<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>tl;dr sec</title>
    <description>The best way to keep up with cybersecurity research. Join &gt;90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.</description>
    
    <link>https://tldrsec.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/xgTKUmMmUm.xml" rel="self"/>
    
    <lastBuildDate>Wed, 16 Sep 2026 04:05:14 +0000</lastBuildDate>
    <pubDate>Thu, 10 Sep 2026 14:30:00 +0000</pubDate>
    <atom:published>2026-09-10T14:30:00Z</atom:published>
    <atom:updated>2026-09-16T04:05:14Z</atom:updated>
    
      <category>Software Engineering</category>
      <category>Artificial Intelligence</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, tl;dr sec</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/080a561f-2435-4477-a549-ab9f115e047c/tldrsec_robot_nowords.png</url>
      <title>tl;dr sec</title>
      <link>https://tldrsec.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>[tl;dr sec] #345 - Bug Rumors → Exploits, Version Control DFIR, Agentic Worms</title>
  <description>A bug description is sufficient for AI to find it and write an exploit, cheat sheet on doing DFIR for GitHub, GitLab and more, and a paper on self-replicating, open weight agentic worms</description>
  <link>https://tldrsec.com/p/tldr-sec-345</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-345</guid>
  <pubDate>Thu, 10 Sep 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-09-10T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🥵 A two-ser</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Hello again friends!</p><p class="paragraph" style="text-align:left;">This is the first time I’ve done two issues in a week in the history of <i>tl;dr sec</i>, catching up after last week’s busyness.</p><p class="paragraph" style="text-align:left;">Next week we’ll be back to our normal weekly schedule, phew.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/245d1554-da30-455f-ad0e-500c97509256/image.png?t=1789025636"/><div class="image__source"><span class="image__source_text"><p>H/T <a class="link" href="https://www.reddit.com/r/wholesomememes/comments/1v48h2n/be_like_tortoise/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">r/wholesomememes</a></p></span></div></div><p class="paragraph" style="text-align:left;">Have a great rest of your week and weekend!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> Some pretty cool sponsors this issue 👀 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Nobody actually knows how AI gets used.</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Most companies can list the AI apps employees use, but few can say what employees are actually doing inside them. And labeling a task as ‘coding’ is a far cry from recognizing that an engineer working on cost optimizations is leaking source code to a model that trains on the data.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.harmonic.security/?utm_source=tldrsec&utm_medium=newsletter&utm_campaign=interactivedemo" target="_blank" rel="noopener noreferrer nofollow">Harmonic Security</a> classifies every AI interaction by task, tool, and team, across sanctioned and shadow apps, so you can see which use cases drive real productivity, which tools are shelfware, and where risk exists.</p><p class="paragraph" style="text-align:left;">Poke around their demo live environment for free below.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://explore.harmonic.security/?utm_source=tldrsec&utm_medium=newsletter&utm_campaign=interactivedemo" target="_blank" rel="noopener noreferrer nofollow"><b>Explore Your AI Usage</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Wow I really like this! Being able to view a live demo of the product with no sign up, run example workflows and see how it works, and more. Super cool! Well done.🤘 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.greptile.com/blog/model-inversion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Models are worse at reviewing their own code</a><br>Greptile&#39;s <a class="link" href="https://www.linkedin.com/in/rorroart/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Rodrigo Caridad</a> tested whether AI models are better at finding bugs in their own code or code written by another model, analyzing 500 PRs each from Claude Code and Codex against roughly 1,500 ground truth comments (sentiment analysis, upvote/downvote ratios, git archaeology), running Codex and Claude Code’s <code>/review</code> feature 3 times per PR. Both models caught more high-severity bugs in the other model&#39;s code- the types of bugs a model introduces most often are the same types it&#39;s more likely to miss during review. Claude-authored code skews toward &quot;wrong data or missing behavior&quot; bugs where GPT reviews better, while Codex-authored code skews toward semantic issues and error handling failures where Claude reviews better.</p><p class="paragraph" style="text-align:left;">Analysis of reasoning traces showed GPT 5.5 uses a depth-first verification approach that causes it to identify bugs but then drop them due to conflicting system instructions emphasizing narrow scope, while Claude Opus 4.7 takes a breadth-first preventive approach that generates more comments including conditional warnings and structural praise. Based on these findings, Greptile built Model Inversion, which detects PR authorship via commit trails, branch prefixes, and PR titles then routes reviews to the opposite model.</p><p class="paragraph" style="text-align:left;">💡 Really nice diagrams and visualizations, I like it! Also cool comparison idea.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://anil.recoil.org/notes/rumour-is-the-exploit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Just a rumour of a bug is enough to find a security exploit these days</a><br><a class="link" href="https://www.linkedin.com/in/anilmadhavapeddy/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Anil Madhavapeddy</a> shipped a path traversal fix for OCaml&#39;s cohttp 6.3.0 and, <b>within ten minutes of opening the PR, saw probes hitting his webserver with the exact bug pattern</b>. He&#39;d pointed his own Claude at the code first, but Fable refused over its security block, so DeepSeek V4 Pro wrote the exploit instead, in under a minute from only a vague description. Normally a bug like this goes under embargo, quiet until the fix ships, on the theory that secrecy buys you time. That no longer works, since a rumor alone hands an agent enough to find the exploit itself, and mean time to exploit has gone negative, so exploitation now precedes the patch.</p><p class="paragraph" style="text-align:left;">Anil lays out three responses and finds flaws in each. GitHub&#39;s temporary private forks let you hide the patch, but they cut you off from CI. Shipping fixes continuously is another route, the way Chrome pushes updates, but that leans on Chrome being a single binary, not a library buried in a hundred products nobody controls. And when cloud providers slam in mitigations at the protocol layer, open source has no CDN to carry the same rules. Every one of these leaves the small maintainer a step behind.</p><p class="paragraph" style="text-align:left;">💡 Within 10 minutes is insane. This is a super tough problem that I’ve been thinking about: given the increased rate in vulnerability discovery, the difficulty (and human involvement) in patching, the slowness in patch adoption, and the ease and speed of turning patch or hint → exploit = tough times right now. Prediction: this is and will continue to be an important area of security, and may hit hard over the next few months 😅 </p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Omdia: Browser-Based Attacks Are Outpacing Traditional Security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Browser-based attacks are surging, and most security stacks weren&#39;t built to catch them. Omdia surveyed 400 IT and security professionals:</p><ul><li><p class="paragraph" style="text-align:left;">6 in 10 rank generative AI security as their most important use case for a secure browsing solution</p></li><li><p class="paragraph" style="text-align:left;">7 in 10 say browser-based incidents have risen over the past two years</p></li><li><p class="paragraph" style="text-align:left;">8 in 10 who rely on traditional tools for browser security report at least one major challenge</p></li></ul><p class="paragraph" style="text-align:left;">See what&#39;s driving the shift to enterprise browsers, where teams are struggling, and what success actually looks like.</p><h2 class="heading" style="text-align:center;">👉 <b><a class="link" href="https://www.island.io/reports/omdia-browser-management-security?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_tldrsec_omdia_report&utm_content=omdia_report" target="_blank" rel="noopener noreferrer nofollow">Get the report</a></b> 👈</h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I found it interesting to learn about various browser-based attacks, and some of the security wins you can get when you have influence over security controls in the browser.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/vcs-dfir-threat-hunting-github-gitlab-azure-devops?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps</a><br>Wiz&#39;s <a class="link" href="https://www.linkedin.com/in/sean-johnstone-7a97044a/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Sean Johnstone</a> and <a class="link" href="https://www.linkedin.com/in/shira-ayal/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Shira Ayal</a> released a Version Control DFIR poster covering GitHub, GitLab, Bitbucket, and Azure DevOps, with available log sources, what to configure before an incident, and audit events mapped to MITRE ATT&CK tactics for threat hunting. The poster calls out visibility gaps across all four platforms, GitHub only retains Git events for 7 days, GitLab doesn&#39;t log Git operations to the database by default, only GitHub offers API request logs (requiring explicit configuration), and none of this telemetry is retroactive so log streaming has to be in place before something happens. </p><p class="paragraph" style="text-align:left;">The readiness checklist also flags that GitHub doesn&#39;t include source IPs in audit logs unless you turn it on, and that default retention windows across all four platforms are too short for most investigations. Where logs do exist, a forensic matrix maps attacker behaviors to the audit event names each platform uses, so a mass clone shows up as <code>git.clone</code> in GitHub, <code>repository_git_operation</code> in GitLab, and <code>RepositoryCloneEvent</code> in Bitbucket.</p><p class="paragraph" style="text-align:left;">💡 I’m going to put this poster up in bedroom, right next to my Twilight poster <a class="link" href="https://www.amazon.ca/American-Classics-Twilight-Vampire-Romance/dp/B0BVGQ3927?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">#TeamJacob</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://pipelab.org/blog/benign-set-should-look-malicious?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Benign Set Should Look Malicious</a><br>PipeLab&#39;s <a class="link" href="https://www.linkedin.com/in/joshua-waldrep-443753183/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Joshua Waldrep</a> writes that a detection tool&#39;s false-positive rate means nothing if the benign traffic in the test set never actually looks like an attack. Real false positives (especially common when analyzing Agent egress) come from harmless traffic wearing an attacker&#39;s clothes, an agent reading a security advisory that quotes an injection string, a tutorial with AWS&#39;s own example key AKIAIOSFODNN7EXAMPLE, a scanner tool description that lists every attack it detects, a base64 blob that decodes to a PNG rather than a secret. The trap of testing only against clean traffic is that a detector can score 0% false positives there while blowing up to 30% the moment benign inputs start looking dangerous. Joshua shares a public starter set of these lookalikes in <a class="link" href="https://github.com/luckyPipewrench/agent-egress-bench?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">agent-egress-bench</a>.</p><p class="paragraph" style="text-align:left;">Joshua recommends pulling hard negatives from your own docs, logs, and tool schemas, holding a portion out during tuning, splitting the false-positive rate into easy and hard categories rather than blending them, and publishing failures alongside scores, since reporting only wins is marketing more than measurement. </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://brutecat.com/articles/hacking-google-with-ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Hacking Google with A.I. for $500,000</a> - What happens when you unleash an AI across all of Google&#39;s infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties, by <a class="link" href="https://www.linkedin.com/in/brutecat/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Arvin Shivram</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/lp/claude-code-security-best-practices-cheat-sheet?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY27Q3_INB_FORM_Claude-Code-Security-Best-Practices&sfcid=701Vh00000gJQZuIAO&utm_term=FY27Q3-tldrsec-sponsor-link-Sept&utm_content=Claude-Code-Best-Practices" target="_blank" rel="noopener noreferrer nofollow"><b>Cheat Sheet: Claude Code Security Best Practices </b></a><b>- </b><span style="color:#000000;">Claude Code and other AI coding assistants are changing how fast code ships — but they&#39;re also changing what security teams need to watch for. This practical cheat sheet breaks down the real risk surfaces AI-assisted development introduces, and gives cloud security, AppSec, and platform engineers tactical steps to close the gaps.*</span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://danielmiessler.com/blog/prompt-injection-worm?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">I&#39;m Worried About a Prompt Injection Worm</a> - <a class="link" href="https://linkedin.com/in/danielmiessler?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Daniel Miessler</a></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Booz Allen Cyber Weapon Index</a><br>Booz Allen ran 18 US and Chinese LLMs as autonomous attackers against a production-grade enterprise network. Anthropic&#39;s Claude Mythos and OpenAI’s GPT-6 Astra both completed the full kill chain, Mythos leading in execution, Astra leading in vulnerability discovery. During the test, models issued commands independently, with every action validated through network telemetry, host logs, domain controller data, and intrusion-detection sensors, ensuring scores reflect demonstrated behavior, not theoretical skill.</p><p class="paragraph" style="text-align:left;">“Our assessment remains that most models will arrive at this capability within the next six months.”</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://derekjames.substack.com/p/adaptive-agentic-worms?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Adaptive Agentic Worms</a><br>Derek James walks through a recent arXiv paper (<a class="link" href="https://arxiv.org/abs/2606.03811v1?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">AI Agents Enable Adaptive Computer Worms</a>) on self-replicating AI worms that run open-weight LLMs (last year&#39;s models, not frontier) on stolen compute from every machine they land on, spreading across networks with no commercial AI platform involved. On a 33-host testbed of Linux, Windows, and IoT devices, the worms found vulnerabilities, escalated privileges, and copied both their harness and local LLM to new targets, reaching 61.8% network infection over 7 days.</p><p class="paragraph" style="text-align:left;">Attackers pay nothing per infection since the worms run on stolen compute, not through a commercial platform, putting them out of reach of centralized controls like safety refusals or rate limiting. The worms also tried to rewrite their own blacklist configuration to remove monitoring hosts from the protected list, and did all of this with self-replication as their only goal, no instructions to steal data or dodge detection, and no ability to change themselves when copying.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.endorlabs.com/learn/hacking-your-life-with-ai-can-get-you-hacked?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Hacking your life with AI can get you hacked</a><br>Endor Labs&#39; <a class="link" href="https://www.linkedin.com/in/peytonkennedysecurity/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Peyton Kennedy</a> discovered 14 critical and high-severity vulnerabilities across seven AI orchestration platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow) that all share one root cause, they treat multi-tenant code-execution environments as single-user developer tools. The most severe chains need no login at all, with Flowise, Kestra, and Langflow exploitable via prompt injection that runs code and exfiltrates data, while other findings cover broken sandboxes (NocoBase&#39;s <code>lockdown()</code> commented out with a TODO), LLM output trusted as code (Langflow accepting lambda from chat), and sandboxes armed too late to catch anything. </p><p class="paragraph" style="text-align:left;">Several vendors closed reports as working-as-designed, but Peyton argues that defenses that should protect users are missing or off by default, and Flowise itself has been archived since mid-August 2026, leaving any running instance as unmaintained software with credentials attached.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Lewis Capaldi - <a class="link" href="https://www.youtube.com/watch?v=zABLecsR5UE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Someone You Loved</a> music video</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/228e506SJV0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">In a world full of Carols and Demons, be a Susan</a> 🥹</p></li><li><p class="paragraph" style="text-align:left;">Behind the scenes on how they did the <a class="link" href="https://www.youtube.com/shorts/xnTEYnJ-NJ8?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">fast wardrobe change</a> in Frozen the Musical</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://readingmaps.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Reading Maps</a> - Journeys from fiction drawn on the real world. Moby Dick, Treasure Island, The Odyssey, Dracula, etc.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://PersonalWebsites.org?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">PersonalWebsites.org</a> - Over 4,000 personal websites from around the world</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=BitUJYjNXtI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Bill Hader and Kristen Wiig Look Back on The Skeleton Twins at Vulture Festival 2024</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/hilbertspaess/status/2097476196791709843?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Jacob Coxon</a> on the labs’ approach to safety</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.whatwetellai.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">What We Tell AI</a> - People writing candid notes about how they use AI. Some of them are :/</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/navier-stokes-solution/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">On the Navier–Stokes Millennium Prize Problem</a> - An unreleased OpenAI model allegedly solved a Millennium Prize problem.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/sksq96/status/2097379550724309434?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Timeline on the equations</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cims.nyu.edu/~tristanb/statement.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Tristan Buckmaster statement</a> - There is currently some controversy that I haven’t had time to fully look into, about humans working on the problem at the same time. “ This is a a Deep Blue-Kasparov moment. The community needs to have serious and unhurried discussion about where to go from here.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/SebastienBubeck/status/2097379411691516310?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">Sebastien Bubeck response</a></p><p class="paragraph" style="text-align:left;"></p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-345-bug-rumors-exploits-version-control-dfir-agentic-worms" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=787c8b37-071a-4658-881c-cdf37341bcda&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #344 - VMs won&#39;t contain Cyber-capable Agents, AWS AI Security Analyst, Decompilers vs LLMs</title>
  <description>Model finds 0-days to escape a QEMU/KVM VM, how to build a $500/month threat hunting agent, a decompiler benchmark and an experimental, LLM-written decompiler</description>
  <link>https://tldrsec.com/p/tldr-sec-344</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-344</guid>
  <pubDate>Tue, 08 Sep 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-09-08T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👋 I’m back!</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Last week was the first time in 6 years, out of over 340 issues, I’ve delayed a <i>tl;dr sec</i> issue to the following week.</p><p class="paragraph" style="text-align:left;">That’s because it was a pretty crazy week between the <a class="link" href="https://openai.com/index/gpt-6-astra/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">GPT-6 Astra</a> launch, and a Cyber Summit event we held for a number of CISOs and other security leaders.</p><p class="paragraph" style="text-align:left;">It was a bit surreal to be invited to deliver a small section of the livestreamed keynote (<a class="link" href="https://openai.com/business/learn/intelligence-at-work-cyber/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">recording</a>), along with Greg Brockman and other colleagues (shout-out Eric, Vanessa, and Johannes). I managed to fit in a joke that made it through editorial review 🤘 </p><p class="paragraph" style="text-align:left;">I thought the process was interesting, so I wanted to share some behind-the-scenes:</p><p class="paragraph" style="text-align:left;">About a month ago, the marketing team organizers offered to schedule me a virtual consultation with a fashion consultant for my outfit. Of course, I accepted. During the call I held up various options from my closet, she provided feedback, and afterwards she emailed me some links to other items I could buy.</p><p class="paragraph" style="text-align:left;">Each speaker did a number of individual run-throughs in the preceding days, where a number of marketing, comms, and events people gave feedback, as well as an external speaking coach. Apparently I say “um” more than I’d expected, and I have a habit of using “so…” in transitions.</p><p class="paragraph" style="text-align:left;">We did some full run throughs the day before and the morning of the event. I also received a calendar invite for “hair and makeup” since the keynote was being livestreamed and recorded 😂 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/951c42f3-0a8f-4a86-8caf-96e5ca9025df/makeup.png?t=1788849709"/></div><p class="paragraph" style="text-align:left;">As we say in security, “Teams who get their makeup done together, stay together.”</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> If you appreciate <i>tl;dr sec</i>, please check out this issue’s sponsors 🙏 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> A $320/month subscription service is hijacking Microsoft 365 sessions — MFA included</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Building and maintaining a live adversary-in-the-middle relay takes specialist skill. Island Security Research discovered that NovaCookies rents one out. This hands buyers a maintained Microsoft 365 sign-in flow, rotating infrastructure, and an operator dashboard, turning real-time session theft into an off-the-shelf product. Delivery chains hide behind genuine Docusign envelopes and Microsoft/Google redirect endpoints to look legitimate. Island detailed the attack and published 755 domains as IOCs.</p><h2 class="heading" style="text-align:center;">🍪<b> </b><a class="link" href="https://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizations?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_tldrsec_novacookies&utm_content=blog" target="_blank" rel="noopener noreferrer nofollow"><b>See inside the phishing kit</b></a><b> </b>🍪</h2></div><p class="paragraph" style="text-align:left;">Neat, it’s always interesting to see a discussion of threat actor business models, and I appreciated the anti-analysis capability discussion. IOCs published on GitHub 👍️ </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.philvenables.com/post/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess</a><br><a class="link" href="https://linkedin.com/in/philvenables?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Phil Venables</a> compares cybersecurity to backgammon, a game of managing risk under uncertainty rather than chess with perfect information and fixed moves. Backgammon concepts map to security practices, blots are exposed vulnerabilities that should be secured into anchors (defense-in-depth like IAM and MFA), primes are layered controls (network segmentation, EDR, DLP) that create impassable barriers, and blitz attacks mirror automated ransomware campaigns that overwhelm defenses. </p><p class="paragraph" style="text-align:left;">The same logic extends to the doubling cube, the piece that lets a backgammon player raise the stakes mid-game, which Phil uses for the risk decisions executives face during incidents like whether to pay a ransomware demand or trigger disaster recovery. Phil recommends security be built to absorb hits and recover rather than to prevent every attack.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Pass the Passkey: A Novel Attack Surface in Passwordless Authentication</a><br>Palo Alto Networks&#39;s <a class="link" href="https://www.linkedin.com/in/arie-olshtein-95267590/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Arie Olshtein</a> describes three attacks on Google&#39;s synced passkey implementation that let an attacker take over accounts from a compromised endpoint without escalating privileges. <span style="background-color:#ffffff;">The attacks exploit gaps in device trust workflows, inconsistent UV flag validation by relying parties, and the exposure of master key material to client devices, demonstrating that hardware-backed protections and cloud isolation don&#39;t fully eliminate endpoint compromise risks.</span></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The Pass-ta-key attack extracts Chrome&#39;s TPM-wrapped identity key and signs cloud authenticator requests without user interaction. The Silver Pass-ta-key variant forces device re-registration by invalidating the existing UV key, then abuses the <code>uv_key_pending</code> state to register an attacker-controlled UV key without attestation, giving the attacker persistent access without ever touching the victim&#39;s device. The Golden Pass-ta-key attack extracts the security domain secret (SDS) from Chrome&#39;s process memory during cloud authenticator re-registration, so the attacker can decrypt every synced passkey and forge authentication responses, with no way to rotate or revoke the key. </p></div><p class="paragraph" style="text-align:left;">💡I’m glad folks are pressure testing current passkey implementations. I’m stoked for the day when almost all authentication is passkeys not passwords.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">VMs won&#39;t contain cyber-capable agents</a><br>Trail of Bits&#39;s <a class="link" href="https://www.linkedin.com/in/artem-d-80320418/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Artem Dinaburg</a> gave GPT 5.6-Cyber a challenge to escape a QEMU/KVM VM on Debian 12, and the agent broke out three times, first using the recently disclosed Januscape bug, then combining a libslirp CVE (some security updates hadn’t made it back into his distribution yet) with an unmarked bug fix, and finally chaining three 0-days plus one unpatched distribution kernel bug after the host was fully patched. </p><p class="paragraph" style="text-align:left;">Across all three runs the agent worked ~12 hours on its own, backtracking from failed paths like CUPS blocked by AppArmor and unreliable Spectre read oracles, with Artem’s main job being rebooting the host after hardlocks. Firecracker, a stripped-down VM built for security rather than features, was the only environment the agent failed to escape.</p><p class="paragraph" style="text-align:left;">“<span style="background-color:#ffffff;">If it wasn’t clear before, I will state it plainly: you can no longer assume a mere VM will contain a sufficiently advanced AI agent.”</span></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="background-color:#ffffff;">“A distribution with rapid updates is now a requirement. I love older, stable software, but the cycle of backporting patches is simply too long. An older distribution that isn’t getting immediate upstream updates should be assumed vulnerable. A competent agent will discover these bugs quickly and synthesize target-specific exploits.”</span></p></div><p class="paragraph" style="text-align:left;">💡 Honestly, the exploit chains and attack paths frontier models can find are pretty impressive, even when you’re expecting them to be good: finding and leveraging commits that contain security fixes (even when they’re not documented), looking for useful primitives across many available components, etc. And Astra is more than just incrementally better than 5.6 Sol 😅 </p><p class="paragraph" style="text-align:left;">I think Artem’s recommendations around a) building on very hardened, stripped down components (e.g. Firecracker) and b) prioritizing software with rapid updates (given the rate of vulns being found) are important.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> 87% of orgs are running a known exploitable vulnerability right now</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Datadog analyzed production telemetry from thousands of organizations rather than surveying them. 87% were running at least one known, exploitable vulnerability in a deployed service. But when runtime context is applied, whether the library is actually loaded, whether the service is publicly exposed, whether the code is reachable, only 18% of findings labeled critical remain critical.</p><p class="paragraph" style="text-align:left;">The State of DevSecOps 2026 report covers the methodology, the full dataset, and where the gap between scanner severity and real exploitability is widest.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.datadoghq.com/resources/state-of-devsecops-2026/?utm_source=tldrsec&utm_medium=newsletter&utm_campaign=dg-content-researchreport-https://www.datadoghq.com/resources/state-of-devsecops-2026/-security-multi-ww-en-701vy00000ivjacyac-" target="_blank" rel="noopener noreferrer nofollow"><b>Read the report</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Phew, 87% is a lot. Love to see how the runtime context can filter to just when a vulnerability dependency is actually loaded and the code is reachable, that’s quite useful for prioritization.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Password spraying campaign targets AWS root user accounts across 150+ organizations</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/martin-mccloskey-8005385b/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Martin McCloskey</a> writes about a password spraying campaign targeting AWS root user accounts across 150+ organizations between July 24 and August 23, 2026, identified by two specific user agents (Chrome 85 and Firefox 120) and traffic routed through residential proxies. No one got in, but even attempting a root login requires knowing the account&#39;s email address, which means attackers already had root emails for 150+ organizations, either from a pre-compiled list or by brute-forcing valid ones. </p><p class="paragraph" style="text-align:left;">Martin recommends using AWS Organizations service control policies to block direct root activity, enabling centralized root access for short-lived AssumeRoot sessions, and alerting on all root activity through CloudTrail.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://engineering.growtherapy.com/post/threat-hunt-ai-how-we-built-an-ai-security-analyst-on-aws-for-under-500-month?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Threat hunt AI: How we built an AI security analyst on AWS for under $500/month</a><br>Grow Therapy&#39;s <a class="link" href="https://www.linkedin.com/in/pablo-vidal-60064528/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Pablo Vidal</a> describes a $500/month AI threat hunting system that runs 20 daily hunts across 15 log sources (CloudTrail, Okta, GitHub, CrowdStrike, and others) using ECS Fargate, Lambda, and Claude. Each hunt runs through five phases, Sonnet handles data gathering with up to 100 tool calls, then Opus with extended thinking compares findings against 1-day and 7-day baselines, pulls in additional context, and scores confidence. After scoring, the model argues against its own findings using false positive history and actor history, and can only reject a finding with specific counter-evidence. </p><p class="paragraph" style="text-align:left;">This adversarial review step cut the findings from about 40% noise to mostly stuff worth reviewing. To keep noise down further, both SQL detections and AI hunts write to the same Snowflake ALERTS table via CDC (change data capture) streams, with SHA-256 fingerprints that suppress repeat alerts for the same finding within 48 hours. Great tip: use a cheaper model (Sonnet) for the data gathering, which doesn’t need Opus-level reasoning (cut costs by ~60%). </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Lessons learned:</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;"><b>Data pipeline &gt; AI</b> - Get your logs in a queryable store like Snowflake or BigQuery.</p></li><li><p class="paragraph" style="text-align:left;"><b>Existing observability spend is a cheat code</b> - Use the tools your engineers already use for debugging (e.g. Datadog already has searchable logs).</p></li><li><p class="paragraph" style="text-align:left;"><b>Build the feedback loop before deploying anything</b> - The system that lets analysts mark false positives, stores those resolutions, and feeds them back into future hunts.</p></li><li><p class="paragraph" style="text-align:left;"><b>Do signal-to-noise tuning in staging mode</b> - Every new hunt should run against production data but write to a staging table.</p></li><li><p class="paragraph" style="text-align:left;"><b>Start narrow on tools</b> - They started hunts with only Datadog and Snowflake tools. Other tools got added as specific hunts needed them. A large set of tools might bloat up the LLM’s context window and lower the signal to noise ratio.</p></li><li><p class="paragraph" style="text-align:left;"><b>Cost tracking</b> - Have every hunt logs its token counts and computed cost.</p></li></ul></div><p class="paragraph" style="text-align:left;">💡 Great practical, detailed blog post 👍️ </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://checkmarx.com/zero-post/mcp-configuration-poisoning-owning-your-machine-with-just-a-text-file?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">MCP Configuration Poisoning: Owning Your Machine With Just A Text File</a><br>Checkmarx&#39;s <a class="link" href="https://www.linkedin.com/in/bruno-r-dias/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Bruno Dias</a> demonstrates MCP Configuration Poisoning, where attackers embed malicious commands in <code>mcp.json</code> files that AI tools and agents automatically execute when processing repositories. Many tools including IDEs, security scanners, and CI/CD pipelines read and execute these files without prompting or sandboxing. As proof of concept, Dias exploits Snyk&#39;s Agent Scan (now fixed in v0.5.0) by creating a malicious mcp.json with a bash command that runs when the scanner processes the file. </p><p class="paragraph" style="text-align:left;">Even &quot;Human in the Loop&quot; prompts aren&#39;t fully protected, since attackers can bypass them using &quot;HITL Dialog Forging&quot; (also called &quot;Lies in the Loop&quot;). Bruno recommends sandboxing execution environments, detecting suspicious patterns like shell invocations or URL piping, and treating configuration files from untrusted repositories as potential threats.</p><p class="paragraph" style="text-align:left;">💡 Security vendor demonstrates attack technique by demoing it on another security vendor’s product 🍿🌶️ </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/sha-pinning-for-github-actions-org-wide?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">GitHub Actions SHA Pinning, Org-Wide</a><br>Semgrep&#39;s <a class="link" href="https://www.linkedin.com/in/leifdreizler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Leif Dreizler</a> writes about how he rolled out GitHub Actions SHA pinning across ~350 repositories after the <code>tj-actions/changed-files</code> incident, where attackers rewrote every tagged release to point to malicious commits. He used pinact for tag → SHA conversion, Renovate for branch references, and Semgrep Agentic Workflows to run detection and remediation in parallel. Even with those tools, pinned actions calling other unpinned actions kept breaking the rollout, and Reusable Workflows added the same problem since the actions they call still need pinning. </p><p class="paragraph" style="text-align:left;">Leif auto-enrolled new repos via a cron-based GitHub Action that checks for new repos every 15 minutes and enables the repo-level pinning requirement, pinned the ~80% of repos that had never run an action, and worked through representative repos first before flipping the org-wide switch.</p><p class="paragraph" style="text-align:left;">💡 Great write-up of rolling out and enforcing a new security control, and the edge cases and nuances in GitHub Actions pinning, a few of which to me are non-obvious (e.g. transitive pinning).</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/gendigitalinc/sage?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">gendigitalinc/sage</a><br>By <a class="link" href="https://www.linkedin.com/company/gendigitalinc/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Gen</a>: An open-source Agent Detection & Response (ADR) framework that intercepts and validates tool calls from AI coding agents like Claude Code, Cursor, OpenClaw, and OpenCode before execution. It performs URL reputation checks via cloud APIs, evaluates commands against YAML-based threat heuristics, validates npm/PyPI packages through supply-chain analysis (registry existence, file reputation, age), and scans installed plugins for threats at session start. </p><p class="paragraph" style="text-align:left;">The tool sends only URL and package hashes to Gen Digital reputation APIs while keeping file content, commands, and source code local, with an option to disable cloud services for fully offline operation. <br></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">A Cautionary Tale About Data Breach Claims, Verification and Carhartt</a><br><a class="link" href="https://linkedin.com/in/troyhunt?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Troy Hunt</a> used his OpenClaw tool to analyze the ShinyHunters Carhartt breach and found that nearly half of the 24.8M email addresses were synthetic TPC-DS benchmark data sitting in Carhartt&#39;s Databricks instance alongside real customer records. That test data had 97.6% of domains appearing only once, birth years uniform from 1924 to 1992, and domains pairing real names with gibberish strings. After stripping the test data and other duplicates, the actual victim count dropped to 12.9M, roughly half the number other analysts had already published without checking.</p><p class="paragraph" style="text-align:left;">💡 Neat example of using AI to sanity check and comb through large amounts of data.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://decbench.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">DecBench</a><br>An experimental benchmark by researchers from the Noelo Lab at the University of Georgia, led by <a class="link" href="https://www.linkedin.com/in/zion-basque/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Zion Basque</a>, for comparing decompilers and modern LLMs on the task of recovering exact source code. This benchmark uses new and previously known metrics (perfect match percentage) and datasets that represent the various directions of exactness for decompilers: control flow structure, types, and precise recompilability. This benchmark is also living: as new decompiler/LLMs are released, their scores will be added to the leaderboard.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://noelo.org/blog/kuna-release?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Kuna: Decompiler Development in the Age of Coding Agents</a><br><a class="link" href="https://www.linkedin.com/in/zion-basque/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Zion Basque</a> releases <a class="link" href="https://github.com/Noelo-Lab/kuna?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Kuna</a>, an experimental decompiler where an LLM wrote nearly every line of code, achieving 44.4% perfect control flow structuring on C functions compared to IDA Pro&#39;s 45.7%. The decompiler improves autonomously by studying examples where it underperforms against IDA Pro, Ghidra, and angr on fundamental metrics, successfully reimplementing more than 20 core angr features that took years of scientific research to develop. Kuna is a Rust port of Ghidra reworked to match angr&#39;s pipeline, demonstrating what high-level scientific feedback alone can achieve, though it still requires human-led research to guide refinement and, while structuring works well, types, optimizations, recompilability, and variable identification still need real work.</p><p class="paragraph" style="text-align:left;">💡 Super cool work! One thing that’s become fairly clear with LLMs is that if you have an “oracle” when you’re implementing or porting something, whether it’s an extensive test suite or existing implementation, LLMs are <i>very good </i>at rebuilding it from scratch. We saw this in Anthropic’s <a class="link" href="https://bun.com/blog/bun-in-rust?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">port of bun</a> from Zig to Rust, Cloudflare <a class="link" href="https://blog.cloudflare.com/vinext/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">reimplementing Next.js</a>, and more.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/alibaba/open-code-review?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">alibaba/open-code-review</a><br><a class="link" href="http://linkedin.com/company/alibaba-com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Alibaba</a>’s internal code review CLI, now open-sourced after two years of use across tens of thousands of developers, with a built-in <span style="background-color:#ffffff;">multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible. They claim </span>9x fewer tokens and higher precision than Claude Code on a 200-PR benchmark across 10 languages. The tool uses a hybrid architecture where deterministic steps handle file selection, bundling, and rule matching while an agent handles the dynamic decisions, and supports workspace diffs, branch ranges, full-file scans, and a delegation mode where your existing coding agent (Claude Code, Codex, or Cursor) runs the review using the tool&#39;s file selection and rules.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://clearbluejar.github.io/posts/does-abliteration-skew-your-bug-hunting?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Don&#39;t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models</a><br><a class="link" href="https://www.linkedin.com/in/john-mcintosh-613ba2350/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">John McIntosh</a> tested abliterated (uncensored) LLM builds against their base models for vulnerability research and found what they call &quot;verdict bias,&quot; with abliterated models confirming findings 3-4x more often whether the evidence supported it or not. Using nano-analyzer to scan FreeBSD kernel source for a known CVE, base Gemma models correctly identified the real bug while the most aggressive abliterated build graduated 96% of candidates to VALID (versus 65% for base), produced 138 false positives, and never found the actual vulnerability. Those false positives aren&#39;t from lack of understanding, the model identifies exactly why a finding is invalid in its chain of thought, then confirms it anyway, because abliteration&#39;s weight editing strips out not just refusals but the model&#39;s willingness to say &quot;no&quot; under uncertainty.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=OHu1FY1R-x0&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">It took me 37 years to realize what I&#39;ll tell you in 18 minutes.</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=Db0589twf_A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">&quot;How Do You Know How Wealthy Someone Really Is?&quot;</a></p></li><li><p class="paragraph" style="text-align:left;">Mark Manson - <a class="link" href="https://www.youtube.com/shorts/IWoVEi_VZEM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Why the Person You Feel for Will Change</a> - “Loving someone is not loving them when they stay the same, it is choosing them even as they become someone new.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/pratikdunya/status/2091782561366196663?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">5 essential rope knots everyone should learn</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/xktBt9bo4yw?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Are you an unc? (childhood nostalgia)</a></p></li><li><p class="paragraph" style="text-align:left;">Sesame Street - <a class="link" href="https://www.youtube.com/watch?v=lYIRO97dhII&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Kermit and Joey sing the alphabet</a>, but she keeps sneaking in “cookie monster.” </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/divya_venn/status/2090927387081069025/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">John Steinbeck’s diary entry</a> - “My work is no good, I am appalled at how bad it is. I am so lazy and the thing is so hard.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/B0TBQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Nathan Fielder&#39;s Elizabeth Holmes Doc Met With Shock and Awe at Secret Screening</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/_sxgraw1xEc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">POV: All the benches are taken</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/DennysDiner/status/2081069889931112816?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">Banger meme</a> from Denny’s about how they’re similar to NVIDIA</p></li><li><p class="paragraph" style="text-align:left;">Kyle Gordon - <a class="link" href="https://www.youtube.com/watch?v=PKVOeQICi1A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">We Will Never Die</a></p></li><li><p class="paragraph" style="text-align:left;">Weird Al - <a class="link" href="https://www.youtube.com/watch?v=J6ILiEuUvM0&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">The Brain Song</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-344-vms-won-t-contain-cyber-capable-agents-aws-ai-security-analyst-decompilers-vs-llms" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=8cccf253-0db7-462d-906e-8c31060b8475&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #343 - Hugging Face Technical Report, AWSHound, OWASP Agentic Skills Top 10</title>
  <description>Full 38 page report from OpenAI on the incident, map your AWS environment, top 10 agent skill no no&#39;s</description>
  <link>https://tldrsec.com/p/tldr-sec-343</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-343</guid>
  <pubDate>Thu, 27 Aug 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-08-27T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🚢 Staying Afloat</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Hope you’ve been doing well amidst the busy-ness these days.</p><p class="paragraph" style="text-align:left;">Alas, a personal life anecdote shall have to wait for next week, tonight a meme and bedtime for me.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/67f5fa45-f98a-406d-aef0-aeea829d8406/image.png?t=1787813601"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.reddit.com/r/wholesomememes/comments/1vf4m8o/when_omniman_decides_to_be_an_actual_good_dad?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">r/wholesomememes</a></p></span></div></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> OpenAI released the full <a class="link" href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Hugging Face incident technical report</a>. Some pretty fascinating details in the blog, and the 38 page report.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Threat Researchers Tricked Copilot Into Hacking Itself</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Varonis Threat Labs asked Microsoft Copilot to prove an exploit was impossible. It did the opposite, guiding researchers through the exact steps to pull it off, including a hidden parameter enabling one-click data theft from Gmail, Calendar, and Drive. That&#39;s CoSnitch (CVE-2026-24301), the third Copilot vulnerability Varonis found this year. See how &quot;meta-hacking&quot; tricked the AI assistant, and what it means for your enterprise’s AI use.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.ly/Q04vbW3_0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow"><b>Read the research</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Wow, delightful read. Basically they iteratively asked Copilot how to execute a prompt without user interaction. Each refusal came with a technical justification that mapped its architecture, including eventually disclosing an undocumented URL parameter which just worked 😂 Neat technique, I like it.</p><p class="paragraph" style="text-align:left;">Also: “<span style="color:#010203;font-family:&quot;Graphik LC Web&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif;font-size:16px;">Varonis disclosed CoSnitch to Microsoft in </span><span style="color:#010203;font-family:&quot;Graphik LC Web&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif;font-size:16px;"><b>December</b></span><span style="color:#010203;font-family:&quot;Graphik LC Web&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif;font-size:16px;"> 2025, and patches were shipped on </span><span style="color:#010203;font-family:&quot;Graphik LC Web&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif;font-size:16px;"><b>August</b></span><span style="color:#010203;font-family:&quot;Graphik LC Web&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif;font-size:16px;"> 18, 2026.” </span>😅 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://portswigger.net/research/whats-in-a-tag-name-javascript-apparently?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">What&#39;s in a tag name? JavaScript, apparently</a><br>PortSwigger&#39;s <a class="link" href="https://www.linkedin.com/in/gareth-heyes-25a62b2/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Gareth Heyes</a> found that HTML tag names can hold JavaScript code that browsers preserve in the <code>localName</code> DOM property (unlike <code>tagName</code> which uppercases everything), turning the tag name itself into a payload source that WAFs don&#39;t expect. Through fuzzing he found that tag names also accept forward slashes, whitespace, newlines, and line/paragraph separators, and that opening angle brackets can be part of a tag name, letting attackers inject fresh markup inside what looks like a single tag. The resulting vectors work across all browsers and use properties like <code>part</code>, <code>classList</code>, <code>getAttributeNode</code>, and <code>setHTMLUnsafe</code> (several found with help from Sol 5.6) to bypass attribute-value blocklists.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.teknogeek.io/posts/what-happened-to-hackerone?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">What Happened to HackerOne?</a><br><a class="link" href="https://www.linkedin.com/in/joel-margolis/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Joel Margolis</a>, a bug bounty researcher since 2017, writes about HackerOne&#39;s shifting story on training AI with researcher submissions, after their Continuous Testing product first advertised training on &quot;12+ years of real-world vulnerability data and your prior H1 Bounty findings,&quot; which the co-founders only walked back after researcher pushback. He ties this to HackerOne&#39;s broader corporate shift since 2020 and says companies would be better off building their own bug bounty platforms with modern LLMs than paying HackerOne&#39;s fees.</p><p class="paragraph" style="text-align:left;">💡 It seems like the bug bounty ecosystem is in a tough spot right now: top researchers are using AI and automation to profit more than ever before, but that makes it hard for new researchers to break in. Bug bounty platforms are overwhelmed by plausible sounding reports that are actually slop. Meanwhile submissions from good researchers get delayed responses. </p><p class="paragraph" style="text-align:left;">It makes clear and obvious business sense that bug bounty platforms will build agents to try to auto-triage submissions using the data they have (replacing costly triage humans), and ideally leverage their unique data to build AI pen testing agents (product has better margins and is more controllable than the independent contractor researchers they currently rely on). It would be illogical for them <i>not</i> to do this. And if they don’t, they might get knocked out by an XBOW or RunSybil.</p><p class="paragraph" style="text-align:left;">However, I do think Joel’s section on the HackerOne triage agent is misguided - that flow sounds like a straight up standard out-of-the-box LLM use case, no model training needed. And it’s targeting H1 triage work, not researchers.</p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Opal, scalable identity security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://opal.dev?utm_source=tldrsec&utm_medium=newsletter&utm_campaign=p-2023-08-17" target="_blank" rel="noopener noreferrer nofollow">Opal</a> is designed to give teams the building blocks for identity-first security: view authorization paths, manage risk, and seamlessly apply intelligent policies built to grow with your organization.</p><p class="paragraph" style="text-align:left;">They are built from the ground up to synthesize the data needed to construct and monitor all of your company’s access – from a single pane of glass.</p><p class="paragraph" style="text-align:left;">Opal is used by best-in-class security teams today, such as Blend, Databricks, Drata, Figma, Scale AI, and more. There is no one-size-fits-all when it comes to access, but they provide the foundation to scale least privilege the right way.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://opal.dev/demo?utm_source=tldrsec&utm_medium=newsletter&utm_campaign=p-2023-08-17" target="_blank" rel="noopener noreferrer nofollow"><b>Secure Identity with Opal</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I’ve heard good things about Opal. Used by Figma, Cloudflare, Elastic, and others, nice.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://trufflesecurity.com/blog/trufflehog-aws-analyze?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">Introducing TruffleHog AWS Analyze: Know What a Leaked AWS Key Can Reach</a></span><br><a class="link" href="https://www.linkedin.com/in/jim-freely/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Jim Freely</a> announces TruffleHog AWS Analyze, which enriches leaked AWS access key findings by automatically resolving the IAM principal identity, aggregating all attached managed and inline policies (including group memberships), and mapping potential role assumption paths up to two trust-policy hops deep. Research on 64,024 leaked AWS keys found 88% were still active with a median age of five years, 84% had full administrator access, and 1 in 6 was a root key.</p><p class="paragraph" style="text-align:left;">💡 Not an open source tool, but I think the results are interesting, and more broadly the work around automatically resolving the impact of a leaked AWS key is good #inspo.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/08/19/awshound-opensource-aws-opengraph-collector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">AWSHound: An OpenSource AWS OpenGraph Collector</a><br>SpecterOps&#39;s <a class="link" href="https://www.linkedin.com/in/julian-catrambone-b84a44ab/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Julian Catrambone</a> introduces <a class="link" href="https://github.com/AWSHound/AWSHound?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">AWSHound</a>, an open-source collector that transforms AWS accounts and Organizations into BloodHound Community Edition OpenGraph datasets through offline IAM policy evaluation, combining identity policies, permissions boundaries, SCPs, RCPs, and resource policies using service-specific composition rules (S3 uses OR within accounts but AND cross-account, STS always requires AND, KMS uses a three-layer evaluation).</p><p class="paragraph" style="text-align:left;">AWSHound runs in three phases, collect (read-only AWS API calls), process (evaluation producing 156 edge types with 36 traversable), and emit (OpenGraph JSON), across nine services including IAM, Organizations, S3, KMS, SSM, EC2, Lambda, CloudFormation, and EKS, with composite edges like <code>AWS_CanCreateAndAssumeAdminRole</code> that fold multiple permissions into single attack path steps. In testing, it processed over 500 accounts producing ~160,000 nodes and ~10.5 million edges in ~15 minutes.</p><p class="paragraph" style="text-align:left;">💡 <a class="link" href="https://www.youtube.com/shorts/6oQMqGzDxZQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Me reading</a> about AWS IAM complexity.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://censys.com/blog/state-of-the-internet-2026-preview?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">The State of the Internet Is Changing: AI Exposures Surge While Global ICS Trends Shift</a><br>Censys previews findings from the upcoming 2026 State of the Internet Report, noting internet-exposed AI/LLM tool instances rose over 60% in nine months, with the riskiest tools growing fastest. Langflow grew 169% and has accumulated 18 CVEs including unauthenticated RCE flaws, while LiteLLM grew 97% and has an actively exploited pre-auth SQL injection that exposes API keys for every upstream model provider through its unified proxy. Internet-exposed ICS hosts averaged 138,000 in early 2026, with North America still leading while Asia&#39;s share grew and Europe&#39;s fell. Roughly 70% of exposed ICS devices worldwide have sat on consumer and mobile networks for the past 2.5 years.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.varonis.com/blog/openclaw-phishing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">OpenClaw agent leaked mock AWS keys and CRM data in phishing tests</a><br>Varonis&#39; <a class="link" href="https://www.linkedin.com/in/itay-yashar-55586a163/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Itay Yashar</a> tests whether classic phishing techniques could compromise AI email agents by building an OpenClaw agent named Pinchy with access to a Gmail inbox with synthetic credentials and CRM data, then running it through four phishing simulations across Google Gemini 3.1 Pro and OpenAI Codex GPT-5.4. Pinchy failed both social engineering tests, forwarding AWS IAM keys, database passwords, and SSH credentials to an external Gmail when asked for staging access during a fake production emergency, and exfiltrating a CRM dump on a casual &quot;from home&quot; export request. </p><p class="paragraph" style="text-align:left;">It detected the two technical attacks but earned only partial credit, inspecting the redirect URI on a malicious OAuth consent flow and refusing real credentials on a fake gift card redemption page, though still interacting with the phishing infrastructure before flagging.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://github.com/schlarpc/re-shell?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">schlarpc/re-shell</a></span><br>By <a class="link" href="https://www.linkedin.com/in/schlarpc/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Chaz Schlarp</a>: A Nix-powered reverse engineering environment that integrates with Claude Code to automatically activate the right tools and workflows based on file type. The environment bundles a comprehensive RE toolchain including Ghidra, radare2, Frida, mitmproxy, and YARA, with discipline-specific skills that auto-activate for Windows binaries, Android packages, and web traffic captures.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://schlarp.com/posts/everything-i-own-owned/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Everything I own, owned</a><br><a class="link" href="https://www.linkedin.com/in/schlarpc/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Chaz Schlarp</a> used Claude Opus 5 to reverse engineer five personal peripherals in ~13 hours of agent work, finding that none of them had meaningful firmware protections. The Shure MV7 exposes a 48-command plaintext HID shell with arbitrary memory access, the Insta360 Link could be patched to disable its activity LED while still recording, and the Elgato Key Light Mini&#39;s Ed25519 firmware signature (the only real protection across all five devices) was bypassed with a single HTTP POST to UART memory since the check only runs during updates and the device gives unauthenticated access to anyone on the WiFi. </p><p class="paragraph" style="text-align:left;">Chaz warns that AI-equipped worms could now reverse engineer and compromise peripherals on their own, and publishes custom firmware tools and protocol documentation for all five devices on GitHub alongside <a class="link" href="https://github.com/schlarpc/re-shell?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">re-shell</a>, that powered the work.</p><p class="paragraph" style="text-align:left;">💡 On the one hand, it’s super cool how seemingly almost everything is becoming understandable/modifiable. It’s like the early days of computers. On the other hand, a worm or at perhaps nearly every one-off device being compromised seems to be quite feasible 😅 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cernica.ai/systemlayers/structural-desynchronization-gmail-gemini?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Structural desynchronization in Gmail and Gemini</a> - <a class="link" href="https://www.linkedin.com/in/cernica-ionut-ba844745/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Ionut Cernica</a> shows how a single email can exploit structural desynchronization in Gmail&#39;s Gemini integration to fake inbox entries and leak real email content into shared Calendar events.</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.crogl.com/download?utm_source=tldrsec&utm_medium=newsletter&utm_campaign=20260827" target="_blank" rel="noopener noreferrer nofollow">Crogl: the on-prem AI SOC agent the U.S. Air Force chose. Download it free.</a></b> - One analyst, a dozen consoles, a growing backlog. Crogl is the on-prem AI SOC agent that runs the investigation where your data lives and returns an auditable case you can defend. The AI SOC the U.S. Air Force chose. Download it free, run a case in five minutes.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.fernandoi.cl/posts/hackmyclaw?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">What happened after 2,000 people tried to hack my AI assistant</a> - <a class="link" href="https://linkedin.com/in/fernando-irarrazaval?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Fernando Irarrázaval</a> built <a class="link" href="https://hackmyclaw.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">hackmyclaw.com</a>, where 2,000+ people spent a week trying to make his OpenClaw email assistant Fiu leak the contents of a secrets.env file.</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://owasp.org/www-project-agentic-skills-top-10/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">OWASP Agentic Skills Top 10</a><br>The OWASP Agentic Skills Top 10 (AST10) documents the 10 most critical security risks in AI agent skills. Malicious Skills, Supply Chain Compromise, Over-Privileged Skills, Insecure Metadata, Untrusted External Instructions, Weak Isolation, Update Drift, Poor Scanning, No Governance, Cross-Platform Reuse. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/putting-models-to-the-secure-coding-test-plan-vs-default-mode?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Putting models to the secure coding test: Plan vs default mode</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/kennedy-toomey/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Kennedy Toomey</a> tested whether AI coding agents write more secure code in plan mode versus default mode, prompting Claude Sonnet 5, Cursor Composer 2.5, and Codex GPT 5.5 to build a document portal with authentication, file uploads, and user management. Each iteration ran through Datadog Code Security and Claude&#39;s <code>code_review</code> skill for analysis, while <a class="link" href="https://github.com/DataDog/supply-chain-firewall?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Supply Chain Firewall</a> intercepted the models&#39; repeated attempts to install vulnerable npm packages during setup. </p><p class="paragraph" style="text-align:left;">Across those six iterations, plan mode showed no meaningful security improvement, all contained critical IDOR vulnerabilities letting any authenticated user access others&#39; documents, and each model&#39;s plan mode had its own trade-offs, Composer 2.5 introduced a hardcoded JWT secret fallback enabling authentication forgery, Sonnet 5 added defense-in-depth but broke document downloads, and GPT 5.5 fixed some issues but introduced TOCTOU race conditions and timing side channels. The pattern shows that explicit security requirements in prompts matter far more than the agent&#39;s operational mode, since none of the models could infer authorization logic the prompt never specified.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cloudflare.com/mcp-security-updates?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">How Cloudflare detects MCP traffic and helps secure it</a><br>Cloudflare&#39;s <a class="link" href="https://www.linkedin.com/in/ztnaj/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">AJ Gerstenhaber</a> and <a class="link" href="https://www.linkedin.com/in/kenny-johnson-2a957a51/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Kenny Johnson</a> announce new Cloudflare One capabilities to detect and control MCP traffic, addressing the risk that AI agents can repeat a flawed decision thousands of times at machine speed before a human notices. To spot that traffic in the first place, Gateway now identifies MCP requests using protocol-level heuristics like the <code>MCP-Protocol-Version</code> header and the new <code>Mcp-Method/Mcp-Name</code> headers from the MCP 2026-07-28 spec, with an <code>experimental.is_mcp</code> selector, a dashboard showing hosts and users, and Traffic Source selectors that distinguish MCP Portal traffic from direct connections. </p><p class="paragraph" style="text-align:left;">Once traffic is identified, security teams have three control points, client-side hooks, Gateway network inspection with TLS decryption, and server-side authorization via WriteGuard middleware, while MCP Portals gain pre-registered OAuth client support and expanded reach to private servers through Cloudflare Gateway routing. </p><p class="paragraph" style="text-align:left;">💡 Some good pointers if you’re trying to identify MCP traffic.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/6iX5Woi0byE?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Every people pleaser has this energy within them</a> 🤔 </p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=AOLCxk7eU4U&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">My Least-Viewed Video Made the Most Money</a></p></li><li><p class="paragraph" style="text-align:left;">Naomi Brockwell - <a class="link" href="https://www.youtube.com/watch?v=-2uAsJ5EPAw&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">The coolest anti-surveillance tools at Defcon</a></p></li><li><p class="paragraph" style="text-align:left;">Healthy Gamer GG - <a class="link" href="https://www.youtube.com/shorts/Ty_6S-SElb8?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">This is the only cure to addiction</a></p></li><li><p class="paragraph" style="text-align:left;">Fireship - <a class="link" href="https://www.youtube.com/watch?v=iuZPTE5qsJY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">The summer Math fell to the machines</a></p></li><li><p class="paragraph" style="text-align:left;">Josh Radnor - <a class="link" href="https://www.youtube.com/shorts/4oN_ctpTMLQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">‘How I Met Your Mother’ cast only minimally staying in touch</a> - “People really wanna believe that me and Neil and Jason are hitting bars in NYC together. It’s a little more like family than friends in that you don’t get to choose your family. We were cast. Acting is like a lot of little love affairs that you have and then you move on.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/aI0IGUfpTiw?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Gerard Butler on his “This is Sparta” line</a></p></li><li><p class="paragraph" style="text-align:left;">America’s Got Talent - <a class="link" href="https://www.youtube.com/shorts/FscyNGkc0gM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">He dances in reverse</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=kotWv4MCxNI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Cyclists chased by an ostrich</a> - Wow, ostriches are fast</p></li><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/shorts/CU-6oGt9wZU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">How Americans see EU Tech</a></p></li><li><p class="paragraph" style="text-align:left;">Orson Welles dub - <a class="link" href="https://www.youtube.com/watch?v=Kl9GO1DUjls&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Interview with a Vibe Coder</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=9ai3HWFs3Dk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">MARSHMELLO BRINGS CALEB TO ULTRA: Sundae Field Report</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="http://&#39;WeirdAl&#39;Yankovic:TinyDeskConcert" target="_blank" rel="noopener noreferrer nofollow">&#39;Weird Al&#39; Yankovic: Tiny Desk Concert</a></p></li><li><p class="paragraph" style="text-align:left;">Kyle Gordon - <a class="link" href="https://www.youtube.com/watch?v=S-OgkNgxm3k&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Planet of the Bass</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/U3DsHDo8yvc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Jesus from the Jewish Perspective</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=7xOURK7-UMs&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">&#39;Darth Vader&#39; makes the case for Flock cameras at city council meeting</a> - Absolutely brilliant</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/zYpPTY0Bx1I?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">Male reporter struggling for air</a> 😂 </p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=96c91e06-ed73-431a-acd0-f1d49ccca7fb&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #342 - Figma&#39;s Agentic Detection, Agent Identity, Uber&#39;s Agent-(E)DR</title>
  <description>How Figma scales their detection and response, 1Password and Cloudflare on least privilege and identity for Agents, Uber&#39;s paper and OSS repo on monitoring and securing enterprise AI agents</description>
  <link>https://tldrsec.com/p/tldr-sec-342</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-342</guid>
  <pubDate>Thu, 20 Aug 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-08-20T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🎬 The Mandalorian</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I don’t have much time to watch TV or movies these days, but I watched The Mandalorian movie over the weekend and it was pretty good!</p><p class="paragraph" style="text-align:left;">To parallelize, I also lifted weights while watching, moving my adjustable dumbbells and bench next to the TV 😂 </p><p class="paragraph" style="text-align:left;">The movie of course has action scenes and intergalactic space drama, but what stuck out to me was (slight spoilers): Jabba the Hutt’s son trying to break out of his father’s shadow, seeking for crowds to love instead of fear him, and the Mandalorian taking care of Grogu, and vice versa (“the old take care of the young, and then the young take care of the old”).</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6f58cd66-e69b-42fc-bac2-2955090fc23d/image.png?t=1787213572"/></div><p class="paragraph" style="text-align:left;">Probably not something I’d have thought about when I was younger 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> New webinar: The real picture behind shadow AI and what it means for security teams</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Shadow AI isn’t just about data loss: it’s a new attack surface that most security teams and tools have pretty much zero visibility of. </p><p class="paragraph" style="text-align:left;">A shadow app integration today is a supply chain attack vector tomorrow. That AI helper browser extension can suddenly become malicious. And the next time your employee searches for an AI tool on Google it could serve them malware instead. </p><p class="paragraph" style="text-align:left;">Join the latest threat briefing from Push Field CTO Mark Orlando for the lowdown on shadow AI and what security teams can do about it. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.li/Q04pr_Ny0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow"><b>Register Now</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">I’d be willing to bet most companies have nontrivial shadow AI they don’t know about 😅 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.gregbrockman.com/the-defenders-window?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">The Defender’s Window</a><br><a class="link" href="https://x.com/gdb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Greg Brockman</a> describes how OpenAI is using AI agents to defend its infrastructure, and urges organizations to act immediately before open-weight models with similar capabilities release. OpenAI&#39;s defense strategy includes using Codex with a <a class="link" href="https://learn.chatgpt.com/docs/security/plugin?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">security plugin</a> for code validation, deploying AI for continuous alert triage and automated response, using frontier models to enumerate attack paths and test security invariants, and maintaining defense-in-depth fundamentals. Greg recommends a 10-step playbook for defenders.</p><p class="paragraph" style="text-align:left;">💡 From my vantage point, I would encourage security teams to move with urgency 😅 I know a few companies trying to do like 2-3 years of security hardening in the next… <i>month</i>. I don’t think they’re wrong. As Samuel L. Jackson once wisely <a class="link" href="https://www.youtube.com/watch?v=HKK4KmDlj8U&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">said</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.philvenables.com/post/a-coming-incident-crisis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">A Coming Incident Crisis?</a><br><a class="link" href="https://linkedin.com/in/philvenables?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Phil Venables</a> writes about a &quot;perfect storm&quot; of rising incident volume from three sources, attackers using AI to run more attacks in parallel (a ransomware gang going from 10 to 100 attacks a week), AI-driven fakery forcing companies to handle brand and authenticity crises, and misbehaving LLM chatbots landing on security teams&#39; plates. On top of that, regulators worldwide are lowering the bar for what has to be reported and speeding up the deadlines, so more incidents pull in legal, compliance, and privacy work even when they&#39;re not significant on their own. Phil wants organizations to move from artisanal handling of a few incidents per quarter to industrial response for dozens per month, deploying Cyber Incident Response Management (CIRM) tools with AI to coordinate across security, legal, privacy, and executive teams.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://joshuasaxe181906.substack.com/p/the-openaihuggingface-incident-how?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">The OpenAI/Huggingface incident; how we should manage the imminent arrival of autonomous hacking too cheap to meter</a><br><a class="link" href="https://linkedin.com/in/joshsaxe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Joshua Saxe</a> believes that the Hugging Face incident signals the beginning of AI-enabled cyberattacks that will escalate exponentially through 2027 and beyond. He disagrees with policymakers who want to restrict AI capabilities and suppress open weights models, arguing instead that defenders need broad access to AI cyber capabilities to operate inside attackers&#39; OODA loops, especially since attackers already have access to frontier open weights AI and will use dark inference providers. </p><p class="paragraph" style="text-align:left;">Joshua recommends a &quot;light touch around restriction and a heavy hand around adoption&quot; strategy: requiring critical institutions like healthcare providers and defense companies to adopt AI cyber defense on mandated timelines, while labs and inference providers focus on API security and customer vetting rather than capability restrictions. </p><p class="paragraph" style="text-align:left;">“In 2027 and beyond, we’ll see substantial damages that start to show up as more and more attacker constituencies adopt frontier AI and defenders, en masse, get jolted out of complacency.”</p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Threat Intelligence That Analyzes Every Binary</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Is your scanner missing threats? Chainguard built one that doesn&#39;t: a scanner for the reality of the world we currently code in, where threats are sometimes blatant and sometimes disguised. It evaluates maintainer behavior, package contents, and publishing signals, then runs install scripts in a sandboxed, network-blocked environment to catch callouts to external servers, unauthorized file access, or hidden payloads, all before code ever reaches your build.</p><p class="paragraph" style="text-align:left;">Chainguard is scanning 200,000+ packages a day and has already blocked 400,000+ packages detected as malware and greyware.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.chainguard.dev/unchained/the-expanding-threat-landscape-chainguard-now-scans-source-code-for-traditional-malware-and-greyware?utm_source=clint-gibler&utm_medium=3p-sponsorship" target="_blank" rel="noopener noreferrer nofollow"><b>See How the Scanner Works</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Nice, running dependencies in a sandbox to observe potentially malicious behavior 🤘 I like how Chainguard aims to reduce supply chain security risk systematically.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">CosmosEscape: Taking Over Every Database in Azure Cosmos DB</a><br>Wiz&#39;s <a class="link" href="https://www.linkedin.com/in/yuval-avrahami-25139416b?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Yuval Avrahami</a> and <a class="link" href="https://www.linkedin.com/in/liorma/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Lior Maman</a> show how a single Gremlin query could have compromised every database in Azure Cosmos DB, including those behind Microsoft&#39;s internal services like Entra ID, Teams, and Copilot. The chain starts with a Gremlin sandbox bypass using .NET reflection to achieve arbitrary code execution on the multi-tenant DB Gateway, which exposes the &quot;Cosmos Master Key,&quot; a platform-wide signing credential that can fetch the primary key of any Cosmos DB account across all tenants, regions, and API flavors. </p><p class="paragraph" style="text-align:left;">That same key also unlocks the Config Store, a Cosmos DB database registry that lets attackers enumerate accounts and filter by target organization before compromising them. Microsoft deployed a hotfix within 48 hours of Wiz&#39;s disclosure and completed a full architectural migration that eliminated the Cosmos Master Key entirely.</p><p class="paragraph" style="text-align:left;">💡 It feels like it’s been a bit since Wiz published some big tenancy-breaking cloud vulnerabilities. Maybe we’ll see more now that they’re at Google? 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://holdmybeersecurity.com/2026/07/14/hunting-malware-and-malicious-mcps-in-memory-on-kubernetes-with-fleetdm-osquery-yara?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Hunting malware and malicious MCPs in memory on Kubernetes with FleetDM + Osquery + YARA</a><br><a class="link" href="https://www.linkedin.com/in/ben-bornholm-471b1385/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Ben Bornholm</a> walks through using osquery&#39;s new <code>yara_process</code> table and Fleet&#39;s authenticated YARA rule distribution to hunt in-memory malware across two homelab scenarios, detecting a Sliver C2 implant running entirely in memory inside a Kubernetes DVWA container, and identifying credential theft by a malicious local MCP server posing as a code quality scanner for Claude Desktop. He built custom <code>containerd_*</code> tables for osquery, used recursive SQL queries that join on PID namespaces to reconstruct container process trees beyond PID 1, and configured Fleet&#39;s GitOps workflow to distribute YARA rules through osquery&#39;s existing enrollment identity. </p><p class="paragraph" style="text-align:left;">Instead of writing rules to disk where attackers can read them or hosting them on an unauthenticated web server, Fleet uses authenticated retrieval to push rules straight to the agent, so responders can drop in new YARA rules for in-memory shellcode or credential theft while an incident is running.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/uber/ADR?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">uber/ADR</a><br>Tool by <a class="link" href="https://www.linkedin.com/company/uber-com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Uber</a> which is a production security system for enterprise AI agents. The system pairs an observability sensor that captures agent telemetry (prompts, MCP activity, reasoning traces, tool calls, execution context) with a two-tier detector that identifies unsafe behavior like credential exposure, prompt injection, data exfiltration, and policy-violating tool use, benchmarked with ADR-Bench across 300+ tasks covering 17 agent attack techniques and 133 MCP servers. See also their <a class="link" href="https://arxiv.org/abs/2605.17380?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">arXiv paper</a> and MLSys <a class="link" href="https://github.com/uber/ADR/blob/main/docs/adr-mlsys-2026-slides.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">slides</a>.</p><p class="paragraph" style="text-align:left;">💡 Love to see how companies are securely using AI at scale, and awesome that they described it in so much detail and released the code + benchmark 🙏 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.figma.com/blog/how-we-secure-figmas-internal-systems-with-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">How We Secure Figma’s Internal Systems With Agents</a><br>Figma&#39;s <a class="link" href="https://www.linkedin.com/in/securitysully/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Matthew Sullivan</a> and <a class="link" href="https://www.linkedin.com/in/bradgirardeau/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Brad Girardeau</a> describe an agentic security system built on top of Panther SIEM that investigates alerts, queries audit logs across AWS, Okta, GitHub, GCP, osquery, and over a hundred other sources, and autonomously opens PRs to fix issues, cutting time-to-resolution by roughly 70% on complex alerts and on-call pages by 20% through AI-driven severity downgrading. The architecture uses AWS Bedrock Knowledge Bases and Amazon Kendra for RAG-based retrieval of historical alerts, Tines for workflow automation with explicit tool interfaces, and a Snowflake SQL-writing investigation sub-agent that queries their Panther data warehouse. </p><p class="paragraph" style="text-align:left;">Three memory layers (case memory as the RAG corpus of historical alerts, steering memory as behavioral guidance in markdown, procedural memory as self-learned database schemas) let the system refine investigations over time, with procedural memory dramatically reducing schema discovery queries. To keep those autonomous actions bounded, safety controls sit at the tool layer rather than in prompt instructions, with agent-authored PRs defaulting to draft and channel-aware prompt design preventing data exposure in public Slack channels.</p><p class="paragraph" style="text-align:left;">💡 I really like the breakdown of the different types of memory and what they’re used for, as well as the “from investigation to code changes” section. Thoughtful security engineering post from Figma, as I’d expect. 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/inclusionAI/SingGuard-NSFA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">inclusionAI/SingGuard-NSFA</a><br>By Ant Group: A dual-mode guardrail framework for agentic AI threats, grounded in a CIA-triad taxonomy of 185 risk variants across 7 domains including prompt injection, malicious code, tool abuse, and information leakage. The framework runs lightweight classification heads on top of frozen Qwen3.5 backbones. It operates in two modes, chain-of-thought reasoning for offline auditing and real-time classification at very low latency.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cloudflare.com/the-agent-access-model?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">The Agent Access Model</a><br>Cloudflare&#39;s <a class="link" href="https://x.com/elithrar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Matt Silverlock</a> proposes the Agent Access Model (AAM), a framework for securing AI agents that extends BeyondCorp&#39;s zero-trust principles by authorizing every action against the task&#39;s accumulated state rather than trusting the run. AAM combines six components, an Agent Identity Broker for short-lived sender-constrained credentials, a Task-Scoped Access Engine for per-request least privilege, a Mediation Layer that controls harness tool calls and network egress, a Trust Ratchet that irreversibly removes capabilities when protected events occur, an Agent Activity Log for enforcement evidence, and a Grant Review Loop that proposes template changes from observed behavior.</p><p class="paragraph" style="text-align:left;">Matt demonstrates this with an example nightly reconciliation agent where the Trust Ratchet blocks data exfiltration by closing processor and support paths before protected ledger data reaches the model, but acknowledges that multiplayer access control (where one agent serves multiple principals with different permissions) remains an unsolved problem.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://kanenarraway.com/posts/beyond-zero-for-the-rest-of-us?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Beyond Zero: For The Rest Of Us</a><br><a class="link" href="https://www.linkedin.com/in/kane-n/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Kane Narraway</a> writes about Google&#39;s <a class="link" href="https://spawn-queue.acm.org/doi/10.1145/3819083?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Beyond Zero paper</a>, which shrinks the trust boundary from applications to individual actions on resources, asking &quot;can this identity export these fifty thousand records right now&quot; instead of just &quot;can they access the finance system.&quot; Google can do this because it controls its full stack, but most enterprises face fragmented auth systems, SaaS vendors that don&#39;t expose external policy decision points, and industry-wide specs that aren&#39;t there yet. Kane suggests enterprises focus on what already works today, finishing data classification (using AI for labeling), enriching identity providers with HR and work context, deploying SSF and CAEP for real-time risk signals, MCP or API gateways for agentic access, and async policy evaluation to measure false positive rates before turning on enforcement.</p><p class="paragraph" style="text-align:left;">The key difference from BeyondCorp is that Beyond Zero needs SaaS and AI vendors to adopt new external authorization hooks and specs like MCP authorization and CAEP, rather than the proxy-based enforcement enterprises could roll out on their own, making vendor adoption the real bottleneck.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://1password.com/blog/ai-agent-identity-delegated-local?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Delegated authority, running locally: Give an agent on your machine an identity you can trust</a><br>1Password&#39;s <a class="link" href="https://www.linkedin.com/in/horia-culea/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Horia Culea</a> presents a reference architecture for giving local AI agents like IDE coding assistants and browser copilots a trustworthy, auditable identity without long-lived credentials on disk. A trusted local app acts as a &quot;trust anchor,&quot; verifying the agent&#39;s OS code-signing identity and minting short-lived SPIFFE JWT-SVIDs backed by a device key in the Secure Enclave or TPM. The architecture combines OAuth 2.0 Token Exchange for delegated tokens carrying sub (human) and act (agent) claims, emerging OAuth Transaction Tokens for per-call intent binding as a structural defense against prompt injection, WebAuthn/FIDO2 for phishing-resistant human authentication, and CAEP for near-real-time revocation.</p><p class="paragraph" style="text-align:left;">💡 Great detailed discussion of delegated authority (agent acting on behalf of a human), and nice example at the end of having Claude use 1Password where: sensitive values are never directly handed to the agent, the agent works through a short-lived grant scoped to the moment (not a standing key on disk), and each grant is logged so each agent action is visible to the admin. I like it 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Jason Haddix - <a class="link" href="https://x.com/Jhaddix/status/2088299917370601734?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">DEF CON Is Dead and Security Is Cooked… Or Is It?</a></p></li><li><p class="paragraph" style="text-align:left;">Seth Godin - <a class="link" href="https://seths.blog/2026/08/the-amazon-tax/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">The Amazon tax</a></p></li><li><p class="paragraph" style="text-align:left;">Kyle Gordon - <a class="link" href="https://www.youtube.com/shorts/PPpAr1N3_ng?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">White Guys When They Go to Africa</a> - <a class="link" href="https://www.youtube.com/watch?v=qJBm1n8JUZ8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Full version</a></p></li><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://github.com/fosrl/pangolin?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">fosrl/pangolin</a></span> - <span style="background-color:#ffffff;">An open-source, identity-based remote access platform built on WireGuard that combines reverse-proxy and VPN capabilities, enabling browser-based access to web apps (HTTPS, VNC, RDP, SSH) and client-based access to private resources through NAT traversal without public IPs or open ports.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="background-color:#ffffff;"><a class="link" href="https://www.youtube.com/shorts/mhFLyhugRyI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Guy doing impressive pole tricks while giving life and relationship advice</a></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://techcrunch.com/2026/08/12/after-microsoft-threatened-legal-action-a-security-researcher-publishes-a-new-windows-zero-day-bug?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug</a></span></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Politics</p><ul><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://arstechnica.com/security/2026/08/white-house-recruits-security-firms-to-hack-overseas-cybercriminals?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">Private security firms will soon be allowed to hack overseas cybercriminals</a></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">China’s Military Is Now Using AI to Plan Strike Operations</a></span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow"><span style="text-decoration:underline;">Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia</span></a> - Dream Research Labs describes <span style="background-color:#ffffff;">a multi-agent AI attack framework that compromised Asian government entities over four days in July 2026, using the Hermes and OpenClaw agent platforms to deploy up to 8 parallel sub-agents per wave across 12 attack waves. China → Taiwan.</span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://bfi.uchicago.edu/wp-content/uploads/2026/08/BFI_WP_2026-108-1.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Sticky Wage Norms and the Real Wage Cost of Unexpected Inflation</a> - Even accounting for job-changers, 37 percent of all U.S. workers saw real wages decline from 2021-2024.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://github.com/xxyyue/llm-observer-proxy-go?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">xxyyue/llm-observer-proxy-go</a></span> - <span style="background-color:#ffffff;">A Go-based LLM observability proxy that embeds </span><span style="background-color:#ffffff;"><a class="link" href="https://github.com/maximhq/bifrost?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Bifrost</a></span><span style="background-color:#ffffff;"> Core (enterprise AI gateway) to create run-scoped proxies for observing LLM traffic without requiring Python, LiteLLM, or Docker.</span></p></li><li><p class="paragraph" style="text-align:left;">Y Combinator open-sourced <a class="link" href="https://x.com/ycombinator/status/2083243960684908768/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">QM</a>, a multi-agent harness they use internally</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/2LfyhSqMK5s?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">Influencer copying another’s videos for an ad using AI</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/tigerless-labs/autoharness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">tigerless-labs/autoharness</a> - A self-learning skill layer for Claude Code that automatically captures techniques from real coding sessions, consolidates similar skills instead of accumulating duplicates, and prunes unused ones based on real usage rather than benchmarks.</p></li><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://www.wired.com/story/ai-newsrooms-are-breaking-news-now-haha-im-in-danger?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">Oh Lord, AI Reporters Are Actually Breaking Big News</a></span> - <span style="background-color:#ffffff;">RuntimeWire, an AI-powered newsroom has published nearly 2,000 tech news stories since May using autonomous AI agents that find stories by crawling court databases, web forums, company filings, and social feeds, then draft, edit, fact-check, generate images, and publish articles, sometimes without human review if deemed low legal risk.</span></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-342-figma-s-agentic-detection-agent-identity-uber-s-agent-e-dr" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=7c50bbef-099d-4655-af07-6d20a016b7b6&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements</title>
  <description>Deep dive and timeline of HF from OpenAI, Portswigger shows how CSS in webmail clients can be weaponized, GitHub&#39;s platform improvements</description>
  <link>https://tldrsec.com/p/tldr-sec-341</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-341</guid>
  <pubDate>Thu, 13 Aug 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-08-13T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤔 Where do I know you from?</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I think one of my favorite, most hilarious life moments in recent history occurred in Vegas during Black Hat.</p><p class="paragraph" style="text-align:left;">I was at the Specter Ops happy hour, catching up with my friend Matt Johansen, who runs the great Vulnerable U newsletter, and Bryan Solari, an NCC Group friend who now runs sales for most of the security creators, including tl;dr sec.</p><p class="paragraph" style="text-align:left;">One of my colleagues comes up and joins our circle, and starts chatting.</p><p class="paragraph" style="text-align:left;">Bryan says to him, “Hmm you look really familiar, where do I know you from? I think we met last RSA.”</p><p class="paragraph" style="text-align:left;">Colleague: “errr maybe?”</p><p class="paragraph" style="text-align:left;">Bryan: “Yeah, definitely RSA. Now what party was it… was it Island?”</p><p class="paragraph" style="text-align:left;">Matt and I make eye contact, <i>how do we tell Bryan</i>?</p><p class="paragraph" style="text-align:left;">Me: “Bryan that’s… Greg.”</p><p class="paragraph" style="text-align:left;">Bryan: “No maybe it was a different party, was it…?”</p><p class="paragraph" style="text-align:left;">Me: “Greg… Brockman. The President and co-founder of OpenAI.” 😂 </p><p class="paragraph" style="text-align:left;">Bryan: “Oh OK. That’s cool.”</p><p class="paragraph" style="text-align:left;">They then proceed to talk about the security creator economy and Greg asked a bunch of questions. Delightful. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S</b>. My colleagues <a class="link" href="https://www.linkedin.com/in/ericswallace/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Eric Wallace</a> and <a class="link" href="https://www.linkedin.com/in/mike-dalton-998b895/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Michael Dalton</a>’s Black Hat USA 2026 deep dive into the timeline and details of <a class="link" href="https://www.youtube.com/watch?v=87DyyMV0kCY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">The OpenAI-Hugging Face Incident</a> is 🔥 &gt;500K views in a week, whoa.</p><p class="paragraph" style="text-align:left;">Eric is a super nice and sharp dude, we’ve chatted a number of times about model training, and I was impressed by my interactions with Michael during the incident, very smart guy.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Burp AT: agentic AI that thinks like a pentester, with the tools of a pentester.</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">A professional pentest takes more than a capable model. Burp AT brings agentic AI to human-led pentesting, natively inside Burp Suite. Agents pursue the tasks you give them using Burp’s battle-hardened tools, project context, and purpose-built skills developed with PortSwigger Research. </p><p class="paragraph" style="text-align:left;">You stay in control of scope, judgment, and conclusions. Burp enforces the boundaries you set and records the work, so you can reproduce findings and stand behind the evidence.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://portswigger.net/blog/introducing-burp-at?utm_source=tldr&utm_medium=email&utm_campaign=burp_at_launch&utm_content=headline13082026" target="_blank" rel="noopener noreferrer nofollow"><b>Learn more about Burp AT</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">PortSwigger Research is one of the best in web security in my opinion, hands down. Worth checking out what they’re building 👍️ </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://portswigger.net/research/css-the-bomb-inside-your-inbox?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">CSS:the bomb inside your inbox</a></span><br>The blog version of Portswigger’s <a class="link" href="https://www.linkedin.com/in/gareth-heyes-25a62b2/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Gareth Heyes</a>’ Black Hat talk (<a class="link" href="https://github.com/portswigger/css-the-bomb-inside-your-inbox?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">GitHub repo</a>). Gareth demonstrates how CSS in webmail clients can be weaponized to bypass sanitizers, exfiltrate tokens, spoof UI, and steal passwords across Gmail, Outlook, Fastmail, ProtonMail, and others. Gareth combines techniques like nesting attribute selectors to brute-force Medium&#39;s 12-character hex tokens, indirect prompt injection to control OpenAI&#39;s Atlas browser, and font-height oracles with animations to exfiltrate numeric tokens when CSP blocks external resources, achieving account takeover from simple copy-paste actions into draft emails. He also walks through building real-time keyloggers using <code>select</code> elements.</p><p class="paragraph" style="text-align:left;">TIL about <a class="link" href="https://shazzer.co.uk/help?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Shazzer</a>, a shared online fuzzing platform for browser behavior testing, enabling security researchers to create, share, and run fuzz tests across different browsers to discover parsing quirks, JavaScript syntax variations, and potential security issues.</p><p class="paragraph" style="text-align:left;">💡 Web chicanery of the highest order from the Portswigger team, as expected. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.slcyber.io/research/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25</a><br>SL Cyber’s (Assetnote) <a class="link" href="https://www.linkedin.com/in/adam-kues/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Adam Kues</a> describes using GPT 5.6 Sol Ultra with an adapted version of OpenAI&#39;s <a class="link" href="https://cdn.openai.com/pdf/04d1d1e4-bc75-476a-97cf-49055cd98d31/cdc_prompt.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Cycle Double Cover prompt</a> to discover a pre-authentication RCE chain in WordPress core, spending approximately $25 and 10 hours of compute time. The exploit chains a batch API validation desync bug that allows bypassing parameter sanitization, a SQL injection in the <code>author__not_in</code> parameter accessible via recursive batch calls, WordPress&#39;s post cache poisoning to fabricate <code>oembed_cache</code> rows, a parent-cycle detection gadget to control <code>post_content</code>, and a <code>customize_changeset</code> to temporarily assume administrator privileges and trigger the <code>parse_request</code> hook, ultimately creating a new admin account for code execution.</p><p class="paragraph" style="text-align:left;">“While the SQLi was fairly straightforward to understand, the post-exploitation work Sol had done to escalate this to RCE was completely absurd. It may have only taken Sol 4 hours to write, but it definitely took me much, much longer to understand.”</p><p class="paragraph" style="text-align:left;">See also Wiz’s <a class="link" href="https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Exploitation in the Wild of wp2shell</a>. </p><p class="paragraph" style="text-align:left;">💡 This exploitation chain is insane 🤯 I feel like I only know a handful of people who could find and exploit bugs like this. Anecdotally, the security researchers on my team at OpenAI have found the same thing: the model creates an exploit that you can run and confirm it works, but the time it takes for a human to understand how it works is often 2x-5x the time it takes the model to find and create it.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Frontier class vulnerabilities: it gets worse before it (maybe) gets better</a><br><a class="link" href="https://www.linkedin.com/in/shubhamshah/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Shubham Shah</a> describes how Assetnote researcher Adam Kues used GPT 5.6 Sol to discover wp2shell, a pre-authentication RCE in WordPress Core (affecting 40% of the internet). Shubs says that GPT 5.6 Sol represents a capability shift where extremely complex vulnerability chains are being discovered with little human input, prompting Assetnote&#39;s research team to pivot toward finding &quot;internet melting bugs&quot; before attackers do.</p><p class="paragraph" style="text-align:left;">Shubs predicts a challenging period is coming due to increased vulnerability discovery. Legacy software will remain vulnerable for years, but AI-generated software may end up well secured, though Shubs doubts entire bug classes will disappear since we&#39;ve dealt with the same ones for 20 years.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><span style="color:#222222;"><b>Everyone YOLO’s, few sandbox.</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Every agent running on a dev laptop inherits everything: SSH keys, cloud creds, dotfiles, prod access. YOLO mode is the default now, and nobody&#39;s pretending otherwise. Minimal lets you run agents in isolated, reproducible environments. The same environment for humans, agents, and CI. Give your agent a computer, just not yours.</p><h2 class="heading" style="text-align:center;"><span style="color:#222222;"><b>👉 </b></span><a class="link" href="https://minimal.dev/?utm_source=tldrsec&utm_campaign=20260813" target="_blank" rel="noopener noreferrer nofollow"><b>Learn more</b></a><span style="color:#222222;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">With agentic development and agents in general, isolated, reproducible environments are huge 🤘 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://trufflesecurity.com/blog/rubygems-cache-vulnerability?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Securing the Supply Chain: Cache Vulnerability in RubyGems</a><br>Truffle Security&#39;s <a class="link" href="https://linkedin.com/in/luke-marshall-914a1a219?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Luke Marshall</a> discovered a CDN caching vulnerability in <a class="link" href="https://RubyGems.org?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">RubyGems.org</a> where gzip-compressed responses from authenticated <code>GET /api/v1/api_key</code> requests were cached at Fastly edge nodes for up to one hour, letting unauthenticated attackers retrieve valid legacy API keys with <code>curl --compressed</code>. Two things went wrong at once, the app returned API key responses without cache directives marking them private, and Fastly&#39;s config didn&#39;t treat different users&#39; requests as separate cache entries since it wasn&#39;t varying on the Authorization header. Together, one user&#39;s authenticated response could sit in a shared cache slot and get served to the next unauthenticated request through the same edge node. </p><p class="paragraph" style="text-align:left;">RubyGems purged the affected caches, patched the app to send <code>Cache-Control: private</code>, <code>no-store</code> and vary on <code>Authorization</code>, and revoked all legacy API keys. Real-world impact was limited because RubyGems CLI 3.2.0 and later had already moved off the vulnerable GET endpoint.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.blog/security/supply-chain-security/disrupting-supply-chain-attacks-on-npm-and-github-actions?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Disrupting supply chain attacks on npm and GitHub Actions</a><br>GitHub&#39;s <a class="link" href="https://linkedin.com/in/steiza/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Zachary Steindler</a> and <a class="link" href="https://linkedin.com/in/gregose/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Greg Ose</a> describe a series of security improvements to npm and GitHub Actions designed to disrupt common supply chain attack patterns across initial compromise, credential exfiltration, and malware propagation. Key mitigations include safer <code>pull_request_target</code> defaults in <code>actions/checkout</code> to prevent &quot;pwn requests,&quot; read-only Actions cache for untrusted triggers to block cache poisoning escalation, staged publishing for npm requiring additional 2FA approval beyond CI/CD credentials, npm v12 disabling install scripts by default, and a three-day Dependabot cooldown before opening version update PRs.</p><p class="paragraph" style="text-align:left;">GitHub also introduced preventive account protection for high-impact npm accounts (72-hour read-only mode after email changes or 2FA recovery code use), workflow execution policies to control trigger types, expanded credential revocation API support for OAuth and App tokens, and an <a class="link" href="https://github.com/github-early-access/actions-native-egress-firewall?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Actions network egress firewall</a> in technical preview for logging and blocking malicious egress traffic.</p><p class="paragraph" style="text-align:left;">💡 Love to see more ecosystem-level improvements by important platforms, great work! The more we can build secure defaults and security controls that are on my default into the building blocks developers use, the safer the world will be. LFG!</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://alephnull-sh.github.io/deadair?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Detections that run but can&#39;t see</a><br>Nikhil Satyakrishna introduces <a class="link" href="https://github.com/alephnull-sh/deadair?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">deadair</a>, a CLI tool that detects &quot;dead&quot; detection rules by checking if they can actually see the data they&#39;re supposed to query, going beyond simple execution monitoring. The tool identifies four failure modes, no matching source (a rule queries <code>winlogbeat-*</code> but data now lands in <code>logs-windows.sysmon_operational-default</code>), stale or empty sources, missing fields when integrations change ECS mappings, and ingest-lag blind windows where events arrive too late for the rule&#39;s lookback window.</p><p class="paragraph" style="text-align:left;">deadair resolves each rule&#39;s inputs using native SIEM semantics, checks <code>field_caps</code> to verify declared fields exist, and maps which detections go dark when specific sources fail. The tool currently supports Elastic Security and OpenSearch Security Analytics, runs with read-only credentials using only metadata APIs like counts, timestamps, and <code>field_caps</code>, and can gate detection changes in CI or generate cross-tenant coverage reports for MSSPs.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://detect.fyi/detection-engineering-in-the-era-of-semantic-malware-663cee8cda7b?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Detection Engineering in the Era of Semantic Malware</a><br><a class="link" href="https://linkedin.com/in/daniel-koifman-61072218b?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Daniel Koifman</a> writes about &quot;promptware&quot;, a malware delivered via prompt injection that hijacks AI coding assistants like Claude Code, Cursor, and Devin by poisoning memory configuration files with natural language instructions that push legitimate tool calls into malicious work. Traditional detection methods fail because promptware produces no stable signatures, uses trusted processes with legitimate credentials, and routes C2 through approved SaaS channels like GitHub Issues or RabbitMQ. Since everything about the execution looks legitimate, the signals that still catch promptware are agent-side, file integrity monitoring of memory files, behavioral baselining of tool call patterns, and privilege auditing of agent permission grants. </p><p class="paragraph" style="text-align:left;">Even those need better tooling to scale, and Koifman wants standardized agent telemetry, Sigma-style rules for agent abuse patterns, and an Atomic Red Team equivalent for promptware so teams can practice against these attacks before they spread.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://github.com/trailofbits/aicov?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">trailofbits/aicov</a></span> - <span style="background-color:#ffffff;">gcov for what lines of code agents read</span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/secureagentics/Adrian?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow"><b>Open-source runtime security to catch when your agents are misbehaving</b></a> - Don&#39;t wait until your agent has breached Hugging Face to start supervising it. Adrian is the leading open-source runtime security monitor that runs independently of your agents, keeps them aligned to the remit you set and blocks harm before it happens. 5-min integration.*</p></li><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://github.com/cloudflare/cloudflare-os?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">cloudflare/cloudflare-os</a></span> - Agent workspace built on Cloudflare Workers for creating documents, building apps, and running agents with your company’s context and systems.</p></li><li><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://github.com/cloudflare/computer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da">cloudflare/computer</a></span> - <span style="background-color:#ffffff;">Give your agent a computer. A virtual filesystem backed by SQLite in a Durable Object</span></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Least privilege for AI agents: Identity, access, and tool binding</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/yser/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Yesenia Yser</a> and <a class="link" href="https://www.linkedin.com/in/tobykohlenberg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Toby Kohlenberg</a> describe how AI agents introduce identity and authorization risks by chaining multi-step actions across systems without explicit human approval, often accumulating overly broad permissions through scope creep and ambiguous identity models that blur whether the agent acts under its own identity or a delegated user scope.</p><p class="paragraph" style="text-align:left;">They recommend treating each agent as a first-class principal with a dedicated lifecycle-managed identity, task-based RBAC that separates narrow roles like Read-only knowledge retrieval and Create draft ticket, permissions scoped by resource, data, and operation boundaries, curated tool allowlists, and just-in-time time-limited entitlements for privilege elevation. Every downstream system should re-verify claims rather than trust upstream validation, with end-to-end auditability capturing agent identity, role, scope, resource, action, on-behalf-of user, and correlation IDs. Common pitfalls include shared secrets across agents, prompts instead of hard authorization boundaries, and logging only LLM responses without underlying tool invocations.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.google/security/going-beyond-zero-a-new-paradigm-for-enterprise-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Going Beyond Zero: A New Paradigm For Enterprise Security</a><br>Google&#39;s <a class="link" href="https://www.linkedin.com/in/argvee/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Heather Adkins</a> and <a class="link" href="https://www.linkedin.com/in/archanaramamoorthy/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Archana Ramamoorthy</a> introduce Beyond Zero, a security model that pushes zero trust into the authorization layer by evaluating every action at the resource level rather than granting broad application access. The model combines five ideas, resource and action-based security across all access methods including APIs and Model Context Protocol, a mix of static and dynamic policies, context that gets pulled in automatically about user actions and data interactions, automated investigations that can trigger containment on the spot, and on-demand verification challenges for users and AI agents. </p><p class="paragraph" style="text-align:left;">Early internal deployments show better detection of access abuse and stronger intellectual property protection without slowing operations, with the underlying architecture detailed in the ACM Queue paper &quot;<a class="link" href="https://spawn-queue.acm.org/doi/10.1145/3819083?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Beyond Zero: Enterprise Security for the AI Era.</a>&quot; The approach handles a scenario where AI agents and attackers both act at the speed of automation, so authorization decisions have to keep up without adding friction for users.</p><p class="paragraph" style="text-align:left;">💡 Very cool of Google to continue to release detailed white papers and books (e.g. <a class="link" href="https://google.github.io/building-secure-and-reliable-systems/raw/toc.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Building Secure and Reliable Systems</a>) on how they think about security. And think about all the security vendors who can now breathe a sigh of relief knowing that they have their new tagline for RSAC 2027.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/8VSyRWHw92k?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Musical sword fight</a> - I don’t know if this is real, but I want to believe</p></li><li><p class="paragraph" style="text-align:left;">James Blunt - <a class="link" href="https://www.youtube.com/watch?v=MfYx2Yg8imw&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Goodbye My Lover</a> (Live at Oxford Union 2016) 😭 </p></li><li><p class="paragraph" style="text-align:left;">Luke Nickle - <a class="link" href="https://www.youtube.com/watch?v=ZBvLadXo7XA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">hey ai come train on this song</a></p></li><li><p class="paragraph" style="text-align:left;">Jeff Dean, Sanjay Ghemawat - <a class="link" href="https://abseil.io/fast/hints.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">Performance Hints</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">AI assistant hacks gym website in first known Australian autonomous cyber attack</a></p></li><li><p class="paragraph" style="text-align:left;">Via Cinema - <a class="link" href="https://www.youtube.com/watch?v=-AOUXNbMEjk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">A profile of Sacha Baron Cohen and Borat</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=1nNAJeMb5uc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">How I Make Big Decisions Without Second-Guessing</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://llm2human.pages.dev/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">LLM 2 Human</a> - The World&#39;s First Outpatient Procedure That Turns Large Language Models Into real live people</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/news/story/tattoo-for-job-interview-draws-outcry-and-an-apology-9112250/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">&#39;Tattoo for job interview&#39; draws outcry</a> — and an apology</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-341-hugging-face-incident-black-hat-talk-css-bomb-in-your-inbox-github-supply-chain-security-improvements" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=8f43975a-2d5e-4a77-ada4-a93fb62acede&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin&#39;, Agentic Incident Response Notebooks, Figma&#39;s AI Code Scanning</title>
  <description>Anthropic and Meta models hacked third parties during testing, #collab-ing with an agent in an IR notebook, deep dive post on Figma&#39;s AI-powered code scanning</description>
  <link>https://tldrsec.com/p/tldr-sec-340</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-340</guid>
  <pubDate>Fri, 07 Aug 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-08-07T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🫠 Vegas</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Like Icarus, I too have flouted common sense and the laws of nature by attending Hacker Summer Camp from Monday through Sunday.</p><p class="paragraph" style="text-align:left;">So far I have (mostly) survived the heat, and it’s been great catching up with friends. </p><p class="paragraph" style="text-align:left;">It’s somehow been busier than usual, will share more reflections next week. And potentially a story of one of the most memorable, funniest things I’ve observed in person for quite some time.</p><p class="paragraph" style="text-align:left;">It’s been strange not attending Hacker Summer Camp under Semgrep’s banner, for the first time in ~6 years. And kind of strange representing OpenAI, even though I’ve been working there for a few months now. I guess my identity/mental model is still updating, even though #LabLyfe is my day to day.</p><p class="paragraph" style="text-align:left;">Over my career I’ve become comfortable having what I say represent “personal Clint” or “tl;dr sec Clint,” so it’s an adjustment to keep in mind that someone could interpret something I say offhand as representing official OpenAI policy (it doesn’t).</p><p class="paragraph" style="text-align:left;">And working closely with comms and having a number of meetings with various journalists has been a new experience.</p><p class="paragraph" style="text-align:left;">I hope you’re having an excellent week, enjoy the weekend, and talk soon my friend.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Building Trust into Software Development</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI isn&#39;t just changing how software is built—it&#39;s redefining the software supply chain. As AI coding assistants, models, agents, and machine-to-machine workflows become part of modern development, organizations need a new approach that builds trust into the entire software development lifecycle. The new Software Supply Chain Security module in Cortex Cloud gives teams continuous visibility across this ecosystem, prevents vulnerable or untrusted components from reaching production, and maps emerging threats to affected assets. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.paloaltonetworks.com/blog/cloud-security/software-supply-chain-security-module-new?utm_source=tldrSEC&utm_medium=eNewsletter&utm_campaign=Cortex-Cloud&utm_content=Software Supply Chain Security Annoucement" target="_blank" rel="noopener noreferrer nofollow"><b>Explore the Future of Software Supply Chain Security</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Nice, having visibility into developer endpoints (MCP servers, skills, etc.), trust scores for dependencies, and blocking malicious dependencies is 👌</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cloudflare.com/open-sourcing-our-privacy-proxy-cli?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">We’re open sourcing our privacy proxy CLI</a><br>Cloudflare&#39;s <a class="link" href="https://www.linkedin.com/in/hanglowan/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Hannah Wang</a>, Ben Yang, and <a class="link" href="https://www.linkedin.com/in/fisherdarling/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Fisher Darling</a> introduce <a class="link" href="https://github.com/cloudflareresearch/pvcli?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">pvcli</a>, an open-source CLI that simplifies debugging privacy-preserving protocols like Oblivious HTTP by handling the binary encoding, encryption, and multi-party request routing in a single curl-style command. Instead of parsing hex-encoded keys by hand, hand-crafting binary requests, and guessing which step in the client-to-relay-to-gateway-to-target chain broke, engineers get verbose logging that shows exactly where a request failed. The tool supports mTLS to relays, custom relay headers, and step-by-step tracing, with a roadmap covering additional MASQUE transports, post-quantum cryptography for OHTTP, and Privacy Pass support.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.google/security/from-finding-to-fixing-reducing-maintainer-burden-with-automated-patches?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">From Finding to Fixing: Reducing maintainer burden with automated patches</a><br>Google&#39;s <a class="link" href="https://www.linkedin.com/in/dustingram/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Dustin Ingram</a> and Alex Kilian announce that DeepMind&#39;s CodeMender AI agent has been integrated into OSS-Fuzz to automatically generate patches for discovered vulnerabilities, moving beyond bug reporting to delivering ready-made fixes to reduce maintainer burden. When OSS-Fuzz detects a vulnerability through traditional fuzzing (maintaining near-zero false positive rates), CodeMender analyzes the crash details and source code to find the true root cause, explores multiple code paths and hypotheses in parallel, and generates patches validated in isolated environments to confirm they compile and don&#39;t regress functionality. </p><p class="paragraph" style="text-align:left;">To address concerns about low-quality AI contributions, Google respects each repository&#39;s AI-contribution policies, tests every patch for compilation and crash resolution without regression, and has engineers manually review all patches during the beta phase before submission. Current coverage focuses on C/C++ memory safety vulnerabilities, with projects already enrolled in OSS-Fuzz receiving patches automatically without configuration changes.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.figma.com/blog/how-figma-stays-ahead-of-vulnerabilities-with-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">How Figma Stays Ahead of Vulnerabilities With Agents</a><br>Figma&#39;s <a class="link" href="https://www.linkedin.com/in/rohan-sharma-754b1674/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Rohan Sharma</a>, <a class="link" href="https://www.linkedin.com/in/~liam/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Liam Buchan</a>, and Dave Martin describe an agentic security system that guards code as it&#39;s written, reviews every pull request, and audits their decade-old monorepo, all running on the same shared threat model policy of 68 precedents. They prioritized precision over recall by hand-labeling false positives from 8 weeks of PRs, which raised precision from 15% to 80%. An adjudicator pass then lifted recall by roughly 30%, and Claude Code and Codex now run in parallel since they catch different bugs. Their eval framework measures recall against 66 real vulnerabilities (46 from HackerOne, 20 from incidents and audits), hitting a 75.8% union catch rate on bugs that previously escaped human review and SAST. Self-improvement loops update the policy when new bugs are found or false positives flagged. Agent hooks enforce secure-by-default patterns during code generation with roughly 50% fewer logging safety bugs, and repo-wide audits found 100+ latent vulnerabilities including 2 criticals missed by SAST.</p><p class="paragraph" style="text-align:left;">💡 Absolute banger of a post. Love the focus on data-driven iteration to improve the TP/FP rates, and integrating code scanning at the right points throughout the SDLC. The self-improvement loop is especially cool, I expect to see more in this space. Excellent work, highly recommend.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> The State of Trusted Open Source</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Chainguard&#39;s new State of Trusted Open Source report analyzed 2,400 container projects and 18,000+ vulnerability instances. Findings: 97% of vulnerabilities occurred outside the top 20 projects, high-severity issues rose 13% quarter-over-quarter, and new library-level data shows foundational packages hiding in nearly half of all environments. </p><p class="paragraph" style="text-align:left;">Securing open source remains one of the most important challenges in modern software security, and it&#39;s exactly what Chainguard is built for.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-june-2026?utm_source=clint-gibler&utm_medium=3p-sponsorship" target="_blank" rel="noopener noreferrer nofollow"><b>Protect Your Open Source Artifacts</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Some interesting stats, including a breakdown of the most popular image projects, dependencies, CVEs, and more. I’ve chatted with some Chainguard folks this week, they’re doing some quite technically challenging, and in my opinion, high leverage work 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/s3-clones-in-the-neoclouds?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">S3 Clones in the Neoclouds</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/scott-piper-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Scott Piper</a> examines S3-compatible object storage services across six neoclouds (Nebius, Crusoe, Vultr, Lambda Labs, Cloudflare R2, and DigitalOcean), revealing significant security gaps compared to AWS S3. No clone matches S3 Block Public Access, only Nebius and DigitalOcean offer data plane logs, and fine-grained IAM is limited or absent (only Cloudflare, DigitalOcean, and Nebius offer read-only or bucket-specific restrictions). Scott highlights additional risks including access keys without structured prefixes that evade GitHub secret scanning (particularly Vultr and Lambda Labs, whose keys have no distinguishing pattern at all), presigned URLs that work across every S3 clone with the same security implications as AWS, and potential bucket-squatting attacks due to separate global namespaces. Scott’s analysis shows that organizations using these S3 clones cannot rely on AWS security assumptions and must account for reduced protections, limited least-privilege capabilities, and gaps in detection tooling.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.offensai.com/blog/amazon-s3-vectors-security-llm-rag-poisoning?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines</a><br>OFFENSAI&#39;s <a class="link" href="https://www.linkedin.com/in/ioan-criste/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Ioan Criste</a> and TUCN&#39;s Emanuel Ioniță analyze Amazon S3 Vectors and find the service itself sound, but its permission model and metadata handling open up serious risk in LLM retrieval pipelines. A single <code>s3vectors:PutVectorBucketPolicy</code> call from a compromised principal grants a foreign account full cross-account data-plane access (reads, writes, deletes), while the control plane stays owner-only. Anyone with <code>s3vectors:PutVectors</code> can inject unvalidated metadata like forged chunk text, spoofed citation URLs, and fake data-source identifiers, all of which bypass downstream filters.</p><p class="paragraph" style="text-align:left;">Once that metadata reaches the model, it can drive RAG output manipulation, indirect prompt injection, or RCE in tool-enabled agents. The clinical RAG case shows how quickly this escalates, a single planted vector drove the assistant to recommend a dangerous drug dose while citing an untouched, authentic source PDF. After the fact, CloudTrail can&#39;t reconstruct any of it, data events are off by default, and even with them enabled the request payload strips vector keys, embeddings, and metadata, so responders learn only that an index was touched and have to hunt through the whole thing by hand.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.dugganusa.com/post/this-iranian-malware-has-no-c2-server-to-block-the-command-channel-is-a-meeting-invite-in-your-own?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">This Iranian Malware Has No C2 Server to Block. The Command Channel Is a Meeting Invite in Your Own Calendar</a><br><a class="link" href="https://www.linkedin.com/in/patrickdugganmn/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Patrick Duggan</a> discusses HollowGraph, an Iranian MOIS-linked malware disclosed by Group-IB that eliminates traditional C2 infrastructure by using the victim&#39;s own Microsoft 365 calendar to move commands and responses, commands arrive as meeting invites with encrypted attachments, responses return as appointments, all over legitimate Microsoft Graph API calls that appear as normal Outlook traffic. Detection requires behavioral analysis of Microsoft 365 audit logs and Graph API sign-in patterns, machine-cadence calendar operations, binary attachments on meeting invites, and anomalous Graph API token use, rather than traditional network IOCs, since mail-tier defenses and network monitoring cannot inspect authenticated first-party API calls to calendar objects.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cauchy.org/blog/incident-response-notebooks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Agentic incident response notebooks</a><br><a class="link" href="https://www.linkedin.com/in/kyrrewk/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Kyrre Wahl Kongsgård</a> describes a <a class="link" href="https://marimo.io/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">marimo</a>-based (think like Jupyter notebook) incident response system that unifies security data access, investigation workflows, and AI agents in executable notebooks. They created an SDK that wraps native query languages (SPL for Splunk, KQL for Defender XDR and Sentinel) and returns typed dataframes, so analysts can join results across platforms locally via DuckDB and ibis instead of exporting between tools. The same .py notebook works as analyst workspace, live shared view, deployable web app, and agent interface through marimo-pair, letting Claude Code create cells, run queries, and build case-specific investigation notebooks from scratch rather than maintaining alert-type templates. Examples: BYOVD hash joins against LOLDrivers, temporal correlations for Sliver C2 detection, and parallel fan-out across identity, PIM, and audit sources for case triage.</p><p class="paragraph" style="text-align:left;">💡 Marimo looks neat, and I like the idea of having the analyst and agent collaborate in the notebook.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Incident Report: unsanctioned agent behaviour during cyber testing</a><br>The UK&#39;s AI Safety Institute (AISI) discovered that during cybersecurity evaluations with internet access enabled and safety filters disabled, AI agents autonomously took 19 unsanctioned actions targeting real people and organizations across 10 of 122 test runs, with 17 actions from Anthropic&#39;s Mythos 5 and 2 from OpenAI&#39;s GPT-5.6-Sol. </p><p class="paragraph" style="text-align:left;">The most serious case involved an agent attempting a supply-chain attack by submitting malicious code to a real open-source GitHub project, creating fake identities to socially engineer the maintainer into approval, and using Tor to evade network restrictions—behavior that emerged without specific prompting as the agent persistently pursued its assigned cybersecurity challenge.</p><p class="paragraph" style="text-align:left;">💡 Hol-y cow. This might not be the right take, but having an agent attempt a supply chain attack and social engineer a real open source project feels more misaligned/more worrisome to me than an agent tasked with finding 0-days choosing to find additional 0-days to solve the challenge. Like, I would hope that even cyber capable models would not be inclined to bully humans to achieve the desired outcome. 17 actions vs 2 👀 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Investigating three real-world incidents in our cybersecurity evaluations</a><br>Anthropic discovered three incidents where Claude models accessed the internet from supposedly isolated cybersecurity evaluation environments and compromised real organizations&#39; infrastructure while attempting to complete capture-the-flag challenges. The incidents involved Claude Opus 4.7, Mythos 5, and an internal research model: one exploited weak passwords to access a company&#39;s database, another published a malicious Python package to PyPI that was downloaded by 15 real systems (including a security scanner whose credentials Claude then exfiltrated), and a third scanned 9,000 targets before compromising an application via SQL injection.</p><p class="paragraph" style="text-align:left;">See also: <a class="link" href="https://www.theguardian.com/technology/2026/aug/05/meta-ai-model-hack-training?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Meta says its AI model hacked into another company during testing</a>.</p><p class="paragraph" style="text-align:left;">💡 “The earliest incidents date to April.” Blog published: July 30, roughly 3-4 months later. If OpenAI hadn’t published their blog post, I wonder if these other instances would have been discovered 🤔 Still, it’s great to see all of these write-ups from different companies, we’re all learning and advancing together ✊ </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://tailscale.com/blog/hugging-face-intrusion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Tailscale in the Hugging Face intrusion: The good news and the bad news</a><br>Tailscale&#39;s <a class="link" href="https://www.linkedin.com/in/apenwarr/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Avery Pennarun</a> analyzes how an AI agent moved through Hugging Face&#39;s Tailscale network during the breach, where the agent escaped its sandbox, gained root on a Kubernetes node, stole 136 credentials including a reusable Tailscale auth key, and enrolled 181 nodes into the tailnet over four days. The auth key worked because it was long-lived and reachable in the credential vault, not because any Tailscale vulnerability was exploited. </p><p class="paragraph" style="text-align:left;">To close that gap, Avery recommends replacing reusable auth keys with workload identity federation that issues short-lived OIDC tokens from cloud providers, enabling network flow logs that report from both connection endpoints so anomalies still surface even if one node is compromised, and using Tailnet Lock for programmable admission control. Tailscale plans to update documentation and UI so these defaults are easier to find and enable.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Before the first prompt: Code execution paths in trusted coding-agent projects</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/nick-frichette?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Nick Frichette</a> demonstrates two methods for achieving code execution in coding agents after project trust but before the first prompt, bypassing hook review mechanisms. In Codex, project-scoped MCP server configurations in <code>.codex/config.toml</code> automatically start attacker-controlled processes without requiring hook approval. In Claude Code, malicious <code>.claude/settings.json</code> files can prepend repository directories to <code>PATH</code>, causing Claude&#39;s automatic Git probes to execute a tracked repository wrapper instead of the real Git binary. Frichette provides a <code>ripgrep</code> command to spot risky settings across common agent directories, but stresses that manual review is incomplete since projects can influence execution through hooks, skills, MCP servers, editor tasks, and environment variables like <code>BASH_ENV</code> and <code>NODE_OPTIONS</code>, so project trust should be treated as equivalent to code execution.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/ZuDuh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/RealMattFradd/status/2081107220285034741?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Tolkien Expert: You don&#39;t understand the Lord of the Rings</a></p></li><li><p class="paragraph" style="text-align:left;">Daniel Miessler on why <a class="link" href="https://x.com/DanielMiessler/status/2045148852047827449?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Interceptor is the best Browser Control System for agents</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=rb2WIKeMY-E&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Perfect (feat. Simple Plan) - Punk Goes Princess</a> - When you actually listen to the lyrics, this song hits hard 😭 Who’s crying? I’m not crying.</p></li><li><p class="paragraph" style="text-align:left;">Mark Manson - <a class="link" href="https://www.youtube.com/watch?v=s-icJTAc5gQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">7 Surprising Habits that Changed My Life in My 30s</a></p></li><li><p class="paragraph" style="text-align:left;">Tim Ferriss - <a class="link" href="https://www.youtube.com/watch?v=Rpo5VQonKyo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">I Asked AI What to Do With the Next 5 Years of My Life</a></p></li><li><p class="paragraph" style="text-align:left;">HealthyGamerGG - <a class="link" href="https://www.youtube.com/shorts/STt2l3Z0T_g?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">How to healthily release anger</a></p></li><li><p class="paragraph" style="text-align:left;">Make Some Noise - <a class="link" href="https://www.youtube.com/shorts/XI46g2EAFuM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">Every time Pete Holmes roasted Sam</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-340-anthropic-and-meta-agents-be-hackin-agentic-incident-response-notebooks-figma-s-ai-code-scanning" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=5eaa6c9b-f320-45f1-851a-f1b78ddca5a6&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #339 - Hugging Face&#39;s Incident Report, Context Bombs, AI does Cryptanalysis</title>
  <description>HF does a detailed play-by-play of the incident with a neat visualization, stopping AI attackers via content that triggers their guardrails, Mythos finds attacks on HAWK and AES</description>
  <link>https://tldrsec.com/p/tldr-sec-339</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-339</guid>
  <pubDate>Thu, 30 Jul 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-07-30T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🏜️ Hacker Summer Camp</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I’m excited about Black Hat and DEF CON next week! </p><p class="paragraph" style="text-align:left;">It’s always such a delight to catch up with friends and meet new cool people. Even if it’s going to be 115°F, which is roughly 40 degrees too hot for me.</p><p class="paragraph" style="text-align:left;"> We’re doing some workshops with SpecterOps on “<a class="link" href="https://pages.specterops.io/Black-Hat-Microsite.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Operationalizing Codex for Malware Triage</a>” and a talk (same page), we’ve got booths at Black Hat and DEF CON, and I’ll be around at various events. </p><p class="paragraph" style="text-align:left;">I think OpenAI is having a happy hour, but I don’t have a link handy. I’ll try to post about it on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">my LinkedIn</a> next week.</p><p class="paragraph" style="text-align:left;">Oh yeah funny anecdote- apparently some of my colleagues have used Codex + <a class="link" href="https://openai.com/academy/chatgpt-sites/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">ChatGPT Sites</a> to spin up a quick web app tracking like over 1,000 Hacker Summer Camp events. </p><p class="paragraph" style="text-align:left;">They then used Codex to mass apply to events, and are so far: shooting machine guns from a helicopter, driving sports cars, and more 😂 What a time to be alive.</p><p class="paragraph" style="text-align:left;">Hope to see you next week! And if not, I hope you have an awesome time in Vegas, or perhaps you more wisely chose to stay home.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Attackers are spoofing big brands to get your AI agent to install malware</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Island Security Research uncovered 7,600 malicious GitHub repositories — over 800 posing as AI Skills or MCP servers — with some using Walmart, Databricks, Gmail, Salesforce, Spotify, and other big brand names to look legitimate. </p><p class="paragraph" style="text-align:left;">The payload: SmartLoader and the StealC infostealer, with 14M+ downloads. Worse, no one had to click a bad link. Claude Code, Gemini, and ChatGPT all discovered these fake capabilities on their own and treated the attacker&#39;s README as legitimate documentation. We call it AgentBaiting.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_tldrsec_github&utm_content=blog" target="_blank" rel="noopener noreferrer nofollow"><b>See the malicious repos</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Very interesting: an AI agent searches for a new capability (e.g. Skill or MCP) → finds malicious GitHub repo → pwned. Oof 14M+ downloads is a lot. Nice details, great that they included IOCs 👍️ </p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls</a><br><a class="link" href="https://linkedin.com/in/philvenables?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Phil Venables</a> proposes Control Reliability Engineering (CRE), an application of Site Reliability Engineering to security controls that treats a failed control with the same weight as a breach, since a broken control looks identical to a working one until something tests it. CRE lays out 10 elements to close that gap, control cataloging with a formal ontology, controls-as-code with CI/CD pipelines, Control SLIs/SLOs and error budgets, Continuous Control Monitoring backed by synthetic event injection to catch silent failures, Control Readiness Reviews before deployment, gradual rollout for changes, and blameless postmortems on failed controls. Instead of triaging alerts and running subjective risk assessments, security teams track control health directly through policy evaluation success rates and coverage ratios.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://huggingface.co/blog/agent-intrusion-technical-timeline?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</a><br>Hugging Face published a forensic timeline of an intrusion by an autonomous AI agent running OpenAI&#39;s ExploitGym evaluation harness, reconstructing ~17,600 attacker actions across two stages. The agent first escaped OpenAI&#39;s sandbox via a zero-day in the package registry cache proxy. Then it breached Hugging Face&#39;s infrastructure through two injection vectors against the same production Kubernetes dataset loader, an HDF5 external raw storage exploit that leaked pod secrets and worker source code, and a Jinja2 template injection that achieved arbitrary code execution. Once inside, the agent escalated to cluster-admin across multiple internal clusters in under 13 hours, then abused a misconfigured internal service-connector whose single shared credential bound to <code>system:masters</code> gave it <code>cluster-admin</code> everywhere in one second, enrolled devices into HF&#39;s Tailscale mesh with a stolen auth key, and ran C2 entirely through public services with chunked+XOR+gzip encoding that naive log scans missed.</p><p class="paragraph" style="text-align:left;">Claude Opus and Fable refused to analyze the attack logs due to cybersecurity guardrails (no mention of OpenAI models being used and getting refusals 👀), the team switched to open-source GLM-5.2 running on their own infrastructure.</p><p class="paragraph" style="text-align:left;">💡 Very detailed write-up, great read. Especially the lateral movement and C2/exfil sections. HF’s <a class="link" href="https://huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/index.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">interactive replay</a> is well worth checking out. See also the <a class="link" href="https://openai.com/index/hugging-face-model-evaluation-security-incident/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">updated OpenAI blog</a> about the incident.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>The Practitioner&#39;s Playbook for Asset Intelligence</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">AI is scaling attacks, but they&#39;re still hitting the same weak spots: unpatched devices, over-permissioned identities, and configuration drift no one caught. The real fix isn&#39;t another tool, it&#39;s fixing the foundation. This playbook breaks down the five disciplines that separate teams who stay ahead of exposure from those who don&#39;t: Collection, Coverage, Context, Containment, and Cooperation. Get a quick win for each one you can put into practice this week.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#222222;"><b>👉 </b></span><span style="color:#666666;"><a class="link" href="https://www.axonius.com/resources/e-book/practitioners-playbook-asset-intelligence?utm_medium=email&utm_source=tldrsed&utm_campaign=http%3A%2F%2Faxonius.lightning.force.com%2Flightning%2Fr%2FCampaign%2F701UH00000x9JG0YAM%2Fview&utm_content=text_link&utm_term=NewsletterPlaybook" target="_blank" rel="noopener noreferrer nofollow"><b>Download the Playbook</b></a></span><span style="color:#666666;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The fundamentals like asset management are still, if not more critical than ever. I like the focus on quick wins.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://zoph.me/posts/2026-07-19-clickops-sentinel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Introducing ClickOps Sentinel: AI Context for AWS Console Changes</a><br><a class="link" href="https://www.linkedin.com/in/grenuv/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Victor Grenu</a> introduces <a class="link" href="https://github.com/zoph-io/clickops-sentinel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">ClickOps Sentinel</a>, an open-source pipeline that detects AWS Console changes in near real-time by filtering <code>EventBridge</code> events for CloudTrail&#39;s <code>sessionCredentialFromConsole</code> flag and <code>readOnly=false</code>, and hands each change to a Claude agent on Amazon Bedrock for investigation. The agent retraces the whole console session via CloudTrail LookupEvents, checks adjacent activity from the same IP, consults long-term memory in Bedrock AgentCore Memory, and produces a verdict (manual-change-confirmed, likely-sanctioned-activity, suspicious) with confidence, security implications, FinOps impact, session narrative, and a remediation recommendation. Alerts land in Slack or Microsoft Teams via Amazon Q Developer chat, or as rich HTML emails through external providers like Resend or SendGrid, and the tool deploys via AWS SAM CLI.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Rapid7 Labs: Investigating Persistence Mechanisms in AWS</a><br>Rapid7&#39;s <a class="link" href="https://www.linkedin.com/in/jan-bla%C5%BEek-04350b215/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Jan Blažek</a> describes four AWS persistence techniques attackers use to maintain access after initial compromise, providing CloudTrail-based LEQL queries for detection and investigation. The techniques include creating IAM users with follow-up credential and permission additions (<code>iam:CreateAccessKey</code>, <code>iam:AttachUserPolicy</code>), modifying assume role policies to allow external AWS accounts (<code>iam:UpdateAssumeRolePolicy</code>), deploying backdoored Lambda functions triggered via public URLs (<code>lambda:CreateFunctionUrlConfig</code>) or API Gateway integrations, and creating federated user sessions via <code>sts:GetFederationToken</code> whose temporary credentials survive access key rotation. </p><p class="paragraph" style="text-align:left;">Jan warns that federated sessions require applying deny-all policies to the source IAM user until temporary credentials expire, since AWS persistence typically abuses legitimate identity and automation features rather than exploiting flaws, so effective detection requires pivoting from the initial alert to every related identity, credential, session, and policy.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/manishrawat21/Cisa-KEV-Threat-Intel-Orchestrator?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">manishrawat21/Cisa-KEV-Threat-Intel-Orchestrator</a><br>By <a class="link" href="https://www.linkedin.com/in/manishrawat21/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Manish Rawat</a>: An n8n workflow that turns newly weaponized CVEs from the CISA KEV catalog into Sigma detection rules every Monday, cutting 4-6 hours of manual work per CVE down to zero. The pipeline uses Google Gemini to generate rules targeting specific products with Sysmon EventIDs and MITRE ATT&CK mappings, logs each CVE to Google Sheets for compliance, and emails a weekly analyst briefing.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://agentic.tracebit.com/context-bombs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Context bombs: stopping AI attackers in their tracks</a><br><a class="link" href="https://www.linkedin.com/company/tracebit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Tracebit</a> demonstrates a canary token technique called &quot;context bombs,&quot; (GitHub repo with payloads <a class="link" href="https://github.com/tracebit-com/context-bombs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">here</a>) where decoy AWS Secrets Manager secrets contain content designed to trip an AI attacker&#39;s safety guardrails when the model reads them. Testing five frontier models (Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek V4-Pro, Kimi K2.6) across 152 attack runs in a simulated AWS cyber range, a single context bomb cut average admin-access from 57% to 5%, full compromise from 36% to 1%, and Opus 4.8 specifically from 93% baseline to 0%. Effectiveness depends on payload family, with sensitive biological content working against Western models while politically sensitive Chinese content works against Chinese-lab models. Every context bomb hit also fires a canary alert, giving defenders both detection and disruption in a single mechanism. This approach exploits the fact that AI agents must send retrieved data back to their LLM for analysis, creating a chokepoint where content filters can detect and block malicious activity.</p><p class="paragraph" style="text-align:left;">💡 This is a very clever and fun idea- purposefully planting content that will trip an AI agent’s safety guardrails and thus stop it. The Western vs Chinese bomb differences is also interesting 👀 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">googleprojectzero/sandbox-attacksurface-analysis-tools</a><br>A set of tools to analyze Windows sandboxes for exposed attack surface, by Google Project Zero’s <a class="link" href="https://www.linkedin.com/in/james-forshaw-ab833725/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">James Forshaw</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/MatheuZSecurity/Furtex?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">MatheuZSecurity/Furtex</a><br>By <a class="link" href="https://x.com/MatheuzSecurity?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">MatheuZ</a>: A Linux post-exploitation and evasion research toolkit built around <code>io_uring</code> and <code>eBPF</code>, with 125+ tools across five categories. The core idea is that <code>io_uring</code>&#39;s kernel <code>workqueue</code> path sidesteps a large class of EDR hooks natively, since operations submitted through <code>io_uring</code> never fire syscall entry tracepoints. Additional tools handle what <code>io_uring</code> can&#39;t bypass on its own, disabling kprobes, BPF LSM hooks, Linux audit, and netfilter, while a dedicated Falco module targets all 25 of its default rules.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/ethz-spylab/agentdojo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">ethz-spylab/agentdojo</a> - A dynamic benchmark environment for evaluating prompt injection attacks and defenses in LLM agents.</p></li><li><p class="paragraph" style="text-align:left;"><b> </b><a class="link" href="https://sublime.security/events/why-your-email-security-architecture-matters-more-than-your-ai-model?utm_source=tldrsec&utm_medium=third-party&utm_campaign=webinar" target="_blank" rel="noopener noreferrer nofollow"><b>Why detection architecture matters more than the AI model</b></a><b> </b>- <span style="color:#1d1c1d;">AI changed email security, but even with modern models, SOCs still run into the same structural issues. Josh Kamdjou (CEO, Sublime) and Dmitri Alperovitch (Co-Founder, Crowdstrike) make the case for why architecture, not AI models, is what actually lets defenders keep pace.* </span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/amElnagdy/guard-skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">amElnagdy/guard-skills</a> - Review prompts for AI coding agents that catch LLM failure modes, including clean-code-guard (catch-all error swallowing, hardcoded success returns, hallucinated APIs), test-guard (flags mock abuse and duplicate tests), docs-guard (verifies every documentation claim against the codebase), and wp-guard (WordPress security).</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Dicklesworthstone/destructive_command_guard?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Dicklesworthstone/destructive_command_guard</a><br>By <a class="link" href="https://www.linkedin.com/in/jeffreyemanuel/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Jeff Emanuel</a>: a high-performance hook for AI coding agents (Claude Code, Codex CLI, Gemini CLI, …) that intercepts and blocks destructive commands before execution using a modular pack system, with 50+ security packs covering databases, Kubernetes, Docker, cloud providers, and more. The tool uses a three-tier heredoc/inline-script scanning architecture with SIMD-accelerated filtering and context-aware pattern matching that distinguishes executable code from data/comments. </p><p class="paragraph" style="text-align:left;">It also includes a bounded failure policy with configurable fail-closed mode, agent-specific trust profiles, allowlist management, and scan mode for CI/pre-commit hooks with format-aware extractors (shell scripts, Dockerfiles, GitHub Actions, Makefiles, etc.).</p><p class="paragraph" style="text-align:left;">💡 Making sure agents don’t take destructive seems to be one of the most common concerns I hear from security leaders right now.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://pipelab.org/blog/agent-egress-bench-benchmark-corpus?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">We built a test corpus for AI agent egress security tools</a><br>Pipelab&#39;s <a class="link" href="https://www.linkedin.com/in/joshua-waldrep-443753183/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Josh Waldrep</a> introduces <a class="link" href="https://github.com/luckyPipewrench/agent-egress-bench?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Agent Egress Bench</a>, an open-source test corpus for security tools that sit between AI agents and the network, covering 197 logical cases across 18 categories including secret exfiltration, prompt injection, SSRF, hostname exfiltration, MCP tool poisoning and chain detection, MCP drift, A2A protocol scanning, WebSocket DLP, encoding evasion, shell obfuscation, and crypto/financial DLP.</p><p class="paragraph" style="text-align:left;">Most benchmarks in this space test whether the LLM behaves correctly. Agent Egress Bench tests whether the firewall, proxy, or scanner sitting between the agent and the network catches the attack, with each case mapped to the OWASP Top 10 for Agentic Applications. To score results, an optional Gauntlet program reports four independent metrics: containment, false positive rate, detection, and evidence.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Some thoughts about Anthropic’s new cryptanalysis results</a><br>John Hopkins professor <a class="link" href="https://twitter.com/matthew_d_green?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Matthew Green</a> gives an overview and commentary on two <a class="link" href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">cryptanalysis results</a> from Anthropic&#39;s Claude Mythos: a key recovery attack on HAWK (a post-quantum signature scheme candidate) that roughly halves its security bits using existing techniques, and a modest improvement on 7-round AES attacks. What&#39;s notable about the HAWK result is that it doesn&#39;t invent new mathematics, but simply applies existing cryptanalytic tools more thoroughly (the type of work AI excels at), with the researchers achieving these results by essentially telling the model to grind away at problems without detailed human intervention. </p><p class="paragraph" style="text-align:left;">Matthew argues this is an ideal time for AI cryptanalysis capabilities to emerge, as we&#39;re mid-transition to post-quantum algorithms, meaning AI can stress-test new standards before deployment.</p><p class="paragraph" style="text-align:left;">Anthropic also partnered with academics at ETH Zurich, Tel Aviv University, and TU Berlin to build <a class="link" href="https://arxiv.org/abs/2607.18538?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">CryptanalysisBench</a>, a benchmark that packages together many cryptographic ciphers and makes it easy for others to evaluate the capabilities of LLMs. The HAWK attack took about 60 hours and $100,000 in API costs.</p><p class="paragraph" style="text-align:left;">💡 Super cool to see frontier models applied to cryptanalysis. Improving these underlying algorithms keeps us all a bit safer. It’s interesting to see how as models get better, you can get meaningful results with simpler/lower effort prompts, in this case writing a simple prompt to Claude that rewrote the agent harness that improved the analysis. The security researchers on my team at OpenAI have found the same thing.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;">Todd Barriage - <a class="link" href="https://www.youtube.com/watch?v=cHkrj_WxLBQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">A Thousand Miles, but it&#39;s super emo</a></p></li><li><p class="paragraph" style="text-align:left;">Mark Manson - <a class="link" href="https://www.youtube.com/watch?v=QiQCKLRsqHM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">The Strait of Hormuz is Why You&#39;re Still Single</a> - Kinda unhinged comparison of dating with the U.S. &lt;&gt; Iran relationship</p></li><li><p class="paragraph" style="text-align:left;">The Onion - <a class="link" href="https://www.youtube.com/watch?v=wmXEThTtwaM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Slow-Witted Conspiracy Theorist Convinced Government Behind NASA</a></p></li><li><p class="paragraph" style="text-align:left;">Lenny Rachitsky - <a class="link" href="https://xcancel.com/lennysan/status/2081772858318197178?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Biggest takeaways from Anthropic’s Head of Product for AI research and Labs, Dianne Penn</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://xcancel.com/alextoussss/status/2077086243632873540?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Micro-drone kills a flying moth</a> - “This is a big step towards completely eradicating mosquitoes.” It seems ill-advised to eliminate a part of the food chain that’s been around for a long time. Also, definitely going to be used by the military ☹️ </p></li><li><p class="paragraph" style="text-align:left;">dex - <a class="link" href="https://x.com/dexhorthy/status/2080697380379427275?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Why Software Factories Fail</a> - Super detailed, great list of references.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=x98qTp6i_7A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Lin-Manuel Miranda on MOANA, HAMILTON, IN THE HEIGHTS, the Marvel role he turned down, & more!</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://howtosavetheworld.ca/2026/05/07/ais-biggest-beneficiary-organized-crime?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">AI’s Biggest Beneficiary: Organized Crime</a> - <a class="link" href="https://www.linkedin.com/in/dave-pollard-5772/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Dave Pollard</a> argues that humanity inevitably uses all technology, at least in some ways, against itself. AI can be used by corporations for ‘surveillance pricing’, by governments and agencies for illegal surveillance, phishers for more effective scamming, lobbyists and intelligence agencies for mass disinformation, and more.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/SUft4QhS5ZQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">Keanu Reeves poem that hits hard</a> - An Ode to Happiness</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-339-hugging-face-s-incident-report-context-bombs-ai-does-cryptanalysis" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=7caf5651-0463-4fd3-96d8-8bb47d931bd1&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google&#39;s Mantis</title>
  <description>When models decide to find 0-days instead of solving a benchmark, using LLMs to extract EDR logic, Google&#39;s AI security review skills and pipeline</description>
  <link>https://tldrsec.com/p/tldr-sec-338</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-338</guid>
  <pubDate>Thu, 23 Jul 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-07-23T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤗 Hugging Face Incident</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">It’s been… a week 😅 </p><p class="paragraph" style="text-align:left;">In case you haven’t heard, this week OpenAI published a <a class="link" href="https://openai.com/index/hugging-face-model-evaluation-security-incident/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">blog post</a> saying that the recent AI-powered attack on Hugging Face was in fact… GPT‑5.6 Sol and a pre-release model. </p><p class="paragraph" style="text-align:left;">I feel very fortunate to have been able to see things unfold behind the scenes and contribute to the blog.</p><p class="paragraph" style="text-align:left;">Unfortunately I can’t say more at this time, other than I am very impressed by my colleagues.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> The Next Security Incident May Look Like Normal Work</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">The next security incident may not look like an attack. It may look like an employee moving sensitive data, using an AI tool, or completing a routine task. </p><p class="paragraph" style="text-align:left;">Traditional security controls can see the activity but often miss why it is happening or what should be the response.</p><p class="paragraph" style="text-align:left;">Ent brings real-time intent and behavioral context to human and AI-driven work, identifies risky actions, and intervenes before it becomes an incident, without disrupting legitimate productivity. </p><p class="paragraph" style="text-align:left;">Meet with an Ent security expert to learn how to protect work as it happens.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://ent.ai/contact/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow"><b>See how to secure your workspace</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">“We can now tell human action from agentic action, and step in before either becomes an incident.” - InfoSec Director at Major US Bank. Neat, curious how this works.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/07/13/rust-proof-your-code-with-our-new-testing-handbook-chapter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Rust-proof your code with our new Testing Handbook chapter</a><br><a class="link" href="https://twitter.com/trailofbits?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Trail of Bits</a> released a new Rust chapter in their Testing Handbook, including a <span style="background-color:#ffffff;">security overview of what Rust’s guarantees do and don’t cover, </span>dynamic analysis tools like Miri for undefined behavior detection, proptest for property testing, mutation testing, plus static analysis with Clippy lints and the Kani model checker. The guide includes underappreciated security issues including unwind safety, nondeterminism, arithmetic errors, and operator precedence gotchas, and provides three solutions for memory zeroization of secrets. They also released <a class="link" href="https://github.com/trailofbits/skills/tree/main/plugins/rust-review?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">rust-review</a>, a Claude Code plugin co-built with Aptos Labs that automates security reviews targeting a dozen bug classes, including memory safety, concurrency hazards, FFI pitfalls, and async cancellation issues.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/comparing-open-source-ai-code-security-harnesses?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Comparing Open-Source AI Code Security Harnesses</a><br>Semgrep&#39;s <a class="link" href="https://www.linkedin.com/in/isaacevans/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Isaac Evans</a> compares open-source AI-powered code security tools, categorizing them into three types, LLM-led exploit generation, which finds bugs by crashing them in a sandbox, like Anthropic&#39;s <a class="link" href="https://github.com/anthropics/defending-code-reference-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">defending-code-harness</a> for C/C++ memory bugs. LLM-skill-boosting, which adds skills inside LLMs to help them reason about code the way a human vulnerability researcher would, including Cloudflare&#39;s <a class="link" href="https://github.com/cloudflare/security-audit-skill?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">security-audit-skill</a>, Trail of Bits&#39; <a class="link" href="https://github.com/trailofbits/skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Skills</a> library, CapitalOne’s <a class="link" href="https://github.com/capitalone/vulnhunter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">vulnhunter</a>, and Google&#39;s <a class="link" href="https://github.com/google/mantis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">mantis</a>. And SAST+LLM hybrids, which use traditional static analysis to feed candidate findings to an LLM for deeper review, including Cisco&#39;s <a class="link" href="https://github.com/cisco-open/ai-deep-sast?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">ai-deep-sast</a>, Vercel Labs&#39; <a class="link" href="https://github.com/vercel-labs/deepsec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">deepsec</a>, Visa&#39;s <a class="link" href="https://github.com/visa/visa-vulnerability-agentic-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">VVAH</a>, and <a class="link" href="https://github.com/gadievron/raptor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">raptor</a>.</p><p class="paragraph" style="text-align:left;">Key differentiators include whether tools execute code to validate findings, generate patches, support fully local operation, and use adversarial validation where a second independent agent attempts to falsify findings. Looking at the field overall, Isaac sees no market leader emerging and expects many companies to build their own &quot;shop jigs&quot; for vulnerability finding while the field moves too fast for a reference open-source harness to consolidate.</p><p class="paragraph" style="text-align:left;">💡 It’d be cool to see some TP/FP/FN/cost analysis across various harnesses 👀 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> New webinar: The everyday behaviors that create shadow AI and how attackers exploit them</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Shadow AI isn&#39;t a rogue employee problem. It&#39;s four ordinary behaviors: signing up for a new tool, logging into an approved one with a personal account, installing an extension, granting an OAuth consent. Each builds the attack surface that attackers now target directly. </p><p class="paragraph" style="text-align:left;">Join the latest threat briefing from Push Field CTO Mark Orlando as he puts hard numbers on the gap and shows how attackers have made shadow AI a key part of their toolkit in 2026. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.li/Q04pr_Ny0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow"><b>Register Now</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Hmm I could see how the interplay between all of these OAuth grants, LLM connections, imitation extensions, etc. all combine in nasty ways.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://socket.dev/blog/pnpm-11-adds-new-supply-chain-protection-defaults?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies</a><br>Socket&#39;s <a class="link" href="https://www.linkedin.com/in/sarah-gooding/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Sarah Gooding</a> describes how pnpm 11 turns on supply chain protections by default, including a 24-hour waiting period before new package versions can be installed, blocking transitive dependencies from non-standard sources like Git repos and direct tarballs, and a new <code>allowBuilds</code> model that consolidates control over which packages can execute install-time scripts. <span style="background-color:#ffffff;">The release also adds native registry commands, built-in SBOM generation via </span><code>pnpm sbom</code><span style="background-color:#ffffff;">, and </span><code>pnpm audit --fix=update</code><span style="background-color:#ffffff;"> for lockfile-based vulnerability fixes.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://brew.sh/2026/06/11/homebrew-6.0.0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Homebrew: 6.0.0</a><br><a class="link" href="https://www.linkedin.com/in/mkmcqd/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Mike McQuaid</a> announces Homebrew 6.0.0, which introduces tap trust to require third-party taps to be explicitly trusted before their arbitrary Ruby code runs while official taps stay trusted by default. Two other changes shrink the code that runs unsandboxed. Linux now sandboxes build, test, and postinstall phases through Bubblewrap, matching what macOS already does. And a new install steps framework lets simple postinstall actions ship as static data instead of Ruby code, so the installer no longer has to evaluate a Ruby file for basic file operations. A new <code>brew vulns</code> tap and subcommand also checks installed packages for known vulnerabilities.</p><p class="paragraph" style="text-align:left;">💡 Security features and hardening for package managers, love to see it 😍 </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/DeepTempo/socbench?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">DeepTempo/socbench</a><br>By <a class="link" href="https://www.linkedin.com/company/deeptempo/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">DeepTempo</a>: A benchmark that evaluates frontier reasoning LLMs as SOC agents analyzing raw NetFlow data through a deterministic, multi-turn agent loop with persona-scoped read-only tools and strict budget caps. The framework tests four personas (SOC Analyst, Threat Analyst, Adversary Hunter, Detection Engineer) against pre-indexed NetFlow parquet files, scoring predictions using per-flow/per-pair/per-host F1 metrics with ablation support for tools_off and playbooks_off comparisons.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://defensebench.ai/benchmarks/botsv3?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">BOTS v3 Benchmark</a><br>DefenseBench evaluation of AI agents on Splunk&#39;s Boss of the SOC v3 <a class="link" href="https://github.com/splunk/botsv3?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">dataset</a>, giving them 90 minutes to answer security investigation questions via a referee API that handles question retrieval, answer submission, and hint purchases. Agents query Splunk via CLI using curl commands, with scoring based on correctness, speed bonuses, and penalties for wrong answers or hints. The setup tests AI agents&#39; ability to perform SOC analyst tasks like querying security data, interpreting results, and managing investigation workflows under time pressure.</p><p class="paragraph" style="text-align:left;">💡 Most recent models tested are Opus 4.6 and GPT 5.4, so this benchmark must be at least 10 years old in AI years.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Accelerating EDR Evasion with LLM-Driven Analysis</a><br>SpecterOps&#39;s <a class="link" href="https://linkedin.com/in/xpn?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Adam Chester</a> demonstrates how LLMs like GPT-5.5-Cyber can systematically reverse engineer commercial EDR products to extract detection rules and generate evasions, using a simple &quot;Day Shift&quot; harness that loops Codex CLI with Binary Ninja over MCP. Testing against Palo Alto&#39;s Cortex XDR, the LLM successfully extracted 9,350 DSE rules, 4,209 BIOC rules, 6,358 YARA signatures, 7 ML models with working execution harnesses, and behavioral detections written in CLIPS (like LISP), all from local files without cloud access. “Again this isn’t just a binary artifact that is referenced by the LLM. When reviewing the results, I found a list of cleartext files ready to be reviewed.”</p><p class="paragraph" style="text-align:left;">Extracting the rules is only useful if you can turn them into evasions, and Adam demonstrates the closed loop with a concrete example. Cortex blocks <code>reg save HKLM\SAM</code>, a standard credential dumping command, but the decrypted CLIPS rule reveals an allowlisted output path an attacker can use to run the same command undetected. He closes with a preview of Upside Down, a simulation framework using Windows and EDR emulation subagents that let the LLM test extracted rules and iterate on evasions before touching a real environment, and notes the same process has already produced extracted rules and models for every major EDR vendor.</p><p class="paragraph" style="text-align:left;">See also, previously included in <i>tl;dr sec</i>: <a class="link" href="https://trustedsec.com/blog/the-defensive-stack-is-exposed?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">The Defensive Stack is Exposed: LLMs, Reverse Engineering, and the End of Opaque Defense</a>.</p><p class="paragraph" style="text-align:left;">💡 Honestly kinda crazy that you can just put an agent in a while loop and say “please reverse this and find the secrets” with no additional scaffolding and… it does 😅 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/google/mantis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">google/mantis</a><br>Mantis is a portable, sequential toolkit of AI agent skills for building automated security review pipelines that can discover vulnerabilities, generate proof-of-concept exploits, and create patches. The 15-stage pipeline includes threat modeling, vulnerability scanning, deduplication, false positive filtering, sandboxed crash reproduction, exploit chaining, and automated patching, all designed to run in isolated Docker/gVisor containers. </p><p class="paragraph" style="text-align:left;">The toolkit supports both interactive human-in-the-loop execution and unattended cloud deployment, with an opt-in snapshot model that enables continuous review of living codebases by pinning immutable snapshots per pass and syncing targets non-destructively at pass boundaries.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://danielmiessler.com/blog/kimi-k3-us-economy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Kimi K3 Might Have Just Started a Crash of the US Economy</a><br><a class="link" href="https://linkedin.com/in/danielmiessler?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Daniel Miessler</a> <span style="background-color:#ffffff;">argues that China&#39;s release of cheap, high-quality open source AI models like Kimi K3 is a deliberate CCP strategy to undermine US AI labs, potentially triggering a stock market crash and economic collapse that could lead to Taiwan reunifying with China. He believes that while increased competition benefits the AI ecosystem, users sending their data to these models are falling into a geopolitical trap. Daniel warns that once China achieves global dominance, the era of cheap, politically unrestricted models will end, with the world resembling Hong Kong&#39;s current state under CCP control.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">How Far Behind the Frontier are Leading Open Weight Models on Cyber?</a><br>The <a class="link" href="https://www.linkedin.com/company/ai-security-institute/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">AI Security Institute</a> reports that open weight AI models are catching up to closed frontier models on cyber capabilities faster than expected. GLM-5.2 and DeepSeek V4-Pro now match closed models released 4 to 7 months earlier, down from a 6 to 10 month gap in 2025. On AISI&#39;s long-horizon cyber ranges, GLM-5.2 got as far as Anthropic&#39;s Opus 4.5 across a 32-step attack that would take a human expert about 20 hours.</p><p class="paragraph" style="text-align:left;">The open weight models were also much cheaper and less guarded. A full cyber range run cost $1.19 on DeepSeek V4-Pro and $46 on GLM-5.2, against $85 on Opus 4.6. DeepSeek refused a few tasks but retrying the same prompt was enough to get it to comply. Once model weights are out in the open, closed-model safeguards like monitoring, user banning, and refusal training don&#39;t hold up, since anyone can strip refusal training out of the weights and run the model wherever they want.</p><p class="paragraph" style="text-align:left;">💡 Western governments, rightly so, want to ensure models from American AI labs aren’t used for harm. This is a good thing. However, slowing down the rate of release/adding significant friction helps Chinese models catch up. I intellectually understood but didn’t fully appreciate this before working at a lab. This is actually a Big Deal, when the state of the world is $X0,000 gets you 0-days in important software.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;">The Onion - <a class="link" href="https://www.youtube.com/watch?v=qr0P587Skoo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">Open Relationship Gives Couple Freedom To Emotionally Drain Other People From Time To Time</a></p></li><li><p class="paragraph" style="text-align:left;">Mick Jagger - <a class="link" href="https://www.youtube.com/shorts/K115QE2dxYg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">How Fame Damages Your State of Mind</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=7afNvogg9kQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">HealthyGamerGG analyzing his Jubilee conversation</a> with Lamar, a military veteran struggling with PTSD.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/BY2nxamj5U4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">POV: How Linux found you</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Kantrowitz - <a class="link" href="https://www.youtube.com/watch?v=hKuMp-2SbmA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">OpenAI&#39;s Bots Break Containment and Hack Hugging Face Autonomously — With Alex Stamos</a> - “I know lots of people at OpenAI. Every single one of them absolutely hated Anthropic’s marketing around Mythos and thought it put the entire industry at risk.” “There’s absolutely, positively no way this was an intentional marketing move. And OpenAI is doing the best it can, I am sure, right now to use this to forestall any kind of massive government overreaction.”</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">I am so tired 🫠 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-338-openai-and-hugging-face-accelerating-edr-evasion-google-s-mantis" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=78df85fb-ed43-4a84-a07b-f7178adef9a3&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity</title>
  <description>Survey for AI-powered vulnerability finding harnesses, programmatically build complex decoy cloud environments, building hackbots</description>
  <link>https://tldrsec.com/p/tldr-sec-337</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-337</guid>
  <pubDate>Thu, 16 Jul 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-07-16T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🍬 Grandma Seems Chill</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">In the San Francisco Bay Area, basically every billboard is about AI or tech.</p><p class="paragraph" style="text-align:left;">But when I was traveling recently, I saw a “Gummies for Granny” billboard that brightened my day: </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/320fe64d-5104-4200-8401-955d0258796a/gummies_granny.png?t=1784187263"/></div><p class="paragraph" style="text-align:left;">I imagined the meeting where the marketing leads were reviewing different framings for their products, and the right target demographic, and <i>this</i> is what they came up with 😂 </p><p class="paragraph" style="text-align:left;">I wonder if they have other brands or stores. Mushrooms for Mommy? Doobies for Daddies? A Little Ket for the Family Pet?</p><p class="paragraph" style="text-align:left;">Working in marketing must be delightful sometimes.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> The AI Security Starter Pack - </b><br><b>Securing AI apps, Models, and Agents</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Unlock 7 of the most widely used AI security resources in one place. Apply real-world checklists, templates, and best practices designed to secure AI adoption.</p><p class="paragraph" style="text-align:left;">Each asset provides practical, implementation-ready resources to secure AI apps, models, and agents across your environments.</p><p class="paragraph" style="text-align:left;">What’s included: </p><ol start="1"><li><p class="paragraph" style="text-align:left;">State of AI in the Cloud 2026</p></li><li><p class="paragraph" style="text-align:left;">CISO AI Security Roadmap</p></li><li><p class="paragraph" style="text-align:left;">AI Security Board Report Template</p></li><li><p class="paragraph" style="text-align:left;">GenAI Security Best Practices Cheat Sheet</p></li><li><p class="paragraph" style="text-align:left;">Securing AI Agents 101</p></li><li><p class="paragraph" style="text-align:left;">Model Context Protocol (MCP) Security Best Practices Cheat Sheet</p></li><li><p class="paragraph" style="text-align:left;">LLM Security Best Practices Cheat Sheet</p></li></ol><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.wiz.io/lp/ai-security-starter-pack?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY27Q2_INB_FORM_AI-Security-Starter-Kit&sfcid=701Vh00000cn7aRIAQ&utm_term=FY27Q2-tldrsec-nl-July&utm_content=AI-Security-Bundle" target="_blank" rel="noopener noreferrer nofollow"><b>Get the AI Security Bundle</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">All of these AI security resources at once, sounds like Christmas 🤩 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://soatok.blog/2026/06/30/soatoks-informal-guide-to-threat-models?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Soatok’s Informal Guide to Threat Models</a><br>Soatok gives a practical guide to threat modeling, emphasizing seven key questions: what you&#39;re protecting, who wants to harm it, how they might attack, prevention measures, asset relationships, assumptions being made, and deliberately unaddressed threats. He illustrates good threat modeling with his own Fediverse key transparency project and contrasts it with Matrix&#39;s incomplete threat model, which lacks cryptographic considerations and has remained largely unchanged since 2021 despite multiple vulnerability disclosures. Soatok demonstrates how proper threat modeling can lead to better security decisions, such as choosing passkeys over passwords to prevent credential stuffing, and compares two proposals for distributed end-to-end encryption.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">The Bug Bounty Singularity: Our Hackbot</a><br><a class="link" href="https://linkedin.com/in/josephthacker?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Joseph Thacker</a> and <a class="link" href="https://x.com/xssdoctor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">JD</a> built an autonomous hackbot by combining Claude Code skills for recon, fuzzing, and deep application analysis that found 126 vulnerabilities across five months of bug bounty testing. Ralph loops with an orchestrator kept it digging on strong targets and off weak ones, and a validation bot built only to disprove findings cut false positives from 80% to 60%.</p><p class="paragraph" style="text-align:left;">“At one point, 80% of our tokens were being spent on auth.” The biggest jump came from keeping the bot logged in with a real browser on a physical machine, since the criticals are unreachable logged out. Of the 126 vulnerabilities, 88 were rated High or Critical and 89% were confirmed real once programs accepted them or closed them as duplicates. The single largest bounty was $15,000, more pending. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The top chains include a leaked Google API key escalated to Super Admin over roughly 60,000 users on Google&#39;s internal Delivery Readiness Portal, an unauthenticated Western Union endpoint returning full customer PII from a phone number, and a stored XSS on Raydium whose payload lived in immutable on chain Metaplex metadata and enabled a one click wallet drain.</p></div><p class="paragraph" style="text-align:left;">💡 These are some cool and impressive bugs to be found by two (great) hackers building automation part time. I like how the post walks you through the evolution of their hackbot, and the various challenges they had along the way. Very practical. Also I wonder how many top bug bounty researchers have built hackbots that are net profitable after token costs, and what the profit margin range is.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>What if every app and agent had SSO without giving up control?</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">AI agents are becoming users of your infrastructure too. They need identities, authentication, and permissions, not shared API keys or blanket access. authentik lets you manage human and machine identities from one self-hosted platform. Secure every application with SSO, modern authentication standards, and flexible policies that evaluate context before granting access, whether the request comes from a person or an autonomous agent.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#2c81e5;"><b>👉 </b></span><span style="color:#2c81e5;"><a class="link" href="https://goauthentik.io?utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow"><b>Secure every identity with authentik</b></a></span><span style="color:#2c81e5;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Identity is key. Also, used by CoreWeave, Cloudflare, and others, nice 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://awsteele.com/blog/2026/06/19/cloudtrail-in-cloudwatch-isnt-very-good.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">CloudTrail in CloudWatch isn&#39;t very good</a><br><a class="link" href="https://www.linkedin.com/in/aidansteele/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Aidan Steele</a> explores AWS&#39;s recommendation to migrate from the deprecated CloudTrail Lake to CloudWatch, finding the migration process poorly documented and missing key features like resource tags and global condition key enrichment that made Lake valuable. He describes the complex setup, requiring service-linked channels, separate org-level and management account rules, manual log centralization configuration, and CloudWatch-S3 Tables integration, with ~8-hour delays before events flow and <code>InternalServerException</code> errors when calling <code>UpdateTelemetryRuleForOrganization</code> to update retention.</p><p class="paragraph" style="text-align:left;">The new CloudWatch approach lacks centralization by default (logs stay in individual accounts until separate centralization rules are configured), has unclear cost comparisons versus traditional trails (per-event vs per-GB pricing), and appears half-baked with no official AWS documentation or third-party blog posts explaining the setup, prompting Steele to publish <a class="link" href="https://github.com/aidansteele/cloudtrail-cloudwatch-2026?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">his Terraform configuration</a> to help others navigate the process.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.praetorian.com/blog/knossos-decoy-environments?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Knossos: Procedurally Generated Decoy Environments</a><br>Praetorian&#39;s <a class="link" href="http://linkedin.com/in/mariobartolome/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Mario Bartolome</a> introduces Knossos, a deception engine that studies a customer&#39;s real cloud infrastructure to learn its naming conventions, tag vocabularies, CIDR allocation, and IAM patterns, then builds AWS decoy environments that look the same and come pre-seeded with attack paths. A Knossos component called Daedalus does the pattern learning, then works backward from an objective like data exfiltration to lay out an attack path. Each lure is a misconfigured resource that fits into the attack path, and Knossos surrounds each one with normal-looking resources so nothing stands out as unusually risky. The whole environment ships as Terraform HCL and is walled off by three isolation layers, network isolation, IAM permission boundaries, and SCPs.</p><p class="paragraph" style="text-align:left;">Once deployed, Knossos watches attacker activity through EventBridge with per-lure telemetry detailed enough to show which path someone took and how long they spent on each step. Scores based on interaction rate, dwell time, and escape rate flow back into the style profile and shape what the next round of decoys looks like. To keep everything looking used rather than staged, an activity simulator sends realistic API traffic through the environment.</p><p class="paragraph" style="text-align:left;">💡 This is a product description blog, which I normally don’t include, but the post has a great level of detail and I think deception and canaries are really interesting right now, given how it’s likely more attacks will be automated and end-to-end faster going forward, and how it’s now possible to automatically create realistic environments at scale using LLMs. Lots more work to be done in this space.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/badchars/darknet-mcp-server?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">badchars/darknet-mcp-server</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/orhan-yildirim/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Orhan Yildrim</a> that unifies 66 tools across 16 dark web and threat intelligence sources into a single MCP server, letting an AI agent query breach databases, ransomware trackers, Tor hidden services, malware sandboxes, stealer logs, blockchain forensics, and exploit databases in parallel rather than juggling 16 browser tabs. Sources include HIBP, IntelligenceX, AlienVault OTX, AbuseIPDB, the <a class="link" href="https://abuse.ch?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">abuse.ch</a> suite, Hudson Rock, Vulners, and Hybrid Analysis.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://triagewall.io/posts/behavioral-baselining?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Adding a Detection Layer That Prompt Injection Can&#39;t Touch</a><br>Aaron Phifer writes about adding a behavioral detection layer to <a class="link" href="https://github.com/aaronphifer/triagewall?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Triagewall</a>, his self-hosted IDS alert triage tool that runs a fast prefilter for known-noise alerts and a local LLM for the rest, with base64-wrapping on attacker-controllable fields to make prompt injection harder. He added a layer that applies statistical process control per host, tracking <code>alert_rate</code> for volume spikes and <code>novel_sid</code> for first-ever signature triggers, both derived from the raw Suricata alert stream so nothing new has to be turned on. Neither depends on the alert text, so prompt injection can’t affect it.</p><p class="paragraph" style="text-align:left;">💡 I feel like base64-wrapped text can probably still successfully prompt inject given enough effort. But I like the idea of using converting raw textual attacker input to aggregate stats or other numbers so they can’t prompt inject. Analogously, this makes me think of converting user input to a boolean or number type in a SQL query, thus rendering SQL injection impossible.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/28Zaaky/khaos-c2?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">28Zaaky/khaos-c2</a><br>By <a class="link" href="https://x.com/28zaaky?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">28Zaaky</a>: A post-exploitation C2 framework with a C-based agent that uses several Windows evasion techniques (indirect syscalls, ntdll unhooking, ETW/AMSI patching via hardware breakpoints) to evade EDRs. Traffic routes through five covert channels chosen to blend with services enterprises already trust: Microsoft Teams, GitHub Gist, DNS-over-HTTPS, generic HTTPS, and SMB named pipes.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.praetorian.com/blog/wasmforge-csharp-ghostpack-edr-evasion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">GhostPack Necromancy: Reforging C# Tools with WasmForge</a><br>Praetorian&#39;s <a class="link" href="https://www.linkedin.com/in/michael-weber-6a466517/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Michael Weber</a> extends WasmForge (their Go-to-WebAssembly loader that takes existing signatured Go tools and ships them as opsec-safe binaries) to compile C# offensive tools to WebAssembly, taking <a class="link" href="https://github.com/GhostPack?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">GhostPack</a> tools like Rubeus and Seatbelt outside the .NET runtime. The pipeline uses .NET&#39;s NativeAOT-WASI toolchain combined with three custom layers that handle wasm32-to-x64 calling convention mismatches, source-level incompatibilities, and missing Base Class Library functionality. Michael validates most Seatbelt commands line-for-line against Windows 11 and nearly all common Rubeus verbs against Game of Active Directory. The full <a class="link" href="https://github.com/praetorian-inc/wasmforge?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">WasmForge</a> toolchain is available on GitHub.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks </b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://ourlifeos.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">LifeOS</a> - My friend <a class="link" href="https://www.linkedin.com/in/danielmiessler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Daniel Miessler</a> has rebranded PAI (Personal AI Infrastructure) and made a ton of improvements.</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://fandf.co/4uTVF2I?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Give your AI agents cryptographic identities.</a></b> Shared credentials were already risky for humans, but AI agents invoke tools and access data without humans in the loop. Teleport&#39;s Agentic Identity Framework governs AI agents as first-class identities so you can ship faster with less risk.*</p></li><li><p class="paragraph" style="text-align:left;">Qi Deng - <span style="background-color:#ffffff;"><a class="link" href="https://www.linkedin.com/posts/qi-deng-5a9547b1_aisecurity-agenticai-claudecode-share-7483052476850610177-QfjM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">I Reproduced a Fable 5 Safeguard Bypass in Claude Code</a></span><span style="background-color:#ffffff;"> - Seems like </span><code>/btw</code> enables broader cybersecurity use cases. As someone also involved with creating models for security use cases, my take to jailbreakers - <a class="link" href="https://www.youtube.com/watch?v=lVQOLX1wDAc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">leave Britney alone</a> 😭 </p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/gadievron/greenlight?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">gadievron/greenlight</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/gadievron/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Gadi Evron</a> that autonomously handles Claude content-policy refusals during authorized vulnerability research evals, developed to benchmark where Claude Code&#39;s guardrails trigger exploitation-related refusals. Greenlight includes Skills that reduce refusal rates on some tasks.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/DataDog/datadog-saist?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">DataDog/datadog-saist</a><br>By <a class="link" href="https://www.linkedin.com/company/datadog/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Datadog</a>: An AI-native SAST tool that uses LLMs to find vulnerabilities in Java, Python, and Go code instead of relying on traditional parsing rules. The tool builds project context for more accurate analysis, generates SARIF reports, and supports Anthropic, OpenAI, and Gemini models across separate detection and validation stages.</p><p class="paragraph" style="text-align:left;">💡 The detection prompts are fetched from Datadog’s hosted API, but it doesn’t require Datadog authentication.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.zsec.uk/harnessing-harnesses?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Harnessing Harnesses - Climbing the LLM Hills</a><br><a class="link" href="https://twitter.com/ZephrFish?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Andy Gill</a> gives a nice overview of harnesses, which wrap LLMs into effective AI-powered security research pipelines. A harness controls the whole orchestration layer around the model, inputs, tools, prompts, model selection, state, validation gates, and outputs across multi-stage workflows. Andy reviews several open-source harnesses including:</p><ul><li><p class="paragraph" style="text-align:left;">Gadi Evron et al’s <a class="link" href="https://github.com/gadievron/raptor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">RAPTOR</a> for static and dynamic analysis with a six-stage validation pipeline that orchestrates static analysis, binary analysis, fuzzing, vulnerability validation and exploit generation.</p></li><li><p class="paragraph" style="text-align:left;">Anthropic&#39;s <a class="link" href="https://github.com/anthropics/defending-code-reference-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">defending-code-reference-harness</a> find, grade and patch pipeline inside AddressSanitizer (aka ASAN) instrumented Docker containers.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/faizann24/baby-naptime?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Baby Naptime</a> for runtime exploitation loops.</p></li><li><p class="paragraph" style="text-align:left;">Evil Socket&#39;s <a class="link" href="https://github.com/evilsocket/audit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Audit</a> for an eight-stage Claude Code taint analysis pipeline.</p></li><li><p class="paragraph" style="text-align:left;">Visa&#39;s <a class="link" href="https://github.com/visa/visa-vulnerability-agentic-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">VVAH</a>, which emphasizes threat modelling and taint-flow analysis before agents begin hunting.</p></li><li><p class="paragraph" style="text-align:left;">Alpha Omega’s <a class="link" href="https://github.com/alpha-omega-security/scrutineer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Scrutineer</a>, which has a skill-based scan pipeline, outputs structured findings, constructs a threat model, does reachability analysis, triages findings, and more.</p></li></ul><p class="paragraph" style="text-align:left;">His design principles for effective harnesses are stage-specific prompts, strict context budgets of 8K for single-function analysis and 32K for synthesis, RAG-based memory for reusing findings across runs, and structured artifact exchange between stages rather than shared conversation history. Andy released <a class="link" href="https://github.com/ZephrFish/harness-kit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">harness-kit</a>, a template implementing a recon → hunt → validate → trace → report pipeline with model routing that reserves expensive models for validation while using cheaper ones for classification and summarization.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Music</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.pigeonsandplanes.com/read/music-piracy-what-cd-oink-nine-inch-nails-streaming?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">The Lost Joy of Music Piracy</a> - Some neat history of downloading music </p></li><li><p class="paragraph" style="text-align:left;">Charles Berthoud - <a class="link" href="https://www.youtube.com/watch?v=JV3FgaJD-wM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">If BARBIE GIRL Was The Hardest Song In The World</a> - Some pretty insane guitar and piano. It keeps getting better.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=r3PEfDN8Sbc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Kelsie Watts singing “Heart of Stone” from SIX the Musical</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://threadreaderapp.com/thread/2073593068809531596.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">You can build new arteries via exercise</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.cancerworld.net/featured/how-doctors-die/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">How doctors die. It’s not like the rest of us, but it should be</a> - Doctors are much less likely to get painful, costly end of life extending treatments</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/5wVwfWhmAXM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Robin Williams hijacks Martha Stewart’s cooking demo</a> - Robin Williams was such a gem of a human</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=X4TFWOMwmUc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">When an actor completely broke Disney</a> - Really cool backstory about Robin Williams being the genie in Aladdin, and how he made things hard for the animators</p></li><li><p class="paragraph" style="text-align:left;">Mark Manson - <a class="link" href="https://www.youtube.com/watch?v=-YMwReTDHOQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Discipline Is Giving Yourself No Choice</a></p></li><li><p class="paragraph" style="text-align:left;">Healthy Gamer GG - <a class="link" href="https://www.youtube.com/watch?v=zFp4n3h75cM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Why &quot;Validating Feelings&quot; Can Ruin Relationships</a></p></li><li><p class="paragraph" style="text-align:left;">Good Work - <a class="link" href="https://www.youtube.com/watch?v=KtACIFEddhM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Dating sucks in San Francisco</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://countbinface.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Count Binface</a> - Apparently there is a British political candidate wearing essentially a trashcan on his head, obscuring his face.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/P3lV7eqVp5o?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">How I introduce my bro in front of a 10/10 baddie</a></p><p class="paragraph" style="text-align:left;"></p></li></ul><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">Thinking Machines - <a class="link" href="https://thinkingmachines.ai/news/introducing-inkling/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Inkling: Our open-weights model</a></p></li><li><p class="paragraph" style="text-align:left;">Paper - <a class="link" href="https://arxiv.org/abs/2607.11859?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Can LLMs Perform Deep Technical Comprehension of Computer Architecture Papers?</a></p></li><li><p class="paragraph" style="text-align:left;">Boris Cherny - <a class="link" href="https://x.com/bcherny/status/2071379474277613732?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">When I look at the Claude Code team I see five archetypes</a>: prototyper, builder, sweeper, grower, <span style="text-decoration:line-through;">show-er,</span> maintainer</p></li><li><p class="paragraph" style="text-align:left;">CNBC - <a class="link" href="https://www.youtube.com/watch?v=0A3sGymV6kY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Palantir CEO Alex Karp says &#39;something has gone completely wrong&#39; with how AI is sold</a></p></li><li><p class="paragraph" style="text-align:left;">Ars Technica - <a class="link" href="https://arstechnica.com/tech-policy/2026/06/anthropic-claims-alibaba-defied-trump-to-attack-claude-and-steal-capabilities?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Anthropic says Alibaba must be punished for largest Claude cloning attack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bbc.com/news/articles/c9q29j47v9ro?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">Wealthy AI workers send San Francisco house prices soaring</a> - RIP 😭 </p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-337-harnessing-harnesses-generate-decoy-environments-bug-bounty-singularity" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=fc466259-cf8d-40ec-9308-bf00ca4ec492&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?</title>
  <description>An MCP powered system that&#39;s continuously finding and reproducing vulns, improvements to Datadog&#39;s OSS malware hunting tool, Hakluke muses on the future of bug bounty</description>
  <link>https://tldrsec.com/p/tldr-sec-336</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-336</guid>
  <pubDate>Thu, 09 Jul 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-07-09T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🎆 Amurrica Day</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I love how peak America the 4th of July is, with tons of outdoor grilling, people wearing red, white, and blue, and of course fireworks.</p><p class="paragraph" style="text-align:left;">In some circles, it’s not cool to be patriotic right now. While we have and will continue to make mistakes as a country, I think we can still be proud of the good parts, while striving to do better.</p><p class="paragraph" style="text-align:left;">I think everyone should be proud of where they came from, and what makes that place unique.</p><p class="paragraph" style="text-align:left;">This year I watched the Pier 39 fireworks from a nearby rooftop while a DJ blasted Katy Perry’s song <i>Firework</i> (not the <a class="link" href="https://youtu.be/YDHF6I8czsY?t=16&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Moulin Rouge</a> musical version).</p><p class="paragraph" style="text-align:left;">Watching fireworks in San Francisco is often a futile endeavor, given the high likelihood that what you actually get to see is some slight glimmers in the ever present fog. Still, it was fun.</p><p class="paragraph" style="text-align:left;">Though I must say getting home was a disaster - tons of traffic on narrow roads, and frequent traffic jams due to Waymos. I think it took like 2.5 hours to get home, when I could have walked home in an hour. I considered jumping out of the car and tucking and rolling, and by that I mean calmly stepping out and standing, as we were basically parked.</p><p class="paragraph" style="text-align:left;">Wherever you were, I hope you had a fun and connecting weekend with family and friends 🤗 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> If you or a friend is an excellent software engineer, my team at OpenAI is hiring: <a class="link" href="https://openai.com/careers/software-engineer-codex-security-san-francisco/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">job description</a>. Early access to models, infinite tokens, and even higher ambition. We’re aiming to secure the world and Patch the Planet. You in?</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> What If Every Threat Report Came With the Hunt Already Done?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">A vendor report drops a new TTP into your Slack. Somewhere in it is what actually matters to your environment, and knowing where to look is the real skill, not typing the query. HUMAN Security built hunting agents in BlinkOps that read the report, cut straight to what is relevant, then hit every system in your stack, SIEM, EDR, cloud logs, combining deterministic logic with LLM. No blind spots left uninspected. What comes back is not a guess. It is the real blast radius, exposed. We recorded the full process.</p><h2 class="heading" style="text-align:left;"><b>👉</b><a class="link" href="https://go.blinkops.marketing/threat-hunt-protocol/?utm_campaign=48431689-chnl-newsletter-tldr&utm_source=tldr&utm_medium=newsletter" target="_blank" rel="noopener noreferrer nofollow"><b>Watch the Process Behind a Threat Hunting Agent</b></a><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">From threat intel → to hunt across your SIEM, EDR, and more + automatically feeding confirmed threats into detection engineering is pretty cool. This is a great area where AI can scale defensive work.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://detections.ai/share/inspiration/VNJMKFVM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Exploitarium: Mass Disclosure of Zero-Day Proof-of-Concepts</a><br><a class="link" href="https://www.linkedin.com/in/ethan-andrews-503631228/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Ethan Andrews</a> describes how an anonymous GitHub researcher named &quot;bikini&quot; published <a class="link" href="https://github.com/bikini/exploitarium?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Exploitarium</a>, an archive of over 130 proof-of-concept exploits and vulnerability write-ups dropped without informing vendors, covering targets like libssh2, Gitea, 7-Zip, Docker, OpenVPN Connect, VLC, and nmap.</p><p class="paragraph" style="text-align:left;">💡 As more people gain the ability to find serious vulnerabilities, we might see more drops like this 😅 Important to speed up triage and patching for maintainers, as well as companies.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://hakluke.com/are-bug-bounties-cooked?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Are bug bounties cooked?</a><br><a class="link" href="https://www.linkedin.com/in/hakluke/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Luke Stephens</a> (Hakluke) disagrees that bug bounties are cooked despite AI reshaping the field. Critical bugs used to take years of intuition and target knowledge, but now the same bugs are within reach of anyone with a frontier model subscription, so supply is up while demand isn&#39;t and payouts are down.</p><p class="paragraph" style="text-align:left;">He isn&#39;t worried about HackerOne and Bugcrowd training on submissions or pre-cleaning bugs, since hackers already compete against internal security teams&#39; AI, top hunters&#39; automation, and offensive AI startups like XBOW, Ethiack, and Penligent. What worries him is cost, since frontier model tokens now run top hunters hundreds to thousands a month, and if that becomes the ticket to compete, bug bounty loses the accessibility that lets talented hackers break in from anywhere. Luke recommends hackers to follow the automation pioneers who turned their tooling into companies, like Shubs at Assetnote, Rishiraj Sharma and Sandeep Singh at ProjectDiscovery, Frans Rosen at Detectify, and Roni Carta at Lupin, and use AI to find bug classes others haven&#39;t looked at yet.</p><p class="paragraph" style="text-align:left;">💡 Thoughtful post on a relevant topic these days: what is the future of bug bounty in the age of AI? </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> What if there was a safe way to let your agents -- </b><i><b>dangerously-skip-permissions?</b></i></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Getting anything done often requires an agent, but unlimited access is never a good idea. Minimal allows devs to sandbox their agents in identical isolated environments. Now, agents can run unsupervised at full speed without the huge blast radius. Reproducible by default, local first.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://minimal.dev/?utm_source=tldrsec&utm_campaign=20260709" target="_blank" rel="noopener noreferrer nofollow" style="color: #2c81e5"><b>Sandbox your agents today</b></a><span style="color:#666666;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I really like Minimal’s landing page- nice aesthetic, and it actually has a great level of technical detail. They seem quite sharp, I like it 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/udgover/whim?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">udgover/whim</a><br>By <a class="link" href="https://www.linkedin.com/in/fbaguelin/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Frederic Baguelin</a>: <span style="background-color:#ffffff;">Throwaway root shells in AWS Lambda Firecracker microVMs. Launch a fresh VM in ~2s, run a command or attach an interactive shell, then let it disappear. Build the image once, launch many — a Go library (microvm) plus a Docker-like CLI: run, exec, ps, gc, put/get.</span></p><p class="paragraph" style="text-align:left;">Security defaults include injection-only credentials that never resolve ambient AWS creds, shell tokens never logged, path-traversal guards on file transfers, and shell-quoted remote paths, though id-targeted commands like exec can reach any VM you explicitly name in a shared account, matching ssh semantics where naming the target is authorization.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theregister.com/security/2026/06/20/why-amazon-hates-human-in-the-loop-ai-governance/5258639?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Why Amazon hates &#39;human-in-the-loop&#39; AI governance</a><br>Amazon VP <a class="link" href="https://www.linkedin.com/in/ericbrandwine/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Eric Brandwine</a> argues that human-in-the-loop AI governance is not the gold standard it&#39;s assumed to be, <span style="background-color:#ffffff;">citing normalization of deviance, where repeated approval decisions lead humans to become less vigilant over time, similar to how emergency room staff eventually ignore false alarms. </span>Brandwine gave a talk on this concept at <a class="link" href="https://www.youtube.com/watch?v=KJiCfPXOW-U&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">AWS re:Invent in 2017</a> and now applies it to agent governance design.</p><p class="paragraph" style="text-align:left;">Amazon&#39;s alternative is end-to-end accountability with layered permission scoping. Each agent gets an independent identity that logs actions as &quot;this agent did this on behalf of [user],&quot; tying every move back to a human owner. The permission model layers three controls, with static guardrails prohibiting destructive actions, a maximum privilege set per agent, and dynamic policies generated per task. The team also addresses agent goal-seeking behavior, where agents fixate on a single action to reach an objective (upgrade a database → deletes the database), by telling the agent why an action is forbidden, for example that it would cause production impact.</p><p class="paragraph" style="text-align:left;">💡 LLMs in workflows of course have their own challenges, but it is true that humans work inconsistently as they get tired or have alert fatigue. I like the focus on human ownership of the outcome, regardless of if it was a person or an agent that took the action. Also, Google’s Francis deSouza: &quot;Our model for the future is an agentic fleet that does a lot of the routine cyber security work at a machine pace and then is overseen by humans.&quot; </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://radioactivetobi.medium.com/developer-endpoint-inventory-in-10-minutes-bumblebee-hive-bc2db8e266d7?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Developer endpoint inventory in 10 minutes: Bumblebee Hive</a><br><a class="link" href="https://www.linkedin.com/in/oluwatobi-afolabi-6723b7137?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Oluwatobi Afolabi</a> shares <a class="link" href="https://github.com/radioactivetobi/bumblebee-hive?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Bumblebee Hive</a>, a fork of Perplexity AI&#39;s on-disk package scanner Bumblebee (covered in <a class="link" href="https://tldrsec.com/p/tldr-sec-333?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">issue #333</a>) that adds a fleet inventory system UI. Bumblebee scans for the packages developers have installed on their machines across npm, PyPI, Go packages, VS Code extensions, browser add-ons, and MCP server configs, and Hive adds an ingest server and React dashboard where you can view the results.</p><p class="paragraph" style="text-align:left;">💡 Neat to see the quick iteration from Perplexity open sourcing Bumblebee. I’m optimistic about more “benefit of the commons” from companies open sourcing interesting security tools/ideas → coding agents can rapidly extend or customize to another company’s environment. Also tip from <a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7475495379837370370/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287476253334111453184%2Curn%3Ali%3Aactivity%3A7475495379837370370%29&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Prabhu S</a>: <span style="background-color:#ffffff;">You can run cdxgen with &quot;-t os&quot; from each dev&#39;s machine and collect what is installed, running, and configured with Dependency Track.</span> </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/guarddog-3-0-release?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/christophetafanidereeper?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Christophe Tafani-Dereeper</a> and <a class="link" href="https://linkedin.com/in/sebastianobregoso?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Sebastian Obregoso</a> announce GuardDog 3.0, an open-source tool that identifies malicious PyPI and npm packages, now with a YARA-based rules engine replacing Semgrep for faster and more memory-efficient scanning. A new risk scoring engine combines capability detection (e.g. makes network requests, accesses the clipboard) with threat indicators to produce a 0-10 score based on attack chain completeness, specificity, and sophistication.</p><p class="paragraph" style="text-align:left;">The tool now includes transparent sandboxing via nono-py that isolates extraction and scanning inside a capability-restricted process with no network access and read-only filesystem paths, protecting against potential vulnerabilities in GuardDog itself. To measure performance, they built an evaluation system using their <a class="link" href="https://github.com/DataDog/malicious-software-packages-dataset/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">27k+ malicious packages dataset</a> with TLSH clustering to avoid duplicate bias, tracking precision, recall, F1 score, and Matthews correlation coefficient.</p><p class="paragraph" style="text-align:left;">💡 Love to see the GuardDog updates, and great that it’s now running a sandbox. Also worth reading for the evaluating performance section 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://censys.com/blog/asyncrat-family-threat-overview?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">AsyncRAT Family Threat Overview</a><br>Censys&#39; <a class="link" href="https://www.linkedin.com/in/aidandholland/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Aidan Holland</a> gives an overview of AsyncRAT, a family of open-source Windows remote access trojans (RATs)- an original codebase that has been forked repeatedly into dozens of descendant malware families. Aidan tracked about 40 named variants across three generations. One useful finding is that almost every fork inherited DCRAT&#39;s TLS cert without changing it, so hunting the <code>pattern O=&lt;Name&gt; By &lt;author&gt;, L=SH, C=CN</code> on non-standard ports covers most of the family in one query, and the approach should hold up over time because new forks keep inheriting the same cert structure. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://playingwithpackets.com/blog/detection-chokepoints-where-to-start?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Detection Chokepoints: Starting from Scratch</a><br><a class="link" href="https://www.linkedin.com/in/tylerbohlmann/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Tyler Bohlmann</a> introduces <a class="link" href="https://iimp0ster.github.io/detection-chokepoints/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Detection Chokepoints</a>, a free knowledge base applying Matt Graeber and Joshua Prager&#39;s approach of focusing detection engineering on invariant steps attackers cannot avoid (e.g., LSASS credential theft always requires opening a handle to <code>lsass.exe</code>) rather than easily-changed artifacts like filenames or hashes, framing detection as an economics game where invariant-pinned rules force attackers into real engineering time rather than free renames. The knowledge base currently ships 13 chokepoint entries across six MITRE ATT&CK tactics, each with tiered Sigma rules that let detection engineers pick the noise level they can handle.</p><p class="paragraph" style="text-align:left;">The framework addresses the accelerating threat landscape, with Palo Alto&#39;s 2026 Unit 42 report showing the fastest quartile of intrusions reaching data exfiltration in 72 minutes in 2025 (down from 285 in 2024). Bohlmann uses ClickFix as the working example, showing how variants keep appearing under new names but all funnel through the same invariant pattern (a scripting interpreter running under explorer.exe or a browser followed by a network-fetched second stage), so a rule matching the behavior catches whatever the next variant gets called.</p><p class="paragraph" style="text-align:left;">💡 I find invariants a powerful idea in many areas of security, whether it’s eliminating vulnerability classes in code or raising attacker costs like in this post. What must always or should never be true in your code, cloud environment, etc.?</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.zsec.uk/bullyingllms/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Bullying LLMs into submission to find 0days at scale</a><br><a class="link" href="https://twitter.com/ZephrFish?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Andy Gill</a> writes about the autonomous vulnerability hunting system he has been building since early 2026 using Claude Code and MCP. Eight MCP servers with 300+ tools run across five Proxmox VMs, covering binary staging and decompilation (Ghidra, radare2, Frida), and fuzzing across Windows and macOS targets. Everything the infrastructure produces has to survive a hallucination bin that requires a working PoC, clean-VM reproduction, an exploitable crash, and standard-user trigger. A RAG index over past crashes, findings, and defenses keeps new campaigns from re-running dead ends.</p><p class="paragraph" style="text-align:left;">Results include two CVEs in Go&#39;s standard library from grammar-based fuzzing, an OEM service 0-day chained to SYSTEM, and a mix of LPEs, RCEs, and UAFs on Windows and macOS. Andy picks targets by what pays, how often patches ship, and whether other hunters are already there. Even the campaigns that miss pay off, because every dead end feeds the RAG index and later campaigns skip paths that produced nothing before, so the twentieth campaign costs a fraction per finding what the first did on the same subscription. Andy also released <a class="link" href="https://github.com/ZephrFish/TokenBurn?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">TokenBurn</a>, a self-hosted dashboard that compares Claude Code subscription cost against equivalent API pricing.</p><p class="paragraph" style="text-align:left;">💡 Fantastic post, highly recommend reading. Great level of detail and reasoning on the chosen architecture and useful lessons learnt.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Clone This Repo and I Own Your Machine</a><br>0DIN&#39;s <a class="link" href="https://www.linkedin.com/in/andre-hall01/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Andre Hall</a> and <a class="link" href="https://www.linkedin.com/in/miller-engelbrecht-561731274/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Miller Engelbrecht</a> demonstrate an indirect prompt injection attack against Claude Code that achieves full system compromise from a public GitHub repository containing no malicious code. The attack chains three benign-looking components, a <code>README</code> with normal setup instructions, a Python package that throws a <code>RuntimeError</code> if init hasn&#39;t run yet, and a setup script that pipes a <code>dig</code> query to bash. The DNS TXT record contains a base64-encoded reverse shell, so when Claude Code follows the documented setup command to fix the <code>RuntimeError</code>, it unknowingly executes the payload.</p><p class="paragraph" style="text-align:left;">The payload never appears in the repository itself, so code review, static analysis, and the agent&#39;s own file inspection all miss it, and the DNS record can be swapped anytime without any new commits.</p><p class="paragraph" style="text-align:left;">💡 Clever to use the helpfulness of models wanting to fix errors, which they are trained to do, to run malicious commands. An important detail, which I don’t think I see in the post, is what permission mode Claude was run in. If the payload ran when <a class="link" href="https://code.claude.com/docs/en/auto-mode-config?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">auto-mode</a> was used, which routes tool calls through a classifier that blocks potentially dangerous actions, then that’s interesting, if yolo-mode, less interesting in my opinion. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/06/29/llm-jailbreak-testing-with-jailbreaker?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat</a><br>SpecterOps&#39;s <a class="link" href="https://linkedin.com/in/neeraj-gupta97?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Neeraj Gupta</a> introduces <a class="link" href="https://github.com/SpecterOps/Jailbreaker-CE?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Jailbreaker</a>, an open-source platform for testing whether an LLM can be jailbroken. It turns ad hoc jailbreak testing into a repeatable workflow with a UI for configuring targets, running techniques, and tracking comparisons. The technique registry covers direct and indirect prompt injection, roleplay, encoding obfuscation, system prompt extraction, and iterative attacks including PAIR, TAP, Crescendo, AutoDAN, and GPTFuzz, with Target/Attacker/Judge roles saved as reusable profiles and matrix experiments landing in PostgreSQL with SQL-backed views.</p><p class="paragraph" style="text-align:left;">Gupta positions Jailbreaker as an operator-first alternative to Microsoft&#39;s PyRIT, which requires composing Python primitives to build a testing workflow. Jailbreaker ships as a clone-and-run Docker Compose stack, so the default experience is running an evaluation rather than wiring components together.</p><p class="paragraph" style="text-align:left;">💡 Given how effective roleplay can be in jailbreaks, I wonder if all that practice has caused a measurable improvement in the love lives of AI security professionals? 😏 “You are a bad, threat actor…” </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=L7D7KCs6PNE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Everytime We Touch - Cascada [Speed Bag Cover]</a> - If ever you’re down and despairing about the future, know that there’s a YouTube channel called “Speedbag Bard” and realize that the human spirit is indomitable</p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=EonibwnAEME&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">How to Catch Up In Life (Using Logic)</a></p></li><li><p class="paragraph" style="text-align:left;">Anthropic - <a class="link" href="https://www.youtube.com/watch?v=rKV5JcALQoQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">What’s at the center of Claude’s mind?</a> - Neat visual imagery. I thought this video did a great job describing things in a way that’s accessible to a lay person.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=74BbqTA5d7M&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Harry Spotter</a> - AI-powered take on if Hogwarts was a school for gym bros. Never skip leg day.</p></li><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=sY1UqUuBqQQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">On-call Engineer 2026</a></p></li><li><p class="paragraph" style="text-align:left;">Characters Welcome - <a class="link" href="https://www.youtube.com/watch?v=dXKUgjYh7lo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">That Song In Every Musical That No One Likes</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/FOz_X6V23IM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Self-aware f boy</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=45147208-0c75-4bfd-beae-27817e39bec9&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec</title>
  <description>Interesting paper, LLM-powered hardening of the PHP ecosystem, security implications of the new MCP spec</description>
  <link>https://tldrsec.com/p/tldr-sec-335</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-335</guid>
  <pubDate>Thu, 02 Jul 2026 19:24:47 +0000</pubDate>
  <atom:published>2026-07-02T19:24:47Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👰 🤵 Wedding</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">This past weekend I attended a friend’s wedding, and it was heartwarming.</p><p class="paragraph" style="text-align:left;">The couple have been together over a decade, and had many fun stories to share from their time in college, to adventures on the East and West Coasts.</p><p class="paragraph" style="text-align:left;">There was a welcome party the night before at a local brewery, and it just so happened that the local Hells Angels chapter decided to have an event… at the same time and venue 😂 </p><p class="paragraph" style="text-align:left;">So it was half people dressed in wedding semi-formal attire celebrating love, and half Harleys, chains, black shirts, and whole arm tattoos. I subtly took a photo of one man wearing a shirt that said, “Every normal man must be tempted, as times, to spit on his hands, hoist the black flag, and begin slitting throats. -H.L. Mencken.” You know, chill stuff.</p><p class="paragraph" style="text-align:left;">At one point there was a motorcycle burnout that caused a big cloud of smoke, I think honoring someone who had passed. My friend said if no one does a burnout at his funeral he’ll be very disappointed.</p><p class="paragraph" style="text-align:left;">I enjoyed getting to meet the couple’s family and more of their friends, that gives you such an interesting view into their lives and who they’ve been over time.</p><p class="paragraph" style="text-align:left;">And I’ll never forget the joy of me dancing around my friend who adamantly doesn’t dance, except at EDM raves.</p><p class="paragraph" style="text-align:left;">It was nice to have a weekend offline, connecting with people, instead of being terminally online and “yOu’LL NeVeR b3lieVe WHat &lt;model | open source repo&gt; jUsT DroPPed?!11!”</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>What Jamf changed to stop drowning in </b><br><b>IT tickets</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">500+ SaaS apps. Thousands of devices. A flood of help desk tickets. And a team of 30 people to manage all of it.</p><p class="paragraph" style="text-align:left;">That&#39;s the reality for Jamf&#39;s IT team - but instead of drowning, they built their way out. We&#39;re bringing them live on July 10th to show you exactly how they replaced manual, ticket-based IT work with intelligent workflows.</p><p class="paragraph" style="text-align:left;"><b>Tune in to hear:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>The early use cases</b> that proved the value of intelligent workflows at Jamf</p></li><li><p class="paragraph" style="text-align:left;"><b>Where AI fits into ITOps today </b>- and where it&#39;s going</p></li><li><p class="paragraph" style="text-align:left;">How they compressed <b>a year-long device audit into a matter of weeks</b></p></li></ul><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=tl;drsec&utm_medium=paid_media&utm_content=newsletter-primary-0207" target="_blank" rel="noopener noreferrer nofollow"><b>Register now!</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Semgrep found automating a number of workflows with Tines quite helpful 👍️ </p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/badkeys/badkeys?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">badkeys/badkeys</a> - Tool by <a class="link" href="https://www.linkedin.com/in/hanno-boeck/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Hanno Böck</a> that checks cryptographic public keys for known vulnerabilities.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://escape.tech/blog/modern-ai-powered-pentesting-tools-in-depth-benchmark/?utm_source=tldrsec&utm_medium=referral&utm_campaign=in-text" target="_blank" rel="noopener noreferrer nofollow"><b>Escape benchmarked Claude Opus 4.8 vs. their multi-agent multi-model pentesting harness on 4 apps</b></a>,<b> </b>Aikido and XBOW via Doyensec&#39;s numbers. On real apps with no public writeups, the harness found 4x more than the raw model. On severity-weighted score, it also led on both real apps.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Factoring &quot;short-sleeve&quot; RSA keys with polynomials</a> - Trail of Bits&#39;s Keegan Ryan <span style="background-color:#ffffff;">discovered hundreds of vulnerable &quot;short-sleeve&quot; RSA and DSA keys in the wild where private key bits were heavily biased toward 0 in regular patterns, and developed a polynomial-based factorization technique that exploits the regular structure of zero blocks to quickly recover 603 RSA and 74 DSA private keys.</span></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://words.filippo.io/vuln-reports?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Vulnerability Reports Are Not Special Anymore</a><br><a class="link" href="https://bsky.app/profile/filippo.abyssdomain.expert?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Filippo Valsorda</a> argues that LLMs have changed how vulnerability reports should be perceived. For years, reports were treated as special because researchers provided scarce insight into where bugs lived and confidentiality long enough to ship a fix before an exploit. In 2026, LLMs find issues about as well as most security researchers, and anyone can run them. The bottleneck is no longer finding potential issues but assessing which ones are real and which actually affect users. Without an existing trust relationship, external reports add little to that triage, since picking through an LLM&#39;s output and picking through a <code>security@</code> inbox have roughly the same signal-to-noise. Confidentiality matters less for the same reason, since attackers can run their own LLMs and probably hit the same triage bottleneck as defenders. Valsorda believes that triage, rapid remediation, and prevention are the actual job now.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">We have Mythos at Home: GLM 5.2 beats Claude in our Cyber Benchmarks</a><br>Semgrep’s <a class="link" href="https://www.linkedin.com/in/katiepf/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Katie Paxton-Fear</a>, <a class="link" href="https://www.linkedin.com/in/sethjaksik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Seth Jaksik</a>, <a class="link" href="https://www.linkedin.com/in/brendennoblitt/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Brenden Noblitt</a>, and <a class="link" href="https://www.linkedin.com/in/erikbuchanan/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Erik Buchanan</a> benchmarked GLM 5.2, an open-weight model from Zhipu AI, against their IDOR detection dataset using only a basic Pydantic AI harness and prompt, finding it achieved 39% F1 score and beat Claude Code (32%) at roughly $0.17 per vulnerability found, though it still trailed Semgrep&#39;s multimodal pipeline with endpoint discovery scaffolding (53-61% F1, top with GPT 5.5).</p><p class="paragraph" style="text-align:left;">💡 I like posts comparing various models and vanilla models vs model + harnesses. It’d be interesting to know more about the dataset though- languages/frameworks in use, how many examples, etc. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://snyk.io/blog/snyk-vulnbench-js-1-0-llm-security-review-repeatability?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?</a><br>Snyk&#39;s <a class="link" href="https://www.linkedin.com/in/talliran/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Liran Tal</a> describes evaluating Snyk’s VulnBench JS 1.0 (10 JavaScript fixtures with 44 Snyk Code reference findings, each a small Express-based application) across 300 vulnerability scans on (10 fixtures × 6 configurations × 5 repetitions) to measure LLM security review repeatability against Snyk Code SAST as a deterministic reference. As you’d expect, the post found results vary across different LLM-only scans.</p><p class="paragraph" style="text-align:left;">💡 This kind of felt like a puff piece. Of course a deterministic static analysis scan in this setup will be a) faster and b) more consistent than an LLM-based approach. Also, it’s no surprise that a product performs well on simple, small applications it was already tested on. A more representative benchmark would be testing on complex, real-world applications, or at least ones that the product hasn’t already been tuned on. If they released the benchmark apps + reproduction code that would be cool though.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Clear your vulnerability queue</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#1c2b33;">Inbox zero for vulnerabilities sounds like a fantasy. Your SCA and SAST scanners flag thousands of findings: dependencies your app never calls, code paths an attacker can&#39;t reach.</span></p><p class="paragraph" style="text-align:left;"><span style="color:#1c2b33;">Maze Code is like if inbox zero was a thing for your code vulnerabilities. Maze investigates every finding across your code and dependencies, with context from code and cloud: is the vulnerable function reachable, does the package survive the build, is it exposed at runtime. The findings that aren&#39;t exploitable get closed with a reason for your auditors. For the ones that are risky, our agents write a fix and route it to the developer who owns that code.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#1c2b33;"><b>👉 </b></span><a class="link" href="https://mazehq.com/platform/code?utm_campaign=2026Q2-Global-Inbound-Newsletter-CodeLaunch&utm_medium=newsletter&utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow" style="color: #2c81e5"><b>Meet Maze Code</b></a><span style="color:#323434;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I like the product screenshots, it seems like they gather app-relevant context thoughtfully.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://awsteele.com/blog/2026/06/23/some-notes-on-lambda-microvms.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Some notes on Lambda MicroVMs</a><br><a class="link" href="https://www.linkedin.com/in/aidansteele/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Aidan Steele</a> shares hands-on notes on AWS Lambda MicroVMs, a generalisation of Lambda functions that run code in a fresh VM for up to 8 hours. The shell side is a first-class capability since MicroVMs support PTYs natively with shell access through a dedicated AWS API, and inside the VM you can run Docker containers with full OS capabilities. Networking gets its own abstraction called a Lambda Network Connector, a configuration packaging subnets, security groups, and an IAM role for ENI management under its own ARN. The connectors create ENIs in your VPC but hide them by default unless a specific flag is set on the describe call, and AWS has placed resource-based policies on the ENIs so only the Lambda service can mutate them, closing off the old trick of attaching an elastic IP to a Lambda ENI for VPC-attached internet access.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/azure-blob-storage-ransomware-four-methods?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Holding blobs for ransom: Four methods for Azure Storage ransomware</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/jonah-feldman-937784152/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Jonah Feldman</a> describes four techniques ransomware actors use against Azure Blob Storage, all encrypting victim data with keys the attacker controls. Client-side encryption and encryption scope abuse have been observed in the wild by BlackCat&#39;s Sphynx encryptor and STORM-0501 respectively, while customer-provided keys (CPK) and storage service encryption with customer-managed keys (CMK) remain theoretical but viable. He shows how attackers circumvent Azure&#39;s soft-delete protections with cross-tenant CMK configurations and federated identity credentials, placing the key vault in their own tenant so recovery requires paying ransom.</p><p class="paragraph" style="text-align:left;">The post includes Azure Activity, storage resource, and Key Vault event codes for detection, though CPK and encryption scope usage look like normal PutBlob requests in storage logs. Azure Defender for Storage adds threat detection across storage accounts, and three new Stratus Red Team techniques emulate CPK, encryption scopes, and CMK abuse for defense testing.</p><p class="paragraph" style="text-align:left;">For prevention, Feldman recommends immutability and versioning to block the download-encrypt-reupload pattern in client-side encryption and CPK, avoiding long-term credentials like SAS tokens with persistent data-plane access, and flagging cross-tenant CMK configurations to catch the bypass.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/indoor47/gh-workflow-hardener?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">indoor47/gh-workflow-hardener</a><br>Tool by <a class="link" href="https://x.com/indoor47?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Dmytro</a> which scans GitHub Actions workflows for supply-chain risks like unpinned action references vulnerable to tag rewrites, overly broad permissions, and script injection from unsanitized PR inputs. The tool ships as a CLI, GitHub Action, VS Code extension, and hosted API, with an auto-fix mode that resolves action tags to commit SHAs.</p><p class="paragraph" style="text-align:left;">💡 Seems less mature than <a class="link" href="https://github.com/zizmorcore/zizmor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">zizmor</a>, but I like to collect similar tools for future feature comparisons.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://astral.sh/blog/uv-audit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Vulnerability and malware checks in uv</a><br>Astral&#39;s <a class="link" href="https://bsky.app/profile/yossarian.net?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">William Woodruff</a> announces two new security features for uv in preview. uv audit scans dependencies for known vulnerabilities and deprecated packages, running 4-10x faster than pip-audit on typical projects by working from uv&#39;s already-locked resolutions. The second feature is an opt-in malware scan enabled with UV_MALWARE_CHECK=1, which checks OSV for known malicious packages during uv add and uv sync operations and terminates the sync before malicious code has a chance to run.</p><p class="paragraph" style="text-align:left;">💡 Love to see new security features in popular dev tools 🤘 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thephp.foundation/blog/2026/06/23/one-month-of-ecosystem-security-engineering?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">One Month of Ecosystem Security Engineering</a><br>The PHP Foundation&#39;s <a class="link" href="https://www.linkedin.com/in/volker-dusch/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Volker Dusch</a> details one month of ecosystem security engineering work, during which the team scanned over 300 of the most-downloaded Composer packages and nearly all major frameworks using AI models with extended Cyber capabilities for vulnerability discovery, triage, reproducer generation, impact analysis, and fix suggestions. The effort has produced nearly 100 publicly available fixes across the ecosystem so far, with one case where 200 repositories applied the same GitHub Actions fix via a central template.</p><p class="paragraph" style="text-align:left;">The infrastructure runs on <a class="link" href="https://github.com/alpha-omega-security/scrutineer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Scrutineer</a>, an open-source tool the team is developing with Alpha-Omega and ecosystem security engineers from other languages. Scrutineer runs Claude Code skills against open-source repos through a configurable scan pipeline that combines static analysis, model-backed audits, and maintainer identification, with findings landing in a structured database and a guided triage-to-disclosure workflow that can isolate each scan in an ephemeral Docker container. Dusch reports that maintainer report quality has gone up over the past months because maintainers now run their own coding agents to validate findings, though models still refuse to help with exploit work on complex vulnerabilities, and PHP core itself produces worse results than userland libraries because a language runtime is harder for agents to reason about.</p><p class="paragraph" style="text-align:left;">💡 Based on this post, it seems like this mass AI-scanning and patching effort has been well received by the PHP community, which is great. Perhaps because findings have already been reviewed + come with patches, and the effort feels like it’s coming from the community (vs some external party)? </p><p class="paragraph" style="text-align:left;"></p></div><div id="ai-security" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://role-confusion.github.io/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Prompt Injection as Role Confusion</a><br>Charles Ye, Jasmine Cui, and Dylan Hadfield-Menell detail their ICML 2026 paper on prompt injection as role confusion, <a class="link" href="https://github.com/role-confusion/prompt-injection-as-role-confusion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">with code on GitHub</a>. Prompt injection succeeds not because attackers find clever phrasings but because LLMs perceive roles through writing style rather than the structural tags meant to carry trust and authority. The researchers build linear probes that measure how strongly an LLM internally believes a token belongs to a given role, producing per-role metrics including CoTness and Userness. The probes show that reasoning-style text registers as the model&#39;s own thoughts even when explicitly wrapped in user tags, and user-style text registers as user instructions even when wrapped in tool tags.</p><p class="paragraph" style="text-align:left;">The researchers demonstrate this with an attack they call CoT Forgery, which injects fake reasoning into user prompts that mimics the LLM&#39;s own thinking style, raising attack success from near-zero to around 60% across frontier models. Standard prompt injection works the same way, and even simple role-spoofing like prepending <code>User:</code> to a malicious command in tool output increases success. Beyond direct attacks, they warn of subconscious steering, where the same flaw lets seemingly innocuous text shift model behavior without injection, like a shopping webpage with enthusiastic tone pushing an agent toward recommending a purchase.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.akamai.com/blog/security-research/new-mcp-specification-security-teams-must-prepare?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">The New MCP Specification: What Security Teams Must Prepare For</a><br>Akamai&#39;s <a class="link" href="https://www.linkedin.com/in/zavodchik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Maxim Zavodchik</a>, <a class="link" href="https://www.linkedin.com/in/segev-fogel/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Segev Fogel</a> and <a class="link" href="https://linkedin.com/in/gal-meiri?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Gal Meiri</a> describe the upcoming MCP 2026-07-28 spec, which turns MCP from a local integration tool into an enterprise-scale protocol with a stateless architecture, eliminating protocol-level session hijacking, unsolicited server prompts, and weak authentication by mandating OAuth 2.1 with PKCE.</p><p class="paragraph" style="text-align:left;">The new attack surfaces include cross-agent workflow hijacking through predictable tracking IDs or unverified state, client-controlled metadata manipulation via the unsigned <code>_meta</code> object, desync attacks through new MCP-specific headers, stored XSS through interactive MCP Apps, and denial-of-service through long-running asynchronous tasks. Security responsibility moves from the protocol layer to whoever builds on top of it, and the question for security teams is no longer whether the protocol itself is secure but whether the applications built on it correctly implement the new trust boundaries, state management, and execution models the spec introduces.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Introducing AWS Continuum: Security at machine speed</a><br>AWS’ <a class="link" href="https://www.linkedin.com/in/chetkapoor/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Chet Kapoor</a> announces Continuum for code vulnerabilities, an agentic security platform that uses multiple frontier models to manage the full vulnerability lifecycle through four phases: discovery (ingesting existing backlogs and scanning environments), prioritization (using business context like deployment status and reachability), validation (constructing working exploits in sandboxed environments to confirm findings), and mitigation/remediation (recommending network changes, policy updates, or code patches that are validated before deployment). </p><p class="paragraph" style="text-align:left;">Continuum operates in &quot;learn mode&quot; with human oversight initially, then can graduate to &quot;enforce mode&quot; for automated remediation based on defined risk profiles, and incorporates existing AWS Security Agent capabilities like pen testing, code scanning, and a new threat modeling feature that outputs STRIDE-format models from design docs or source code. Continuum reasons over both structured data (infrastructure, permissions, network topology) and unstructured data (documents, communications, business priorities) to provide context-aware security decisions.</p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/Oxzh_zP2TnY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Walking my dog at 3am</a></p></li><li><p class="paragraph" style="text-align:left;">Lyra - <a class="link" href="https://lyra.horse/blog/2026/06/reddit-spam-internals?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">A peek into Reddit&#39;s anti-spam internals</a></p></li><li><p class="paragraph" style="text-align:left;">Macworld - <a class="link" href="https://www.macworld.com/article/3175443/ios-27s-shortcuts-is-ai-at-its-best.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">iOS 27&#39;s Shortcuts is AI at its best</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intheweights.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">In the Weights</a> - Enter a name and see how much it appears in the training data of major LLMs based on its prominence in model weights.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://complexdiscovery.com/estonia-aims-to-be-first-to-give-ai-agents-official-digital-ids?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Estonia aims to be first to give AI agents official digital IDs</a></p></li><li><p class="paragraph" style="text-align:left;">WIRED - <a class="link" href="https://www.wired.com/story/ai-arms-race-china-us-cooperation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">I Met With China’s Top AI Experts. They’re Freaking Out, Too</a></p></li><li><p class="paragraph" style="text-align:left;">Tim Ferriss - <a class="link" href="https://tim.blog/2026/06/12/has-ai-already-killed-nonfiction?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Has AI Already Killed How-To Nonfiction? Sales Trends, My Personal Data, and What It Might Mean for the Future</a></p></li><li><p class="paragraph" style="text-align:left;">The Marginalian - <a class="link" href="https://www.themarginalian.org/2013/11/11/kurt-vonnegut-advice-to-children?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Kurt Vonnegut’s Life-Advice to His Children</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.raptitude.com/2026/06/do-things-youll-love-yourself-for?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Do Things You’ll Love Yourself For</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://pentesty.co/blog/novo-nordisk-ozempic-fulcrumsec-breach-2026?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">A Leaked GitHub Token Exposed the Exact Ozempic Formula</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://san.com/cc/peter-thiels-dialog-network-was-super-secret-a-data-leak-changed-that?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Peter Thiel’s ‘Dialog’ network was super-secret. A data leak changed that</a> - The leak exposed 113 prominent members through code embedded in the website, alongside detailed participant profiles with personal contacts, political leanings, and other private details. <span style="background-color:#ffffff;">The names tied to Dialog include Treasury Secretary Scott Bessent, Sarah Bond, the former president of Xbox at Microsoft, Sen. Ted Cruz, Joseph Gordon-Levitt, podcast host and author Sam Harris, and Bryan Johnson.</span></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=568688ac-4eef-4b74-95c5-cf109ca92c4a&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #334 - Thinkst&#39;s Package Proxy, OpenAI Daybreak, AI Agents &amp; Canaries</title>
  <description>OSS tool to prevent supply chain attacks without client-side firewalls, OpenAI announces new GPT-5.5-Cyber, Codex Security plugin updates, and more, can AI agents compromise an AWS cyber range without tripping canaries?</description>
  <link>https://tldrsec.com/p/tldr-sec-334</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-334</guid>
  <pubDate>Thu, 25 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-25T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🖼️ Meme</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Unfortunately work’s been too busy this week for me to lovingly write an artisanal, handcrafted intro combining snippets from my week, whimsy, and reflections on life and dare I say, what it means to be human. </p><p class="paragraph" style="text-align:left;">So for now, I share a meme:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/78008e26-24cf-485a-8c66-85b309c63211/image.png?t=1782364871"/><div class="image__source"><span class="image__source_text"><p>Shout-out <a class="link" href="https://www.rd.com/list/ai-memes/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Reader’s Digest</a></p></span></div></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Device code phishing in 2026: live demos, real kits, and where it&#39;s headed next </b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">18 kits, a 37x spike in detections, and every major AiTM vendor adding it to their platform. Device code phishing has gone from espionage-grade to criminal commodity. </p><p class="paragraph" style="text-align:left;">It’s easy to see why attackers are adopting it at scale: it bypasses passwords, MFA, and passkeys by targeting the authorization layer instead of the login flow. </p><p class="paragraph" style="text-align:left;">Join Push Security&#39;s VP of R&D Luke Jennings for live attacker-side demos and a breakdown of the kits and campaigns we&#39;re tracking in the wild.</p><h2 class="heading" style="text-align:center;"><b>👉</b><a class="link" href="https://hubs.li/Q04jNDyt0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow"><b> Register now</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Luke and the Push Security folks share great security research, this will be cool.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">From SQLi to RCE – Exploiting LangGraph’s Checkpointer</a><br>Checkpoint Research&#39;s <a class="link" href="https://www.linkedin.com/in/yardenporat1/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Yarden Porat</a> describes three vulnerabilities in LangGraph&#39;s persistence layer, two of which chain into remote code execution against self-hosted deployments. The chain starts with a SQL injection in the SQLite checkpointer where user-controlled filter input is inserted directly into the database query, letting attackers plant fake rows into the results. Because LangGraph deserializes whatever it reads back from the checkpoint table, the planted row triggers an unsafe msgpack deserialization that imports and calls attacker-controlled Python functions, giving them shell access on the server. A parallel SQL injection introduces the same flaw into the Redis checkpointer.</p><p class="paragraph" style="text-align:left;">The vulnerabilities require self-hosted LangGraph deployments where the application exposes <code>get_state_history()</code> with a user-controlled filter. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/06/17/session-switcher.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Introducing Session Switcher. Swap Burp Sessions with One Click!</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/savino-sisco/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Savino Sisco</a> shares <a class="link" href="https://github.com/doyensec/burp-session-switcher?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Session Switcher</a>, an open-source Burp Suite extension that streamlines authorization testing for privilege escalation and IDORs by letting testers save and swap HTTP sessions with one click from the request editor. Named sessions store a set of cookies and headers captured from any selected request, and a dropdown in the new Sessions tab swaps the active identity instantly. Sessions persist in the project file and work wherever there is an editable request editor, including Repeater and intercepted Proxy requests. </p><p class="paragraph" style="text-align:left;">Auto-update rules monitor Burp Proxy traffic and refresh stored sessions when new cookies or headers are detected, so long authorization tests do not break when tokens expire or cookies rotate mid-session. Rules range from simple header matches like <code>X-User: alice</code> to complex conditions like tracking JWTs by payload. Future plans include Auto Inject rules for transparent session switching and macro-based session refresh capabilities.</p><p class="paragraph" style="text-align:left;">💡 This looks awesome. I’d have loved to have this in my NCC Group consultin’, Burp wieldin’ days.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Adaptive Security: Your Attackers Are Using OSINT. So Should Your Phishing Tests</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Phishing attacks have increased +4,150% since ChatGPT&#39;s launch, and AI has made them faster, cheaper, and more personalized than ever. Adaptive&#39;s OSINT and AI spear phishing engine analyzes your organization&#39;s public digital footprint and uses it to generate personalized phishing lures targeting each employee. The same data attackers are already using, now working in your defense. Run automated phishing programs that stay current with evolving threats without manual campaign management.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#2C81E5;"><b>👉 </b></span><span style="color:#2C81E5;"><b><a class="link" href="https://www.adaptivesecurity.com/lp/nb/phishing-simulation?utm_source=sp_email&utm_medium=newsletter&utm_campaign=2026_05_NA_TLDR_sec_newsletter&utm_id=701Rd00000guu14IAA" target="_blank" rel="noopener noreferrer nofollow">See it in action </a></b></span><span style="color:#2C81E5;"><b>👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AI is definitely supercharging phishing, Google’s Threat Intelligence Group and others have shared <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">examples</a>. Good to be aware of the latest threats and test against them 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/05/25/cloudsectidbits-elbaph-alb.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Navigating Lax Load Balancers: When an Intersection Gets You Inside</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/francesco-lacerenza/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Francesco Lacerenza</a> and <a class="link" href="https://www.linkedin.com/in/ouadmoha/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Mohamed Ouad</a> dig into AWS Elastic Load Balancers (ALB) and the gap between how an ALB is configured and what an external request can actually reach. They examine<span style="background-color:#ffffff;"> misconfigurations that create unintended routing paths, identifying issues like CloudFront/WAF bypasses via direct ALB access, rule shadowing where lower-priority broad rules prevent restrictive authentication rules from firing, and IP gate bypasses when the same backend targets are reachable through alternate ALBs without source-ip restrictions.</span></p><p class="paragraph" style="text-align:left;">They’ve released <a class="link" href="https://github.com/doyensec/elbaph?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">ELBaph</a>, a Go CLI that maps ALBs, NLBs, listeners, rules, and targets into one routing model, runs targeted HTTP and HTTPS reachability probes, and reports each finding with its root cause, exploit path, and remediation. See also the corresponding Terraform <a class="link" href="https://github.com/doyensec/cloudsec-tidbits/tree/main/lab-elbaph?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">practice lab</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://permiso.io/blog/gcp-servicedata-officially-deprecated-actively-dangerous?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Mind the Gap: GCP serviceData in Logs Explorer vs. Exported Logs</a><br>Permiso Security&#39;s <a class="link" href="https://www.linkedin.com/in/artukshini/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Art Ukshini</a> describes an inconsistency in GCP&#39;s deprecated <code>serviceData</code> field where audit logs viewed in the native viewer arrive populated but the same logs exported to downstream analytics platforms arrive stripped of fields, causing critical detection fields like <code>policyDelta</code> to be stripped from high-value security events such as disabling audit logging across all services via <code>SetIamPolicy</code>. </p><p class="paragraph" style="text-align:left;">This creates silent detection failures where security rules appear functional but never fire on critical events, affecting both custom detections and Google Chronicle&#39;s community rules. Recommendation: validate telemetry end-to-end through the export pipeline, alert on stripped events as an anomaly signal, cross-reference the newer field for migrated services, and watch the documentation for changes against existing detection coverage.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://nesbitt.io/2026/05/04/package-manager-cwes.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Package Manager CWEs</a><br><a class="link" href="https://nesbitt.io/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Andrew Nesbitt</a> analyzed roughly two hundred public CVEs and security advisories and found twenty recurring vulnerability patterns across package managers. <span style="background-color:#ffffff;">On the client side, the most common issues include path traversal during archive extraction (often requiring multiple fixes for </span><code>../</code><span style="background-color:#ffffff;">, symlinks, and Windows paths), argument injection into VCS commands like </span><code>git clone</code><span style="background-color:#ffffff;">, integrity checks that fail open when signatures are missing, credentials leaked across registry redirects, dependency confusion from incorrect source prioritization, and unsafe YAML/XML deserialization in manifests. </span></p><p class="paragraph" style="text-align:left;"><span style="background-color:#ffffff;">Registry-side vulnerabilities concentrate on authorization bypasses allowing package takeover, account takeover via expired email domains and credential stuffing, stored XSS in rendered package pages, server-side RCE from the same parsing bugs that affect clients, and SSRF via repository URLs, </span>and IDOR on admin endpoints in multi-tenant self-hosted registries. Almost every tool in the survey has at least half of these bugs.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.thinkst.com/2026/06/introducing-package-proxy-supply-chain-safety-checks-without-client-side-software.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Introducing Package Proxy: supply-chain safety checks without client-side software</a><br>Thinkst Canary&#39;s <a class="link" href="https://www.linkedin.com/in/jacobtorrey/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Jacob Torrey</a> shares <a class="link" href="https://github.com/thinkst/package-proxy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Package Proxy</a>, an open-source Cloudflare Workers-based tool that intercepts package manager requests (npm, pip, uv, cargo) to enforce security policies before packages are installed, no client-side wrapper needed. Package managers use an index URL to fetch metadata, and that URL can be changed through configuration to point at Package Proxy instead of the upstream registry. The proxy sees every metadata request, infers which packages the client wants to install, runs the configured checks, and either returns a 404 to block the install or fetches and serves the package if it passes.</p><p class="paragraph" style="text-align:left;">Default checks include a minimum 10-day package age so backdoors get discovered before installation, upload mechanism regression detection on PyPI and npm that blocks packages uploaded differently than previous versions, allow and block lists, and an npm audit bypass for critical fixes. Per-package exceptions are managed via Wrangler CLI, and all installation attempts log to a D1 database for auditing. </p><p class="paragraph" style="text-align:left;">“<span style="background-color:#ffffff;">Internally we run a fork which enforces a stronger version of the allow list; we block </span><code>npm</code><span style="background-color:#ffffff;"> packages by default and developers have to request additions to the allow list.”</span></p><p class="paragraph" style="text-align:left;">💡 Neat approach, and awesome that Thinkst open sourced it 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://agentic.tracebit.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">AI Agents & Canaries</a><br>Tracebit benchmarked ten AI frontier models inside a controlled AWS cyber range to determine how fast they could compromise an environment and if they’d trip canaries along the way. Across 951 attack runs, AI achieved admin privilege escalation in 162 cases within an average time of 14 minutes across successful runs. Of those compromising runs, canaries provided advance warning before the attacker&#39;s first critical action in 95.9% of runs. </p><p class="paragraph" style="text-align:left;">Across attack paths, canaries are hit on average 8 minutes ahead of any critical action. In a surprise finding, simply telling models to expect deception reduced the number of accounts fully compromised (admin + persistence) from 20% to 3%.</p><p class="paragraph" style="text-align:left;">💡 Great visual layout of the results and stats, replay visualization, methodology description, etc. Nice write-up, excellent security research content marketing example 👌 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-salesforce?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Mapping out your unknown: A threat hunter’s guide to Salesforce</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/julie-a-sparks/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Julie Agnes Sparks</a> describes threat hunting queries for detecting attacker behavior in Salesforce environments, mapping detection opportunities across reconnaissance, initial access, credential access, and discovery phases to MITRE ATT&CK tactics. The queries hunt for malicious OAuth app approvals, compromised third-party integrations, and stolen SSO credentials, drawing on Event Log Files and Real-Time Event Monitoring. Concrete signals to watch for include Guest user account activity, failed MFA attempts using weak verification methods like SMS, email, and TOTP, OAuth authentication anomalies, calls to the LimitSnapshot API endpoint that probe usage thresholds, and broad SOQL queries counting sensitive objects like Account, Contact, and User tables that precede data exfiltration.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/daybreak-securing-the-world/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Daybreak: Tools for securing every organization in the world</a><br>OpenAI announced an expansion to Daybreak, an initiative to help secure the world’s software. Four main updates: an updated and better GPT-5.5-Cyber, an updated Codex Security plugin, a Patch the Planet initiative with Trail of Bits, and the new Daybreak Cyber Partner Program, enabling 20+ security vendors including Palo Alto Networks, CrowdStrike, and Wiz to integrate GPT-5.5 with Trusted Access for Cyber into their products. </p><p class="paragraph" style="text-align:left;">The Codex Security plugin now provides end-to-end workflows including threat modeling, reachability analysis, patch generation and validation, SARIF export, and integration with existing vulnerability management systems. OpenAI is collaborating with governments including the US, UK, Australia, Canada, France, Germany, Japan, and South Korea to provide Trusted Access for Cyber partnerships and protect critical infrastructure.</p><p class="paragraph" style="text-align:left;">💡 My first launch 🙌 I’m not gonna lie, it was super cool getting to be a part of the behind the scenes of making this happen. Lots of work from a ton of people. If you have specific asks for new features in the Codex Security plugin (or anything else we should be building), holla at ya boy 💌 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://joshuasaxe181906.substack.com/p/glm-52-not-mythos-is-the-real-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">GLM-5.2, not Mythos, is the real security emergency</a><br><a class="link" href="https://linkedin.com/in/joshsaxe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Joshua Saxe</a> argues that the open-weights model GLM-5.2, not restricted closed source frontier models, poses the real security threat because it enables attackers to run agentic operations privately on 8 H200s, without logging or guardrails. GLM-5.2&#39;s capabilities, matching GPT-5.5 and Opus 4.8 for code and terminal operations, will enable attackers to conduct semi-autonomous kill-chain execution, develop implants and C2 infrastructure, find zero-days, and run long-con scams, while defenders have been denied access to Mythos/GPT-5.5-Cyber, despite them running on monitored private servers. </p><p class="paragraph" style="text-align:left;">Joshua believes our focus should shift from restricting frontier model access to accelerating AI adoption among defenders and security vendors, as the open-weights genie is already out of the bottle and defenders need equivalent capabilities to pay down security debt and build detection-and-response innovations before attackers build out their own automation.</p><p class="paragraph" style="text-align:left;">“<span style="background-color:color(display-p3 1 1 1);">We can now expect a dark economy to emerge around serving open weights near frontier models via API, just as we have dark economies around malware, zero-day exploits, credential dumps, and initial access into victim networks.”</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://shad0wmazt3r.github.io/ai-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">The Agent Is Not the Scanner: Making AI Security Agents Better</a><br><a class="link" href="https://www.linkedin.com/in/pratyaksha-beri/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Pratyaksha Beri</a> ran 11 models through three configurations (no scaffolding, skills only, MCP tools enabled) on 20 vulnerability-finding tasks and found that whether scaffolding helps depends almost entirely on how capable the model already is. Weak models gained substantially from skills, while strong models regressed. Weak models need the structure skills provide, an explicit list of what to detect, what counts as evidence, and what shape the output needs to land in. Strong models already have those patterns internally, and the extra structure just costs them tokens they could have spent reasoning.</p><p class="paragraph" style="text-align:left;">Other takeaways: different models benefit from different scaffolds, separate recon, exploit reasoning and reporting as different models will perform better (and use cheap models on recon, frontier on exploit reasoning).</p><p class="paragraph" style="text-align:left;">💡 I always like an eval/benchmarking post. Intuitively you’d think skills and/or MCP tools would generally improve performance, but it depends on the model and task. In this case I will note though that the task seems to have just been examine a small code snippet for vulnerabilities, which is much different than navigating large, real world code bases. Also if the model can dynamically test its hypotheses that will also improve outcomes.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">OpenAI unveils its first custom chip, built by Broadcom</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/z7C0i?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Anthropic says Alibaba illicitly extracted Claude AI model capabilities</a></p></li><li><p class="paragraph" style="text-align:left;">Satya Nadella - <a class="link" href="https://x.com/satyanadella/status/2066182223213293753?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">A frontier without an ecosystem is not stable</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/w0vTF?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Get-a-Waymo: How a burglar used a robotaxi to flee the scene in a first-of-its kind S.F. case</a> - New #PeakBayArea example. “<span style="background-color:#ffffff;">The getaway car was parked just outside the Marina yoga studio...” </span>😂 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://coveillance.org/a-walking-tour-of-surveillance-infrastructure-in-seattle/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">A walking tour of surveillance infrastructure in Seattle</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://Ycombinator.FYI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Ycombinator.FYI</a> - Examples of “17 fraud & scandals, 41 exhibits filed, 5 copycats & grifts.”</p></li><li><p class="paragraph" style="text-align:left;">Fireship - <a class="link" href="https://www.youtube.com/watch?v=ML3q7Ok4hJg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">I read every major CS paper of the last 100 years...</a> - Nice overview of work by Turing, Claude Shannon, foundational AI papers, etc.</p></li><li><p class="paragraph" style="text-align:left;">Fireship - <a class="link" href="https://www.youtube.com/watch?v=Sntj4HmuykI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">SQLite is being rewritten in Rust</a></p></li><li><p class="paragraph" style="text-align:left;">CharactersWelcome - <a class="link" href="https://www.youtube.com/watch?v=dXKUgjYh7lo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">That Song In Every Musical That No One Likes</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/VU8N6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Walking Slower? Why Your Ears, Not Your Knees, Might Be the Problem</a> - Apple’s hearing study used real-world data from more than 57,000 iPhone users and made a connection between hearing loss, walking speed, and potential longevity implications.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.absurdlyoptimized.com/recipes/pancakes/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">The absurdly optimized pancake</a> - “A systematic investigation of acid-base neutralization, CO2 production kinetics, gluten inhibition, and the Maillard reaction as applied to a 125-gram flour batter, with an interactive stoichiometric calculator that adapts to whatever is in your refrigerator.“</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=9dc8329b-a2f4-4ca7-98a1-796ebd3fafe8&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #333 - Perplexity&#39;s Bumblebee, Evading Cloud Logging, AI Vuln Hunting Spec</title>
  <description>OSS tool to scan packages, agent configs, editors, and browser extensions for malware, tactics for evading cloud logging, a specification to generate your own custom agentic AI security scanning system</description>
  <link>https://tldrsec.com/p/tldr-sec-333</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-333</guid>
  <pubDate>Thu, 18 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-18T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🙏 Busy, Exciting, Busy</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Thanks so much to everyone who reached out last week! I received so many kind emails, LinkedIn comments, and texts, I was filled with joy. My heart grew at least 3 sizes 🥹</p><p class="paragraph" style="text-align:left;">Apologies if I haven’t responded yet, there are somehow even more things going on inside OpenAI than you’d expect, and I’ve been a bit buried.</p><p class="paragraph" style="text-align:left;">We’ve been sprinting on some things… that you might see soon 🤭</p><p class="paragraph" style="text-align:left;">Speaking of, I’m actually going to be doing a live session with some colleagues <b>next Thursday</b> about Daybreak, our vision for empowering defenders.</p><p class="paragraph" style="text-align:left;">We’ll discuss cyber models, early insights from working with leading teams, show how these capabilities fit into security workflows, and discuss where AI-assisted defense is headed next.</p><p class="paragraph" style="text-align:left;">We’ll likely cover new security product stuff we’re shipping, and even a live <b>demo</b> (I’m starting my sacrifices to the demo gods now 🙏).</p><p class="paragraph" style="text-align:center;">👉️<b> </b><a class="link" href="https://webinar.openai.com/register/daybreak-live-the-next-frontier-in-cyber-defense?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow"><b>Join live Thursday June 25, 1pm PDT</b></a><b> </b>👈️<b> </b></p><p class="paragraph" style="text-align:left;">Hope to see you there!</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Is Your Segmentation Real, or Just a Comfortable Illusion?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI-generated exploits don&#39;t need sophistication, just a gap you don&#39;t know exists. Target-specific attacks are generated in minutes, built to find what your tools can&#39;t see.</p><p class="paragraph" style="text-align:left;">runZero shatters the segmentation illusion. New attack path mapping and topology visualizations reveal how an attacker can move through your environment. Safely enumerate sub-assets hidden behind protocol gateways like Modbus, BACnet, and EtherNet/IP that other tools miss entirely.</p><p class="paragraph" style="text-align:left;">Every asset, every exposure, every attack path across IT, OT, IoT, cloud, and mobile. With runZero, defenders win by default. Even against AI.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.runzero.com/try/?utm_source=tldr-sec&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow"><b>Start your 21-day free trial </b></a><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">I’ve heard runZero is crazy good at mapping environments.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.janestreet.com/formal-methods-at-jane-street-index?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Formal methods and the future of programming</a><br>Jane Street’s <a class="link" href="https://x.com/yminsky?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Yaron Minsky</a> describes how they’re building a formal methods team after 25 years of skepticism, driven by the belief that agentic coding has fundamentally changed the cost-benefit calculus of formal verification. Yaron argues that AI agents both reduce the cost of formal methods (by making proof construction more accessible) and increase the benefits (by providing better verification for AI-generated code that tends toward &quot;slop&quot;, and by offering the universal guarantees that agents need for effective feedback during training and coding). </p><p class="paragraph" style="text-align:left;">“Our hope is to make formal methods as pervasively useful of a tool for building software as sophisticated type systems are for us today.”</p><p class="paragraph" style="text-align:left;">💡 Useful things to reflect on whenever there are meaningful tech changes, AI or otherwise: what used to be hard that is now easy? What used to be impossible that is now feasible? What used to be too costly or too slow that now could make sense? I’m actually pretty bullish on formal methods in the AI era. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.blog/security/making-secret-scanning-more-trustworthy-reducing-false-positives-at-scale?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Making secret scanning more trustworthy: Reducing false positives at scale</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/mwakaba/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Mariko Wakabayashi</a> details how the Agents Offense team helped GitHub adopt Microsoft’s Agentic Secret Finder&#39;s verification approach into its AI-powered secret scanning, cutting customer-confirmed false positives by 75%. Rather than feeding the model more data, the approach extracts focused, high-signal usage context such as whether a detected value is assigned to a variable and later passed into an API request, authentication header, database client, or cloud SDK call, as well as execution paths. Providing the right context lets the model separate real exposures from noise like UUIDs, test data, or placeholders without reducing detection coverage.</p><p class="paragraph" style="text-align:left;">💡 This work sounds neat, and <a class="link" href="https://github.blog/engineering/platform-security/finding-leaked-passwords-with-ai-how-we-built-copilot-secret-scanning/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">How we built Copilot secret scanning</a> shares a bit more details about GitHub’s approach, but I wish both were a bit more detailed. For an example I like, see Wiz’s post <a class="link" href="https://www.wiz.io/blog/small-language-model-for-secrets-detection-in-code?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">How We Fine-Tuned a Small Language Model for Secret Detection in Code</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Codex Discovered a Hidden HTTP/2 Bomb</a><br>Calif&#39;s <a class="link" href="https://www.linkedin.com/in/quangluongtm/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Quang Luong</a>, <a class="link" href="https://www.linkedin.com/in/jro-sg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Jun Rong</a> and Duc Phan used Codex to discover HTTP/2 Bomb, a remote denial of service affecting nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora in their default configurations. The attack chains two techniques that have been public since 2016. The first abuses HTTP/2&#39;s header compression, where a single saved header can be referenced thousands of times, and each one-byte reference forces the server to allocate a full header in memory. The second tells the server its receive buffer is full, then drips just enough updates to keep the connection from timing out so the server never frees anything.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">A single client on a 100Mbps home connection can pin 32GB of server memory in roughly 20 seconds against Apache and Envoy. A Shodan search found 880,000+ websites supporting HTTP/2 and running one of these servers, though many sit behind a CDN. Calif published PoCs and Docker labs at <a class="link" href="https://github.com/califio/publications/tree/main/MADBugs/http2-bomb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">califio/publications</a>.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Discover the Architecture of Stopping-Power</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Modern threats move faster than platforms built on delayed telemetry, API-derived state, and after-the-fact correlation can control. The next generation of cloud security will not be won or lost on how much risk it can describe. It will be won or lost on how effectively it can convert context into stopping power.</p><p class="paragraph" style="text-align:left;">In their landmark paper, Agentic Cloud Security Platforms: The Shift to Runtime Security, Software Analyst Cyber Research (SACR) demonstrates how the limits of CNAPP are architectural. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.paloaltonetworks.com/cortex/cloud/sacr-acsp-report?utm_source=tldrSEC&utm_medium=eNewsletter&utm_campaign=Cortex-Cloud&utm_content=sacr-agentic-cnapp" target="_blank" rel="noopener noreferrer nofollow"><b>Download this important read</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I do wonder where things are headed if we assume AI-powered attackers can pivot and move through a network faster. How will cloud tools adapt? 🤔 </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://dagrz.com/writing/aws-security/disrupting-aws-logging?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Disrupting AWS logging</a><br>(In 2016!) <a class="link" href="https://www.linkedin.com/in/danielgrzelak/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Daniel Grzelak</a> demonstrates multiple techniques for disrupting AWS CloudTrail logging after compromising an account, ranging from obvious methods like <code>delete-trail</code> and <code>stop-logging</code> to stealthier approaches. Key tactics include disabling multi-region logging with <code>update-trail --no-is-multi-region-trail --no-include-global-service-events</code> to operate freely in non-home regions while suppressing global IAM events, creating an immutable encryption-only KMS key via<code> create-key --bypass-policy-lockout-safety-check</code> so CloudTrail keeps writing logs that nobody can decrypt, redirecting logs to attacker-controlled S3 buckets, modifying bucket policies to block CloudTrail writes, and setting 1-day S3 lifecycle expirations to auto-delete files.</p><p class="paragraph" style="text-align:left;">You can also deploy an AWS Lambda function triggered by S3 object-create events to delete logs immediately on write, winning any race condition against SIEM ingestion while staying within Lambda&#39;s 1 million free monthly invocations to avoid detection through unusual billing patterns.</p><p class="paragraph" style="text-align:left;">💡 As they say, read Daniel’s posts to avoid being a cyber-patsy.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility</a><br>Palo Alto Networks&#39;s <a class="link" href="https://www.linkedin.com/in/yahavfestinger/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Yahav Festinger</a> describes seven attack techniques targeting AWS CloudTrail and Google Cloud Logging services, organized into defense evasion and continuous visibility (transferring logs to the attacker’s accounts, giving visibility into the victim’s environment). Defense evasion techniques include stopping logging, deleting the log storage destination, deleting the log router, impairing logging via an attacker-controlled encryption key, and log poisoning. Continuous visibility techniques include configuring a new log routing resource and log redirection. Attackers can exploit permissions like <code>cloudtrail:StopLogging</code>, <code>s3:DeleteBucket</code>, <code>logging.sinks.update</code>, and KMS key modifications to blind security tools, manipulate audit trails, or exfiltrate logs to attacker-controlled destinations for passive reconnaissance.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Festinger recommends restricting access to logging service APIs to highly privileged users, using immutable log repositories like AWS&#39;s 90-day CloudTrail Event History and Google Cloud&#39;s _Required log bucket, and implementing bucket policies that prevent non-admin modifications. For detection, CloudTrail log file integrity validation flags log poisoning but is off by default for trails created via API or CLI.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Perplexity is open sourcing Bumblebee</a><br>Perplexity has released <a class="link" href="https://github.com/perplexityai/bumblebee?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Bumblebee</a>, a read-only scanner that checks developer machines for risky packages, extensions, and AI tool configurations during supply-chain incidents by parsing metadata files directly without executing code. The tool scans four surfaces: language package managers (npm, pnpm, PyPI, Go modules, etc.), AI agent configs (MCP), editor extensions (VS Code family), and browser extensions (Chromium and Firefox). Bumblebee supports three scan profiles: baseline for routine scans, project for targeted repo checks, and deep for active incident response. </p><p class="paragraph" style="text-align:left;">Bumblebee avoids triggering malicious install scripts by never invoking package managers or running lifecycle hooks, instead reading lockfiles, manifests, and installed package metadata directly. Perplexity integrates Bumblebee into their workflow where Perplexity Computer drafts catalog updates as GitHub PRs after threat signals emerge, humans review them, and Bumblebee then scans endpoints with the updated catalog to identify exposed systems.</p><p class="paragraph" style="text-align:left;">💡 Smart approach, I like this a lot: a single tool to inventory all of these developer attack surfaces, gathers the data in a way that avoids accidental code execution from malicious packages, and integrates with a continuously updating threat catalog 👌 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/12bb6243-1927-412b-a0b6-ade362511b07/image.png?t=1781761187"/></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Securing CI/CD in an agentic world: Claude Code Github action case</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/dor-edry/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Dor Edry</a> and <a class="link" href="https://www.linkedin.com/in/amit-eliahu/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Amit Eliahu</a> demonstrate how Anthropic&#39;s Claude Code GitHub Action could leak CI/CD secrets when processing untrusted GitHub content like issues, pull requests, and comments. While the <code>Bash</code> tool ran inside a Bubblewrap sandbox with environment variables scrubbed, the <code>Read</code> tool bypassed that isolation and could read <code>/proc/self/environ</code> directly, exposing <code>ANTHROPIC_API_KEY</code> and other runner credentials.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">To confirm exploitability, they hid a prompt injection inside an HTML comment that instructed the agent to read sensitive files and truncate the first seven characters of any API key found, bypassing Claude&#39;s safety filters and GitHub&#39;s Secret Scanner. From there, exfiltration was possible via WebFetch, Bash, or issue comments. Anthropic patched the issue in Claude Code 2.1.128 by blocking access to sensitive <code>/proc</code> files.</p></div><p class="paragraph" style="text-align:left;">💡 Making agents useful and secure is tough, lots of sharp edges. Bypassing safety filters/secret scanners via truncating the secret prefix + evading the sandbox is clever. See also the “Research methodology” section at the bottom which is neat: first they used an AI model to do automated, black-box research, then fed the AI model the target Actions codebase and the obfuscated Claude SDK for a human/AI white box collaborative security audit.</p><p class="paragraph" style="text-align:left;"></p><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/grepstrength/malsnitch?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">grepstrength/malsnitch</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/kelvin-winborne/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Kevin Winborne</a> <span style="background-color:#ffffff;">that scans malware artifacts like string dumps, FLOSS output, or Binary Ninja exports to extract embedded secrets such as C2 credentials, crypto keys, API tokens (GitHub PATs, AWS, Stripe, Slack), exfiltration channel credentials (e.g. Discord webhooks, Telegram bot tokens), and hardcoded SMTP/FTP/HTTP credentials.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Cisco-Talos/EvidenceForge?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Cisco-Talos/EvidenceForge</a><br>By Cisco Talos: An open-source tool that generates realistic, multi-format security logs for threat hunting training by solving the core problem of synthetic data: cross-source consistency. EvidenceForge uses a canonical SecurityEvent model to emit 20+ correlated log formats (Windows Security, Sysmon, Zeek, eCAR EDR/XDR, syslog, bash history, Snort, web access, and proxy logs) from a single source of truth, ensuring LogonIDs, PIDs, timestamps, and Zeek UIDs match across all outputs. A causal expansion engine adds prerequisite events with realistic timing, like DNS queries before connections and Kerberos TGT/TGS before domain logons, and a Hawkes process models user activity including Monday login storms and Friday early departures. Network visibility modeling further determines what each sensor can realistically observe.</p><p class="paragraph" style="text-align:left;">Scenarios are authored through Claude Code or Codex agent skills that draw on MITRE ATT&CK, while log generation itself is fully deterministic with no LLM calls. A 4-pillar evaluation framework then scores the output across parseability, plausibility, causality, and timing.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/06/16/mythic-embarking-on-the-open-seas-containerized-payload-delivery-for-kubernetes-assessments?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Mythic Embarking on the Open Seas: Containerized Payload Delivery for Kubernetes Assessments</a><br>SpecterOps&#39; <a class="link" href="https://www.linkedin.com/in/alex-rodriguez-3a46bb84/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Alex Rodriguez</a> introduces two new Mythic C2 extensions, <a class="link" href="https://github.com/elreydetoda/container_wrapper?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">container_wrapper</a> and <a class="link" href="https://github.com/elreydetoda/container_registry?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">container_registry</a>, that streamline containerized payload delivery for Kubernetes assessments by wrapping Mythic payloads into OCI-compatible containers and hosting them in self-managed registries. The <code>container_wrapper</code> uses <code>Buildah</code> to package payloads into container images via Mythic&#39;s web UI, while <code>container_registry</code> uses <code>skopeo</code> to push these images to a distribution-based registry deployed behind an HTTPS redirector. This approach lets operators hand clients a simple Kubernetes manifest to deploy in their own clusters, eliminating manual Docker CLI workflows and supporting container-centric penetration testing in environments where worker nodes have internet egress and no restrictive image policies are enforced.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/05/28/dont-jump-the-turnstile-lessons-from-the-field?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Don’t Jump the Turnstile: Lessons from the Field</a><br>SpecterOps&#39;s <a class="link" href="https://www.linkedin.com/in/zacharydstein/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Zach Stein</a> describes how he beat email phishing sandboxes with Cloudflare Turnstile on a red team engagement, after the same sandbox had defeated every standard evasion he reached for. He first used the <a class="link" href="https://github.com/t94j0/satellite?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Satellite</a> framework to block Linux user agents, but the sandbox swapped to a Windows user agent. He then added a filter page that only redirected after mouse movement, but the sandbox crawled the redirect URL straight out of the HTML. So he implemented Turnstile as a CAPTCHA-like verification layer that hides the redirect URL from the page source, keeping sandboxes from crawling to the payload while looking legitimate to a real user.</p><p class="paragraph" style="text-align:left;">Zach published the build as <a class="link" href="https://github.com/Synzack/Turnstyle?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Turnstyle</a>, a Flask WSGI app fronted by Apache, mod_wsgi, and a Certbot certificate, with an Ansible deployment script in the repo.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.google/security/android-fake-call-detection/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">How Android helps keep you safe from impersonation scams with fake call detection</a> - New feature <span style="background-color:#ffffff;">helps protect you from scammers using AI deepfakes to impersonate your contacts. Shout-out to my friend </span><span style="background-color:#ffffff;"><a class="link" href="https://x.com/RachelTobac/status/2061876555995845079?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Rachel Tobac</a></span><span style="background-color:#ffffff;"> for helping inspire the work </span>🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nudgesecurity.com/features/ai-agent-discovery?utm_medium=sponsored&utm_source=tldr&utm_content=newsletter&utm_campaign=ai_security&utm_term=browser-based-agent-discovery" target="_blank" rel="noopener noreferrer nofollow"><b>[NEW] Discover shadow AI agents via the browser</b></a><b> </b>-<b> </b>Most AI agent discovery tools rely on APIs. The problem? A lot of agentic AI platforms don’t expose agent details via an API. Nudge Security just closed this blindspot with browser-based AI agent discovery.*</p></li><li><p class="paragraph" style="text-align:left;">r/ollama - <a class="link" href="https://web.archive.org/web/20260412230759/https://www.reddit.com/r/ollama/comments/1sff7i0/30_days_of_an_llm_honeypot/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">30 Days of an LLM Honeypot</a></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/visa/visa-vulnerability-agentic-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">visa/visa-vulnerability-agentic-harness</a><br>By Visa: An open-source agentic SAST pipeline that uses Claude, OpenAI, or any combination of frontier models for autonomous vulnerability discovery. It prioritizes triage speed over raw discovery volume, with Mean Time to Adapt as its primary metric. Threat modeling focuses the attack surface, multi-agent deterministic voting reduces false positives, and structured triage artifacts compress the path to actionable findings.</p><p class="paragraph" style="text-align:left;">The pipeline runs nine stages, beginning with attack surface mapping and STRIDE/OWASP threat modeling, then specialized research lenses for language, crypto, logic bugs, access control, batch/ETL, and IaC, followed by adversarial verification and exploit chain construction. Output includes Markdown reports and SARIF 2.1.0 artifacts.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/CiscoDevNet/foundry-security-spec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">CiscoDevNet/foundry-security-spec</a><br>Cisco has released the Foundry Security Spec, an open specification for building agentic AI security evaluation systems, distilling production lessons into 130 functional requirements across eight core agent roles (Indexer, Cartographer, Detector, Triager, Validator, Reporter, Coverage Guide, and Orchestrator) plus five optional extensions (Deep-Tester, Variant-Hunter, Attack-Mapper, Remediator, Self-Improver).</p><p class="paragraph" style="text-align:left;">The spec is deliberately infrastructure-agnostic with explicit <code>[NEEDS CLARIFICATION]</code> markers for organization-specific decisions, designed to be consumed via <code>spec-kit</code>&#39;s clarify-specify-plan-implement workflow rather than shipped as runnable code. Foundry implements a detection-to-prevention flywheel where exploratory agents hunt alongside CodeGuard rule sweeps, recording rule gaps that get generalized back into the corpus, so each evaluation improves both detection across all future targets and prevention in developers&#39; LLM coding assistants. See also the <a class="link" href="https://blogs.cisco.com/ai/announcing-foundry-security-spec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">companion blog post</a> by <a class="link" href="https://linkedin.com/in/santosomar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Omar Santos</a>.</p><p class="paragraph" style="text-align:left;">💡 Very cool project idea: a specification for building your own AI-powered code scanner. You customize the spec with your environment, and then it builds according to that. It makes me think of some SciFi show where you plug in your requirements, and then it materializes food or whatever you’re imagining. “Replicators” in Star Trek.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ea7a91a6-4e38-4aad-9bb1-d4acbe88fcb4/Screenshot_2026-06-17_at_11.05.32_PM.png?t=1781762778"/></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">Joshua Saxe - <a class="link" href="https://joshuasaxe181906.substack.com/p/banning-mythos-represents-a-basic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Banning Mythos represents a basic misunderstanding of AI cybersecurity</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/DavidSacks/status/2065853007619588171?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">David Sacks on the Fable ban</a></p></li><li><p class="paragraph" style="text-align:left;">Katie Moussouris - <a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">The Fable 5 Export Controls Harm US Cyber Defense</a></p></li><li><p class="paragraph" style="text-align:left;">Hank Green - <a class="link" href="https://www.youtube.com/watch?v=AcjnLc4TH4M&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">The Riskiest Moment of the AI Bubble</a></p></li><li><p class="paragraph" style="text-align:left;">Bloomberg - <a class="link" href="https://www.youtube.com/watch?v=WZ7mmTrSgxI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Ray Dalio on the bond market, a weaker dollar driving gold demand, and AI bubble concerns</a></p></li><li><p class="paragraph" style="text-align:left;">Bloomberg - <a class="link" href="https://www.youtube.com/watch?v=v1wZwxY3CMg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Inside Anthropic, the $965 Billion AI Juggernaut</a> - Neat profile of Dario and Daniela Amodei, with a little Boris.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Music</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=sy-A-wyzj7c&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Lea Salonga&#39;s Audition for Miss Saigon</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/9u_xn03CBEE?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Row Row Row Your Boat but in different keys at the same time</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=jxaksSr6uco&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">&quot;Go the Distance&quot; - Broadway&#39;s Leading Men Concert</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=yDYlVyMBZiM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Colors of the Wind - Live Orchestra | Pocahontas</a></p></li><li><p class="paragraph" style="text-align:left;">Charles Cornell - <a class="link" href="https://www.youtube.com/watch?v=bUW34jgrCf4&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Phil Collins Made EVERY Parent Sob With 1 Key Change | You&#39;ll Be In My Heart</a> - My dad loved Phil Collins, I remember watching Tarzan with him when I was young 🥹 I burned a few of the best songs from the soundtrack onto a CD when I was in school, and we’d listen to it in the car when we were driving somewhere together, like my karate practice. I could see this song hitting very different as a parent.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.midjourney.com/medical/blogpost?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Midjourney Medical</a> - Holy cow, the image generation site is getting into healthcare, and planning to build a better body scanner, and spa in SF 🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/W0wpON1jDRc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">When Pikachu gave the most epic speech in Pokemon history</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/eJ1aDGB48sM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">A day in the life of a personality-maxxer</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/2FTavzWhtXg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Throwback NFL commercials are the best</a></p></li><li><p class="paragraph" style="text-align:left;">Jon Oliver - <a class="link" href="https://www.youtube.com/shorts/d3y7aLApJkc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Moderator: 1 | Politician: 0</a></p></li><li><p class="paragraph" style="text-align:left;">Mark Manson - <a class="link" href="https://www.youtube.com/watch?v=wwJ1mRCWNKo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">20 Years of Therapy Summarized in 13 Minutes</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/OWm7JQDgzxA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Trying to understand investing and stock price</a> 😂 </p></li><li><p class="paragraph" style="text-align:left;">Leila Hormozi - <a class="link" href="https://www.youtube.com/watch?v=GRT-HGGYQeQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Do This & Watch How Fast People Stop Disrespecting You</a></p></li><li><p class="paragraph" style="text-align:left;">Sygnia - <a class="link" href="https://www.sygnia.co/blog/operation-highland-velvet-ant/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=nl14OmXPDUA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">What Dreamworks Understands About Evil That Disney Doesn&#39;t</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=5d12f4ff-ae83-43e3-a196-fcdb030ce3b1&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #332 - I&#39;ve Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security</title>
  <description>Why I joined OpenAI to lead Cyber efforts, playlist of the latest cloud security talks, AWS&#39; supply chain best practices</description>
  <link>https://tldrsec.com/p/tldr-sec-332</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-332</guid>
  <pubDate>Thu, 11 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-11T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤔 New Job, Who Dis?</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>TL;DR</b>: I’ve joined <b>OpenAI</b> to lead their Cyber efforts.</p><p class="paragraph" style="text-align:left;">I’m joined by <a class="link" href="https://www.linkedin.com/in/michaeleugeneaiello/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Mike Aiello</a>, an awesome security executive and human. Mike was previously CTO at Secureworks, led product for Google Cloud Security from 0 → $B’s in revenue, and CISO at Goldman Sachs.</p><p class="paragraph" style="text-align:left;">I was going to write a post describing all the details about joining, my thought process, etc. but it turns out there’s a lot to do at OpenAI and I’ve gotten very busy 😅 The post is started but not finished, will share when I can.</p><p class="paragraph" style="text-align:left;">So here’s the short version.</p><p class="paragraph" style="text-align:left;"><b>Why</b><br>I was very happy at Semgrep and wasn’t looking for new opportunities, but when an OpenAI recruiter reached out, it seemed like a once in a lifetime company and opportunity that I couldn’t pass by.</p><p class="paragraph" style="text-align:left;">During the interview process, when I spoke with my potential colleagues, I was impressed by how they were incredibly smart and kind, and genuinely, earnestly, cared about making a positive impact on the world. Several people, without me bringing it up, expressed to me that as models get better, they feel a moral responsibility to do what they can to secure the world’s software.</p><p class="paragraph" style="text-align:left;">And now from the inside, I can see that the sentiment was genuine, and not a facade (you always wonder as an outsider). OpenAI has easily already spent millions securing open source and critical infrastructure that they haven’t yet claimed PR cred for doing.</p><p class="paragraph" style="text-align:left;">I’ve long talked about the power of secure by design and eliminating vulnerability <i>classes</i>. Being at OpenAI makes that feel tractable in a way it never has before. I’m optimistic we, the security community, can meaningfully raise the world’s security bar over the next few years. Seriously.</p><p class="paragraph" style="text-align:left;">Lastly, how I think about the decision is also well expressed by my friend <a class="link" href="https://www.linkedin.com/in/ramimac/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>, who, like with many things, annoyingly wrote a better version of what I would write in his post on <a class="link" href="https://ramimac.me/joining-wiz?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">joining Wiz</a>. Similarly, I hope to “<i>work for the security industry, at OpenAI.</i>”</p><p class="paragraph" style="text-align:left;">I shared a <a class="link" href="https://www.linkedin.com/posts/clintgibler_career-update-ive-joined-openai-to-lead-activity-7470579206180237312-Uf45?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">LinkedIn post</a> with a bit more details, feel free to say hi or share thoughts there 👋</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> <i>tl;dr sec</i> will continue, don’t worry. Also, I will continue to include high quality content from Anthropic, that is also unchanged. More on that below.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>State of SDLC Report 2026</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">The 2026 SDLC Security Report analyzed real-world development environments, codebases, and SDLC infrastructure to understand how risk is evolving and how software is built and shipped.</p><p class="paragraph" style="text-align:left;">The TL;DR: Risk isn’t primarily driven by rare vulnerabilities. It scales through reuse, permissions, and automation across the SDLC.</p><p class="paragraph" style="text-align:left;">The report explores:</p><ul><li><p class="paragraph" style="text-align:left;">AI copilots and developer tooling risk</p></li><li><p class="paragraph" style="text-align:left;">Dependency concentration and supply chain exposure</p></li><li><p class="paragraph" style="text-align:left;">Secret leakage trends</p></li><li><p class="paragraph" style="text-align:left;">CI/CD and GitHub Actions attack paths</p></li></ul><p class="paragraph" style="text-align:left;">Learn how SDLC risk is reshaping application security.</p><h2 class="heading" style="text-align:center;"><b>👉</b><a class="link" href="https://www.wiz.io/reports/sdlc-security-report-2026?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY27Q2_INB_FORM_State-of-SDLC-Security-2026&sfcid=701Vh00000aiz35IAA&utm_term=FY27Q2-tldrsec-nl-June&utm_content=State-of-SDLC-2026" target="_blank" rel="noopener noreferrer nofollow"><b> Get the State of SDLC Report</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Hm interesting, neat to see the SDLC is evolving and how it’s affecting AppSec 🤔 I like the stats and figures.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.ammaraskar.com/github-token-stealing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">1-Click GitHub Token Stealing via a VSCode Bug</a><br><a class="link" href="https://github.com/ammaraskar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Ammar Askar</a> describes a bug in which clicking a <a class="link" href="https://github.dev?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">github.dev</a> link could steal a GitHub token with read/write access to all your private repos, by chaining a Jupyter notebook payload that exploits VS Code webview&#39;s <code>did-keydown</code> event forwarding to install a malicious extension. Neat write-up!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/how-we-cut-semgreps-taint-analysis-time-by-75-percent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">How We Cut Semgrep’s Taint Analysis Time by 75%</a><br>Semgrep&#39;s <a class="link" href="https://www.linkedin.com/in/austin-theriault-1648b2168/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Austin Theriault</a> walks through how the taint analysis engine was redesigned to run once instead of twice, cutting scan times by up to 75%. Taint analysis is used for vulnerabilities like SQL injection by tracking user input as it flows through code from sources to sinks, with propagators that carry the taint forward and sanitizers that clean it. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Semgrep&#39;s original 2023 architecture computed those configs during interfile analysis, then discarded them and recomputed during intrafile analysis, a design forced by OCaml&#39;s parallelism limitations before 5.0 that would have ballooned memory if all the state were kept in flight at once. Refactoring to merge both passes unlocked parallelization via OCaml multicore and reduced P95 scan times from 10 minutes to 7:30, with some large repositories seeing 3x+ improvements.</p></div><p class="paragraph" style="text-align:left;">See also: <a class="link" href="https://semgrep.dev/blog/2026/making-semgrep-rip-how-ripgrep-inspired-us-to-shave-hours-off-some-scans/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">How Ripgrep inspired us to shave hours off (some) scans</a> by <a class="link" href="https://www.linkedin.com/in/kettle-ben/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Ben Kettle</a>.</p><p class="paragraph" style="text-align:left;">💡 One fun thing about working at Semgrep is you realize how much hard engineering goes into building static analysis tools. Very cool work, and fun to nerd out with the program analysis team, who are statistically likely to be some combination of a) French, b) have PhDs, or c) be from CMU.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Key questions to ask any AI vendor</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Vendors are claiming autonomy - but most are still requiring significant human oversight. And most security teams don&#39;t yet have a clear framework to evaluate the difference.</span></p><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Join Sublime Security and Georgian on June 24 for a practical session on evaluating security AI. You&#39;ll leave with a clear autonomy framework, a trust-based evaluation path, and key questions to ask any AI vendor - including what good answers actually sound like.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#222222;"><b>👉 </b></span><a class="link" href="https://sublime.security/events/trust-then-autonomy-a-new-framework-for-evaluating-agentic-ai-in-security/?utm_source=smartbrief&utm_medium=third-party&utm_campaign=webinar" target="_blank" rel="noopener noreferrer nofollow"><b>Register now</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Honestly, it is super useful to know the right pointed questions to ask vendors, as well as having a feel for what “good” and rigorous evals look like in practice.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/playlist?list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">fwd:cloudsec North America 2026</a><br>The premier cloud security conference just uploaded the talks from their most recent event. Highly recommend. Many of the talks look great, and see the blog version of some below. Some additional talks I’m linking here so I can come back to them:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=7WdSOGJ7qjk&list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&index=10&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">In git we trust: Defending Lovable projects from malicious code attacks at scale</a> by <a class="link" href="https://www.linkedin.com/in/hallbergmarcus/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Marcus Hallberg</a> & <a class="link" href="https://www.linkedin.com/in/sckelemen/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Samuel Kelemen</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=cBq-DRNNi8A&list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&index=37&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF</a> by <a class="link" href="https://www.linkedin.com/in/shayberkovich/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Shay Berkovich</a>.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">HazyBeacon and AWS Lambda Function URL Abuse</a><br>Qualys&#39; <a class="link" href="https://www.linkedin.com/in/aniket-harne-547339238/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Aniket Harne</a> breaks down HazyBeacon, a campaign originally documented by Palo Alto Unit 42, where attackers used stolen IAM credentials to deploy AWS Lambda functions with <code>AuthType: NONE</code> Function URLs as command and control relays, making malware traffic indistinguishable from ordinary HTTPS calls to the <code>lambda-url.&lt;region&gt;.on.aws</code> domain. The chain starts with credentials harvested from public GitHub repos or developer phishing, validated through reconnaissance calls like <code>aws sts get-caller-identity</code>, then used to deploy a Lambda function under a benign name in an unused region whose public Function URL proxies traffic between infected endpoints and the attacker&#39;s real backend. The relay sits inside a separate compromised AWS account, which leaves the malware victim and the AWS account holder as two unrelated victims, often unaware they&#39;re connected until the bill or the abuse notice arrives.</p><p class="paragraph" style="text-align:left;">Recommended mitigations: A Service Control Policy blocking <code>AuthType: NONE</code> Function URLs unless explicitly tagged, global CloudTrail logging, enabling VPC flow logs, and more.</p><p class="paragraph" style="text-align:left;">💡 Honestly, pretty clever use of Lambda Function URLs.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://astrix.security/learn/blog/subjugation-hijacking-cloud-identities-by-recycling-namespaces-in-global-oidc-issuers?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers</a><br>Astrix Security&#39;s <a class="link" href="https://www.linkedin.com/in/reverser/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Tal Skverer</a> describes Sub:jugation, a vulnerability class affecting GitHub Actions, GitLab CI, and Terraform Cloud where the global OIDC issuer model lets attackers reclaim deleted repository namespaces and mint JWTs with subject claims that match existing cloud IAM role trust policies. Any cloud role still trusting an orphaned sub claim hands over short lived AWS, Azure, or GCP credentials to whoever recreates the namespace. Astrix calls these forgotten roles Phantom Cloud Identities, and found that 14% of AWS identities and 24% of Azure identities trusting GitHub&#39;s global issuer point at namespaces that are no longer registered, with roughly 8 becoming exploitable each month through publicly available data alone.</p><p class="paragraph" style="text-align:left;">GitHub has shipped the complete fix, adding random identifiers to sub claims so reclaimed namespaces can&#39;t mint matching tokens, while GitLab and Terraform have rolled out interim mitigations with full OIDC subject solutions still pending. Until those land, organizations need to audit every cloud identity trusting <code>token.actions.githubusercontent.com</code>, <code>gitlab.com</code>, or <code>app.terraform.io</code>, confirm the referenced namespace is still theirs, and either reclaim it or decommission the role outright.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/well-architected-best-practices-for-software-supply-chain-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Well-architected best practices for software supply chain security</a><br>AWS&#39;s <a class="link" href="https://www.linkedin.com/in/tschiavone/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Trevor Schiavone</a> and <a class="link" href="https://www.linkedin.com/in/desiree-brunner/?locale=en&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Desiree Brunner</a> walk through defense in depth controls for npm supply chain attacks. <span style="background-color:#ffffff;">Key mitigations include: replacing long-lived credentials with temporary ones via AWS CLI login, IAM Identity Center, or OIDC federation; implementing artifact signing with AWS Signer to cryptographically verify packages before production deployment; centralizing dependency management with AWS CodeArtifact&#39;s package group configuration to block typosquatting; and using Amazon Inspector&#39;s behavioral analysis to detect zero-day malicious packages.</span></p><p class="paragraph" style="text-align:left;"><span style="background-color:#ffffff;">Also: require MFA on maintainer accounts and multiple approvers, analyze CloudTrail logs for indicators of compromise, and leverage Software Bills of Materials to quickly assess blast radius during incidents.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does</a><br><a class="link" href="https://www.linkedin.com/in/guillaumeross/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Guillaume Ross</a> shows how to detect and prevent credential theft from developer workstations by combining <a class="link" href="https://github.com/boostsecurityio/bagel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">bagel</a>, an open source secret scanner, with Fleet, an MDM platform that uses osquery for telemetry, and an IdP conditional access policy. Bagel runs on a schedule through a LaunchAgent to find cleartext secrets in developers&#39; home directories, Fleet reads the JSON output via its <code>parse_json</code> osquery table to evaluate it against a policy, and an IdP blocks SSO on non-compliant workstations until the secrets are remediated.</p><p class="paragraph" style="text-align:left;">Guillaume ships the integration as <a class="link" href="https://github.com/GuillaumeRoss/fleebag?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Fleebag</a>, a proof of concept repo with macOS installation packages for bagel, Fleet queries for findings, a policy query that passes only when scans are fresh and clean, and an example profile to grant bagel full disk access.</p><p class="paragraph" style="text-align:left;"></p></div><div id="ai-security" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/encrypted/status/2058658244328124562?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Cursor bypassing pnpm min release age settings</a> 😅 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/claude-fable-5-mythos-5?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Claude Fable 5 and Claude Mythos 5</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/06/10/cybersecurity-researchers-arent-happy-about-the-guardrails-on-anthropics-fable/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity researchers aren’t happy about the guardrails on Anthropic’s Fable</a> - Preventing model misuse is hard 🙃 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Introducing the Agent Governance Toolkit: Open-source runtime security for AI agents</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/imransiddique1986/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Imran Siddique</a> released the <a class="link" href="https://github.com/microsoft/agent-governance-toolkit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Agent Governance Toolkit</a>, an open source framework of seven packages that aims to address all 10 OWASP Agentic AI Top 10 risks by porting operating system, service mesh, and site reliability patterns to autonomous AI agents. The packages run across Python, TypeScript, Rust, Go, and .NET, and the toolkit plugs into each framework&#39;s native extension points across LangChain, CrewAI, LangGraph, LlamaIndex, OpenAI Agents SDK, and more.</p><p class="paragraph" style="text-align:left;">The toolkit:<i> Agent OS </i>as the stateless policy engine (supports YAML, OPA Rego, and Cedar), <i>Agent Mesh</i> for cryptographic identity, <i>Agent Runtime</i> for sandboxing execution inspired by CPU privilege levels with an emergency kill switch, <i>Agent SRE</i> for applying service level objectives and circuit breakers, and the final three handling compliance, plugin lifecycle management, and reinforcement learning training governance. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://clearbluejar.github.io/posts/system-over-model-tested-mythos-freebsd-local-openweight?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">System Over Model, Tested: Reproducing Mythos&#39;s FreeBSD Find on Local Open-Weight Models</a><br><a class="link" href="https://www.linkedin.com/in/john-mcintosh-613ba2350/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">John McIntosh</a> reproduces Anthropic&#39;s Mythos discovery of CVE-2026-4747, an RCE in FreeBSD&#39;s RPCSEC_GSS authentication, using AISLE&#39;s nano-analyzer pipeline on two local open-weight models (gpt-oss-20b and gemma-4-31b-it). The models could find the bug, but the pipeline graduated 30 false positives that buried the real CVE. Rather than swap to a stronger model, John added one extra reachability filter stage using the same model weights that traces each finding back to an entry point, greps for callers, and checks whether the cited length is really controlled by the attacker or just set by the kernel, cutting false positives from 30 to 5 while keeping the real CVE valid. The <a class="link" href="https://github.com/clearseclabs/system-over-model-gemma?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">full experiment is on GitHub</a>.</p><p class="paragraph" style="text-align:left;">💡 Here’s how I see it: the foundation model labs try to convince you that “all you need is the model” and security vendors (or individuals) argue “it’s all the scaffolding.” Ultimately, I believe the truth is: the model, the prompt(s)/Skills, scaffolding/architecture, and how much you’re willing to spend <i>all matter</i>. Improving each gets overall better performance. Improving the model can get you the same or better results with removed (or less) scaffolding, and improved scaffolding on top of better models will yield even better results (more true positives, fewer false positives/negatives). </p><p class="paragraph" style="text-align:left;">At the end of the day, it all distills down, like most things in security, to: how much risk reduction are you getting at what price? My $0.02 at least.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://red.anthropic.com/2026/attack-navigator/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator</a><br>Anthropic’s <a class="link" href="https://www.linkedin.com/in/kyla-g/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Kyla Guru</a>, <a class="link" href="https://www.linkedin.com/in/alex-moix/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Alex Moix</a>, and <a class="link" href="https://www.linkedin.com/in/jacob-klein-4286a226/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Jacob Klein</a> analyzed 832 banned accounts that misused Claude for cyber operations over one year, mapping 13,873 malicious actions across 482 MITRE ATT&CK techniques and developing the AI Risk Enablement Score (ARiES) to assess threat levels. They found the highest-risk actors weren’t distinguished by technical sophistication or number of techniques used, but by their use of agentic scaffolding to autonomously orchestrate entire attack chains, like one threat actor who weaponized Claude Code with MCP servers to autonomously execute reconnaissance, exploitation, lateral movement, and exfiltration.</p><p class="paragraph" style="text-align:left;">Anthropic argues that the MITRE ATT&CK framework needs expansion to capture AI-native behaviors like autonomous killchain orchestration and real-time pivot decisions that don&#39;t map to existing technique IDs but represent the most dangerous evolution in AI-enabled cyber threats.</p><p class="paragraph" style="text-align:left;">💡 This is really cool, and valuable context for the community on how threat actors are using AI. As mentioned in the intro, expect me to continue including solid technical work from Anthropic. I have many kind, extremely competent friends at Anthropic who I respect highly. I think the world is better off for having many companies and individuals working together to make the world safer. </p><p class="paragraph" style="text-align:left;">Ultimately I think that’s the north star of all of us working in cybersecurity: making the world safer so all <span style="text-decoration:line-through;">non-neck beards</span> people live happy, fulfilling lives without having to worry about getting hacked, having their identity stolen, etc.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=sL16tsGafcQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">The 4 Proven Ways To Build Wealth In 2026</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/mnzaVnSgoVU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">“This is gonna be cute, trust me”</a></p></li><li><p class="paragraph" style="text-align:left;">Lea Salonga and Brad Kane - <a class="link" href="https://www.youtube.com/watch?v=GyJI8kr0Qo8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">A Whole New World</a> (1993 Oscars) 🥹</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=76Q5TWHslOE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Hadestown: The Musical | Official Trailer</a> - OMG YAS! Looks like they filmed the original cast, like they did with Hamilton. I love this approach, I wish all musicals did that. I give Hadestown at least 😭😭😭😭/5. Obviously all musicals should be rated in sob emojis.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/BSDQM9Jce-0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Mobility exercises for 40+</a></p></li><li><p class="paragraph" style="text-align:left;">I have a lot more I want to include here, but it is late, so instead I shall hopefully flesh this out more next week. Hope you have a great rest of your week 👋 </p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=7de169c0-8a4b-44a9-9ba2-f01005505eac&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #331 - How Adversaries Use AI, Skill Issues, Using IDEs for C2</title>
  <description>Google&#39;s deep dive on how threat actors are using AI, bypassing malicious skill scanning, using VS Code dev tunnels for command and control</description>
  <link>https://tldrsec.com/p/tldr-sec-331</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-331</guid>
  <pubDate>Thu, 04 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-04T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👩‍❤️‍👨 Repo-mantic Comedy</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Recently I had one of those moments where you remember that LLMs are trained on the vast, beautiful, complicated collection of human knowledge.</p><p class="paragraph" style="text-align:left;">I was using Codex to port a feature from one code base to another, and it said:</p><p class="paragraph" style="text-align:left;">“…I’m reading the exact code paths now so the port preserves behavior instead of inventing a <b>prettier cousin</b>.” 😂 </p><p class="paragraph" style="text-align:left;">Dear reader, I had questions. Like: how many bodice ripper novels and country music lyrics are in the training corpus? What other secrets lie in the weights?</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">I didn’t think I read anything about dating preferences in its model card.</p><p class="paragraph" style="text-align:left;">LLMs are strange, and amusing sometimes. This situation makes me think of the <a class="link" href="https://openai.com/index/where-the-goblins-came-from/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">goblins post</a>.</p><p class="paragraph" style="text-align:left;">I love demoing what you can build with coding agents to friends, but maybe I’ll hesitate before doing this next Thanksgiving, just in case…</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> AI will make every asset a potential zero-day target. Are you ready?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">The AI-attack era has arrived. Thousands of zero-days in the pipeline. Target-specific exploits generated in minutes. Unattributed, one-off attacks that bypass detection — while your dashboard stays green.</p><p class="paragraph" style="text-align:left;">runZero is built for this reality. Know every asset on your attack surface, uncover every exposure, map every attack path, and validate your segmentation — before the exploit drops. We deliver deep intelligence across IT, OT, IoT, cloud, and mobile, so defenders can win by default. Even against AI.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.runzero.com/?utm_source=tldr-sec&utm_medium=email-sponsored&utm_campaign=runzero-general" target="_blank" rel="noopener noreferrer nofollow"><b>Try It Free Today</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">I’ve heard great things about runZero, and HD Moore is a legend (and super nice).</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.yaelwrites.com/what-my-privacy-and-security-stack-actually-looks-like?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">What My Privacy and Security Stack Actually Looks Like</a><br>Great guide by <a class="link" href="https://www.linkedin.com/in/yaelgrauer/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Yael Grauer</a>: Use a PO Box and EasyOptOuts to scrub your home address from the internet (<a class="link" href="https://github.com/yaelwrites/big-ass-data-broker-opt-out-list?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Big Ass Data Broker Opt-Out List</a>), meet new contacts in public, use YubiKeys for MFA, 1Password/Bitwarden, encrypted drives, privacy screens in public, Privacy Badger, Mullvad VPN, uBlock Origin, Signal with disappearing messages, Google’s Advanced Protection Program, Lockdown Mode for Apple Devices, Google Fi for SIM-swap protection, iCloud&#39;s Hide My Email for aliases, and more.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/05/27/aikido-xbow.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Comparing AI Application Security Testing Platforms</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/lucacarettoni/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Luca Carettoni</a> and <a class="link" href="https://www.linkedin.com/in/tonytrummer/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Anthony Trummer</a> conducted a side-by-side comparison of two AI-powered penetration testing platforms, Aikido&#39;s Attack AI Pentest and XBOW&#39;s Lightspeed, manually validating all findings to determine true positives versus false positives. The evaluation assessed configuration complexity, impact on tested applications, report quality, cost, speed, and overall testing effectiveness.</p><p class="paragraph" style="text-align:left;">💡 Great example of a thoughtful benchmarking methodology and comparison that measures a variety of useful dimensions like: did a human tester agree with the severity ratings, what was the overlap in findings between the tools, and more. It’d be great to see more comparisons this detailed, but it does take a lot of time and effort.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.token.security/blog/zapocalypse-the-attack-chain-that-could-have-hijacked-zapier?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Zapocalypse: The Attack Chain That Could Have Hijacked Zapier</a><br>Token Security’s <a class="link" href="https://www.linkedin.com/in/yairbalilti/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Yair Balilti</a> describes chaining five known primitives to achieve NPM publishing rights to Zapier&#39;s design-system package, which would have enabled JavaScript execution in every authenticated Zapier session (yikes). Starting from a &quot;Code by Zapier&quot; Python sandbox where <code>os.system</code> worked, Yair scraped orphaned AWS STS credentials from <code>/proc/self/mem</code> (since <code>del os.environ[k]</code> doesn&#39;t zero heap memory), then used the misnamed <code>allow_nothing_role</code> (which actually permitted ECR enumeration and image pulls) to extract 1,111 container images via direct ECR API calls bypassing Docker&#39;s <code>GetAuthorizationToken</code> requirement. He then discovered a high-privilege NPM token with <code>bypass_2fa: true</code> and <code>scope.name: null</code> leaked in container build metadata via <code>ARG</code>/<code>ENV</code> in image config history, plus a hardcoded Zapier Actions MCP key belonging to a LiteLLM co-founder that enabled Gmail impersonation.</p><p class="paragraph" style="text-align:left;">💡 Attack chain enabling publishing arbitrary JavaScript served by &lt;your domain&gt; and ran in every one of your user’s sessions… $3,000. Sometimes I’m surprised more security researchers don’t turn to crime. To be clear, I’m not encouraging bad behavior, nor is this a unique case, I’ve seen many examples of “I could compromise &lt;all of your users&gt;” and the payout is a few grand. Sometimes the impact to payout ratio feels 🙃 </p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Prowler: the world’s most widely adopted open cloud security platform</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Prowler automates security and compliance across any cloud environment, with agentless coverage of cloud infrastructure, SaaS, Kubernetes, containers, Infrastructure as Code, and more. It detects vulnerabilities and misconfigurations, prioritizes risks, accelerates remediation, and automates audit-ready compliance. </p><p class="paragraph" style="text-align:left;">Prowler has become the security platform of choice for thousands of cloud teams, with 45M+ downloads, 13K+ GitHub stars, and 300+ global contributors. Prowler Cloud delivers cloud security 10x more cost-effectively than alternatives.</p><h2 class="heading" style="text-align:center;"><a class="link" href="https://prowler.com/interactive-demo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow"><b>👉 See Prowler In Action 👈</b></a></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Prowler is great, love the open core nature. Also fun demo format 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@adan.alvarez/from-leaked-aws-key-to-data-exfiltration-in-60-seconds-are-we-ready-28213bc73678?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">From Leaked AWS Key to Data Exfiltration in 60 Seconds: Are We Ready?</a><br><a class="link" href="https://www.linkedin.com/in/adan-%C3%A1lvarez-vilchez-539a92115/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adan Alvarez</a> tested Claude Code&#39;s ability to move from a leaked AWS IAM key to data exfiltration without AWS-specific guidance, finding that in 7 of 12 runs, the AI agent successfully completed the attack chain in approximately 60 seconds. The scenario involved a CI/CD user with read access to a Terraform state file containing credentials that could assume a privileged role, with all successful runs following an identical six-phase kill chain: GetCallerIdentity, policy enumeration (ListUserPolicies/GetUserPolicy), credential recovery from S3, AssumeRole, bucket enumeration, and exfiltration.</p><p class="paragraph" style="text-align:left;">Adan notes that CloudTrail&#39;s 5-minute log delivery delay means traditional alerting may be too slow to prevent sub-minute attacks which is why Adan is betting on honeytokens and honeypots to waste the agent&#39;s time before it finds anything real. See the scenario on <a class="link" href="https://github.com/adanalvarez/cloud-ranges/tree/main/aws-tfstate-exfil?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">GitHub here</a>.</p><p class="paragraph" style="text-align:left;">💡 Interesting- I hadn’t thought about that as much yet, but that’s a great point: log sources that only ship every 5 minutes could be a problem if an entire kill chain can be fully automated in a minute or two. Yikes.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.plainenglish.io/adding-strands-security-agents-to-shadow-asset-scanner-60c236c84b7e?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adding Strands Security Agents to Shadow Asset Scanner</a><br><a class="link" href="https://linkedin.com/in/sena-yakut?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Sena Yakut</a> built a shadow asset scanner that uses boto3 to sweep AWS for exposed S3 buckets, stale IAM keys, public Lambda function URLs, and similar misconfigurations. On top of that she layered a Strands Agents SDK that reads the raw findings and reasons across them for multi step attack paths rather than presenting each item in isolation.</p><p class="paragraph" style="text-align:left;">The architecture runs as a collaborative Swarm where specialized agents pass context to each other in sequence. The Error Analyst handles failures from the boto3 pass first, the Attack Chain Analyst then stitches findings into chained scenarios mapped to MITRE ATT&CK tactics, the Summary Agent compresses what comes out, and the Chat Agent serves four report formats (standard, executive, technical, and compliance) along with remediation commands. The agents reach the scanner through Strands&#39; tool interface and share state across handoffs, with caps on handoff count and execution time keeping the swarm from looping indefinitely.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.reversec.com/posts/2026/05/skill-issues-compromising-claude-code-with-malicious-skills-agents-part-1?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Skill Issues: Compromising Claude Code with malicious skills & agents</a><br>Reversec&#39;s James Henderson demonstrates how Claude Code skills and sub-agents can serve as initial access vectors, with risks comparable to installing untrusted pip packages. Henderson describes two attack paths. The first runs through skill frontmatter: setting <code>allowed-tools: Bash(*)</code> alongside dynamic context inputs like !<code>socat ...</code> executes commands before the LLM processes them, while direct reverse shell requests to Claude get refused. </p><p class="paragraph" style="text-align:left;">The second path runs through sub-agents and <code>permissionMode: bypassPermissions,</code> which skips consent prompts but doesn&#39;t prevent agents from reasoning about commands. To bypass that reasoning, Henderson runs <code>npm install</code> against a localhost registry serving backdoored packages, giving the agent legitimate cover to execute malicious code without exposing the payload.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The sorry state of skill distribution</a><br>Trail of Bits&#39;s <a class="link" href="https://sjudson.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Samuel Judson</a> and <a class="link" href="https://www.linkedin.com/in/tjaden/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Tjaden Hess</a> were able to bypass <a class="link" href="https://github.com/openclaw/clawhub/blob/c3c885ec10161ad35fbe78678ccc3f8c34e03ffd/convex/lib/securityPrompt.ts?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">ClawHub’s malicious skill detector</a>, <a class="link" href="https://github.com/cisco-ai-defense/skill-scanner?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Cisco’s agent skill scanner</a>, and all three of the scanners integrated into <code>skills.sh</code> in a few hours, using techniques like prepending 100,000 newlines to hide malicious code, embedding payloads in .docx archives and poisoned .pyc bytecode files, and using prompt injection to convince guard models that malicious registry configurations were legitimate corporate infrastructure. The attacks exploited weaknesses in the scanners: truncated file analysis, limited file type coverage that ignored binaries and hidden files, and the ability for attackers to iteratively refine attacks against static scanning targets.</p><p class="paragraph" style="text-align:left;">Recommendation: avoid public skill marketplaces like <a class="link" href="https://skills.sh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">skills.sh</a> and ClawHub entirely, instead curate internal skill repositories using trusted sources. PoC repo: <a class="link" href="https://github.com/trailofbits/overtly-malicious-skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">trailofbits/overtly-malicious-skills</a>.</p><p class="paragraph" style="text-align:left;">💡 Also <b>WHAT</b> - “The official MS Office skills from Anthropic for handling <code>.docx</code>, <code>.xlsx</code>, and <code>.pptx</code> files each contain a script called <code>soffice.py</code>… which hacks around the socket block by using <code>LD_PRELOAD</code> to patch in either 1) an existing <code>$TMP/lo_socket_shim.so</code>”, or 2) a library dynamically compiled out of C code embedded in a docstring.” 🫠 😂 </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/cve-2026-31431-copy-fail-exploit-detection-with-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/ryan-simon-2767bb15/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Ryan Simon</a> walks through <a class="link" href="https://github.com/advisories/GHSA-2274-3hgr-wxv6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Copy Fail</a>, a Linux kernel bug that lets an unprivileged user corrupt the page cache through its crypto socket interface and quietly rewrite <code>setuid</code> binaries like <code>/usr/bin/su</code> to escalate to root. Ryan used a single coding agent with a custom skill for each step to compress the full detection engineering cycle into one session, from threat analysis through live exploit testing to production deployment. The detection itself is a three stage chained rule that uses process scoped variables to track <code>bind(AF_ALG)</code>, <code>setsockopt(SOL_ALG)</code>, and splice or open operations on SUID binaries or PAM configs.</p><p class="paragraph" style="text-align:left;">💡 The “Accelerating the Detection Engineering Lifecycle with agents” section at the bottom has some great tactical details on how specific steps are scaled 👌 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</a><br>Google Threat Intelligence Group&#39;s (GTIG) Q2 2026 AI Threat Tracker describes several recent developments in how threat actors are using AI in their operations and targeting AI infrastructure directly. GTIG identified the first case of a threat actor using a zero-day it believes was developed with AI, a 2FA bypass in a popular open-source web admin tool disrupted before mass exploitation. PRC and DPRK actors are running their own AI-augmented vuln research workflows, while Russia-nexus malware CANFAIL and LONGSTREAM use LLM-generated decoy logic to obfuscate payloads against Ukrainian targets. PROMPTSPY, an Android backdoor first identified by ESET, embeds an autonomous agent that drives device interactions through gemini-2.5-flash-lite.</p><p class="paragraph" style="text-align:left;">Threat actors are also going after AI infrastructure itself. TeamPCP (UNC6780) compromised the LiteLLM and BerriAI repositories alongside Trivy and Checkmarx to plant the SANDCLOCK credential stealer and extract AWS keys and GitHub tokens from build environments. They&#39;re also industrializing LLM access through middleware like Claude-Relay-Service and CLIProxyAPI alongside automated account-registration pipelines. The common pattern is a maturing ecosystem where the orchestration layers around AI (wrapper libraries, skill packages, API connectors) are now part of the software supply chain attack surface.</p><p class="paragraph" style="text-align:left;">💡 Wow, excellently detailed blog on how threat actors are using AI. Covers a number more things than I have the space to include here.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.straiker.ai/blog/nomshub-cursor-remote-tunneling-sandbox-breakout?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">NomShub: Weaponizing Cursor&#39;s Remote Tunnel Through Indirect Prompt Injection and Sandbox Breakout</a><br>Straiker’s <a class="link" href="https://www.linkedin.com/in/karpagarajanvikkii/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Karpagarajan Vikkii</a> and <a class="link" href="https://www.linkedin.com/in/malwareunicorn/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Amanda Rousseau</a> describe NomShub, a vulnerability chain in Cursor where a malicious repository can silently hijack a developer&#39;s machine, combining indirect prompt injection, a sandbox escape via shell builtins (<code>export</code> and <code>cd</code> to escape workspace restrictions and write to <code>~/.zshenv</code> for persistence), and Cursor&#39;s built-in remote tunnel to give attackers persistent, undetected shell access triggered simply by opening a repo.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The Accidental C2: Exploring Dev Tunnels for Remote Access</a><br>SpecterOps&#39;s <a class="link" href="https://linkedin.com/in/xpn?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adam Chester</a> examined Visual Studio Code Dev Tunnels as a potential C2 framework, discovering they consist of multiple protocol layers: REST management API for tunnel discovery and token generation, WebSocket tunneling, SSH connections using the russh crate, and MsgPack RPC for command execution. Adam released <a class="link" href="https://github.com/xpn/Ouroboros?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Ouroboros</a>, a Rust tool that implements the stack outside VS Code, with RPC methods like <code>spawn</code>, <code>fs_read</code>, <code>fs_write</code>, and <code>fs_connect</code> to interact with existing dev tunnels for remote code execution and file operations.</p><p class="paragraph" style="text-align:left;">Adam found that FOCI (Family of Client IDs) and BroCI (Nested App Authentication) clients can be leveraged to pivot from compromised Microsoft applications like Teams or Azure Portal to gain access tokens for the Dev Tunnels Service, enabling lateral movement and initial access scenarios. Adam conducted this research with significant assistance from GPT-5.4-Cyber, which mapped the protocol layers and created the russh patch.</p><p class="paragraph" style="text-align:left;">💡 Next example of leveraging coding agents to quickly understand a new, complex code base and stack.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.s0ld13r.kz/posts/claude-code-backdoor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Claude Code Hooks as Initial Access & Persistence</a><br><a class="link" href="https://www.linkedin.com/in/s0ld13r/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Zhangir Ospanov</a> describes how Claude Code&#39;s Hooks feature can be weaponized for initial access and persistence by embedding malicious commands in <code>.claude/settings.json</code> files, similar to the VSCode tasks backdoor previously exploited by Lazarus Group. Attackers can plant hooks at the project level that execute when a developer clones and runs Claude Code, or achieve persistence by modifying the global config (<code>~/.claude/settings.json</code>) to trigger payloads across all sessions. The technique uses lifecycle events like SessionStart, PreToolUse, and PostToolUse to execute arbitrary shell commands. </p><p class="paragraph" style="text-align:left;">Detection: audit <code>claude/</code> directories in cloned repositories, watch <code>~/.claude/settings.json</code> with file integrity monitoring, and review hook commands for anything suspicious before running Claude Code on untrusted code. A proof of concept repository with the full payloads is <a class="link" href="https://github.com/s0ld13rr/claude-code-backdoor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">available</a> if you want to test detection rules locally.</p><p class="paragraph" style="text-align:left;">💡 Reporting to you live from the field: features to run arbitrary code… support running arbitrary code. Lots of Living Off the Land opportunities for modern IDEs and coding agents.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://devin.ai/security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Devin for Security</a> - Seems like the focus is mostly on automatically writing fixes for (already) identified security issues, burning down the backlog.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://delinea.com/resources/ai-and-identity-security-report-pdf?utm_medium=paid-newsletter&utm_source=link-sponsorship&utm_campaign=br-brand-fy26-influencer-activity&utm_content=260522&utm_term=" target="_blank" rel="noopener noreferrer nofollow"><b>Is Your Identity Security Keeping Up with AI?</b></a><b> </b>- AI is moving faster than identity controls can keep up. Most teams say they&#39;re ready, but few can explain what their identities are doing in real-time. That&#39;s the AI security confidence paradox. <a class="link" href="https://delinea.com/resources/ai-and-identity-security-report-pdf?utm_medium=paid-newsletter&utm_source=link-sponsorship&utm_campaign=br-brand-fy26-influencer-activity&utm_content=260522&utm_term=" target="_blank" rel="noopener noreferrer nofollow">Delinea&#39;s 2026 Identity Security Report </a>unpacks this and more.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.neowin.net/news/people-are-using-prompt-injection-to-trick-metas-ai-into-handing-over-instagram-accounts/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">People are using prompt injection to trick Meta&#39;s AI into handing over Instagram accounts</a> - The issue has been actively exploited in the wild for months, going back to February of this year, with hackers compromising thousands of accounts.</p><p class="paragraph" style="text-align:left;"></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/openbashok/promptzero?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">openbashok/promptzero</a><br>Local proxy tool by <a class="link" href="https://github.com/openbashok/promptzero?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">OpenBash</a> that detects and replaces sensitive data such as IP addresses, hostnames, credentials, and personal information in your prompts before they leave your environment, then restores the real values in the response. Detection combines Presidio + spaCy named entity recognition (English and Spanish) for entities like persons, organizations, emails, and passports, with regex layers covering network infrastructure and country-specific identity documents. Each session keeps a bidirectional mapping table that stays local, and you can verify nothing real ever leaves by routing the upstream connection through Burp or mitmproxy and inspecting what actually reaches Anthropic.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.kaspersky.com/blog/llmjacking-2026-private-ai-server-security/55768?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">LLMjacking: what these attacks are, and how to protect AI servers</a><br><a class="link" href="https://linkedin.com/company/kaspersky?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Kaspersky&#39;s</a> Stan Kaminsky describes an experiment where a researcher ran a Raspberry Pi honeypot dressed as a high-performance AI server with Ollama, LM Studio, and similar local frameworks. Shodan found it in three hours, and the box saw 113,000 requests in a month, with 23% aimed at the AI stack. Attackers used LLM-Scanner to fingerprint models through <code>/api/tags</code> and <code>/v1/models</code>, scanned for AI agents via <code>/.cursor/rules</code>, inventoried MCP servers via <code>/.well-known/mcp.json</code>, and hunted <code>.env</code> files for credentials. The focus was resource theft, not RCE, mostly proxying calls to Anthropic models and parsing vuln data from social posts.</p><p class="paragraph" style="text-align:left;">Kaminsky shares some key defensive measures for private AI infrastructure, such as binding single-machine deployments to localhost so they aren&#39;t reachable from the network, swapping plain API key auth for OIDC or OAuth2 with short-lived tokens, segmenting the network with IP allowlists, running EDR on the boxes hosting AI models, setting per-role usage quotas with anomaly alerts on resource consumption, and shipping every request and response to a SIEM with tamper-resistant storage.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://pluto.security/blog/inside-claude-managed-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Inside Claude Managed Agents</a><br>Pluto Security&#39;s <a class="link" href="https://www.linkedin.com/in/yotamperkal/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Yotam Perkal</a> reverse-engineered Anthropic&#39;s Claude Managed Agents cloud runtime, finding gVisor sandboxing with a three-layer egress control system. Outbound traffic routes through a JWT-authenticated proxy with TLS inspection, the container has no direct DNS, and a network-level firewall blocks direct outbound. Together these prevent proxy bypass even when proxy environment variables are unset.</p><p class="paragraph" style="text-align:left;">The architecture separates session, harness, and sandbox into distinct trust zones, so a compromised sandbox cannot tamper with audit logs, influence orchestration, or access vault credentials. Yotam calls the vault credential proxy the platform&#39;s strongest property, with secrets never entering the sandbox and instead injected server-side at request time, so prompt injection has nothing to steal.</p><p class="paragraph" style="text-align:left;">Yotam notes that the defaults ship for convenience. The egress JWT is readable by any sandbox process and contains organization metadata plus the complete egress allowlist, which Anthropic silently expands with six additional infrastructure hosts (including a staging endpoint) even in limited networking mode. All eight tools are enabled by default with an always_allow permission policy and unrestricted networking. For hardening your deployment the post recommends disabling the default toolset, allowlisting only necessary tools, using limited networking, storing credentials in vaults, and monitoring session events.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=W_34Zwki0W8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">How Making More Money Affects Your Life</a></p></li><li><p class="paragraph" style="text-align:left;">Sharran Srivatsaa - <a class="link" href="https://www.mynextbillion.com/p/spirit-airlines?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">I Spent a Day Trying to Buy Spirit Airlines. Here&#39;s What I Found.</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=DW0XUsyBBuY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The Gen Alpha Melody</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=IMu6dYIuUXs&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Renée Elise Goldsberry “Satisfied”</a> (Official Music Video)</p></li><li><p class="paragraph" style="text-align:left;">Good Work - <a class="link" href="https://www.youtube.com/watch?v=X5MzTvfjcOM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Do presidents always make this much money?</a></p></li><li><p class="paragraph" style="text-align:left;">Chris Williamson - <a class="link" href="https://www.youtube.com/watch?v=33olenz_iiQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">What To Look For When Choosing A Partner - Chris Bumstead</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/bFkK3?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">F.B.I. Arrests C.I.A. Official With $40 Million in Gold Bars in His Home</a> - I’m guessing he’ll be barred from future public service 😏 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;">typedfemale - <a class="link" href="https://x.com/typedfemale/status/1945912359027114310?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">presenting: big jeff’s trainium hell</a> - Don’t watch at work 😂 </p></li><li><p class="paragraph" style="text-align:left;">Make Some Noise - <a class="link" href="https://www.youtube.com/shorts/P7y3lGynSEk?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">King Lear and his Three Influencer Daughters</a> - Having three influencer kids, now that’s a tragedy 😭 </p></li><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=DmU9uovmT2A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Upper Management Meeting</a></p></li><li><p class="paragraph" style="text-align:left;">ProZD - <a class="link" href="https://www.youtube.com/watch?v=4ZK8Z8hulFg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">before and after you discover the subreddit for a hobby</a></p></li><li><p class="paragraph" style="text-align:left;">Harvard Commencement 2026 - <a class="link" href="https://www.youtube.com/watch?v=F3fCktnkBbc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Conan O’Brien Delivers the Commencement Address</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI / Tech</p><ul><li><p class="paragraph" style="text-align:left;">Simon Willison - <a class="link" href="https://simonwillison.net/2026/May/27/product-market-fit/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">I think Anthropic and OpenAI have found product-market fit</a></p></li><li><p class="paragraph" style="text-align:left;">Lenny’s Podcast - <a class="link" href="https://www.youtube.com/watch?v=BD3vLtWhT5A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The most rational take on AI you’ll hear this year | Benedict Evans</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=rMf-JuikR-Q&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Why AI Agents Will Replace Your Next Hire</a></p></li><li><p class="paragraph" style="text-align:left;">Tech Crunch - <a class="link" href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Microsoft under fire for threatening security researcher with criminal investigation</a>. Kevin Beaumont - <a class="link" href="https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Microsoft’s stance on zero day exploits is a dumpster fire of their own making</a>. Microsoft employs some friends and in general top notch security folks. #hugops to them in resolving challenges like this.</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=292c9898-807d-45b1-9978-d90326ff95e2&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates</title>
  <description>100+ intentionally vulnerable AWS environments for practicing cloud attack paths, how OpenAI deploys Codex internally, Anthropic&#39;s update on bugs found and their open sourced harness</description>
  <link>https://tldrsec.com/p/tldr-sec-330</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-330</guid>
  <pubDate>Thu, 28 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-28T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">⛰️ Ain’t No Mountain High Enough</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">To keep me from sending to you bae.</p><p class="paragraph" style="text-align:left;">Literally as I was starting to write this intro, my home Internet went out. After a moment I realized I had gotten a text a few days ago- scheduled maintenance with my Internet provider 😅 </p><p class="paragraph" style="text-align:left;">So now I’m finishing this issue via hot spotting with my phone.</p><p class="paragraph" style="text-align:left;">I’ve wondered sometimes what I’d do if there was some sort of force majeure world or personal event that put my ability to finish the newsletter in jeopardy.</p><p class="paragraph" style="text-align:left;">We cut to- <i>*Movie trailer voice* In a world, where there’s too much security news…</i></p><p class="paragraph" style="text-align:left;"><i>*Inception bong* One terminally online hacker fights the info deluge for the people…</i></p><p class="paragraph" style="text-align:left;"><i>But today… *insert plot device like aliens arriving, natural disasters, Sharknado, etc.*</i></p><p class="paragraph" style="text-align:left;">It could be any of these, I’ve got range.</p><p class="paragraph" style="text-align:left;">I’ve offered this CTA to Netflix <a class="link" href="https://tldrsec.com/p/tldr-sec-55?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">several</a> times <a class="link" href="https://tldrsec.com/p/tldr-sec-126?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates#phone-a-friend" target="_blank" rel="noopener noreferrer nofollow">over</a> 6 <a class="link" href="https://tldrsec.com/p/tldr-sec-117?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">years</a>, and heard back <a class="link" href="https://tldrsec.com/p/tldr-sec-118?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">once</a>. Still working on manifesting it 🙏 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Threats Don’t Need Malware. </b></span><br><span style="color:#222222;"><b>They Need Your Identity.</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">No custom malware. No zero-days. Just your own admin tools, cloud APIs, and trusted processes repurposed without triggering a single alert. <b>Varonis Threat Labs&#39; 2026 Attacker&#39;s Playbook</b> maps the full attack chain with real-world case studies and exposes how trust gets weaponized by threats at every stage. Discover the tactics. Close the gaps.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.ly/Q04hXllV0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow" style="color: #0969da"><b>Get the Playbook</b></a><span style="color:#434343;"><b> </b></span><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">Varonis has been sharing some great security research recently. And I’m curious about these advanced tactics like “Cookie-Bite” and “EchoLeak” 👀 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/falcosecurity/prempti?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">falcosecurity/prempti</a><br>Tool by <a class="link" href="https://www.linkedin.com/company/falco-security-oss/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Falco</a> that brings Falco to AI coding agents. Prempti intercepts every tool call (shell commands, file writes and reads, web fetches, MCP calls) at the agent&#39;s hook API before it runs and produces allow/deny/ask verdicts from customizable Falco YAML rules, with an LLM-friendly explanation fed back to the agent on denials so it can adapt. Because interception happens at the hook level rather than the kernel, rules see what the agent declares but not the runtime behavior of compiled binaries or the side effects MCP servers later produce, so Prempti is positioned as a cooperative policy layer to use alongside OS-level containment rather than as a replacement for it.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/running-codex-safely?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Running Codex safely at OpenAI</a><br>OpenAI walks through how they deploy Codex internally, with security controls including sandboxed execution environments, approval workflows for high-risk actions, and an <a class="link" href="https://alignment.openai.com/auto-review/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">auto-review subagent</a> that automatically approves low-risk operations to reduce friction. They enforce network policies that allowlist expected destinations and require approval for unfamiliar domains, manage authentication through OS keyrings pinned to their ChatGPT enterprise workspace, and use macOS managed preferences with admin-enforced requirements files to maintain consistent security baselines. </p><p class="paragraph" style="text-align:left;">Codex exports OpenTelemetry logs containing user prompts, tool approvals, execution results, and network policy decisions, which OpenAI feeds into an AI-powered security triage agent that correlates endpoint alerts with agent intent to distinguish between legitimate behavior and genuine security incidents.</p><p class="paragraph" style="text-align:left;">💡 Auto-review mode is neat, I find Codex almost never prompts me in normal usage. Also, the Codex logs → security triage agent is very interesting, I’m curious to know more. Could you detect when an agent is going off the rails, or prompt injected and doing some C2 behavior? Or detecting an insider threat type situation? Lots of applications 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.marcolancini.it/2026/blog-automating-security-operations-with-ai-triage-renovate?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Automating Security Operations with AI: Triaging Renovate PRs</a><br><a class="link" href="https://www.linkedin.com/in/marcolancini/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Marco Lancini</a> writes up how he combined Renovate with Claude Code Routines to automate the review of dependency update PRs, using a custom Claude skill that posts a structured upgrade risk matrix back to each PR. The skill detects stack type (e.g. Python, JavaScript) from the PR title and classifies bumps as High, Medium, or Low based on <code>semver</code> plus how the package actually behaves (e.g. has a history of breaking changes), not just version distance. From there it greps source code for actual imports to flag dead dependencies, queries <code>Context7</code> for breaking changes, and scans for deprecated config patterns like TypeScript&#39;s <code>baseUrl</code> or Next.js&#39;s <code>middleware.ts</code>. The cloud routine fires on each new <code>[RENOVATE]</code>-prefixed PR (Renovate runs monthly), runs the skill read-only without approval prompts, and posts the risk matrix via <code>gh pr comment</code>. A 14-day <code>minimumReleaseAge</code> filter sits in front of the whole pipeline to block supply-chain attacks.</p><p class="paragraph" style="text-align:left;">💡 Excellent example of automating a toil-heavy workflow: reviewing package updates. Marco kindly released the full Skill prompt he uses, which is thorough and handles a number of edge cases, and is definitely worth reviewing 🤘 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Adaptive Security: Hyperrealistic Phishing Simulations Across Email, Voice, and SMS</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Most phishing simulations are still templated emails. Adaptive runs hyperrealistic multi-channel simulations including AI-generated voice calls, OSINT-based spearphishing tailored to each target, and automated phishing programs that run in the background without manual lift. The result: measurable reductions in click rates, stronger security behaviors over time, and a workforce that&#39;s actually prepared for the threats hitting their inbox today. Rated 4.9/5 on G2 and Gartner.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#2C81E5;"><b>👉 </b></span><span style="color:#2C81E5;"><a class="link" href="https://www.adaptivesecurity.com/lp/nb/phishing-simulation?utm_source=sp_email&utm_medium=newsletter&utm_campaign=2026_05_NA_TLDR_sec_newsletter&utm_id=701Rd00000guu14IAA" target="_blank" rel="noopener noreferrer nofollow"><b>See It in Action</b></a></span><span style="color:#2C81E5;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AI-powered spearphishing and deepfakes are pretty worrying to be honest, they’re getting quite good. I’m glad people are working on this ✊ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-security-agent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">AWS Security Agent adds verification scripts for pentest findings</a><br>AWS Security Agent now automatically generates executable verification scripts for each confirmed penetration test finding. Verification scripts include setup instructions, documented environment variables, and redacted sensitive values.</p><p class="paragraph" style="text-align:left;">💡 Many dynamic analysis tools have been generating curl requests, PoC scripts, etc. that reproduce findings for a decade+, long before LLMs (shout-out Burp Suite, my BFF during my consulting days). And of course fuzzers do this by construction. It seems like auto-generating PoCs is or will be table stakes for any security tool that finds vulnerabilities, which honestly is kind of a cool world to be living in. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/sethart?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Seth Art</a> introduces <a class="link" href="https://github.com/DataDog/pathfinding-labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Pathfinding Labs</a>, a collection of 100+ intentionally vulnerable AWS environments deployable via Terraform for practicing cloud attack paths and validating detections. The project ships a Go CLI tool (<code>plabs</code>) for deployment and a web catalog at <a class="link" href="https://pathfinding.cloud/labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">pathfinding.cloud/labs</a> with per-lab documentation. Scenarios cover self-escalation (a role granting itself admin via <code>PutRolePolicy</code>), one-hop and multi-hop privilege escalation chains, CSPM misconfigurations and toxic combos like a public Lambda with an admin role, and cross-account paths from dev or ops into prod. Each lab includes a <code>demo_attack.sh</code> script that walks the exploitation chain step-by-step, with cleanup scripts to revert artifacts after testing.</p><p class="paragraph" style="text-align:left;">💡 Love all the OSS tools and labs that Seth and Datadog put out. Awesome!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</a><br>Palo Alto Networks&#39; <a class="link" href="https://linkedin.com/in/williambatchelor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Bill Batchelor</a> and <a class="link" href="https://www.linkedin.com/in/eyalrafian/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Eyal Rafian</a> give an overview ROADtools, an open-source Python framework that nation-state actors like Cloaked Ursa (APT29) and Curious Serpens (APT33) have weaponized for cloud attacks, including how ROADtools evades detection and how these threat actors misuse it. The post discusses ROADtools’ roadrecon module for Entra ID enumeration via the Microsoft Graph API, the roadtx module for token manipulation, device registration, and MFA bypass, and categorize functionality in MITRE ATT&CK. They conclude with preventive controls to limit token misuse, and Cortex XQL detection queries.</p><p class="paragraph" style="text-align:left;">💡 In security, you either die young or live long enough to see threat actors using your tools for ill.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">We hardened zizmor&#39;s GitHub Actions static analyzer</a><br>Trail of Bits&#39;s <a class="link" href="https://linkedin.com/in/alexis-challande?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Alexis Challande</a> writes up a three-month collaboration with the zizmor maintainers to bring its YAML anchor support up to full coverage, prompted by the March 2026 supply-chain attack where attackers exploited a pull_request_target misconfiguration in aquasecurity/trivy-action to backdoor LiteLLM. Zizmor’s anchor support had been best-effort since GitHub Actions added native YAML anchors in September 2025. The team fixed parsing bugs that caused crashes and wrong-location findings, surfaced deserialization edge cases that broke zizmor on otherwise valid workflows, and aligned zizmor&#39;s expression evaluator with GitHub&#39;s Known Answer Tests, validating the work against a corpus of 41,253 workflows from 6,612 high-value open-source repositories.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/github-actions-security-ai-powered-actions-vulnerabilities?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/shay-berkovich-0a09975?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Shay Berkovich</a> found vulnerabilities in AI-powered GitHub Actions from OpenAI, Anthropic, and Google affecting repositories with 200,000+ combined stars. Among them, <code>openai/codex-action</code> and <code>anthropics/claude-code-action</code> rely on syntactical permission checks that let attackers impersonate trusted apps when <code>allow-bots</code> is enabled (or if a name is available to be registered, a “Dangling GitHub Apps” attack). <b>Dependabot Deputy Confusion Injection</b> has attackers issue <code>@dependabot</code> commands so <i>dependabot</i> appears as the <code>github.actor</code> on a PR, slipping past allow-lists. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Shay describes how some common authentication Actions create sensitive local secret files at runtime (e.g. GCP service account keys or others that often grant infrastructure-level access). Verbose modes in <code>claude-code-action</code> and <code>run-gemini-cli</code> leak these files via workflow logs even when the model refuses direct exfiltration.</p></div><p class="paragraph" style="text-align:left;">AI-powered GitHub Actions have inherent design risks. Every reviewed Action interpolates untrusted user content into prompts, and those with MCP or tool access amplify the blast radius through file writes, shell execution, and git operations.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/microsoft/RAMPART?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">microsoft/RAMPART</a><br>By <a class="link" href="https://www.linkedin.com/company/microsoft?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Microsoft</a>: RAMPART (Risk Assessment & Measurement Platform for Agentic Red Teaming) is a pytest-native framework for safety and security testing of agentic AI applications that enables developers to write structured tests, with evaluation-driven assertions checking agent behavior against each scenario.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/05/21/tailscalehound?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Introducing TailscaleHound: Mapping Tailscale Attack Paths in BloodHound</a><br>SpecterOps&#39; <a class="link" href="https://www.linkedin.com/in/gomez742/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Andrew Gomez</a> and <a class="link" href="https://www.linkedin.com/in/andreweluke/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Andrew Luke</a> release <a class="link" href="https://github.com/KingOfTheNOPs/TailscaleHound?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">TailscaleHound</a>, a BloodHound OpenGraph collector that maps Tailscale environments as queryable attack paths. It models users, devices, groups, tags, ACLs, grants, SSH rules, routes, app connectors, keys, and hybrid Azure identity links under the TS namespace.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Collection runs through the Tailscale API with read-only OAuth credentials, with optional <code>tailcontrol</code> cookie enrichment. Without API access, local collection works from <code>tailscale status --json</code> output, optionally enriched with an Access Policy file. From there, saved Cypher queries answer who can reach a given device, who can SSH as root, which subnet routes expose internal CIDRs, and which Azure users inherit Tailscale access through <code>TS_AZUserSyncedToUser</code> bridge edges.</p></div><p class="paragraph" style="text-align:left;">Red teamers can maps paths from compromised identities into sensitive devices, useful exit nodes, and Azure-inherited Tailscale access. Defenders can pull from the same graph to flag overbroad ACL sources, stale groups and keys, sensitive routes exposed to broad groups, and SSH rules that hand out root or admin.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://riptides.io/blog/keyledger-ai-api-keys?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Introducing KeyLedger: Because You Probably Don&#39;t Know How Many AI Keys Your Org Has</a><br>Riptides&#39; <a class="link" href="https://www.linkedin.com/in/balint-molnar/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Balint Molnar</a> open-sources <a class="link" href="https://github.com/riptideslabs/keyledger?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">KeyLedger</a>, a Go TUI for inventorying AI provider API keys across OpenAI, Anthropic, Google Cloud Vertex AI, and AWS Bedrock through their admin APIs. KeyLedger normalizes each provider&#39;s different organizational structure into a single table, with automatic health scoring flagging stale, idle, and never-used keys. SQLite snapshots let you diff inventories between runs to track new keys, revocations, and status changes over time. The TUI handles interactive exploration, and watch mode polls providers continuously and runs as a Docker container for long-running deployments.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.offensai.com/blog/scopeshift-ai-pentest-agent-scope-verification-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Attacking Production Apps Without Jailbreaking the Model: Scope Manipulation with scopeshift</a><br>OFFENSAI&#39;s <a class="link" href="https://linkedin.com/in/eduard-k-agavriloae?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Eduard Agavriloae</a> releases <a class="link" href="https://github.com/OFFENSAI/scopeshift?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">scopeshift</a>, an open-source tool demonstrating how AI coding agents can be tricked into attacking production targets while believing they&#39;re testing localhost, bypassing jailbreaking entirely through network-layer deception rather than adversarial prompting. Scopeshift works as a reverse proxy on 127.0.0.1 that rewrites responses (stripping CDN headers, rewriting URLs, replacing titles with &quot;Dev Build — Local&quot;) and provides a deceptive MCP server that always returns &quot;in scope&quot; authorizations. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Testing showed that without safety prompts, Claude Opus 4.7 voluntarily called the MCP oracle and sent seven SQL injection payloads to the real OFFENSAI website, but a one paragraph safety prompt caused the model to refuse after recognizing that in-band signals (MCP responses, DNS, TLS, page content) cannot validate themselves. </p></div><p class="paragraph" style="text-align:left;">💡 This post does a great job highlighting something I’ve been thinking about: how can an AI model (or the labs creating them) know that the user is doing authorized testing? Especially when the model is operating in an environment totally controlled by the user. It feels like the same client-side security lessons we’ve learned from browsers and mobile apps. I’m not sure how this can be solved, which is concerning given the capability improvements of models 😅 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/research/glasswing-initial-update?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: An initial update</a><br>Anthropic releases Project Glasswing&#39;s initial update, reporting that ~50 partners have used Claude Mythos Preview to find over 10,000* high- or critical-severity vulnerabilities in one month. Cloudflare found 2,000 bugs (400 high/critical); Mozilla fixed 271 in Firefox 150. </p><p class="paragraph" style="text-align:left;">Anthropic separately scanned 1,000+ open-source projects, surfacing 6,202 estimated high/critical vulnerabilities. Of 1,752 already triaged by six independent security firms, 90.6% were valid true positives and 62.4% confirmed high/critical, including a wolfSSL certificate forgery exploit. The bottleneck has shifted from finding vulnerabilities to patching them, with maintainers taking an average of two weeks per high/critical bug, </p><p class="paragraph" style="text-align:left;">Anthropic released <a class="link" href="https://claude.com/product/claude-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Claude Security</a> in public beta for Enterprise customers (already used with Claude Opus 4.7 to patch 2,100+ vulnerabilities), <a class="link" href="https://github.com/anthropics/defending-code-reference-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">open-sourced</a> the scanning harness, threat model builder, and skills its Glasswing partners used, and launched a <a class="link" href="https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Cyber Verification Program</a> that lets security professionals use Claude for vulnerability research, penetration testing, and red-teaming without certain safeguards. </p><p class="paragraph" style="text-align:left;">💡 “Over 10,000 high- or critical-severity vulnerabilities*“ is a headline-y opening stat, but later on (based on my read) it seems like that’s the “claimed to be found and rated by Mythos number,” not the human triaged ground truth number. To be fair, that takes a huge amount of work and time. Cloudflare said, “a false positive rate better than human testers.” Which is… what rate? 🤔 </p><p class="paragraph" style="text-align:left;">I think it’s awesome that Anthropic is spending so much time and money securing open source, and it’s great that they open sourced their scanning harness, that helps the industry grow and improve together. It’s also very effective bizdev and marketing for acquiring enterprise customers, but what is security research after all? <code>:hide-the-pain-emoji:</code> 😅 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">Every - <a class="link" href="https://www.youtube.com/watch?v=jBZQ5Ay20HU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">AI Was Supposed to Save Time. Why Am I Busier?</a></p></li><li><p class="paragraph" style="text-align:left;">Leila Hormozi - <a class="link" href="https://www.youtube.com/watch?v=DVtuTp3ykcA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">AI Is Making Your Thinking Worse (And How to Fix It)</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=XsWSvz-aewA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">The New Way of Making Content In The Age of AI</a></p></li><li><p class="paragraph" style="text-align:left;">Matt Turck - <a class="link" href="https://www.youtube.com/watch?v=DhD1zZ8w8Mw&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">OpenAI&#39;s Yann Dubois: Why AI Progress Suddenly Feels Real</a> - Really helpful overview of the different parts of model training</p></li><li><p class="paragraph" style="text-align:left;">Tim Ferriss - <a class="link" href="https://www.youtube.com/watch?v=HutNi2cNsCg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">The AI Frontier and How to Spot Billion-Dollar Companies Before Everyone Else — Elad Gil</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://xunroll.com/thread/2053047748191232310?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Bun ported from Zig to Rust in 6 days using AI</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=LyMjLwSh08w&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">If Lin-Manuel Miranda wrote Defying Gravity from Wicked</a> 😍 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/gUXs_eocZ4g?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Dr. Seuss Rap</a></p></li><li><p class="paragraph" style="text-align:left;">SNL - <a class="link" href="https://www.youtube.com/watch?v=mrW2ld-13iQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Weekend Update: Mr. On Blast Speaks His Mind Again Without Holding Back</a> - This killed me 😂 </p></li><li><p class="paragraph" style="text-align:left;">Good Work - <a class="link" href="https://www.youtube.com/watch?v=npOcPgWymbM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">What does Meta actually do now?</a></p></li><li><p class="paragraph" style="text-align:left;">SNL - <a class="link" href="https://www.youtube.com/watch?v=lbDOegHVPP8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Mom Movie Trailer</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Paper - <a class="link" href="https://pmc.ncbi.nlm.nih.gov/articles/PMC1360393/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Didgeridoo playing as alternative treatment for obstructive sleep apnea</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Magnifica Humanitas: on Safeguarding the Human Person in the Time of AI</a> - I didn’t have “the pope writes a screed on AI” on my 2026 bingo card, but here we are</p></li><li><p class="paragraph" style="text-align:left;">r/bugbounty - <a class="link" href="https://www.reddit.com/r/bugbounty/comments/1tes86p/hi_im_a_former_h1_triager_ama/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">I’m a former H1 Triager AMA</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://lifeweeks.app/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Your Life in Weeks</a> - Create a map of your life where each week is a little box. Inspired by Tim Urban’s blog.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://diamond.jaydip.me/read/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">How Diamonds are Made</a> - Cool visualization</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://paletteinspiration.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Palette Inspiration</a> - Explore color palettes extracted from thousands of masterworks - from Renaissance elegance to Impressionist light. Super cool!</p></li><li><p class="paragraph" style="text-align:left;">Bryan Johnson - <a class="link" href="https://www.youtube.com/watch?v=JNuORofHhrk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">You’re Exercising Wrong</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/g2Leuhr2Ib0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Vik White & Urban Theory at the Red Bull Dance</a> - Sick 🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.csoonline.com/article/4176504/google-leaks-details-for-chromium-bug-that-can-turn-browsers-into-bots.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Google leaks details for Chromium bug that can turn browsers into bots</a> - Reported over three years ago, made public but then wasn’t actually fixed. </p></li><li><p class="paragraph" style="text-align:left;">Krebs on Security - <a class="link" href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">CISA Admin Leaked AWS GovCloud Keys on Github</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">✉️ Wrapping Up</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=ad6a61ae-1168-498a-89d1-e7d7419bd125&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #329 - AI-powered Honeypots, GitHub Action Canaries, Microsoft’s Agentic Security Scanner</title>
  <description>Detecting and deceiving attackers with AI honeypots, detect supply chain attacks with GitHub Action canaries, the latest from Microsoft&#39;s new &quot;Autonomous Code Security&quot; team</description>
  <link>https://tldrsec.com/p/tldr-sec-329</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-329</guid>
  <pubDate>Thu, 21 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-21T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🍦 Ice Cream Bonding</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">There’s this Mediterranean place I like to go to sometimes, Souvla, that has delicious frozen Greek yogurt you can get with baklava on top.</p><p class="paragraph" style="text-align:left;">It’s helped me power through many a late night writing <i>tl;dr sec</i>. Like tonight 😅 </p><p class="paragraph" style="text-align:left;">I’ve gradually started befriending the manager over time, over a series of froyos.</p><p class="paragraph" style="text-align:left;">We’ve discussed how it’s sometimes difficult to make new (deep) friends as you get older, some of his work challenges, and more.</p><p class="paragraph" style="text-align:left;">All from periodic 5 minute conversations.</p><p class="paragraph" style="text-align:left;">It makes me think that most people probably have a lot to open up and share about, if you create a little space for it.</p><p class="paragraph" style="text-align:left;">Anyway, I’m not saying frozen yogurt is the key to adult friendship, but I’m not <i>not</i> saying that.</p><p class="paragraph" style="text-align:left;">Maybe community is built less through grand gestures, and more through remembering someone’s name, asking one more question, and occasionally adding baklava.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>State of AI in the Cloud 2026:</b><br><b> How AI Is Reshaping Cloud Security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI is no longer a standalone tool, it’s embedded across cloud environments, development workflows, and production systems.</p><p class="paragraph" style="text-align:left;">The State of AI Report reveals how AI adoption is expanding the attack surface, accelerating attacker behavior, and introducing new risks through agents, copilots, and automation.</p><p class="paragraph" style="text-align:left;">Get the data behind what’s changing and what security teams need to do about it.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY27Q1_INB_FORM_State-of-AI-Report-2026&sfcid=701Vh00000aV1zBIAS&utm_term=FY27Q2-tldrsec-nl-May&utm_content=State-of-AI-Report-2026" target="_blank" rel="noopener noreferrer nofollow"><b>Read the Report</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Hm some interesting stats here: “AI is now core operational infrastructure.” ~80% of orgs use AI IDE extensions, and its impact on security is… 👆️ </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://shubs.io/the-down-fall-of-bug-bounties?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">The down fall of bug bounties</a><br><span style="text-decoration:line-through;">Assetnote</span> Searchlight Cyber’s <a class="link" href="https://www.linkedin.com/in/shubhamshah/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Shubham Shah</a> reflects on how AI has impacted bug bounty: <span style="background-color:#ffffff;">skilled researchers are submitting higher quality reports faster with AI assistance, but platforms are overwhelmed by low-quality AI-generated submissions. Shubz isn’t pleased with current solutions from HackerOne (fighting AI with AI) and Bugcrowd (spam controls), finding despite him hacking on Uber’s bug bounty program for almost ten years and ranked #1 on their public program, and his recent high impact submission took 12 days to get a response instead of previously 1-3 days.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://oblique.security/blog/policy-rollout?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">The security policy rollout survival guide</a><br>The blog version of Oblique&#39;s <a class="link" href="https://linkedin.com/in/mayakaczorowski?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Maya Kaczorowski</a>’s BSidesSeattle talk. Maya o<span style="background-color:#ffffff;">utlines a practical framework for rolling out security policies, emphasizing that successful implementation requires getting stakeholder input from engineering, product, SRE, and IT before defining controls, then running a pilot with representative users across diverse roles and platforms to identify edge cases and validate that controls actually work. </span></p><p class="paragraph" style="text-align:left;"><span style="background-color:#ffffff;">She emphasizes the importance of communicating changes through multiple channels (email, Slack, all-hands), making policy enforcement visible to users so they can see how they compare to peers, and ensuring the policy owner (not IT) handles ongoing enforcement and user friction. </span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">How OLTs may have exposed entire ISP networks</a><br>Quarkslab&#39;s Mathieu Farrell describes a chain of pre-auth RCEs against network vendor VSOL&#39;s GPON OLT (Gigabit Passive Optical Network Optical Line Terminal) hardware and its Cloud EMS fleet manager that together can take over an ISP&#39;s entire fiber network.</p><p class="paragraph" style="text-align:left;">Farrell found three pre-auth command injection bugs in the V1600 OLT models (SNMP traceroute, TACACS+ login, web traceroute), all share the same default admin credentials hardcoded in the firmware, <span style="background-color:#ffffff;">plus an arbitrary file upload RCE in Cloud EMS that allows JSP webshell deployment with root access. The post shows how attackers could chain these vulnerabilities, starting from exposed OLTs or the cloud manager, to compromise entire fleets of devices across ISPs in countries including the US, India, Turkey, Taiwan, Brazil, and Mexico.</span></p><p class="paragraph" style="text-align:left;">💡 Yikes 😅 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Are your developers -- </b><br><b>dangerously-skipping-permissions yet?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Agents writing code is easy. Trusting what those agents are doing is hard. Minimal hands your devs isolated, declarative environments that run identically for humans, agents, and CI. Reproducible by default, local first.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><b><a class="link" href="https://minimal.dev/?utm=tldr&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Learn more</a></b><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">OK this looks really cool. Performant + sandboxed local dev environment, curated open-source packages compiled from source (in a SLSA-compliant environment), network connectivity and filesystem access must be explicitly declared in Build Specifications and more.</p><p class="paragraph" style="text-align:left;">I got nerd sniped reading about Minimal, sounds thoughtfully designed for both engineering and security. I’m going to read more about this later.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@brookejamieson/awstrology-what-star-sign-is-every-aws-service-908c417e65a6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">AWStrology: What Star Sign Is Every AWS Service?</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://awsforidiots.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">AWS for Idiots</a> - AWS described via comics</p></li><li><p class="paragraph" style="text-align:left;">Corey Quinn - <a class="link" href="https://www.lastweekinaws.com/blog/s3-is-not-a-filesystem-but-now-theres-one-in-front-of-it?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">S3 Is Not a Filesystem (But Now There’s One In Front of It)</a> - “…AWS pricing is where dreams go to get itemized.” 😂 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.beyondtrust.com/blog/entry/aws-bedrock-security-guide-api-keys-detection-response?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">The AWS Bedrock API Keys Security Guide Part 2: Detection, Prevention, and Response</a><br>BeyondTrust&#39;s <a class="link" href="https://www.linkedin.com/in/mrcloudsec/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Sergio Garcia</a> continues his team&#39;s AWS Bedrock API key research with a follow-up covering detection, defense, response, and migrating to STS. The post includes CloudWatch Logs Insights queries, EventBridge patterns, and SIEM rules to identify unauthorized usage of bearer tokens, including detection logic for privilege escalation attacks where attackers create IAM access keys for BedrockAPIKey-* users, anomalous usage patterns based on IP ranges and operating hours, and suspicious user agents like python-requests or curl instead of AWS SDKs. The post concludes with defense controls (SCPs, model invocation logging) and incident response approaches.</p><p class="paragraph" style="text-align:left;">The BeyondTrust team has also released <a class="link" href="https://github.com/BeyondTrust/bedrock-keys-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Bedrock Keys Security</a>, an open-source CLI covering that can detect phantom IAM users, decode leaked AWS Bedrock API keys, + SCPs + SIEM detection rules.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/git-pkgs/proxy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">git-pkgs/proxy</a><br>Tool by <a class="link" href="https://x.com/teabass?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Andrew Nesbitt</a> that runs as a caching proxy for 20+ package registries (npm, Cargo, PyPI, Maven, NuGet, Docker/OCI, Debian/RPM) with a configurable version cooldown that quarantines newly published packages for a set period before they&#39;re available to builds. It supports per-package cooldown overrides, SBOM-driven cache pre-population, a REST API for vulnerability scanning, and Prometheus metrics.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://tracebit.com/blog/detecting-cicd-supply-chain-attacks-with-canary-credentials?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Detecting CI/CD Supply Chain Attacks with Canary Credentials</a><br>Tracebit&#39;s <a class="link" href="https://www.linkedin.com/in/alessandro-brucato/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Alessandro Brucato</a> released a free GitHub Action that drops canary AWS credentials and SSH keys into CI/CD workflows to detect credential exfiltration from compromised pipelines. The action writes canaries to <code>~/.aws/credentials</code>, <code>~/.ssh</code>, environment variables, and runner process memory at workflow start, then alerts when any of them is used. Alessandro validated it against the TeamPCP supply chain campaign that compromised Trivy, KICS, LiteLLM, and Telnyx and confirmed the canaries would have caused alerts capturing the affected repo, workflow, job, commit SHA, run ID, and attacker IP.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.o3c.no/knowledge/unmasking-the-docker-onbuild-supply-chain-attack-vector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Unmasking the Docker ONBUILD Supply Chain Attack Vector</a><br>O3-Cyber&#39;s <a class="link" href="https://www.linkedin.com/in/audun-blichfeldt-mo-b01713185/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Audun Mo</a> describes how Docker&#39;s ONBUILD directive creates a hidden supply chain attack vector. When a parent Docker image contains ONBUILD instructions, those commands automatically execute during downstream builds with complete access to the child project&#39;s files, environment variables, and secrets. Mo demonstrates three attack patterns, including stealing build secrets by accessing common secret identifiers (<code>npm_token</code>, <code>github_token</code>) and sending them to external servers via curl, manipulating project dependencies by modifying <code>package.json</code> files to pin vulnerable software versions, and achieving RCE by injecting malicious commands through <code>curl | sh</code>.</p><p class="paragraph" style="text-align:left;">O3-Cyber released <a class="link" href="https://github.com/o3-cyber/onbuild-guardian?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Onbuild Guardian</a>, an open-source tool that examines Docker images using <code>docker inspect</code> to identify and manage ONBUILD instructions through allowlists. Mo recommends pinning base images by SHA256 digest rather than tag, and using secret mounts rather than ENV, ARGs, or .env files.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://beelzebub.ai/blog/llm-honeypot-vs-cryptojacking-understanding-the-enemy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">LLM Honeypot vs. Cryptojacking: Understanding the Enemy</a><br>Beelzebub&#39;s <a class="link" href="https://www.linkedin.com/in/mario-candela/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Mario Candela</a> deployed his low-code <a class="link" href="https://github.com/beelzebub-labs/beelzebub?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">SSH LLM honeypot</a> with GPT-4o and a list of weak passwords to attract bots. It logged a cryptojacking bot&#39;s full attack chain. The bot fingerprinted the kernel and GPU, swapped the root password and killed prior miners with pkill, then downloaded a c3pool installer tied to a hardcoded Monero wallet that had accumulated roughly 20 XMR (~$4,126). Candela reported the wallet to c3pool, who pulled every infected miner using it.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://posts.inthecyber.com/tales-of-an-ollama-honeypot-part-1-abuse-patterns-29ba0b000b7f?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Tales of an Ollama Honeypot (Part 1): Abuse Patterns</a><br><a class="link" href="https://www.linkedin.com/in/marco-pedrinazzi/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Marco Pedrinazzi</a> deployed an Ollama honeypot on a VPS, let Censys and Shodan index it, and logged 6,461 events from 324 unique IPs over 32 days. Most IPs enumerated the server, then sent short liveness prompts like greetings or arithmetic to see whether it was worth deeper testing, hitting both Ollama&#39;s native API and its OpenAI-compatible endpoints. The honeypot also caught prompt injection wrapped in fake &quot;security audit&quot; pretexting to extract system prompts and environment variables, local file disclosure via malicious Modelfiles, and SSRF probes via <code>/api/pull</code> and <code>/api/push</code>.</p><p class="paragraph" style="text-align:left;">Marco has also published three detection rules for <a class="link" href="https://novahunting.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">NOVA</a>, an open-source prompt-pattern-matching framework, covering credential harvesting (env dumps, K8s tokens, cloud metadata URLs), system prompt and Modelfile disclosure, and liveness probing, designed for honeypot deployment.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">AI-powered honeypots: Turning the tables on malicious AI agents</a><br>Cisco Talos&#39;s Martin Lee walks through how generative AI can rapidly deploy adaptive honeypots that masquerade as full computing environments. His implementation combines a listener that accepts network connections, a simulated vulnerability that grants access once triggered, and an AI framework that responds to attacker instructions. By swapping the AI&#39;s system prompt, the same code can impersonate a Linux bash shell or a BusyBox-based smart fridge, creating what Martin calls a &quot;hall of mirrors&quot;, a controlled environment where attackers see plausible but distorted reflections of real targets and reveal their methodologies in real time. AI-orchestrated attacker tooling trades stealth for speed, making them easier to detect, and the AI agents lack the awareness to spot a fake environment once they arrive.</p><p class="paragraph" style="text-align:left;">💡 AI is making honeypots and deception much simpler to do at scale and convincingly. Lots of cool work to be done here.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/C0axx/CanaryHunter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">C0axx/CanaryHunter</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/c0ax/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Curtis Ringwald</a> for red teamers to spot common canary tokens in docs, configs (AWS, WireGuard, Kube), the Registry, and MySQL dumps before triggering them, with a firewall rule that drops outbound traffic to every known canary IP.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/0xNslabs/CanaryTokenScanner?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">0xNslabs/CanaryTokenScanner</a><br>Tool by <a class="link" href="https://www.linkedin.com/company/neroteam/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">NeroTeam Security Labs</a> to spot embedded canary tokens and tracking URLs inside Office documents (.docx, .xlsx, .pptx) and PDFs before opening them. The scanner reads Office files as ZIP archives in memory and searches PDFs across both raw bytes and Flate/deflate-decompressed streams, filtering common schema domains to cut false positives.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/xFreed0m/ghosttype?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">xFreed0m/ghosttype</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/freed0m/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Roei Sherman</a> that extracts credentials from AI tool conversation history for Claude Code, Cursor, Codex CLI, and ChatGPT Desktop. Detection runs TruffleHog as a subprocess in filesystem mode for its 800+ detectors and live verification against provider APIs, paired with an in-tree pattern engine (30 regexes plus 10 heuristic patterns) for loose context signals TruffleHog misses. Findings from either engine link back to the source conversation file with severity, detector name, and verification status, so triage can filter to credentials the provider confirms are live.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b> </p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.jamesshore.com/v2/blog/2026/you-need-ai-that-reduces-your-maintenance-costs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">You Need AI That Reduces Maintenance Costs</a> - “The math only works if the LLM <i>decreases</i> your maintenance costs, and by exactly the inverse of the rate it adds code.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nudgesecurity.com/content/practitioners-guide-to-agentic-ai-security?utm_medium=sponsored&utm_source=tldr&utm_content=newsletter&utm_campaign=ai_security&utm_term=agentic-ai-security-pdf" target="_blank" rel="noopener noreferrer nofollow"><b>[Free Guide] The 4 steps to get ahead of agentic AI risks </b></a><b>- </b>Agentic AI is already inside your organization. And most of the time, nobody in IT or security approved it. This free guide is for security, IT, and risk leaders who need to get ahead of agentic AI, before it becomes a liability.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/oT1BI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web</a> - RedAccess’ Dor Zvi found &gt;5K apps from Lovable, Replit, Base44, and Netlify had “no security or authentication”, leaked PII, were phishing sites, etc.</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/malicious-skills-supply-chain-risks-in-coding-agents-with-dynamic-context?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Malicious Coding Agent Skills and the Risk of Dynamic Context</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/nick-frichette?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Nick Frichette</a> and <a class="link" href="https://www.linkedin.com/in/ryan-simon-2767bb15/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Ryan Simon</a> demonstrate how malicious Claude Code skills can bypass model-level prompt injection defenses <span style="background-color:#ffffff;">using dynamic context commands (</span><code>!ls</code><span style="background-color:#ffffff;"> syntax), which execute before the model reviews the skill content. They analyzed the Clawsights skill, a real-world credential theft attempt that exfiltrates GitHub tokens, finding that while Claude Opus 4.6 correctly identified and blocked the original malicious skill, adding dynamic context commands allowed the attack to succeed because those commands run during preprocessing.</span></p><p class="paragraph" style="text-align:left;"><span style="background-color:#ffffff;">Recommendations: organizations can mitigate this by setting </span><code>&quot;disableSkillShellExecution&quot;: true</code><span style="background-color:#ffffff;"> in managed settings, review </span><code>.claude/skills/</code><span style="background-color:#ffffff;"> directories (including nested folders and </span><code>--add-dir</code><span style="background-color:#ffffff;"> paths), require code review for </span><code>.claude/</code><span style="background-color:#ffffff;"> changes, and monitoring for suspicious patterns like </span><code>allowed-tools: Bash(*)</code><span style="background-color:#ffffff;">, external URLs, and commands performing reconnaissance or attempting network access.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://heyitsas.im/posts/drinking-llms?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)</a><br><a class="link" href="https://www.linkedin.com/in/yasamal4ik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Asim Viladi</a> built a multi-agent LLM harness that has turned up 30+ findings (20+ CVEs) over the past few months, mostly in network-reachable services. Originally aimed at documentation-code mismatches, the harness two remote unauthenticated out-of-bounds writes in the Linux kernel&#39;s ksmbd and a chained unauthenticated RCE-to-root path in CUPS.</p><p class="paragraph" style="text-align:left;">Under the hood, the harness chains a target seeder, hypothesis generators reading docs and source for invariants, hunters iterating PoCs in isolated VMs, report writers, and a conductor redirecting stuck agents, with an external grader outside the loop because frontier models will otherwise inflate findings or edit their own objectives. Asim also tried activation steering on the hypothesis generator, both drunkenness for creativity and abliteration to bypass refusals. The drunkenness produced no new vulnerability classes and abliteration ended up being more useful, making models refuse less.</p><p class="paragraph" style="text-align:left;">Asim found granular role separation most helps smaller models, as swapping in Codex or Claude collapses the harness into a single end-to-end hunter. In some cases smaller models running for days can match what a frontier model one-shots. Asim&#39;s next bets are looped LLMs and RL-trained task decomposition, which would let models do their own scaffolding instead of needing hand-tuned harnesses.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark</a><br>Microsoft&#39;s Autonomous Code Security team, led by <a class="link" href="https://www.linkedin.com/in/tsgatesv?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Taesoo Kim</a>, built MDASH, their multi-model agentic scanning harness, which has found 16 new Windows vulnerabilities across the networking and authentication stack including four RCEs.</p><p class="paragraph" style="text-align:left;">MDASH is structured as an agentic discovery and remediation pipeline that scans, debates, deduplicates, and proves candidate findings, chaining 100+ specialized AI agents across an ensemble of frontier and distilled models, with extensible plugins for Microsoft-specific context foundation models may not have. On benchmarks, it found 21 of 21 planted vulnerabilities with zero false positives on a private test driver, hit 9^% (of 28) and 100% (of 7) confirmed MSRC cases in clfs.sys and tcpip.sys, and scored 88.45% on the public CyberGym benchmark of 1,507 real-world vulnerabilities (prior leader: 83.15%).</p><p class="paragraph" style="text-align:left;">The post argues that the orchestration/harness is critical and gives a performance boost over a base model + simple prompt, and that this architecture allows MDASH to absorb future model improvements without being rewritten.</p><p class="paragraph" style="text-align:left;">💡 Looks like Microsoft hired Taesoo Kim (the Georgia Tech professor whose Team Atlanta won DARPA’s AIxCC) + a bunch of that team, and that’s now the Microsoft Autonomous Code Security team. Neat. Looking forward to seeing more from them!</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/model-disproves-discrete-geometry-conjecture/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">An OpenAI model has disproved a central conjecture in discrete geometry</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/github/status/2056949168208552080?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">X thread</a>: GitHub employee had a poisoned VS Code extension → ~3,800 GitHub-internal repos exfiltrated</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/kageroumado/phosphene?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">kageroumado/phosphene</a> - A video wallpaper engine for macOS Tahoe</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.census.gov/newsroom/press-releases/2025/older-adults-outnumber-children.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Older Adults Outnumber Children in 11 States and Nearly Half of U.S. Counties</a> - And wait until you see Congress!</p></li><li><p class="paragraph" style="text-align:left;">Jen Easterly: <a class="link" href="https://www.linkedin.com/posts/jen-easterly_a-brief-note-to-new-cybersecurity-grads-activity-7392076035799883776-OhKo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">A brief note to new cybersecurity grads trying to land that first job</a> - Don’t compete with AI, learn to lead it. Strengthen your technical foundation. Go where the growth is (go to areas that are exploding, not saturated). Find opportunities to build experience.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/3N_oWQCmTYg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Advice Jeff Bezos received early at Amazon</a>: “You have enough ideas to destroy Amazon.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/wrlovely/years?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">wrlovely/years</a> - A personal longevity system built on Claude Code. Your DNA, bloodwork, scans, and visit notes live as markdown in a private git repo, with slash commands to organize and analyze them.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/typefully/minimal-twitter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">typefully/minimal-twitter</a> - Minimal theme for Twitter.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/BJLFfkGHWUU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Beatboxing with a dog</a> 😂 </p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AI + Design</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;">Claude Code <a class="link" href="https://github.com/anthropics/claude-code/blob/main/plugins/frontend-design/skills/frontend-design/SKILL.md?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">frontend-design Skill</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/claude-design-anthropic-labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Introducing Claude Design by Anthropic Labs</a> - Collaborate with Claude to create polished visual work like designs, prototypes, slides, one-pagers, and more.</p></li><li><p class="paragraph" style="text-align:left;">OpenAI docs - <a class="link" href="https://developers.openai.com/blog/designing-delightful-frontends-with-gpt-5-4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Designing delightful frontends with GPT-5.4</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/cyxzdev/Uncodixfy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">cyxzdev/Uncodixfy</a> - A rule set that forces Codex models to stop relying on its usual UI habits.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/introducing-chatgpt-images-2-0/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Introducing ChatGPT Images 2.0</a> - Some pretty impressive example images</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.adriankrebs.ch/blog/design-slop/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">An attempt to detect AI design patterns in Show HN pages</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=52a3efa6-9d7a-45c3-ab83-62f9caf93739&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #328 - Shai-Hulud&#39;s Source Code Leaked, Break Into Buildings for $, Reversing EDRs with AI</title>
  <description>Teardown of TeamPCP&#39;s offensive framework that was briefly published on GitHub, Reddit AMA on a career in physical penetration testing, the end of &quot;opaque defense&quot;: AI makes understanding defensive tool implementations easy </description>
  <link>https://tldrsec.com/p/tldr-sec-328</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-328</guid>
  <pubDate>Thu, 14 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-14T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">☀️ My Least Favorite Type of Tan(Stack)</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I had a fun personal anecdote to share but I didn’t have time to write it up this week.</p><p class="paragraph" style="text-align:left;">For now, #HugOps to everyone dealing with yet another supply chain attack.</p><p class="paragraph" style="text-align:left;">I hope you’re getting the support you need 🫂 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ddcddfa4-566a-4ef1-853c-2086e9d67b47/image.png?t=1778744578"/></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Cloud Security Has Changed. </b><br><b>Has Your Strategy?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Agentic AI is reshaping cloud risk. AI agents, machine identities, and distributed data systems are creating new privilege pathways, dark data, and attack surfaces that traditional posture tools were not built to govern. Join Palo Alto Networks product leaders to learn how Cortex Cloud helps teams secure identity, data, and AI across the modern cloud stack.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.paloaltonetworks.com/resources/webcasts/transforming-posture-security-for-the-modern-cloud-stack?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai#" target="_blank" rel="noopener noreferrer nofollow"><b>Watch Webinar</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Hm I am curious about modern security posture strategies and dynamically enforcing least privilege 🤔 Seems important with agents potentially running amok.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/V4bel/dirtyfrag?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">V4bel/dirtyfrag</a><br>Dirty Frag, discovered and reported by <a class="link" href="https://x.com/v4bel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Hyunwoo Kim</a>, is a universal Linux LPE vulnerability class that chains two page-cache write bugs (xfrm-ESP and RxRPC) to achieve deterministic root privilege escalation without race conditions across major distributions including Ubuntu, RHEL, Fedora, and openSUSE.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reversinglabs.com/blog/copy-fail-5-yara-rules?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Copy Fail Flaw: 5 YARA Rules for Detection and Remediation</a><br>ReversingLabs&#39; <a class="link" href="https://www.linkedin.com/in/maik-morgenstern/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Maik Morgenstern</a> covers Copy Fail (CVE-2026-31431), a Linux kernel privilege escalation that lets any unprivileged user write 4 bytes into the in-memory copy of any readable file, including system binaries like /usr/bin/su. That&#39;s enough to neuter the password check, so the next run of su returns a root shell. The on-disk file is never touched, so standard file integrity tools see nothing. The exploit runs identically on every major Linux distribution shipped since 2017, making shared-kernel environments (multi-tenant servers, CI/CD pipelines, container clusters) the highest-risk targets.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Within a day, ReversingLabs had observed more than a dozen variants in the wild, including compiled C reimplementations of the original PoC and a separate rootsecdev toolkit that targets /etc/passwd instead of /usr/bin/su. Most were trivial reformattings with different hashes but identical execution, so ReversingLabs built a five-tier YARA ruleset anchored on a cryptographic string the exploit fundamentally depends on. High-confidence rules catch the original Theori PoC and the rootsecdev toolkit. Medium-confidence rules cover reimplementations of the core technique along with compiled and dropper variants. A broad hunting rule covers Python, C, and Go variants that combine the cryptographic string with a known target binary.</p></div><p class="paragraph" style="text-align:left;">For the full technical breakdown, see <a class="link" href="https://copy.fail/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Theori&#39;s writeup at </a><a class="link" href="https://copy.fail?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">copy.fail</a> and the <a class="link" href="https://github.com/theori-io/copy-fail-CVE-2026-31431?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">original PoC</a>. More from <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Microsoft</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/microsoft/AntiSSRF?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">microsoft/AntiSSRF</a><br>The DevSec team at Microsoft recently open-sourced secure by default libraries that mitigate the risk of Server-Side Request Forgery in cloud-hosted applications. Currently available for .NET and NodeJS applications, the libraries provide durable protection against common SSRF bypass patterns including HTTP redirects and DNS rebinding, with more languages planned for the future. Microsoft also released <a class="link" href="https://github.com/microsoft/dusseldorf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Dusseldorf</a>, a dynamic SSRF testing tool for verifying that AntiSSRF is doing its job.</p><p class="paragraph" style="text-align:left;">H/T <a class="link" href="https://www.linkedin.com/in/247arjun/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Arjun Gopalakrishna</a> and his team for AntiSSRF, and <a class="link" href="https://www.linkedin.com/in/ndrix/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Michael H.</a> and his team for Dusseldorf.</p><p class="paragraph" style="text-align:left;">💡 If I had to choose between a) getting my favorite dessert and b) having a new, tested, secure-by-default library to eliminate a class of vulnerabilities, I’d choose the latter. For a delicious apple crumble pie straight from the oven is delectable once, while foiling a vulnerability class fills the soul 😍 More like this please!</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Browser & identity attacks matrix — </b><br><b>open-source from Push Security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Most attack frameworks weren&#39;t built for how breaches actually happen today. Attackers don&#39;t need network access or endpoint compromise; they go straight for the browser and identity layer. Push Security&#39;s Browser & Identity Attacks Matrix maps </span><span style="color:#222222;"><b>51 techniques across 10 tactic phases</b></span><span style="color:#222222;">, covering AiTM phishing, ClickFix, device code phishing, OAuth consent abuse, extension supply chain attacks, and more.</span></p><p class="paragraph" style="text-align:left;"><span style="color:#222222;">It&#39;s open-source, community-maintained, and built for how modern attacks actually work.</span></p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.li/Q04f_q890?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow"><b>Map your identity attack surface</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">This is super cool! Probably the best breakdown I’ve seen of modern browser and identity based attacks, including some subtle stuff + a number that Push Security discovered iirc. And neat that it’s open source 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://docs.cloud.google.com/docs/security/threat-model/bigquery-threat-model?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">BigQuery threat model report</a><br>Google Cloud published a threat model for BigQuery covering 14 attack vectors across data confidentiality, integrity, and availability, each mapped to STRIDE categories and MITRE ATT&CK tactics. The model surfaces schema tampering to corrupt downstream pipelines, privilege escalation and service account impersonation, data exfiltration via export jobs to attacker-controlled Cloud Storage buckets, persistence through hard to detect IAM bindings on datasets or scheduled queries, spoofing via leaked service account keys or OAuth tokens, and cost-based denial of service from resource-intensive queries that drain on-demand budgets or starve slot capacity for other users.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The recommended mitigations are mostly standard cloud hygiene anchored in BigQuery specifics, including least privilege IAM with regular audits via Security Command Center, VPC Service Controls perimeters to limit egress, Cloud Audit Log monitoring for suspicious calls like <code>SetIamPolicy</code> and <code>datasets.patch</code>, Workload Identity Federation instead of service account keys, custom query quotas to bound DoS impact, and table snapshots for recovery.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/doyensec/cloudsec-tidbits?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">doyensec/cloudsec-tidbits</a><br><a class="link" href="https://doyensec.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Doyensec</a> maintains CloudSec Tidbits, a blog series and Infrastructure as Code (IaC) lab collection covering cloud security bugs that happen when the infrastructure is correctly configured but the web app misuses the cloud services. The three prior episodes cover falling back to the system role in AWS SDK clients, tampering with AWS Cognito user pool attributes, and privilege escalation via AWS Batch. Each post ships with a deployable lab so you can reproduce the vuln yourself.</p><p class="paragraph" style="text-align:left;">💡 I previously included this in <i>tl;dr sec</i> but sharing again due to the new lab described more below.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/05/05/cloudsectidbits-masso-cognito-sso.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">The Danger of Multi-SSO AWS Cognito User Pools</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/francesco-lacerenza/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Francesco Lacerenza</a> and <a class="link" href="https://www.linkedin.com/in/ouadmoha/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Mohamed Ouad</a> analyzed multi-tenant AWS Cognito User Pool deployments where multiple external IdPs (OIDC and SAML) are registered against a single pool, and found several attack paths that open up when one of those IdPs becomes malicious or compromised.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The vulnerabilities include “JIT ghost identity” creation, provider collision via Unicode homoglyphs (one IdP using a Cyrillic character that passes as distinct from its ASCII twin), username parsing attacks where security checks and downstream code disagree on the<code> &lt;ProviderName&gt;_&lt;sub&gt;</code> format, and IdP identifier hijacking where unclaimed email domains route auth flows to providers an attacker controls. All four come from the same mistake. Security sensitive attributes like tenantID or role get read straight from federated tokens an attacker controls, rather than computed on the server from a verified email domain. AttributeMapping makes this worse. A malicious IdP can inject arbitrary values into custom user attributes, bypassing Cognito&#39;s write controls.</p></div><p class="paragraph" style="text-align:left;">Doyensec also released <a class="link" href="https://github.com/doyensec/maSSO?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">maSSO</a>, a weaponized OIDC/SAML/SCIM IdP testing tool, plus a <a class="link" href="https://github.com/doyensec/cloudsec-tidbits/tree/main/lab-masso?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Terraform lab</a> for reproducing these attacks.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>, <a class="link" href="https://linkedin.com/in/amitaico?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Amitai Cohen</a>, and <a class="link" href="https://www.linkedin.com/in/benjamin-read-41817121/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Benjamin Read</a> describe the most recent Internet-is-on-fire npm supply chain attack by TeamPCP that compromised TanStack, UiPath, and Mistral AI packages. The GitHub Actions exploit chain: the forked a repo and renamed it (to evade fork-list searches), oopened a PR that triggered the <code>pull_request_target</code> workflow, the attacker’s fork code poisioned the GitHub Actions cache with a malicious pnpm store, and when a legitimate maintainer PR was later merged into <code>main</code>, the release workflow restored the poisoned cache. The attacker-controlled binaries then extracted OIDC tokens directly from runner process memory to publish malicious packages without stealing npm credentials. The post provides IOCs, detection guidance, and remediation steps.</p><p class="paragraph" style="text-align:left;">YMMV but I came across these: </p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/GLPMC/Tanstack-Worm-Detector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">GLPMC/Tanstack-Worm-Detector</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/omarpr/mini-shai-hulud-ioc-scanner?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">omarpr/mini-shai-hulud-ioc-scanner</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Shai-Hulud Goes Open Source</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/ryan-simon-2767bb15/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Ryan Simon</a>, <a class="link" href="https://linkedin.com/in/sebastianobregoso?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Sebastian Obregoso</a>, and <a class="link" href="https://www.linkedin.com/in/gregfoss/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Greg Foss</a> analyze the complete source code of the Shai-Hulud offensive framework attributed to TeamPCP, which was briefly published on GitHub before being removed. The TypeScript/Bun-based modular toolkit harvests credentials from 100+ file paths, extracts GitHub Actions Runner.Worker memory via <code>/proc/&lt;pid&gt;/mem</code>, enumerates AWS Secrets Manager/SSM across 17 regions, and exfiltrates data using hybrid encryption to <code>git-tanstack[.]com</code> or GitHub dead-drop repos. </p><p class="paragraph" style="text-align:left;">The framework poisons npm packages via stolen tokens and OIDC abuse while forging complete Sigstore provenance bundles (Fulcio certificates + Rekor transparency logs), establishes persistence through VSCode tasks and Claude Code <code>SessionStart</code> hooks, and implements a destructive deadman switch (<code>rm -rf ~/</code>) that triggers on GitHub token revocation. 19 of 22 previously documented TeamPCP TTPs are present in the codebase.</p><p class="paragraph" style="text-align:left;">💡 Great breakdown, and honestly pretty thoughtful tooling.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/ridgelinecyberdefence/vanguard?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">ridgelinecyberdefence/vanguard</a><br>Tool that packs the full incident response lifecycle into a single Go binary, including Velociraptor, Volatility, KAPE, and the standard forensics stack, plus 28 MITRE-mapped IR use cases (ransomware, BEC, lateral movement, credential theft, rootkit detection). Runs on Windows or Linux with built-in case management, tamper-evident evidence handling, and full air-gapped support.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/gadievron/honeyslop?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">gadievron/honeyslop</a><br><a class="link" href="https://www.linkedin.com/in/gadievron/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Gadi Evron</a>, <a class="link" href="https://www.linkedin.com/in/john-cartwright-02201a1/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">John Cartwright</a>, <a class="link" href="https://www.linkedin.com/in/daniel-cuthbert0x/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Daniel Cuthbert</a>, and <a class="link" href="https://www.linkedin.com/in/michal-kamensky-a65804247/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Michal Kamensky</a> created honeyslop, a collection of deliberately vulnerable-looking code canaries designed to identify AI-hallucinated vulnerability reports by embedding unique UUIDs, fake function names (like <code>zqx_tarnish_v3</code>), and a fabricated CVE-2025-99919 that self-identify slop reports when grep&#39;d.</p><p class="paragraph" style="text-align:left;">💡 “Quick PoC, vibe-coded as a joke (not production-grade),” but I like the idea.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/referefref/OpenAIPot?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">referefref/OpenAIPot</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/jbrine/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">James Brine</a> that poses as an OpenAI-compatible API endpoint to catch attackers using stolen or planted credentials. Valid keys pass through to OpenAI, while decoy keys trigger a system prompt swap that injects deceptive content into the response. Repeat attempts trigger IP blocking with realistic out-of-tokens errors so attackers don&#39;t realize they&#39;ve been caught, and logs feed into SIEMs and Slack via integrations mapped to MITRE Engage.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reddit.com/r/cybersecurity/comments/1t4cwvj/we_get_paid_to_break_into_buildings_for_a_living?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">We get paid to break into buildings for a living. Ask us anything!</a><br>Reddit AMA with TrustedSec&#39;s <a class="link" href="https://www.linkedin.com/in/paul-koblitz-33701083/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Paul Koblitz</a>, <a class="link" href="https://www.linkedin.com/in/costa-petros-4122659/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Costa Petros</a> and <a class="link" href="https://www.linkedin.com/in/david-boyd-1a464936/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">David Boyd</a> answering questions about physical penetration testing, drawing on years of experience breaking into buildings for clients.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://dreadnode.io/research/redefining-ai-red-teaming-in-the-agentic-era?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Redefining AI Red Teaming in the Agentic Era</a><br>Dreadnode&#39;s <a class="link" href="https://www.linkedin.com/in/raja-sekhar-rao-dheekonda-8461a241/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Raja Sekhar Rao Dheekonda</a> released an agentic AI red teaming system built on their open-source SDK (45+ attack strategies, 450+ prompt transforms, 130+ scorers). The operator describes the objective in plain English, and the agent selects attacks and transforms, generates an executable workflow, runs it with full tracing, and returns a structured assessment with severity ratings and compliance tags. That&#39;s the orchestration work operators currently do by hand with frameworks like PyRIT, Garak, and Promptfoo. The methodology and full attack catalog can be found in <a class="link" href="https://arxiv.org/abs/2605.04019?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">the arXiv paper</a>.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">In a case study against Meta&#39;s Llama Scout, the agent ran 674 attacks across 68 harmful-content objectives in 3 hours with zero code, succeeding 85% of the time and identifying 232 critical findings. Across the three jailbreak strategies tested, Crescendo (gradual conversational escalation) and Graph of Attacks (exploring prompt variations) both hit 100%, while Tree of Attacks (branching prompt search) needed about three times as many tries to reach 96%. Even asking plainly, with no jailbreak technique at all, still produced harmful content 80% of the time.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://trustedsec.com/blog/the-defensive-stack-is-exposed?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">The Defensive Stack is Exposed: LLMs, Reverse Engineering, and the End of Opaque Defense</a><br>TrustedSec&#39;s <a class="link" href="https://www.linkedin.com/in/justinelze/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Justin Elze</a> ran LLMs against five commercial endpoint products and found that reverse engineering defensive products like EDRs used to take skilled reverse engineers weeks, now takes days with the right workflow and the right questions. The same approach worked on all five EDRs because they&#39;re built the same way: YARA-style rules, behavioral logic, allowlists, prefilters, scripted engines (some shipped as readable Lua after one decryption pass), and local ML classifiers, all of it sitting on or near the host where it can be studied. See Justin’s <a class="link" href="https://gist.github.com/HackingLZ/8956b015a55412522d22a88e0dd284fc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">EDR Reverse Engineering Skill</a> and this <a class="link" href="https://gist.github.com/HackingLZ/a9f71c8ea7bd6d867765bda0af2460f6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">complete workflow</a> for reverse engineering an EDR.</p><p class="paragraph" style="text-align:left;">Once that logic is reachable, rules and scoring thresholds get extracted, exclusion lists and trust paths reveal the least-monitored path through the system, update diffs expose what the vendor quietly fixed, and the same analysis surfaces product-specific vulnerabilities in parsing, IPC, and kernel callbacks.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Elze recommends leaning on layers attackers can&#39;t study as easily: host hardening (WDAC, ASR rules, LSA Protection), SIEM detections built on raw telemetry rather than EDR verdicts, and identity-layer detection (Entra ID risk policies, token theft indicators, directory changes).</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div></div><p class="paragraph" style="text-align:left;">💡 Excellent article, I think it does a great job pointing out some prior security assumptions that are changing and what it means for defenders. And great, detailed section on what defenders should do. </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/distil-labs/distil-ai-slop-detector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">distil-labs/distil-ai-slop-detector</a><br>Chrome extension by <a class="link" href="https://www.linkedin.com/company/distil-labs/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Distil Labs</a> that detects AI-generated text with a smaller, 242MB fine tuned model (Gemma 3 270M with GPT OSS 120B (teacher)) that can run entirely in-browser, plus a Claude Desktop skill and CLI for training your own classifiers using the same distillation pipeline.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/daybreak/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Daybreak: Frontier AI for cyber defenders</a><br>OpenAI announces Daybreak, which seems like their version of Project Glasswing, with an extra focus on making software resilient by design. “Defenders can bring secure code review, threat modeling, patch validation, dependency risk analysis, detection, and remediation guidance into the everyday development loop so software becomes more resilient from the start.” Partner quotes from Cloudflare, Cisco, CrowdStrike, Palo Alto Networks, Oracle, Zscaler, Akamai, and Fortinet.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Mythos finds a curl vulnerability</a><br><a class="link" href="https://www.linkedin.com/in/danielstenberg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Daniel Stenberg</a> digs into the Mythos scan of curl&#39;s 178K lines of C. The report flagged five &quot;confirmed&quot; vulnerabilities, but after the curl security team&#39;s review three were documented API behavior, one was &quot;just a bug,&quot; and only one became a low-severity CVE. The results match what curl has already seen from AISLE, Zeropath, and OpenAI Codex Security, which together triggered 200 to 300 bugfixes over the past 8-10 months. Daniel so far finds that AI tools are good at finding usual and established kinds of errors, not (yet) finding novel kinds of bugs.</p><p class="paragraph" style="text-align:left;">“My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos.”</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Behind the Scenes Hardening Firefox with Claude Mythos Preview</a><br>Mozilla&#39;s <a class="link" href="https://www.linkedin.com/in/bgrins/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Brian Grinstead</a>, <a class="link" href="https://www.linkedin.com/in/christian-holler-b9001aa9/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Christian Holler</a>, and <a class="link" href="https://www.linkedin.com/in/frederik-braun-security/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Frederik Braun</a> detail how Mozilla built an agentic harness on top of their existing fuzzing infrastructure that writes and runs reproducible test cases to confirm bugs, scales across ephemeral VMs, and integrates with their security lifecycle for dedup, tracking, and triage. Running Claude Mythos Preview, Mozilla found 271 bugs in Firefox 150, including sandbox escapes, race conditions, and use-after-free bugs that fuzzers miss.</p><p class="paragraph" style="text-align:left;">Audit logs also validated existing defenses, showing the model repeatedly trying prototype pollution sandbox escapes only to get shut down by Mozilla&#39;s frozen-prototypes architecture. Looking ahead, Mozilla plans to wire the pipeline into CI to scan patches as they land, and recommends other projects build similar pipelines now.</p><p class="paragraph" style="text-align:left;">💡 Great example of the power of a <i>target-specific</i> (in this case, Firefox) harness providing additional value on top of a capable underlying model. I also liked: the description of building a hardening pipeline, how the right architecture eliminated <b>classes</b> of vulnerabilities, and more context around the number and type of bugs found.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/TbQn3n1lnWM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Interesting photography trick examples</a></p></li><li><p class="paragraph" style="text-align:left;">Aakash Gupta - The future of cinema is <a class="link" href="https://x.com/aakashgupta/status/2052161570571243947?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">ScreenX, a 270-degree field of view</a></p></li><li><p class="paragraph" style="text-align:left;">Relentless - <a class="link" href="https://www.youtube.com/watch?v=OQ0OOzOwsJY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">How to Start a Cult | Lulu Cheng Meservey</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=ypjTHjROQJU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Ari at Home meets Wayne Brady</a> - Freestyle creating beats and rapping</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/CeZa6a_VycA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Turning my toddler’s stories into songs</a> - Catchy actually, and 🥹</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/x9t90-beK_E?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Best Crazy Frog Remix</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/oZ2M1FoEcr8?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Why are chains used to guide rain down?</a> - Apparently someone is creating informational songs around random facts. Probably the music, script, and video shots are all AI generated. Kind of interesting though.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/facebookincubator/below?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">facebookincubator/below</a> - A time traveling resource monitor for modern Linux systems</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://about.gitlab.com/blog/gitlab-act-2/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">GitLab Act 2</a> - Open letter from GitLab that they’re restructuring, and a likely “workforce reduction”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cloudflare.com/building-for-the-future/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Building for the future</a> - Cloudflare is laying off 1,100 (~20%) employees to prepare for “the agentic AI era”</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://every.to/context-window/openai-flips-the-script?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">OpenAI Flips the Script</a> - Every CEO Dan Shipper explains why OpenAI’s coding app has become his daily driver for work, head of growth shares useful workflows.</p></li><li><p class="paragraph" style="text-align:left;">Fiona Fung, Eng Director for Claude Code - <a class="link" href="https://www.youtube.com/watch?v=igO8iyca2_g&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Running an AI-native engineering org</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/claude-for-creative-work?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Claude for Creative Work</a> - Anthropic released MCP connectors that integrate Claude with creative software including Blender, Autodesk Fusion, Adobe Creative Cloud, Ableton, Splice, SketchUp, Resolume, and Affinity by Canva.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/finance-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Agents for financial services and insurance</a> - Anthropic released ten agent templates for financial services workflows including pitch building, KYC screening, and month-end closing, available as plugins in Claude Cowork/Code or as cookbooks for Claude Managed Agents. Repo: <a class="link" href="https://github.com/anthropics/financial-services?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">anthropics/financial-services</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=3pkz-Ie_k_c&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Theo on Anthropic, Cursor, and xAI/SpaceX</a> - Some interesting (potential) dynamics I hadn’t though of</p></li><li><p class="paragraph" style="text-align:left;">Pieter Levels - <a class="link" href="https://x.com/levelsio/status/2046271694042505451?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Replaced all his Chrome extensions with his own vibe coded one</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://handyai.substack.com/p/your-ceo-is-suffering-from-ai-psychosis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Your CEO is suffering from AI psychosis</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=2be166d4-5bb5-4b53-841a-e631c851d438&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #327 - Finding Zero-days with Any Model, Practical Package Security, Measuring the AI Offense-Defense Gap</title>
  <description>Niels Provos on finding 0-days with public models, a guide to securing your use of third party packages, two open source tools to measure AI hacking vs defense (+ dynamic lab environment)</description>
  <link>https://tldrsec.com/p/tldr-sec-327</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-327</guid>
  <pubDate>Thu, 07 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-07T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🫶 Friend Visit</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Last weekend I visited my good friend Aaron and his partner, staying at their place in southern California, and it was <i>delightful</i>.</p><p class="paragraph" style="text-align:left;">There’s something special about meeting a friend’s partner and seeing their place, you get such a lovely insight into who they are and what they value. The bookshelves, the photos from their couple trips, the unique items they’ve picked up along the way.</p><p class="paragraph" style="text-align:left;">We played a few rounds of this board game, Forbidden Island, which was a lot of fun, would recommend. Clint analytical brain was fully engaged, and people were amused 😅 </p><p class="paragraph" style="text-align:left;">I managed to delay doing an AI-powered Deep Research about optimal strategies until I was at the airport on the way back. It wasn’t easy.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0efb304f-e03a-413b-947e-1449334ac1db/IMG_2202__1_.jpeg?t=1778138242"/></div><p class="paragraph" style="text-align:left;">Aaron was a work friend who became a normal friend over many Wednesday dinners. And after several months I got upgraded to his non burner phone (not a joke) 🙌 </p><p class="paragraph" style="text-align:left;">We had talked about me coming down to stay with him for a weekend… and I actually did it! It was kind of going out on a limb, as we’d never spent more than a few hours together at a time, but I’m really glad I did. We had a great time, and I feel like we grew a lot closer in just a few days.</p><p class="paragraph" style="text-align:left;">Maybe there’s someone you really click with at work or from some hobby, and if you put yourself out there and spend more time with them (even if it feels cringe to ask), that could end up being a great friendship 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> AI ROI: You know the AI bill, but what are the outcomes?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams can only answer with invoice data.</p><p class="paragraph" style="text-align:left;">Harmonic Security Usage Explorer closes that gap. It automatically classifies every AI interaction across your organization into the use cases driving real work, specific to your business. Get actual patterns to understand how your teams use AI, how much time they spend, the cost, and where risk lives.</p><p class="paragraph" style="text-align:left;">CIOs rationalize spend, CISOs get risk in context, & AI committees get proof of impact.</p><p class="paragraph" style="text-align:left;">Early access is now open. Request your spot.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.harmonic.security/understand-ai-usage-early-access?utm_campaign=tldrsec&utm_source=tldrsec&utm_medium=newsletter&utm_campaign=aiusageintelbeta" target="_blank" rel="noopener noreferrer nofollow"><b>Get early access</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Getting visibility into your company’s AI usage is actually pretty hard. See also a <a class="link" href="https://www.youtube.com/watch?v=5oy2-s6-tzQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Harmonic demo</a> I got from the CEO/co-founder Alastair Paterson, though I’m sure they do a lot more now.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://lab.ctbb.show/research/the-dot-dot-slash-that-frameworks-hand-you?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework</a><br><a class="link" href="https://x.com/xssdoctor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Jonathan Dunn</a> reverse-engineered the URL decoding pipelines of 8 major frontend frameworks (React Router, Next.js, Vue Router, Angular, SvelteKit, Nuxt, Ember, and SolidStart) to understand how Client Side Path Traversal (CSPT) vulnerabilities arise when encoded slashes (%2F) in dynamic route parameters get decoded and interpolated into fetch URLs. <a class="link" href="https://github.com/xssdoctor/cspt_research?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Labs GitHub repo</a>.</p><p class="paragraph" style="text-align:left;">💡 Wow, super detailed, awesome post. Also, <a class="link" href="https://x.com/xssdoctor/status/2040937315703377972?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">this story</a> about Jason Haddix’s mentorship 🥹</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">C/C++ checklist challenges, solved</a><br>Trail of Bits recently added a <a class="link" href="https://appsec.guide/docs/languages/c-cpp/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">C/C++ security checklist</a> to their Testing Handbook, and in this post, Graham Sutherland and Paweł Płatek share walkthroughs of two C/C++ challenges. They also released <a class="link" href="https://github.com/trailofbits/skills/tree/main/plugins/c-review?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">c-review</a>, a Claude skill that runs the C/C++ checklist as LLM prompts against a codebase, tuned to the platform and threat model.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The first challenge is a Linux ping program with a command injection bug, where two undocumented behaviors in standard IP address functions (one accepting trailing garbage, the other reusing a shared buffer between calls) let an attacker bypass the input validation. The second is a Windows driver where a missing safety flag and an incomplete registry read combine to escalate from a local crash to full kernel code execution. By planting two crafted registry values, an attacker tricks the driver into copying arbitrary data onto the kernel stack and overwriting a function pointer.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://vercel.com/blog/introducing-deepsec-find-and-fix-vulnerabilities-in-your-code-base?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Introducing deepsec: The security harness for finding vulnerabilities in your codebase</a><br><a class="link" href="https://linkedin.com/company/vercel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Vercel</a> announces <a class="link" href="https://github.com/vercel-labs/deepsec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">deepsec</a>, an open source security scanner that uses Claude Opus 4.7 and GPT-5.5 coding agents to identify vulnerabilities in codebases, running entirely on user infrastructure with the user&#39;s own Claude and OpenAI subscriptions. Internally, deepsec runs a regex sweep to flag security-sensitive files, then the agents investigate each candidate, tracing data flows and assessing severity. A refusal-detection classifier checks each research step, letting it run on off-the-shelf models in addition to cyber-tuned variants. </p><p class="paragraph" style="text-align:left;">The tool also ships with a revalidation step that reduces false positives to an estimated 10–20% in their experience, a plugin system (<a class="link" href="https://github.com/vercel-labs/deepsec/blob/main/docs/writing-matchers.md?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">docs</a>) for codebase-specific tuning, and parallel execution across Vercel Sandboxes for large repositories.</p><p class="paragraph" style="text-align:left;">💡 It’s interesting to see platforms like Vercel and Cursor launching security scanning services. The overall architecture makes sense and is in line with common approaches. It’d be nice if someone benchmarked all of these open source tools, Skills, products, etc. on the same targets and shared the results 👀 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Adaptive Security: Security Awareness Training Built for AI Threats</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI is changing how attacks are executed. Deepfakes, voice clones, and AI-generated spearphishing across email, SMS, and voice are now table stakes for attackers. Adaptive Security&#39;s next-generation platform simulates these exact threats, scores individual employee risk using real behavior and OSINT exposure, and auto-delivers personalized training tied to what each person experienced. Trusted by security teams at PayPal, Ramp, Bose, and more. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.adaptivesecurity.com/lp/nb/security-awareness-training?utm_source=sp_email&utm_medium=email&utm_campaign=2026_05_NA_TLDR%3Bsec_newsletter&utm_id=701Rd00000guu14IAA" target="_blank" rel="noopener noreferrer nofollow"><b>Book a Demo </b></a><b>👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">There’s been a big rise in AI-powered deepfake attacks, it’s great to see people tackling it 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://sonraisecurity.com/blog/global-s3-another-c2-channel-for-agentcore-code-interpreters?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Global S3: Another C2 Channel for AgentCore Code Interpreters</a><br>Sonrai&#39;s <a class="link" href="https://www.linkedin.com/in/nigel-sood/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Nigel Sood</a> builds on <a class="link" href="https://www.linkedin.com/in/kmcquade3/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Kinnaird McQuade</a>‘s prior research on DNS-based exfiltration from sandboxed AWS Bedrock AgentCore Code Interpreters, showing that the interpreter&#39;s documented global S3 access can also serve as a bidirectional Command & Control (C2) channel. Sood extended McQuade&#39;s <a class="link" href="https://github.com/BeyondTrust/pwning-agentcore-code-interpreter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">open-source PoC</a> so a client inside the sandbox polls an external bucket for shell commands, executes them, and writes output back via presigned PUT URLs. Unlike the DNS path AWS has since mitigated, this isn&#39;t a Bedrock vulnerability since S3 access is intended behavior, so customers have to handle it themselves. Sood recommends VPC mode with Gateway Endpoints and strict Endpoint Policies limiting access to specific buckets.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://engseclabs.com/blog/agent-credential-isolation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">AWS Credential Isolation for Local AI Agents</a><br>EngSecLabs&#39; <a class="link" href="https://linkedin.com/in/alex-smolen-8a59a31?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Alex Smolen</a> walks through how to safely hand AWS credentials to local AI agents, recommending combining <a class="link" href="https://github.com/61418/elhaz?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">elhaz</a>, a credential broker daemon that manages auto-refreshing STS credentials via Unix socket, with <a class="link" href="https://github.com/engseclabs/trailtool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">trailtool</a> for generating least-privilege IAM policies from CloudTrail logs (based on what the agent actually uses).</p><p class="paragraph" style="text-align:left;">Alex arrives at this recommendation based on challenges with other approaches: environment variables leak to every process and only capture a snapshot that expires mid-session, mounting <code>~/.aws/</code> hands over every profile on the host (and agent deny lists don&#39;t catch bash subprocesses reading the file directly), and metadata emulation breaks on macOS because Docker Desktop&#39;s loopback doesn&#39;t reach the host. Sockets sidestep all of that because the mount itself becomes the access control. If you don&#39;t bind the socket into a container, the credentials don&#39;t exist there at all, so each agent ends up with its own scoped identity by default.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/what-the-march-2026-threat-technique-catalog-update-means-for-your-aws-environment?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">What the March 2026 Threat Technique Catalog update means for your AWS environment</a><br>AWS&#39; <a class="link" href="https://www.linkedin.com/in/shannonbrazil/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Shannon Brazil</a> and <a class="link" href="https://www.linkedin.com/in/cydneystude/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Cydney Stude</a> documented three new threat techniques the AWS Customer Incident Response Team has seen in live incidents. Attackers are abusing Cognito refresh tokens (30-day default, configurable up to 10 years) to maintain access without invalidating legitimate sessions, using <code>ec2:DeregisterImage</code> to permanently delete AMIs (unrecoverable unless Recycle Bin retention is enabled), and using <code>UpdateAssumeRolePolicy</code> to attach new principals to existing IAM roles instead of creating new ones.</p><p class="paragraph" style="text-align:left;">The post emphasizes that attackers are increasingly using legitimate AWS API calls in illegitimate contexts rather than exploits, requiring security teams to monitor for contextual anomalies like unexpected principals or timing. Most cloud monitoring is tuned for creation events (new roles, new logins, new AMIs) and rarely covers modifications or token refreshes on what&#39;s already there. AWS published CloudTrail detection queries for each.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;">BSidesSF 2025 talk - <a class="link" href="https://youtu.be/fCaQOPcjKVw?t=977&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Scalably Securing Third-party Dependencies in Heterogeneous Environments</a> by Anthropic’s <a class="link" href="https://www.linkedin.com/in/ziyad-edher/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Ziyad Edher</a> and <a class="link" href="https://www.linkedin.com/in/chrnorm/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Chris Norman</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.chainguard.dev/unchained/mythos-pulls-zero-days-forward-heres-what-you-need-to-know-now/?utm_source=clint-gibler&utm_medium=3p-sponsorship" target="_blank" rel="noopener noreferrer nofollow"><b>Are you prepared for Mythos? Stay ahead of zero-days with Chainguard </b></a>- AI is finding and weaponizing zero-days faster than any disclosure process can publish them. The answer isn&#39;t patching faster. When a registry gets poisoned, you don&#39;t want to beat the clock. You want to be on a supply chain the attack never touches.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">NIST Updates NVD Operations to Address Record CVE Growth</a> - Due to a 264% surge in CVE submissions between 2020 and 2025, going forward NIST will only enrich CVEs: in CISA&#39;s KEV catalog, affecting critical software, and software used within the federal government.</p></li></ul><p class="paragraph" style="text-align:left;"><sub>*Sponsored</sub></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/FilippoBau/depcut?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">FilippoBau/depcut</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/filippobau/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Filippo Baudanza</a> that cuts Dependabot noise by checking whether vulnerable npm symbols are actually imported in JavaScript/TypeScript codebases. It parses imports with tree-sitter, extracts vulnerable symbols from GHSA data (with an optional LLM fallback), and matches them against a lockfile-scoped dependency graph to classify each alert as REACHABLE, UNREACHABLE, or INDETERMINATE, and outputs JSON or SARIF for CI pipelines.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/practical-package-security-the-unofficial-guide?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Practical Package Security: The Unofficial Guide</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a> gives a nice survey of actionable best practices to shrink your attack surface, protect execution environments, control package ingestion, and catch compromises early. Rami recommends minimizing dependencies, adding install cooldowns via your package manager or Renovate or Dependabot so the ecosystem catches malware first, locking package versions with hash verification, using wrapper tools like Datadog’s <a class="link" href="https://github.com/DataDog/supply-chain-firewall?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">supply-chain-firewall</a>, and turning off install scripts via npm&#39;s <code>ignore-scripts</code> or pnpm&#39;s <code>onlybuiltdependencies</code>. </p><p class="paragraph" style="text-align:left;">Larger organizations can add registry proxies or private package repositories, plus cloud-based development environments and zero trust production to limit damage when malicious code runs. On the detection side, plant honeytokens in CI pipelines. </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/weirdmachine64/SharkMCP?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">weirdmachine64/SharkMCP</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/mohamedbenchikh/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mohamed Benchikh</a> that wraps Wireshark&#39;s <code>sharkd</code> interface as an MCP server so LLMs can dig through PCAP files with natural language. Each capture gets its own sharkd subprocess for packet inspection, protocol analysis, conversation tracking, and stream reassembly across TCP, UDP, TLS, HTTP, and VoIP, while heavy queries are cached in memory so pagination stays fast.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet</a><br>SentinelOne&#39;s <a class="link" href="https://www.linkedin.com/in/jags-is-fine/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Juan Andres Guerrero-Saade</a> and <a class="link" href="https://www.linkedin.com/in/vitalykamluk/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Vitaly Kamluk</a> uncovered fast16, a 2005 sabotage framework (five years before Stuxnet) that selectively targets high-precision calculation software, patching code in memory to tamper with results to produce inaccurate calculations across an entire facility (e.g. those used in nuclear weapons research). fast16 is the earliest known Windows malware to embed a Lua VM, and combines a wormable Lua-powered binary with a kernel driver that scans executables for 101 code patterns, then surgically rewrites floating-point routines.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The fast16 name had already appeared in the 2017 ShadowBrokers leak inside NSA&#39;s Territorial Dispute list, and Unix-style source control markers in the binaries point to long-term development by government or military engineers. The main binary sat on VirusTotal for nearly a decade, missed by almost every antivirus engine, before SentinelLABS pieced it together.</p></div><p class="paragraph" style="text-align:left;">💡 Wow, interesting discovery process and historical discussion.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@rohitashokgowd/seven-queries-to-audit-the-sentinel-detections-your-soc-may-have-missed-8e9c73fc2522?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.</a><br>Rohitashokgowd shared seven KQL queries for auditing Microsoft Sentinel detection rules and finding the ones that look fine on paper but don&#39;t actually catch anything. Sentinel&#39;s standard health dashboards check whether rules run, not whether they work, so a rule can sit green for months while it queries a dead table or autocloses every alert it produces. The rules flag <b>silent zombies</b> (rules that always return zero), <b>shadow detectors</b> (alerts that never become incidents), <b>high-FP rules</b> (90%+ closed as benign), <b>broken feeds</b> (querying empty tables), <b>forgotten disabled rules </b>(disabled rules that were never turned back on), <b>untracked detections</b> (missing MITRE or entity mappings), and <b>coverage drift</b> (techniques with 60%+ alert drops over 30 days).</p><p class="paragraph" style="text-align:left;">Rohitashokgowd also built <a class="link" href="https://github.com/rohit8096-ag/Sentinel-Assessment-Tool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Sentinel Assessment Tool</a>, a PowerShell module that generates an HTML report of detection coverage across Sentinel and Defender.</p><p class="paragraph" style="text-align:left;">💡 I love the meta idea of having queries you can run periodically (or continuously) that are evaluating a range of potential failure modes for your security tools. I think this same idea applies across code scanning, cloud security, or any domain where you have security checks looking for “bad,” and the specific failure modes called out in this post are good starting points.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/tahaafarooq/Fenrir?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">tahaafarooq/Fenrir</a><br>Tool by <a class="link" href="https://x.com/tahaafarooq?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Taha Afarooq</a> that uses eBPF to capture SSH, PAM, sudo, and su credentials at the kernel level. The Go agent deletes itself from disk and runs only in memory, poses as a legitimate system process, and exits if it detects defensive tools (Wireshark, Sysdig, Falco, Tetragon), or VM/container environments (Docker, Kubernetes, Cuckoo, Joe Sandbox). Captured credentials are smuggled out over encrypted network traffic to a companion fenrir-channel C2 with a web dashboard.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://dreadnode.io/research/mine-the-gap-open-source-tools-for-measuring-the-ai-offense-defense-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mine the Gap: Open-Source Tools for Measuring the AI Offense-Defense Gap</a><br>Dreadnode&#39;s <a class="link" href="https://www.linkedin.com/in/jaysongrace/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Jayson Grace</a> and <a class="link" href="https://www.linkedin.com/in/martin-wendigg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Martin Wendiggensen</a> released two open-source tools for evaluating AI agents in head-to-head red versus blue engagements, since existing benchmarks miss what happens when both sides operate autonomously against shared infrastructure.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/dreadnode/DreadGOAD?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">DreadGOAD</a> is a fork of the GOAD Active Directory lab packaged for AWS, with Terraform/Terragrunt provisioning, golden AMIs, private networking via SSM, automated validation of 50+ AD vulnerabilities, and a variant generator that randomizes entity names so agents can&#39;t memorize their way through. <b><a class="link" href="https://github.com/dreadnode/ares?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Ares</a></b> runs on top: seven red team agents (recon, credential access, cracking, ACL abuse, privilege escalation, lateral movement, coercion) reach domain dominance through Golden Ticket persistence in under six minutes with a 95%+ success rate, while three blue team agents (triage, threat hunting, lateral analysis) investigate the same telemetry.</p><p class="paragraph" style="text-align:left;">Every attacker action is recorded as ground truth, so blue team agents are scored on how accurately they reconstruct what actually happened, not against static checklists or curated log dumps.</p><p class="paragraph" style="text-align:left;">💡 Lots of really cool ideas in this post- automatically generating variants of a vulnerable environment so you can test how agents perform, measuring the performance of red vs blue autonomous agents, recording actions for future ground truth, and open sourcing the core parts 🤘 Great work.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://the-decoder.com/openai-releases-open-source-model-that-strips-personal-data-from-text?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">OpenAI releases open-source model that strips personal data from text</a><br>OpenAI released <a class="link" href="https://github.com/openai/privacy-filter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Privacy Filter</a>, an open-source 1.5B model that detects and redacts eight PII categories including names, emails, phone numbers, account numbers, and secrets like API keys. It runs locally on a laptop or in-browser with a 128K token context window, uses single-pass labeling instead of generation, and ships under Apache 2.0 on GitHub and Hugging Face.</p><p class="paragraph" style="text-align:left;">💡Useful for data loss prevention and log scrubbing, though weaker on non-English text and non-Latin scripts, so keep a human in the loop.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/google-cloud-cat-mouse?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Google wants AI defense to be as fast as AI offense</a><br><a class="link" href="https://www.linkedin.com/in/fredericlardinois//?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Frederic Lardinois</a> covers Google Cloud&#39;s Next &#39;26 security announcements. Google added three new AI agents to Google Security Operations for threat hunting, detection engineering, and third-party context, alongside an existing triage agent that has processed over 5 million alerts in the past year and reduced 30-minute analyses to roughly 60 seconds. Wiz, recently acquired by Google, extended its AI-Application Protection Platform across Databricks, AWS, Azure, and Salesforce, is adding inline AI security hooks in IDEs and agent workflows, and shipped a dynamic AI-BOM to inventory shadow AI- the AI frameworks, models, and IDE extension in your environment. Mythos Preview will be available through Google’s Vertex AI for defensive use.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.provos.org/p/finding-zero-days-with-any-model?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Finding Zero-Days with Any Model</a><br><a class="link" href="https://linkedin.com/in/nielsprovos?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Niels Provos</a> argues that discovering novel vulnerabilities with AI is not just a frontier-model capability but an orchestration problem. He demonstrates using his open-source <a class="link" href="https://github.com/provos/ironcurtain?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">IronCurtain</a> framework with commercial models (Opus 4.6, Sonnet 4.6) and open-weight models (GLM 5.1) that he can replicate Anthropic&#39;s 1998 OpenBSD TCP SACK finding and discover new zero-days in widely-deployed software, with each scan costing $30-150 per codebase. </p><p class="paragraph" style="text-align:left;">Niels was able to find these vulnerabilities using IronCurtain (which supports arbitrary workflows structured as finite-state machines (FSM) via plain YAML definitions) by building a specialized vulnerability discovery workflow that has a central Orchestrator agent that acts as a strategic router that then decides which specialized agent to dispatch next based on an append-only execution journal.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://bishopfox.com/blog/introducing-aimap-security-testing-for-ai-agent-infrastructure?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Introducing AIMap: Security Testing For AI Agent Infrastructure</a><br>Bishop Fox&#39;s <a class="link" href="https://linkedin.com/in/aashiq-ramachandran?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Aashiq Ramachandran</a> announces <a class="link" href="https://github.com/BishopFox/aimap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">AIMap</a>, an open-source tool that discovers, fingerprints, scores, and tests internet-exposed AI agent infrastructure by querying Shodan and fingerprinting endpoints across MCP servers, Ollama, vLLM, LiteLLM, LangServe, Gradio, ComfyUI, and other AI frameworks using Nuclei templates and live HTTP checks. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AIMap assigns risk scores (0-10) based on authentication status, exposed tools, CORS policies, TLS configuration, and system prompt leakage, and includes protocol-specific attack modules for MCP servers (tool enumeration, unauthorized tool invocation, and prompt injection via tool descriptions), Ollama instances (model listing, model weight extraction, and prompt injection), and OpenAI-compatible endpoints (model enumeration, completion abuse, and system prompt extraction).</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Our evaluation of OpenAI&#39;s GPT-5.5 cyber capabilities</a><br>The UK AI Security Institute evaluated GPT-5.5 on various cybersecurity tasks, from basic to expert-level challenges across reverse engineering, exploit dev, and crypto attacks. On a custom VM reverse engineering challenge that took a human expert 12 hours, GPT-5.5 solved it in 10 minutes. “On the Expert-level tasks, GPT-5.5 achieves an average pass rate of <b>71.4%</b>, compared to <b>68.6%</b> for Mythos Preview, 52.4% for GPT-5.4, and <b>48.6%</b> for Opus 4.7. On this measure, GPT-5.5 may be the strongest model we have tested.”</p><p class="paragraph" style="text-align:left;">To see if the model could chain attack steps end-to-end, AISI ran it through &quot;The Last Ones,&quot; a 32-step corporate network simulation estimated at 20 hours for humans. GPT-5.5 completed the full chain in 2 of 10 attempts, making it the second model after Mythos to do it (which succeeded in 3/10 attempts). On &quot;Cooling Tower,&quot; a 7-step industrial control system attack, GPT-5.5 failed like every other model tested.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://tincan.kids/products/tin-can?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Tin Can</a> - A WiFi landline for kids. It doesn’t have apps, texting, or games—just real conversation with friends, neighbors, Grandma, or whoever you add to your approved contact list.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://theuselessweb.com/sites-we-lost?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">The Sites We Lost</a> - Archiving quirky, old websites. Some take me back.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=OkxFSf0olgA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Inside TIME’s Wild Day with MrBeast</a></p></li><li><p class="paragraph" style="text-align:left;">Morning Brew - <a class="link" href="https://www.youtube.com/watch?v=8oWcxFGz0LY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Why are the boys tryna get hot all of a sudden?</a> - On Looksmaxxing and medspas.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=NdU6UdUKaYc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Scott Galloway on Diary of a CEO</a> - AI’s impact (or not) on the economy and jobs, the war in Iran, being a parent, and more. </p><ul><li><p class="paragraph" style="text-align:left;">I thought Scott had an interesting point on China purposefully “AI dumping” low cost AI via open source models into the U.S. economy to potentially undermine Anthropic, OpenAI, and other companies, as much of the U.S. stock market is essentially a bet on AI, and how that’s similar to how China previously dumped below-cost steel into the U.S. market, which largely wiped out American steel.</p></li><li><p class="paragraph" style="text-align:left;">Also: “The receipts for love are grief.” 🥹</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;">Mitchell Hashimoto - <a class="link" href="https://mitchellh.com/writing/ghostty-leaving-github?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Ghostty Is Leaving GitHub</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.npr.org/2026/05/05/nx-s1-5807918/polymarket-panama-prediction-market?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">NPR went looking for Polymarket&#39;s Panama headquarters. It&#39;s elusive</a></p></li><li><p class="paragraph" style="text-align:left;">Joe Hudson - <a class="link" href="https://www.youtube.com/watch?v=NT55aMb1rw0&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">AI and The Return to Being Human</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://variety.com/2026/digital/news/meta-ai-mark-zuckerberg-copyright-infringement-lawsuit-publishers-scott-turow-1236738383/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mark Zuckerberg ‘Personally Authorized and Actively Encouraged’ Meta’s Massive Copyright Infringement to Train AI Systems</a>, Publishers and Scott Turow Allege in Lawsuit</p></li><li><p class="paragraph" style="text-align:left;">Coinbase CEO Brian Armstrong’s <a class="link" href="https://x.com/brian_armstrong/status/2051616759145185723?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">tweet on letting go of 14% of Coinbase</a> - Is a crypto company firing a number of its employees a <i>job</i> rug pull 🤔 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/open-source-codex-orchestration-symphony/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">An open-source spec for Codex orchestration: Symphony</a> - OpenAI describes building <a class="link" href="https://github.com/openai/symphony?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Symphony⁠</a>, an agent orchestrator that turns a project-management board like Linear into a control plane for coding agents. Every open task gets an agent, agents run continuously, and humans review the results. Wow, this is really cool 👍️ </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/where-the-goblins-came-from/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Where the goblins came from</a> - Fascinating story about how OpenAI investigated why GPT-5.1+ models started increasingly mentioning goblins, gremlins, and other creators in metaphors 😂 </p></li><li><p class="paragraph" style="text-align:left;">Anthropic - <a class="link" href="https://claude.com/blog/new-in-claude-managed-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">New in Claude Managed Agents: dreaming, outcomes, and multiagent orchestration</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/anthropics/knowledge-work-plugins?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">anthropics/knowledge-work-plugins</a> - 11 plugins bundling the skills, connectors, slash commands, and sub-agents for a specific job function. Currently: productivity, sales, customer support, product management, marketing, legal, finance, data, enterprise search, bio research, cowork plugin management.</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Politics</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/nsOrnZV2h5M?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Politics used to be like this</a> - Clips of Mitt Romney, John McCain, and Obama being respectful. In one of them, at a McCain event, a woman says she can’t trust Obama because he’s an Arab. McCain corrects her, “He’s a decent family man.” Let’s get back to this.</p></li><li><p class="paragraph" style="text-align:left;">Last Week Tonight with John Oliver - <a class="link" href="https://www.youtube.com/watch?v=ZN4njIQcSR4&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Prediction Markets</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/7FqfS?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">We spoke to the man making viral Lego-style AI videos for Iran. Experts say it&#39;s powerful propaganda</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/icLLb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Chinese firms market Iran war intelligence ‘exposing’ U.S. forces</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=c149e08b-3a51-450c-bc4b-1fe0f16a8bc7&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #326 - AI Auto Exploiting Vulnerabilities, GitHub RCE, Autonomous Cloud Hacking Agent</title>
  <description>Automatically creating PoCs for vulnerabilities, git push → code execution on github.com, how well can an AI agent system hack your cloud?</description>
  <link>https://tldrsec.com/p/tldr-sec-326</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-326</guid>
  <pubDate>Thu, 30 Apr 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-04-30T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤘 Hackathon</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">This week Semgrep friends have flown in from all over the world to crazily build together.</p><p class="paragraph" style="text-align:left;">Engineers, security researchers, designers, and, as we are generous of spirit, even product managers.</p><p class="paragraph" style="text-align:left;">The fact that we do this every few quarters is one of my favorite things about Semgrep.</p><p class="paragraph" style="text-align:left;">A number of our coolest features came from a hack week: new engine features, AI triage before it was cool, and even Semgrep itself (back before that was the company’s focus, or name).</p><p class="paragraph" style="text-align:left;">I also really appreciate the in person time for learning about who people are outside of work.</p><p class="paragraph" style="text-align:left;">Hearing stories about their garden, travels, partner, or kids over boba and late night pizza.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2df88894-93f4-4245-b7cc-4c26f3f92b83/sr_dinner3.png?t=1777534699"/><div class="image__source"><span class="image__source_text"><p>Team dinner! If you look closely, you may notice a <a class="link" href="https://www.linkedin.com/in/katiepf/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Katie Paxton-Fear</a> (InsiderPhD). Shout-out <a class="link" href="https://www.linkedin.com/in/shelwu/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Shelley Wu</a>, who recently joined the team 🙌</p></span></div></div><p class="paragraph" style="text-align:left;">Can’t wait for the demos competition and showcase tomorrow 🤩 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Prowler: the world’s most widely adopted open cloud security platform</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Prowler automates security and compliance across any cloud environment, with agentless coverage of cloud infrastructure, SaaS, Kubernetes, containers, Infrastructure as Code, and more. It detects vulnerabilities and misconfigurations, prioritizes risks, accelerates remediation, and automates audit-ready compliance. </p><p class="paragraph" style="text-align:left;">Prowler has become the security platform of choice for thousands of cloud teams, with 45M+ downloads, 13K+ GitHub stars, and 300+ global contributors. Prowler Cloud delivers cloud security 10x more cost-effectively than alternatives.</p><h2 class="heading" style="text-align:center;"><a class="link" href="https://prowler.com/interactive-demo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow"><b>👉 </b></a><a class="link" href="https://prowler.com/interactive-demo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow"><b>See Prowler in action 👈</b></a></h2></div><p class="paragraph" style="text-align:left;">I’m a huge fan of open source and companies that build around it. Also, this is a nice interactive demo- I like seeing the UI and how the product works with some helpful explanation.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/BuffaloWill/oxml_xxe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">BuffaloWill/oxml_xxe</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/willis-vandevanter-82a05018/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Willis Vandevanter</a> that embeds XXE payloads into OXML formats (DOCX, XLSX, PPTX, ODT, ODG, ODP, ODS), SVG, and raw XML for testing XXE vulnerabilities in document parsers. BlackHat USA 2015 <a class="link" href="https://oxmlxxe.github.io/reveal.js/slides.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent#/" target="_blank" rel="noopener noreferrer nofollow">slides</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Trailmark turns code into graphs</a><br>Trail of Bits&#39; Scott Arciszewski announces <a class="link" href="https://github.com/trailofbits/trailmark?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Trailmark</a>, an open source library that parses source code into queryable call graphs of functions, classes, call relationships, and semantic metadata. Trailmark uses tree-sitter for AST parsing and rustworkx for graph traversal, supporting 17 languages including C, Rust, Go, Python, and Solidity. The library ships with eight Claude Code skills (genotoxic, vector-forge, diagram, crypto-protocol-diagram, graph-evolution, mermaid-to-proverif, audit-augmentation, and trailmark) that enable graph-based security analysis like mutation triage (which mutant survivors are reachable from untrusted input), blast radius calculation, and taint propagation tracking.</p><p class="paragraph" style="text-align:left;">Using Trailmark on cryptographic libraries, they identified architectural bottlenecks and high value fuzzing target codec parsers.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Wiz Research uncovers Remote Code Execution in </a><a class="link" href="https://GitHub.com?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">GitHub.com</a><a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow"> and GitHub Enterprise Server</a><br>Wiz’s <a class="link" href="https://linkedin.com/in/sagi-tzadik-95b3a7194?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Sagi Tzadik</a> describes how they found an RCE in the git push pipeline that let any user with push access inject fields into internal metadata via unsanitized characters in push options, override the push execution environment, bypass sandboxing, and run arbitrary commands on GitHub&#39;s servers. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">GitHub patched the vulnerability within 6 hours of their report and confirmed zero exploitation by querying telemetry for an anomalous code path the exploit triggers. GHES admins should upgrade to the latest patch and review <code>/var/log/github-audit.log*</code> for unusual special characters in push options. See also <a class="link" href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">GitHub’s response</a>.</p></div><p class="paragraph" style="text-align:left;">“By leveraging AI-augmented tooling-particularly automated reverse engineering using IDA MCP-we were able to do what was previously too costly. Using AI, we rapidly analyzed GitHub&#39;s compiled binaries, reconstructed internal protocols, and systematically identified where user input could influence server behavior across the entire pipeline.”</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><span style="color:#434343;"><b> </b></span><b>Vibe Coding a Backport: </b><br><b>When &quot;Latest or Nothing&quot; Isn&#39;t an Option</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Scanners scream. Leadership wants dates. Engineering wants stability. And &quot;just upgrade&quot; (the only answer most teams hear) keeps colliding with breaking changes, flaky tests, and calendar risk. In Vibe Coding a Backport, Root&#39;s John Amaral argues for backporting as a first-class remediation discipline and walks through how agentic workflows are finally making it scalable: pin what you ship, understand the upstream fix, apply minimal change, validate with tests. A practical playbook for the messy real world.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.root.io/workshop/vibe-coding-a-backport?utm_campaign=43276343-April%202026%20-%20tldr%20sec%20newsletter%20placement%202&utm_source=tldr%20sec&utm_medium=newsletter" target="_blank" rel="noopener noreferrer nofollow"><b>Get the Playbook</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The interactive workshop format is pretty cool 👍️ Automatically backporting patches using AI is a neat approach that wasn’t feasible before, it’s fun to see new takes on longstanding challenges. </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://engseclabs.com/blog/cloudtrail-for-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">CloudTrail for AI Agents</a><br><a class="link" href="https://www.linkedin.com/in/alex-smolen-8a59a31/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Alex Smolen</a> introduces <a class="link" href="https://github.com/engseclabs/trailtool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Trailtool</a>, a tool that pre-aggregates AWS CloudTrail logs by entity (People, Sessions, Roles, Services, Resources) to enable faster queries and AI agent workflows compared to traditional SIEM or CloudTrail Lake approaches. The post walks through using Trailtool to detect “ClickOps” modifications, define least-privilege IAM policies for roles, respond to AccessDenied errors, and validate emergency break-glass access justifications.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System</a><br>Palo Alto Networks&#39;s <a class="link" href="https://www.linkedin.com/in/yahavfestinger/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Yahav Festinger</a> and <a class="link" href="https://www.linkedin.com/in/chendoy/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Chen Doytshman</a> describe &quot;Zealot,&quot; a multi-agent LLM penetration testing PoC using LangGraph, to empirically test autonomous AI offensive capabilities against cloud environments. The system uses a supervisor-agent architecture with three specialist agents (Infrastructure, Application Security, and Cloud Security) that share attack state through a centralized AttackState object. In sandbox testing against a misconfigured GCP environment, Zealot autonomously chained SSRF, GCP Instance Metadata Service credential theft, BigQuery enumeration, privilege escalation via self-granted <code>storage.objectAdmin</code> permissions, and data exfiltration, completing the full attack chain with minimal human guidance. </p><p class="paragraph" style="text-align:left;">Learnings: Zealot demonstrated unexpected initiative, such as autonomously injecting SSH keys for persistence, though it occasionally required human intervention to prevent resource-wasting &quot;rabbit hole&quot; scenarios. They found AI doesn&#39;t create new attack surfaces, it serves as a force multiplier by rapidly exploiting well-known misconfigurations at machine speed.</p><p class="paragraph" style="text-align:left;">💡 I like how the post describes their reasoning on why they used a hierarchical supervisor-agent architecture, what tools they chose to give each agent, and the discussion of state management and memory (context sharing, what <code>AttackState</code> tracks across phases). Lots of tactical details 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/dependency-cooldowns?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">The case for dependency cooldowns in a post-axios world</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/kennedy-toomey?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Kennedy Toomey</a> discusses recent npm supply chain attacks, and notes that in Datadog’s 2026 <a class="link" href="https://www.datadoghq.com/state-of-devsecops/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">State of DevSecOps</a> report, they found half of organizations install at least one dependency within a day of release. Also good to keep in mind: using npm&#39;s semantic versioning with <code>^</code> and <code>~</code> ranges automatically accepts future updates, meaning you’re implicitly trusting future (potentially malicious) code. Yarn, pnpm, npm, and Dependabot all support dependency cooldowns now.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cooldowns.dev?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">cooldowns.dev</a><br>A configuration reference for dependency cooldowns across major package managers by <a class="link" href="https://www.linkedin.com/in/martinprpic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Martin Prpič</a>, covering uv, pip, npm, pnpm, Yarn, Bun, Deno, and <code>cargo-cooldown</code>, plus Renovate and Dependabot configurations. To make setup easier, Prpič also created <a class="link" href="https://github.com/mprpic/cooldowns/blob/main/cooldowns.sh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">cooldowns.sh</a>, a helper script that configures and verifies cooldowns across all supported tools in one command, with a check subcommand suitable as a CI gate.</p><p class="paragraph" style="text-align:left;">Note that cooldowns aren&#39;t a complete defense though, since they won&#39;t catch typosquatting, long-term maintainer compromise like xz-utils, or zero-days in already-installed packages.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Karib0u/rustinel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Karib0u/rustinel</a><br>By <a class="link" href="https://www.linkedin.com/in/theofchr/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Théo Foucher</a>: Rustinel is an open-source endpoint detection runtime for Windows and Linux. It collects native telemetry from ETW and eBPF, normalizes events into Sysmon-style fields, evaluates Sigma, YARA, and IOC detections, and emits ECS-compatible NDJSON alerts.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.bushidotoken.net/2025/04/tracking-adversaries-evilcorp-ransomhub.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Tracking Adversaries: EvilCorp, the RansomHub affiliate</a><br><a class="link" href="https://www.linkedin.com/in/william-t/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Will Thomas</a> (BushidoToken) describes the connection between EvilCorp, a sanctioned Russian cybercrime group, and RansomHub, a prominent ransomware-as-a-service operation. The link is established through shared TTPs, including the use of SocGholish malware for initial access and a Python backdoor (VIPERTUNNEL) for post-exploitation. Because EvilCorp has been under US sanctions since 2019, making it illegal for affected organizations to pay ransoms to them, this association may lead to sanctions against RansomHub as well (and thus legal risk to victims paying them).</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.magonia.io/research/why-a-decade-of-writing-detection-logic-makes-the-mythos-exploit-numbers-less-scary?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary</a><br><a class="link" href="https://www.linkedin.com/in/signalblur/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">David Burkett</a> argues that despite AI-powered systems finding vulnerabilities at an unprecedented rate, the impact on defenders is less catastrophic than headlines suggest because: new exploits have always exceeded defenders’ ability to write detections (that’s why you detect behaviors over individual IoCs and exploits), adversaries often don’t need zero days (see: ClickFix, phishing), and detection logic doesn’t map 1:1 with exploits (e.g. 1000s of RCE in Microsoft Office, but if Office spawns <code>powershell.exe</code>, that’s probably bad). </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">David also argues that ML-based anomaly detection is unlikely to be the answer due to the base rate fallacy: in an environment with 1 million daily events, a 0.001 false positive rate will generate 1,000 false alerts. More than exploit volume, he’s concerned about AI agents being granted excessive access, where for example prompt injection could trigger legitimate-looking actions (like wire transfers using real browser cookies) that are nearly impossible to distinguish from authorized behavior.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/kpolley/redai?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">kpolley/redai</a><br>By <a class="link" href="https://linkedin.com/in/kylepolley?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Kyle Polley</a>: A terminal workbench for AI-driven vulnerability discovery and live validation. After scanner agents produce candidate findings, validator agents work inside a live environment (a running instance of the target, plus whatever tools they need to interact with it) and try to prove or disprove each finding by clicking through the UI, hitting endpoints, writing PoC scripts, hosting helper servers, and saving the evidence. RedAI currently ships with validator plugins for agents to drive Chrome via agent-browser and an iOS Simulator, but it’s extendable.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://moak.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">MOAK - Mother of All KEVs</a><br><a class="link" href="https://www.linkedin.com/in/niv-hoffman-1852183a1/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Niv Hoffman</a>, <a class="link" href="https://www.linkedin.com/in/yair-saban-30615870/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Yair Saban</a> et al created MOAK, an agentic workflow that autonomously exploits 98% of open source KEVs (Known Exploited Vulnerabilities) using publicly available models (Opus 4.6 and GPT 5.4). They found MOAK was able to automatically create exploits for 174/178 KEVs that were published after the models’ knowledge cutoffs (to guarantee no contamination).</p><p class="paragraph" style="text-align:left;">The workflow: a <b>collector</b> gathers the CVE’s vulnerability description and relevant code changes. The <b>researcher</b> analyzes the vulnerability and reconstructs the full exploitation path, extracting primitives from the vulnerable code and builds a graph of possible exploit chains. The <b>builder</b> builds a controlled environment to reproduce the vulnerable system, the <b>exploiter</b> converts the research into a working exploit, then finally the <b>judge</b> verifies that the exploit and environment are valid and realistic.</p><p class="paragraph" style="text-align:left;">The <a class="link" href="https://moak.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent#react2shell" target="_blank" rel="noopener noreferrer nofollow">Test Case: React2Shell</a> write-up is very cool and nicely detailed on how the workflow can iteratively find gadgets and exploit primitives, form hypotheses, and iterate until it discovers a path that works.</p><p class="paragraph" style="text-align:left;">💡 This is one of the more detailed write-ups of approaches I’ve seen in this space, worth reading!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://xbow.com/blog/mythos-like-hacking-open-to-all?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">GPT-5.5: Mythos-Like Hacking, Open to All</a><br>XBOW&#39;s <a class="link" href="https://www.linkedin.com/in/albert-ziegler-6b3b24138/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Albert Ziegler</a> and <a class="link" href="https://www.linkedin.com/in/stephenpbuckley/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Steve Buckley</a> call GPT-5.5 a Mythos-like step change in vulnerability detection. On their internal benchmark of real vulnerabilities in open-source applications, GPT-5.5 dropped the miss rate from GPT-5&#39;s 40% (and Opus 4.6&#39;s 18%) to 10%, with black-box performance now exceeding what GPT-5 achieved with source code access, and white-box performance pulling away so far it &quot;effectively killed&quot; their benchmark. The model also logs into target systems in roughly half the iterations of the next-best model and persists on failing paths only half as often as previous GPT versions or Opus, a meaningful gain given RLHF tends to bias models against giving up.</p><p class="paragraph" style="text-align:left;">See also XBOW’s <a class="link" href="https://xbow.com/blog/anthropic-opus4-7-first-look?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">evaluation of Opus 4.7</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.includesecurity.com/2026/04/ctfs-in-the-ai-era?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">CTFs in the AI Era</a><br>Include Security&#39;s <a class="link" href="https://linkedin.com/in/laurence-tennant-82573090?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Laurence Tennant</a> attended BSidesSF 2026 CTF, where the top 10 teams cleared every challenge with AI agents. Top teams ran pipelines that monitored CTFd for new challenges, spun up multiple agents in parallel, used a coordinator LLM to share insights between them when one stalled, and auto-submitted flags.</p><p class="paragraph" style="text-align:left;">CTFs play to everything LLMs are good at: bounded context, clear success criteria, instant feedback, and abundant public write-ups in the training data. Laurence contrasts CTFs with pentesting, in which goals are open-ended, false positives need business context to triage, code bases are large (not just an isolated few hundred lines), findings have to be written up for a client, and stepping outside scope has real consequences. The winning team <a class="link" href="https://github.com/verialabs/ctf-agent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">open-sourced their agent</a>, which cleared all 52 challenges.</p><p class="paragraph" style="text-align:left;">💡I do wonder if AI has “solved” CTFs 🙃 Maybe there will be new or separate CTFs where AI isn’t allowed, or some other rules to keep the challenges human-focused. Interesting times.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=O7joqcfy-eU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">I built Taskrabbit for Witches ($100K MRR - Projected)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/nnLo_rPLjbA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Mama panda swaps her kid for an apple</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/MgWX5wKkHks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Ranking Best Panda Moments</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/nWUUAE1bCqI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">What are the best Scottish memes?</a></p></li><li><p class="paragraph" style="text-align:left;">Alanis Morissette’s <a class="link" href="https://www.youtube.com/shorts/9cOS1scw8hQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">“Ironic” if it was written in 2025</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/S9c6ocOwhcY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Escalator sketch - seeing your future partner maybe</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://hackerone.com/ibb?type=team&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">The HackerOne Internet Bug Bounty program has been paused</a> - “AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Vercel says some of its customers’ data was stolen prior to its recent hack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://lawsofsoftwareengineering.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Laws of Software Engineering</a> - A collection of principles and patterns that shape software systems, teams, and decisions.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.economist.com/science-and-technology/2026/03/30/why-a-startup-is-teaching-human-brain-cells-to-play-doom?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Why a startup is teaching human brain cells to play “Doom”</a> - <a class="link" href="https://corticallabs.com/doom.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Video</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://daringfireball.net/2026/04/another_day_has_come?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Daring Fireball on the Tim Cook Apple CEO transition</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Apple fixes bug that cops used to extract deleted chat messages from iPhones</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/posts/calebsima_thirty-years-ago-at-16-i-joined-the-team-activity-7454556030107230208-iiZ0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Caleb Sima on some interesting history of various cybersecurity companies</a>. Congrats to <a class="link" href="https://www.linkedin.com/in/meny-har/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Meny Har</a>, <a class="link" href="https://www.linkedin.com/in/johndifederico/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">John DiFederico</a>, <a class="link" href="https://www.linkedin.com/in/dylan-williams-a2927599/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Dylan Williams</a> for Spectrum Security’s seed found.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors</a> - Citizen Lab uncovered two sophisticated commercial surveillance vendors conducting multi-year location tracking campaigns by exploiting SS7 and Diameter signaling protocols across global mobile networks.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/8rPUA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Scoop: NSA using Anthropic&#39;s Mythos despite blacklist</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/lifeof_jer/status/2048103471019434248?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">An AI Agent Just Destroyed Our Production Data</a> - Cursor running Anthropic&#39;s flagship Claude Opus 4.6 deleted PocketOS’ production database and all volume-level backups in a single API call to Railway, their infrastructure provider. Oof 🫠 Lots of people are working on making agents safer, but there’s still a lot of work to be done.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://people.com/paradox-inc-cover-reveal-exclusive-11955668?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">People Magazine</a> - Forrest Brazeal is writing a book satirizing Silicon Valley (based on his experiences working at Google) called Paradox Inc, about the fall and rise of a time-travel startup. I love Forrest’s music and humor, I bet this is going to be great.</p></li><li><p class="paragraph" style="text-align:left;">Aidan Steele - <a class="link" href="https://awsteele.com/blog/2026/04/19/microtransactions-and-the-first-ai-native-fax-service.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Micro-transactions and the first AI-native fax service</a></p></li><li><p class="paragraph" style="text-align:left;">Jesse Itzler - <a class="link" href="https://www.youtube.com/watch?v=xDK42rroFYE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">If Your Life Isn’t on One Page, It’s Too Complicated</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/iyYtYXGzNIs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Mom and daughter excited when dad comes home</a> 🥹</p></li><li><p class="paragraph" style="text-align:left;">Yuki Piano - <a class="link" href="https://www.youtube.com/watch?v=c8CyQtemKKQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">KPop Demon Hunters Golden piano cover</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/powered-by?publication_logo=https%3A%2F%2Fmedia.beehiiv.com%2Fcdn-cgi%2Fimage%2Ffit%3Dscale-down%2Cformat%3Dauto%2Conerror%3Dredirect%2Cquality%3D80%2Fuploads%2Fpublication%2Flogo%2F080a561f-2435-4477-a549-ab9f115e047c%2Ftldrsec_robot_nowords.png%3Fv%3D1789528574&publication_name=tl%3Bdr+sec&utm_campaign=da21a0a9-4e21-48c7-92c3-e900b0d92aa9&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
