<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">A researcher performed a test where they instructed Sonnet 5, Composer 2.5, and GPT 5.5 to construct a webapp using the same prompt in both normal </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/BcFmgeX82ywHR2env8uz4Pc81ZhOjJ10vXtWU976UnI=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/uyfFsud55TSCVuFiVb_aR_HVgGXBk_6TVZgHS8UkBYQ=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=99b98e02-a065-11f1-ad07-a19140e44705%26pt=campaign%26t=1787663322%26s=de1f671272743ede5555293c918fc274b2204fa49b104d35392cafdea762a84c/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/6LGpy-BpLmDyDZbfmakHPc9DPJxDdV1-uT1f8N6MsIc=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-25</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.scworld.com%2Fbrief%2Falation-confirms-cyberattack-after-reporting-system-incident%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/_2A3U66I_KMqB4xoTXJrHK4x8O89JJxEw6vV3Xp-V8Q=452">
<span>
<strong>Alation Confirms Cyberattack After Reporting System Incident (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Enterprise data software provider Alation confirmed unauthorized activity in one system after users experienced degraded availability earlier this week. The service disruption was resolved within an hour. The company has not identified the attack method, root cause, affected customer count, data exposure, notification status, or recommended defensive actions.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.theregister.com%2Fcyber-crime%2F2026%2F08%2F19%2Faustralian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator%2F5289341%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/g-cgAyS5ipXtd9NlTXzTQU9wP_aSkn49NT3Vb4x6k58=452">
<span>
<strong>Australian Hotel Chain Leaks Guests' PII After Breach at Third-Party Database Operator (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Quest identified unauthorized database access on August 17 through a third-party provider. Records from before June 2025 exposed guest names and contact details. Some included dates of birth. The company says it notified affected guests, contained the incident, remediated systems, and began forensic work.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FC49Zyg/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/BlsT2weSfEthLP1vy8AwfCgC_-6e4XcU4Bg0rtoa6ik=452">
<span>
<strong>Hackers Target WordPress Sites in miniOrange Auth Bypass Attacks (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Attackers are actively chaining two critical vulnerabilities (CVE-2026-61979 and CVE-2026-15981) in the miniOrange SAML 2.0 SSO plugin to bypass authentication and gain administrator access to WordPress sites. Malicious actors can successfully forge legitimate SAML responses by manipulating cryptographic algorithms and bypassing OpenSSL signature checks. Administrators must manually verify their plugin version and immediately upgrade to the latest patched release, as the native WordPress dashboard will not surface update warnings for premium editions.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.endorlabs.com%2Flearn%2Fghsa-864f-rcv7-6rh4-critical-type-confusion-vulnerability-in-isolated-vm%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/UlAmngSrRsIW7-LP1gRt3QlGXOMSkzaMECflhhaTu8U=452">
<span>
<strong>GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm (8 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Endor Labs found a type confusion bug in isolated-vm's ExternalCopy transferList handling. A getter returns different values across two validation walks, letting attacker code pass a bad pointer through an unchecked cast. From one shared ivm.Reference, researchers reached the ExternalCopy constructor, crashed the host with SIGSEGV, then built a working exploit that recovers ASLR base, forges a vtable, and redirects an indirect call to invoke a chosen libc function. The vulnerability affects isolated-vm versions below 7.0.1 and 6.2.0, used by n8n, Activepieces, Mastra, Budibase, Directus, and Rocket.Chat. Upgrade immediately and audit which capabilities you pass into any sandboxed Reference.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fobjective-see.org%2Fblog%2Fblog_0x89.html%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/CjeXnb2yOYL01Qe3Fz3WkKkc4AcHbgLA2ObyJNgTtuo=452">
<span>
<strong>Detecting (Evil) Dylibs (12 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
This post details how attackers utilize macOS dynamic library (dylib) injection to inherit a host process's trust, entitlements, and TCC grants while blinding native security tools. By employing techniques such as DYLD_INSERT_LIBRARIES injection, @rpath hijacking, or trojanizing libraries, threat actors can bypass System Integrity Protection (SIP) and achieve deep persistence. To close this process-level blind spot, the post recommends that security tools statically parse Mach-O LC_LOAD_DYLIB commands for collisions, dynamically enumerate loaded libraries, and subscribe to Endpoint Security's ES_EVENT_TYPE_AUTH_MMAP to intercept malicious dylibs before they map into memory.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fsecuritylabs.datadoghq.com%2Farticles%2Fputting-models-to-the-secure-coding-test-plan-vs-default-mode%2F%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/phvSorJDMddHeAj09_Hz419YgJ4BaU5OTaglytVbH18=452">
<span>
<strong>Putting Models to the Secure Coding Test: Plan vs Default Mode (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A researcher performed a test where they instructed Sonnet 5, Composer 2.5, and GPT 5.5 to construct a webapp using the same prompt in both normal and plan modes to observe if plan mode had any noticeable impact on secure coding practices. All six implementations produced an identical IDOR vulnerability in addition to other vulnerabilities that varied across implementations. While Sonnet 5 produced a much more mature implementation in plan mode and Composer 2.5 produced the most glaring security vulnerability while using plan mode, the experiment proved inconclusive on whether plan mode produced more secure code.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftrufflesecurity.com%2Fblog%2Ftrufflehog-aws-analyze%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/4oK2wqGD3pYLkokfSJDBZzDC86zPlcPy5AypZ4AFNm0=452">
<span>
<strong>Introducing TruffleHog AWS Analyze: Know What a Leaked AWS Key Can Reach (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
TruffleHog AWS Analyze added an AWS-specific view to TruffleHog Enterprise that resolves the IAM principal behind a leaked access key and maps its policies, group memberships, and assumable-role paths up to two trust-policy hops away.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fopendefender%2FOpenRisk%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/j1uK6GgtNxM_SS0CNCzVretTUOJGum-yPkBClRaWYUU=452">
<span>
<strong>OpenRisk (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenRisk is a modern, enterprise-grade Risk Management Platform that transforms how organizations identify, assess, mitigate, and monitor risks
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Ftemporalio%2Fdeputy%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/CHeVLGsOl2GAbTZYG8tVKI_mubzfzH7yYkMuUa8hdkQ=452">
<span>
<strong>Deputy (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Deputy aims to enable dependency management at scale by providing core dependency management primitives along with a unified toolchain
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frisky.biz%2Frisky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras%2F%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/tb5hSwUriUQMFSy6c7jRrw_UQtUO0f8K764mmN2cOj0=452">
<span>
<strong>Risky Bulletin: Slovakia Finds Russian Backdoor in Traffic Speed Cameras (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Slovakia's national security service (NBU) discovered that recently installed traffic cameras contain a backdoor granting shell and network access via SMS commands from hardcoded Russian phone numbers. The compromised NERO R-ONE cameras, allegedly purchased through a Cyprus shell company, were identified as rebadged units manufactured by a St. Petersburg-based firm. In addition to the SMS backdoor, the NBU technical report revealed that the devices shipped with SecureBoot disabled and exposed live video streams without authentication.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2Futub4N/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/bqyUbKsq52cg6_4WC2z9liaP_BqQFnIXWFszRKFEAp4=452">
<span>
<strong>OWASP Flags Top AI Skill Risks in New Security Blueprint (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OWASP released its Agentic Skills Top 10 and Universal Agentic Skill Format v1.0. Malicious skills and supply-chain compromise rank first and second. A Paperclip impersonation campaign used Trojanized packages and skills. The skills exceeded 300,000 installs, and it shows that the skill format should record provenance, permissions, dependencies, hashes, and changes. Security teams should inventory agent skills and quickly disable flagged ones.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ffuturumgroup.com%2Finsights%2Fwhy-ai-learned-to-attack-before-it-learned-to-defend%2F%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/tS-JGyRIKZY1eWTq9gRHCu8dwusqwKT3mNB14qTKBtk=452">
<span>
<strong>Why AI Learned to Attack Before It Learned to Defend (11 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Offensive AI is outpacing defensive AI due to a structural asymmetry: offensive exploits provide a clear verification "oracle" (the exploit either lands or fails), allowing reinforcement learning loops to train attackers much faster than defenders. The industry is actively experiencing this imbalance: Anthropic's Project Glasswing recently surfaced over 10,000 high- or critical-severity flaws, far outpacing the two-week average patch time, while OpenAI's Daybreak Red achieved a roughly 95% success rate on advanced offensive security tasks. This rapid offensive acceleration, illustrated by the Hugging Face breach in July and the rise of highly capable open-weight models, highlights a growing threat landscape where AI substitutes human effort on offense but only assists on defense.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F08%2F21%2Fprivate-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants%2F%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/5M0FNaqfMDBSKH-h11I-deFaM9bhgMpWb8QZFyRZ-mI=452">
<span>
<strong>Private Equity Firm Apollo Confirms Data Breach Amid Hacking Wave Targeting Financial Giants (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Apollo disclosed that attackers accessed its cloud environment from July 6 to 10 through social engineering.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Featon-works.com%2F2026%2F08%2F24%2Ftata-nexarc-hack%3Futm_source=tldrinfosec/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/m8Yx2KcPIwh7V0l-MM1ttudGnTpmRmoJa329JkZnQUc=452">
<span>
<strong>Tata's B2B Platform Returned OTPs in API Responses (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Tata nexarc's login API returned the OTP directly in its response body, letting researcher Eaton take over any account, including Tata Steel's own, just by knowing the target's phone number, until CERT-IN confirmed a fix on July 31.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/pdDWLNaixYTt3F9Weel6-ANSIXI9Jv3khdiHJEvpDLw=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/HWtVxQ2NzNEAu09xhZCfe_4mToEDokxOr5RkUHDxJc4=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/c-0a6-nnidWyEGLVprmb0AKI87Cio9NUwgmVnKzcJpQ=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/dKcfxcfjgieS6LF5m5ORzOB3F8bYTLpLf87AEiXiKKg=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/hGHsyRPiTLvHkb90hsX9fBD27pb3plVzU0QJmTTjJ_I=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/pVj94EAm_MaiTEe3dQVKKdZLXKn-5FVLPxSTy7wX0-w=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/CQLyC-JSxkvVt10JOQWtpSZKca9U_C-3had9hve2pjI=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/ZWGAOGPw-b8kb2S7DSPX06tfGOe5lvj9-dFIN_KgY-M=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/v2urdGNpn_ZdwlCSId9k24WdGJw865MuXsdXWG38KW0=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/qcUy6zb27jDWZsYS1dtxc9aswF15ggzCXkml86ofwiM=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=99b98e02-a065-11f1-ad07-a19140e44705%26pt=campaign%26pv=4%26spa=1787662887%26t=1787663322%26s=36870076919a653fafad3e9e3989d6376adfb19391c3e91e8149112ba498a83c/1/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/WatAhs-tS5jSqWavTtImC__I4hKUExTCklMXI211X2U=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a039098f0e-9bae7592-ff1b-46d5-b899-5a46a02c1ab4-000000/-GFXk0Ysdd3FeTWuf9YpLvUG1lnXH1Q8bk6hP9Fwz0Q=452" style="display: none; width: 1px; height: 1px;">
</body></html>