<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">A signature check alone doesn't prove a device is safe. This post breaks secure boot into four failure buckets: did the check run β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β β </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/wUjgxpZxzh6eTHMhoorN0hvlXPXBMIMVFrnwbB64aDE=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/YGRwE_Y-Jo6CuVZJ4cTTi6vMXbpR3RCYi032KoHZ498=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=047a3a74-9c89-11f1-8e69-ef3eb2468a1e%26pt=campaign%26t=1787231262%26s=5a131758f38f7cc72b2f969c0b4048567034aa6ea2e653bb986aa96f059d03d4/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/48DHYWZf5AN5jxbuxObyU0Zny6ebkWeUmaoOAMKnl7E=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-20</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FPFF8Rv/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/VChA1RFLde3C-DdEy_rbb-i1jHGTNniZldu7eF4Qdsg=452">
<span>
<strong>CareCloud Data Breach Impact Grows to 3.7 Million Individuals (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CareCloud detected a network intrusion after an electronic health-record disruption in March. Attackers accessed an AWS environment from March 10 to 16 and claimed database theft. Exposed data includes identity details, insurance and medical records, and payment-card data for a limited group. HHS now lists 3,756,469 affected people, up from roughly 350,000 in state filings.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FA4O2A7/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/lX5V3oLFhwx1QmEOfLjAUSnR3Nz3psJW1AZSWzlgSNg=452">
<span>
<strong>Sakura Internet Hack Exposes Data of up to 1.36M Accounts (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Japanese cloud and data center provider Sakura Internet disclosed that hackers accessed its sales management system, exposing data of 1.36M users. Sakura detected the hack while investigating another incident involving unauthorized access to 538 accounts. Sakura is currently notifying customers and relevant authorities.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FrKqK4Q/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/MNgoTLeeIlhxO_TQYODJbEIGouPdo9ovapL8i_9beCc=452">
<span>
<strong>Hackers Compromise 14,500 Dahua Web Cameras in 35-Day Campaign (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers at Hunt.io uncovered a hacking campaign that targeted Dahua IP cameras, mostly in Ukraine and Russia. Hunt.io discovered the campaign by finding a working directory on an HTTP server that the operators left unprotected. The threat actors compromised 12,234 cameras by brute-force scanning on TCP port 37777, 1,923 cameras by exploiting known vulnerabilities using a tool called p2pwn, and 283 cameras that were behind NAT using only serial numbers and SDK credentials embedded in Dahua applications.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§ </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.endorlabs.com%2Flearn%2Fhacking-your-life-with-ai-can-get-you-hacked%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/gUi0e90ACe2ln2EUNG2WGS8SyyRnrTwBgdP6bJ-FHZc=452">
<span>
<strong>Hacking Your Life With AI Can Get You Hacked (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Endor Labs found 14 critical and high-severity flaws across NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Airflow. Several described paths allowed unauthenticated remote code execution, prompt-driven code execution, sandbox escapes, command injection, or data theft. Flowise, Kestra, and Langflow exposed exploitable paths without sign-in under some configurations.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F0x434b.dev%2Fbreaking-secure-boot-without-breaking-the-crypto%2F%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/Uzq1VJEHVB-xmbPkin2LAD9Fgt_Z5RdM5cOg29YcA9Y=452">
<span>
<strong>Breaking Secure Boot Without Breaking the Crypto (57 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A signature check alone doesn't prove a device is safe. This post breaks secure boot into four failure buckets: did the check run, did it cover the right bytes, was the signer authorized, and do those bytes still run at execution time? It walks through Qualcomm's PBL/XBL-SC/TME chain, Android Verified Boot, DICE key derivation, and RATS attestation roles. Real CVEs illustrate each bucket: CVE-2019-2278 let a rejected keystore still verify a boot image, CVE-2023-48425 chains an AVB failure into a full bypass on a retail Chromecast, and CVE-2021-1931 lets one signed image authorize a different one.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fpipelab.org%2Fblog%2Fbenign-set-should-look-malicious%2F%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/QFFx-CGZE1B0h7olkJC9qO2eDYebE0BP8p_UoiuR_4w=452">
<span>
<strong>Your Benign Set Should Look Malicious (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
When testing detections to establish a false positive rate, it is common to build a set of benign data that should not be flagged. However, often the benign set is too benign and leads to artificially deflated false positive rates because the traffic doesn't resemble data that could be malicious. Instead, organizations should draw upon their internal docs, examples, etc to find negatives that matter to the organization and build a benign set that includes those.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π§βπ»</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_medium=referral%26utm_source=tldr/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/C76gwdBJnQHMaPhtDshhfwkICcFzGvPAXSUm_xZhxgI=452">
<span>
<strong>6,000+ "guardrail-free" AI models. One download away. (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
AI-powered cybercrime is no longer just a future risk. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/JrnK7Mpf1fg_TGt-W4wX_GrWxCXEaOCC3mBOGDh1f0w=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown's </span></a>new research found it's already here, hiding in plain sight on infrastructure organizations already trust. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2F/2/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/3oataZaO-SYtF2LzPCc2isJyNP2FnU6law6PjqP5qgM=452" rel="noopener noreferrer nofollow" target="_blank"><span>ThreatDown</span></a> researchers assess that AI capable of exploiting vulnerabilities at scale could reach criminal marketplaces within roughly six months. Read the <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.threatdown.com%2Fdl-cybercrime-in-age-of-ai-2026%2F%3Futm_medium=referral%26utm_source=tldr/2/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/YFoTOTGIYQ0ycAHIWSX4St3t6FFT1dOCfPORvL67ras=452" rel="noopener noreferrer nofollow" target="_blank"><span><em>Cybercrime in the age of AI</em></span></a> report.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fedoardottt%2Fsecfiles%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/H5DGLhu0RcXXafhhwgAlm1Qd6nswTZjpbNZgyUws3wI=452">
<span>
<strong>SecFiles (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Useful files for penetration tests, security assessments, bug bounty, and other security-related stuff.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fshazzer.co.uk%2Fblog%2Fshazzer-teams-collaborative-fuzzing%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/a-yxZzVgZ1SRAPxFYKqxMttdC_CTscTk7yWuV0QFpmU=452">
<span>
<strong>Shazzer Teams: Collaborative Fuzzing (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Shazzer Teams lets security researchers pool browser resources on a private distributed fuzzing network separate from the public pool while sharing a common vector library. Owners manage membership through expiring, usage-limited invite links and role-based permissions, and any member's browser automatically joins the team's fuzzing pool when the Network page is open.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fseifreed%2FCipherRun%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/T6o6CLbQd6OS9mB9NyhhQJgbBRkDfvXbNNPKsLBxOv4=452">
<span>
<strong>CipherRun (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CipherRun is a comprehensive, TLS/SSL scanner written in Rust. It combines protocol and cipher analysis, vulnerability testing, compliance checks, and certificate transparency monitoring in a single high-performance CLI and API-ready engine.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">π</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fransom-busters-claims-it-hacked.html%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/ndINCZ_7IhmFdXUE9nUH11OHUk6b4nu5oXt6VlRYs8s=452">
<span>
<strong>Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Ransom Busters emailed ransomware victims, seeking $20,000 to $60,000. It claimed access to ransomware servers and offered file recovery and deletion of stolen data. GuidePoint linked two incidents through shared tooling, a βNumlock!123β backdoor account, and hostname DESKTOP-BBETH6K. The activity may be a ransomware affiliate posing as a recovery service, but payments cannot verify data deletion.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwccftech.com%2Fchina-state-agencies-uninstall-windows-10-cmit-government-edition%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/bWK8CKdhYl3-7mf8_UtV6oemoRag11RQd27CGOxHTNg=452">
<span>
<strong>China Directs State Agencies to Uninstall Custom Windows 10 Edition Over Security Concerns (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
China's Ministry of State Security has ordered state-linked organizations to immediately uninstall the custom Windows 10 CMIT edition due to data security concerns regarding foreign software reliance. This sweeping directive abruptly accelerates the retirement of the operating system originally developed through a 2016 joint venture with Microsoft. The government had previously scheduled the highly modified software to remain in active use until February 2027.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">β‘</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdecipher.sc%2F2026%2F08%2F18%2Fmlflow-bug-actively-exploited-to-steal-credentials%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/WqZefvWwDZ5kkjMU3aCKZPm1GycN_plC35JEVLVc6aQ=452">
<span>
<strong>MLflow Bug Actively Exploited to Steal Credentials (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Organizations running MLflow versions prior to 3.15.0 must urgently patch to mitigate an actively exploited Server-Side Request Forgery vulnerability (CVE-2026-64849) that allows unauthenticated attackers to steal cloud credentials via DNS rebinding and malicious webhook redirects.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdanielmiessler.com%2Fblog%2Fprompt-injection-worm%3Futm_source=tldrinfosec/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/nWq4Kp4027-55cFm8tlWQPJhKNU8wPetBs1QDMoEQ_M=452">
<span>
<strong>I'm Worried About a Prompt Injection Worm (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A prompt-injection worm could exploit AI agents parsing external inputs, such as emails, to exfiltrate data and propagate through victims' communication channels, so organizations should map AI integrations, model access levels, and build AI-specific incident response plans.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/awxYkvrElCjsXpEEhaj63hD29j2yvQ9cy8PG-kNR-Fo=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/2dUYWKjez0lgNe24-Kejr9VxSD9KmaZMgiV2jQb3yfo=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? π°
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/hmJ0dzKJrFfT21JBqnFh3KvAiWHpM2B-UURuTsWRoZU=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? πΌ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/56ojouh4bOgInLBHl8Z42JT4MGIev-B-IRIzTIhINi8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/XamT-WKHkAJyoxFcM4BR6_DGiZhpk3zDXkVIOw60Eog=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/aWykcNYxh-HwZc57Bi3c5TouwMVWhRdClHNYeNN8N60=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/Q1M6y1Bs3kpJ-5zhcaWR_9Ml2rEBtQobStJsSqKXPlg=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/kMvWS6jEgBfEuTpfRqA_Ukd5cPFESrGEwps1GquRTPQ=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/TziEHWM6pRc31yWMxQvzI8Gy0uN0QYP2F2eM7_Nwavg=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/QWCm9HJwG0FsG5vEx613P4kIKeKVFXN_XgH3mgSfjJg=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=047a3a74-9c89-11f1-8e69-ef3eb2468a1e%26pt=campaign%26pv=4%26spa=1787230821%26t=1787231262%26s=2f64d236097d8c413155685eee6791d84396c5bb6d427ae714719666c1ac4de4/1/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/cYwJ9ReSvHQ5HkkKRhg-_Jxo8I7C3FUBJor29zZKRrg=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a01f48d61c-34ae6122-0a5c-4a89-8f8e-072a21ca99ae-000000/vrZU0aKlmKtliN6ukdJkHBl7rSQKFPnrk1aSfODjZTA=452" style="display: none; width: 1px; height: 1px;">
</body></html>