<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Beacon CRM confirmed an attacker used an AWS access key exposed in public JavaScript. Cost data showed transfers matching all stored records </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/Kb-5rrVjvgyQiS3e0PSos6tx4LLzrvfqkjw2W0jTEY8=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/Tg1QYMnOZ2It6_iR2jN4p33p-CbC76-dAZujwZMwmhM=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=122b5b14-9aca-11f1-91c5-c3a09e944feb%26pt=campaign%26t=1787058455%26s=77c3976c742b374ad734221902aa7fa9ad004e77e276b7cf85561f584297eeb5/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/I0OP2nrNGA00UEf241ptxYHb_75WiDv6agnWqe2WvlA=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.horizon3.ai%2Foperationalizing-ctem-a-practical-playbook-for-continuous-threat-exposure-management%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctem-webinar_header_gartner_orgs_prioritize/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/xQRZOfZGiq8hocRNrERp02CTfBOdrrCiHGdt8z27nok=452"><img src="https://images.tldr.tech/horizon3.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="Horizon 3"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-18</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.horizon3.ai%2Foperationalizing-ctem-a-practical-playbook-for-continuous-threat-exposure-management%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctem-webinar_header_gartner_orgs_prioritize/2/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/SedsiDc1t8pJkdC0ZZdaHBv2pRLhS-H_-706nH5RH5U=452">
<span>
<strong>Gartner: Orgs that prioritize CTEM are 3x less likely to suffer a breach (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
You have more visibility than ever. Is your risk actually lower?<p></p><p>Instead of chasing vulnerability noise, security teams want to verify real attack paths so they know what they do matters. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.horizon3.ai%2Foperationalizing-ctem-a-practical-playbook-for-continuous-threat-exposure-management%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctem-webinar_body_intro_horizon3_webinar/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/3tRy1Y7SgL6cCO6fu-QnbtjbYRR_XlLS5wm1SgYTsZI=452" rel="noopener noreferrer nofollow" target="_blank"><span>This Horizon3 webinar</span></a> lays out how to do that by operationalizing CTEM. </p>
<p>📊 Join for the people, process, and metrics changes that you need to put CTEM principles into practice.</p>
<p>🥷 Take the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.horizon3.ai%2Foperationalizing-ctem-a-practical-playbook-for-continuous-threat-exposure-management%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctem-webinar_body_outro_attackers_perspective/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/iAV_U4XbQsY4OudpJW7nBOz55N6HGGh8gcQVItxfjCo=452" rel="noopener noreferrer nofollow" target="_blank"><span>attacker's perspective</span></a> to pivot from static CVE lists to demonstrating meaningful risk reduction.</p>
<p>👉 If you feel like you're getting too much visibility without reducing risk, this is for you. </p>
<p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.horizon3.ai%2Foperationalizing-ctem-a-practical-playbook-for-continuous-threat-exposure-management%3Futm_source=tldr%26utm_medium=newsletter%26utm_campaign=2026q3%26utm_content=ctem-webinar_cta_how_reduce_exposure/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/RM5DugdcispR-xr_T60ENEIc3Aj_GiwWon5_iGWAiwQ=452" rel="noopener noreferrer nofollow" target="_blank"><span>See how to reduce your exposure with CTEM</span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcybersecuritynews.com%2Fbeacon-crm-database-theft%2F%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/qC863WeRyYQyiwnPpR1Y2gUWgdBW8Uk2pClwdvJuAhE=452">
<span>
<strong>Beacon CRM Confirms Full Database Theft After AWS Access Key Breach (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Beacon CRM confirmed an attacker used an AWS access key exposed in public JavaScript. Cost data showed transfers matching all stored records and attachments. With valid credentials, the attackers were able to decrypt protected data during download. Beacon rotated keys, removed client-side secrets, and added endpoint and cloud monitoring.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fkoreaherald.com%2Farticle%2F10842345%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/jlsBJxKig8eQxfVwHqTx1QL4CqqfkXI6akATIbw6-ZY=452">
<span>
<strong>Sogang University Hit By Personal Information Breach of 180,000 (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
South Korea's Sogang University disclosed a data breach affecting 180k students, alumni, and employees. The compromised information includes student identification numbers, names, affiliations, email addresses, mobile phone numbers, and encrypted passwords for the university's integrated login system.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FB5XZcL/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/uPT-62Ij54fMbjek-iL59-ALvuhlyaYa7n097JKbhZA=452">
<span>
<strong>Wallet Provider SafePal Says Data Breach Exposed Personal Info of Nearly 40,000 Customers (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
This past weekend, crypto wallet provider SafePal announced that an authorization flaw in its order tracking system allowed unauthorized access to personal data belonging to nearly 40k customers. The breached data includes customer names, email and shipping addresses, phone numbers, and purchase details, but did not involve any wallet credentials, financial details, or government IDs.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fportswigger.net%2Fresearch%2Fcss-the-bomb-inside-your-inbox%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/7cdQdgTqos02durafYeBo5IjhoZeUoohKecV2bpBQ0I=452">
<span>
<strong>CSS: The Bomb Inside Your Inbox (20 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Portswigger demonstrates CSS and HTML attacks against webmail sanitizers. Outlook labels can trigger interface actions, while a CSS parser flaw enables arbitrary CSS injection and a spoofed login screen that captures passwords in Firefox. Yahoo Mail and AOL Mail allowed pasted CSS to race sanitization, exposing Medium email-login tokens. Fastmail image-proxy flaws enabled view tracking, ProtonMail could reveal an IP address, and hidden prompt instructions in email content directing Atlas browser actions. The recommended security controls include sandboxed iframes, restrictive allowlists, blocked image requests, and filtering dangerous selectors.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fowasp.org%2Fwww-project-top-10-ci-cd-security-risks%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/Z0kmI1EcuqPCDkz_rhaMhlE5HP4F5s-wHwRVyPANN2g=452">
<span>
<strong>OWASP Top 10 CI/CD Security Risks (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The OWASP Top 10 CI/CD Security Risks initiative provides a framework to help defenders identify and secure vulnerabilities within continuous integration and delivery environments. The list catalogs critical risks including dependency-chain abuse, poisoned pipeline execution, inadequate access controls, credential hygiene issues, artifact integrity gaps, insecure configurations, and insufficient logging. The project provides recommended security controls and references to help organizations mitigate identified CI/CD risks.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhackers-arise.com%2Fdigital-forensics-attacking-sam-and-extracting-hashes-with-7z%2F%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/-Zzag9vgaZwC8-fbDflQr70Q8Ucd71sJnXwNalwtaUY=452">
<span>
<strong>Attacking SAM and Extracting Hashes With 7z (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
7z is an archiving and unarchiving tool that is incredibly popular on Windows systems. Users can extract hives by typing \\.\ in the 7z address bar and then navigating to PhysicalDrive0 followed by 0.ntfs to locate the system hives which can be extracted to a separate system and then cracked. This technique requires GUI access as 7z can only parse physical disks and NTFS partitions through the File Manager GUI.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fpages.awscloud.com%2Fawsmp-gim-85hk-webinar-sec-grc-webinar-grc-webinar.html%3Ftrk=3df23b3d-8c60-4c12-acfc-67e2ea5e8849%26sc_channel=el%26utm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/NtDTvf7DCuw_6Pve7-nu1a0tZL-qk7PTrFj-RtYyzO8=452">
<span>
<strong>Modernize application and API security (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Watch this <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fpages.awscloud.com%2Fawsmp-gim-85hk-webinar-sec-grc-webinar-grc-webinar.html%3Ftrk=3df23b3d-8c60-4c12-acfc-67e2ea5e8849%26sc_channel=el/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/pyvGDCo3stAUoHLmS3lB554rVBOAPrzZcTprONWIAwI=452" rel="noopener noreferrer nofollow" target="_blank"><span>on-demand webinar</span></a> from AWS and SANS Institute to explore how APIs, cloud-native development, and agentic AI reshape security risks. Learn strategies to evolve threat models, strengthen governance, and adapt controls. Watch now and <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fpages.awscloud.com%2Fawsmp-gim-85hk-webinar-sec-grc-webinar-grc-webinar.html%3Ftrk=3df23b3d-8c60-4c12-acfc-67e2ea5e8849%26sc_channel=el/2/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/KNLmgbzRppBdN_ERs_vjGnFUm36wH589Y4gxqAFYyvM=452" rel="noopener noreferrer nofollow" target="_blank"><span>explore AWS Partner solutions in AWS Marketplace.</span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FBikebrainz%2FNullock%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/69BtqaJAMdR7R0RqMrYly2689tBF-Nr46gabxAL0juY=452">
<span>
<strong>Nullock (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Nullock is a free, self-hosted alternative to Burp Suite Pro that contains an MITM proxy with a full active scanner (SQLi/XSS/SSRF/XXE/SSTI/smuggling), recon, OAST, nuclei-style templates, and a CI security gate.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Falephnull-sh%2Fdeadair%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/9lL1fsoIs5nfQgpq4qssvQfIpUAziEhyACzADYDcdYw=452">
<span>
<strong>deadair (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
deadair is an open-source tool that audits live SIEM rule inventories to identify active detections that are failing silently due to missing, stale, or schema-incompatible telemetry. By utilizing read-only metadata credentials, the tool resolves rule inputs against backend semantics to verify index resolution, document freshness, and ingest lag across Elastic Security and OpenSearch Security Analytics environments. Security engineering teams can deploy deadair to generate fleet-wide coverage reports or to automatically gate candidate detection rules within their CI pipelines.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Frabbitstack%2Ffibratus%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/Rw9dNwH8Cwnl5e-hXaeYocC6CjEkIHisRicbYH11FEI=452">
<span>
<strong>Fibratus (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Fibratus detects and eradicates advanced attacker tradecraft, malware, and emerging threats by scrutinizing and asserting a wide spectrum of system events against a behavior-driven rule engine and YARA memory scanner.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fsecurity%2F2026%2F08%2F11%2Fmozilla-revokes-firefox-signing-key-after-unencrypted-copy-lands-in-github%2F5285908%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/DMzM51cUVAG5TkAAbzU7zwLKwHiGCszklDVHNXQjOrI=452">
<span>
<strong>Mozilla Revokes Firefox Signing Key After Unencrypted Copy Lands in GitHub (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Mozilla revoked and replaced a GPG private subkey after an unencrypted copy of it was pushed to a private GitHub repository. The key signed Firefox and Thunderbird Linux tarballs, RPM packages, and checksums. Mozilla found no unauthorized access in the available audit records, but manual signature verifiers must import the new key and revoke the old key.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FZKxwUp/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/PFa06YuLRW1bE2HVQx1J6Cc7a15Q_KiRtrUyXwrNgpQ=452">
<span>
<strong>Trivy, Not LiteLLM Behind the 2,500 Org Compromise (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
SOCRadar tied 2,085 of 2,188 tracked data exposures to the earlier Trivy compromise. Data collection ran from March 19 to March 24 and showed that malicious LiteLLM packages appeared only for 40 minutes on March 24. The worm stole tokens, keys, and credentials from CI/CD systems, then used developer secrets to poison more packages. Stolen datasets are now being sold on Telegram.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Floongleakattack.com%2F%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/VxMCufi_9uI4FoWQf4eBBOvcykGCEatdclNEKHbTYA4=452">
<span>
<strong>LoongLeak (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
LoongLeak affects Loongson 3A5000 and 3A6000 processors.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.windowslatest.com%2F2026%2F08%2F17%2Fwindows-11-is-losing-a-legacy-tool-wmic-hat-malware-and-ransomware-have-abused-for-years%2F%3Futm_source=tldrinfosec/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/0Ahuv3igy_1ihcMWsUhFq6iooB_Pr-Ut2FPoPXoH5CI=452">
<span>
<strong>Windows 11 is Fully Removing a Legacy Tool that Malware and Ransomware Have Abused for Years (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Microsoft will be removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 systems starting in 24H2, 25H2, and 26H2.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/geIA5qZ5Y_50mF6EI6gd3jJzj1gttU9z8CsjLbZUexY=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/PL-XRKyQoEaLhpfgWbnpjjKphSq9GLLOTE-7OUb1jac=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/8siHowyGld2LmqklQ8t1-QZ-3QCjcQv4bAyZ3mGUR6g=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/LZAVc9pK0-S5kcHdRvkn2PxXa5js7rEXHCYj9zR1zYA=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/Z9v4AQ1IVO6hNK2Ilwn1Ud7Z4aPLlJvzLaSKqj4ayYs=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/lN2681Rrw40kgsII3OFeyz4CqUIY86WDospTvw2PqX4=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/asYX5UbLZFIWw46LfqlZsXBbB4sHvCFsdUkMmOtyfPA=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/pYwkW14E8wMIL4_G62Ie7k7DXDzMRJdlbvMUyDLG_Rs=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/m5e8jNCFiyXWmwa6bN6NLstnDzld1nQj0W7sAv2KUCM=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/XCKy7RCpVkKmy8SSH39lexiWd-4jrfx4OJkH4CoZ-JI=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=122b5b14-9aca-11f1-91c5-c3a09e944feb%26pt=campaign%26pv=4%26spa=1787058045%26t=1787058455%26s=8529a5505d025ecf606a8050ba974307f3bb779a55f46c83370b316aefdbf070/1/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/vB3urPKhB5udvBNLW7u0A02UFgwMLq_H_0SRcUreU3k=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a014fc0272-f3cc1b10-e63b-45d1-8ec4-47dc8c57cf26-000000/IL3_mfKYVEYYh78KZTRe8vUNEFYHkO9FC1VEGBgMJ-w=452" style="display: none; width: 1px; height: 1px;">
</body></html>