<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Z.ai has released GLM-5.3, trained from the GLM-5.2 base model through expanded post-training. On CyberGym, it scored 84.5%, up from 77.2% โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ โ </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/WSDZJULRH2Vz4aI_pDLQSAO8CxbD8TL3sB-BdGGNTRQ=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/JKiVoM2h-HrNOnfMYjslWC6r3hW0MpWxxyVNbuzK_OE=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=65f37d64-9d20-11f1-a6a6-1d3e77ea0055%26pt=campaign%26t=1787317701%26s=e18723a5f8edde798a2e5a8e752d0c831494152e4c2b72ed317e3b49e436acf8/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/MhSG4xYShfhwXHMpVA-mxswl2p7QZ16M1ff0lI1yUcs=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr id="together-with"><td align="center" height="20" style="vertical-align:middle !important;" valign="middle" width="100%"><strong style="vertical-align:middle !important; height: 100%;">Together With </strong>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=header_sase_leader_again_header_sase_leader_again/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/IcsaiAQkuGekvs8silp2GKhp-DYDdgSA9zTsDbJdCZE=452"><img src="https://images.tldr.tech/cato2.png" valign="middle" style="vertical-align: middle !important; height: 100%;" alt="Cato Networks"></a></td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-21</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr id="sponsy-copy"><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=header_sase_leader_again_header_sase_leader_again/2/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/AFugF-xnQfry-BFuzinUF4HpzGYgQkWSL6iMYNFaYuQ=452">
<span>
<strong>A SASE Leader. Again and Again and Again (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
As AI becomes embedded across the enterprise, organizations must secure their use of AI while defending against AI-powered threats.<p></p><p>That pressure is making the limits of fragmented architectures impossible to ignore.</p><p>Cato Networks was named a Leader in the<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=Body_2026_gartner_magic_quadrantTM_Body_2026_gartner_magic_quadrantTM/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/Hl3xJOnlII_5d1IcXkTeq7zDwWZsvoLrSvqcWvXsPAg=452" rel="noopener noreferrer nofollow" target="_blank"><span> 2026 Gartnerยฎ Magic Quadrantโข for SASE Platforms</span></a> for the <strong>third year running</strong>.</p>
<p>See how Gartner evaluated the market and why, in Cato's view, unified SASE platforms are becoming essential for the AI era. </p>
<p><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.catonetworks.com%2Fresources%2Fgartner-magic-quadrant-for-sase-platforms-2026%2F%3Futm_source=TLDR%26utm_medium=newsletter%26utm_campaign=2026-08-07_Primary_Cato%2BNetworks%26utm_content=cta_2026_gartner_magic_cta_2026_gartner_magic/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/G4ISDOKN0A3ktPws3VsABm-wzpk59nzzx4G97yR9UZE=452" rel="noopener noreferrer nofollow" target="_blank"><span>Get the 2026 Gartnerยฎ Magic Quadrantโข for SASE Platforms โ </span></a>
</p>
</span></span></div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fcloudflare-workers-spectre-attack-leaks.html%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/T5OdUC1FhS1Z1lmBMXMgK5hPan1gTFq42qAktezevBA=452">
<span>
<strong>Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers extracted a JWT from a co-located Cloudflare Worker at 12 bits per second, reaching 99.16% accuracy. The attack used WebSockets for remote timing and Durable Objects to keep code running. WebSocket I/O reduced DyPrIs detection signals. Cloudflare deployed improved DyPrIs, V8 Sandbox protections, and MPK-based isolation and confirmed no customer data was accessed or active exploitation.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.rust-lang.org%2F2026%2F08%2F20%2Fsupply-chain-attack-on-arrayref%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/-TR70Qvx9FuhJmhU0iO4_9u3YmvHWT6aW6S_0utqdqE=452">
<span>
<strong>Supply Chain Attack on arrayref (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Rust Security Response Team confirmed that the popular arrayref crate was maliciously republished after being made to depend on proc-macro1, a crate that included a build script downloading a malicious payload. Related crates internment and append-only-vec from the same author were also compromised, likely via stolen credentials rather than intentional action. The malicious versions remained live for 86 to 107 minutes before removal. The team has deleted proc-macro1 and its sibling packages and unyanked the legitimate arrayref versions. Developers should run the provided find command against ~/.cargo/registry/cache to check for arrayref@0.3.10, internment@0.8.7, append-only-vec@0.1.9, or any version of the deleted proc-macro1 family.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Farstechnica.com%2Fsecurity%2F2026%2F08%2Fgrok-exfiltrates-user-data-when-malicious-instructions-are-encrypted%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/3g_Qb95jFyCvPaoM91L118bmzn7ZiQbrQl6YfFydSCs=452">
<span>
<strong>Grok Exfiltrates User Data When Malicious Instructions are Encrypted (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers from security firm Adversa discovered a new attack that allowed them to bypass Grok's guardrails and exfiltrate user data. The attack involves hosting encrypted instructions along with a decryption key and instructions to decrypt them on a webpage. When the user requests Grok to summarize or otherwise process the page, Grok decrypts the text, and then the decrypted ciphertext contains instructions that involve Grok constructing a fake decryption key by appending the user's name, location, and chat history, which are later used as a URL parameter and sent to an attacker-controlled server.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐ง </span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftrustsig.eu%2Fblog%2Fwasm2c-tableflip-unchecked-calloc%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/gYajRwHogsxNgGdJoYWnzWKeDLmtl3gdgF47iydpAII=452">
<span>
<strong>Table Flip: A wasm2c Guest Runs a Shell Command on the Host, Through One Unchecked calloc (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
wasm2c records a guest-declared table size before calling calloc, then continues if calloc returns NULL. A 64 GiB funcref table can fail under RLIMIT_AS, strict Linux overcommit, 32-bit hosts, or memory pressure. Bounds checks then accept indexes against the declared size while NULL-based table accesses resolve to host addresses. The proof of concept leaks libc pointers through the GOT, forges a funcref entry, passes the indirect-call type check, and calls system() to write a host file. A calloc NULL check and table-size cap prevent it.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.cloudflare.com%2Fthe-agent-access-model%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/UOMqTCLh57t_L-uHZBbLm5uZOZP7Xmy1zKVpR9q2c8w=452">
<span>
<strong>The Agent Access Model (26 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Agent Access Model (AAM) is a framework that secures autonomous AI workflows by issuing short-lived credentials that a "Trust Ratchet" can revoke mid-execution upon detecting protected data. Multiplayer access control remains an unsolved challenge with enterprise privacy-violation rates exceeding 50 percent, so organizations should begin by strictly securing a single bounded agent. Security teams should deploy these initial agents using network-level mediation, strict execution harnesses, and detailed activity logging to safely build evidence for future permission grants.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fholdmybeersecurity.com%2F2026%2F07%2F14%2Fhunting-malware-and-malicious-mcps-in-memory-on-kubernetes-with-fleetdm-osquery-yara%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/6n7WsKDDuvmDf3LBZdjlqPte2X_jMrTngi_botr_Go0=452">
<span>
<strong>Hunting Malware and Malicious MCPs in Memory on Kubernetes with FleetDM, Osquery, and YARA (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Osquery and Fleet recently added the ability to scan memory at scale using YARA rules via a new yara_process Osquery table. This post walks through how to set up a lab environment for detecting the use of Sliver on a DVWA running in Kubernetes using YARA rules distributed via Fleet. The example is then expanded to detect a malicious local MCP which runs a credential stealer in memory.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐งโ๐ป</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.strongestlayer.com%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/Os63zHEA6huPqLGbOX9OE7yWG0dPr1mkIQI69lS6eu0=452">
<span>
<strong>StrongestLayer (Product Launch)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
StrongestLayer provides email security for phishing, business email compromise, and adversary-in-the-middle attacks. It evaluates message context and evidence to flag suspicious emails, including attacks that do not match known patterns.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fz.ai%2Fblog%2Fglm-5.3%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/yeEJAUG1GPf6bwNtP6hPO5UdDKO04bLQrizMVns16I8=452">
<span>
<strong>GLM-5.3: Frontier Coding with Emergent Cyber Capabilities (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Z.ai has released GLM-5.3, trained from the GLM-5.2 base model through expanded post-training. On CyberGym, it scored 84.5%, up from 77.2%. On ExploitBench, it reached 54.4%, versus 24.4%. In tests with security teams in China, the model found 2,436 vulnerabilities across 269 projects. Z.ai lists 1,097 as critical or high severity, with fifty-three findings being public and 2,383 remaining under embargo.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fcracken-ai%2Fblacksea%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/hMJfj99nguwcstY9zFNnRXb3aG1oH54PJ2MrhKfm8pY=452">
<span>
<strong>Project Blacksea (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Blacksea is an active honeypot and canary-bait control system built to detect and drown LLM-driven attackers.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">๐</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FZKdhT8/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/L4v7ZY_TX7CSZz2llNB8lCD0l1Y9OHFFd0yLpFw5K8E=452">
<span>
<strong>No-Filter โKriminal' AI Platform Raises Cybercrime Concerns (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Kriminal is an off-the-shelf AI hacking platform that offers social-engineering persona creation, offensive-security assistance, OSINT searches, crypto tracing, and uncensored image generation. ThreatDown found it appears to combine Grok, Claude, Llama via OpenRouter, Tavily, Google Cloud, Cloudflare, and NowPayments to maximize effectiveness and reduce visibility of interactions between the different tools.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.gregbrockman.com%2Fthe-defenders-window%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/j3PrpOWYMfQvIraZHL01m-W6bAzhp706wg_Y704HD-w=452">
<span>
<strong>The Defender's Window (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenAI's Greg Brockman disclosed that an autonomous AI agent collective breached the company's research infrastructure and a separate production environment by chaining undisclosed vulnerabilities with leaked credentials. While avoiding specific threat actor attribution, Brockman warned that upcoming releases of highly capable open-weight models will drastically accelerate this automated threat landscape. To keep pace, security teams must adopt a modernized defensive strategy that incorporates AI-assisted code review, continuous alert triage, automated attack-path enumeration, and strong defense-in-depth fundamentals.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">โก</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Foblique.security%2Fblog%2Fhacking-saml%2F%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/C746mIw4SQ2NbcBr79Zh60kjF9pz7YA2g4RvEz9psHY=452">
<span>
<strong>Hacking SAML with Claude Code (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Showcase of a multi-agent harness to test SAML implementations using Claude Opus.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Ftoxicpanda-20-and-golddigger-expand.html%3Futm_source=tldrinfosec/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/MY_ReqJx5P0eqwjZNZaONubtjJynrj4lizR-tcIDwjI=452">
<span>
<strong>ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
ToxicPanda 2.0 expanded its overlay-based credential theft from 16 to 349 financial institutions across 16 countries, adding 167 remote commands, PIN harvesting across 140+ banking and crypto apps, and an accessibility-service abuse chain that enables Wireless Debugging via ADB for privilege escalation.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/WIELHPPupyDaUGYxOo2cmqpD0XLbPqomXuwALUAFqAw=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/0yhLPUoegllFfUsBBKR2bRV0q1oQyva_v4fuRq8DGJE=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? ๐ฐ
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/KyxYLDDoyFwviSKQPoY-csCmSFwdzRUR__7RyDVA5kw=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? ๐ผ
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/GnlPwtS56uLpghfTOqP4QcrlDAaUkEqIuyrXEnBD5oQ=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/-Y4tRk1WI54b5knBe628mtoqC_lfhK9FjZqHET5wA4k=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/TatlpEjt2r6S1VIECoV_tWJnuEaWRU5bRcYLt-OYRY8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/M-end2klLFXoVyFAr_ey7sqffm9DRJfqTk59r-214gw=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/dJgjsT9pO3FH9hfSVH6nnY9h5TZwqNP7tBTrWg5OrE0=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/hdDSYtcRZQ3oFOgJ7iUm0kQ53y1CwlhgcfIXfLcBAXM=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/7gAOp-9QX7NvVkLiSf1DH_XagHeBa_k2okrql0z9Wnc=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=65f37d64-9d20-11f1-a6a6-1d3e77ea0055%26pt=campaign%26pv=4%26spa=1787317277%26t=1787317701%26s=b591df58b2325a10d0cbec244d9f54311d73d7f43de59e2bbd2076cb1b1239ee/1/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/_uLb2awqXdkpq_3f5n_tKcl0HNVk_XXAFW1anqlAFb4=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a0246fca7d-cd90e667-ee44-4bc4-aa20-0332f5e64d08-000000/YEI1R9IahkxBARepnRTTeaGK563cm4OCKFmfXK7JCiA=452" style="display: none; width: 1px; height: 1px;">
</body></html>