' programs for trusted security partners, leading to them falling behind attackers. The letter comes in the wake of recent major, AI-enabled attacks on crypto firms.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.scworld.com%2Fbrief%2Fuber-freight-investigating-data-security-incident-after-helix-claims-breach%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/WIt7OclVEzJaHexfmBiwWXByhaQipcuiE55_Ipo9CEo=452">
<span>
<strong>Uber Freight investigating data security incident after Helix claims breach (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Helix claims it stole nearly one million Uber Freight files.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Farstechnica.com%2Fsecurity%2F2026%2F08%2Fwhite-house-recruits-security-firms-to-hack-overseas-cybercriminals%2F%3Futm_source=tldrinfosec/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/ufPOA7hbw4X1-WDHtXrYeZ68vrsNL5tj-8eGIjuaP-c=452">
<span>
<strong>Private security firms will soon be allowed to hack overseas cybercriminals (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Trump administration will authorize vetted private security firms to conduct offensive cyber operations against overseas criminal networks operating ransomware, sextortion, and financial fraud schemes, subject to a $1 million compliance escrow.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/Sp2C_ivyGo1btRsy6G906-98JcbdwPYYeRted-cglgY=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/LtLdX8plJHa4mB9LK1Z4TI3EiAZBe5Y5LkzVJibfKdY=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/aXn7rwNeMJThGgxxUbQFPMl7wlJ_b9pxX0W3AnY_CAo=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/mXFsVXta8ODPZnKx6MbDkZkUhWBBnzgtRyoZ5MHMcXo=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/hho-lnLnhh_5PwH4LYO9C_7x0rE9_VVRG6BzLw1MF-M=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/MEA4pcFBvlY4CJOZ-GvUwXfUy3SH2BvWdTbWVsF8R0c=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/uekKIYsgmtNNNcrVn-EOudfonoCgFx7M6omQqIefsUw=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/IYTiRiAThNEO8vX7JswBRzcPZWEGyn8Z9x4SKMAV3_g=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/Q8XoxgbCVl4XbUEFs8OQsVybXXdaJqkQiZiUAA-Poho=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/WGgxEqZ6fqO8CHJ7uRiIqRhtupz9JTYIp-wSwiakHlA=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=8c3b92d2-97d4-11f1-8af4-1d92364540fe%26pt=campaign%26pv=4%26spa=1786712486%26t=1786712905%26s=509fb9cfe35ff1b85d652af9e3e701cb40b55affbc641c14865a6a3d2f4265e2/1/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/RI18H23J-Ps84LS7E5mSRSt46GwoQe-qYvZ8Uxs869s=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a0006356a7-0fa986ef-f546-4c38-9798-d48e10b4f069-000000/mBpuWUIaxYP9q2VfYIJ7OdVLNUfwg5rXeYpR4uYULKU=452" style="display: none; width: 1px; height: 1px;">
</body></html>