<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">CVE-2026-18963 (CVSS 9.1) lets an unauthenticated attacker send a crafted request to Keycloak's reset-credentials endpoint </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/LOu5Zo7Yo6pXwOK4dGTCiGDRXjcdxpEvgSHuDOYNevM=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/TUx-Lo1Vrf9Re0hKmyOXyEnvbsl66etzQEvZ9LEHOAk=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=f8921cba-a136-11f1-9484-7dc5f5d462e4%26pt=campaign%26t=1787749751%26s=ad2d81374d3d4aabb8acf16a9787715591ae11eb514d9462acf44c74babf048b/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/jhWG3c0DC9IJO1KSlLUVR9c-tsbs53H-BpJJPFTnZGM=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-26</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fcritical-keycloak-password-reset-flaw.html%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/Z7Q2V-sIshwUKH9cp7ypocLADDBMYw-5Etg7gB4HIH0=452">
<span>
<strong>Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
CVE-2026-18963 (CVSS 9.1) lets an unauthenticated attacker send a crafted request to Keycloak's reset-credentials endpoint, bypassing the email verification via recovery token and allowing the attacker to update the account password, enabling full account takeover. Administrators should update Keycloak and disable "Forgot password" in every realm until servers are patched.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2FX0z3nd/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/4cb2vy6_hTlRbvHDsue9ZoMc9LunYvRHrhavptR7ODc=452">
<span>
<strong>ReliaQuest Confirms ShinyHunters Hack (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
ShinyHunters ran a phishing campaign using "company.claims" domains, then called ReliaQuest staff posing as security employees to push them to a fake SSO page. One employee entered a password and approved a push notification, giving attackers a brief session on the identity dashboard. ReliaQuest says access was view-only, all further access attempts were blocked, no other identities or business apps were reached, no customer data was taken, and no ransomware was involved.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgbhackers.com%2Ffake-codex-download%2F%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/molKDLFuvQOg2W0A1qPPVrE6rcdRCF-JK3O_nF4JZXU=452">
<span>
<strong>Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users (3 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Threat actors are leveraging sponsored Google Search ads to position fake OpenAI Codex download pages above legitimate results. The campaign utilizes a ClickFix-style social engineering trick to convince macOS users to paste a malicious Terminal command that decodes a Base64 URL, strips quarantine attributes using xattr -c, and drops a universal Mach-O payload linked to Atomic macOS Stealer (AMOS) infrastructure. Security teams should proactively block associated domains like brightlinks[.]com and configure SIEM alerts for any curl-to-zsh pipelines paired with xattr -c execution.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fipurple.team%2F2026%2F08%2F24%2Ftext-template%2F%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/oiXrbDjbdteHBp0Qyr7zSZlwJH1J6vx5Uoo17F3o53k=452">
<span>
<strong>Text Template (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
T4 template files (.tt) run C# or VB code at build time through TextTransform.exe, TextTransformCore.exe, t4.exe, and MSBuild.exe. Attackers can plant malicious .tt files on developer machines or in build pipelines to trigger code execution, including supply chain scenarios. This post provides working PoC templates that spawn calc.exe or a MessageBox, and shows how tampering a .csproj with TextTemplatingFileGenerator entries lets MSBuild.exe compile and run arbitrary .tt code via the /t:Transform flag. Detection relies on Sysmon: process creation for the four binaries, image loads of three Microsoft.TextTemplating DLLs (only with MSBuild), and file creation in %Temp% during MSBuild transforms, since t4.exe also spawns dotnet.exe and csc.dll to compile the payload.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcitizenlab.ca%2Fresearch%2Funcovering-global-telecom-exploitation-by-covert-surveillance-actors%2F%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/RlIIaAzc-GcbvJhiN3IPuH9Y5eOwlHbc5A_02EKxZR0=452">
<span>
<strong>Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors (19 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Citizen Lab found two surveillance vendors exploiting SS7 and Diameter signalling to track phones globally. One campaign hit a VVIP executive's phone across 11 operator identities in nine countries in four hours, switching protocols to dodge firewalls. A second used a malicious SMS with hidden SIM commands to turn a phone into a tracking beacon.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjeffreyappel.nl%2Fauditing-microsoft-defender-and-intune-configuration-changes%2F%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/HP4oYtCHonMK8aTtrMqIYrm87ZB5-bLCWh4sf7wWR_A=452">
<span>
<strong>Auditing Microsoft Defender and Intune Configuration Changes (11 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Microsoft's unified Defender SecOps portal contains a critical logging gap: changes to security-critical settings, such as Tamper Protection and Intune device policies, do not generate default alerts. To maintain a reliable audit trail of configuration changes, security teams must manually engineer custom detections. This requires enabling Unified Audit Log integration, forwarding Purview audit data into the CloudAppEvents table via Defender for Cloud Apps, and actively routing Intune operational logs to Log Analytics for KQL-based hunting.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2F1-3-7%2Fdisrobe%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/5T3L5a3k-abkFeT-bW5ita8dspyRspUB96P6t4K5jbM=452">
<span>
<strong>Disrobe (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Decompile, deobfuscate, and unpack almost anything. Disrobe is a universal, deterministic, single-binary reverse-engineering toolkit in Rust for Python, JVM/Android, .NET, WebAssembly, JS, Go, and native packers (UPX/PyArmor/PyInstaller/Nuitka) and 20+ more. It was built for malware analysis, CTFs, and security research.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fcloud.google.com%2Fblog%2Ftopics%2Fthreat-intelligence%2Fstaying-ahead-of-adversarial-ai-through-agentic-source-code-review%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/ig-gQIdu4SLgz1Cou8pbRLOOsr9Zlo2JEV5sKT0mYek=452">
<span>
<strong>Staying Ahead of Adversarial AI Through Agentic Source Code Review (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Mandiant's Agentic Vulnerability Discovery Harness (AVDH) is a Gemini-powered multi-agent pipeline built on Google's Agent Development Kit. The tool conducts deep source code reviews by autonomously chaining threat modeling, entry-point discovery, and hypothesis generation before escalating confirmed findings for human validation. Mandiant positions the harness as a point-in-time, deep-dive complement to continuous scanning tools like CodeMender, establishing a robust two-layered defensive strategy.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2FSpecterOps%2FBlacklight%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/HrEtDpA6idDNDIyrPuVzlTsOqLEDrvgxQ24I-q_vtX8=452">
<span>
<strong>Blacklight (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Blacklight is a cross-platform toolkit for mapping, analyzing, and understanding the local AI agent attack surface.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fdetect.fyi%2Fthreat-hunting-using-pair-probabilities-55194ddb8309%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/DrhyOVbXAyKi5iCd86n-iSqcRhTJ6LUtTwKwudiJnVQ=452">
<span>
<strong>Threat Hunting Using Pair Probabilities (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A KQL threat hunting technique built on Microsoft's pair_probabilities_fl() user-defined function calculates how statistically unusual a categorical pair (like a binary and its execution directory) is across a dataset, surfacing outliers such as cmd.exe launching from a user's Desktop instead of System32. The author extended the function to return top co-occurring values, per-device context, and occurrence counts alongside the core probability metrics (P_A|B, Lift, and Jaccard), making rare pairings easier to triage. The approach is explicitly framed as a statistical rarity detector rather than a maliciousness classifier, useful for narrowing investigation scope but unreliable on small datasets or environments where malicious activity has already been baked into the baseline.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fmysk.blog%2F2026%2F08%2F25%2Fresponsible-disclosure%2F%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/CLmccQHgOkuoTHLyY_zbcqaYyq4TxsFtE9OFr1LoFe0=452">
<span>
<strong>Thoughts on Responsible Disclosure (9 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Security researchers at Mysk publicly disclosed three WebKit vulnerabilities that leak users' DNS traffic and real IP addresses, successfully bypassing privacy protections in iCloud Private Relay and proxy-based browsers like Tor. Frustrated by Apple's historically slow patch cycles, the team bypassed standard coordinated disclosure, opting to publicly release the details after privately securing mitigations for Psylo and the Onion Browser. While Apple patched iCloud Private Relay within two weeks of the announcement, the underlying WebKit proxy flaws remain active, forcing affected users to rely on full-device VPNs for comprehensive protection.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fpulse%2Fedition-3-inside-ai-run-bug-bounty-report-anshuman-bhartiya-ch8rc%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/xfWmDp-3FU3yRxZqTNauqHG_RHu-ZCFNxptdQkCZqvM=452">
<span>
<strong>Inside an AI-Run Bug Bounty Report (5 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Anshuman Bhartiya details his setup and experience with a largely AI-driven bug bounty workflow. Bhartiya uses a custom-built harness that uses the pi coding-agent harness to monitor source code changes and route security-relevant diffs through 18 deterministic, vulnerability-specific detectors. The report was then generated and submitted by Claude, with the researcher only reviewing and guiding the agent.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftechcrunch.com%2F2026%2F08%2F25%2Fwhatsapp-tightens-account-security-with-stronger-two-step-verification-and-more%2F%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/1m9m6GkpQiAhWN3F0W0qw-g04CiNDT9326rnWZzJ3y4=452">
<span>
<strong>WhatsApp Tightens Account Security with Stronger Two-Step Verification and More (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
WhatsApp now supports longer two-step verification passwords with letters, numbers, and special characters.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fmarimo-notebook-flaw-could-run-mcp.html%3Futm_source=tldrinfosec/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/DqbeGG2oplc6lWYChk2RmNT5bRXN4myKFfOSD2zh3mU=452">
<span>
<strong>Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Marimo patched CVE-2026-75149 (CVSS 8.8), a code injection flaw in versions before 0.23.15 that let a crafted notebook launch an attacker-controlled MCP server command as a local subprocess the moment the notebook opened in edit mode, before any cell executed, so users should upgrade to 0.24.0.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/_HX8E7nZ5DjzC9yvceIHTEombZG0PrWnrgl9K5XU2dw=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/L_xFRBVDlNP4H3hI70Uw_lzlPekSbnDJA_wgxlU1P4w=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/6AA3aGkYl63OEAE0EGN6dk7psVZ3sTDo_Ran8jufvfw=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/m6AQPDo3ZTOj4C3ndrHTiU3TEGzWF9iRT8vq-Auz5_A=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/WZBmAsT-V77ILhqUqTp9RgcLfG72QKEbx_CLTzt7tsM=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/RIlNDD_PeNpcJ97DNyohI96lNmNBBQANfA7W0sdrn4E=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/m79kuZLV9brwt39bv7zl_1xA23K8wL0BVkZzd0NMG4s=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/pvPWu-kYu-j4o7Jcalu8rE_4sEqt100cBSDhHpT8PxE=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/LUIz8wank6w2fw3cGvrhHLn8yUFLVvw22r599t6Tyxk=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/QIjTizKxzB6f9DYtSC5cvSl0ab86LeNcpPa6IBdGkOk=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=f8921cba-a136-11f1-9484-7dc5f5d462e4%26pt=campaign%26pv=4%26spa=1787749345%26t=1787749751%26s=c3eb2285f23e4485210d452a9f2e9dd859ce59e6dd3f6233844e72fa5196d43b/1/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/Ub9JRyF3wPLCy1zErCyffKrohlvAba6M9kB2tBLjp28=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a03e305b90-2febbd34-c644-40c6-84bb-e1965385f73f-000000/c3_KYe0pjdragbRQtrRTHPQllBfdGBN5U-Ovo7Uen9Y=452" style="display: none; width: 1px; height: 1px;">
</body></html>