<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">Researchers have trained LoRA to embed a dormant backdoor into Qwen 3.5 2B that will activate on a later date, executing a shell command </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/TgNSGs608gRd8gNAwqacg94KFOir3KkDqMAyv9mr_aU=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/4rlLxV-QiV6__uBb7b_Hcu1Lcj80bxi0-pgjMW7ICNA=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=3da714e6-9f92-11f1-a958-e33990d209d7%26pt=campaign%26t=1787576907%26s=4c0c16f7c364db09a57ed3673ca7e0ac3129a4d44f2015bc66ac2063185166fc/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/TRqezeeggAkmNGpJPhaa-1s_62NRUrPa_G02SdgVQrY=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-24</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FUAt9DH/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/qAHzIvGvqzXMRRt2nFzVjGy4NErY5lwwYCHkXObmIOg=452">
<span>
<strong>Hackers Infect Android Car Head Units with Proxy Botnet Malware (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The MoYu threat group has compromised DoFun-branded Android automotive head units by utilizing a rogue APK to deploy the "JarService" botnet malware. Delivered through the legitimate TWCore system app, the malware pulls instructions from an MQTT broker to convert infected vehicles into remote SOCKS5 proxy nodes and click-fraud clients. While researchers found no evidence of interference with physical vehicle controls, affected owners should actively monitor their network traffic for unauthorized communication with the cardoor[.]cn command domain.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FZ3OJZs/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/hJyKYQAkQX-qp4W12NGR_jIxxk1ae_1NlxTyT0vdOqo=452">
<span>
<strong>SickKids Data Breach Exposes Employee and Job Applicant Info (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Hospital for Sick Children (SickKids) disclosed that it suffered a data breach that impacted employees and job applicants. The hospital stated that the breach was caused by a vulnerability in a third-party software that SickKids and other organizations use.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FRL68xl/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/0_rNLoPFn96Tj3X2jHv8HGE3r2fQmM5y8DSgSMsV5rE=452">
<span>
<strong>New SynkLoader Malware Pushed in Microsoft Teams Phishing Campaigns (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Security researchers from Expel have discovered a previously unknown malware family which it dubbed SynkLoader and is being distributed via Microsoft Teams phishing campaigns. The attack directs victims to install a fake PowerShell Cleaner executable that is hosted in Azure to provide authenticity. The malware allows the attackers to select between modules to deploy: system profiler, persistence module, PhishLocker, which displays a fake Windows login screen to capture Windows account passwords, TrafficRedirector, which allows attackers to reach internal services, a RAT, a VNC, and a module status script.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fmorgin.ai%2Farticles%2Fyour-open-source-model-could-have-a-hidden-time-release-backdoor.html%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/WpOMyIZ2la5pRGdYQ4Edk-6Q6K-5c9fCJXf2qdf5cTQ=452">
<span>
<strong>Your Open Source Model Could Have a Hidden Time-Release Backdoor (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Researchers have trained LoRA to embed a dormant backdoor into Qwen 3.5 2B that will activate on a later date, executing a shell command instead of responding. This exploits OpenCode's system prompt, which automatically inserts the current date into the context at every turn. The approach builds on Anthropic's 2024 sleeper agent research and successfully triggered on 7 of 8 in-distribution and 9 of 10 held-out prompts on the target date, with no failures elsewhere. Notably, OpenAI's Codex also employs a similar date-leaking mechanism by default. Since OpenCode runs commands via --auto without confirmation, any system that auto-injects timestamps into context should restrict shell command execution to human approval, especially for open-weight models that are unverified.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsemgrep.dev%2Fblog%2F2026%2Fsha-pinning-for-github-actions-org-wide%2F%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/XZx84nMRrDjObhEoY_9W3jzgxDtLz_irD-nG_e9iqo8=452">
<span>
<strong>Speedrunning SHA pinning for GitHub Actions org-wide (18 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Spurred by the 2025 tj-actions/changed-files supply chain compromise, a Semgrep engineer successfully enforced full-length SHA pinning for GitHub Actions across 350 repositories. The deployment utilized native GitHub enforcement settings alongside tools like pinact and Renovate to automatically convert tags and eliminate unpinned reference classes at scale. Security teams adopting this playbook should auto-enroll new repositories via webhooks, monitor for pipeline failures, and update developer guidance files before strictly enforcing the restriction across their organization.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.elastic.co%2Fsecurity-labs%2Fai-coding-agent-audit-cursor-hooks%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/s_armXtuOqrbPfiRU6QtoGQlRbyGjFuDFS_lgW9bp1w=452">
<span>
<strong>13 Million Tool Calls: Auditing Every AI Coding Agent Action with Elastic Agent (12 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Elastic's Security Labs rolled out zero-dependency bash and PowerShell-based hooks for agentic IDEs like Cursor and Claude Code to monitor the commands run by AI agents in their environments. Elastic focused heavily on restricting who has access to agent logs and only collecting metadata to ensure user privacy. The article includes some sample ESQL queries for threat hunting and information extraction utilizing these logs.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fclaude.com%2Fblog%2Fbringing-claude-mythos-5-to-more-defenders%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/CWyosoff1vhTI_tI5NbmuOBhMNqZQEhGl5gek4N38w4=452">
<span>
<strong>Bringing the Cybersecurity Capabilities of Claude Mythos 5 to More Defenders (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Anthropic has upgraded its Enterprise Claude Security scanning tools to utilize the frontier-level Claude Mythos 5 model. To maintain platform security, defenders do not receive raw model outputs. Instead, they are provided with actionable vulnerability findings tagged with specific CWE categories, confidence scores, and severity ratings. Beyond the direct scanning upgrades, Anthropic also announced a $35 million Defender Advantage Fund to support open-source patching and expanded its Cyber Verification Program to grant vetted security researchers less-restricted access to Mythos-class capabilities.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FCDESpace%2FDetection-Skills%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/0sVLEE-Y62mmaEWL2cFNbdgDwrURick2mNTtvhIv8aQ=452">
<span>
<strong>Detection Skills (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Detection Skills is an open standard for the Agentic SOC that transforms static detections into agentic workflows.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Flordx64%2Fpentestkit%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/w1Y4XUE3JKqwEkKhiCjF7cLGKTFf0kpHqAQzY2CiTs4=452">
<span>
<strong>pentestkit (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
pentestkit is a multi-agent, context-accumulating penetration testing framework built on the Claude Agent SDK.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.frankel.ch%2Fsecurity-baked-into-jvm%2F4%2F%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/2YGut2A9AGvgzYdd5lr2qnUezKht9s0D0XHSsjQ7CMs=452">
<span>
<strong>Security Baked Into the JVM: Sixteen Subjects on the Wire (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The fourth installment of a JGDMS security series details how the DirtyChai JVM fork securely propagates user identity across remote calls. To mitigate denial-of-service attacks, the implementation strictly caps requests at 16 Subjects and 64 principals per Subject. Rather than blindly instantiating caller-asserted principal classes, the receiving side enforces a strict four-type allowlist and relies on inert placeholders for unrecognized inputs. Additionally, a SubjectAwareExecutor wrapper preserves calling identities across virtual-thread boundaries, while distributed transactions now require all participants to individually hold commit permissions before a manager will finalize them.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FpDWK0B/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/cjiMDJbpmWKJjXcfoxOrg25OGfxTJlBkDTDdKdoOZJI=452">
<span>
<strong>Hundreds of Leaked AWS Keys Give Full Control Over Corporate Accounts (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Truffle Security has been tracking AWS access key exposure for four years and reports that 9,300 of the access keys that they've discovered and tracked remain active. Of these 9,300 keys, 817 of the keys were linked to companies, with 526 of those being root keys. Truffle Security's testing was limited to read-only metadata, and it has notified affected customers.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjoshuasaxe181906.substack.com%2Fp%2Fwe-urgently-need-a-coherent-national%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/nHzhNenKn4zcWlNyWOafM5quCpsvoDKnLZM4OFAYq7Q=452">
<span>
<strong>We Urgently Need a Coherent National AI Cybersecurity Policy (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Current national AI cybersecurity policy focuses on measuring dual-use capabilities of models and biases towards AI's benefit to attackers. This framing ignores defensive security use cases such as AI code fixing and phishing defenses. The solution to this issue is to assemble an AI cybersecurity observatory that will perform evaluations combined with real-world use to make policy recommendations.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdecrypt.co%2F376287%2Fmicrosoft-perfect-10-exploit-hackers-run-code%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/ulWHVJnIXEfnwjOQ_Vuen5hoIFQgcGFvTmXMZQM_Ys8=452">
<span>
<strong>Microsoft Fixes 'Perfect 10' Exploit That Could Have Let Hackers Run Code Remotely (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Microsoft has fixed CVE-2026-69836, a critical deserialization vulnerability in Entra ID that enabled unauthenticated remote code execution without interaction, and confirmed there was no active exploitation before publicly disclosing the CVE for transparency.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.justice.gov%2Fopa%2Fpr%2Fjustice-department-secures-400m-settlement-tiktok-and-bytedance-resolve-childrens-privacy%3Futm_source=tldrinfosec/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/wirR-RtyNpCgsCYHO4cAVATHfXxSmcZfEWetST57OJc=452">
<span>
<strong>US Secures $400M TikTok Settlement Over Alleged Children's Privacy Violations (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
TikTok and ByteDance will pay $400 million to settle DOJ allegations that the platform allowed children under 13 to hold accounts and collected their data without parental consent.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/Nb33eh4dMtEGg87CuT1wVUXLIA8rmoztTcgyxVIiKF0=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/VcaQhhHL0KYJYF3OGY8ZtwT1brS5TysULHEgEwh2sVw=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/8W8TWC8obXQVbfrV_Jfvzpu5aCjpTRDJK52u-ODD-uE=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/Ih7pxkNSGue8El95wjMOfhIkAURb5Dg-q2mKb1Pl4K8=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/J38gQ7fSy9bUJWokX8_XF3kcYMpqvLYCekp5VHzIHAg=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/rE54sd-7TKxL0vNoyf9LjzqwSd0c3TcnAk-Opvufb8Y=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/DIUnyZ0pEx-HoV-NSVK3yhgIX12ZGk6unrR2OY_2_5s=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/rbJ8TZDRjv6Ppx-ejCFvwsQC-GFVNL1lMPo249ktMZk=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/6ktQx046yaaqFSdBjnwdYM3l_pN_5GczE3quC4MlV00=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/rp45BxEhMuHrQo1YOhcIEojHpMlJXlBE2WRgAqvirc0=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=3da714e6-9f92-11f1-a958-e33990d209d7%26pt=campaign%26pv=4%26spa=1787576437%26t=1787576907%26s=ab7840d6b4acbc451c67fba6761d0a75402b2d623f7610228066d1329014fee7/1/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/JBAuXsyi8wtG1vz1sY5sCpLTnQPWN8kn5LYz6cTc0qc=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a033e2f686-33c612ca-71cd-45ca-990e-6fe0a97af8dd-000000/k6S-2LgVPBKObbjHVJd1SVZpxvUtajBsYmOM_UEYpz4=452" style="display: none; width: 1px; height: 1px;">
</body></html>