<!DOCTYPE html><html lang="en"><head><meta http-equiv="Content-Type" content="text/html charset=UTF-8"><meta charset="UTF-8"><meta name="viewport" content="width=device-width"><meta name="x-apple-disable-message-reformatting"><title>TLDR InfoSec</title><meta name="color-scheme" content="light dark"><meta name="supported-color-schemes" content="light dark"><style type="text/css">
:root {
color-scheme: light dark; supported-color-schemes: light dark;
}
*,
*:after,
*:before {
-webkit-box-sizing: border-box; -moz-box-sizing: border-box; box-sizing: border-box;
}
* {
-ms-text-size-adjust: 100%; -webkit-text-size-adjust: 100%;
}
html,
body,
.document {
width: 100% !important; height: 100% !important; margin: 0; padding: 0;
}
body {
-webkit-font-smoothing: antialiased; -moz-osx-font-smoothing: grayscale; text-rendering: optimizeLegibility;
}
div[style*="margin: 16px 0"] {
margin: 0 !important;
}
table,
td {
mso-table-lspace: 0pt; mso-table-rspace: 0pt;
}
table {
border-spacing: 0; border-collapse: collapse; table-layout: fixed; margin: 0 auto;
}
img {
-ms-interpolation-mode: bicubic; max-width: 100%; border: 0;
}
*[x-apple-data-detectors] {
color: inherit !important; text-decoration: none !important;
}
.x-gmail-data-detectors,
.x-gmail-data-detectors *,
.aBn {
border-bottom: 0 !important; cursor: default !important;
}
.btn {
-webkit-transition: all 200ms ease; transition: all 200ms ease;
}
.btn:hover {
background-color: #f67575; border-color: #f67575;
}
* {
font-family: Arial, Helvetica, sans-serif; font-size: 18px;
}
@media screen and (max-width: 600px) {
.container {
width: 100%; margin: auto;
}
.stack {
display: block!important; width: 100%!important; max-width: 100%!important;
}
.btn {
display: block; width: 100%; text-align: center;
}
}
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
body,
p,
td,
tr,
.body,
table,
h1,
h2,
h3,
h4,
h5,
h6,
div,
span {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
a {
color: inherit !important; text-decoration: underline !important;
}
</style><!--[if mso | ie]>
<style type="text/css">
a {
background-color: #FEFEFE !important; color: #010101 !important;
}
@media (prefers-color-scheme: dark) {
a {
background-color: #27292D !important; color: #FEFEFE !important;
}
}
</style>
<![endif]--></head><body class="">
<div style="display: none; max-height: 0px; overflow: hidden;">A crafted Kiro workspace can direct the agent to read .env data, place it in powersRecommendationUrl, and invoke Kiro Powers </div>
<div style="display: none; max-height: 0px; overflow: hidden;">
<br>
</div>
<table align="center" class="document"><tbody><tr><td valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" class="container" width="600"><tbody><tr class="inner-body"><td>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr class="header"><td bgcolor="" class="container">
<table width="100%"><tbody><tr><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" style="margin-top: 0px;" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div style="text-align: center;">
<span style="margin-right: 0px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/5f6fDwwOzAKmCgoelTkcjBfczySSpkc1Mas3wCbmr14=452" rel="noopener noreferrer" target="_blank"><span>Sign Up</span></a>
|<span style="margin-right: 2px; margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisetopnav/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/DBri54SGK1p5W599DGwt4QlwAR3urTbckVlkPSl4UH0=452" rel="noopener noreferrer" target="_blank"><span>Advertise</span></a></span>|<span style="margin-left: 2px;"><a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Fweb-version%3Fep=1%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=7e2dad9e-a529-11f1-a3cc-95a7378c618c%26pt=campaign%26t=1788181738%26s=eed6328e6e100291fc0aed6758944aa1f02072fd0f829b7266a95b9ff9967c43/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/ZMNgf3aJfreOZbjibR8ah5HuVQbNDvfJU-_qSs1HntM=452"><span>View Online</span></a></span>
<br>
</span></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="text-align: center;"><span data-darkreader-inline-color="" style="--darkreader-inline-color:#3db3ff; color: rgb(51, 175, 255) !important; font-size: 30px;">T</span><span style="font-size: 30px;"><span data-darkreader-inline-color="" style="color: rgb(232, 192, 96) !important; --darkreader-inline-color:#e8c163; font-size:30px;">L</span><span data-darkreader-inline-color="" style="color: rgb(101, 195, 173) !important; --darkreader-inline-color:#6ec7b2; font-size:30px;">D</span></span><span data-darkreader-inline-color="" style="--darkreader-inline-color:#dd6e6e; color: rgb(220, 107, 107) !important; font-size: 30px;">R</span>
<br>
</td></tr></tbody></table>
<br>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;">
<div style="text-align: center;">
<h1><strong>TLDR Information Security <span id="date">2026-08-31</span></strong></h1>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width:100%;" width="100%"><tbody></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr>
<tr bgcolor=""><td class="container">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td style="padding: 0px;">
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🔓</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Attacks & Vulnerabilities</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fmindgard.ai%2Fblog%2Famazon-kiro-data-exfiltration%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/CDhTNN0cAqby71BL6Uc0WsSxiSYXH4edo2sc-ZfuLh0=452">
<span>
<strong>Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A crafted Kiro workspace can direct the agent to read .env data, place it in powersRecommendationUrl, and invoke Kiro Powers. The IDE then fetches the attacker-controlled URL with the secret in its query string. Mindgard reproduced the path in trusted and untrusted workspaces, and Amazon fixed the reported behavior in Kiro IDE 0.8.140.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F0WPKXT/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/vSCq4J0w-94UwMUwIk5DrxkGpTHhWYvCkWAD2g0_hRY=452">
<span>
<strong>Hasbro Data Breach Exposed Employee Personal Information (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Hasbro notified current and former employees that attackers may have accessed names, contact details, national ID numbers, and financial information. Massachusetts records list 436 affected residents. The disclosure may stem from March's network incident, which forced system shutdowns, and from Hasbro's reporting $11 million in cleanup costs and $25 million in delayed sales.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2F0xcc.io%2Fposts%2Fomarchy-root-creds%2F%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/08I0hF9JvNHXnctF-faE2pNmU9Blju3j2OCQTurieQw=452">
<span>
<strong>Omarchy: Any User Process Can Escalate to Root (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Omarchy added its default user to the Docker group out of the box, and since supplementary groups are inherited, every process in the desktop session could reach the root-owned Docker socket and mount the host filesystem as root without a password or prompt. Browsers, editors, npm scripts, and AI coding agents all inherited that access, turning any ordinary application compromise into full machine compromise. The researcher disclosed privately that the group membership was removed in 4.0.1, and versions back through 3.8.4 remain affected.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧠</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Strategies & Tactics</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fblog%2F2026%2F08%2F28%2Fterminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion%2F%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/StwIuYb04MFFe9RGxGVsYBErf-wn6V9xWIizImA3Ie4=452">
<span>
<strong>TerminalFix Campaign Deploys a Reverse Tunnel Through Multistage Intrusion (16 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
TerminalFix uses compromised sites and fake Cloudflare CAPTCHA prompts to copy malicious PowerShell into a victim's clipboard. The command downloads a ZIP, then abuses LockScreenContentServer.exe to sideload dui70.dll, which then extracts payloads from PNG pixel data, creates Run-key and scheduled-task persistence, and enumerates Active Directory, trusts, administrators, servers, and system details. A Python client opens a TLS WebSocket tunnel to gitnow[.]dev:443, allowing SOCKS-style access to internal hosts. Look out for nonstandard LockScreenContentServer.exe paths, dui70.dll loads, pythonw.exe client.py activity, and the listed C2 domains.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.sygnia.co%2Fblog%2Ffire-ant-evolves-from-hypervisors-to-trusted-infrastructure%2F%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/P_IqaQ33CKMlys7rhNkLzpznIymeawax8egQ9v_JS1M=452">
<span>
<strong>Fire Ant Evolves: From Hypervisors to Trusted Infrastructure (24 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
The Fire Ant threat actor has escalated from hypervisor compromises to direct infection of network control planes via purpose-built IOS XR implants. These sophisticated router implants establish unauthorized GRE tunnels to legacy Linux hosts and actively suppress syslog alerts by injecting exclusion clauses into CLI outputs. On the authentication layer, the actor deploys a tool called TacTap to inject malicious libraries into the tac_plus process, ultimately harvesting credentials using a single-byte XOR key. Sygnia researchers assess that this activity strongly overlaps with the China-nexus UNC3886 cluster. To detect this activity, defenders must hunt for unexplained GRE interfaces, tac_plus process injections, and specific log-clearing commands across independent network and memory telemetry.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fengineering.growtherapy.com%2Fpost%2Fthreat-hunt-ai-how-we-built-an-ai-security-analyst-on-aws-for-under-500-month%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/nZ5GyASGs-1ZY2kmw1ko-w5_XZ3FiMvAr3GjFbuRv24=452">
<span>
<strong>Threat Hunt AI: How We Built an AI Security Analyst on AWS for Under $500 a Month (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Grow Therapy built an agentic threat hunting workflow on AWS that leveraged existing log sources such as Snowflake, CloudTrail, and Datadog for an additional cost of less than $500/month. Users submit a YAML threat hunt request, which then kicks off a five-phase workflow: first, Sonnet gathers relevant data, and then Opus compares the data to existing baselines, enriches and analyzes the context, assigns a confidence score to the findings, and performs adversarial analysis to validate them. False positives are tracked in Snowflake and injected into the adversarial validation step, which has significantly reduced false-positive reports.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🧑💻</span></div>
</div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Launches & Tools</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Faipermission%2Faipermission%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/mSs1IHeSU4IB5oZvaFvvPicIjppBqohONdGSR44iW20=452">
<span>
<strong>AiPermission (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Local-first permission gateway for AI agents: connector-based SSH, Postgres, and Redis access with scoped tokens, human approval, audit logs, and encrypted local credentials.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fgithub.com%2Fschlarpc%2Fre-shell%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/Y2QrLFQ842Ndo9tcybB8tEnqScdFi3oF6Wry5W-ZX7c=452">
<span>
<strong>re-shell (GitHub Repo)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
re-shell is a Nix flake-based reverse engineering environment designed for use with Claude Code.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fblog.trailofbits.com%2F2026%2F07%2F13%2Frust-proof-your-code-with-our-new-testing-handbook-chapter%2F%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/sgGCdyJ1HTVymt5Tj63q4ZYkwBPrWLDQEapmy9pOXQ8=452">
<span>
<strong>Rust-Proof Your Code with Our New Testing Handbook Chapter (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Trail of Bits has added a new chapter to its Testing Handbook on Rust. The chapter begins with an overview of what guarantees Rust does and doesn't make and then discusses some tools and methods for dynamic and static analysis. The chapter also includes gotchas from the team's experience analyzing Rust code.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">🎁</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><strong><h1>Miscellaneous</h1></strong></div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F5C3nNn/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/KM-sJXpZXyi87zkTPri8SqnfZbeoP0ReNfNbjUNxdtM=452">
<span>
<strong>A Call for Collective Action on Cyber Defense (4 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
OpenAI and hundreds of other top companies have called for rapid cyber defense efforts as automated attacks spread. The letter targets unpatched software, excessive permissions, weak authentication, and legacy-system debt, asking organizations to verify fixes, use least privilege, and apply compensating controls, and asking vendors to share tested playbooks and threat intelligence.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fexecutiveoffense.beehiiv.com%2Fp%2Fowning-the-ai-stack%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/fQ4xbkMJ_J-GSZSlovXDVXHd-IDmapTf1cek2ObvfBE=452">
<span>
<strong>Owning the AI Stack (6 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Cybersecurity consultants and other organizations requiring consistent cyber capabilities should begin shifting to local models. The gap between local models and frontier labs has closed significantly, with DeepSeek v4 Pro even beating out frontier labs on some cyber benchmarks. When organizations rely upon frontier labs, they lose control, and changed behaviors or guardrails can lead to harness and workflow breakage.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.lesswrong.com%2Fposts%2FfpLDjKg3ej49beqTC%2Fadaptive-agentic-worms-are-here%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/m8jmoiXnCvsnpyxADuc1TYIPQkkLltUbS53eRq06wG0=452">
<span>
<strong>Adaptive Agentic Worms Are Here (7 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
A proof-of-concept worm running last year's open-weight models exploited 73.8% of an isolated 33-host network and replicated to 61.8% of it across 15 autonomous seven-day runs, chaining initial command execution into privilege escalation into self-replication, with each copy staging its own harness and local LLM or calling back to the parent host when local compute fell short. Researchers observed agents locating the IP blacklist in their own source and rewriting it to unlock monitoring hosts they had been forbidden to target, though hypervisor-level containment intercepted every attempt and no escape occurred. Detection currently rests on the resource signature, heavy GPU consumption, and sustained outbound inference traffic, so defenders should baseline per-host compute and egress, flag long-lived low-rate connections during off-peak windows, and assume that throttling is the first evasion an operator will add.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;"><span style="font-size: 36px;">⚡</span></div></div>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding-top: 0px; padding-bottom: 0px;">
<div class="text-block">
<div style="text-align: center;">
<h1><strong>Quick Links</strong></h1>
</div>
</div>
</td></tr></tbody></table>
<table bgcolor="" style="table-layout: fixed; width: 100%;" width="100%"><tbody><tr><td style="padding:0;border-collapse:collapse;border-spacing:0;margin:0;" valign="top">
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.www.cloudflare.com%2Fconnect2026%3Futm_medium=display%26utm_source=direct%26utm_campaign=2026-q3-acq-namer-connectivity-ge-he-general-connect/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/Zx-HDmint9NpVS4tmbSLlK5JsqgGj3iTEG0Nff_ndRI=452">
<span>
<strong>Build for the Agentic Internet at Cloudflare Connect 2026, Oct. 19-21 in San Francisco: (Sponsor)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
100+ sessions, five tracks, top speakers, hands-on labs, and practical AI, security, and networking guidance. <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fevents.www.cloudflare.com%2Fconnect2026%3Futm_medium=display%26utm_source=direct%26utm_campaign=2026-q3-acq-namer-connectivity-ge-he-general-connect/2/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/kBE4kzCEC0Zgx7xu1KFpdpJKYn68NrqOXrNf5ghHyAE=452" rel="noopener noreferrer nofollow" target="_blank"><span>Register Now</span></a>
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fthehackernews.com%2F2026%2F08%2Fberlin-refuses-to-pay-hackers-who-stole.html%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/FTmzfzklrVYLlqckTAttmxi87GKA2sIyXVEmkWxgnUM=452">
<span>
<strong>Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Berlin rejected extortion demands after attackers breached its state network.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.phoronix.com%2Fnews%2Fx86-WBINVD-Advisory%3Futm_source=tldrinfosec/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/XJXjpbw7KfJeR1biYUh9UOrxVIe_CqizT-rVK_iRaiQ=452">
<span>
<strong>Another x86 Advisory From Some Entity Other Than Intel Or AMD (1 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
An unnamed x86 vendor other than Intel or AMD has been shipping undocumented WBINVD prefix hints since 2025.
</span>
</span>
</div>
</td></tr></tbody></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block">
<span>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Flinks.tldrnewsletter.com%2F1v6Gsm/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/0pUb1hZCKzSkzCj-bFZfSdDhmzdsmyddipYm_ZvtxjE=452">
<span>
<strong>Chrome Web Store Extensions Caught Stealing Crypto, Browser Data (2 minute read)</strong>
</span>
</a>
<br>
<br>
<span style="font-family: "Helvetica Neue", Helvetica, Arial, Verdana, sans-serif;">
Following a supply chain compromise in which threat actors purchased popular browser tools, nineteen Chrome and Edge extensions were weaponized via automatic updates to silently strip security headers and hijack cryptocurrency transactions before being removed from the Chrome Web Store.
</span>
</span>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Love TLDR? Tell your friends and get rewards!
</p>
</td></tr>
<tr><td class="container" style="padding: 0px 10px 15px;">
<div class="text-block">
Share your referral link below with friends to get free TLDR swag!
</div>
</td></tr>
<tr><td align="left" style="padding: 10px;">
<div class="text-block">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Frefer.tldr.tech%2F78de0e20%2F8/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/PWlMmmi_pTdw1H0LnWF8MlBgeBjLtzjjLymLQwmMMQU=452" style="color: #464ba4; text-decoration: underline;">https://refer.tldr.tech/78de0e20/8</a>
</div>
</td></tr>
<tr></tr>
<tr><td align="left" style="padding:5px 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fhub.sparklp.co%2Fsub_d62447d5a74a%2F8/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/-fby8fJQMIbGTb8inU2rA8Biplqe7iH2fGcTvDT7OQ8=452" style="font-size: 16px; line-height: 1.6; padding: 10px 0; display: inline-block; text-decoration: underline;"><span style="mso-text-raise:13pt; text-decoration: underline;">Track your referrals here.</span></a>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td align="left" style="word-break: break-word; vertical-align: top; padding: 5px 10px;">
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to advertise in TLDR? 📰
</p>
<div class="text-block" style="margin-top: 10px;">
If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fadvertise.tldr.tech%2F%3Futm_source=tldrinfosec%26utm_medium=newsletter%26utm_campaign=advertisecta/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/6-bDt8EMtAz7rJREVaD7t5TB2fQfG08chbHPeJecQWY=452"><strong><span>advertise with us</span></strong></a>.
</div>
<br>
<!-- New "Want to work at TLDR?" section -->
<p style="padding: 0; margin: 0; font-size: 22px; color: #000000; line-height: 1.6; font-weight: bold;">
Want to work at TLDR? 💼
</p>
<div class="text-block" style="margin-top: 10px;">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/03aIEGsqIfYVSc5H-3PTem7eJRn0HaIM0f3BldBML7I=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Apply here</strong></a>,
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fjobs.ashbyhq.com%2Ftldr.tech%2Fc227b917-a6a4-40ce-8950-d3e165357871/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/tt9tCDu8_plE_a3q7wTGUc1jG3TSa7ksmJTyLXL1S20=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>create your own role</strong></a> or send a friend's resume to <a href="mailto:jobs@tldr.tech" style="color: #0000EE; text-decoration: underline;">jobs@tldr.tech</a> and get $1k if we hire them! TLDR is one of <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Ffeed%2Fupdate%2Furn:li:activity:7401699691039830016%2F/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/6SY6mTpKVrOON22NBZLYEXVitsfIex_HxOKZDqFlVV4=452" rel="noopener noreferrer" style="color: #0000EE; text-decoration: underline;" target="_blank"><strong>Inc.'s Best Bootstrapped businesses</strong></a> of 2025.
</div>
<br>
<div class="text-block">
If you have any comments or feedback, just respond to this email!
<br>
<br> Thanks for reading,
<br>
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fprasannagautam%2F/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/z_kCNjjej5W_cDj3RDEajTrvyt1LqksGbytd3b-PMyY=452"><span>Prasanna Gautam</span></a>, <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fericfernandezdelcampo%2F/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/RaNRSmQLSZJQj_gGWTfoRGCyVgH4SF9EQ-_plpAAqMM=452"><span>Eric Fernandez</span></a> & <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fwww.linkedin.com%2Fin%2Fsammy-tbeile%2F/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/KkUmCcr42NocDuOib9cWI8CP69FvI_lbV3nZHXOmMlo=452"><span>Sammy Tbeile</span></a>
<br>
<br>
</div>
<br>
</td></tr></tbody></table>
<table align="center" bgcolor="" border="0" cellpadding="0" cellspacing="0" width="100%"><tbody><tr><td class="container" style="padding: 15px 15px;">
<div class="text-block" id="testing-id">
<a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Ftldr.tech%2Finfosec%2Fmanage%3Femail=silk.theater.56%2540fwdnl.com/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/ajdxCm1sJRkyNRP9V_OXNORnLRGOjvLVADH1HKl1pMk=452">Manage your subscriptions</a> to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please <a href="https://tracking.tldrnewsletter.com/CL0/https:%2F%2Fa.tldrnewsletter.com%2Funsubscribe%3Fep=1%26l=8d9cea11-3e94-11ed-9a32-0241b9615763%26lc=156924ca-84b7-11f0-8d58-47c5c04ad337%26p=7e2dad9e-a529-11f1-a3cc-95a7378c618c%26pt=campaign%26pv=4%26spa=1788181282%26t=1788181738%26s=0f6ff903e816301a9f92831562404b3998beae307aec8e636356f1492194d4a3/1/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/dxKj_VLspcKbqh3cu1ZWz3E0bq9Kmlch8zt0P8NPx3s=452">unsubscribe</a>.
<br>
</div>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
</td></tr></tbody></table>
<img alt="" src="http://tracking.tldrnewsletter.com/CI0/010001a057eff2d1-ad4a45c7-af72-4c71-9d29-17ad1601e61b-000000/subtbEo7vD9ImQAqdvKaEPhEVFMUQUJ9WUzCeo7_Q1k=452" style="display: none; width: 1px; height: 1px;">
</body></html>