<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>tl;dr sec</title>
    <description>The best way to keep up with cybersecurity research. Join &gt;90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.</description>
    
    <link>https://tldrsec.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/xgTKUmMmUm.xml" rel="self"/>
    
    <lastBuildDate>Fri, 10 Jul 2026 03:49:22 +0000</lastBuildDate>
    <pubDate>Thu, 09 Jul 2026 14:30:00 +0000</pubDate>
    <atom:published>2026-07-09T14:30:00Z</atom:published>
    <atom:updated>2026-07-10T03:49:22Z</atom:updated>
    
      <category>Software Engineering</category>
      <category>Artificial Intelligence</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, tl;dr sec</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/080a561f-2435-4477-a549-ab9f115e047c/tldrsec_robot_nowords.png</url>
      <title>tl;dr sec</title>
      <link>https://tldrsec.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?</title>
  <description>An MCP powered system that&#39;s continuously finding and reproducing vulns, improvements to Datadog&#39;s OSS malware hunting tool, Hakluke muses on the future of bug bounty</description>
  <link>https://tldrsec.com/p/tldr-sec-336</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-336</guid>
  <pubDate>Thu, 09 Jul 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-07-09T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🎆 Amurrica Day</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I love how peak America the 4th of July is, with tons of outdoor grilling, people wearing red, white, and blue, and of course fireworks.</p><p class="paragraph" style="text-align:left;">In some circles, it’s not cool to be patriotic right now. While we have and will continue to make mistakes as a country, I think we can still be proud of the good parts, while striving to do better.</p><p class="paragraph" style="text-align:left;">I think everyone should be proud of where they came from, and what makes that place unique.</p><p class="paragraph" style="text-align:left;">This year I watched the Pier 39 fireworks from a nearby rooftop while a DJ blasted Katy Perry’s song <i>Firework</i> (not the <a class="link" href="https://youtu.be/YDHF6I8czsY?t=16&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Moulin Rouge</a> musical version).</p><p class="paragraph" style="text-align:left;">Watching fireworks in San Francisco is often a futile endeavor, given the high likelihood that what you actually get to see is some slight glimmers in the ever present fog. Still, it was fun.</p><p class="paragraph" style="text-align:left;">Though I must say getting home was a disaster - tons of traffic on narrow roads, and frequent traffic jams due to Waymos. I think it took like 2.5 hours to get home, when I could have walked home in an hour. I considered jumping out of the car and tucking and rolling, and by that I mean calmly stepping out and standing, as we were basically parked.</p><p class="paragraph" style="text-align:left;">Wherever you were, I hope you had a fun and connecting weekend with family and friends 🤗 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> If you or a friend is an excellent software engineer, my team at OpenAI is hiring: <a class="link" href="https://openai.com/careers/software-engineer-codex-security-san-francisco/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">job description</a>. Early access to models, infinite tokens, and even higher ambition. We’re aiming to secure the world and Patch the Planet. You in?</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> What If Every Threat Report Came With the Hunt Already Done?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">A vendor report drops a new TTP into your Slack. Somewhere in it is what actually matters to your environment, and knowing where to look is the real skill, not typing the query. HUMAN Security built hunting agents in BlinkOps that read the report, cut straight to what is relevant, then hit every system in your stack, SIEM, EDR, cloud logs, combining deterministic logic with LLM. No blind spots left uninspected. What comes back is not a guess. It is the real blast radius, exposed. We recorded the full process.</p><h2 class="heading" style="text-align:left;"><b>👉</b><a class="link" href="https://go.blinkops.marketing/threat-hunt-protocol/?utm_campaign=48431689-chnl-newsletter-tldr&utm_source=tldr&utm_medium=newsletter" target="_blank" rel="noopener noreferrer nofollow"><b>Watch the Process Behind a Threat Hunting Agent</b></a><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">From threat intel → to hunt across your SIEM, EDR, and more + automatically feeding confirmed threats into detection engineering is pretty cool. This is a great area where AI can scale defensive work.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://detections.ai/share/inspiration/VNJMKFVM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Exploitarium: Mass Disclosure of Zero-Day Proof-of-Concepts</a><br><a class="link" href="https://www.linkedin.com/in/ethan-andrews-503631228/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Ethan Andrews</a> describes how an anonymous GitHub researcher named &quot;bikini&quot; published <a class="link" href="https://github.com/bikini/exploitarium?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Exploitarium</a>, an archive of over 130 proof-of-concept exploits and vulnerability write-ups dropped without informing vendors, covering targets like libssh2, Gitea, 7-Zip, Docker, OpenVPN Connect, VLC, and nmap.</p><p class="paragraph" style="text-align:left;">💡 As more people gain the ability to find serious vulnerabilities, we might see more drops like this 😅 Important to speed up triage and patching for maintainers, as well as companies.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://hakluke.com/are-bug-bounties-cooked?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Are bug bounties cooked?</a><br><a class="link" href="https://www.linkedin.com/in/hakluke/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Luke Stephens</a> (Hakluke) disagrees that bug bounties are cooked despite AI reshaping the field. Critical bugs used to take years of intuition and target knowledge, but now the same bugs are within reach of anyone with a frontier model subscription, so supply is up while demand isn&#39;t and payouts are down.</p><p class="paragraph" style="text-align:left;">He isn&#39;t worried about HackerOne and Bugcrowd training on submissions or pre-cleaning bugs, since hackers already compete against internal security teams&#39; AI, top hunters&#39; automation, and offensive AI startups like XBOW, Ethiack, and Penligent. What worries him is cost, since frontier model tokens now run top hunters hundreds to thousands a month, and if that becomes the ticket to compete, bug bounty loses the accessibility that lets talented hackers break in from anywhere. Luke recommends hackers to follow the automation pioneers who turned their tooling into companies, like Shubs at Assetnote, Rishiraj Sharma and Sandeep Singh at ProjectDiscovery, Frans Rosen at Detectify, and Roni Carta at Lupin, and use AI to find bug classes others haven&#39;t looked at yet.</p><p class="paragraph" style="text-align:left;">💡 Thoughtful post on a relevant topic these days: what is the future of bug bounty in the age of AI? </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> What if there was a safe way to let your agents -- </b><i><b>dangerously-skip-permissions?</b></i></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Getting anything done often requires an agent, but unlimited access is never a good idea. Minimal allows devs to sandbox their agents in identical isolated environments. Now, agents can run unsupervised at full speed without the huge blast radius. Reproducible by default, local first.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://minimal.dev/?utm_source=tldrsec&utm_campaign=20260709" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(44, 129, 229)"><b>Sandbox your agents today</b></a><span style="color:rgb(102, 102, 102);"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I really like Minimal’s landing page- nice aesthetic, and it actually has a great level of technical detail. They seem quite sharp, I like it 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/udgover/whim?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">udgover/whim</a><br>By <a class="link" href="https://www.linkedin.com/in/fbaguelin/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Frederic Baguelin</a>: <span style="background-color:rgb(255, 255, 255);">Throwaway root shells in AWS Lambda Firecracker microVMs. Launch a fresh VM in ~2s, run a command or attach an interactive shell, then let it disappear. Build the image once, launch many — a Go library (microvm) plus a Docker-like CLI: run, exec, ps, gc, put/get.</span></p><p class="paragraph" style="text-align:left;">Security defaults include injection-only credentials that never resolve ambient AWS creds, shell tokens never logged, path-traversal guards on file transfers, and shell-quoted remote paths, though id-targeted commands like exec can reach any VM you explicitly name in a shared account, matching ssh semantics where naming the target is authorization.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theregister.com/security/2026/06/20/why-amazon-hates-human-in-the-loop-ai-governance/5258639?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Why Amazon hates &#39;human-in-the-loop&#39; AI governance</a><br>Amazon VP <a class="link" href="https://www.linkedin.com/in/ericbrandwine/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Eric Brandwine</a> argues that human-in-the-loop AI governance is not the gold standard it&#39;s assumed to be, <span style="background-color:rgb(255, 255, 255);">citing normalization of deviance, where repeated approval decisions lead humans to become less vigilant over time, similar to how emergency room staff eventually ignore false alarms. </span>Brandwine gave a talk on this concept at <a class="link" href="https://www.youtube.com/watch?v=KJiCfPXOW-U&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">AWS re:Invent in 2017</a> and now applies it to agent governance design.</p><p class="paragraph" style="text-align:left;">Amazon&#39;s alternative is end-to-end accountability with layered permission scoping. Each agent gets an independent identity that logs actions as &quot;this agent did this on behalf of [user],&quot; tying every move back to a human owner. The permission model layers three controls, with static guardrails prohibiting destructive actions, a maximum privilege set per agent, and dynamic policies generated per task. The team also addresses agent goal-seeking behavior, where agents fixate on a single action to reach an objective (upgrade a database → deletes the database), by telling the agent why an action is forbidden, for example that it would cause production impact.</p><p class="paragraph" style="text-align:left;">💡 LLMs in workflows of course have their own challenges, but it is true that humans work inconsistently as they get tired or have alert fatigue. I like the focus on human ownership of the outcome, regardless of if it was a person or an agent that took the action. Also, Google’s Francis deSouza: &quot;Our model for the future is an agentic fleet that does a lot of the routine cyber security work at a machine pace and then is overseen by humans.&quot; </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://radioactivetobi.medium.com/developer-endpoint-inventory-in-10-minutes-bumblebee-hive-bc2db8e266d7?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Developer endpoint inventory in 10 minutes: Bumblebee Hive</a><br><a class="link" href="https://www.linkedin.com/in/oluwatobi-afolabi-6723b7137?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Oluwatobi Afolabi</a> shares <a class="link" href="https://github.com/radioactivetobi/bumblebee-hive?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Bumblebee Hive</a>, a fork of Perplexity AI&#39;s on-disk package scanner Bumblebee (covered in <a class="link" href="https://tldrsec.com/p/tldr-sec-333?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">issue #333</a>) that adds a fleet inventory system UI. Bumblebee scans for the packages developers have installed on their machines across npm, PyPI, Go packages, VS Code extensions, browser add-ons, and MCP server configs, and Hive adds an ingest server and React dashboard where you can view the results.</p><p class="paragraph" style="text-align:left;">💡 Neat to see the quick iteration from Perplexity open sourcing Bumblebee. I’m optimistic about more “benefit of the commons” from companies open sourcing interesting security tools/ideas → coding agents can rapidly extend or customize to another company’s environment. Also tip from <a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7475495379837370370/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287476253334111453184%2Curn%3Ali%3Aactivity%3A7475495379837370370%29&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Prabhu S</a>: <span style="background-color:rgb(255, 255, 255);">You can run cdxgen with &quot;-t os&quot; from each dev&#39;s machine and collect what is installed, running, and configured with Dependency Track.</span> </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/guarddog-3-0-release?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/christophetafanidereeper?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Christophe Tafani-Dereeper</a> and <a class="link" href="https://linkedin.com/in/sebastianobregoso?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Sebastian Obregoso</a> announce GuardDog 3.0, an open-source tool that identifies malicious PyPI and npm packages, now with a YARA-based rules engine replacing Semgrep for faster and more memory-efficient scanning. A new risk scoring engine combines capability detection (e.g. makes network requests, accesses the clipboard) with threat indicators to produce a 0-10 score based on attack chain completeness, specificity, and sophistication.</p><p class="paragraph" style="text-align:left;">The tool now includes transparent sandboxing via nono-py that isolates extraction and scanning inside a capability-restricted process with no network access and read-only filesystem paths, protecting against potential vulnerabilities in GuardDog itself. To measure performance, they built an evaluation system using their <a class="link" href="https://github.com/DataDog/malicious-software-packages-dataset/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">27k+ malicious packages dataset</a> with TLSH clustering to avoid duplicate bias, tracking precision, recall, F1 score, and Matthews correlation coefficient.</p><p class="paragraph" style="text-align:left;">💡 Love to see the GuardDog updates, and great that it’s now running a sandbox. Also worth reading for the evaluating performance section 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://censys.com/blog/asyncrat-family-threat-overview?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">AsyncRAT Family Threat Overview</a><br>Censys&#39; <a class="link" href="https://www.linkedin.com/in/aidandholland/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Aidan Holland</a> gives an overview of AsyncRAT, a family of open-source Windows remote access trojans (RATs)- an original codebase that has been forked repeatedly into dozens of descendant malware families. Aidan tracked about 40 named variants across three generations. One useful finding is that almost every fork inherited DCRAT&#39;s TLS cert without changing it, so hunting the <code>pattern O=&lt;Name&gt; By &lt;author&gt;, L=SH, C=CN</code> on non-standard ports covers most of the family in one query, and the approach should hold up over time because new forks keep inheriting the same cert structure. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://playingwithpackets.com/blog/detection-chokepoints-where-to-start?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Detection Chokepoints: Starting from Scratch</a><br><a class="link" href="https://www.linkedin.com/in/tylerbohlmann/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Tyler Bohlmann</a> introduces <a class="link" href="https://iimp0ster.github.io/detection-chokepoints/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Detection Chokepoints</a>, a free knowledge base applying Matt Graeber and Joshua Prager&#39;s approach of focusing detection engineering on invariant steps attackers cannot avoid (e.g., LSASS credential theft always requires opening a handle to <code>lsass.exe</code>) rather than easily-changed artifacts like filenames or hashes, framing detection as an economics game where invariant-pinned rules force attackers into real engineering time rather than free renames. The knowledge base currently ships 13 chokepoint entries across six MITRE ATT&CK tactics, each with tiered Sigma rules that let detection engineers pick the noise level they can handle.</p><p class="paragraph" style="text-align:left;">The framework addresses the accelerating threat landscape, with Palo Alto&#39;s 2026 Unit 42 report showing the fastest quartile of intrusions reaching data exfiltration in 72 minutes in 2025 (down from 285 in 2024). Bohlmann uses ClickFix as the working example, showing how variants keep appearing under new names but all funnel through the same invariant pattern (a scripting interpreter running under explorer.exe or a browser followed by a network-fetched second stage), so a rule matching the behavior catches whatever the next variant gets called.</p><p class="paragraph" style="text-align:left;">💡 I find invariants a powerful idea in many areas of security, whether it’s eliminating vulnerability classes in code or raising attacker costs like in this post. What must always or should never be true in your code, cloud environment, etc.?</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.zsec.uk/bullyingllms/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Bullying LLMs into submission to find 0days at scale</a><br><a class="link" href="https://twitter.com/ZephrFish?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Andy Gill</a> writes about the autonomous vulnerability hunting system he has been building since early 2026 using Claude Code and MCP. Eight MCP servers with 300+ tools run across five Proxmox VMs, covering binary staging and decompilation (Ghidra, radare2, Frida), and fuzzing across Windows and macOS targets. Everything the infrastructure produces has to survive a hallucination bin that requires a working PoC, clean-VM reproduction, an exploitable crash, and standard-user trigger. A RAG index over past crashes, findings, and defenses keeps new campaigns from re-running dead ends.</p><p class="paragraph" style="text-align:left;">Results include two CVEs in Go&#39;s standard library from grammar-based fuzzing, an OEM service 0-day chained to SYSTEM, and a mix of LPEs, RCEs, and UAFs on Windows and macOS. Andy picks targets by what pays, how often patches ship, and whether other hunters are already there. Even the campaigns that miss pay off, because every dead end feeds the RAG index and later campaigns skip paths that produced nothing before, so the twentieth campaign costs a fraction per finding what the first did on the same subscription. Andy also released <a class="link" href="https://github.com/ZephrFish/TokenBurn?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">TokenBurn</a>, a self-hosted dashboard that compares Claude Code subscription cost against equivalent API pricing.</p><p class="paragraph" style="text-align:left;">💡 Fantastic post, highly recommend reading. Great level of detail and reasoning on the chosen architecture and useful lessons learnt.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Clone This Repo and I Own Your Machine</a><br>0DIN&#39;s <a class="link" href="https://www.linkedin.com/in/andre-hall01/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Andre Hall</a> and <a class="link" href="https://www.linkedin.com/in/miller-engelbrecht-561731274/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Miller Engelbrecht</a> demonstrate an indirect prompt injection attack against Claude Code that achieves full system compromise from a public GitHub repository containing no malicious code. The attack chains three benign-looking components, a <code>README</code> with normal setup instructions, a Python package that throws a <code>RuntimeError</code> if init hasn&#39;t run yet, and a setup script that pipes a <code>dig</code> query to bash. The DNS TXT record contains a base64-encoded reverse shell, so when Claude Code follows the documented setup command to fix the <code>RuntimeError</code>, it unknowingly executes the payload.</p><p class="paragraph" style="text-align:left;">The payload never appears in the repository itself, so code review, static analysis, and the agent&#39;s own file inspection all miss it, and the DNS record can be swapped anytime without any new commits.</p><p class="paragraph" style="text-align:left;">💡 Clever to use the helpfulness of models wanting to fix errors, which they are trained to do, to run malicious commands. An important detail, which I don’t think I see in the post, is what permission mode Claude was run in. If the payload ran when <a class="link" href="https://code.claude.com/docs/en/auto-mode-config?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">auto-mode</a> was used, which routes tool calls through a classifier that blocks potentially dangerous actions, then that’s interesting, if yolo-mode, less interesting in my opinion. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/06/29/llm-jailbreak-testing-with-jailbreaker?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Jailbreaker: LLM Jailbreak Testing You Can Actually Repeat</a><br>SpecterOps&#39;s <a class="link" href="https://linkedin.com/in/neeraj-gupta97?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Neeraj Gupta</a> introduces <a class="link" href="https://github.com/SpecterOps/Jailbreaker-CE?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Jailbreaker</a>, an open-source platform for testing whether an LLM can be jailbroken. It turns ad hoc jailbreak testing into a repeatable workflow with a UI for configuring targets, running techniques, and tracking comparisons. The technique registry covers direct and indirect prompt injection, roleplay, encoding obfuscation, system prompt extraction, and iterative attacks including PAIR, TAP, Crescendo, AutoDAN, and GPTFuzz, with Target/Attacker/Judge roles saved as reusable profiles and matrix experiments landing in PostgreSQL with SQL-backed views.</p><p class="paragraph" style="text-align:left;">Gupta positions Jailbreaker as an operator-first alternative to Microsoft&#39;s PyRIT, which requires composing Python primitives to build a testing workflow. Jailbreaker ships as a clone-and-run Docker Compose stack, so the default experience is running an evaluation rather than wiring components together.</p><p class="paragraph" style="text-align:left;">💡 Given how effective roleplay can be in jailbreaks, I wonder if all that practice has caused a measurable improvement in the love lives of AI security professionals? 😏 “You are a bad, threat actor…” </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=L7D7KCs6PNE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Everytime We Touch - Cascada [Speed Bag Cover]</a> - If ever you’re down and despairing about the future, know that there’s a YouTube channel called “Speedbag Bard” and realize that the human spirit is indomitable</p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=EonibwnAEME&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">How to Catch Up In Life (Using Logic)</a></p></li><li><p class="paragraph" style="text-align:left;">Anthropic - <a class="link" href="https://www.youtube.com/watch?v=rKV5JcALQoQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">What’s at the center of Claude’s mind?</a> - Neat visual imagery. I thought this video did a great job describing things in a way that’s accessible to a lay person.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=74BbqTA5d7M&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Harry Spotter</a> - AI-powered take on if Hogwarts was a school for gym bros. Never skip leg day.</p></li><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=sY1UqUuBqQQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">On-call Engineer 2026</a></p></li><li><p class="paragraph" style="text-align:left;">Characters Welcome - <a class="link" href="https://www.youtube.com/watch?v=dXKUgjYh7lo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">That Song In Every Musical That No One Likes</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/FOz_X6V23IM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">Self-aware f boy</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-336-autonomous-vulnerability-hunting-guarddog-3-0-are-bug-bounties-cooked" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=45147208-0c75-4bfd-beae-27817e39bec9&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec</title>
  <description>Interesting paper, LLM-powered hardening of the PHP ecosystem, security implications of the new MCP spec</description>
  <link>https://tldrsec.com/p/tldr-sec-335</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-335</guid>
  <pubDate>Thu, 02 Jul 2026 19:24:47 +0000</pubDate>
  <atom:published>2026-07-02T19:24:47Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👰 🤵 Wedding</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">This past weekend I attended a friend’s wedding, and it was heartwarming.</p><p class="paragraph" style="text-align:left;">The couple have been together over a decade, and had many fun stories to share from their time in college, to adventures on the East and West Coasts.</p><p class="paragraph" style="text-align:left;">There was a welcome party the night before at a local brewery, and it just so happened that the local Hells Angels chapter decided to have an event… at the same time and venue 😂 </p><p class="paragraph" style="text-align:left;">So it was half people dressed in wedding semi-formal attire celebrating love, and half Harleys, chains, black shirts, and whole arm tattoos. I subtly took a photo of one man wearing a shirt that said, “Every normal man must be tempted, as times, to spit on his hands, hoist the black flag, and begin slitting throats. -H.L. Mencken.” You know, chill stuff.</p><p class="paragraph" style="text-align:left;">At one point there was a motorcycle burnout that caused a big cloud of smoke, I think honoring someone who had passed. My friend said if no one does a burnout at his funeral he’ll be very disappointed.</p><p class="paragraph" style="text-align:left;">I enjoyed getting to meet the couple’s family and more of their friends, that gives you such an interesting view into their lives and who they’ve been over time.</p><p class="paragraph" style="text-align:left;">And I’ll never forget the joy of me dancing around my friend who adamantly doesn’t dance, except at EDM raves.</p><p class="paragraph" style="text-align:left;">It was nice to have a weekend offline, connecting with people, instead of being terminally online and “yOu’LL NeVeR b3lieVe WHat &lt;model | open source repo&gt; jUsT DroPPed?!11!”</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>What Jamf changed to stop drowning in </b><br><b>IT tickets</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">500+ SaaS apps. Thousands of devices. A flood of help desk tickets. And a team of 30 people to manage all of it.</p><p class="paragraph" style="text-align:left;">That&#39;s the reality for Jamf&#39;s IT team - but instead of drowning, they built their way out. We&#39;re bringing them live on July 10th to show you exactly how they replaced manual, ticket-based IT work with intelligent workflows.</p><p class="paragraph" style="text-align:left;"><b>Tune in to hear:</b></p><ul><li><p class="paragraph" style="text-align:left;"><b>The early use cases</b> that proved the value of intelligent workflows at Jamf</p></li><li><p class="paragraph" style="text-align:left;"><b>Where AI fits into ITOps today </b>- and where it&#39;s going</p></li><li><p class="paragraph" style="text-align:left;">How they compressed <b>a year-long device audit into a matter of weeks</b></p></li></ul><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=tl;drsec&utm_medium=paid_media&utm_content=newsletter-primary-0207" target="_blank" rel="noopener noreferrer nofollow"><b>Register now!</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Semgrep found automating a number of workflows with Tines quite helpful 👍️ </p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/badkeys/badkeys?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">badkeys/badkeys</a> - Tool by <a class="link" href="https://www.linkedin.com/in/hanno-boeck/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Hanno Böck</a> that checks cryptographic public keys for known vulnerabilities.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://escape.tech/blog/modern-ai-powered-pentesting-tools-in-depth-benchmark/?utm_source=tldrsec&utm_medium=referral&utm_campaign=in-text" target="_blank" rel="noopener noreferrer nofollow"><b>Escape benchmarked Claude Opus 4.8 vs. their multi-agent multi-model pentesting harness on 4 apps</b></a>,<b> </b>Aikido and XBOW via Doyensec&#39;s numbers. On real apps with no public writeups, the harness found 4x more than the raw model. On severity-weighted score, it also led on both real apps.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Factoring &quot;short-sleeve&quot; RSA keys with polynomials</a> - Trail of Bits&#39;s Keegan Ryan <span style="background-color:rgb(255, 255, 255);">discovered hundreds of vulnerable &quot;short-sleeve&quot; RSA and DSA keys in the wild where private key bits were heavily biased toward 0 in regular patterns, and developed a polynomial-based factorization technique that exploits the regular structure of zero blocks to quickly recover 603 RSA and 74 DSA private keys.</span></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://words.filippo.io/vuln-reports?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Vulnerability Reports Are Not Special Anymore</a><br><a class="link" href="https://bsky.app/profile/filippo.abyssdomain.expert?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Filippo Valsorda</a> argues that LLMs have changed how vulnerability reports should be perceived. For years, reports were treated as special because researchers provided scarce insight into where bugs lived and confidentiality long enough to ship a fix before an exploit. In 2026, LLMs find issues about as well as most security researchers, and anyone can run them. The bottleneck is no longer finding potential issues but assessing which ones are real and which actually affect users. Without an existing trust relationship, external reports add little to that triage, since picking through an LLM&#39;s output and picking through a <code>security@</code> inbox have roughly the same signal-to-noise. Confidentiality matters less for the same reason, since attackers can run their own LLMs and probably hit the same triage bottleneck as defenders. Valsorda believes that triage, rapid remediation, and prevention are the actual job now.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">We have Mythos at Home: GLM 5.2 beats Claude in our Cyber Benchmarks</a><br>Semgrep’s <a class="link" href="https://www.linkedin.com/in/katiepf/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Katie Paxton-Fear</a>, <a class="link" href="https://www.linkedin.com/in/sethjaksik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Seth Jaksik</a>, <a class="link" href="https://www.linkedin.com/in/brendennoblitt/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Brenden Noblitt</a>, and <a class="link" href="https://www.linkedin.com/in/erikbuchanan/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Erik Buchanan</a> benchmarked GLM 5.2, an open-weight model from Zhipu AI, against their IDOR detection dataset using only a basic Pydantic AI harness and prompt, finding it achieved 39% F1 score and beat Claude Code (32%) at roughly $0.17 per vulnerability found, though it still trailed Semgrep&#39;s multimodal pipeline with endpoint discovery scaffolding (53-61% F1, top with GPT 5.5).</p><p class="paragraph" style="text-align:left;">💡 I like posts comparing various models and vanilla models vs model + harnesses. It’d be interesting to know more about the dataset though- languages/frameworks in use, how many examples, etc. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://snyk.io/blog/snyk-vulnbench-js-1-0-llm-security-review-repeatability?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?</a><br>Snyk&#39;s <a class="link" href="https://www.linkedin.com/in/talliran/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Liran Tal</a> describes evaluating Snyk’s VulnBench JS 1.0 (10 JavaScript fixtures with 44 Snyk Code reference findings, each a small Express-based application) across 300 vulnerability scans on (10 fixtures × 6 configurations × 5 repetitions) to measure LLM security review repeatability against Snyk Code SAST as a deterministic reference. As you’d expect, the post found results vary across different LLM-only scans.</p><p class="paragraph" style="text-align:left;">💡 This kind of felt like a puff piece. Of course a deterministic static analysis scan in this setup will be a) faster and b) more consistent than an LLM-based approach. Also, it’s no surprise that a product performs well on simple, small applications it was already tested on. A more representative benchmark would be testing on complex, real-world applications, or at least ones that the product hasn’t already been tuned on. If they released the benchmark apps + reproduction code that would be cool though.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Clear your vulnerability queue</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(28, 43, 51);">Inbox zero for vulnerabilities sounds like a fantasy. Your SCA and SAST scanners flag thousands of findings: dependencies your app never calls, code paths an attacker can&#39;t reach.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(28, 43, 51);">Maze Code is like if inbox zero was a thing for your code vulnerabilities. Maze investigates every finding across your code and dependencies, with context from code and cloud: is the vulnerable function reachable, does the package survive the build, is it exposed at runtime. The findings that aren&#39;t exploitable get closed with a reason for your auditors. For the ones that are risky, our agents write a fix and route it to the developer who owns that code.</span></p><h2 class="heading" style="text-align:center;"><span style="color:rgb(28, 43, 51);"><b>👉 </b></span><a class="link" href="https://mazehq.com/platform/code?utm_campaign=2026Q2-Global-Inbound-Newsletter-CodeLaunch&utm_medium=newsletter&utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(44, 129, 229)"><b>Meet Maze Code</b></a><span style="color:rgb(50, 52, 52);"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I like the product screenshots, it seems like they gather app-relevant context thoughtfully.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://awsteele.com/blog/2026/06/23/some-notes-on-lambda-microvms.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Some notes on Lambda MicroVMs</a><br><a class="link" href="https://www.linkedin.com/in/aidansteele/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Aidan Steele</a> shares hands-on notes on AWS Lambda MicroVMs, a generalisation of Lambda functions that run code in a fresh VM for up to 8 hours. The shell side is a first-class capability since MicroVMs support PTYs natively with shell access through a dedicated AWS API, and inside the VM you can run Docker containers with full OS capabilities. Networking gets its own abstraction called a Lambda Network Connector, a configuration packaging subnets, security groups, and an IAM role for ENI management under its own ARN. The connectors create ENIs in your VPC but hide them by default unless a specific flag is set on the describe call, and AWS has placed resource-based policies on the ENIs so only the Lambda service can mutate them, closing off the old trick of attaching an elastic IP to a Lambda ENI for VPC-attached internet access.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/azure-blob-storage-ransomware-four-methods?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Holding blobs for ransom: Four methods for Azure Storage ransomware</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/jonah-feldman-937784152/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Jonah Feldman</a> describes four techniques ransomware actors use against Azure Blob Storage, all encrypting victim data with keys the attacker controls. Client-side encryption and encryption scope abuse have been observed in the wild by BlackCat&#39;s Sphynx encryptor and STORM-0501 respectively, while customer-provided keys (CPK) and storage service encryption with customer-managed keys (CMK) remain theoretical but viable. He shows how attackers circumvent Azure&#39;s soft-delete protections with cross-tenant CMK configurations and federated identity credentials, placing the key vault in their own tenant so recovery requires paying ransom.</p><p class="paragraph" style="text-align:left;">The post includes Azure Activity, storage resource, and Key Vault event codes for detection, though CPK and encryption scope usage look like normal PutBlob requests in storage logs. Azure Defender for Storage adds threat detection across storage accounts, and three new Stratus Red Team techniques emulate CPK, encryption scopes, and CMK abuse for defense testing.</p><p class="paragraph" style="text-align:left;">For prevention, Feldman recommends immutability and versioning to block the download-encrypt-reupload pattern in client-side encryption and CPK, avoiding long-term credentials like SAS tokens with persistent data-plane access, and flagging cross-tenant CMK configurations to catch the bypass.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/indoor47/gh-workflow-hardener?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">indoor47/gh-workflow-hardener</a><br>Tool by <a class="link" href="https://x.com/indoor47?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Dmytro</a> which scans GitHub Actions workflows for supply-chain risks like unpinned action references vulnerable to tag rewrites, overly broad permissions, and script injection from unsanitized PR inputs. The tool ships as a CLI, GitHub Action, VS Code extension, and hosted API, with an auto-fix mode that resolves action tags to commit SHAs.</p><p class="paragraph" style="text-align:left;">💡 Seems less mature than <a class="link" href="https://github.com/zizmorcore/zizmor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">zizmor</a>, but I like to collect similar tools for future feature comparisons.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://astral.sh/blog/uv-audit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Vulnerability and malware checks in uv</a><br>Astral&#39;s <a class="link" href="https://bsky.app/profile/yossarian.net?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">William Woodruff</a> announces two new security features for uv in preview. uv audit scans dependencies for known vulnerabilities and deprecated packages, running 4-10x faster than pip-audit on typical projects by working from uv&#39;s already-locked resolutions. The second feature is an opt-in malware scan enabled with UV_MALWARE_CHECK=1, which checks OSV for known malicious packages during uv add and uv sync operations and terminates the sync before malicious code has a chance to run.</p><p class="paragraph" style="text-align:left;">💡 Love to see new security features in popular dev tools 🤘 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thephp.foundation/blog/2026/06/23/one-month-of-ecosystem-security-engineering?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">One Month of Ecosystem Security Engineering</a><br>The PHP Foundation&#39;s <a class="link" href="https://www.linkedin.com/in/volker-dusch/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Volker Dusch</a> details one month of ecosystem security engineering work, during which the team scanned over 300 of the most-downloaded Composer packages and nearly all major frameworks using AI models with extended Cyber capabilities for vulnerability discovery, triage, reproducer generation, impact analysis, and fix suggestions. The effort has produced nearly 100 publicly available fixes across the ecosystem so far, with one case where 200 repositories applied the same GitHub Actions fix via a central template.</p><p class="paragraph" style="text-align:left;">The infrastructure runs on <a class="link" href="https://github.com/alpha-omega-security/scrutineer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Scrutineer</a>, an open-source tool the team is developing with Alpha-Omega and ecosystem security engineers from other languages. Scrutineer runs Claude Code skills against open-source repos through a configurable scan pipeline that combines static analysis, model-backed audits, and maintainer identification, with findings landing in a structured database and a guided triage-to-disclosure workflow that can isolate each scan in an ephemeral Docker container. Dusch reports that maintainer report quality has gone up over the past months because maintainers now run their own coding agents to validate findings, though models still refuse to help with exploit work on complex vulnerabilities, and PHP core itself produces worse results than userland libraries because a language runtime is harder for agents to reason about.</p><p class="paragraph" style="text-align:left;">💡 Based on this post, it seems like this mass AI-scanning and patching effort has been well received by the PHP community, which is great. Perhaps because findings have already been reviewed + come with patches, and the effort feels like it’s coming from the community (vs some external party)? </p><p class="paragraph" style="text-align:left;"></p></div><div id="ai-security" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://role-confusion.github.io/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Prompt Injection as Role Confusion</a><br>Charles Ye, Jasmine Cui, and Dylan Hadfield-Menell detail their ICML 2026 paper on prompt injection as role confusion, <a class="link" href="https://github.com/role-confusion/prompt-injection-as-role-confusion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">with code on GitHub</a>. Prompt injection succeeds not because attackers find clever phrasings but because LLMs perceive roles through writing style rather than the structural tags meant to carry trust and authority. The researchers build linear probes that measure how strongly an LLM internally believes a token belongs to a given role, producing per-role metrics including CoTness and Userness. The probes show that reasoning-style text registers as the model&#39;s own thoughts even when explicitly wrapped in user tags, and user-style text registers as user instructions even when wrapped in tool tags.</p><p class="paragraph" style="text-align:left;">The researchers demonstrate this with an attack they call CoT Forgery, which injects fake reasoning into user prompts that mimics the LLM&#39;s own thinking style, raising attack success from near-zero to around 60% across frontier models. Standard prompt injection works the same way, and even simple role-spoofing like prepending <code>User:</code> to a malicious command in tool output increases success. Beyond direct attacks, they warn of subconscious steering, where the same flaw lets seemingly innocuous text shift model behavior without injection, like a shopping webpage with enthusiastic tone pushing an agent toward recommending a purchase.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.akamai.com/blog/security-research/new-mcp-specification-security-teams-must-prepare?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">The New MCP Specification: What Security Teams Must Prepare For</a><br>Akamai&#39;s <a class="link" href="https://www.linkedin.com/in/zavodchik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Maxim Zavodchik</a>, <a class="link" href="https://www.linkedin.com/in/segev-fogel/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Segev Fogel</a> and <a class="link" href="https://linkedin.com/in/gal-meiri?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Gal Meiri</a> describe the upcoming MCP 2026-07-28 spec, which turns MCP from a local integration tool into an enterprise-scale protocol with a stateless architecture, eliminating protocol-level session hijacking, unsolicited server prompts, and weak authentication by mandating OAuth 2.1 with PKCE.</p><p class="paragraph" style="text-align:left;">The new attack surfaces include cross-agent workflow hijacking through predictable tracking IDs or unverified state, client-controlled metadata manipulation via the unsigned <code>_meta</code> object, desync attacks through new MCP-specific headers, stored XSS through interactive MCP Apps, and denial-of-service through long-running asynchronous tasks. Security responsibility moves from the protocol layer to whoever builds on top of it, and the question for security teams is no longer whether the protocol itself is secure but whether the applications built on it correctly implement the new trust boundaries, state management, and execution models the spec introduces.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Introducing AWS Continuum: Security at machine speed</a><br>AWS’ <a class="link" href="https://www.linkedin.com/in/chetkapoor/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Chet Kapoor</a> announces Continuum for code vulnerabilities, an agentic security platform that uses multiple frontier models to manage the full vulnerability lifecycle through four phases: discovery (ingesting existing backlogs and scanning environments), prioritization (using business context like deployment status and reachability), validation (constructing working exploits in sandboxed environments to confirm findings), and mitigation/remediation (recommending network changes, policy updates, or code patches that are validated before deployment). </p><p class="paragraph" style="text-align:left;">Continuum operates in &quot;learn mode&quot; with human oversight initially, then can graduate to &quot;enforce mode&quot; for automated remediation based on defined risk profiles, and incorporates existing AWS Security Agent capabilities like pen testing, code scanning, and a new threat modeling feature that outputs STRIDE-format models from design docs or source code. Continuum reasons over both structured data (infrastructure, permissions, network topology) and unstructured data (documents, communications, business priorities) to provide context-aware security decisions.</p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/Oxzh_zP2TnY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Walking my dog at 3am</a></p></li><li><p class="paragraph" style="text-align:left;">Lyra - <a class="link" href="https://lyra.horse/blog/2026/06/reddit-spam-internals?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">A peek into Reddit&#39;s anti-spam internals</a></p></li><li><p class="paragraph" style="text-align:left;">Macworld - <a class="link" href="https://www.macworld.com/article/3175443/ios-27s-shortcuts-is-ai-at-its-best.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">iOS 27&#39;s Shortcuts is AI at its best</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intheweights.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">In the Weights</a> - Enter a name and see how much it appears in the training data of major LLMs based on its prominence in model weights.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://complexdiscovery.com/estonia-aims-to-be-first-to-give-ai-agents-official-digital-ids?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Estonia aims to be first to give AI agents official digital IDs</a></p></li><li><p class="paragraph" style="text-align:left;">WIRED - <a class="link" href="https://www.wired.com/story/ai-arms-race-china-us-cooperation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">I Met With China’s Top AI Experts. They’re Freaking Out, Too</a></p></li><li><p class="paragraph" style="text-align:left;">Tim Ferriss - <a class="link" href="https://tim.blog/2026/06/12/has-ai-already-killed-nonfiction?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Has AI Already Killed How-To Nonfiction? Sales Trends, My Personal Data, and What It Might Mean for the Future</a></p></li><li><p class="paragraph" style="text-align:left;">The Marginalian - <a class="link" href="https://www.themarginalian.org/2013/11/11/kurt-vonnegut-advice-to-children?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Kurt Vonnegut’s Life-Advice to His Children</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.raptitude.com/2026/06/do-things-youll-love-yourself-for?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Do Things You’ll Love Yourself For</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://pentesty.co/blog/novo-nordisk-ozempic-fulcrumsec-breach-2026?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">A Leaked GitHub Token Exposed the Exact Ozempic Formula</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://san.com/cc/peter-thiels-dialog-network-was-super-secret-a-data-leak-changed-that?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">Peter Thiel’s ‘Dialog’ network was super-secret. A data leak changed that</a> - The leak exposed 113 prominent members through code embedded in the website, alongside detailed participant profiles with personal contacts, political leanings, and other private details. <span style="background-color:rgb(255, 255, 255);">The names tied to Dialog include Treasury Secretary Scott Bessent, Sarah Bond, the former president of Xbox at Microsoft, Sen. Ted Cruz, Joseph Gordon-Levitt, podcast host and author Sam Harris, and Bryan Johnson.</span></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-335-prompt-injection-as-role-confusion-php-ecosystem-security-new-mcp-spec" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=568688ac-4eef-4b74-95c5-cf109ca92c4a&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #334 - Thinkst&#39;s Package Proxy, OpenAI Daybreak, AI Agents &amp; Canaries</title>
  <description>OSS tool to prevent supply chain attacks without client-side firewalls, OpenAI announces new GPT-5.5-Cyber, Codex Security plugin updates, and more, can AI agents compromise an AWS cyber range without tripping canaries?</description>
  <link>https://tldrsec.com/p/tldr-sec-334</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-334</guid>
  <pubDate>Thu, 25 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-25T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🖼️ Meme</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Unfortunately work’s been too busy this week for me to lovingly write an artisanal, handcrafted intro combining snippets from my week, whimsy, and reflections on life and dare I say, what it means to be human. </p><p class="paragraph" style="text-align:left;">So for now, I share a meme:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/78008e26-24cf-485a-8c66-85b309c63211/image.png?t=1782364871"/><div class="image__source"><span class="image__source_text"><p>Shout-out <a class="link" href="https://www.rd.com/list/ai-memes/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Reader’s Digest</a></p></span></div></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Device code phishing in 2026: live demos, real kits, and where it&#39;s headed next </b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">18 kits, a 37x spike in detections, and every major AiTM vendor adding it to their platform. Device code phishing has gone from espionage-grade to criminal commodity. </p><p class="paragraph" style="text-align:left;">It’s easy to see why attackers are adopting it at scale: it bypasses passwords, MFA, and passkeys by targeting the authorization layer instead of the login flow. </p><p class="paragraph" style="text-align:left;">Join Push Security&#39;s VP of R&D Luke Jennings for live attacker-side demos and a breakdown of the kits and campaigns we&#39;re tracking in the wild.</p><h2 class="heading" style="text-align:center;"><b>👉</b><a class="link" href="https://hubs.li/Q04jNDyt0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow"><b> Register now</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Luke and the Push Security folks share great security research, this will be cool.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">From SQLi to RCE – Exploiting LangGraph’s Checkpointer</a><br>Checkpoint Research&#39;s <a class="link" href="https://www.linkedin.com/in/yardenporat1/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Yarden Porat</a> describes three vulnerabilities in LangGraph&#39;s persistence layer, two of which chain into remote code execution against self-hosted deployments. The chain starts with a SQL injection in the SQLite checkpointer where user-controlled filter input is inserted directly into the database query, letting attackers plant fake rows into the results. Because LangGraph deserializes whatever it reads back from the checkpoint table, the planted row triggers an unsafe msgpack deserialization that imports and calls attacker-controlled Python functions, giving them shell access on the server. A parallel SQL injection introduces the same flaw into the Redis checkpointer.</p><p class="paragraph" style="text-align:left;">The vulnerabilities require self-hosted LangGraph deployments where the application exposes <code>get_state_history()</code> with a user-controlled filter. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/06/17/session-switcher.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Introducing Session Switcher. Swap Burp Sessions with One Click!</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/savino-sisco/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Savino Sisco</a> shares <a class="link" href="https://github.com/doyensec/burp-session-switcher?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Session Switcher</a>, an open-source Burp Suite extension that streamlines authorization testing for privilege escalation and IDORs by letting testers save and swap HTTP sessions with one click from the request editor. Named sessions store a set of cookies and headers captured from any selected request, and a dropdown in the new Sessions tab swaps the active identity instantly. Sessions persist in the project file and work wherever there is an editable request editor, including Repeater and intercepted Proxy requests. </p><p class="paragraph" style="text-align:left;">Auto-update rules monitor Burp Proxy traffic and refresh stored sessions when new cookies or headers are detected, so long authorization tests do not break when tokens expire or cookies rotate mid-session. Rules range from simple header matches like <code>X-User: alice</code> to complex conditions like tracking JWTs by payload. Future plans include Auto Inject rules for transparent session switching and macro-based session refresh capabilities.</p><p class="paragraph" style="text-align:left;">💡 This looks awesome. I’d have loved to have this in my NCC Group consultin’, Burp wieldin’ days.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Adaptive Security: Your Attackers Are Using OSINT. So Should Your Phishing Tests</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Phishing attacks have increased +4,150% since ChatGPT&#39;s launch, and AI has made them faster, cheaper, and more personalized than ever. Adaptive&#39;s OSINT and AI spear phishing engine analyzes your organization&#39;s public digital footprint and uses it to generate personalized phishing lures targeting each employee. The same data attackers are already using, now working in your defense. Run automated phishing programs that stay current with evolving threats without manual campaign management.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#2C81E5;"><b>👉 </b></span><span style="color:#2C81E5;"><b><a class="link" href="https://www.adaptivesecurity.com/lp/nb/phishing-simulation?utm_source=sp_email&utm_medium=newsletter&utm_campaign=2026_05_NA_TLDR_sec_newsletter&utm_id=701Rd00000guu14IAA" target="_blank" rel="noopener noreferrer nofollow">See it in action </a></b></span><span style="color:#2C81E5;"><b>👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AI is definitely supercharging phishing, Google’s Threat Intelligence Group and others have shared <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">examples</a>. Good to be aware of the latest threats and test against them 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/05/25/cloudsectidbits-elbaph-alb.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Navigating Lax Load Balancers: When an Intersection Gets You Inside</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/francesco-lacerenza/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Francesco Lacerenza</a> and <a class="link" href="https://www.linkedin.com/in/ouadmoha/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Mohamed Ouad</a> dig into AWS Elastic Load Balancers (ALB) and the gap between how an ALB is configured and what an external request can actually reach. They examine<span style="background-color:rgb(255, 255, 255);"> misconfigurations that create unintended routing paths, identifying issues like CloudFront/WAF bypasses via direct ALB access, rule shadowing where lower-priority broad rules prevent restrictive authentication rules from firing, and IP gate bypasses when the same backend targets are reachable through alternate ALBs without source-ip restrictions.</span></p><p class="paragraph" style="text-align:left;">They’ve released <a class="link" href="https://github.com/doyensec/elbaph?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">ELBaph</a>, a Go CLI that maps ALBs, NLBs, listeners, rules, and targets into one routing model, runs targeted HTTP and HTTPS reachability probes, and reports each finding with its root cause, exploit path, and remediation. See also the corresponding Terraform <a class="link" href="https://github.com/doyensec/cloudsec-tidbits/tree/main/lab-elbaph?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">practice lab</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://permiso.io/blog/gcp-servicedata-officially-deprecated-actively-dangerous?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Mind the Gap: GCP serviceData in Logs Explorer vs. Exported Logs</a><br>Permiso Security&#39;s <a class="link" href="https://www.linkedin.com/in/artukshini/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Art Ukshini</a> describes an inconsistency in GCP&#39;s deprecated <code>serviceData</code> field where audit logs viewed in the native viewer arrive populated but the same logs exported to downstream analytics platforms arrive stripped of fields, causing critical detection fields like <code>policyDelta</code> to be stripped from high-value security events such as disabling audit logging across all services via <code>SetIamPolicy</code>. </p><p class="paragraph" style="text-align:left;">This creates silent detection failures where security rules appear functional but never fire on critical events, affecting both custom detections and Google Chronicle&#39;s community rules. Recommendation: validate telemetry end-to-end through the export pipeline, alert on stripped events as an anomaly signal, cross-reference the newer field for migrated services, and watch the documentation for changes against existing detection coverage.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://nesbitt.io/2026/05/04/package-manager-cwes.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Package Manager CWEs</a><br><a class="link" href="https://nesbitt.io/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Andrew Nesbitt</a> analyzed roughly two hundred public CVEs and security advisories and found twenty recurring vulnerability patterns across package managers. <span style="background-color:rgb(255, 255, 255);">On the client side, the most common issues include path traversal during archive extraction (often requiring multiple fixes for </span><code>../</code><span style="background-color:rgb(255, 255, 255);">, symlinks, and Windows paths), argument injection into VCS commands like </span><code>git clone</code><span style="background-color:rgb(255, 255, 255);">, integrity checks that fail open when signatures are missing, credentials leaked across registry redirects, dependency confusion from incorrect source prioritization, and unsafe YAML/XML deserialization in manifests. </span></p><p class="paragraph" style="text-align:left;"><span style="background-color:rgb(255, 255, 255);">Registry-side vulnerabilities concentrate on authorization bypasses allowing package takeover, account takeover via expired email domains and credential stuffing, stored XSS in rendered package pages, server-side RCE from the same parsing bugs that affect clients, and SSRF via repository URLs, </span>and IDOR on admin endpoints in multi-tenant self-hosted registries. Almost every tool in the survey has at least half of these bugs.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.thinkst.com/2026/06/introducing-package-proxy-supply-chain-safety-checks-without-client-side-software.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Introducing Package Proxy: supply-chain safety checks without client-side software</a><br>Thinkst Canary&#39;s <a class="link" href="https://www.linkedin.com/in/jacobtorrey/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Jacob Torrey</a> shares <a class="link" href="https://github.com/thinkst/package-proxy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Package Proxy</a>, an open-source Cloudflare Workers-based tool that intercepts package manager requests (npm, pip, uv, cargo) to enforce security policies before packages are installed, no client-side wrapper needed. Package managers use an index URL to fetch metadata, and that URL can be changed through configuration to point at Package Proxy instead of the upstream registry. The proxy sees every metadata request, infers which packages the client wants to install, runs the configured checks, and either returns a 404 to block the install or fetches and serves the package if it passes.</p><p class="paragraph" style="text-align:left;">Default checks include a minimum 10-day package age so backdoors get discovered before installation, upload mechanism regression detection on PyPI and npm that blocks packages uploaded differently than previous versions, allow and block lists, and an npm audit bypass for critical fixes. Per-package exceptions are managed via Wrangler CLI, and all installation attempts log to a D1 database for auditing. </p><p class="paragraph" style="text-align:left;">“<span style="background-color:rgb(255, 255, 255);">Internally we run a fork which enforces a stronger version of the allow list; we block </span><code>npm</code><span style="background-color:rgb(255, 255, 255);"> packages by default and developers have to request additions to the allow list.”</span></p><p class="paragraph" style="text-align:left;">💡 Neat approach, and awesome that Thinkst open sourced it 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://agentic.tracebit.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">AI Agents & Canaries</a><br>Tracebit benchmarked ten AI frontier models inside a controlled AWS cyber range to determine how fast they could compromise an environment and if they’d trip canaries along the way. Across 951 attack runs, AI achieved admin privilege escalation in 162 cases within an average time of 14 minutes across successful runs. Of those compromising runs, canaries provided advance warning before the attacker&#39;s first critical action in 95.9% of runs. </p><p class="paragraph" style="text-align:left;">Across attack paths, canaries are hit on average 8 minutes ahead of any critical action. In a surprise finding, simply telling models to expect deception reduced the number of accounts fully compromised (admin + persistence) from 20% to 3%.</p><p class="paragraph" style="text-align:left;">💡 Great visual layout of the results and stats, replay visualization, methodology description, etc. Nice write-up, excellent security research content marketing example 👌 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-salesforce?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Mapping out your unknown: A threat hunter’s guide to Salesforce</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/julie-a-sparks/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Julie Agnes Sparks</a> describes threat hunting queries for detecting attacker behavior in Salesforce environments, mapping detection opportunities across reconnaissance, initial access, credential access, and discovery phases to MITRE ATT&CK tactics. The queries hunt for malicious OAuth app approvals, compromised third-party integrations, and stolen SSO credentials, drawing on Event Log Files and Real-Time Event Monitoring. Concrete signals to watch for include Guest user account activity, failed MFA attempts using weak verification methods like SMS, email, and TOTP, OAuth authentication anomalies, calls to the LimitSnapshot API endpoint that probe usage thresholds, and broad SOQL queries counting sensitive objects like Account, Contact, and User tables that precede data exfiltration.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/daybreak-securing-the-world/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Daybreak: Tools for securing every organization in the world</a><br>OpenAI announced an expansion to Daybreak, an initiative to help secure the world’s software. Four main updates: an updated and better GPT-5.5-Cyber, an updated Codex Security plugin, a Patch the Planet initiative with Trail of Bits, and the new Daybreak Cyber Partner Program, enabling 20+ security vendors including Palo Alto Networks, CrowdStrike, and Wiz to integrate GPT-5.5 with Trusted Access for Cyber into their products. </p><p class="paragraph" style="text-align:left;">The Codex Security plugin now provides end-to-end workflows including threat modeling, reachability analysis, patch generation and validation, SARIF export, and integration with existing vulnerability management systems. OpenAI is collaborating with governments including the US, UK, Australia, Canada, France, Germany, Japan, and South Korea to provide Trusted Access for Cyber partnerships and protect critical infrastructure.</p><p class="paragraph" style="text-align:left;">💡 My first launch 🙌 I’m not gonna lie, it was super cool getting to be a part of the behind the scenes of making this happen. Lots of work from a ton of people. If you have specific asks for new features in the Codex Security plugin (or anything else we should be building), holla at ya boy 💌 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://joshuasaxe181906.substack.com/p/glm-52-not-mythos-is-the-real-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">GLM-5.2, not Mythos, is the real security emergency</a><br><a class="link" href="https://linkedin.com/in/joshsaxe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Joshua Saxe</a> argues that the open-weights model GLM-5.2, not restricted closed source frontier models, poses the real security threat because it enables attackers to run agentic operations privately on 8 H200s, without logging or guardrails. GLM-5.2&#39;s capabilities, matching GPT-5.5 and Opus 4.8 for code and terminal operations, will enable attackers to conduct semi-autonomous kill-chain execution, develop implants and C2 infrastructure, find zero-days, and run long-con scams, while defenders have been denied access to Mythos/GPT-5.5-Cyber, despite them running on monitored private servers. </p><p class="paragraph" style="text-align:left;">Joshua believes our focus should shift from restricting frontier model access to accelerating AI adoption among defenders and security vendors, as the open-weights genie is already out of the bottle and defenders need equivalent capabilities to pay down security debt and build detection-and-response innovations before attackers build out their own automation.</p><p class="paragraph" style="text-align:left;">“<span style="background-color:color(display-p3 1 1 1);">We can now expect a dark economy to emerge around serving open weights near frontier models via API, just as we have dark economies around malware, zero-day exploits, credential dumps, and initial access into victim networks.”</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://shad0wmazt3r.github.io/ai-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">The Agent Is Not the Scanner: Making AI Security Agents Better</a><br><a class="link" href="https://www.linkedin.com/in/pratyaksha-beri/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Pratyaksha Beri</a> ran 11 models through three configurations (no scaffolding, skills only, MCP tools enabled) on 20 vulnerability-finding tasks and found that whether scaffolding helps depends almost entirely on how capable the model already is. Weak models gained substantially from skills, while strong models regressed. Weak models need the structure skills provide, an explicit list of what to detect, what counts as evidence, and what shape the output needs to land in. Strong models already have those patterns internally, and the extra structure just costs them tokens they could have spent reasoning.</p><p class="paragraph" style="text-align:left;">Other takeaways: different models benefit from different scaffolds, separate recon, exploit reasoning and reporting as different models will perform better (and use cheap models on recon, frontier on exploit reasoning).</p><p class="paragraph" style="text-align:left;">💡 I always like an eval/benchmarking post. Intuitively you’d think skills and/or MCP tools would generally improve performance, but it depends on the model and task. In this case I will note though that the task seems to have just been examine a small code snippet for vulnerabilities, which is much different than navigating large, real world code bases. Also if the model can dynamically test its hypotheses that will also improve outcomes.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">OpenAI unveils its first custom chip, built by Broadcom</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/z7C0i?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Anthropic says Alibaba illicitly extracted Claude AI model capabilities</a></p></li><li><p class="paragraph" style="text-align:left;">Satya Nadella - <a class="link" href="https://x.com/satyanadella/status/2066182223213293753?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">A frontier without an ecosystem is not stable</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/w0vTF?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Get-a-Waymo: How a burglar used a robotaxi to flee the scene in a first-of-its kind S.F. case</a> - New #PeakBayArea example. “<span style="background-color:rgb(255, 255, 255);">The getaway car was parked just outside the Marina yoga studio...” </span>😂 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://coveillance.org/a-walking-tour-of-surveillance-infrastructure-in-seattle/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">A walking tour of surveillance infrastructure in Seattle</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://Ycombinator.FYI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Ycombinator.FYI</a> - Examples of “17 fraud & scandals, 41 exhibits filed, 5 copycats & grifts.”</p></li><li><p class="paragraph" style="text-align:left;">Fireship - <a class="link" href="https://www.youtube.com/watch?v=ML3q7Ok4hJg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">I read every major CS paper of the last 100 years...</a> - Nice overview of work by Turing, Claude Shannon, foundational AI papers, etc.</p></li><li><p class="paragraph" style="text-align:left;">Fireship - <a class="link" href="https://www.youtube.com/watch?v=Sntj4HmuykI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">SQLite is being rewritten in Rust</a></p></li><li><p class="paragraph" style="text-align:left;">CharactersWelcome - <a class="link" href="https://www.youtube.com/watch?v=dXKUgjYh7lo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">That Song In Every Musical That No One Likes</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/VU8N6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">Walking Slower? Why Your Ears, Not Your Knees, Might Be the Problem</a> - Apple’s hearing study used real-world data from more than 57,000 iPhone users and made a connection between hearing loss, walking speed, and potential longevity implications.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.absurdlyoptimized.com/recipes/pancakes/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">The absurdly optimized pancake</a> - “A systematic investigation of acid-base neutralization, CO2 production kinetics, gluten inhibition, and the Maillard reaction as applied to a 125-gram flour batter, with an interactive stoichiometric calculator that adapts to whatever is in your refrigerator.“</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-334-thinkst-s-package-proxy-openai-daybreak-ai-agents-canaries" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=9dc8329b-a2f4-4ca7-98a1-796ebd3fafe8&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #333 - Perplexity&#39;s Bumblebee, Evading Cloud Logging, AI Vuln Hunting Spec</title>
  <description>OSS tool to scan packages, agent configs, editors, and browser extensions for malware, tactics for evading cloud logging, a specification to generate your own custom agentic AI security scanning system</description>
  <link>https://tldrsec.com/p/tldr-sec-333</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-333</guid>
  <pubDate>Thu, 18 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-18T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🙏 Busy, Exciting, Busy</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Thanks so much to everyone who reached out last week! I received so many kind emails, LinkedIn comments, and texts, I was filled with joy. My heart grew at least 3 sizes 🥹</p><p class="paragraph" style="text-align:left;">Apologies if I haven’t responded yet, there are somehow even more things going on inside OpenAI than you’d expect, and I’ve been a bit buried.</p><p class="paragraph" style="text-align:left;">We’ve been sprinting on some things… that you might see soon 🤭</p><p class="paragraph" style="text-align:left;">Speaking of, I’m actually going to be doing a live session with some colleagues <b>next Thursday</b> about Daybreak, our vision for empowering defenders.</p><p class="paragraph" style="text-align:left;">We’ll discuss cyber models, early insights from working with leading teams, show how these capabilities fit into security workflows, and discuss where AI-assisted defense is headed next.</p><p class="paragraph" style="text-align:left;">We’ll likely cover new security product stuff we’re shipping, and even a live <b>demo</b> (I’m starting my sacrifices to the demo gods now 🙏).</p><p class="paragraph" style="text-align:center;">👉️<b> </b><a class="link" href="https://webinar.openai.com/register/daybreak-live-the-next-frontier-in-cyber-defense?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow"><b>Join live Thursday June 25, 1pm PDT</b></a><b> </b>👈️<b> </b></p><p class="paragraph" style="text-align:left;">Hope to see you there!</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Is Your Segmentation Real, or Just a Comfortable Illusion?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI-generated exploits don&#39;t need sophistication, just a gap you don&#39;t know exists. Target-specific attacks are generated in minutes, built to find what your tools can&#39;t see.</p><p class="paragraph" style="text-align:left;">runZero shatters the segmentation illusion. New attack path mapping and topology visualizations reveal how an attacker can move through your environment. Safely enumerate sub-assets hidden behind protocol gateways like Modbus, BACnet, and EtherNet/IP that other tools miss entirely.</p><p class="paragraph" style="text-align:left;">Every asset, every exposure, every attack path across IT, OT, IoT, cloud, and mobile. With runZero, defenders win by default. Even against AI.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.runzero.com/try/?utm_source=tldr-sec&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow"><b>Start your 21-day free trial </b></a><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">I’ve heard runZero is crazy good at mapping environments.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.janestreet.com/formal-methods-at-jane-street-index?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Formal methods and the future of programming</a><br>Jane Street’s <a class="link" href="https://x.com/yminsky?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Yaron Minsky</a> describes how they’re building a formal methods team after 25 years of skepticism, driven by the belief that agentic coding has fundamentally changed the cost-benefit calculus of formal verification. Yaron argues that AI agents both reduce the cost of formal methods (by making proof construction more accessible) and increase the benefits (by providing better verification for AI-generated code that tends toward &quot;slop&quot;, and by offering the universal guarantees that agents need for effective feedback during training and coding). </p><p class="paragraph" style="text-align:left;">“Our hope is to make formal methods as pervasively useful of a tool for building software as sophisticated type systems are for us today.”</p><p class="paragraph" style="text-align:left;">💡 Useful things to reflect on whenever there are meaningful tech changes, AI or otherwise: what used to be hard that is now easy? What used to be impossible that is now feasible? What used to be too costly or too slow that now could make sense? I’m actually pretty bullish on formal methods in the AI era. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.blog/security/making-secret-scanning-more-trustworthy-reducing-false-positives-at-scale?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Making secret scanning more trustworthy: Reducing false positives at scale</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/mwakaba/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Mariko Wakabayashi</a> details how the Agents Offense team helped GitHub adopt Microsoft’s Agentic Secret Finder&#39;s verification approach into its AI-powered secret scanning, cutting customer-confirmed false positives by 75%. Rather than feeding the model more data, the approach extracts focused, high-signal usage context such as whether a detected value is assigned to a variable and later passed into an API request, authentication header, database client, or cloud SDK call, as well as execution paths. Providing the right context lets the model separate real exposures from noise like UUIDs, test data, or placeholders without reducing detection coverage.</p><p class="paragraph" style="text-align:left;">💡 This work sounds neat, and <a class="link" href="https://github.blog/engineering/platform-security/finding-leaked-passwords-with-ai-how-we-built-copilot-secret-scanning/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">How we built Copilot secret scanning</a> shares a bit more details about GitHub’s approach, but I wish both were a bit more detailed. For an example I like, see Wiz’s post <a class="link" href="https://www.wiz.io/blog/small-language-model-for-secrets-detection-in-code?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">How We Fine-Tuned a Small Language Model for Secret Detection in Code</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Codex Discovered a Hidden HTTP/2 Bomb</a><br>Calif&#39;s <a class="link" href="https://www.linkedin.com/in/quangluongtm/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Quang Luong</a>, <a class="link" href="https://www.linkedin.com/in/jro-sg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Jun Rong</a> and Duc Phan used Codex to discover HTTP/2 Bomb, a remote denial of service affecting nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora in their default configurations. The attack chains two techniques that have been public since 2016. The first abuses HTTP/2&#39;s header compression, where a single saved header can be referenced thousands of times, and each one-byte reference forces the server to allocate a full header in memory. The second tells the server its receive buffer is full, then drips just enough updates to keep the connection from timing out so the server never frees anything.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">A single client on a 100Mbps home connection can pin 32GB of server memory in roughly 20 seconds against Apache and Envoy. A Shodan search found 880,000+ websites supporting HTTP/2 and running one of these servers, though many sit behind a CDN. Calif published PoCs and Docker labs at <a class="link" href="https://github.com/califio/publications/tree/main/MADBugs/http2-bomb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">califio/publications</a>.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Discover the Architecture of Stopping-Power</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Modern threats move faster than platforms built on delayed telemetry, API-derived state, and after-the-fact correlation can control. The next generation of cloud security will not be won or lost on how much risk it can describe. It will be won or lost on how effectively it can convert context into stopping power.</p><p class="paragraph" style="text-align:left;">In their landmark paper, Agentic Cloud Security Platforms: The Shift to Runtime Security, Software Analyst Cyber Research (SACR) demonstrates how the limits of CNAPP are architectural. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.paloaltonetworks.com/cortex/cloud/sacr-acsp-report?utm_source=tldrSEC&utm_medium=eNewsletter&utm_campaign=Cortex-Cloud&utm_content=sacr-agentic-cnapp" target="_blank" rel="noopener noreferrer nofollow"><b>Download this important read</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I do wonder where things are headed if we assume AI-powered attackers can pivot and move through a network faster. How will cloud tools adapt? 🤔 </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://dagrz.com/writing/aws-security/disrupting-aws-logging?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Disrupting AWS logging</a><br>(In 2016!) <a class="link" href="https://www.linkedin.com/in/danielgrzelak/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Daniel Grzelak</a> demonstrates multiple techniques for disrupting AWS CloudTrail logging after compromising an account, ranging from obvious methods like <code>delete-trail</code> and <code>stop-logging</code> to stealthier approaches. Key tactics include disabling multi-region logging with <code>update-trail --no-is-multi-region-trail --no-include-global-service-events</code> to operate freely in non-home regions while suppressing global IAM events, creating an immutable encryption-only KMS key via<code> create-key --bypass-policy-lockout-safety-check</code> so CloudTrail keeps writing logs that nobody can decrypt, redirecting logs to attacker-controlled S3 buckets, modifying bucket policies to block CloudTrail writes, and setting 1-day S3 lifecycle expirations to auto-delete files.</p><p class="paragraph" style="text-align:left;">You can also deploy an AWS Lambda function triggered by S3 object-create events to delete logs immediately on write, winning any race condition against SIEM ingestion while staying within Lambda&#39;s 1 million free monthly invocations to avoid detection through unusual billing patterns.</p><p class="paragraph" style="text-align:left;">💡 As they say, read Daniel’s posts to avoid being a cyber-patsy.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility</a><br>Palo Alto Networks&#39;s <a class="link" href="https://www.linkedin.com/in/yahavfestinger/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Yahav Festinger</a> describes seven attack techniques targeting AWS CloudTrail and Google Cloud Logging services, organized into defense evasion and continuous visibility (transferring logs to the attacker’s accounts, giving visibility into the victim’s environment). Defense evasion techniques include stopping logging, deleting the log storage destination, deleting the log router, impairing logging via an attacker-controlled encryption key, and log poisoning. Continuous visibility techniques include configuring a new log routing resource and log redirection. Attackers can exploit permissions like <code>cloudtrail:StopLogging</code>, <code>s3:DeleteBucket</code>, <code>logging.sinks.update</code>, and KMS key modifications to blind security tools, manipulate audit trails, or exfiltrate logs to attacker-controlled destinations for passive reconnaissance.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Festinger recommends restricting access to logging service APIs to highly privileged users, using immutable log repositories like AWS&#39;s 90-day CloudTrail Event History and Google Cloud&#39;s _Required log bucket, and implementing bucket policies that prevent non-admin modifications. For detection, CloudTrail log file integrity validation flags log poisoning but is off by default for trails created via API or CLI.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Perplexity is open sourcing Bumblebee</a><br>Perplexity has released <a class="link" href="https://github.com/perplexityai/bumblebee?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Bumblebee</a>, a read-only scanner that checks developer machines for risky packages, extensions, and AI tool configurations during supply-chain incidents by parsing metadata files directly without executing code. The tool scans four surfaces: language package managers (npm, pnpm, PyPI, Go modules, etc.), AI agent configs (MCP), editor extensions (VS Code family), and browser extensions (Chromium and Firefox). Bumblebee supports three scan profiles: baseline for routine scans, project for targeted repo checks, and deep for active incident response. </p><p class="paragraph" style="text-align:left;">Bumblebee avoids triggering malicious install scripts by never invoking package managers or running lifecycle hooks, instead reading lockfiles, manifests, and installed package metadata directly. Perplexity integrates Bumblebee into their workflow where Perplexity Computer drafts catalog updates as GitHub PRs after threat signals emerge, humans review them, and Bumblebee then scans endpoints with the updated catalog to identify exposed systems.</p><p class="paragraph" style="text-align:left;">💡 Smart approach, I like this a lot: a single tool to inventory all of these developer attack surfaces, gathers the data in a way that avoids accidental code execution from malicious packages, and integrates with a continuously updating threat catalog 👌 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/12bb6243-1927-412b-a0b6-ade362511b07/image.png?t=1781761187"/></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Securing CI/CD in an agentic world: Claude Code Github action case</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/dor-edry/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Dor Edry</a> and <a class="link" href="https://www.linkedin.com/in/amit-eliahu/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Amit Eliahu</a> demonstrate how Anthropic&#39;s Claude Code GitHub Action could leak CI/CD secrets when processing untrusted GitHub content like issues, pull requests, and comments. While the <code>Bash</code> tool ran inside a Bubblewrap sandbox with environment variables scrubbed, the <code>Read</code> tool bypassed that isolation and could read <code>/proc/self/environ</code> directly, exposing <code>ANTHROPIC_API_KEY</code> and other runner credentials.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">To confirm exploitability, they hid a prompt injection inside an HTML comment that instructed the agent to read sensitive files and truncate the first seven characters of any API key found, bypassing Claude&#39;s safety filters and GitHub&#39;s Secret Scanner. From there, exfiltration was possible via WebFetch, Bash, or issue comments. Anthropic patched the issue in Claude Code 2.1.128 by blocking access to sensitive <code>/proc</code> files.</p></div><p class="paragraph" style="text-align:left;">💡 Making agents useful and secure is tough, lots of sharp edges. Bypassing safety filters/secret scanners via truncating the secret prefix + evading the sandbox is clever. See also the “Research methodology” section at the bottom which is neat: first they used an AI model to do automated, black-box research, then fed the AI model the target Actions codebase and the obfuscated Claude SDK for a human/AI white box collaborative security audit.</p><p class="paragraph" style="text-align:left;"></p><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/grepstrength/malsnitch?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">grepstrength/malsnitch</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/kelvin-winborne/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Kevin Winborne</a> <span style="background-color:rgb(255, 255, 255);">that scans malware artifacts like string dumps, FLOSS output, or Binary Ninja exports to extract embedded secrets such as C2 credentials, crypto keys, API tokens (GitHub PATs, AWS, Stripe, Slack), exfiltration channel credentials (e.g. Discord webhooks, Telegram bot tokens), and hardcoded SMTP/FTP/HTTP credentials.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Cisco-Talos/EvidenceForge?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Cisco-Talos/EvidenceForge</a><br>By Cisco Talos: An open-source tool that generates realistic, multi-format security logs for threat hunting training by solving the core problem of synthetic data: cross-source consistency. EvidenceForge uses a canonical SecurityEvent model to emit 20+ correlated log formats (Windows Security, Sysmon, Zeek, eCAR EDR/XDR, syslog, bash history, Snort, web access, and proxy logs) from a single source of truth, ensuring LogonIDs, PIDs, timestamps, and Zeek UIDs match across all outputs. A causal expansion engine adds prerequisite events with realistic timing, like DNS queries before connections and Kerberos TGT/TGS before domain logons, and a Hawkes process models user activity including Monday login storms and Friday early departures. Network visibility modeling further determines what each sensor can realistically observe.</p><p class="paragraph" style="text-align:left;">Scenarios are authored through Claude Code or Codex agent skills that draw on MITRE ATT&CK, while log generation itself is fully deterministic with no LLM calls. A 4-pillar evaluation framework then scores the output across parseability, plausibility, causality, and timing.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/06/16/mythic-embarking-on-the-open-seas-containerized-payload-delivery-for-kubernetes-assessments?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Mythic Embarking on the Open Seas: Containerized Payload Delivery for Kubernetes Assessments</a><br>SpecterOps&#39; <a class="link" href="https://www.linkedin.com/in/alex-rodriguez-3a46bb84/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Alex Rodriguez</a> introduces two new Mythic C2 extensions, <a class="link" href="https://github.com/elreydetoda/container_wrapper?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">container_wrapper</a> and <a class="link" href="https://github.com/elreydetoda/container_registry?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">container_registry</a>, that streamline containerized payload delivery for Kubernetes assessments by wrapping Mythic payloads into OCI-compatible containers and hosting them in self-managed registries. The <code>container_wrapper</code> uses <code>Buildah</code> to package payloads into container images via Mythic&#39;s web UI, while <code>container_registry</code> uses <code>skopeo</code> to push these images to a distribution-based registry deployed behind an HTTPS redirector. This approach lets operators hand clients a simple Kubernetes manifest to deploy in their own clusters, eliminating manual Docker CLI workflows and supporting container-centric penetration testing in environments where worker nodes have internet egress and no restrictive image policies are enforced.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/05/28/dont-jump-the-turnstile-lessons-from-the-field?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Don’t Jump the Turnstile: Lessons from the Field</a><br>SpecterOps&#39;s <a class="link" href="https://www.linkedin.com/in/zacharydstein/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Zach Stein</a> describes how he beat email phishing sandboxes with Cloudflare Turnstile on a red team engagement, after the same sandbox had defeated every standard evasion he reached for. He first used the <a class="link" href="https://github.com/t94j0/satellite?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Satellite</a> framework to block Linux user agents, but the sandbox swapped to a Windows user agent. He then added a filter page that only redirected after mouse movement, but the sandbox crawled the redirect URL straight out of the HTML. So he implemented Turnstile as a CAPTCHA-like verification layer that hides the redirect URL from the page source, keeping sandboxes from crawling to the payload while looking legitimate to a real user.</p><p class="paragraph" style="text-align:left;">Zach published the build as <a class="link" href="https://github.com/Synzack/Turnstyle?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Turnstyle</a>, a Flask WSGI app fronted by Apache, mod_wsgi, and a Certbot certificate, with an Ansible deployment script in the repo.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.google/security/android-fake-call-detection/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">How Android helps keep you safe from impersonation scams with fake call detection</a> - New feature <span style="background-color:rgb(255, 255, 255);">helps protect you from scammers using AI deepfakes to impersonate your contacts. Shout-out to my friend </span><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://x.com/RachelTobac/status/2061876555995845079?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Rachel Tobac</a></span><span style="background-color:rgb(255, 255, 255);"> for helping inspire the work </span>🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nudgesecurity.com/features/ai-agent-discovery?utm_medium=sponsored&utm_source=tldr&utm_content=newsletter&utm_campaign=ai_security&utm_term=browser-based-agent-discovery" target="_blank" rel="noopener noreferrer nofollow"><b>[NEW] Discover shadow AI agents via the browser</b></a><b> </b>-<b> </b>Most AI agent discovery tools rely on APIs. The problem? A lot of agentic AI platforms don’t expose agent details via an API. Nudge Security just closed this blindspot with browser-based AI agent discovery.*</p></li><li><p class="paragraph" style="text-align:left;">r/ollama - <a class="link" href="https://web.archive.org/web/20260412230759/https://www.reddit.com/r/ollama/comments/1sff7i0/30_days_of_an_llm_honeypot/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">30 Days of an LLM Honeypot</a></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/visa/visa-vulnerability-agentic-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">visa/visa-vulnerability-agentic-harness</a><br>By Visa: An open-source agentic SAST pipeline that uses Claude, OpenAI, or any combination of frontier models for autonomous vulnerability discovery. It prioritizes triage speed over raw discovery volume, with Mean Time to Adapt as its primary metric. Threat modeling focuses the attack surface, multi-agent deterministic voting reduces false positives, and structured triage artifacts compress the path to actionable findings.</p><p class="paragraph" style="text-align:left;">The pipeline runs nine stages, beginning with attack surface mapping and STRIDE/OWASP threat modeling, then specialized research lenses for language, crypto, logic bugs, access control, batch/ETL, and IaC, followed by adversarial verification and exploit chain construction. Output includes Markdown reports and SARIF 2.1.0 artifacts.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/CiscoDevNet/foundry-security-spec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">CiscoDevNet/foundry-security-spec</a><br>Cisco has released the Foundry Security Spec, an open specification for building agentic AI security evaluation systems, distilling production lessons into 130 functional requirements across eight core agent roles (Indexer, Cartographer, Detector, Triager, Validator, Reporter, Coverage Guide, and Orchestrator) plus five optional extensions (Deep-Tester, Variant-Hunter, Attack-Mapper, Remediator, Self-Improver).</p><p class="paragraph" style="text-align:left;">The spec is deliberately infrastructure-agnostic with explicit <code>[NEEDS CLARIFICATION]</code> markers for organization-specific decisions, designed to be consumed via <code>spec-kit</code>&#39;s clarify-specify-plan-implement workflow rather than shipped as runnable code. Foundry implements a detection-to-prevention flywheel where exploratory agents hunt alongside CodeGuard rule sweeps, recording rule gaps that get generalized back into the corpus, so each evaluation improves both detection across all future targets and prevention in developers&#39; LLM coding assistants. See also the <a class="link" href="https://blogs.cisco.com/ai/announcing-foundry-security-spec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">companion blog post</a> by <a class="link" href="https://linkedin.com/in/santosomar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Omar Santos</a>.</p><p class="paragraph" style="text-align:left;">💡 Very cool project idea: a specification for building your own AI-powered code scanner. You customize the spec with your environment, and then it builds according to that. It makes me think of some SciFi show where you plug in your requirements, and then it materializes food or whatever you’re imagining. “Replicators” in Star Trek.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ea7a91a6-4e38-4aad-9bb1-d4acbe88fcb4/Screenshot_2026-06-17_at_11.05.32_PM.png?t=1781762778"/></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">Joshua Saxe - <a class="link" href="https://joshuasaxe181906.substack.com/p/banning-mythos-represents-a-basic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Banning Mythos represents a basic misunderstanding of AI cybersecurity</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/DavidSacks/status/2065853007619588171?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">David Sacks on the Fable ban</a></p></li><li><p class="paragraph" style="text-align:left;">Katie Moussouris - <a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">The Fable 5 Export Controls Harm US Cyber Defense</a></p></li><li><p class="paragraph" style="text-align:left;">Hank Green - <a class="link" href="https://www.youtube.com/watch?v=AcjnLc4TH4M&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">The Riskiest Moment of the AI Bubble</a></p></li><li><p class="paragraph" style="text-align:left;">Bloomberg - <a class="link" href="https://www.youtube.com/watch?v=WZ7mmTrSgxI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Ray Dalio on the bond market, a weaker dollar driving gold demand, and AI bubble concerns</a></p></li><li><p class="paragraph" style="text-align:left;">Bloomberg - <a class="link" href="https://www.youtube.com/watch?v=v1wZwxY3CMg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Inside Anthropic, the $965 Billion AI Juggernaut</a> - Neat profile of Dario and Daniela Amodei, with a little Boris.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Music</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=sy-A-wyzj7c&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Lea Salonga&#39;s Audition for Miss Saigon</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/9u_xn03CBEE?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Row Row Row Your Boat but in different keys at the same time</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=jxaksSr6uco&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">&quot;Go the Distance&quot; - Broadway&#39;s Leading Men Concert</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=yDYlVyMBZiM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Colors of the Wind - Live Orchestra | Pocahontas</a></p></li><li><p class="paragraph" style="text-align:left;">Charles Cornell - <a class="link" href="https://www.youtube.com/watch?v=bUW34jgrCf4&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Phil Collins Made EVERY Parent Sob With 1 Key Change | You&#39;ll Be In My Heart</a> - My dad loved Phil Collins, I remember watching Tarzan with him when I was young 🥹 I burned a few of the best songs from the soundtrack onto a CD when I was in school, and we’d listen to it in the car when we were driving somewhere together, like my karate practice. I could see this song hitting very different as a parent.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.midjourney.com/medical/blogpost?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Midjourney Medical</a> - Holy cow, the image generation site is getting into healthcare, and planning to build a better body scanner, and spa in SF 🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/W0wpON1jDRc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">When Pikachu gave the most epic speech in Pokemon history</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/eJ1aDGB48sM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">A day in the life of a personality-maxxer</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/2FTavzWhtXg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Throwback NFL commercials are the best</a></p></li><li><p class="paragraph" style="text-align:left;">Jon Oliver - <a class="link" href="https://www.youtube.com/shorts/d3y7aLApJkc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Moderator: 1 | Politician: 0</a></p></li><li><p class="paragraph" style="text-align:left;">Mark Manson - <a class="link" href="https://www.youtube.com/watch?v=wwJ1mRCWNKo&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">20 Years of Therapy Summarized in 13 Minutes</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/OWm7JQDgzxA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Trying to understand investing and stock price</a> 😂 </p></li><li><p class="paragraph" style="text-align:left;">Leila Hormozi - <a class="link" href="https://www.youtube.com/watch?v=GRT-HGGYQeQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Do This & Watch How Fast People Stop Disrespecting You</a></p></li><li><p class="paragraph" style="text-align:left;">Sygnia - <a class="link" href="https://www.sygnia.co/blog/operation-highland-velvet-ant/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=nl14OmXPDUA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">What Dreamworks Understands About Evil That Disney Doesn&#39;t</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-333-perplexity-s-bumblebee-evading-cloud-logging-ai-vuln-hunting-spec" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=5d12f4ff-ae83-43e3-a196-fcdb030ce3b1&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #332 - I&#39;ve Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security</title>
  <description>Why I joined OpenAI to lead Cyber efforts, playlist of the latest cloud security talks, AWS&#39; supply chain best practices</description>
  <link>https://tldrsec.com/p/tldr-sec-332</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-332</guid>
  <pubDate>Thu, 11 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-11T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤔 New Job, Who Dis?</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>TL;DR</b>: I’ve joined <b>OpenAI</b> to lead their Cyber efforts.</p><p class="paragraph" style="text-align:left;">I’m joined by <a class="link" href="https://www.linkedin.com/in/michaeleugeneaiello/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Mike Aiello</a>, an awesome security executive and human. Mike was previously CTO at Secureworks, led product for Google Cloud Security from 0 → $B’s in revenue, and CISO at Goldman Sachs.</p><p class="paragraph" style="text-align:left;">I was going to write a post describing all the details about joining, my thought process, etc. but it turns out there’s a lot to do at OpenAI and I’ve gotten very busy 😅 The post is started but not finished, will share when I can.</p><p class="paragraph" style="text-align:left;">So here’s the short version.</p><p class="paragraph" style="text-align:left;"><b>Why</b><br>I was very happy at Semgrep and wasn’t looking for new opportunities, but when an OpenAI recruiter reached out, it seemed like a once in a lifetime company and opportunity that I couldn’t pass by.</p><p class="paragraph" style="text-align:left;">During the interview process, when I spoke with my potential colleagues, I was impressed by how they were incredibly smart and kind, and genuinely, earnestly, cared about making a positive impact on the world. Several people, without me bringing it up, expressed to me that as models get better, they feel a moral responsibility to do what they can to secure the world’s software.</p><p class="paragraph" style="text-align:left;">And now from the inside, I can see that the sentiment was genuine, and not a facade (you always wonder as an outsider). OpenAI has easily already spent millions securing open source and critical infrastructure that they haven’t yet claimed PR cred for doing.</p><p class="paragraph" style="text-align:left;">I’ve long talked about the power of secure by design and eliminating vulnerability <i>classes</i>. Being at OpenAI makes that feel tractable in a way it never has before. I’m optimistic we, the security community, can meaningfully raise the world’s security bar over the next few years. Seriously.</p><p class="paragraph" style="text-align:left;">Lastly, how I think about the decision is also well expressed by my friend <a class="link" href="https://www.linkedin.com/in/ramimac/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>, who, like with many things, annoyingly wrote a better version of what I would write in his post on <a class="link" href="https://ramimac.me/joining-wiz?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">joining Wiz</a>. Similarly, I hope to “<i>work for the security industry, at OpenAI.</i>”</p><p class="paragraph" style="text-align:left;">I shared a <a class="link" href="https://www.linkedin.com/posts/clintgibler_career-update-ive-joined-openai-to-lead-activity-7470579206180237312-Uf45?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">LinkedIn post</a> with a bit more details, feel free to say hi or share thoughts there 👋</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> <i>tl;dr sec</i> will continue, don’t worry. Also, I will continue to include high quality content from Anthropic, that is also unchanged. More on that below.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>State of SDLC Report 2026</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">The 2026 SDLC Security Report analyzed real-world development environments, codebases, and SDLC infrastructure to understand how risk is evolving and how software is built and shipped.</p><p class="paragraph" style="text-align:left;">The TL;DR: Risk isn’t primarily driven by rare vulnerabilities. It scales through reuse, permissions, and automation across the SDLC.</p><p class="paragraph" style="text-align:left;">The report explores:</p><ul><li><p class="paragraph" style="text-align:left;">AI copilots and developer tooling risk</p></li><li><p class="paragraph" style="text-align:left;">Dependency concentration and supply chain exposure</p></li><li><p class="paragraph" style="text-align:left;">Secret leakage trends</p></li><li><p class="paragraph" style="text-align:left;">CI/CD and GitHub Actions attack paths</p></li></ul><p class="paragraph" style="text-align:left;">Learn how SDLC risk is reshaping application security.</p><h2 class="heading" style="text-align:center;"><b>👉</b><a class="link" href="https://www.wiz.io/reports/sdlc-security-report-2026?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY27Q2_INB_FORM_State-of-SDLC-Security-2026&sfcid=701Vh00000aiz35IAA&utm_term=FY27Q2-tldrsec-nl-June&utm_content=State-of-SDLC-2026" target="_blank" rel="noopener noreferrer nofollow"><b> Get the State of SDLC Report</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Hm interesting, neat to see the SDLC is evolving and how it’s affecting AppSec 🤔 I like the stats and figures.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.ammaraskar.com/github-token-stealing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">1-Click GitHub Token Stealing via a VSCode Bug</a><br><a class="link" href="https://github.com/ammaraskar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Ammar Askar</a> describes a bug in which clicking a <a class="link" href="https://github.dev?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">github.dev</a> link could steal a GitHub token with read/write access to all your private repos, by chaining a Jupyter notebook payload that exploits VS Code webview&#39;s <code>did-keydown</code> event forwarding to install a malicious extension. Neat write-up!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/how-we-cut-semgreps-taint-analysis-time-by-75-percent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">How We Cut Semgrep’s Taint Analysis Time by 75%</a><br>Semgrep&#39;s <a class="link" href="https://www.linkedin.com/in/austin-theriault-1648b2168/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Austin Theriault</a> walks through how the taint analysis engine was redesigned to run once instead of twice, cutting scan times by up to 75%. Taint analysis is used for vulnerabilities like SQL injection by tracking user input as it flows through code from sources to sinks, with propagators that carry the taint forward and sanitizers that clean it. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Semgrep&#39;s original 2023 architecture computed those configs during interfile analysis, then discarded them and recomputed during intrafile analysis, a design forced by OCaml&#39;s parallelism limitations before 5.0 that would have ballooned memory if all the state were kept in flight at once. Refactoring to merge both passes unlocked parallelization via OCaml multicore and reduced P95 scan times from 10 minutes to 7:30, with some large repositories seeing 3x+ improvements.</p></div><p class="paragraph" style="text-align:left;">See also: <a class="link" href="https://semgrep.dev/blog/2026/making-semgrep-rip-how-ripgrep-inspired-us-to-shave-hours-off-some-scans/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">How Ripgrep inspired us to shave hours off (some) scans</a> by <a class="link" href="https://www.linkedin.com/in/kettle-ben/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Ben Kettle</a>.</p><p class="paragraph" style="text-align:left;">💡 One fun thing about working at Semgrep is you realize how much hard engineering goes into building static analysis tools. Very cool work, and fun to nerd out with the program analysis team, who are statistically likely to be some combination of a) French, b) have PhDs, or c) be from CMU.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Key questions to ask any AI vendor</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);">Vendors are claiming autonomy - but most are still requiring significant human oversight. And most security teams don&#39;t yet have a clear framework to evaluate the difference.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);">Join Sublime Security and Georgian on June 24 for a practical session on evaluating security AI. You&#39;ll leave with a clear autonomy framework, a trust-based evaluation path, and key questions to ask any AI vendor - including what good answers actually sound like.</span></p><h2 class="heading" style="text-align:center;"><span style="color:rgb(34, 34, 34);"><b>👉 </b></span><a class="link" href="https://sublime.security/events/trust-then-autonomy-a-new-framework-for-evaluating-agentic-ai-in-security/?utm_source=smartbrief&utm_medium=third-party&utm_campaign=webinar" target="_blank" rel="noopener noreferrer nofollow"><b>Register now</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Honestly, it is super useful to know the right pointed questions to ask vendors, as well as having a feel for what “good” and rigorous evals look like in practice.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/playlist?list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">fwd:cloudsec North America 2026</a><br>The premier cloud security conference just uploaded the talks from their most recent event. Highly recommend. Many of the talks look great, and see the blog version of some below. Some additional talks I’m linking here so I can come back to them:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=7WdSOGJ7qjk&list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&index=10&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">In git we trust: Defending Lovable projects from malicious code attacks at scale</a> by <a class="link" href="https://www.linkedin.com/in/hallbergmarcus/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Marcus Hallberg</a> & <a class="link" href="https://www.linkedin.com/in/sckelemen/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Samuel Kelemen</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=cBq-DRNNi8A&list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&index=37&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF</a> by <a class="link" href="https://www.linkedin.com/in/shayberkovich/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Shay Berkovich</a>.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">HazyBeacon and AWS Lambda Function URL Abuse</a><br>Qualys&#39; <a class="link" href="https://www.linkedin.com/in/aniket-harne-547339238/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Aniket Harne</a> breaks down HazyBeacon, a campaign originally documented by Palo Alto Unit 42, where attackers used stolen IAM credentials to deploy AWS Lambda functions with <code>AuthType: NONE</code> Function URLs as command and control relays, making malware traffic indistinguishable from ordinary HTTPS calls to the <code>lambda-url.&lt;region&gt;.on.aws</code> domain. The chain starts with credentials harvested from public GitHub repos or developer phishing, validated through reconnaissance calls like <code>aws sts get-caller-identity</code>, then used to deploy a Lambda function under a benign name in an unused region whose public Function URL proxies traffic between infected endpoints and the attacker&#39;s real backend. The relay sits inside a separate compromised AWS account, which leaves the malware victim and the AWS account holder as two unrelated victims, often unaware they&#39;re connected until the bill or the abuse notice arrives.</p><p class="paragraph" style="text-align:left;">Recommended mitigations: A Service Control Policy blocking <code>AuthType: NONE</code> Function URLs unless explicitly tagged, global CloudTrail logging, enabling VPC flow logs, and more.</p><p class="paragraph" style="text-align:left;">💡 Honestly, pretty clever use of Lambda Function URLs.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://astrix.security/learn/blog/subjugation-hijacking-cloud-identities-by-recycling-namespaces-in-global-oidc-issuers?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers</a><br>Astrix Security&#39;s <a class="link" href="https://www.linkedin.com/in/reverser/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Tal Skverer</a> describes Sub:jugation, a vulnerability class affecting GitHub Actions, GitLab CI, and Terraform Cloud where the global OIDC issuer model lets attackers reclaim deleted repository namespaces and mint JWTs with subject claims that match existing cloud IAM role trust policies. Any cloud role still trusting an orphaned sub claim hands over short lived AWS, Azure, or GCP credentials to whoever recreates the namespace. Astrix calls these forgotten roles Phantom Cloud Identities, and found that 14% of AWS identities and 24% of Azure identities trusting GitHub&#39;s global issuer point at namespaces that are no longer registered, with roughly 8 becoming exploitable each month through publicly available data alone.</p><p class="paragraph" style="text-align:left;">GitHub has shipped the complete fix, adding random identifiers to sub claims so reclaimed namespaces can&#39;t mint matching tokens, while GitLab and Terraform have rolled out interim mitigations with full OIDC subject solutions still pending. Until those land, organizations need to audit every cloud identity trusting <code>token.actions.githubusercontent.com</code>, <code>gitlab.com</code>, or <code>app.terraform.io</code>, confirm the referenced namespace is still theirs, and either reclaim it or decommission the role outright.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/well-architected-best-practices-for-software-supply-chain-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Well-architected best practices for software supply chain security</a><br>AWS&#39;s <a class="link" href="https://www.linkedin.com/in/tschiavone/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Trevor Schiavone</a> and <a class="link" href="https://www.linkedin.com/in/desiree-brunner/?locale=en&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Desiree Brunner</a> walk through defense in depth controls for npm supply chain attacks. <span style="background-color:rgb(255, 255, 255);">Key mitigations include: replacing long-lived credentials with temporary ones via AWS CLI login, IAM Identity Center, or OIDC federation; implementing artifact signing with AWS Signer to cryptographically verify packages before production deployment; centralizing dependency management with AWS CodeArtifact&#39;s package group configuration to block typosquatting; and using Amazon Inspector&#39;s behavioral analysis to detect zero-day malicious packages.</span></p><p class="paragraph" style="text-align:left;"><span style="background-color:rgb(255, 255, 255);">Also: require MFA on maintainer accounts and multiple approvers, analyze CloudTrail logs for indicators of compromise, and leverage Software Bills of Materials to quickly assess blast radius during incidents.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does</a><br><a class="link" href="https://www.linkedin.com/in/guillaumeross/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Guillaume Ross</a> shows how to detect and prevent credential theft from developer workstations by combining <a class="link" href="https://github.com/boostsecurityio/bagel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">bagel</a>, an open source secret scanner, with Fleet, an MDM platform that uses osquery for telemetry, and an IdP conditional access policy. Bagel runs on a schedule through a LaunchAgent to find cleartext secrets in developers&#39; home directories, Fleet reads the JSON output via its <code>parse_json</code> osquery table to evaluate it against a policy, and an IdP blocks SSO on non-compliant workstations until the secrets are remediated.</p><p class="paragraph" style="text-align:left;">Guillaume ships the integration as <a class="link" href="https://github.com/GuillaumeRoss/fleebag?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Fleebag</a>, a proof of concept repo with macOS installation packages for bagel, Fleet queries for findings, a policy query that passes only when scans are fresh and clean, and an example profile to grant bagel full disk access.</p><p class="paragraph" style="text-align:left;"></p></div><div id="ai-security" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/encrypted/status/2058658244328124562?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Cursor bypassing pnpm min release age settings</a> 😅 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/claude-fable-5-mythos-5?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Claude Fable 5 and Claude Mythos 5</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/06/10/cybersecurity-researchers-arent-happy-about-the-guardrails-on-anthropics-fable/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity researchers aren’t happy about the guardrails on Anthropic’s Fable</a> - Preventing model misuse is hard 🙃 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Introducing the Agent Governance Toolkit: Open-source runtime security for AI agents</a><br>Microsoft&#39;s <a class="link" href="https://www.linkedin.com/in/imransiddique1986/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Imran Siddique</a> released the <a class="link" href="https://github.com/microsoft/agent-governance-toolkit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Agent Governance Toolkit</a>, an open source framework of seven packages that aims to address all 10 OWASP Agentic AI Top 10 risks by porting operating system, service mesh, and site reliability patterns to autonomous AI agents. The packages run across Python, TypeScript, Rust, Go, and .NET, and the toolkit plugs into each framework&#39;s native extension points across LangChain, CrewAI, LangGraph, LlamaIndex, OpenAI Agents SDK, and more.</p><p class="paragraph" style="text-align:left;">The toolkit:<i> Agent OS </i>as the stateless policy engine (supports YAML, OPA Rego, and Cedar), <i>Agent Mesh</i> for cryptographic identity, <i>Agent Runtime</i> for sandboxing execution inspired by CPU privilege levels with an emergency kill switch, <i>Agent SRE</i> for applying service level objectives and circuit breakers, and the final three handling compliance, plugin lifecycle management, and reinforcement learning training governance. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://clearbluejar.github.io/posts/system-over-model-tested-mythos-freebsd-local-openweight?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">System Over Model, Tested: Reproducing Mythos&#39;s FreeBSD Find on Local Open-Weight Models</a><br><a class="link" href="https://www.linkedin.com/in/john-mcintosh-613ba2350/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">John McIntosh</a> reproduces Anthropic&#39;s Mythos discovery of CVE-2026-4747, an RCE in FreeBSD&#39;s RPCSEC_GSS authentication, using AISLE&#39;s nano-analyzer pipeline on two local open-weight models (gpt-oss-20b and gemma-4-31b-it). The models could find the bug, but the pipeline graduated 30 false positives that buried the real CVE. Rather than swap to a stronger model, John added one extra reachability filter stage using the same model weights that traces each finding back to an entry point, greps for callers, and checks whether the cited length is really controlled by the attacker or just set by the kernel, cutting false positives from 30 to 5 while keeping the real CVE valid. The <a class="link" href="https://github.com/clearseclabs/system-over-model-gemma?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">full experiment is on GitHub</a>.</p><p class="paragraph" style="text-align:left;">💡 Here’s how I see it: the foundation model labs try to convince you that “all you need is the model” and security vendors (or individuals) argue “it’s all the scaffolding.” Ultimately, I believe the truth is: the model, the prompt(s)/Skills, scaffolding/architecture, and how much you’re willing to spend <i>all matter</i>. Improving each gets overall better performance. Improving the model can get you the same or better results with removed (or less) scaffolding, and improved scaffolding on top of better models will yield even better results (more true positives, fewer false positives/negatives). </p><p class="paragraph" style="text-align:left;">At the end of the day, it all distills down, like most things in security, to: how much risk reduction are you getting at what price? My $0.02 at least.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://red.anthropic.com/2026/attack-navigator/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator</a><br>Anthropic’s <a class="link" href="https://www.linkedin.com/in/kyla-g/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Kyla Guru</a>, <a class="link" href="https://www.linkedin.com/in/alex-moix/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Alex Moix</a>, and <a class="link" href="https://www.linkedin.com/in/jacob-klein-4286a226/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Jacob Klein</a> analyzed 832 banned accounts that misused Claude for cyber operations over one year, mapping 13,873 malicious actions across 482 MITRE ATT&CK techniques and developing the AI Risk Enablement Score (ARiES) to assess threat levels. They found the highest-risk actors weren’t distinguished by technical sophistication or number of techniques used, but by their use of agentic scaffolding to autonomously orchestrate entire attack chains, like one threat actor who weaponized Claude Code with MCP servers to autonomously execute reconnaissance, exploitation, lateral movement, and exfiltration.</p><p class="paragraph" style="text-align:left;">Anthropic argues that the MITRE ATT&CK framework needs expansion to capture AI-native behaviors like autonomous killchain orchestration and real-time pivot decisions that don&#39;t map to existing technique IDs but represent the most dangerous evolution in AI-enabled cyber threats.</p><p class="paragraph" style="text-align:left;">💡 This is really cool, and valuable context for the community on how threat actors are using AI. As mentioned in the intro, expect me to continue including solid technical work from Anthropic. I have many kind, extremely competent friends at Anthropic who I respect highly. I think the world is better off for having many companies and individuals working together to make the world safer. </p><p class="paragraph" style="text-align:left;">Ultimately I think that’s the north star of all of us working in cybersecurity: making the world safer so all <span style="text-decoration:line-through;">non-neck beards</span> people live happy, fulfilling lives without having to worry about getting hacked, having their identity stolen, etc.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><ul><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=sL16tsGafcQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">The 4 Proven Ways To Build Wealth In 2026</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/mnzaVnSgoVU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">“This is gonna be cute, trust me”</a></p></li><li><p class="paragraph" style="text-align:left;">Lea Salonga and Brad Kane - <a class="link" href="https://www.youtube.com/watch?v=GyJI8kr0Qo8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">A Whole New World</a> (1993 Oscars) 🥹</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=76Q5TWHslOE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Hadestown: The Musical | Official Trailer</a> - OMG YAS! Looks like they filmed the original cast, like they did with Hamilton. I love this approach, I wish all musicals did that. I give Hadestown at least 😭😭😭😭/5. Obviously all musicals should be rated in sob emojis.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/BSDQM9Jce-0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">Mobility exercises for 40+</a></p></li><li><p class="paragraph" style="text-align:left;">I have a lot more I want to include here, but it is late, so instead I shall hopefully flesh this out more next week. Hope you have a great rest of your week 👋 </p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-332-i-ve-joined-openai-fwd-cloudsec-aws-well-architected-supply-chain-security" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=7de169c0-8a4b-44a9-9ba2-f01005505eac&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #331 - How Adversaries Use AI, Skill Issues, Using IDEs for C2</title>
  <description>Google&#39;s deep dive on how threat actors are using AI, bypassing malicious skill scanning, using VS Code dev tunnels for command and control</description>
  <link>https://tldrsec.com/p/tldr-sec-331</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-331</guid>
  <pubDate>Thu, 04 Jun 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-06-04T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👩‍❤️‍👨 Repo-mantic Comedy</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Recently I had one of those moments where you remember that LLMs are trained on the vast, beautiful, complicated collection of human knowledge.</p><p class="paragraph" style="text-align:left;">I was using Codex to port a feature from one code base to another, and it said:</p><p class="paragraph" style="text-align:left;">“…I’m reading the exact code paths now so the port preserves behavior instead of inventing a <b>prettier cousin</b>.” 😂 </p><p class="paragraph" style="text-align:left;">Dear reader, I had questions. Like: how many bodice ripper novels and country music lyrics are in the training corpus? What other secrets lie in the weights?</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">I didn’t think I read anything about dating preferences in its model card.</p><p class="paragraph" style="text-align:left;">LLMs are strange, and amusing sometimes. This situation makes me think of the <a class="link" href="https://openai.com/index/where-the-goblins-came-from/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">goblins post</a>.</p><p class="paragraph" style="text-align:left;">I love demoing what you can build with coding agents to friends, but maybe I’ll hesitate before doing this next Thanksgiving, just in case…</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> AI will make every asset a potential zero-day target. Are you ready?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">The AI-attack era has arrived. Thousands of zero-days in the pipeline. Target-specific exploits generated in minutes. Unattributed, one-off attacks that bypass detection — while your dashboard stays green.</p><p class="paragraph" style="text-align:left;">runZero is built for this reality. Know every asset on your attack surface, uncover every exposure, map every attack path, and validate your segmentation — before the exploit drops. We deliver deep intelligence across IT, OT, IoT, cloud, and mobile, so defenders can win by default. Even against AI.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.runzero.com/?utm_source=tldr-sec&utm_medium=email-sponsored&utm_campaign=runzero-general" target="_blank" rel="noopener noreferrer nofollow"><b>Try It Free Today</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">I’ve heard great things about runZero, and HD Moore is a legend (and super nice).</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.yaelwrites.com/what-my-privacy-and-security-stack-actually-looks-like?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">What My Privacy and Security Stack Actually Looks Like</a><br>Great guide by <a class="link" href="https://www.linkedin.com/in/yaelgrauer/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Yael Grauer</a>: Use a PO Box and EasyOptOuts to scrub your home address from the internet (<a class="link" href="https://github.com/yaelwrites/big-ass-data-broker-opt-out-list?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Big Ass Data Broker Opt-Out List</a>), meet new contacts in public, use YubiKeys for MFA, 1Password/Bitwarden, encrypted drives, privacy screens in public, Privacy Badger, Mullvad VPN, uBlock Origin, Signal with disappearing messages, Google’s Advanced Protection Program, Lockdown Mode for Apple Devices, Google Fi for SIM-swap protection, iCloud&#39;s Hide My Email for aliases, and more.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/05/27/aikido-xbow.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Comparing AI Application Security Testing Platforms</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/lucacarettoni/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Luca Carettoni</a> and <a class="link" href="https://www.linkedin.com/in/tonytrummer/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Anthony Trummer</a> conducted a side-by-side comparison of two AI-powered penetration testing platforms, Aikido&#39;s Attack AI Pentest and XBOW&#39;s Lightspeed, manually validating all findings to determine true positives versus false positives. The evaluation assessed configuration complexity, impact on tested applications, report quality, cost, speed, and overall testing effectiveness.</p><p class="paragraph" style="text-align:left;">💡 Great example of a thoughtful benchmarking methodology and comparison that measures a variety of useful dimensions like: did a human tester agree with the severity ratings, what was the overlap in findings between the tools, and more. It’d be great to see more comparisons this detailed, but it does take a lot of time and effort.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.token.security/blog/zapocalypse-the-attack-chain-that-could-have-hijacked-zapier?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Zapocalypse: The Attack Chain That Could Have Hijacked Zapier</a><br>Token Security’s <a class="link" href="https://www.linkedin.com/in/yairbalilti/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Yair Balilti</a> describes chaining five known primitives to achieve NPM publishing rights to Zapier&#39;s design-system package, which would have enabled JavaScript execution in every authenticated Zapier session (yikes). Starting from a &quot;Code by Zapier&quot; Python sandbox where <code>os.system</code> worked, Yair scraped orphaned AWS STS credentials from <code>/proc/self/mem</code> (since <code>del os.environ[k]</code> doesn&#39;t zero heap memory), then used the misnamed <code>allow_nothing_role</code> (which actually permitted ECR enumeration and image pulls) to extract 1,111 container images via direct ECR API calls bypassing Docker&#39;s <code>GetAuthorizationToken</code> requirement. He then discovered a high-privilege NPM token with <code>bypass_2fa: true</code> and <code>scope.name: null</code> leaked in container build metadata via <code>ARG</code>/<code>ENV</code> in image config history, plus a hardcoded Zapier Actions MCP key belonging to a LiteLLM co-founder that enabled Gmail impersonation.</p><p class="paragraph" style="text-align:left;">💡 Attack chain enabling publishing arbitrary JavaScript served by &lt;your domain&gt; and ran in every one of your user’s sessions… $3,000. Sometimes I’m surprised more security researchers don’t turn to crime. To be clear, I’m not encouraging bad behavior, nor is this a unique case, I’ve seen many examples of “I could compromise &lt;all of your users&gt;” and the payout is a few grand. Sometimes the impact to payout ratio feels 🙃 </p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Prowler: the world’s most widely adopted open cloud security platform</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Prowler automates security and compliance across any cloud environment, with agentless coverage of cloud infrastructure, SaaS, Kubernetes, containers, Infrastructure as Code, and more. It detects vulnerabilities and misconfigurations, prioritizes risks, accelerates remediation, and automates audit-ready compliance. </p><p class="paragraph" style="text-align:left;">Prowler has become the security platform of choice for thousands of cloud teams, with 45M+ downloads, 13K+ GitHub stars, and 300+ global contributors. Prowler Cloud delivers cloud security 10x more cost-effectively than alternatives.</p><h2 class="heading" style="text-align:center;"><a class="link" href="https://prowler.com/interactive-demo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow"><b>👉 See Prowler In Action 👈</b></a></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Prowler is great, love the open core nature. Also fun demo format 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@adan.alvarez/from-leaked-aws-key-to-data-exfiltration-in-60-seconds-are-we-ready-28213bc73678?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">From Leaked AWS Key to Data Exfiltration in 60 Seconds: Are We Ready?</a><br><a class="link" href="https://www.linkedin.com/in/adan-%C3%A1lvarez-vilchez-539a92115/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adan Alvarez</a> tested Claude Code&#39;s ability to move from a leaked AWS IAM key to data exfiltration without AWS-specific guidance, finding that in 7 of 12 runs, the AI agent successfully completed the attack chain in approximately 60 seconds. The scenario involved a CI/CD user with read access to a Terraform state file containing credentials that could assume a privileged role, with all successful runs following an identical six-phase kill chain: GetCallerIdentity, policy enumeration (ListUserPolicies/GetUserPolicy), credential recovery from S3, AssumeRole, bucket enumeration, and exfiltration.</p><p class="paragraph" style="text-align:left;">Adan notes that CloudTrail&#39;s 5-minute log delivery delay means traditional alerting may be too slow to prevent sub-minute attacks which is why Adan is betting on honeytokens and honeypots to waste the agent&#39;s time before it finds anything real. See the scenario on <a class="link" href="https://github.com/adanalvarez/cloud-ranges/tree/main/aws-tfstate-exfil?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">GitHub here</a>.</p><p class="paragraph" style="text-align:left;">💡 Interesting- I hadn’t thought about that as much yet, but that’s a great point: log sources that only ship every 5 minutes could be a problem if an entire kill chain can be fully automated in a minute or two. Yikes.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.plainenglish.io/adding-strands-security-agents-to-shadow-asset-scanner-60c236c84b7e?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adding Strands Security Agents to Shadow Asset Scanner</a><br><a class="link" href="https://linkedin.com/in/sena-yakut?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Sena Yakut</a> built a shadow asset scanner that uses boto3 to sweep AWS for exposed S3 buckets, stale IAM keys, public Lambda function URLs, and similar misconfigurations. On top of that she layered a Strands Agents SDK that reads the raw findings and reasons across them for multi step attack paths rather than presenting each item in isolation.</p><p class="paragraph" style="text-align:left;">The architecture runs as a collaborative Swarm where specialized agents pass context to each other in sequence. The Error Analyst handles failures from the boto3 pass first, the Attack Chain Analyst then stitches findings into chained scenarios mapped to MITRE ATT&CK tactics, the Summary Agent compresses what comes out, and the Chat Agent serves four report formats (standard, executive, technical, and compliance) along with remediation commands. The agents reach the scanner through Strands&#39; tool interface and share state across handoffs, with caps on handoff count and execution time keeping the swarm from looping indefinitely.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.reversec.com/posts/2026/05/skill-issues-compromising-claude-code-with-malicious-skills-agents-part-1?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Skill Issues: Compromising Claude Code with malicious skills & agents</a><br>Reversec&#39;s James Henderson demonstrates how Claude Code skills and sub-agents can serve as initial access vectors, with risks comparable to installing untrusted pip packages. Henderson describes two attack paths. The first runs through skill frontmatter: setting <code>allowed-tools: Bash(*)</code> alongside dynamic context inputs like !<code>socat ...</code> executes commands before the LLM processes them, while direct reverse shell requests to Claude get refused. </p><p class="paragraph" style="text-align:left;">The second path runs through sub-agents and <code>permissionMode: bypassPermissions,</code> which skips consent prompts but doesn&#39;t prevent agents from reasoning about commands. To bypass that reasoning, Henderson runs <code>npm install</code> against a localhost registry serving backdoored packages, giving the agent legitimate cover to execute malicious code without exposing the payload.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The sorry state of skill distribution</a><br>Trail of Bits&#39;s <a class="link" href="https://sjudson.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Samuel Judson</a> and <a class="link" href="https://www.linkedin.com/in/tjaden/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Tjaden Hess</a> were able to bypass <a class="link" href="https://github.com/openclaw/clawhub/blob/c3c885ec10161ad35fbe78678ccc3f8c34e03ffd/convex/lib/securityPrompt.ts?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">ClawHub’s malicious skill detector</a>, <a class="link" href="https://github.com/cisco-ai-defense/skill-scanner?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Cisco’s agent skill scanner</a>, and all three of the scanners integrated into <code>skills.sh</code> in a few hours, using techniques like prepending 100,000 newlines to hide malicious code, embedding payloads in .docx archives and poisoned .pyc bytecode files, and using prompt injection to convince guard models that malicious registry configurations were legitimate corporate infrastructure. The attacks exploited weaknesses in the scanners: truncated file analysis, limited file type coverage that ignored binaries and hidden files, and the ability for attackers to iteratively refine attacks against static scanning targets.</p><p class="paragraph" style="text-align:left;">Recommendation: avoid public skill marketplaces like <a class="link" href="https://skills.sh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">skills.sh</a> and ClawHub entirely, instead curate internal skill repositories using trusted sources. PoC repo: <a class="link" href="https://github.com/trailofbits/overtly-malicious-skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">trailofbits/overtly-malicious-skills</a>.</p><p class="paragraph" style="text-align:left;">💡 Also <b>WHAT</b> - “The official MS Office skills from Anthropic for handling <code>.docx</code>, <code>.xlsx</code>, and <code>.pptx</code> files each contain a script called <code>soffice.py</code>… which hacks around the socket block by using <code>LD_PRELOAD</code> to patch in either 1) an existing <code>$TMP/lo_socket_shim.so</code>”, or 2) a library dynamically compiled out of C code embedded in a docstring.” 🫠 😂 </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/cve-2026-31431-copy-fail-exploit-detection-with-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/ryan-simon-2767bb15/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Ryan Simon</a> walks through <a class="link" href="https://github.com/advisories/GHSA-2274-3hgr-wxv6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Copy Fail</a>, a Linux kernel bug that lets an unprivileged user corrupt the page cache through its crypto socket interface and quietly rewrite <code>setuid</code> binaries like <code>/usr/bin/su</code> to escalate to root. Ryan used a single coding agent with a custom skill for each step to compress the full detection engineering cycle into one session, from threat analysis through live exploit testing to production deployment. The detection itself is a three stage chained rule that uses process scoped variables to track <code>bind(AF_ALG)</code>, <code>setsockopt(SOL_ALG)</code>, and splice or open operations on SUID binaries or PAM configs.</p><p class="paragraph" style="text-align:left;">💡 The “Accelerating the Detection Engineering Lifecycle with agents” section at the bottom has some great tactical details on how specific steps are scaled 👌 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</a><br>Google Threat Intelligence Group&#39;s (GTIG) Q2 2026 AI Threat Tracker describes several recent developments in how threat actors are using AI in their operations and targeting AI infrastructure directly. GTIG identified the first case of a threat actor using a zero-day it believes was developed with AI, a 2FA bypass in a popular open-source web admin tool disrupted before mass exploitation. PRC and DPRK actors are running their own AI-augmented vuln research workflows, while Russia-nexus malware CANFAIL and LONGSTREAM use LLM-generated decoy logic to obfuscate payloads against Ukrainian targets. PROMPTSPY, an Android backdoor first identified by ESET, embeds an autonomous agent that drives device interactions through gemini-2.5-flash-lite.</p><p class="paragraph" style="text-align:left;">Threat actors are also going after AI infrastructure itself. TeamPCP (UNC6780) compromised the LiteLLM and BerriAI repositories alongside Trivy and Checkmarx to plant the SANDCLOCK credential stealer and extract AWS keys and GitHub tokens from build environments. They&#39;re also industrializing LLM access through middleware like Claude-Relay-Service and CLIProxyAPI alongside automated account-registration pipelines. The common pattern is a maturing ecosystem where the orchestration layers around AI (wrapper libraries, skill packages, API connectors) are now part of the software supply chain attack surface.</p><p class="paragraph" style="text-align:left;">💡 Wow, excellently detailed blog on how threat actors are using AI. Covers a number more things than I have the space to include here.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.straiker.ai/blog/nomshub-cursor-remote-tunneling-sandbox-breakout?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">NomShub: Weaponizing Cursor&#39;s Remote Tunnel Through Indirect Prompt Injection and Sandbox Breakout</a><br>Straiker’s <a class="link" href="https://www.linkedin.com/in/karpagarajanvikkii/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Karpagarajan Vikkii</a> and <a class="link" href="https://www.linkedin.com/in/malwareunicorn/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Amanda Rousseau</a> describe NomShub, a vulnerability chain in Cursor where a malicious repository can silently hijack a developer&#39;s machine, combining indirect prompt injection, a sandbox escape via shell builtins (<code>export</code> and <code>cd</code> to escape workspace restrictions and write to <code>~/.zshenv</code> for persistence), and Cursor&#39;s built-in remote tunnel to give attackers persistent, undetected shell access triggered simply by opening a repo.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The Accidental C2: Exploring Dev Tunnels for Remote Access</a><br>SpecterOps&#39;s <a class="link" href="https://linkedin.com/in/xpn?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Adam Chester</a> examined Visual Studio Code Dev Tunnels as a potential C2 framework, discovering they consist of multiple protocol layers: REST management API for tunnel discovery and token generation, WebSocket tunneling, SSH connections using the russh crate, and MsgPack RPC for command execution. Adam released <a class="link" href="https://github.com/xpn/Ouroboros?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Ouroboros</a>, a Rust tool that implements the stack outside VS Code, with RPC methods like <code>spawn</code>, <code>fs_read</code>, <code>fs_write</code>, and <code>fs_connect</code> to interact with existing dev tunnels for remote code execution and file operations.</p><p class="paragraph" style="text-align:left;">Adam found that FOCI (Family of Client IDs) and BroCI (Nested App Authentication) clients can be leveraged to pivot from compromised Microsoft applications like Teams or Azure Portal to gain access tokens for the Dev Tunnels Service, enabling lateral movement and initial access scenarios. Adam conducted this research with significant assistance from GPT-5.4-Cyber, which mapped the protocol layers and created the russh patch.</p><p class="paragraph" style="text-align:left;">💡 Next example of leveraging coding agents to quickly understand a new, complex code base and stack.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.s0ld13r.kz/posts/claude-code-backdoor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Claude Code Hooks as Initial Access & Persistence</a><br><a class="link" href="https://www.linkedin.com/in/s0ld13r/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Zhangir Ospanov</a> describes how Claude Code&#39;s Hooks feature can be weaponized for initial access and persistence by embedding malicious commands in <code>.claude/settings.json</code> files, similar to the VSCode tasks backdoor previously exploited by Lazarus Group. Attackers can plant hooks at the project level that execute when a developer clones and runs Claude Code, or achieve persistence by modifying the global config (<code>~/.claude/settings.json</code>) to trigger payloads across all sessions. The technique uses lifecycle events like SessionStart, PreToolUse, and PostToolUse to execute arbitrary shell commands. </p><p class="paragraph" style="text-align:left;">Detection: audit <code>claude/</code> directories in cloned repositories, watch <code>~/.claude/settings.json</code> with file integrity monitoring, and review hook commands for anything suspicious before running Claude Code on untrusted code. A proof of concept repository with the full payloads is <a class="link" href="https://github.com/s0ld13rr/claude-code-backdoor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">available</a> if you want to test detection rules locally.</p><p class="paragraph" style="text-align:left;">💡 Reporting to you live from the field: features to run arbitrary code… support running arbitrary code. Lots of Living Off the Land opportunities for modern IDEs and coding agents.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://devin.ai/security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Devin for Security</a> - Seems like the focus is mostly on automatically writing fixes for (already) identified security issues, burning down the backlog.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://delinea.com/resources/ai-and-identity-security-report-pdf?utm_medium=paid-newsletter&utm_source=link-sponsorship&utm_campaign=br-brand-fy26-influencer-activity&utm_content=260522&utm_term=" target="_blank" rel="noopener noreferrer nofollow"><b>Is Your Identity Security Keeping Up with AI?</b></a><b> </b>- AI is moving faster than identity controls can keep up. Most teams say they&#39;re ready, but few can explain what their identities are doing in real-time. That&#39;s the AI security confidence paradox. <a class="link" href="https://delinea.com/resources/ai-and-identity-security-report-pdf?utm_medium=paid-newsletter&utm_source=link-sponsorship&utm_campaign=br-brand-fy26-influencer-activity&utm_content=260522&utm_term=" target="_blank" rel="noopener noreferrer nofollow">Delinea&#39;s 2026 Identity Security Report </a>unpacks this and more.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.neowin.net/news/people-are-using-prompt-injection-to-trick-metas-ai-into-handing-over-instagram-accounts/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">People are using prompt injection to trick Meta&#39;s AI into handing over Instagram accounts</a> - The issue has been actively exploited in the wild for months, going back to February of this year, with hackers compromising thousands of accounts.</p><p class="paragraph" style="text-align:left;"></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/openbashok/promptzero?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">openbashok/promptzero</a><br>Local proxy tool by <a class="link" href="https://github.com/openbashok/promptzero?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">OpenBash</a> that detects and replaces sensitive data such as IP addresses, hostnames, credentials, and personal information in your prompts before they leave your environment, then restores the real values in the response. Detection combines Presidio + spaCy named entity recognition (English and Spanish) for entities like persons, organizations, emails, and passports, with regex layers covering network infrastructure and country-specific identity documents. Each session keeps a bidirectional mapping table that stays local, and you can verify nothing real ever leaves by routing the upstream connection through Burp or mitmproxy and inspecting what actually reaches Anthropic.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.kaspersky.com/blog/llmjacking-2026-private-ai-server-security/55768?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">LLMjacking: what these attacks are, and how to protect AI servers</a><br><a class="link" href="https://linkedin.com/company/kaspersky?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Kaspersky&#39;s</a> Stan Kaminsky describes an experiment where a researcher ran a Raspberry Pi honeypot dressed as a high-performance AI server with Ollama, LM Studio, and similar local frameworks. Shodan found it in three hours, and the box saw 113,000 requests in a month, with 23% aimed at the AI stack. Attackers used LLM-Scanner to fingerprint models through <code>/api/tags</code> and <code>/v1/models</code>, scanned for AI agents via <code>/.cursor/rules</code>, inventoried MCP servers via <code>/.well-known/mcp.json</code>, and hunted <code>.env</code> files for credentials. The focus was resource theft, not RCE, mostly proxying calls to Anthropic models and parsing vuln data from social posts.</p><p class="paragraph" style="text-align:left;">Kaminsky shares some key defensive measures for private AI infrastructure, such as binding single-machine deployments to localhost so they aren&#39;t reachable from the network, swapping plain API key auth for OIDC or OAuth2 with short-lived tokens, segmenting the network with IP allowlists, running EDR on the boxes hosting AI models, setting per-role usage quotas with anomaly alerts on resource consumption, and shipping every request and response to a SIEM with tamper-resistant storage.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://pluto.security/blog/inside-claude-managed-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Inside Claude Managed Agents</a><br>Pluto Security&#39;s <a class="link" href="https://www.linkedin.com/in/yotamperkal/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Yotam Perkal</a> reverse-engineered Anthropic&#39;s Claude Managed Agents cloud runtime, finding gVisor sandboxing with a three-layer egress control system. Outbound traffic routes through a JWT-authenticated proxy with TLS inspection, the container has no direct DNS, and a network-level firewall blocks direct outbound. Together these prevent proxy bypass even when proxy environment variables are unset.</p><p class="paragraph" style="text-align:left;">The architecture separates session, harness, and sandbox into distinct trust zones, so a compromised sandbox cannot tamper with audit logs, influence orchestration, or access vault credentials. Yotam calls the vault credential proxy the platform&#39;s strongest property, with secrets never entering the sandbox and instead injected server-side at request time, so prompt injection has nothing to steal.</p><p class="paragraph" style="text-align:left;">Yotam notes that the defaults ship for convenience. The egress JWT is readable by any sandbox process and contains organization metadata plus the complete egress allowlist, which Anthropic silently expands with six additional infrastructure hosts (including a staging endpoint) even in limited networking mode. All eight tools are enabled by default with an always_allow permission policy and unrestricted networking. For hardening your deployment the post recommends disabling the default toolset, allowlisting only necessary tools, using limited networking, storing credentials in vaults, and monitoring session events.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=W_34Zwki0W8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">How Making More Money Affects Your Life</a></p></li><li><p class="paragraph" style="text-align:left;">Sharran Srivatsaa - <a class="link" href="https://www.mynextbillion.com/p/spirit-airlines?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">I Spent a Day Trying to Buy Spirit Airlines. Here&#39;s What I Found.</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=DW0XUsyBBuY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The Gen Alpha Melody</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=IMu6dYIuUXs&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Renée Elise Goldsberry “Satisfied”</a> (Official Music Video)</p></li><li><p class="paragraph" style="text-align:left;">Good Work - <a class="link" href="https://www.youtube.com/watch?v=X5MzTvfjcOM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Do presidents always make this much money?</a></p></li><li><p class="paragraph" style="text-align:left;">Chris Williamson - <a class="link" href="https://www.youtube.com/watch?v=33olenz_iiQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">What To Look For When Choosing A Partner - Chris Bumstead</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/bFkK3?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">F.B.I. Arrests C.I.A. Official With $40 Million in Gold Bars in His Home</a> - I’m guessing he’ll be barred from future public service 😏 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;">typedfemale - <a class="link" href="https://x.com/typedfemale/status/1945912359027114310?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">presenting: big jeff’s trainium hell</a> - Don’t watch at work 😂 </p></li><li><p class="paragraph" style="text-align:left;">Make Some Noise - <a class="link" href="https://www.youtube.com/shorts/P7y3lGynSEk?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">King Lear and his Three Influencer Daughters</a> - Having three influencer kids, now that’s a tragedy 😭 </p></li><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=DmU9uovmT2A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Upper Management Meeting</a></p></li><li><p class="paragraph" style="text-align:left;">ProZD - <a class="link" href="https://www.youtube.com/watch?v=4ZK8Z8hulFg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">before and after you discover the subreddit for a hobby</a></p></li><li><p class="paragraph" style="text-align:left;">Harvard Commencement 2026 - <a class="link" href="https://www.youtube.com/watch?v=F3fCktnkBbc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Conan O’Brien Delivers the Commencement Address</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI / Tech</p><ul><li><p class="paragraph" style="text-align:left;">Simon Willison - <a class="link" href="https://simonwillison.net/2026/May/27/product-market-fit/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">I think Anthropic and OpenAI have found product-market fit</a></p></li><li><p class="paragraph" style="text-align:left;">Lenny’s Podcast - <a class="link" href="https://www.youtube.com/watch?v=BD3vLtWhT5A&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">The most rational take on AI you’ll hear this year | Benedict Evans</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=rMf-JuikR-Q&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Why AI Agents Will Replace Your Next Hire</a></p></li><li><p class="paragraph" style="text-align:left;">Tech Crunch - <a class="link" href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Microsoft under fire for threatening security researcher with criminal investigation</a>. Kevin Beaumont - <a class="link" href="https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">Microsoft’s stance on zero day exploits is a dumpster fire of their own making</a>. Microsoft employs some friends and in general top notch security folks. #hugops to them in resolving challenges like this.</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-331-how-adversaries-use-ai-skill-issues-using-ides-for-c2" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=292c9898-807d-45b1-9978-d90326ff95e2&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates</title>
  <description>100+ intentionally vulnerable AWS environments for practicing cloud attack paths, how OpenAI deploys Codex internally, Anthropic&#39;s update on bugs found and their open sourced harness</description>
  <link>https://tldrsec.com/p/tldr-sec-330</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-330</guid>
  <pubDate>Thu, 28 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-28T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">⛰️ Ain’t No Mountain High Enough</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">To keep me from sending to you bae.</p><p class="paragraph" style="text-align:left;">Literally as I was starting to write this intro, my home Internet went out. After a moment I realized I had gotten a text a few days ago- scheduled maintenance with my Internet provider 😅 </p><p class="paragraph" style="text-align:left;">So now I’m finishing this issue via hot spotting with my phone.</p><p class="paragraph" style="text-align:left;">I’ve wondered sometimes what I’d do if there was some sort of force majeure world or personal event that put my ability to finish the newsletter in jeopardy.</p><p class="paragraph" style="text-align:left;">We cut to- <i>*Movie trailer voice* In a world, where there’s too much security news…</i></p><p class="paragraph" style="text-align:left;"><i>*Inception bong* One terminally online hacker fights the info deluge for the people…</i></p><p class="paragraph" style="text-align:left;"><i>But today… *insert plot device like aliens arriving, natural disasters, Sharknado, etc.*</i></p><p class="paragraph" style="text-align:left;">It could be any of these, I’ve got range.</p><p class="paragraph" style="text-align:left;">I’ve offered this CTA to Netflix <a class="link" href="https://tldrsec.com/p/tldr-sec-55?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">several</a> times <a class="link" href="https://tldrsec.com/p/tldr-sec-126?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates#phone-a-friend" target="_blank" rel="noopener noreferrer nofollow">over</a> 6 <a class="link" href="https://tldrsec.com/p/tldr-sec-117?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">years</a>, and heard back <a class="link" href="https://tldrsec.com/p/tldr-sec-118?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">once</a>. Still working on manifesting it 🙏 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Threats Don’t Need Malware. </b></span><br><span style="color:#222222;"><b>They Need Your Identity.</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">No custom malware. No zero-days. Just your own admin tools, cloud APIs, and trusted processes repurposed without triggering a single alert. <b>Varonis Threat Labs&#39; 2026 Attacker&#39;s Playbook</b> maps the full attack chain with real-world case studies and exposes how trust gets weaponized by threats at every stage. Discover the tactics. Close the gaps.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.ly/Q04hXllV0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(9, 105, 218)"><b>Get the Playbook</b></a><span style="color:rgb(67, 67, 67);"><b> </b></span><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">Varonis has been sharing some great security research recently. And I’m curious about these advanced tactics like “Cookie-Bite” and “EchoLeak” 👀 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/falcosecurity/prempti?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">falcosecurity/prempti</a><br>Tool by <a class="link" href="https://www.linkedin.com/company/falco-security-oss/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Falco</a> that brings Falco to AI coding agents. Prempti intercepts every tool call (shell commands, file writes and reads, web fetches, MCP calls) at the agent&#39;s hook API before it runs and produces allow/deny/ask verdicts from customizable Falco YAML rules, with an LLM-friendly explanation fed back to the agent on denials so it can adapt. Because interception happens at the hook level rather than the kernel, rules see what the agent declares but not the runtime behavior of compiled binaries or the side effects MCP servers later produce, so Prempti is positioned as a cooperative policy layer to use alongside OS-level containment rather than as a replacement for it.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/running-codex-safely?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Running Codex safely at OpenAI</a><br>OpenAI walks through how they deploy Codex internally, with security controls including sandboxed execution environments, approval workflows for high-risk actions, and an <a class="link" href="https://alignment.openai.com/auto-review/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">auto-review subagent</a> that automatically approves low-risk operations to reduce friction. They enforce network policies that allowlist expected destinations and require approval for unfamiliar domains, manage authentication through OS keyrings pinned to their ChatGPT enterprise workspace, and use macOS managed preferences with admin-enforced requirements files to maintain consistent security baselines. </p><p class="paragraph" style="text-align:left;">Codex exports OpenTelemetry logs containing user prompts, tool approvals, execution results, and network policy decisions, which OpenAI feeds into an AI-powered security triage agent that correlates endpoint alerts with agent intent to distinguish between legitimate behavior and genuine security incidents.</p><p class="paragraph" style="text-align:left;">💡 Auto-review mode is neat, I find Codex almost never prompts me in normal usage. Also, the Codex logs → security triage agent is very interesting, I’m curious to know more. Could you detect when an agent is going off the rails, or prompt injected and doing some C2 behavior? Or detecting an insider threat type situation? Lots of applications 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.marcolancini.it/2026/blog-automating-security-operations-with-ai-triage-renovate?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Automating Security Operations with AI: Triaging Renovate PRs</a><br><a class="link" href="https://www.linkedin.com/in/marcolancini/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Marco Lancini</a> writes up how he combined Renovate with Claude Code Routines to automate the review of dependency update PRs, using a custom Claude skill that posts a structured upgrade risk matrix back to each PR. The skill detects stack type (e.g. Python, JavaScript) from the PR title and classifies bumps as High, Medium, or Low based on <code>semver</code> plus how the package actually behaves (e.g. has a history of breaking changes), not just version distance. From there it greps source code for actual imports to flag dead dependencies, queries <code>Context7</code> for breaking changes, and scans for deprecated config patterns like TypeScript&#39;s <code>baseUrl</code> or Next.js&#39;s <code>middleware.ts</code>. The cloud routine fires on each new <code>[RENOVATE]</code>-prefixed PR (Renovate runs monthly), runs the skill read-only without approval prompts, and posts the risk matrix via <code>gh pr comment</code>. A 14-day <code>minimumReleaseAge</code> filter sits in front of the whole pipeline to block supply-chain attacks.</p><p class="paragraph" style="text-align:left;">💡 Excellent example of automating a toil-heavy workflow: reviewing package updates. Marco kindly released the full Skill prompt he uses, which is thorough and handles a number of edge cases, and is definitely worth reviewing 🤘 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Adaptive Security: Hyperrealistic Phishing Simulations Across Email, Voice, and SMS</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:#222222;">Most phishing simulations are still templated emails. Adaptive runs hyperrealistic multi-channel simulations including AI-generated voice calls, OSINT-based spearphishing tailored to each target, and automated phishing programs that run in the background without manual lift. The result: measurable reductions in click rates, stronger security behaviors over time, and a workforce that&#39;s actually prepared for the threats hitting their inbox today. Rated 4.9/5 on G2 and Gartner.</span></p><h2 class="heading" style="text-align:center;"><span style="color:#2C81E5;"><b>👉 </b></span><span style="color:#2C81E5;"><a class="link" href="https://www.adaptivesecurity.com/lp/nb/phishing-simulation?utm_source=sp_email&utm_medium=newsletter&utm_campaign=2026_05_NA_TLDR_sec_newsletter&utm_id=701Rd00000guu14IAA" target="_blank" rel="noopener noreferrer nofollow"><b>See It in Action</b></a></span><span style="color:#2C81E5;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AI-powered spearphishing and deepfakes are pretty worrying to be honest, they’re getting quite good. I’m glad people are working on this ✊ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-security-agent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">AWS Security Agent adds verification scripts for pentest findings</a><br>AWS Security Agent now automatically generates executable verification scripts for each confirmed penetration test finding. Verification scripts include setup instructions, documented environment variables, and redacted sensitive values.</p><p class="paragraph" style="text-align:left;">💡 Many dynamic analysis tools have been generating curl requests, PoC scripts, etc. that reproduce findings for a decade+, long before LLMs (shout-out Burp Suite, my BFF during my consulting days). And of course fuzzers do this by construction. It seems like auto-generating PoCs is or will be table stakes for any security tool that finds vulnerabilities, which honestly is kind of a cool world to be living in. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/sethart?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Seth Art</a> introduces <a class="link" href="https://github.com/DataDog/pathfinding-labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Pathfinding Labs</a>, a collection of 100+ intentionally vulnerable AWS environments deployable via Terraform for practicing cloud attack paths and validating detections. The project ships a Go CLI tool (<code>plabs</code>) for deployment and a web catalog at <a class="link" href="https://pathfinding.cloud/labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">pathfinding.cloud/labs</a> with per-lab documentation. Scenarios cover self-escalation (a role granting itself admin via <code>PutRolePolicy</code>), one-hop and multi-hop privilege escalation chains, CSPM misconfigurations and toxic combos like a public Lambda with an admin role, and cross-account paths from dev or ops into prod. Each lab includes a <code>demo_attack.sh</code> script that walks the exploitation chain step-by-step, with cleanup scripts to revert artifacts after testing.</p><p class="paragraph" style="text-align:left;">💡 Love all the OSS tools and labs that Seth and Datadog put out. Awesome!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</a><br>Palo Alto Networks&#39; <a class="link" href="https://linkedin.com/in/williambatchelor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Bill Batchelor</a> and <a class="link" href="https://www.linkedin.com/in/eyalrafian/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Eyal Rafian</a> give an overview ROADtools, an open-source Python framework that nation-state actors like Cloaked Ursa (APT29) and Curious Serpens (APT33) have weaponized for cloud attacks, including how ROADtools evades detection and how these threat actors misuse it. The post discusses ROADtools’ roadrecon module for Entra ID enumeration via the Microsoft Graph API, the roadtx module for token manipulation, device registration, and MFA bypass, and categorize functionality in MITRE ATT&CK. They conclude with preventive controls to limit token misuse, and Cortex XQL detection queries.</p><p class="paragraph" style="text-align:left;">💡 In security, you either die young or live long enough to see threat actors using your tools for ill.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">We hardened zizmor&#39;s GitHub Actions static analyzer</a><br>Trail of Bits&#39;s <a class="link" href="https://linkedin.com/in/alexis-challande?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Alexis Challande</a> writes up a three-month collaboration with the zizmor maintainers to bring its YAML anchor support up to full coverage, prompted by the March 2026 supply-chain attack where attackers exploited a pull_request_target misconfiguration in aquasecurity/trivy-action to backdoor LiteLLM. Zizmor’s anchor support had been best-effort since GitHub Actions added native YAML anchors in September 2025. The team fixed parsing bugs that caused crashes and wrong-location findings, surfaced deserialization edge cases that broke zizmor on otherwise valid workflows, and aligned zizmor&#39;s expression evaluator with GitHub&#39;s Known Answer Tests, validating the work against a corpus of 41,253 workflows from 6,612 high-value open-source repositories.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/github-actions-security-ai-powered-actions-vulnerabilities?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/shay-berkovich-0a09975?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Shay Berkovich</a> found vulnerabilities in AI-powered GitHub Actions from OpenAI, Anthropic, and Google affecting repositories with 200,000+ combined stars. Among them, <code>openai/codex-action</code> and <code>anthropics/claude-code-action</code> rely on syntactical permission checks that let attackers impersonate trusted apps when <code>allow-bots</code> is enabled (or if a name is available to be registered, a “Dangling GitHub Apps” attack). <b>Dependabot Deputy Confusion Injection</b> has attackers issue <code>@dependabot</code> commands so <i>dependabot</i> appears as the <code>github.actor</code> on a PR, slipping past allow-lists. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Shay describes how some common authentication Actions create sensitive local secret files at runtime (e.g. GCP service account keys or others that often grant infrastructure-level access). Verbose modes in <code>claude-code-action</code> and <code>run-gemini-cli</code> leak these files via workflow logs even when the model refuses direct exfiltration.</p></div><p class="paragraph" style="text-align:left;">AI-powered GitHub Actions have inherent design risks. Every reviewed Action interpolates untrusted user content into prompts, and those with MCP or tool access amplify the blast radius through file writes, shell execution, and git operations.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/microsoft/RAMPART?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">microsoft/RAMPART</a><br>By <a class="link" href="https://www.linkedin.com/company/microsoft?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Microsoft</a>: RAMPART (Risk Assessment & Measurement Platform for Agentic Red Teaming) is a pytest-native framework for safety and security testing of agentic AI applications that enables developers to write structured tests, with evaluation-driven assertions checking agent behavior against each scenario.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/05/21/tailscalehound?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Introducing TailscaleHound: Mapping Tailscale Attack Paths in BloodHound</a><br>SpecterOps&#39; <a class="link" href="https://www.linkedin.com/in/gomez742/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Andrew Gomez</a> and <a class="link" href="https://www.linkedin.com/in/andreweluke/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Andrew Luke</a> release <a class="link" href="https://github.com/KingOfTheNOPs/TailscaleHound?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">TailscaleHound</a>, a BloodHound OpenGraph collector that maps Tailscale environments as queryable attack paths. It models users, devices, groups, tags, ACLs, grants, SSH rules, routes, app connectors, keys, and hybrid Azure identity links under the TS namespace.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Collection runs through the Tailscale API with read-only OAuth credentials, with optional <code>tailcontrol</code> cookie enrichment. Without API access, local collection works from <code>tailscale status --json</code> output, optionally enriched with an Access Policy file. From there, saved Cypher queries answer who can reach a given device, who can SSH as root, which subnet routes expose internal CIDRs, and which Azure users inherit Tailscale access through <code>TS_AZUserSyncedToUser</code> bridge edges.</p></div><p class="paragraph" style="text-align:left;">Red teamers can maps paths from compromised identities into sensitive devices, useful exit nodes, and Azure-inherited Tailscale access. Defenders can pull from the same graph to flag overbroad ACL sources, stale groups and keys, sensitive routes exposed to broad groups, and SSH rules that hand out root or admin.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://riptides.io/blog/keyledger-ai-api-keys?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Introducing KeyLedger: Because You Probably Don&#39;t Know How Many AI Keys Your Org Has</a><br>Riptides&#39; <a class="link" href="https://www.linkedin.com/in/balint-molnar/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Balint Molnar</a> open-sources <a class="link" href="https://github.com/riptideslabs/keyledger?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">KeyLedger</a>, a Go TUI for inventorying AI provider API keys across OpenAI, Anthropic, Google Cloud Vertex AI, and AWS Bedrock through their admin APIs. KeyLedger normalizes each provider&#39;s different organizational structure into a single table, with automatic health scoring flagging stale, idle, and never-used keys. SQLite snapshots let you diff inventories between runs to track new keys, revocations, and status changes over time. The TUI handles interactive exploration, and watch mode polls providers continuously and runs as a Docker container for long-running deployments.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.offensai.com/blog/scopeshift-ai-pentest-agent-scope-verification-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Attacking Production Apps Without Jailbreaking the Model: Scope Manipulation with scopeshift</a><br>OFFENSAI&#39;s <a class="link" href="https://linkedin.com/in/eduard-k-agavriloae?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Eduard Agavriloae</a> releases <a class="link" href="https://github.com/OFFENSAI/scopeshift?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">scopeshift</a>, an open-source tool demonstrating how AI coding agents can be tricked into attacking production targets while believing they&#39;re testing localhost, bypassing jailbreaking entirely through network-layer deception rather than adversarial prompting. Scopeshift works as a reverse proxy on 127.0.0.1 that rewrites responses (stripping CDN headers, rewriting URLs, replacing titles with &quot;Dev Build — Local&quot;) and provides a deceptive MCP server that always returns &quot;in scope&quot; authorizations. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Testing showed that without safety prompts, Claude Opus 4.7 voluntarily called the MCP oracle and sent seven SQL injection payloads to the real OFFENSAI website, but a one paragraph safety prompt caused the model to refuse after recognizing that in-band signals (MCP responses, DNS, TLS, page content) cannot validate themselves. </p></div><p class="paragraph" style="text-align:left;">💡 This post does a great job highlighting something I’ve been thinking about: how can an AI model (or the labs creating them) know that the user is doing authorized testing? Especially when the model is operating in an environment totally controlled by the user. It feels like the same client-side security lessons we’ve learned from browsers and mobile apps. I’m not sure how this can be solved, which is concerning given the capability improvements of models 😅 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/research/glasswing-initial-update?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: An initial update</a><br>Anthropic releases Project Glasswing&#39;s initial update, reporting that ~50 partners have used Claude Mythos Preview to find over 10,000* high- or critical-severity vulnerabilities in one month. Cloudflare found 2,000 bugs (400 high/critical); Mozilla fixed 271 in Firefox 150. </p><p class="paragraph" style="text-align:left;">Anthropic separately scanned 1,000+ open-source projects, surfacing 6,202 estimated high/critical vulnerabilities. Of 1,752 already triaged by six independent security firms, 90.6% were valid true positives and 62.4% confirmed high/critical, including a wolfSSL certificate forgery exploit. The bottleneck has shifted from finding vulnerabilities to patching them, with maintainers taking an average of two weeks per high/critical bug, </p><p class="paragraph" style="text-align:left;">Anthropic released <a class="link" href="https://claude.com/product/claude-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Claude Security</a> in public beta for Enterprise customers (already used with Claude Opus 4.7 to patch 2,100+ vulnerabilities), <a class="link" href="https://github.com/anthropics/defending-code-reference-harness?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">open-sourced</a> the scanning harness, threat model builder, and skills its Glasswing partners used, and launched a <a class="link" href="https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Cyber Verification Program</a> that lets security professionals use Claude for vulnerability research, penetration testing, and red-teaming without certain safeguards. </p><p class="paragraph" style="text-align:left;">💡 “Over 10,000 high- or critical-severity vulnerabilities*“ is a headline-y opening stat, but later on (based on my read) it seems like that’s the “claimed to be found and rated by Mythos number,” not the human triaged ground truth number. To be fair, that takes a huge amount of work and time. Cloudflare said, “a false positive rate better than human testers.” Which is… what rate? 🤔 </p><p class="paragraph" style="text-align:left;">I think it’s awesome that Anthropic is spending so much time and money securing open source, and it’s great that they open sourced their scanning harness, that helps the industry grow and improve together. It’s also very effective bizdev and marketing for acquiring enterprise customers, but what is security research after all? <code>:hide-the-pain-emoji:</code> 😅 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">Every - <a class="link" href="https://www.youtube.com/watch?v=jBZQ5Ay20HU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">AI Was Supposed to Save Time. Why Am I Busier?</a></p></li><li><p class="paragraph" style="text-align:left;">Leila Hormozi - <a class="link" href="https://www.youtube.com/watch?v=DVtuTp3ykcA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">AI Is Making Your Thinking Worse (And How to Fix It)</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=XsWSvz-aewA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">The New Way of Making Content In The Age of AI</a></p></li><li><p class="paragraph" style="text-align:left;">Matt Turck - <a class="link" href="https://www.youtube.com/watch?v=DhD1zZ8w8Mw&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">OpenAI&#39;s Yann Dubois: Why AI Progress Suddenly Feels Real</a> - Really helpful overview of the different parts of model training</p></li><li><p class="paragraph" style="text-align:left;">Tim Ferriss - <a class="link" href="https://www.youtube.com/watch?v=HutNi2cNsCg&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">The AI Frontier and How to Spot Billion-Dollar Companies Before Everyone Else — Elad Gil</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://xunroll.com/thread/2053047748191232310?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Bun ported from Zig to Rust in 6 days using AI</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=LyMjLwSh08w&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">If Lin-Manuel Miranda wrote Defying Gravity from Wicked</a> 😍 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/gUXs_eocZ4g?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Dr. Seuss Rap</a></p></li><li><p class="paragraph" style="text-align:left;">SNL - <a class="link" href="https://www.youtube.com/watch?v=mrW2ld-13iQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Weekend Update: Mr. On Blast Speaks His Mind Again Without Holding Back</a> - This killed me 😂 </p></li><li><p class="paragraph" style="text-align:left;">Good Work - <a class="link" href="https://www.youtube.com/watch?v=npOcPgWymbM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">What does Meta actually do now?</a></p></li><li><p class="paragraph" style="text-align:left;">SNL - <a class="link" href="https://www.youtube.com/watch?v=lbDOegHVPP8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Mom Movie Trailer</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Paper - <a class="link" href="https://pmc.ncbi.nlm.nih.gov/articles/PMC1360393/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Didgeridoo playing as alternative treatment for obstructive sleep apnea</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Magnifica Humanitas: on Safeguarding the Human Person in the Time of AI</a> - I didn’t have “the pope writes a screed on AI” on my 2026 bingo card, but here we are</p></li><li><p class="paragraph" style="text-align:left;">r/bugbounty - <a class="link" href="https://www.reddit.com/r/bugbounty/comments/1tes86p/hi_im_a_former_h1_triager_ama/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">I’m a former H1 Triager AMA</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://lifeweeks.app/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Your Life in Weeks</a> - Create a map of your life where each week is a little box. Inspired by Tim Urban’s blog.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://diamond.jaydip.me/read/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">How Diamonds are Made</a> - Cool visualization</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://paletteinspiration.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Palette Inspiration</a> - Explore color palettes extracted from thousands of masterworks - from Renaissance elegance to Impressionist light. Super cool!</p></li><li><p class="paragraph" style="text-align:left;">Bryan Johnson - <a class="link" href="https://www.youtube.com/watch?v=JNuORofHhrk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">You’re Exercising Wrong</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/g2Leuhr2Ib0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Vik White & Urban Theory at the Red Bull Dance</a> - Sick 🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.csoonline.com/article/4176504/google-leaks-details-for-chromium-bug-that-can-turn-browsers-into-bots.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">Google leaks details for Chromium bug that can turn browsers into bots</a> - Reported over three years ago, made public but then wasn’t actually fixed. </p></li><li><p class="paragraph" style="text-align:left;">Krebs on Security - <a class="link" href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">CISA Admin Leaked AWS GovCloud Keys on Github</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">✉️ Wrapping Up</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-330-aws-pathfinding-labs-running-codex-safely-at-openai-glasswing-updates" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=ad6a61ae-1168-498a-89d1-e7d7419bd125&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #329 - AI-powered Honeypots, GitHub Action Canaries, Microsoft’s Agentic Security Scanner</title>
  <description>Detecting and deceiving attackers with AI honeypots, detect supply chain attacks with GitHub Action canaries, the latest from Microsoft&#39;s new &quot;Autonomous Code Security&quot; team</description>
  <link>https://tldrsec.com/p/tldr-sec-329</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-329</guid>
  <pubDate>Thu, 21 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-21T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🍦 Ice Cream Bonding</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">There’s this Mediterranean place I like to go to sometimes, Souvla, that has delicious frozen Greek yogurt you can get with baklava on top.</p><p class="paragraph" style="text-align:left;">It’s helped me power through many a late night writing <i>tl;dr sec</i>. Like tonight 😅 </p><p class="paragraph" style="text-align:left;">I’ve gradually started befriending the manager over time, over a series of froyos.</p><p class="paragraph" style="text-align:left;">We’ve discussed how it’s sometimes difficult to make new (deep) friends as you get older, some of his work challenges, and more.</p><p class="paragraph" style="text-align:left;">All from periodic 5 minute conversations.</p><p class="paragraph" style="text-align:left;">It makes me think that most people probably have a lot to open up and share about, if you create a little space for it.</p><p class="paragraph" style="text-align:left;">Anyway, I’m not saying frozen yogurt is the key to adult friendship, but I’m not <i>not</i> saying that.</p><p class="paragraph" style="text-align:left;">Maybe community is built less through grand gestures, and more through remembering someone’s name, asking one more question, and occasionally adding baklava.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>State of AI in the Cloud 2026:</b><br><b> How AI Is Reshaping Cloud Security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI is no longer a standalone tool, it’s embedded across cloud environments, development workflows, and production systems.</p><p class="paragraph" style="text-align:left;">The State of AI Report reveals how AI adoption is expanding the attack surface, accelerating attacker behavior, and introducing new risks through agents, copilots, and automation.</p><p class="paragraph" style="text-align:left;">Get the data behind what’s changing and what security teams need to do about it.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY27Q1_INB_FORM_State-of-AI-Report-2026&sfcid=701Vh00000aV1zBIAS&utm_term=FY27Q2-tldrsec-nl-May&utm_content=State-of-AI-Report-2026" target="_blank" rel="noopener noreferrer nofollow"><b>Read the Report</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Hm some interesting stats here: “AI is now core operational infrastructure.” ~80% of orgs use AI IDE extensions, and its impact on security is… 👆️ </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://shubs.io/the-down-fall-of-bug-bounties?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">The down fall of bug bounties</a><br><span style="text-decoration:line-through;">Assetnote</span> Searchlight Cyber’s <a class="link" href="https://www.linkedin.com/in/shubhamshah/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Shubham Shah</a> reflects on how AI has impacted bug bounty: <span style="background-color:rgb(255, 255, 255);">skilled researchers are submitting higher quality reports faster with AI assistance, but platforms are overwhelmed by low-quality AI-generated submissions. Shubz isn’t pleased with current solutions from HackerOne (fighting AI with AI) and Bugcrowd (spam controls), finding despite him hacking on Uber’s bug bounty program for almost ten years and ranked #1 on their public program, and his recent high impact submission took 12 days to get a response instead of previously 1-3 days.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://oblique.security/blog/policy-rollout?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">The security policy rollout survival guide</a><br>The blog version of Oblique&#39;s <a class="link" href="https://linkedin.com/in/mayakaczorowski?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Maya Kaczorowski</a>’s BSidesSeattle talk. Maya o<span style="background-color:rgb(255, 255, 255);">utlines a practical framework for rolling out security policies, emphasizing that successful implementation requires getting stakeholder input from engineering, product, SRE, and IT before defining controls, then running a pilot with representative users across diverse roles and platforms to identify edge cases and validate that controls actually work. </span></p><p class="paragraph" style="text-align:left;"><span style="background-color:rgb(255, 255, 255);">She emphasizes the importance of communicating changes through multiple channels (email, Slack, all-hands), making policy enforcement visible to users so they can see how they compare to peers, and ensuring the policy owner (not IT) handles ongoing enforcement and user friction. </span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">How OLTs may have exposed entire ISP networks</a><br>Quarkslab&#39;s Mathieu Farrell describes a chain of pre-auth RCEs against network vendor VSOL&#39;s GPON OLT (Gigabit Passive Optical Network Optical Line Terminal) hardware and its Cloud EMS fleet manager that together can take over an ISP&#39;s entire fiber network.</p><p class="paragraph" style="text-align:left;">Farrell found three pre-auth command injection bugs in the V1600 OLT models (SNMP traceroute, TACACS+ login, web traceroute), all share the same default admin credentials hardcoded in the firmware, <span style="background-color:rgb(255, 255, 255);">plus an arbitrary file upload RCE in Cloud EMS that allows JSP webshell deployment with root access. The post shows how attackers could chain these vulnerabilities, starting from exposed OLTs or the cloud manager, to compromise entire fleets of devices across ISPs in countries including the US, India, Turkey, Taiwan, Brazil, and Mexico.</span></p><p class="paragraph" style="text-align:left;">💡 Yikes 😅 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Are your developers -- </b><br><b>dangerously-skipping-permissions yet?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Agents writing code is easy. Trusting what those agents are doing is hard. Minimal hands your devs isolated, declarative environments that run identically for humans, agents, and CI. Reproducible by default, local first.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><b><a class="link" href="https://minimal.dev/?utm=tldr&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Learn more</a></b><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">OK this looks really cool. Performant + sandboxed local dev environment, curated open-source packages compiled from source (in a SLSA-compliant environment), network connectivity and filesystem access must be explicitly declared in Build Specifications and more.</p><p class="paragraph" style="text-align:left;">I got nerd sniped reading about Minimal, sounds thoughtfully designed for both engineering and security. I’m going to read more about this later.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@brookejamieson/awstrology-what-star-sign-is-every-aws-service-908c417e65a6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">AWStrology: What Star Sign Is Every AWS Service?</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://awsforidiots.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">AWS for Idiots</a> - AWS described via comics</p></li><li><p class="paragraph" style="text-align:left;">Corey Quinn - <a class="link" href="https://www.lastweekinaws.com/blog/s3-is-not-a-filesystem-but-now-theres-one-in-front-of-it?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">S3 Is Not a Filesystem (But Now There’s One In Front of It)</a> - “…AWS pricing is where dreams go to get itemized.” 😂 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.beyondtrust.com/blog/entry/aws-bedrock-security-guide-api-keys-detection-response?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">The AWS Bedrock API Keys Security Guide Part 2: Detection, Prevention, and Response</a><br>BeyondTrust&#39;s <a class="link" href="https://www.linkedin.com/in/mrcloudsec/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Sergio Garcia</a> continues his team&#39;s AWS Bedrock API key research with a follow-up covering detection, defense, response, and migrating to STS. The post includes CloudWatch Logs Insights queries, EventBridge patterns, and SIEM rules to identify unauthorized usage of bearer tokens, including detection logic for privilege escalation attacks where attackers create IAM access keys for BedrockAPIKey-* users, anomalous usage patterns based on IP ranges and operating hours, and suspicious user agents like python-requests or curl instead of AWS SDKs. The post concludes with defense controls (SCPs, model invocation logging) and incident response approaches.</p><p class="paragraph" style="text-align:left;">The BeyondTrust team has also released <a class="link" href="https://github.com/BeyondTrust/bedrock-keys-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Bedrock Keys Security</a>, an open-source CLI covering that can detect phantom IAM users, decode leaked AWS Bedrock API keys, + SCPs + SIEM detection rules.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/git-pkgs/proxy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">git-pkgs/proxy</a><br>Tool by <a class="link" href="https://x.com/teabass?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Andrew Nesbitt</a> that runs as a caching proxy for 20+ package registries (npm, Cargo, PyPI, Maven, NuGet, Docker/OCI, Debian/RPM) with a configurable version cooldown that quarantines newly published packages for a set period before they&#39;re available to builds. It supports per-package cooldown overrides, SBOM-driven cache pre-population, a REST API for vulnerability scanning, and Prometheus metrics.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://tracebit.com/blog/detecting-cicd-supply-chain-attacks-with-canary-credentials?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Detecting CI/CD Supply Chain Attacks with Canary Credentials</a><br>Tracebit&#39;s <a class="link" href="https://www.linkedin.com/in/alessandro-brucato/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Alessandro Brucato</a> released a free GitHub Action that drops canary AWS credentials and SSH keys into CI/CD workflows to detect credential exfiltration from compromised pipelines. The action writes canaries to <code>~/.aws/credentials</code>, <code>~/.ssh</code>, environment variables, and runner process memory at workflow start, then alerts when any of them is used. Alessandro validated it against the TeamPCP supply chain campaign that compromised Trivy, KICS, LiteLLM, and Telnyx and confirmed the canaries would have caused alerts capturing the affected repo, workflow, job, commit SHA, run ID, and attacker IP.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.o3c.no/knowledge/unmasking-the-docker-onbuild-supply-chain-attack-vector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Unmasking the Docker ONBUILD Supply Chain Attack Vector</a><br>O3-Cyber&#39;s <a class="link" href="https://www.linkedin.com/in/audun-blichfeldt-mo-b01713185/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Audun Mo</a> describes how Docker&#39;s ONBUILD directive creates a hidden supply chain attack vector. When a parent Docker image contains ONBUILD instructions, those commands automatically execute during downstream builds with complete access to the child project&#39;s files, environment variables, and secrets. Mo demonstrates three attack patterns, including stealing build secrets by accessing common secret identifiers (<code>npm_token</code>, <code>github_token</code>) and sending them to external servers via curl, manipulating project dependencies by modifying <code>package.json</code> files to pin vulnerable software versions, and achieving RCE by injecting malicious commands through <code>curl | sh</code>.</p><p class="paragraph" style="text-align:left;">O3-Cyber released <a class="link" href="https://github.com/o3-cyber/onbuild-guardian?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Onbuild Guardian</a>, an open-source tool that examines Docker images using <code>docker inspect</code> to identify and manage ONBUILD instructions through allowlists. Mo recommends pinning base images by SHA256 digest rather than tag, and using secret mounts rather than ENV, ARGs, or .env files.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://beelzebub.ai/blog/llm-honeypot-vs-cryptojacking-understanding-the-enemy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">LLM Honeypot vs. Cryptojacking: Understanding the Enemy</a><br>Beelzebub&#39;s <a class="link" href="https://www.linkedin.com/in/mario-candela/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Mario Candela</a> deployed his low-code <a class="link" href="https://github.com/beelzebub-labs/beelzebub?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">SSH LLM honeypot</a> with GPT-4o and a list of weak passwords to attract bots. It logged a cryptojacking bot&#39;s full attack chain. The bot fingerprinted the kernel and GPU, swapped the root password and killed prior miners with pkill, then downloaded a c3pool installer tied to a hardcoded Monero wallet that had accumulated roughly 20 XMR (~$4,126). Candela reported the wallet to c3pool, who pulled every infected miner using it.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://posts.inthecyber.com/tales-of-an-ollama-honeypot-part-1-abuse-patterns-29ba0b000b7f?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Tales of an Ollama Honeypot (Part 1): Abuse Patterns</a><br><a class="link" href="https://www.linkedin.com/in/marco-pedrinazzi/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Marco Pedrinazzi</a> deployed an Ollama honeypot on a VPS, let Censys and Shodan index it, and logged 6,461 events from 324 unique IPs over 32 days. Most IPs enumerated the server, then sent short liveness prompts like greetings or arithmetic to see whether it was worth deeper testing, hitting both Ollama&#39;s native API and its OpenAI-compatible endpoints. The honeypot also caught prompt injection wrapped in fake &quot;security audit&quot; pretexting to extract system prompts and environment variables, local file disclosure via malicious Modelfiles, and SSRF probes via <code>/api/pull</code> and <code>/api/push</code>.</p><p class="paragraph" style="text-align:left;">Marco has also published three detection rules for <a class="link" href="https://novahunting.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">NOVA</a>, an open-source prompt-pattern-matching framework, covering credential harvesting (env dumps, K8s tokens, cloud metadata URLs), system prompt and Modelfile disclosure, and liveness probing, designed for honeypot deployment.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">AI-powered honeypots: Turning the tables on malicious AI agents</a><br>Cisco Talos&#39;s Martin Lee walks through how generative AI can rapidly deploy adaptive honeypots that masquerade as full computing environments. His implementation combines a listener that accepts network connections, a simulated vulnerability that grants access once triggered, and an AI framework that responds to attacker instructions. By swapping the AI&#39;s system prompt, the same code can impersonate a Linux bash shell or a BusyBox-based smart fridge, creating what Martin calls a &quot;hall of mirrors&quot;, a controlled environment where attackers see plausible but distorted reflections of real targets and reveal their methodologies in real time. AI-orchestrated attacker tooling trades stealth for speed, making them easier to detect, and the AI agents lack the awareness to spot a fake environment once they arrive.</p><p class="paragraph" style="text-align:left;">💡 AI is making honeypots and deception much simpler to do at scale and convincingly. Lots of cool work to be done here.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/C0axx/CanaryHunter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">C0axx/CanaryHunter</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/c0ax/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Curtis Ringwald</a> for red teamers to spot common canary tokens in docs, configs (AWS, WireGuard, Kube), the Registry, and MySQL dumps before triggering them, with a firewall rule that drops outbound traffic to every known canary IP.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/0xNslabs/CanaryTokenScanner?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">0xNslabs/CanaryTokenScanner</a><br>Tool by <a class="link" href="https://www.linkedin.com/company/neroteam/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">NeroTeam Security Labs</a> to spot embedded canary tokens and tracking URLs inside Office documents (.docx, .xlsx, .pptx) and PDFs before opening them. The scanner reads Office files as ZIP archives in memory and searches PDFs across both raw bytes and Flate/deflate-decompressed streams, filtering common schema domains to cut false positives.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/xFreed0m/ghosttype?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">xFreed0m/ghosttype</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/freed0m/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Roei Sherman</a> that extracts credentials from AI tool conversation history for Claude Code, Cursor, Codex CLI, and ChatGPT Desktop. Detection runs TruffleHog as a subprocess in filesystem mode for its 800+ detectors and live verification against provider APIs, paired with an in-tree pattern engine (30 regexes plus 10 heuristic patterns) for loose context signals TruffleHog misses. Findings from either engine link back to the source conversation file with severity, detector name, and verification status, so triage can filter to credentials the provider confirms are live.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b> </p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.jamesshore.com/v2/blog/2026/you-need-ai-that-reduces-your-maintenance-costs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">You Need AI That Reduces Maintenance Costs</a> - “The math only works if the LLM <i>decreases</i> your maintenance costs, and by exactly the inverse of the rate it adds code.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nudgesecurity.com/content/practitioners-guide-to-agentic-ai-security?utm_medium=sponsored&utm_source=tldr&utm_content=newsletter&utm_campaign=ai_security&utm_term=agentic-ai-security-pdf" target="_blank" rel="noopener noreferrer nofollow"><b>[Free Guide] The 4 steps to get ahead of agentic AI risks </b></a><b>- </b>Agentic AI is already inside your organization. And most of the time, nobody in IT or security approved it. This free guide is for security, IT, and risk leaders who need to get ahead of agentic AI, before it becomes a liability.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/oT1BI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web</a> - RedAccess’ Dor Zvi found &gt;5K apps from Lovable, Replit, Base44, and Netlify had “no security or authentication”, leaked PII, were phishing sites, etc.</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/malicious-skills-supply-chain-risks-in-coding-agents-with-dynamic-context?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Malicious Coding Agent Skills and the Risk of Dynamic Context</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/nick-frichette?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Nick Frichette</a> and <a class="link" href="https://www.linkedin.com/in/ryan-simon-2767bb15/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Ryan Simon</a> demonstrate how malicious Claude Code skills can bypass model-level prompt injection defenses <span style="background-color:rgb(255, 255, 255);">using dynamic context commands (</span><code>!ls</code><span style="background-color:rgb(255, 255, 255);"> syntax), which execute before the model reviews the skill content. They analyzed the Clawsights skill, a real-world credential theft attempt that exfiltrates GitHub tokens, finding that while Claude Opus 4.6 correctly identified and blocked the original malicious skill, adding dynamic context commands allowed the attack to succeed because those commands run during preprocessing.</span></p><p class="paragraph" style="text-align:left;"><span style="background-color:rgb(255, 255, 255);">Recommendations: organizations can mitigate this by setting </span><code>&quot;disableSkillShellExecution&quot;: true</code><span style="background-color:rgb(255, 255, 255);"> in managed settings, review </span><code>.claude/skills/</code><span style="background-color:rgb(255, 255, 255);"> directories (including nested folders and </span><code>--add-dir</code><span style="background-color:rgb(255, 255, 255);"> paths), require code review for </span><code>.claude/</code><span style="background-color:rgb(255, 255, 255);"> changes, and monitoring for suspicious patterns like </span><code>allowed-tools: Bash(*)</code><span style="background-color:rgb(255, 255, 255);">, external URLs, and commands performing reconnaissance or attempting network access.</span></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://heyitsas.im/posts/drinking-llms?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)</a><br><a class="link" href="https://www.linkedin.com/in/yasamal4ik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Asim Viladi</a> built a multi-agent LLM harness that has turned up 30+ findings (20+ CVEs) over the past few months, mostly in network-reachable services. Originally aimed at documentation-code mismatches, the harness two remote unauthenticated out-of-bounds writes in the Linux kernel&#39;s ksmbd and a chained unauthenticated RCE-to-root path in CUPS.</p><p class="paragraph" style="text-align:left;">Under the hood, the harness chains a target seeder, hypothesis generators reading docs and source for invariants, hunters iterating PoCs in isolated VMs, report writers, and a conductor redirecting stuck agents, with an external grader outside the loop because frontier models will otherwise inflate findings or edit their own objectives. Asim also tried activation steering on the hypothesis generator, both drunkenness for creativity and abliteration to bypass refusals. The drunkenness produced no new vulnerability classes and abliteration ended up being more useful, making models refuse less.</p><p class="paragraph" style="text-align:left;">Asim found granular role separation most helps smaller models, as swapping in Codex or Claude collapses the harness into a single end-to-end hunter. In some cases smaller models running for days can match what a frontier model one-shots. Asim&#39;s next bets are looped LLMs and RL-trained task decomposition, which would let models do their own scaffolding instead of needing hand-tuned harnesses.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark</a><br>Microsoft&#39;s Autonomous Code Security team, led by <a class="link" href="https://www.linkedin.com/in/tsgatesv?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Taesoo Kim</a>, built MDASH, their multi-model agentic scanning harness, which has found 16 new Windows vulnerabilities across the networking and authentication stack including four RCEs.</p><p class="paragraph" style="text-align:left;">MDASH is structured as an agentic discovery and remediation pipeline that scans, debates, deduplicates, and proves candidate findings, chaining 100+ specialized AI agents across an ensemble of frontier and distilled models, with extensible plugins for Microsoft-specific context foundation models may not have. On benchmarks, it found 21 of 21 planted vulnerabilities with zero false positives on a private test driver, hit 9^% (of 28) and 100% (of 7) confirmed MSRC cases in clfs.sys and tcpip.sys, and scored 88.45% on the public CyberGym benchmark of 1,507 real-world vulnerabilities (prior leader: 83.15%).</p><p class="paragraph" style="text-align:left;">The post argues that the orchestration/harness is critical and gives a performance boost over a base model + simple prompt, and that this architecture allows MDASH to absorb future model improvements without being rewritten.</p><p class="paragraph" style="text-align:left;">💡 Looks like Microsoft hired Taesoo Kim (the Georgia Tech professor whose Team Atlanta won DARPA’s AIxCC) + a bunch of that team, and that’s now the Microsoft Autonomous Code Security team. Neat. Looking forward to seeing more from them!</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/model-disproves-discrete-geometry-conjecture/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">An OpenAI model has disproved a central conjecture in discrete geometry</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/github/status/2056949168208552080?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">X thread</a>: GitHub employee had a poisoned VS Code extension → ~3,800 GitHub-internal repos exfiltrated</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/kageroumado/phosphene?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">kageroumado/phosphene</a> - A video wallpaper engine for macOS Tahoe</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.census.gov/newsroom/press-releases/2025/older-adults-outnumber-children.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Older Adults Outnumber Children in 11 States and Nearly Half of U.S. Counties</a> - And wait until you see Congress!</p></li><li><p class="paragraph" style="text-align:left;">Jen Easterly: <a class="link" href="https://www.linkedin.com/posts/jen-easterly_a-brief-note-to-new-cybersecurity-grads-activity-7392076035799883776-OhKo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">A brief note to new cybersecurity grads trying to land that first job</a> - Don’t compete with AI, learn to lead it. Strengthen your technical foundation. Go where the growth is (go to areas that are exploding, not saturated). Find opportunities to build experience.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/3N_oWQCmTYg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Advice Jeff Bezos received early at Amazon</a>: “You have enough ideas to destroy Amazon.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/wrlovely/years?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">wrlovely/years</a> - A personal longevity system built on Claude Code. Your DNA, bloodwork, scans, and visit notes live as markdown in a private git repo, with slash commands to organize and analyze them.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/typefully/minimal-twitter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">typefully/minimal-twitter</a> - Minimal theme for Twitter.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/BJLFfkGHWUU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Beatboxing with a dog</a> 😂 </p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AI + Design</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;">Claude Code <a class="link" href="https://github.com/anthropics/claude-code/blob/main/plugins/frontend-design/skills/frontend-design/SKILL.md?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">frontend-design Skill</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/claude-design-anthropic-labs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Introducing Claude Design by Anthropic Labs</a> - Collaborate with Claude to create polished visual work like designs, prototypes, slides, one-pagers, and more.</p></li><li><p class="paragraph" style="text-align:left;">OpenAI docs - <a class="link" href="https://developers.openai.com/blog/designing-delightful-frontends-with-gpt-5-4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Designing delightful frontends with GPT-5.4</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/cyxzdev/Uncodixfy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">cyxzdev/Uncodixfy</a> - A rule set that forces Codex models to stop relying on its usual UI habits.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/introducing-chatgpt-images-2-0/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">Introducing ChatGPT Images 2.0</a> - Some pretty impressive example images</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.adriankrebs.ch/blog/design-slop/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">An attempt to detect AI design patterns in Show HN pages</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-329-ai-powered-honeypots-github-action-canaries-microsoft-s-agentic-security-scanner" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=52a3efa6-9d7a-45c3-ab83-62f9caf93739&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #328 - Shai-Hulud&#39;s Source Code Leaked, Break Into Buildings for $, Reversing EDRs with AI</title>
  <description>Teardown of TeamPCP&#39;s offensive framework that was briefly published on GitHub, Reddit AMA on a career in physical penetration testing, the end of &quot;opaque defense&quot;: AI makes understanding defensive tool implementations easy </description>
  <link>https://tldrsec.com/p/tldr-sec-328</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-328</guid>
  <pubDate>Thu, 14 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-14T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">☀️ My Least Favorite Type of Tan(Stack)</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I had a fun personal anecdote to share but I didn’t have time to write it up this week.</p><p class="paragraph" style="text-align:left;">For now, #HugOps to everyone dealing with yet another supply chain attack.</p><p class="paragraph" style="text-align:left;">I hope you’re getting the support you need 🫂 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ddcddfa4-566a-4ef1-853c-2086e9d67b47/image.png?t=1778744578"/></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Cloud Security Has Changed. </b><br><b>Has Your Strategy?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Agentic AI is reshaping cloud risk. AI agents, machine identities, and distributed data systems are creating new privilege pathways, dark data, and attack surfaces that traditional posture tools were not built to govern. Join Palo Alto Networks product leaders to learn how Cortex Cloud helps teams secure identity, data, and AI across the modern cloud stack.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.paloaltonetworks.com/resources/webcasts/transforming-posture-security-for-the-modern-cloud-stack?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai#" target="_blank" rel="noopener noreferrer nofollow"><b>Watch Webinar</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Hm I am curious about modern security posture strategies and dynamically enforcing least privilege 🤔 Seems important with agents potentially running amok.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/V4bel/dirtyfrag?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">V4bel/dirtyfrag</a><br>Dirty Frag, discovered and reported by <a class="link" href="https://x.com/v4bel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Hyunwoo Kim</a>, is a universal Linux LPE vulnerability class that chains two page-cache write bugs (xfrm-ESP and RxRPC) to achieve deterministic root privilege escalation without race conditions across major distributions including Ubuntu, RHEL, Fedora, and openSUSE.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reversinglabs.com/blog/copy-fail-5-yara-rules?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Copy Fail Flaw: 5 YARA Rules for Detection and Remediation</a><br>ReversingLabs&#39; <a class="link" href="https://www.linkedin.com/in/maik-morgenstern/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Maik Morgenstern</a> covers Copy Fail (CVE-2026-31431), a Linux kernel privilege escalation that lets any unprivileged user write 4 bytes into the in-memory copy of any readable file, including system binaries like /usr/bin/su. That&#39;s enough to neuter the password check, so the next run of su returns a root shell. The on-disk file is never touched, so standard file integrity tools see nothing. The exploit runs identically on every major Linux distribution shipped since 2017, making shared-kernel environments (multi-tenant servers, CI/CD pipelines, container clusters) the highest-risk targets.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Within a day, ReversingLabs had observed more than a dozen variants in the wild, including compiled C reimplementations of the original PoC and a separate rootsecdev toolkit that targets /etc/passwd instead of /usr/bin/su. Most were trivial reformattings with different hashes but identical execution, so ReversingLabs built a five-tier YARA ruleset anchored on a cryptographic string the exploit fundamentally depends on. High-confidence rules catch the original Theori PoC and the rootsecdev toolkit. Medium-confidence rules cover reimplementations of the core technique along with compiled and dropper variants. A broad hunting rule covers Python, C, and Go variants that combine the cryptographic string with a known target binary.</p></div><p class="paragraph" style="text-align:left;">For the full technical breakdown, see <a class="link" href="https://copy.fail/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Theori&#39;s writeup at </a><a class="link" href="https://copy.fail?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">copy.fail</a> and the <a class="link" href="https://github.com/theori-io/copy-fail-CVE-2026-31431?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">original PoC</a>. More from <a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Microsoft</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/microsoft/AntiSSRF?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">microsoft/AntiSSRF</a><br>The DevSec team at Microsoft recently open-sourced secure by default libraries that mitigate the risk of Server-Side Request Forgery in cloud-hosted applications. Currently available for .NET and NodeJS applications, the libraries provide durable protection against common SSRF bypass patterns including HTTP redirects and DNS rebinding, with more languages planned for the future. Microsoft also released <a class="link" href="https://github.com/microsoft/dusseldorf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Dusseldorf</a>, a dynamic SSRF testing tool for verifying that AntiSSRF is doing its job.</p><p class="paragraph" style="text-align:left;">H/T <a class="link" href="https://www.linkedin.com/in/247arjun/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Arjun Gopalakrishna</a> and his team for AntiSSRF, and <a class="link" href="https://www.linkedin.com/in/ndrix/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Michael H.</a> and his team for Dusseldorf.</p><p class="paragraph" style="text-align:left;">💡 If I had to choose between a) getting my favorite dessert and b) having a new, tested, secure-by-default library to eliminate a class of vulnerabilities, I’d choose the latter. For a delicious apple crumble pie straight from the oven is delectable once, while foiling a vulnerability class fills the soul 😍 More like this please!</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Browser & identity attacks matrix — </b><br><b>open-source from Push Security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);">Most attack frameworks weren&#39;t built for how breaches actually happen today. Attackers don&#39;t need network access or endpoint compromise; they go straight for the browser and identity layer. Push Security&#39;s Browser & Identity Attacks Matrix maps </span><span style="color:rgb(34, 34, 34);"><b>51 techniques across 10 tactic phases</b></span><span style="color:rgb(34, 34, 34);">, covering AiTM phishing, ClickFix, device code phishing, OAuth consent abuse, extension supply chain attacks, and more.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);">It&#39;s open-source, community-maintained, and built for how modern attacks actually work.</span></p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://hubs.li/Q04f_q890?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow"><b>Map your identity attack surface</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">This is super cool! Probably the best breakdown I’ve seen of modern browser and identity based attacks, including some subtle stuff + a number that Push Security discovered iirc. And neat that it’s open source 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://docs.cloud.google.com/docs/security/threat-model/bigquery-threat-model?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">BigQuery threat model report</a><br>Google Cloud published a threat model for BigQuery covering 14 attack vectors across data confidentiality, integrity, and availability, each mapped to STRIDE categories and MITRE ATT&CK tactics. The model surfaces schema tampering to corrupt downstream pipelines, privilege escalation and service account impersonation, data exfiltration via export jobs to attacker-controlled Cloud Storage buckets, persistence through hard to detect IAM bindings on datasets or scheduled queries, spoofing via leaked service account keys or OAuth tokens, and cost-based denial of service from resource-intensive queries that drain on-demand budgets or starve slot capacity for other users.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The recommended mitigations are mostly standard cloud hygiene anchored in BigQuery specifics, including least privilege IAM with regular audits via Security Command Center, VPC Service Controls perimeters to limit egress, Cloud Audit Log monitoring for suspicious calls like <code>SetIamPolicy</code> and <code>datasets.patch</code>, Workload Identity Federation instead of service account keys, custom query quotas to bound DoS impact, and table snapshots for recovery.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/doyensec/cloudsec-tidbits?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">doyensec/cloudsec-tidbits</a><br><a class="link" href="https://doyensec.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Doyensec</a> maintains CloudSec Tidbits, a blog series and Infrastructure as Code (IaC) lab collection covering cloud security bugs that happen when the infrastructure is correctly configured but the web app misuses the cloud services. The three prior episodes cover falling back to the system role in AWS SDK clients, tampering with AWS Cognito user pool attributes, and privilege escalation via AWS Batch. Each post ships with a deployable lab so you can reproduce the vuln yourself.</p><p class="paragraph" style="text-align:left;">💡 I previously included this in <i>tl;dr sec</i> but sharing again due to the new lab described more below.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2026/05/05/cloudsectidbits-masso-cognito-sso.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">The Danger of Multi-SSO AWS Cognito User Pools</a><br>Doyensec&#39;s <a class="link" href="https://www.linkedin.com/in/francesco-lacerenza/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Francesco Lacerenza</a> and <a class="link" href="https://www.linkedin.com/in/ouadmoha/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Mohamed Ouad</a> analyzed multi-tenant AWS Cognito User Pool deployments where multiple external IdPs (OIDC and SAML) are registered against a single pool, and found several attack paths that open up when one of those IdPs becomes malicious or compromised.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The vulnerabilities include “JIT ghost identity” creation, provider collision via Unicode homoglyphs (one IdP using a Cyrillic character that passes as distinct from its ASCII twin), username parsing attacks where security checks and downstream code disagree on the<code> &lt;ProviderName&gt;_&lt;sub&gt;</code> format, and IdP identifier hijacking where unclaimed email domains route auth flows to providers an attacker controls. All four come from the same mistake. Security sensitive attributes like tenantID or role get read straight from federated tokens an attacker controls, rather than computed on the server from a verified email domain. AttributeMapping makes this worse. A malicious IdP can inject arbitrary values into custom user attributes, bypassing Cognito&#39;s write controls.</p></div><p class="paragraph" style="text-align:left;">Doyensec also released <a class="link" href="https://github.com/doyensec/maSSO?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">maSSO</a>, a weaponized OIDC/SAML/SCIM IdP testing tool, plus a <a class="link" href="https://github.com/doyensec/cloudsec-tidbits/tree/main/lab-masso?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Terraform lab</a> for reproducing these attacks.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>, <a class="link" href="https://linkedin.com/in/amitaico?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Amitai Cohen</a>, and <a class="link" href="https://www.linkedin.com/in/benjamin-read-41817121/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Benjamin Read</a> describe the most recent Internet-is-on-fire npm supply chain attack by TeamPCP that compromised TanStack, UiPath, and Mistral AI packages. The GitHub Actions exploit chain: the forked a repo and renamed it (to evade fork-list searches), oopened a PR that triggered the <code>pull_request_target</code> workflow, the attacker’s fork code poisioned the GitHub Actions cache with a malicious pnpm store, and when a legitimate maintainer PR was later merged into <code>main</code>, the release workflow restored the poisoned cache. The attacker-controlled binaries then extracted OIDC tokens directly from runner process memory to publish malicious packages without stealing npm credentials. The post provides IOCs, detection guidance, and remediation steps.</p><p class="paragraph" style="text-align:left;">YMMV but I came across these: </p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/GLPMC/Tanstack-Worm-Detector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">GLPMC/Tanstack-Worm-Detector</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/omarpr/mini-shai-hulud-ioc-scanner?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">omarpr/mini-shai-hulud-ioc-scanner</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Shai-Hulud Goes Open Source</a><br>Datadog&#39;s <a class="link" href="https://www.linkedin.com/in/ryan-simon-2767bb15/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Ryan Simon</a>, <a class="link" href="https://linkedin.com/in/sebastianobregoso?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Sebastian Obregoso</a>, and <a class="link" href="https://www.linkedin.com/in/gregfoss/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Greg Foss</a> analyze the complete source code of the Shai-Hulud offensive framework attributed to TeamPCP, which was briefly published on GitHub before being removed. The TypeScript/Bun-based modular toolkit harvests credentials from 100+ file paths, extracts GitHub Actions Runner.Worker memory via <code>/proc/&lt;pid&gt;/mem</code>, enumerates AWS Secrets Manager/SSM across 17 regions, and exfiltrates data using hybrid encryption to <code>git-tanstack[.]com</code> or GitHub dead-drop repos. </p><p class="paragraph" style="text-align:left;">The framework poisons npm packages via stolen tokens and OIDC abuse while forging complete Sigstore provenance bundles (Fulcio certificates + Rekor transparency logs), establishes persistence through VSCode tasks and Claude Code <code>SessionStart</code> hooks, and implements a destructive deadman switch (<code>rm -rf ~/</code>) that triggers on GitHub token revocation. 19 of 22 previously documented TeamPCP TTPs are present in the codebase.</p><p class="paragraph" style="text-align:left;">💡 Great breakdown, and honestly pretty thoughtful tooling.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/ridgelinecyberdefence/vanguard?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">ridgelinecyberdefence/vanguard</a><br>Tool that packs the full incident response lifecycle into a single Go binary, including Velociraptor, Volatility, KAPE, and the standard forensics stack, plus 28 MITRE-mapped IR use cases (ransomware, BEC, lateral movement, credential theft, rootkit detection). Runs on Windows or Linux with built-in case management, tamper-evident evidence handling, and full air-gapped support.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/gadievron/honeyslop?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">gadievron/honeyslop</a><br><a class="link" href="https://www.linkedin.com/in/gadievron/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Gadi Evron</a>, <a class="link" href="https://www.linkedin.com/in/john-cartwright-02201a1/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">John Cartwright</a>, <a class="link" href="https://www.linkedin.com/in/daniel-cuthbert0x/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Daniel Cuthbert</a>, and <a class="link" href="https://www.linkedin.com/in/michal-kamensky-a65804247/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Michal Kamensky</a> created honeyslop, a collection of deliberately vulnerable-looking code canaries designed to identify AI-hallucinated vulnerability reports by embedding unique UUIDs, fake function names (like <code>zqx_tarnish_v3</code>), and a fabricated CVE-2025-99919 that self-identify slop reports when grep&#39;d.</p><p class="paragraph" style="text-align:left;">💡 “Quick PoC, vibe-coded as a joke (not production-grade),” but I like the idea.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/referefref/OpenAIPot?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">referefref/OpenAIPot</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/jbrine/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">James Brine</a> that poses as an OpenAI-compatible API endpoint to catch attackers using stolen or planted credentials. Valid keys pass through to OpenAI, while decoy keys trigger a system prompt swap that injects deceptive content into the response. Repeat attempts trigger IP blocking with realistic out-of-tokens errors so attackers don&#39;t realize they&#39;ve been caught, and logs feed into SIEMs and Slack via integrations mapped to MITRE Engage.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reddit.com/r/cybersecurity/comments/1t4cwvj/we_get_paid_to_break_into_buildings_for_a_living?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">We get paid to break into buildings for a living. Ask us anything!</a><br>Reddit AMA with TrustedSec&#39;s <a class="link" href="https://www.linkedin.com/in/paul-koblitz-33701083/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Paul Koblitz</a>, <a class="link" href="https://www.linkedin.com/in/costa-petros-4122659/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Costa Petros</a> and <a class="link" href="https://www.linkedin.com/in/david-boyd-1a464936/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">David Boyd</a> answering questions about physical penetration testing, drawing on years of experience breaking into buildings for clients.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://dreadnode.io/research/redefining-ai-red-teaming-in-the-agentic-era?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Redefining AI Red Teaming in the Agentic Era</a><br>Dreadnode&#39;s <a class="link" href="https://www.linkedin.com/in/raja-sekhar-rao-dheekonda-8461a241/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Raja Sekhar Rao Dheekonda</a> released an agentic AI red teaming system built on their open-source SDK (45+ attack strategies, 450+ prompt transforms, 130+ scorers). The operator describes the objective in plain English, and the agent selects attacks and transforms, generates an executable workflow, runs it with full tracing, and returns a structured assessment with severity ratings and compliance tags. That&#39;s the orchestration work operators currently do by hand with frameworks like PyRIT, Garak, and Promptfoo. The methodology and full attack catalog can be found in <a class="link" href="https://arxiv.org/abs/2605.04019?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">the arXiv paper</a>.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">In a case study against Meta&#39;s Llama Scout, the agent ran 674 attacks across 68 harmful-content objectives in 3 hours with zero code, succeeding 85% of the time and identifying 232 critical findings. Across the three jailbreak strategies tested, Crescendo (gradual conversational escalation) and Graph of Attacks (exploring prompt variations) both hit 100%, while Tree of Attacks (branching prompt search) needed about three times as many tries to reach 96%. Even asking plainly, with no jailbreak technique at all, still produced harmful content 80% of the time.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://trustedsec.com/blog/the-defensive-stack-is-exposed?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">The Defensive Stack is Exposed: LLMs, Reverse Engineering, and the End of Opaque Defense</a><br>TrustedSec&#39;s <a class="link" href="https://www.linkedin.com/in/justinelze/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Justin Elze</a> ran LLMs against five commercial endpoint products and found that reverse engineering defensive products like EDRs used to take skilled reverse engineers weeks, now takes days with the right workflow and the right questions. The same approach worked on all five EDRs because they&#39;re built the same way: YARA-style rules, behavioral logic, allowlists, prefilters, scripted engines (some shipped as readable Lua after one decryption pass), and local ML classifiers, all of it sitting on or near the host where it can be studied. See Justin’s <a class="link" href="https://gist.github.com/HackingLZ/8956b015a55412522d22a88e0dd284fc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">EDR Reverse Engineering Skill</a> and this <a class="link" href="https://gist.github.com/HackingLZ/a9f71c8ea7bd6d867765bda0af2460f6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">complete workflow</a> for reverse engineering an EDR.</p><p class="paragraph" style="text-align:left;">Once that logic is reachable, rules and scoring thresholds get extracted, exclusion lists and trust paths reveal the least-monitored path through the system, update diffs expose what the vendor quietly fixed, and the same analysis surfaces product-specific vulnerabilities in parsing, IPC, and kernel callbacks.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Elze recommends leaning on layers attackers can&#39;t study as easily: host hardening (WDAC, ASR rules, LSA Protection), SIEM detections built on raw telemetry rather than EDR verdicts, and identity-layer detection (Entra ID risk policies, token theft indicators, directory changes).</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div></div><p class="paragraph" style="text-align:left;">💡 Excellent article, I think it does a great job pointing out some prior security assumptions that are changing and what it means for defenders. And great, detailed section on what defenders should do. </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/distil-labs/distil-ai-slop-detector?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">distil-labs/distil-ai-slop-detector</a><br>Chrome extension by <a class="link" href="https://www.linkedin.com/company/distil-labs/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Distil Labs</a> that detects AI-generated text with a smaller, 242MB fine tuned model (Gemma 3 270M with GPT OSS 120B (teacher)) that can run entirely in-browser, plus a Claude Desktop skill and CLI for training your own classifiers using the same distillation pipeline.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/daybreak/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Daybreak: Frontier AI for cyber defenders</a><br>OpenAI announces Daybreak, which seems like their version of Project Glasswing, with an extra focus on making software resilient by design. “Defenders can bring secure code review, threat modeling, patch validation, dependency risk analysis, detection, and remediation guidance into the everyday development loop so software becomes more resilient from the start.” Partner quotes from Cloudflare, Cisco, CrowdStrike, Palo Alto Networks, Oracle, Zscaler, Akamai, and Fortinet.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Mythos finds a curl vulnerability</a><br><a class="link" href="https://www.linkedin.com/in/danielstenberg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Daniel Stenberg</a> digs into the Mythos scan of curl&#39;s 178K lines of C. The report flagged five &quot;confirmed&quot; vulnerabilities, but after the curl security team&#39;s review three were documented API behavior, one was &quot;just a bug,&quot; and only one became a low-severity CVE. The results match what curl has already seen from AISLE, Zeropath, and OpenAI Codex Security, which together triggered 200 to 300 bugfixes over the past 8-10 months. Daniel so far finds that AI tools are good at finding usual and established kinds of errors, not (yet) finding novel kinds of bugs.</p><p class="paragraph" style="text-align:left;">“My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos.”</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Behind the Scenes Hardening Firefox with Claude Mythos Preview</a><br>Mozilla&#39;s <a class="link" href="https://www.linkedin.com/in/bgrins/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Brian Grinstead</a>, <a class="link" href="https://www.linkedin.com/in/christian-holler-b9001aa9/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Christian Holler</a>, and <a class="link" href="https://www.linkedin.com/in/frederik-braun-security/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Frederik Braun</a> detail how Mozilla built an agentic harness on top of their existing fuzzing infrastructure that writes and runs reproducible test cases to confirm bugs, scales across ephemeral VMs, and integrates with their security lifecycle for dedup, tracking, and triage. Running Claude Mythos Preview, Mozilla found 271 bugs in Firefox 150, including sandbox escapes, race conditions, and use-after-free bugs that fuzzers miss.</p><p class="paragraph" style="text-align:left;">Audit logs also validated existing defenses, showing the model repeatedly trying prototype pollution sandbox escapes only to get shut down by Mozilla&#39;s frozen-prototypes architecture. Looking ahead, Mozilla plans to wire the pipeline into CI to scan patches as they land, and recommends other projects build similar pipelines now.</p><p class="paragraph" style="text-align:left;">💡 Great example of the power of a <i>target-specific</i> (in this case, Firefox) harness providing additional value on top of a capable underlying model. I also liked: the description of building a hardening pipeline, how the right architecture eliminated <b>classes</b> of vulnerabilities, and more context around the number and type of bugs found.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/TbQn3n1lnWM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Interesting photography trick examples</a></p></li><li><p class="paragraph" style="text-align:left;">Aakash Gupta - The future of cinema is <a class="link" href="https://x.com/aakashgupta/status/2052161570571243947?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">ScreenX, a 270-degree field of view</a></p></li><li><p class="paragraph" style="text-align:left;">Relentless - <a class="link" href="https://www.youtube.com/watch?v=OQ0OOzOwsJY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">How to Start a Cult | Lulu Cheng Meservey</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=ypjTHjROQJU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Ari at Home meets Wayne Brady</a> - Freestyle creating beats and rapping</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/CeZa6a_VycA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Turning my toddler’s stories into songs</a> - Catchy actually, and 🥹</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/x9t90-beK_E?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Best Crazy Frog Remix</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/oZ2M1FoEcr8?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Why are chains used to guide rain down?</a> - Apparently someone is creating informational songs around random facts. Probably the music, script, and video shots are all AI generated. Kind of interesting though.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/facebookincubator/below?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">facebookincubator/below</a> - A time traveling resource monitor for modern Linux systems</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://about.gitlab.com/blog/gitlab-act-2/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">GitLab Act 2</a> - Open letter from GitLab that they’re restructuring, and a likely “workforce reduction”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.cloudflare.com/building-for-the-future/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Building for the future</a> - Cloudflare is laying off 1,100 (~20%) employees to prepare for “the agentic AI era”</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://every.to/context-window/openai-flips-the-script?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">OpenAI Flips the Script</a> - Every CEO Dan Shipper explains why OpenAI’s coding app has become his daily driver for work, head of growth shares useful workflows.</p></li><li><p class="paragraph" style="text-align:left;">Fiona Fung, Eng Director for Claude Code - <a class="link" href="https://www.youtube.com/watch?v=igO8iyca2_g&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Running an AI-native engineering org</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/claude-for-creative-work?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Claude for Creative Work</a> - Anthropic released MCP connectors that integrate Claude with creative software including Blender, Autodesk Fusion, Adobe Creative Cloud, Ableton, Splice, SketchUp, Resolume, and Affinity by Canva.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/finance-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Agents for financial services and insurance</a> - Anthropic released ten agent templates for financial services workflows including pitch building, KYC screening, and month-end closing, available as plugins in Claude Cowork/Code or as cookbooks for Claude Managed Agents. Repo: <a class="link" href="https://github.com/anthropics/financial-services?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">anthropics/financial-services</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=3pkz-Ie_k_c&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Theo on Anthropic, Cursor, and xAI/SpaceX</a> - Some interesting (potential) dynamics I hadn’t though of</p></li><li><p class="paragraph" style="text-align:left;">Pieter Levels - <a class="link" href="https://x.com/levelsio/status/2046271694042505451?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Replaced all his Chrome extensions with his own vibe coded one</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://handyai.substack.com/p/your-ceo-is-suffering-from-ai-psychosis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">Your CEO is suffering from AI psychosis</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-328-shai-hulud-s-source-code-leaked-break-into-buildings-for-reversing-edrs-with-ai" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=2be166d4-5bb5-4b53-841a-e631c851d438&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #327 - Finding Zero-days with Any Model, Practical Package Security, Measuring the AI Offense-Defense Gap</title>
  <description>Niels Provos on finding 0-days with public models, a guide to securing your use of third party packages, two open source tools to measure AI hacking vs defense (+ dynamic lab environment)</description>
  <link>https://tldrsec.com/p/tldr-sec-327</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-327</guid>
  <pubDate>Thu, 07 May 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-05-07T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🫶 Friend Visit</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Last weekend I visited my good friend Aaron and his partner, staying at their place in southern California, and it was <i>delightful</i>.</p><p class="paragraph" style="text-align:left;">There’s something special about meeting a friend’s partner and seeing their place, you get such a lovely insight into who they are and what they value. The bookshelves, the photos from their couple trips, the unique items they’ve picked up along the way.</p><p class="paragraph" style="text-align:left;">We played a few rounds of this board game, Forbidden Island, which was a lot of fun, would recommend. Clint analytical brain was fully engaged, and people were amused 😅 </p><p class="paragraph" style="text-align:left;">I managed to delay doing an AI-powered Deep Research about optimal strategies until I was at the airport on the way back. It wasn’t easy.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0efb304f-e03a-413b-947e-1449334ac1db/IMG_2202__1_.jpeg?t=1778138242"/></div><p class="paragraph" style="text-align:left;">Aaron was a work friend who became a normal friend over many Wednesday dinners. And after several months I got upgraded to his non burner phone (not a joke) 🙌 </p><p class="paragraph" style="text-align:left;">We had talked about me coming down to stay with him for a weekend… and I actually did it! It was kind of going out on a limb, as we’d never spent more than a few hours together at a time, but I’m really glad I did. We had a great time, and I feel like we grew a lot closer in just a few days.</p><p class="paragraph" style="text-align:left;">Maybe there’s someone you really click with at work or from some hobby, and if you put yourself out there and spend more time with them (even if it feels cringe to ask), that could end up being a great friendship 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> AI ROI: You know the AI bill, but what are the outcomes?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams can only answer with invoice data.</p><p class="paragraph" style="text-align:left;">Harmonic Security Usage Explorer closes that gap. It automatically classifies every AI interaction across your organization into the use cases driving real work, specific to your business. Get actual patterns to understand how your teams use AI, how much time they spend, the cost, and where risk lives.</p><p class="paragraph" style="text-align:left;">CIOs rationalize spend, CISOs get risk in context, & AI committees get proof of impact.</p><p class="paragraph" style="text-align:left;">Early access is now open. Request your spot.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.harmonic.security/understand-ai-usage-early-access?utm_campaign=tldrsec&utm_source=tldrsec&utm_medium=newsletter&utm_campaign=aiusageintelbeta" target="_blank" rel="noopener noreferrer nofollow"><b>Get early access</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Getting visibility into your company’s AI usage is actually pretty hard. See also a <a class="link" href="https://www.youtube.com/watch?v=5oy2-s6-tzQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Harmonic demo</a> I got from the CEO/co-founder Alastair Paterson, though I’m sure they do a lot more now.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://lab.ctbb.show/research/the-dot-dot-slash-that-frameworks-hand-you?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework</a><br><a class="link" href="https://x.com/xssdoctor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Jonathan Dunn</a> reverse-engineered the URL decoding pipelines of 8 major frontend frameworks (React Router, Next.js, Vue Router, Angular, SvelteKit, Nuxt, Ember, and SolidStart) to understand how Client Side Path Traversal (CSPT) vulnerabilities arise when encoded slashes (%2F) in dynamic route parameters get decoded and interpolated into fetch URLs. <a class="link" href="https://github.com/xssdoctor/cspt_research?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Labs GitHub repo</a>.</p><p class="paragraph" style="text-align:left;">💡 Wow, super detailed, awesome post. Also, <a class="link" href="https://x.com/xssdoctor/status/2040937315703377972?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">this story</a> about Jason Haddix’s mentorship 🥹</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">C/C++ checklist challenges, solved</a><br>Trail of Bits recently added a <a class="link" href="https://appsec.guide/docs/languages/c-cpp/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">C/C++ security checklist</a> to their Testing Handbook, and in this post, Graham Sutherland and Paweł Płatek share walkthroughs of two C/C++ challenges. They also released <a class="link" href="https://github.com/trailofbits/skills/tree/main/plugins/c-review?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">c-review</a>, a Claude skill that runs the C/C++ checklist as LLM prompts against a codebase, tuned to the platform and threat model.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The first challenge is a Linux ping program with a command injection bug, where two undocumented behaviors in standard IP address functions (one accepting trailing garbage, the other reusing a shared buffer between calls) let an attacker bypass the input validation. The second is a Windows driver where a missing safety flag and an incomplete registry read combine to escalate from a local crash to full kernel code execution. By planting two crafted registry values, an attacker tricks the driver into copying arbitrary data onto the kernel stack and overwriting a function pointer.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://vercel.com/blog/introducing-deepsec-find-and-fix-vulnerabilities-in-your-code-base?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Introducing deepsec: The security harness for finding vulnerabilities in your codebase</a><br><a class="link" href="https://linkedin.com/company/vercel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Vercel</a> announces <a class="link" href="https://github.com/vercel-labs/deepsec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">deepsec</a>, an open source security scanner that uses Claude Opus 4.7 and GPT-5.5 coding agents to identify vulnerabilities in codebases, running entirely on user infrastructure with the user&#39;s own Claude and OpenAI subscriptions. Internally, deepsec runs a regex sweep to flag security-sensitive files, then the agents investigate each candidate, tracing data flows and assessing severity. A refusal-detection classifier checks each research step, letting it run on off-the-shelf models in addition to cyber-tuned variants. </p><p class="paragraph" style="text-align:left;">The tool also ships with a revalidation step that reduces false positives to an estimated 10–20% in their experience, a plugin system (<a class="link" href="https://github.com/vercel-labs/deepsec/blob/main/docs/writing-matchers.md?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">docs</a>) for codebase-specific tuning, and parallel execution across Vercel Sandboxes for large repositories.</p><p class="paragraph" style="text-align:left;">💡 It’s interesting to see platforms like Vercel and Cursor launching security scanning services. The overall architecture makes sense and is in line with common approaches. It’d be nice if someone benchmarked all of these open source tools, Skills, products, etc. on the same targets and shared the results 👀 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:#222222;"><b> </b></span><span style="color:#222222;"><b>Adaptive Security: Security Awareness Training Built for AI Threats</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI is changing how attacks are executed. Deepfakes, voice clones, and AI-generated spearphishing across email, SMS, and voice are now table stakes for attackers. Adaptive Security&#39;s next-generation platform simulates these exact threats, scores individual employee risk using real behavior and OSINT exposure, and auto-delivers personalized training tied to what each person experienced. Trusted by security teams at PayPal, Ramp, Bose, and more. </p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.adaptivesecurity.com/lp/nb/security-awareness-training?utm_source=sp_email&utm_medium=email&utm_campaign=2026_05_NA_TLDR%3Bsec_newsletter&utm_id=701Rd00000guu14IAA" target="_blank" rel="noopener noreferrer nofollow"><b>Book a Demo </b></a><b>👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">There’s been a big rise in AI-powered deepfake attacks, it’s great to see people tackling it 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://sonraisecurity.com/blog/global-s3-another-c2-channel-for-agentcore-code-interpreters?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Global S3: Another C2 Channel for AgentCore Code Interpreters</a><br>Sonrai&#39;s <a class="link" href="https://www.linkedin.com/in/nigel-sood/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Nigel Sood</a> builds on <a class="link" href="https://www.linkedin.com/in/kmcquade3/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Kinnaird McQuade</a>‘s prior research on DNS-based exfiltration from sandboxed AWS Bedrock AgentCore Code Interpreters, showing that the interpreter&#39;s documented global S3 access can also serve as a bidirectional Command & Control (C2) channel. Sood extended McQuade&#39;s <a class="link" href="https://github.com/BeyondTrust/pwning-agentcore-code-interpreter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">open-source PoC</a> so a client inside the sandbox polls an external bucket for shell commands, executes them, and writes output back via presigned PUT URLs. Unlike the DNS path AWS has since mitigated, this isn&#39;t a Bedrock vulnerability since S3 access is intended behavior, so customers have to handle it themselves. Sood recommends VPC mode with Gateway Endpoints and strict Endpoint Policies limiting access to specific buckets.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://engseclabs.com/blog/agent-credential-isolation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">AWS Credential Isolation for Local AI Agents</a><br>EngSecLabs&#39; <a class="link" href="https://linkedin.com/in/alex-smolen-8a59a31?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Alex Smolen</a> walks through how to safely hand AWS credentials to local AI agents, recommending combining <a class="link" href="https://github.com/61418/elhaz?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">elhaz</a>, a credential broker daemon that manages auto-refreshing STS credentials via Unix socket, with <a class="link" href="https://github.com/engseclabs/trailtool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">trailtool</a> for generating least-privilege IAM policies from CloudTrail logs (based on what the agent actually uses).</p><p class="paragraph" style="text-align:left;">Alex arrives at this recommendation based on challenges with other approaches: environment variables leak to every process and only capture a snapshot that expires mid-session, mounting <code>~/.aws/</code> hands over every profile on the host (and agent deny lists don&#39;t catch bash subprocesses reading the file directly), and metadata emulation breaks on macOS because Docker Desktop&#39;s loopback doesn&#39;t reach the host. Sockets sidestep all of that because the mount itself becomes the access control. If you don&#39;t bind the socket into a container, the credentials don&#39;t exist there at all, so each agent ends up with its own scoped identity by default.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/what-the-march-2026-threat-technique-catalog-update-means-for-your-aws-environment?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">What the March 2026 Threat Technique Catalog update means for your AWS environment</a><br>AWS&#39; <a class="link" href="https://www.linkedin.com/in/shannonbrazil/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Shannon Brazil</a> and <a class="link" href="https://www.linkedin.com/in/cydneystude/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Cydney Stude</a> documented three new threat techniques the AWS Customer Incident Response Team has seen in live incidents. Attackers are abusing Cognito refresh tokens (30-day default, configurable up to 10 years) to maintain access without invalidating legitimate sessions, using <code>ec2:DeregisterImage</code> to permanently delete AMIs (unrecoverable unless Recycle Bin retention is enabled), and using <code>UpdateAssumeRolePolicy</code> to attach new principals to existing IAM roles instead of creating new ones.</p><p class="paragraph" style="text-align:left;">The post emphasizes that attackers are increasingly using legitimate AWS API calls in illegitimate contexts rather than exploits, requiring security teams to monitor for contextual anomalies like unexpected principals or timing. Most cloud monitoring is tuned for creation events (new roles, new logins, new AMIs) and rarely covers modifications or token refreshes on what&#39;s already there. AWS published CloudTrail detection queries for each.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;">BSidesSF 2025 talk - <a class="link" href="https://youtu.be/fCaQOPcjKVw?t=977&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Scalably Securing Third-party Dependencies in Heterogeneous Environments</a> by Anthropic’s <a class="link" href="https://www.linkedin.com/in/ziyad-edher/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Ziyad Edher</a> and <a class="link" href="https://www.linkedin.com/in/chrnorm/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Chris Norman</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.chainguard.dev/unchained/mythos-pulls-zero-days-forward-heres-what-you-need-to-know-now/?utm_source=clint-gibler&utm_medium=3p-sponsorship" target="_blank" rel="noopener noreferrer nofollow"><b>Are you prepared for Mythos? Stay ahead of zero-days with Chainguard </b></a>- AI is finding and weaponizing zero-days faster than any disclosure process can publish them. The answer isn&#39;t patching faster. When a registry gets poisoned, you don&#39;t want to beat the clock. You want to be on a supply chain the attack never touches.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">NIST Updates NVD Operations to Address Record CVE Growth</a> - Due to a 264% surge in CVE submissions between 2020 and 2025, going forward NIST will only enrich CVEs: in CISA&#39;s KEV catalog, affecting critical software, and software used within the federal government.</p></li></ul><p class="paragraph" style="text-align:left;"><sub>*Sponsored</sub></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/FilippoBau/depcut?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">FilippoBau/depcut</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/filippobau/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Filippo Baudanza</a> that cuts Dependabot noise by checking whether vulnerable npm symbols are actually imported in JavaScript/TypeScript codebases. It parses imports with tree-sitter, extracts vulnerable symbols from GHSA data (with an optional LLM fallback), and matches them against a lockfile-scoped dependency graph to classify each alert as REACHABLE, UNREACHABLE, or INDETERMINATE, and outputs JSON or SARIF for CI pipelines.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/practical-package-security-the-unofficial-guide?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Practical Package Security: The Unofficial Guide</a><br>Wiz&#39;s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a> gives a nice survey of actionable best practices to shrink your attack surface, protect execution environments, control package ingestion, and catch compromises early. Rami recommends minimizing dependencies, adding install cooldowns via your package manager or Renovate or Dependabot so the ecosystem catches malware first, locking package versions with hash verification, using wrapper tools like Datadog’s <a class="link" href="https://github.com/DataDog/supply-chain-firewall?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">supply-chain-firewall</a>, and turning off install scripts via npm&#39;s <code>ignore-scripts</code> or pnpm&#39;s <code>onlybuiltdependencies</code>. </p><p class="paragraph" style="text-align:left;">Larger organizations can add registry proxies or private package repositories, plus cloud-based development environments and zero trust production to limit damage when malicious code runs. On the detection side, plant honeytokens in CI pipelines. </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/weirdmachine64/SharkMCP?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">weirdmachine64/SharkMCP</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/mohamedbenchikh/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mohamed Benchikh</a> that wraps Wireshark&#39;s <code>sharkd</code> interface as an MCP server so LLMs can dig through PCAP files with natural language. Each capture gets its own sharkd subprocess for packet inspection, protocol analysis, conversation tracking, and stream reassembly across TCP, UDP, TLS, HTTP, and VoIP, while heavy queries are cached in memory so pagination stays fast.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet</a><br>SentinelOne&#39;s <a class="link" href="https://www.linkedin.com/in/jags-is-fine/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Juan Andres Guerrero-Saade</a> and <a class="link" href="https://www.linkedin.com/in/vitalykamluk/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Vitaly Kamluk</a> uncovered fast16, a 2005 sabotage framework (five years before Stuxnet) that selectively targets high-precision calculation software, patching code in memory to tamper with results to produce inaccurate calculations across an entire facility (e.g. those used in nuclear weapons research). fast16 is the earliest known Windows malware to embed a Lua VM, and combines a wormable Lua-powered binary with a kernel driver that scans executables for 101 code patterns, then surgically rewrites floating-point routines.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The fast16 name had already appeared in the 2017 ShadowBrokers leak inside NSA&#39;s Territorial Dispute list, and Unix-style source control markers in the binaries point to long-term development by government or military engineers. The main binary sat on VirusTotal for nearly a decade, missed by almost every antivirus engine, before SentinelLABS pieced it together.</p></div><p class="paragraph" style="text-align:left;">💡 Wow, interesting discovery process and historical discussion.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@rohitashokgowd/seven-queries-to-audit-the-sentinel-detections-your-soc-may-have-missed-8e9c73fc2522?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.</a><br>Rohitashokgowd shared seven KQL queries for auditing Microsoft Sentinel detection rules and finding the ones that look fine on paper but don&#39;t actually catch anything. Sentinel&#39;s standard health dashboards check whether rules run, not whether they work, so a rule can sit green for months while it queries a dead table or autocloses every alert it produces. The rules flag <b>silent zombies</b> (rules that always return zero), <b>shadow detectors</b> (alerts that never become incidents), <b>high-FP rules</b> (90%+ closed as benign), <b>broken feeds</b> (querying empty tables), <b>forgotten disabled rules </b>(disabled rules that were never turned back on), <b>untracked detections</b> (missing MITRE or entity mappings), and <b>coverage drift</b> (techniques with 60%+ alert drops over 30 days).</p><p class="paragraph" style="text-align:left;">Rohitashokgowd also built <a class="link" href="https://github.com/rohit8096-ag/Sentinel-Assessment-Tool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Sentinel Assessment Tool</a>, a PowerShell module that generates an HTML report of detection coverage across Sentinel and Defender.</p><p class="paragraph" style="text-align:left;">💡 I love the meta idea of having queries you can run periodically (or continuously) that are evaluating a range of potential failure modes for your security tools. I think this same idea applies across code scanning, cloud security, or any domain where you have security checks looking for “bad,” and the specific failure modes called out in this post are good starting points.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/tahaafarooq/Fenrir?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">tahaafarooq/Fenrir</a><br>Tool by <a class="link" href="https://x.com/tahaafarooq?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Taha Afarooq</a> that uses eBPF to capture SSH, PAM, sudo, and su credentials at the kernel level. The Go agent deletes itself from disk and runs only in memory, poses as a legitimate system process, and exits if it detects defensive tools (Wireshark, Sysdig, Falco, Tetragon), or VM/container environments (Docker, Kubernetes, Cuckoo, Joe Sandbox). Captured credentials are smuggled out over encrypted network traffic to a companion fenrir-channel C2 with a web dashboard.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://dreadnode.io/research/mine-the-gap-open-source-tools-for-measuring-the-ai-offense-defense-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mine the Gap: Open-Source Tools for Measuring the AI Offense-Defense Gap</a><br>Dreadnode&#39;s <a class="link" href="https://www.linkedin.com/in/jaysongrace/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Jayson Grace</a> and <a class="link" href="https://www.linkedin.com/in/martin-wendigg/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Martin Wendiggensen</a> released two open-source tools for evaluating AI agents in head-to-head red versus blue engagements, since existing benchmarks miss what happens when both sides operate autonomously against shared infrastructure.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/dreadnode/DreadGOAD?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">DreadGOAD</a> is a fork of the GOAD Active Directory lab packaged for AWS, with Terraform/Terragrunt provisioning, golden AMIs, private networking via SSM, automated validation of 50+ AD vulnerabilities, and a variant generator that randomizes entity names so agents can&#39;t memorize their way through. <b><a class="link" href="https://github.com/dreadnode/ares?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Ares</a></b> runs on top: seven red team agents (recon, credential access, cracking, ACL abuse, privilege escalation, lateral movement, coercion) reach domain dominance through Golden Ticket persistence in under six minutes with a 95%+ success rate, while three blue team agents (triage, threat hunting, lateral analysis) investigate the same telemetry.</p><p class="paragraph" style="text-align:left;">Every attacker action is recorded as ground truth, so blue team agents are scored on how accurately they reconstruct what actually happened, not against static checklists or curated log dumps.</p><p class="paragraph" style="text-align:left;">💡 Lots of really cool ideas in this post- automatically generating variants of a vulnerable environment so you can test how agents perform, measuring the performance of red vs blue autonomous agents, recording actions for future ground truth, and open sourcing the core parts 🤘 Great work.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://the-decoder.com/openai-releases-open-source-model-that-strips-personal-data-from-text?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">OpenAI releases open-source model that strips personal data from text</a><br>OpenAI released <a class="link" href="https://github.com/openai/privacy-filter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Privacy Filter</a>, an open-source 1.5B model that detects and redacts eight PII categories including names, emails, phone numbers, account numbers, and secrets like API keys. It runs locally on a laptop or in-browser with a 128K token context window, uses single-pass labeling instead of generation, and ships under Apache 2.0 on GitHub and Hugging Face.</p><p class="paragraph" style="text-align:left;">💡Useful for data loss prevention and log scrubbing, though weaker on non-English text and non-Latin scripts, so keep a human in the loop.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/google-cloud-cat-mouse?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Google wants AI defense to be as fast as AI offense</a><br><a class="link" href="https://www.linkedin.com/in/fredericlardinois//?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Frederic Lardinois</a> covers Google Cloud&#39;s Next &#39;26 security announcements. Google added three new AI agents to Google Security Operations for threat hunting, detection engineering, and third-party context, alongside an existing triage agent that has processed over 5 million alerts in the past year and reduced 30-minute analyses to roughly 60 seconds. Wiz, recently acquired by Google, extended its AI-Application Protection Platform across Databricks, AWS, Azure, and Salesforce, is adding inline AI security hooks in IDEs and agent workflows, and shipped a dynamic AI-BOM to inventory shadow AI- the AI frameworks, models, and IDE extension in your environment. Mythos Preview will be available through Google’s Vertex AI for defensive use.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.provos.org/p/finding-zero-days-with-any-model?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Finding Zero-Days with Any Model</a><br><a class="link" href="https://linkedin.com/in/nielsprovos?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Niels Provos</a> argues that discovering novel vulnerabilities with AI is not just a frontier-model capability but an orchestration problem. He demonstrates using his open-source <a class="link" href="https://github.com/provos/ironcurtain?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">IronCurtain</a> framework with commercial models (Opus 4.6, Sonnet 4.6) and open-weight models (GLM 5.1) that he can replicate Anthropic&#39;s 1998 OpenBSD TCP SACK finding and discover new zero-days in widely-deployed software, with each scan costing $30-150 per codebase. </p><p class="paragraph" style="text-align:left;">Niels was able to find these vulnerabilities using IronCurtain (which supports arbitrary workflows structured as finite-state machines (FSM) via plain YAML definitions) by building a specialized vulnerability discovery workflow that has a central Orchestrator agent that acts as a strategic router that then decides which specialized agent to dispatch next based on an append-only execution journal.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://bishopfox.com/blog/introducing-aimap-security-testing-for-ai-agent-infrastructure?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Introducing AIMap: Security Testing For AI Agent Infrastructure</a><br>Bishop Fox&#39;s <a class="link" href="https://linkedin.com/in/aashiq-ramachandran?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Aashiq Ramachandran</a> announces <a class="link" href="https://github.com/BishopFox/aimap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">AIMap</a>, an open-source tool that discovers, fingerprints, scores, and tests internet-exposed AI agent infrastructure by querying Shodan and fingerprinting endpoints across MCP servers, Ollama, vLLM, LiteLLM, LangServe, Gradio, ComfyUI, and other AI frameworks using Nuclei templates and live HTTP checks. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">AIMap assigns risk scores (0-10) based on authentication status, exposed tools, CORS policies, TLS configuration, and system prompt leakage, and includes protocol-specific attack modules for MCP servers (tool enumeration, unauthorized tool invocation, and prompt injection via tool descriptions), Ollama instances (model listing, model weight extraction, and prompt injection), and OpenAI-compatible endpoints (model enumeration, completion abuse, and system prompt extraction).</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Our evaluation of OpenAI&#39;s GPT-5.5 cyber capabilities</a><br>The UK AI Security Institute evaluated GPT-5.5 on various cybersecurity tasks, from basic to expert-level challenges across reverse engineering, exploit dev, and crypto attacks. On a custom VM reverse engineering challenge that took a human expert 12 hours, GPT-5.5 solved it in 10 minutes. “On the Expert-level tasks, GPT-5.5 achieves an average pass rate of <b>71.4%</b>, compared to <b>68.6%</b> for Mythos Preview, 52.4% for GPT-5.4, and <b>48.6%</b> for Opus 4.7. On this measure, GPT-5.5 may be the strongest model we have tested.”</p><p class="paragraph" style="text-align:left;">To see if the model could chain attack steps end-to-end, AISI ran it through &quot;The Last Ones,&quot; a 32-step corporate network simulation estimated at 20 hours for humans. GPT-5.5 completed the full chain in 2 of 10 attempts, making it the second model after Mythos to do it (which succeeded in 3/10 attempts). On &quot;Cooling Tower,&quot; a 7-step industrial control system attack, GPT-5.5 failed like every other model tested.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://tincan.kids/products/tin-can?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Tin Can</a> - A WiFi landline for kids. It doesn’t have apps, texting, or games—just real conversation with friends, neighbors, Grandma, or whoever you add to your approved contact list.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://theuselessweb.com/sites-we-lost?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">The Sites We Lost</a> - Archiving quirky, old websites. Some take me back.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=OkxFSf0olgA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Inside TIME’s Wild Day with MrBeast</a></p></li><li><p class="paragraph" style="text-align:left;">Morning Brew - <a class="link" href="https://www.youtube.com/watch?v=8oWcxFGz0LY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Why are the boys tryna get hot all of a sudden?</a> - On Looksmaxxing and medspas.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=NdU6UdUKaYc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Scott Galloway on Diary of a CEO</a> - AI’s impact (or not) on the economy and jobs, the war in Iran, being a parent, and more. </p><ul><li><p class="paragraph" style="text-align:left;">I thought Scott had an interesting point on China purposefully “AI dumping” low cost AI via open source models into the U.S. economy to potentially undermine Anthropic, OpenAI, and other companies, as much of the U.S. stock market is essentially a bet on AI, and how that’s similar to how China previously dumped below-cost steel into the U.S. market, which largely wiped out American steel.</p></li><li><p class="paragraph" style="text-align:left;">Also: “The receipts for love are grief.” 🥹</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;">Mitchell Hashimoto - <a class="link" href="https://mitchellh.com/writing/ghostty-leaving-github?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Ghostty Is Leaving GitHub</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.npr.org/2026/05/05/nx-s1-5807918/polymarket-panama-prediction-market?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">NPR went looking for Polymarket&#39;s Panama headquarters. It&#39;s elusive</a></p></li><li><p class="paragraph" style="text-align:left;">Joe Hudson - <a class="link" href="https://www.youtube.com/watch?v=NT55aMb1rw0&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">AI and The Return to Being Human</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://variety.com/2026/digital/news/meta-ai-mark-zuckerberg-copyright-infringement-lawsuit-publishers-scott-turow-1236738383/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Mark Zuckerberg ‘Personally Authorized and Actively Encouraged’ Meta’s Massive Copyright Infringement to Train AI Systems</a>, Publishers and Scott Turow Allege in Lawsuit</p></li><li><p class="paragraph" style="text-align:left;">Coinbase CEO Brian Armstrong’s <a class="link" href="https://x.com/brian_armstrong/status/2051616759145185723?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">tweet on letting go of 14% of Coinbase</a> - Is a crypto company firing a number of its employees a <i>job</i> rug pull 🤔 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/open-source-codex-orchestration-symphony/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">An open-source spec for Codex orchestration: Symphony</a> - OpenAI describes building <a class="link" href="https://github.com/openai/symphony?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Symphony⁠</a>, an agent orchestrator that turns a project-management board like Linear into a control plane for coding agents. Every open task gets an agent, agents run continuously, and humans review the results. Wow, this is really cool 👍️ </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/where-the-goblins-came-from/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Where the goblins came from</a> - Fascinating story about how OpenAI investigated why GPT-5.1+ models started increasingly mentioning goblins, gremlins, and other creators in metaphors 😂 </p></li><li><p class="paragraph" style="text-align:left;">Anthropic - <a class="link" href="https://claude.com/blog/new-in-claude-managed-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">New in Claude Managed Agents: dreaming, outcomes, and multiagent orchestration</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/anthropics/knowledge-work-plugins?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">anthropics/knowledge-work-plugins</a> - 11 plugins bundling the skills, connectors, slash commands, and sub-agents for a specific job function. Currently: productivity, sales, customer support, product management, marketing, legal, finance, data, enterprise search, bio research, cowork plugin management.</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Politics</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/nsOrnZV2h5M?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Politics used to be like this</a> - Clips of Mitt Romney, John McCain, and Obama being respectful. In one of them, at a McCain event, a woman says she can’t trust Obama because he’s an Arab. McCain corrects her, “He’s a decent family man.” Let’s get back to this.</p></li><li><p class="paragraph" style="text-align:left;">Last Week Tonight with John Oliver - <a class="link" href="https://www.youtube.com/watch?v=ZN4njIQcSR4&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Prediction Markets</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/7FqfS?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">We spoke to the man making viral Lego-style AI videos for Iran. Experts say it&#39;s powerful propaganda</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/icLLb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">Chinese firms market Iran war intelligence ‘exposing’ U.S. forces</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-327-finding-zero-days-with-any-model-practical-package-security-measuring-the-ai-offense-defense-gap" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=c149e08b-3a51-450c-bc4b-1fe0f16a8bc7&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #326 - AI Auto Exploiting Vulnerabilities, GitHub RCE, Autonomous Cloud Hacking Agent</title>
  <description>Automatically creating PoCs for vulnerabilities, git push → code execution on github.com, how well can an AI agent system hack your cloud?</description>
  <link>https://tldrsec.com/p/tldr-sec-326</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-326</guid>
  <pubDate>Thu, 30 Apr 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-04-30T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤘 Hackathon</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">This week Semgrep friends have flown in from all over the world to crazily build together.</p><p class="paragraph" style="text-align:left;">Engineers, security researchers, designers, and, as we are generous of spirit, even product managers.</p><p class="paragraph" style="text-align:left;">The fact that we do this every few quarters is one of my favorite things about Semgrep.</p><p class="paragraph" style="text-align:left;">A number of our coolest features came from a hack week: new engine features, AI triage before it was cool, and even Semgrep itself (back before that was the company’s focus, or name).</p><p class="paragraph" style="text-align:left;">I also really appreciate the in person time for learning about who people are outside of work.</p><p class="paragraph" style="text-align:left;">Hearing stories about their garden, travels, partner, or kids over boba and late night pizza.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2df88894-93f4-4245-b7cc-4c26f3f92b83/sr_dinner3.png?t=1777534699"/><div class="image__source"><span class="image__source_text"><p>Team dinner! If you look closely, you may notice a <a class="link" href="https://www.linkedin.com/in/katiepf/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Katie Paxton-Fear</a> (InsiderPhD). Shout-out <a class="link" href="https://www.linkedin.com/in/shelwu/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Shelley Wu</a>, who recently joined the team 🙌</p></span></div></div><p class="paragraph" style="text-align:left;">Can’t wait for the demos competition and showcase tomorrow 🤩 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Prowler: the world’s most widely adopted open cloud security platform</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Prowler automates security and compliance across any cloud environment, with agentless coverage of cloud infrastructure, SaaS, Kubernetes, containers, Infrastructure as Code, and more. It detects vulnerabilities and misconfigurations, prioritizes risks, accelerates remediation, and automates audit-ready compliance. </p><p class="paragraph" style="text-align:left;">Prowler has become the security platform of choice for thousands of cloud teams, with 45M+ downloads, 13K+ GitHub stars, and 300+ global contributors. Prowler Cloud delivers cloud security 10x more cost-effectively than alternatives.</p><h2 class="heading" style="text-align:center;"><a class="link" href="https://prowler.com/interactive-demo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow"><b>👉 </b></a><a class="link" href="https://prowler.com/interactive-demo?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow"><b>See Prowler in action 👈</b></a></h2></div><p class="paragraph" style="text-align:left;">I’m a huge fan of open source and companies that build around it. Also, this is a nice interactive demo- I like seeing the UI and how the product works with some helpful explanation.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/BuffaloWill/oxml_xxe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">BuffaloWill/oxml_xxe</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/willis-vandevanter-82a05018/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Willis Vandevanter</a> that embeds XXE payloads into OXML formats (DOCX, XLSX, PPTX, ODT, ODG, ODP, ODS), SVG, and raw XML for testing XXE vulnerabilities in document parsers. BlackHat USA 2015 <a class="link" href="https://oxmlxxe.github.io/reveal.js/slides.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent#/" target="_blank" rel="noopener noreferrer nofollow">slides</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Trailmark turns code into graphs</a><br>Trail of Bits&#39; Scott Arciszewski announces <a class="link" href="https://github.com/trailofbits/trailmark?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Trailmark</a>, an open source library that parses source code into queryable call graphs of functions, classes, call relationships, and semantic metadata. Trailmark uses tree-sitter for AST parsing and rustworkx for graph traversal, supporting 17 languages including C, Rust, Go, Python, and Solidity. The library ships with eight Claude Code skills (genotoxic, vector-forge, diagram, crypto-protocol-diagram, graph-evolution, mermaid-to-proverif, audit-augmentation, and trailmark) that enable graph-based security analysis like mutation triage (which mutant survivors are reachable from untrusted input), blast radius calculation, and taint propagation tracking.</p><p class="paragraph" style="text-align:left;">Using Trailmark on cryptographic libraries, they identified architectural bottlenecks and high value fuzzing target codec parsers.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Wiz Research uncovers Remote Code Execution in </a><a class="link" href="https://GitHub.com?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">GitHub.com</a><a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow"> and GitHub Enterprise Server</a><br>Wiz’s <a class="link" href="https://linkedin.com/in/sagi-tzadik-95b3a7194?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Sagi Tzadik</a> describes how they found an RCE in the git push pipeline that let any user with push access inject fields into internal metadata via unsanitized characters in push options, override the push execution environment, bypass sandboxing, and run arbitrary commands on GitHub&#39;s servers. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">GitHub patched the vulnerability within 6 hours of their report and confirmed zero exploitation by querying telemetry for an anomalous code path the exploit triggers. GHES admins should upgrade to the latest patch and review <code>/var/log/github-audit.log*</code> for unusual special characters in push options. See also <a class="link" href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">GitHub’s response</a>.</p></div><p class="paragraph" style="text-align:left;">“By leveraging AI-augmented tooling-particularly automated reverse engineering using IDA MCP-we were able to do what was previously too costly. Using AI, we rapidly analyzed GitHub&#39;s compiled binaries, reconstructed internal protocols, and systematically identified where user input could influence server behavior across the entire pipeline.”</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><span style="color:rgb(67, 67, 67);"><b> </b></span><b>Vibe Coding a Backport: </b><br><b>When &quot;Latest or Nothing&quot; Isn&#39;t an Option</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Scanners scream. Leadership wants dates. Engineering wants stability. And &quot;just upgrade&quot; (the only answer most teams hear) keeps colliding with breaking changes, flaky tests, and calendar risk. In Vibe Coding a Backport, Root&#39;s John Amaral argues for backporting as a first-class remediation discipline and walks through how agentic workflows are finally making it scalable: pin what you ship, understand the upstream fix, apply minimal change, validate with tests. A practical playbook for the messy real world.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.root.io/workshop/vibe-coding-a-backport?utm_campaign=43276343-April%202026%20-%20tldr%20sec%20newsletter%20placement%202&utm_source=tldr%20sec&utm_medium=newsletter" target="_blank" rel="noopener noreferrer nofollow"><b>Get the Playbook</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The interactive workshop format is pretty cool 👍️ Automatically backporting patches using AI is a neat approach that wasn’t feasible before, it’s fun to see new takes on longstanding challenges. </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://engseclabs.com/blog/cloudtrail-for-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">CloudTrail for AI Agents</a><br><a class="link" href="https://www.linkedin.com/in/alex-smolen-8a59a31/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Alex Smolen</a> introduces <a class="link" href="https://github.com/engseclabs/trailtool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Trailtool</a>, a tool that pre-aggregates AWS CloudTrail logs by entity (People, Sessions, Roles, Services, Resources) to enable faster queries and AI agent workflows compared to traditional SIEM or CloudTrail Lake approaches. The post walks through using Trailtool to detect “ClickOps” modifications, define least-privilege IAM policies for roles, respond to AccessDenied errors, and validate emergency break-glass access justifications.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System</a><br>Palo Alto Networks&#39;s <a class="link" href="https://www.linkedin.com/in/yahavfestinger/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Yahav Festinger</a> and <a class="link" href="https://www.linkedin.com/in/chendoy/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Chen Doytshman</a> describe &quot;Zealot,&quot; a multi-agent LLM penetration testing PoC using LangGraph, to empirically test autonomous AI offensive capabilities against cloud environments. The system uses a supervisor-agent architecture with three specialist agents (Infrastructure, Application Security, and Cloud Security) that share attack state through a centralized AttackState object. In sandbox testing against a misconfigured GCP environment, Zealot autonomously chained SSRF, GCP Instance Metadata Service credential theft, BigQuery enumeration, privilege escalation via self-granted <code>storage.objectAdmin</code> permissions, and data exfiltration, completing the full attack chain with minimal human guidance. </p><p class="paragraph" style="text-align:left;">Learnings: Zealot demonstrated unexpected initiative, such as autonomously injecting SSH keys for persistence, though it occasionally required human intervention to prevent resource-wasting &quot;rabbit hole&quot; scenarios. They found AI doesn&#39;t create new attack surfaces, it serves as a force multiplier by rapidly exploiting well-known misconfigurations at machine speed.</p><p class="paragraph" style="text-align:left;">💡 I like how the post describes their reasoning on why they used a hierarchical supervisor-agent architecture, what tools they chose to give each agent, and the discussion of state management and memory (context sharing, what <code>AttackState</code> tracks across phases). Lots of tactical details 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://securitylabs.datadoghq.com/articles/dependency-cooldowns?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">The case for dependency cooldowns in a post-axios world</a><br>Datadog&#39;s <a class="link" href="https://linkedin.com/in/kennedy-toomey?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Kennedy Toomey</a> discusses recent npm supply chain attacks, and notes that in Datadog’s 2026 <a class="link" href="https://www.datadoghq.com/state-of-devsecops/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">State of DevSecOps</a> report, they found half of organizations install at least one dependency within a day of release. Also good to keep in mind: using npm&#39;s semantic versioning with <code>^</code> and <code>~</code> ranges automatically accepts future updates, meaning you’re implicitly trusting future (potentially malicious) code. Yarn, pnpm, npm, and Dependabot all support dependency cooldowns now.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cooldowns.dev?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">cooldowns.dev</a><br>A configuration reference for dependency cooldowns across major package managers by <a class="link" href="https://www.linkedin.com/in/martinprpic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Martin Prpič</a>, covering uv, pip, npm, pnpm, Yarn, Bun, Deno, and <code>cargo-cooldown</code>, plus Renovate and Dependabot configurations. To make setup easier, Prpič also created <a class="link" href="https://github.com/mprpic/cooldowns/blob/main/cooldowns.sh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">cooldowns.sh</a>, a helper script that configures and verifies cooldowns across all supported tools in one command, with a check subcommand suitable as a CI gate.</p><p class="paragraph" style="text-align:left;">Note that cooldowns aren&#39;t a complete defense though, since they won&#39;t catch typosquatting, long-term maintainer compromise like xz-utils, or zero-days in already-installed packages.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Karib0u/rustinel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Karib0u/rustinel</a><br>By <a class="link" href="https://www.linkedin.com/in/theofchr/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Théo Foucher</a>: Rustinel is an open-source endpoint detection runtime for Windows and Linux. It collects native telemetry from ETW and eBPF, normalizes events into Sysmon-style fields, evaluates Sigma, YARA, and IOC detections, and emits ECS-compatible NDJSON alerts.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.bushidotoken.net/2025/04/tracking-adversaries-evilcorp-ransomhub.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Tracking Adversaries: EvilCorp, the RansomHub affiliate</a><br><a class="link" href="https://www.linkedin.com/in/william-t/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Will Thomas</a> (BushidoToken) describes the connection between EvilCorp, a sanctioned Russian cybercrime group, and RansomHub, a prominent ransomware-as-a-service operation. The link is established through shared TTPs, including the use of SocGholish malware for initial access and a Python backdoor (VIPERTUNNEL) for post-exploitation. Because EvilCorp has been under US sanctions since 2019, making it illegal for affected organizations to pay ransoms to them, this association may lead to sanctions against RansomHub as well (and thus legal risk to victims paying them).</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.magonia.io/research/why-a-decade-of-writing-detection-logic-makes-the-mythos-exploit-numbers-less-scary?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary</a><br><a class="link" href="https://www.linkedin.com/in/signalblur/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">David Burkett</a> argues that despite AI-powered systems finding vulnerabilities at an unprecedented rate, the impact on defenders is less catastrophic than headlines suggest because: new exploits have always exceeded defenders’ ability to write detections (that’s why you detect behaviors over individual IoCs and exploits), adversaries often don’t need zero days (see: ClickFix, phishing), and detection logic doesn’t map 1:1 with exploits (e.g. 1000s of RCE in Microsoft Office, but if Office spawns <code>powershell.exe</code>, that’s probably bad). </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">David also argues that ML-based anomaly detection is unlikely to be the answer due to the base rate fallacy: in an environment with 1 million daily events, a 0.001 false positive rate will generate 1,000 false alerts. More than exploit volume, he’s concerned about AI agents being granted excessive access, where for example prompt injection could trigger legitimate-looking actions (like wire transfers using real browser cookies) that are nearly impossible to distinguish from authorized behavior.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/kpolley/redai?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">kpolley/redai</a><br>By <a class="link" href="https://linkedin.com/in/kylepolley?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Kyle Polley</a>: A terminal workbench for AI-driven vulnerability discovery and live validation. After scanner agents produce candidate findings, validator agents work inside a live environment (a running instance of the target, plus whatever tools they need to interact with it) and try to prove or disprove each finding by clicking through the UI, hitting endpoints, writing PoC scripts, hosting helper servers, and saving the evidence. RedAI currently ships with validator plugins for agents to drive Chrome via agent-browser and an iOS Simulator, but it’s extendable.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://moak.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">MOAK - Mother of All KEVs</a><br><a class="link" href="https://www.linkedin.com/in/niv-hoffman-1852183a1/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Niv Hoffman</a>, <a class="link" href="https://www.linkedin.com/in/yair-saban-30615870/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Yair Saban</a> et al created MOAK, an agentic workflow that autonomously exploits 98% of open source KEVs (Known Exploited Vulnerabilities) using publicly available models (Opus 4.6 and GPT 5.4). They found MOAK was able to automatically create exploits for 174/178 KEVs that were published after the models’ knowledge cutoffs (to guarantee no contamination).</p><p class="paragraph" style="text-align:left;">The workflow: a <b>collector</b> gathers the CVE’s vulnerability description and relevant code changes. The <b>researcher</b> analyzes the vulnerability and reconstructs the full exploitation path, extracting primitives from the vulnerable code and builds a graph of possible exploit chains. The <b>builder</b> builds a controlled environment to reproduce the vulnerable system, the <b>exploiter</b> converts the research into a working exploit, then finally the <b>judge</b> verifies that the exploit and environment are valid and realistic.</p><p class="paragraph" style="text-align:left;">The <a class="link" href="https://moak.ai/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent#react2shell" target="_blank" rel="noopener noreferrer nofollow">Test Case: React2Shell</a> write-up is very cool and nicely detailed on how the workflow can iteratively find gadgets and exploit primitives, form hypotheses, and iterate until it discovers a path that works.</p><p class="paragraph" style="text-align:left;">💡 This is one of the more detailed write-ups of approaches I’ve seen in this space, worth reading!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://xbow.com/blog/mythos-like-hacking-open-to-all?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">GPT-5.5: Mythos-Like Hacking, Open to All</a><br>XBOW&#39;s <a class="link" href="https://www.linkedin.com/in/albert-ziegler-6b3b24138/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Albert Ziegler</a> and <a class="link" href="https://www.linkedin.com/in/stephenpbuckley/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Steve Buckley</a> call GPT-5.5 a Mythos-like step change in vulnerability detection. On their internal benchmark of real vulnerabilities in open-source applications, GPT-5.5 dropped the miss rate from GPT-5&#39;s 40% (and Opus 4.6&#39;s 18%) to 10%, with black-box performance now exceeding what GPT-5 achieved with source code access, and white-box performance pulling away so far it &quot;effectively killed&quot; their benchmark. The model also logs into target systems in roughly half the iterations of the next-best model and persists on failing paths only half as often as previous GPT versions or Opus, a meaningful gain given RLHF tends to bias models against giving up.</p><p class="paragraph" style="text-align:left;">See also XBOW’s <a class="link" href="https://xbow.com/blog/anthropic-opus4-7-first-look?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">evaluation of Opus 4.7</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.includesecurity.com/2026/04/ctfs-in-the-ai-era?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">CTFs in the AI Era</a><br>Include Security&#39;s <a class="link" href="https://linkedin.com/in/laurence-tennant-82573090?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Laurence Tennant</a> attended BSidesSF 2026 CTF, where the top 10 teams cleared every challenge with AI agents. Top teams ran pipelines that monitored CTFd for new challenges, spun up multiple agents in parallel, used a coordinator LLM to share insights between them when one stalled, and auto-submitted flags.</p><p class="paragraph" style="text-align:left;">CTFs play to everything LLMs are good at: bounded context, clear success criteria, instant feedback, and abundant public write-ups in the training data. Laurence contrasts CTFs with pentesting, in which goals are open-ended, false positives need business context to triage, code bases are large (not just an isolated few hundred lines), findings have to be written up for a client, and stepping outside scope has real consequences. The winning team <a class="link" href="https://github.com/verialabs/ctf-agent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">open-sourced their agent</a>, which cleared all 52 challenges.</p><p class="paragraph" style="text-align:left;">💡I do wonder if AI has “solved” CTFs 🙃 Maybe there will be new or separate CTFs where AI isn’t allowed, or some other rules to keep the challenges human-focused. Interesting times.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=O7joqcfy-eU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">I built Taskrabbit for Witches ($100K MRR - Projected)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/nnLo_rPLjbA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Mama panda swaps her kid for an apple</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/MgWX5wKkHks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Ranking Best Panda Moments</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/nWUUAE1bCqI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">What are the best Scottish memes?</a></p></li><li><p class="paragraph" style="text-align:left;">Alanis Morissette’s <a class="link" href="https://www.youtube.com/shorts/9cOS1scw8hQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">“Ironic” if it was written in 2025</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/S9c6ocOwhcY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Escalator sketch - seeing your future partner maybe</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://hackerone.com/ibb?type=team&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">The HackerOne Internet Bug Bounty program has been paused</a> - “AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Vercel says some of its customers’ data was stolen prior to its recent hack</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://lawsofsoftwareengineering.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Laws of Software Engineering</a> - A collection of principles and patterns that shape software systems, teams, and decisions.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.economist.com/science-and-technology/2026/03/30/why-a-startup-is-teaching-human-brain-cells-to-play-doom?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Why a startup is teaching human brain cells to play “Doom”</a> - <a class="link" href="https://corticallabs.com/doom.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Video</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://daringfireball.net/2026/04/another_day_has_come?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Daring Fireball on the Tim Cook Apple CEO transition</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Apple fixes bug that cops used to extract deleted chat messages from iPhones</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/posts/calebsima_thirty-years-ago-at-16-i-joined-the-team-activity-7454556030107230208-iiZ0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Caleb Sima on some interesting history of various cybersecurity companies</a>. Congrats to <a class="link" href="https://www.linkedin.com/in/meny-har/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Meny Har</a>, <a class="link" href="https://www.linkedin.com/in/johndifederico/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">John DiFederico</a>, <a class="link" href="https://www.linkedin.com/in/dylan-williams-a2927599/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Dylan Williams</a> for Spectrum Security’s seed found.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors</a> - Citizen Lab uncovered two sophisticated commercial surveillance vendors conducting multi-year location tracking campaigns by exploiting SS7 and Diameter signaling protocols across global mobile networks.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/8rPUA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Scoop: NSA using Anthropic&#39;s Mythos despite blacklist</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/lifeof_jer/status/2048103471019434248?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">An AI Agent Just Destroyed Our Production Data</a> - Cursor running Anthropic&#39;s flagship Claude Opus 4.6 deleted PocketOS’ production database and all volume-level backups in a single API call to Railway, their infrastructure provider. Oof 🫠 Lots of people are working on making agents safer, but there’s still a lot of work to be done.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://people.com/paradox-inc-cover-reveal-exclusive-11955668?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">People Magazine</a> - Forrest Brazeal is writing a book satirizing Silicon Valley (based on his experiences working at Google) called Paradox Inc, about the fall and rise of a time-travel startup. I love Forrest’s music and humor, I bet this is going to be great.</p></li><li><p class="paragraph" style="text-align:left;">Aidan Steele - <a class="link" href="https://awsteele.com/blog/2026/04/19/microtransactions-and-the-first-ai-native-fax-service.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Micro-transactions and the first AI-native fax service</a></p></li><li><p class="paragraph" style="text-align:left;">Jesse Itzler - <a class="link" href="https://www.youtube.com/watch?v=xDK42rroFYE&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">If Your Life Isn’t on One Page, It’s Too Complicated</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/iyYtYXGzNIs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">Mom and daughter excited when dad comes home</a> 🥹</p></li><li><p class="paragraph" style="text-align:left;">Yuki Piano - <a class="link" href="https://www.youtube.com/watch?v=c8CyQtemKKQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">KPop Demon Hunters Golden piano cover</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-326-ai-auto-exploiting-vulnerabilities-github-rce-autonomous-cloud-hacking-agent" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=da21a0a9-4e21-48c7-92c3-e900b0d92aa9&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #325 - Dissecting Mythos, The $0 Security Stack, GitHub Action Red Team Framework</title>
  <description>Replicating Mythos bugs with public models and more, building a useful security program for free, new post-exploitation framework for CI/CD pipelines that can replicate the full TeamPCP attack kill chain</description>
  <link>https://tldrsec.com/p/tldr-sec-325</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-325</guid>
  <pubDate>Thu, 23 Apr 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-04-23T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">😅 Bug Hunters Be Like</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I was going to open with a fun, personal story, but then I got caught up trying to cover a round-up of what a bunch of folks are saying about Mythos and frontier of LLM-driven vulnerability discovery, and now it’s past midnight 😅 </p><p class="paragraph" style="text-align:left;">So for now I leave you this meme, H/T <a class="link" href="https://infosec.place/notice/B59AWKU5zyEzlFZnjU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">buherator</a>:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6599b0cf-fd65-4499-ac34-9cd14c77e47a/image.png?t=1776928855"/></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> (Free!) Community Edition: Ready your attack surface for AI with runZero</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Gearing up for a deluge of AI-powered exploits? You’re gonna need fast, accurate visibility into all your assets.</p><p class="paragraph" style="text-align:left;">Created by HD Moore (the mind behind Metasploit), runZero delivers unrivaled discovery and exposure detection across your entire internal and external attack surfaces. No agents, no credentials, and no appliances required. runZero finds everything, including unknown, unmanaged, and &quot;I didn&#39;t know that was plugged in&quot; devices — along with broad classes of exposures from CVEs to default credentials and bad configs.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.runzero.com/try/?utm_source=tldr-sec&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow"><b>Start your 21-day free trial</b></a><b> 👈</b></h2><p class="paragraph" style="text-align:left;">Pro Tip: When your trial ends, downshift to our free Community Edition. It’s perfect for home labs (up to 100 devices!).</p></div><p class="paragraph" style="text-align:left;">I’ve met HD Moore a few times- <i>super</i> nice and sharp guy. I tried not to fan boy out, and he was just really friendly. I’ve heard great things about runZero, which is not surprising given the people behind it.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/thomaspreece/GitHub-Token-Tester?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">thomaspreece/GitHub-Token-Tester</a><br>Tool by <a class="link" href="https://www.linkedin.com/in/thomas-preece-105824335/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Thomas Preece</a> that enumerates the exact permissions of various GitHub tokens. For Classic PATs and OAuth tokens, it checks the scopes header from the user endpoint, while for App Installation Tokens, App User Access Tokens, and Fine-grained PATs, it brute-forces each permission individually against a repository where the user has admin access.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://oblique.security/blog/security-stack?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">The $0 security stack</a><br>Oblique’s <a class="link" href="https://linkedin.com/in/mayakaczorowski?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Maya Kaczorowski</a> describes their $0 security stack that’s gotten them through their first SOC2 audit period: Semgrep (free for up to 10 contributors) for SAST/SCA with AI-based triage, TruffleHog for secret scanning on commits, RunReveal&#39;s Community tier (5 data sources) as their SIEM ingesting GCP/Cloudflare/GitHub logs, and Sublime Security&#39;s Core tier (free for up to 100 mailboxes) for email security integrated with Google Workspace. They also deployed Apple Business for MDM to enforce disk encryption, password locks, and forced updates, noting that Mac devices include XProtect anti-malware that can&#39;t be disabled. The stack caught misconfigurations within 24 hours and provides built-in detections routed to a dedicated Slack channel.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Mutation testing for the agentic era</a><br>Mutation testing is a pretty neat approach in which you introduce bugs (mutants) and check if your tests catch them, flagging hot spots where code is insufficiently tested. Trail of Bits&#39; Bo Henderson announces <a class="link" href="https://github.com/trailofbits/muton?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">MuTON</a> and <a class="link" href="https://github.com/trailofbits/mewt?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">mewt</a>, two new mutation testing tools optimized for agentic use, along with a <a class="link" href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">configuration optimization skill</a> to help agents set up campaigns efficiently. MuTON provides first-class support for TON blockchain languages (FunC, Tolk, and Tact), while mewt is the language-agnostic core that also supports Solidity, Rust, Go, and more.</p><p class="paragraph" style="text-align:left;">The tools use Tree-sitter parsers to systematically introduce bugs into code and verify tests catch them, and implement mutant prioritization (high-severity mutations replace statements with reverts, medium-severity comment out lines, low-severity swap operators) to reduce campaign runtime.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Map your MCP attack surface across four risk categories</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">When MCP agents read data from connected systems and decide autonomously what to do next, the attack surface is the data, not the code. This framework maps risks across four categories (content injection, supply chain, config/governance, and ops), covers the agent-as-inadvertent-adversary problem, and provides a defense matrix mapped to the OWASP MCP Top 10.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.mintmcp.com/guides/mcp-data-risk?utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow"><b>Download the framework</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Lots of companies are working on securing their MCP usage, nice to see a risk framework with practical defenses and governance controls 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.varonis.com/blog/anonymous-s3-requests-evade-aws-logging?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">The Invisible Footprint: How Anonymous S3 Requests Evade AWS Logging</a><br><a class="link" href="https://www.linkedin.com/in/maya-parizer-327b361ba/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Maya Parizer</a> describes how Varonis Threat Labs discovered that anonymous S3 requests made through VPC endpoints weren&#39;t logged in CloudTrail Network Activity events, allowing attackers within compromised VPCs to exfiltrate data to external buckets with zero visibility. When anonymous requests targeted external S3 buckets and the VPC endpoint policy denied access, no events were created in either the source or target account&#39;s CloudTrail logs (management, data, or Network Activity events). AWS has since patched this issue to log all anonymous API requests to external S3 buckets as CloudTrail network activity events in the VPC endpoint owner&#39;s account.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-mode/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Cracks in the Bedrock: Agent God Mode</a><br>Palo Alto Networks’ <a class="link" href="https://www.linkedin.com/in/ori-hadad/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Ori Hadad</a> discovered that AWS Bedrock AgentCore&#39;s starter toolkit generates overly permissive IAM roles with wildcard permissions, enabling a &quot;God Mode&quot; attack where compromising one agent grants access to all others in the account. The post describes a multi-stage attack chain in which an attacker who compromises one agent could exfiltrate proprietary ECR images, access other agents’ memories, invoke every code interpreter, and extract sensitive data. Following responsible disclosure, AWS updated documentation to warn that auto-generated roles are for development/testing only and should never be used in production.</p><p class="paragraph" style="text-align:left;">💡Every time a major platform provider releases an insecure by default product or feature, a fairy loses its wings, and the <i>tl;dr sec</i> robot sheds a single, oily tear.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://trustoncloud.com/blog/wiz-custom-configuration-rules-coverage-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Wiz Custom Rules: Measuring the Cloud Security Coverage Gap</a><br>TrustOnCloud’s <a class="link" href="https://www.linkedin.com/in/jonathanrault/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Jonathan Rault</a> announces the open sourcing of their Wiz Custom Configuration Rule (CCR) packages written in Rego for <a class="link" href="https://github.com/trustoncloud/threatmodel-for-aws-s3?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">AWS S3</a>, <a class="link" href="https://github.com/trustoncloud/threatmodel-for-azure-storage?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Azure Storage</a>, and <a class="link" href="https://github.com/trustoncloud/threatmodel-for-google-bigquery?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">GCP BigQuery</a>. They mapped TrustOnCloud controls across those 3 major cloud services and compared them against the default Wiz coverage, and found Wiz’s default coverage was around 34%.</p><p class="paragraph" style="text-align:left;">The packages include mappings between TrustOnCloud controls and default Wiz rules, plus custom CCRs for gaps (missing high-severity controls including S3 account-level Block Public Access verification, VPC endpoint IAM restrictions, and BigQuery row-level access authorization checks). Each control is weighted using a CVSS-based scoring system that factors threat mitigation, impact, and control difficulty. TrustOnCloud is exploring Sigma rules to convert their detective controls into deployable code across broader security tooling beyond Wiz.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/sadreck/Butler?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">sadreck/Butler</a><br>By <a class="link" href="https://www.linkedin.com/in/tsakalidisp/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Pavel Tsakalidis</a>: Butler scans every repo for workflows, actions, secrets/variables, third-party actions, and produces HTML and CSV outputs to assist with security reviews, third-party dependency audits, and workflow management.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://ramimac.me/imposter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Fork Commit Detector</a><br>Client-side tool by <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a> that detects GitHub fork commits (commits accessible via a repo&#39;s namespace but not in any of its branches), which attackers can exploit to inject malicious code into CI/CD pipelines by referencing them directly via SHA or tags. </p><p class="paragraph" style="text-align:left;">The tool queries GitHub&#39;s API to check if a commit is HEAD of any branch, merged via PR, or referenced by signed tags, flagging unsigned fork commits as potential imposters and highlighting the highest-risk scenario: imposter tags where upstream tags point to attacker-controlled fork commits. This attack has been done in the wild, for example, the TeamPCP supply chain attack (Trivy, KICS) and Shai Hulud 2.0/AsyncAPI.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.boostsecurity.io/articles/introducing-smokedmeat?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">SmokedMeat: A Red Team Tool to Hack Your Pipelines First</a><br>Boost Security’s <a class="link" href="https://linkedin.com/in/francoisp?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">François Proulx</a> announces <a class="link" href="https://github.com/boostsecurityio/smokedmeat/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">SmokedMeat</a>, a post-exploitation framework for CI/CD pipelines that demonstrates the full attack kill chain TeamPCP used to compromise Trivy, LiteLLM, KICS, and more. <a class="link" href="https://www.youtube.com/watch?v=F5Hr_201Au8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Video overview</a>. The framework includes: </p><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Reconnaissance</b> - Scans GitHub Actions for injection flaws and overpermissive tokens.</p></li><li><p class="paragraph" style="text-align:left;"><b>Exploitation</b> - Auto-crafting payloads deployed via PR/issue/comment.</p></li><li><p class="paragraph" style="text-align:left;"><b>Post-exploit</b> - Sweep runner process memory for secrets, enumerate token permissions, collect loot.</p></li><li><p class="paragraph" style="text-align:left;"><b>Pivot</b> - Exchange OIDC tokens for AWS/GCP/Azure access, discover private repos with stolen PATs and run the embedded Gitleaks, probe SSH deploy keys, and map the full blast radius in a live visual attack graph</p></li></ol><p class="paragraph" style="text-align:left;">💡 Cool tool 🔥 </p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/pandaadir05/snoop?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">pandaadir05/snoop</a><br>By Adir Shitrit: A modern syscall tracer built on eBPF. Think strace, but with a real TUI, smart filters, TLS decryption, and output that&#39;s actually readable.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.forbes.com/sites/jonmarkman/2026/04/21/how-a-roblox-cheat-download-triggered-a-2-million-hack-at-vercel/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">How A Roblox Cheat Download Triggered A $2 Million Hack At Vercel</a><br>An employee at Context.ai tried to download a Roblox Cheat but actually got hit by a Lumma Stealer, which exfiltrated every credential in the victim’s browser. The attacker used those credentials to breach Context, steal the OAuth tokens of its customers, and pivot into the Google Workspace of a Vercel employee who had signed up for Context’s product and granted it “Allow All” permissions on their enterprise account. From there, the attacker moved into Vercel&#39;s internal systems and lifted customer environment variables that had not been flagged as sensitive. <a class="link" href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Vercel’s security bulletin</a>.</p><p class="paragraph" style="text-align:left;">💡 Oof, the transitive trust in this example is tough. I feel like most companies probably wouldn’t have had the hardening or detection visibility to detect or prevent this.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://geochen.medium.com/measuring-what-were-missing-58a8259f4c41?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Measuring What We’re Missing</a><br><a class="link" href="https://www.linkedin.com/in/geoc/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">George Chen</a> proposes a framework for measuring detection effectiveness by testing security assumptions and tracking false negatives across control areas (Identity & Access, Endpoint, Network, Cloud, Data Protection). He maps adversarial testing results (red team, purple team, BAS, threat hunting) to specific control areas, calculating detection rates as: <code>Detected / (Detected + Missed under test conditions)</code>, then applies organizational weightings based on critical business services and attack paths. </p><p class="paragraph" style="text-align:left;">George recommends tracking two separate metrics: an <b>effectiveness score</b> from tested scenarios and a <b>discovery count</b> of gaps found outside testing, to avoid penalizing proactive discovery while measuring how quickly teams find gaps, adapt detections, and improve coverage over time.</p><p class="paragraph" style="text-align:left;">💡 I really like the idea of separating a) measuring how we’re doing today and b) new things we discovered we were missing before. In many security domains, if you’re calculating security metrics naively, when you say add a new security scanning tool, you start surfacing vulnerabilities that were already there, but from an “open vulnerabilities” or “new vulns per unit time” in the short term you look worse. But really you just have fewer unknown unknowns / security gaps.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;">Gadi Evron - <a class="link" href="https://www.linkedin.com/posts/gadievron_so-youd-like-to-get-started-finding-0days-activity-7447929001915928577-b0B3/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">So you’d like to get started finding 0days with LLMs?</a></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://goauthentik.io/blog/2026-04-22-open-source-saas-is-dead?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Open Source SaaS is Dead; Long Live Open Source</a></b> - In the current debate around security threats to open source code, the real danger is not new AI tools, but reliance on a broken SaaS model. Security through obscurity was never an option.*</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://vibecoded.vc/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">RSA 2026: The Great Cooking</a> - A 🌶️ roasting of which vendors are GPT wrappers, cooked, or actually hard. I don’t agree with all of the analyses, but it’s also an interesting overview of the product categories, sponsor tiers, etc.</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored by Authentik </sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>Mythos Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Mythos found 271 vulnerabilities in Firefox</a> - “Defenders finally have a chance to win, decisively… The defects are finite, and we are entering a world where we can finally find them all.” LFG security fam 🤘</p><ul><li><p class="paragraph" style="text-align:left;">Davi Ottenheimer dug into the details a bit, I’m not sure what to think yet - <a class="link" href="https://www.flyingpenguin.com/mythos-mystery-in-mozilla-numbers-how-22-vulns-became-271-or-maybe-3-in-april/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Mythos Mystery in Mozilla Numbers: How 22 Vulns Became 271 or Maybe 3 in April</a></p></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.techradar.com/pro/security/mythos-accessed-by-unauthorized-users-as-anthropic-says-were-investigating-cracks-may-be-showing-in-project-glasswing-as-unknown-users-access-model-via-third-parties?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Mythos accessed by unauthorized users</a> - Mercor (training contractor) got breached, which leaked Anthropic’s model naming conventions, some hackers guessed the URL pattern, contractor credentials still worked.</p></li><li><p class="paragraph" style="text-align:left;">Zvi Mowshowitz - <a class="link" href="https://thezvi.substack.com/p/claude-mythos-2-cybersecurity-and?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Claude Mythos #2: Cybersecurity and Project Glasswing</a> - Mega post covering a bunch of related context and discussions</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://joshuasaxe181906.substack.com/p/exploits-dont-cause-cyberattacks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Exploits don&#39;t cause cyberattacks</a><br><a class="link" href="https://linkedin.com/in/joshsaxe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Joshua Saxe</a> argues that predictions of exponential cyberattack growth from AI vulnerability discovery capabilities (like Claude Mythos) are overblown, pointing to how previous AI capabilities (cheap Turing Test-passing chat, voice dialogue, and deepfakes) didn&#39;t cause the predicted tsunami of social engineering attacks, phone scams, or misinformation despite being free and trivially accessible. Attackers choose the easiest path to achieve their goals, and since most attacker groups already accomplish their objectives through simple phishing, credential stuffing, and known CVE exploitation, they&#39;re not blocked by vulnerability research limitations. </p><p class="paragraph" style="text-align:left;">Joshua recommends actor-centric threat modeling by asking which attacker constituencies would actually be unblocked by AI vulnerability research capabilities, what new goals they could pursue, and what cultural/organizational barriers might slow attacker AI adoption.</p><p class="paragraph" style="text-align:left;">💡 Joshua Saxe always has thoughtful, measured takes, I highly recommend his posts.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://pylos.co/2026/04/11/myth-mythos-where-do-we-go-from-here?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Myth & Mythos: Where Do We Go From Here?</a><br><a class="link" href="https://www.linkedin.com/in/joe-slowik/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Joe Slowik</a> examines the marketing hype around Mythos, but the unique perspective he adds here is critiques around Project Glasswing and the consortium, which includes major tech companies (Microsoft, Apple, Linux Foundation, Cisco, Palo Alto), but excludes critical OT/ICS vendors like Siemens, Rockwell, and Schneider Electric, as well as major non-US networking providers like Juniper, Ericsson, and Huawei. Currently, there’s a very “tech-company” focus, when ideally there’d also be an investment in defending legacy infrastructure in critical sectors like healthcare, utilities, and industrial facilities.</p><p class="paragraph" style="text-align:left;">💡 I agree with Joe’s emphasis on the broader set of companies and industries that foundation model labs should be helping as well. I expect Anthropic will, they just haven’t gotten there yet.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Our evaluation of Claude Mythos Preview’s cyber capabilities</a><br>The UK&#39;s AI Security Institute evaluated Mythos on cybersecurity tasks, finding it achieved 73% success on expert-level CTF challenges and became the first model to complete &quot;The Last Ones&quot; (TLO), a 32-step simulated corporate network attack requiring an estimated 20 hours of human expert time, succeeding in 3 out of 10 attempts and averaging 22 out of 32 steps completed. </p><p class="paragraph" style="text-align:left;">The evaluation used progressively harder benchmarks including CTF challenges and cyber ranges, with Mythos demonstrating the ability to autonomously discover and exploit vulnerabilities in multi-stage attacks on vulnerable networks, though it struggled with operational technology environments and was tested without realistic defensive measures like active defenders, EDR, or security monitoring. Performance continued scaling with increased token budgets up to the 100M token limit tested, suggesting further improvements are possible with additional inference compute. </p><p class="paragraph" style="text-align:left;">“There are also no penalties for the model for undertaking actions that would trigger security alerts. This means we cannot say for sure whether Mythos Preview would be able to attack well-defended systems.”</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic</a><br>This post by <a class="link" href="https://infosec.exchange/@flyingpenguin?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Davi Ottenheimer</a> is probably the most critical about Mythos I’ve found. Davi argues that: Anthropic&#39;s Claude Mythos Preview system card claims &quot;thousands of zero-days&quot; but the 244-page document dedicates only 7 pages to cybersecurity, never quantifies vulnerabilities with CVEs or CVSS scores, and its flagship Firefox demonstration collapses under scrutiny: the model exploited two bugs already found by Claude Opus 4.6, in already-patched Firefox 147, in a test harness with sandboxing and defenses stripped out, achieving 72.4% exploit success that drops to 4.4% when those two bugs are removed.</p><p class="paragraph" style="text-align:left;">Anthropic&#39;s own cyber range tests admitted the model &quot;failed against a properly configured sandbox with modern patches&quot; and cannot compromise operational technology environments. The $100M Project Glasswing &quot;defensive initiative&quot; is actually $4M in donations plus $100M in API credits to use Mythos itself, with few partner-confirmed findings, no comparison to existing fuzzers (AFL, libFuzzer, OSS-Fuzz), no false-positive rates, and a 90-day report promise with no delivery yet.</p><p class="paragraph" style="text-align:left;">💡 This post is overall more negative about Mythos than I personally feel is justified, but it’s good to read critical analyses of published results, as it gives us examples of analyzing blog claims more thoughtfully and critically. Worth reading, it pulls out some nuances I haven’t seen discussed elsewhere.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">AI Cybersecurity After Mythos: The Jagged Frontier</a><br>I have <b>thoughts</b> about this post. AISLE’s <a class="link" href="https://www.linkedin.com/in/stanislav-fort/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Stanislav Fort</a> describes attempting to replicate the Mythos showcase vulnerabilities on eight small, cheap, open-weights models. He argues the moat is the system (targeting, iterative deepening, validation, triage, maintainer trust) rather than the model itself.</p><p class="paragraph" style="text-align:left;"> <a class="link" href="https://x.com/kannthu1/status/2042375317306950031?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Dawid Moczadlo</a> pointed out that the prompts are quite specific about how exactly the vulnerability occurred (“Consider the behavior of the SEQ_LT/SEQ_GT macros with sequence number wraparound.”). <a class="link" href="https://x.com/mbleigh/status/2041977760923709667?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Michael Bleigh</a> and <a class="link" href="https://x.com/mooncat_is/status/2041983329398854042?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">julia</a> on giving the models just the code they need to analyze, vs scanning the total repo from scratch. See also the LinkedIn comments on the posts <a class="link" href="https://www.linkedin.com/posts/stanislav-fort_new-post-ai-cybersecurity-after-mythos-share-7447684360943702016-SfHU?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.linkedin.com/posts/niels-rogge-a3b7a3127_look-anthropic-is-lying-to-us-again-you-activity-7448307381312253952-46EC?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:left;">💡 First off: I think the AISLE team has clearly found and reported a number of high impact vulnerabilities in open source, which is great. However, I feel this post is <i>highly misleading</i> from an experimental design point of view, and the claims do not match up with what was tested: </p><ul><li><p class="paragraph" style="text-align:left;">They gave the small models just the context needed to validate the vulnerabilities- the models didn’t need to search the code base, which is a core part of the problem.</p></li><li><p class="paragraph" style="text-align:left;">The prompts given were tailored to the specific vulnerabilities (not even vulnerability class) being evaluated.</p></li><li><p class="paragraph" style="text-align:left;">False positive rates weren’t discussed, nor costs if the whole code base were to be scanned.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">System Over Model: Zero-Day Discovery at the Jagged Frontier</a><br>Follow-up post by AISLE’s <a class="link" href="https://www.linkedin.com/in/stanislav-fort/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Stanislav Fort</a> in which they open sourced <a class="link" href="https://github.com/weareaisle/nano-analyzer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">nano-analyzer</a>, a deliberately simple single-file Python scanner that uses cheap models (gpt-5.4-nano at $0.20/M tokens) to brute-force scan entire codebases in parallel, detecting Anthropic&#39;s flagship Mythos FreeBSD RCE 2/3 times with models as small as 3.6B active parameters at ~100-800x lower cost than Mythos. The three-stage pipeline (context generation, vulnerability scanning, skeptical triage with grep access) found maintainer-confirmed bugs in FreeBSD&#39;s NFS RPCsec_gss subsystem and a responsibly-disclosed 26-year-old memory corruption bug. They scanned the full FreeBSD kernel (35K files, 7.5M lines) in 10 hours for under $100 in API costs. Takeaway: adequate intelligence deployed with massive parallelism can surface real zero-days without hand-scoped snippets.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/seanhn/status/2044175483500114391?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Seen Heelan</a>: “Conventionally, if you want to test if an LLM can find a bug where the root cause is a memcpy into a statically sized stack buffer, you would not put exactly that in the prompt as an example.” <a class="link" href="https://x.com/seanhn/status/2041976616708878420?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">More</a>.</p><p class="paragraph" style="text-align:left;">💡The methodology in this post overall seems much better, though I need to read it in more detail. It’s still not totally clear to me what the false positive rate was though.</p><p class="paragraph" style="text-align:left;">Overall I think it’s great that folks are analyzing what level of model intelligence + scaffolding can replicate the claims of frontier labs using nonpublic models.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/blog/2026/needles-and-haystacks-can-open-source-flagship-models-do-what-mythos-did?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Needles and haystacks: Can open-source & flagship models do what Mythos did?</a><br>Semgrep’s <a class="link" href="https://linkedin.com/in/kurt-boberg-00932664?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Kurt Boberg</a> benchmarked Claude Opus 4.6, GPT 5.4, Gemini 3.1-pro, Deepseek R1-0528, and Qwen 3.6-plus against two vulnerabilities from the Mythos blog post (OpenBSD TCP SACK and FreeBSD NFS RCE), and found that no models reliably identified vulnerabilities when analyzing full files without extremely specific hints. When scope was narrowed to individual functions, performance improved dramatically. Kurt found that using LLMs as &quot;hotspot interrogators&quot; paired with deterministic pre-filtering to surface interesting targets consistently outperformed naive whole-file prompting. Reproduction <a class="link" href="https://github.com/semgrep/mythos-bench?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">GitHub repo here</a>.</p><p class="paragraph" style="text-align:left;">💡 I like how this post emphasizes the importance of the experimental design in replicating Mythos’ findings. Yes, if you pull the needle (vulnerability) out of the haystack (large code base), small models can find it. Also, false positive rates and token costs matter. </p><p class="paragraph" style="text-align:left;">Great Venn diagram-ish visualization at the top of the experiment choices for this vs Anthropic’s vs AISLE’s analyses. The key takeaway: there is a lot to think about when measuring how good a model, tool, or product is at finding vulnerabilities.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">We Reproduced Anthropic&#39;s Mythos Findings with Public Models</a><br>Vidoc’s <a class="link" href="https://www.linkedin.com/in/dawid-moczadlo/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Dawid Moczadło</a> et al describe their attempts to reproduce Anthropic&#39;s Mythos vulnerability findings using the publicly available GPT-5.4 and Claude Opus 4.6 models in opencode. Both Opus 4.6 and GPT-5.4 reproduced Botan and FreeBSD, only Opus 4.6 reproduced OpenBSD, and both models had partial success on FFmpeg and wolfSSL. Across all of the scans, the cost to scan a single file stayed below $30.</p><p class="paragraph" style="text-align:left;">“If there is still a real gap between Mythos and public models here, it looks much more like exploit construction and operationalization than basic discovery of the underlying bug.”</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Humor</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/PVMiWhpvpqk?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Two chess grandmasters talk through the hypothetical moves they could make on this date</a></p></li><li><p class="paragraph" style="text-align:left;">Make Some Noise - <a class="link" href="https://www.youtube.com/shorts/Na7OiRayW-Q?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Swimmy Todd - The Demon Narwhal of Fleet Reef</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.technologyreview.com/2026/03/30/1134780/r3-bio-brainless-human-clones-full-body-replacement-john-schloendorn-aging-longevity/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Inside the stealthy startup that pitched brainless human clones</a> - Building clones of yourself that you can then harvest for parts. Makes sense from a scientific point of view but yikes 😬</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://12gramsofcarbon.com/p/notes-from-the-sf-peptide-scene?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Notes from the SF Peptide Scene</a> - Insane story.</p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=hHkdbr6_JJs&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">How Acquisition.com Makes Money</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/RGTQmxSKwZY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">POV: you wake up next to your family</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/Dvb4VhVxH6I?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Early test footage of Anakin’s duel with Dooku</a> - Awesome</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=IDHq-An83hI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">OZ PEARLMAN: Sundae Conversation with Caleb Pressley</a> - Impressive magic that hurts my brain 😂 </p></li><li><p class="paragraph" style="text-align:left;">Orson Scott Card - <a class="link" href="https://x.com/orsonscottcard/status/2046702294406680751?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">You don’t need advice from editors on rejected manuscripts</a> - Some stories about Ender’s Game getting rejected multiple times</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI + Product Releases, Interviews</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/codex-for-almost-everything/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Codex for (almost) everything</a> - Codex can now operate your computer, generate images, remember your preferences, learn from previous actions, and take on ongoing and repeatable work. The Codex app also now includes deeper support for developer workflows, like reviewing PRs, viewing multiple files & terminals, connecting to remote devboxes via SSH, and an in-app browser to make it faster to iterate on frontend designs, apps, and games.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/introducing-workspace-agents-in-chatgpt/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Introducing workspace agents in ChatGPT</a></p></li><li><p class="paragraph" style="text-align:left;">Alice Hunsberger - <a class="link" href="https://www.linkedin.com/posts/alicehunsberger_resources-for-upskilling-ts-and-fraud-teams-activity-7440078745572495360-y8IA/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Resources for upskilling trust and safety and fraud teams on AI</a></p></li><li><p class="paragraph" style="text-align:left;">Latent Space - <a class="link" href="https://www.youtube.com/watch?v=CeOXx-XTYek&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">Extreme Harness Engineering: 1M LOC, 1B toks/day, 0% human code or review — Ryan Lopopolo, OpenAI</a></p></li><li><p class="paragraph" style="text-align:left;">AI Engineer - <a class="link" href="https://www.youtube.com/watch?v=CS5Cmz5FssI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">How AI is changing Software Engineering: A Conversation with Gergely Orosz</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-325-dissecting-mythos-the-0-security-stack-github-action-red-team-framework" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=a7ac709f-d5c7-48ef-bea6-c80637c6cf9b&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #324 - OpenAI&#39;s GPT-5.4-Cyber, Solve by Default, GitHub Action Security</title>
  <description>OpenAI&#39;s new cyber-focused model and early access program, how to solve instead of defer tasks, securing GitHub Actions</description>
  <link>https://tldrsec.com/p/tldr-sec-324</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-324</guid>
  <pubDate>Thu, 16 Apr 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-04-16T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🎭️ Backstage Tour</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Last weekend one of the primary San Francisco theaters (the Orpheum) had an open house where you could go on the stage, backstage, everywhere. It was awesome 😍 </p><p class="paragraph" style="text-align:left;">There was a magical moment of standing on the stage, and then seeing them raise the curtain.</p><p class="paragraph" style="text-align:left;">I went downstairs backstage and saw the electronics/lighting room, stood in the pit where the orchestra plays, saw the (surprisingly small) dressing rooms with the mirrors, and more.</p><p class="paragraph" style="text-align:left;">Some fun facts I learned:</p><ul><li><p class="paragraph" style="text-align:left;">Everything you need to put on a given musical travels with the show in shipping trucks, including all of the set pieces, costumes, props, lighting, etc.</p></li><li><p class="paragraph" style="text-align:left;">For “smaller shows” that are maybe ~7-12 trucks worth, they arrive at a new venue at say 8am, the crew rapidly sets everything up, breaks for dinner at 5pm, then <i>puts on the first show</i> at 7pm <i>that night</i> 🤯 </p></li><li><p class="paragraph" style="text-align:left;">~60-80% of the behind the scenes folks are local to that theater, and they don’t know the show at all yet opening night. So there’s a handful of folks traveling with the show who are orchestrating everything so it’s set up properly.</p></li><li><p class="paragraph" style="text-align:left;">The folks on lights have ear pieces, and while they’re learning a new show they may just get guidance from the stage manager like, “OK your next cue is you’re going to pick up stage right a man in blue clothing, 50% brightness, these light settings.” But they don’t know which character it is so they’re just kinda guessing at first.</p></li><li><p class="paragraph" style="text-align:left;">Actors often change in almost pitch darkness (except for some lighting they wear around their head) so the light doesn’t bleed on to the stage.</p></li></ul><p class="paragraph" style="text-align:left;">I also saw a “quick change” demo. Sometimes actors only have a few moments to change, so they did a demo of a &lt;1 minute wardrobe change.</p><p class="paragraph" style="text-align:left;">There’s actually a ton of prep and thoughtfulness that goes into orchestrating a quick change: how the pants or dress are “pooled” on the ground so you can just step in, how the boots are positioned so they don’t catch on the clothes, how the top layers are laid down to minimize rotation and movement when putting them on, and how there can be one (or more) wardrobe people helping the actors put everything on. Whoa.</p><p class="paragraph" style="text-align:left;">Meanwhile, I put on my own clothes like a plebe.</p><p class="paragraph" style="text-align:left;">As you might suspect, cybersecurity is just my bridge career, until I get into the stable, lucrative theater or screen industries 👨‍🎤 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Secure Coding from Design to Deployment</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Secure coding starts long before production. </p><p class="paragraph" style="text-align:left;">Modern applications move fast, which means security needs to be built in from the start, not added later. From API design to input handling and access control, early decisions have a big impact on reducing risk.</p><p class="paragraph" style="text-align:left;">The <i><b>Secure Coding Best Practices Cheat Sheet</b></i> covers key areas like secure design foundations, strong authentication and authorization, input validation, and preventing common vulnerabilities such as XSS, SQL injection, and broken access control.</p><p class="paragraph" style="text-align:left;">Reduce risk early with practical secure coding and design best practices.</p><h2 class="heading" style="text-align:center;"><span style="color:#2C81E5;">👉 </span><a class="link" href="https://www.wiz.io/lp/secure-coding-best-practices-cheat-sheet?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY25Q4_INB_FORM_Secure-Coding-Best-Practices&sfcid=701Py00000HFVUjIAP&utm_term=FY27Q1-tldrsec-nl-april&utm_content=Secure-Coding-Best-Practices" target="_blank" rel="noopener noreferrer nofollow"><b>Get the Cheat Sheet</b></a><span style="color:#2C81E5;"><b> </b></span><span style="color:#2C81E5;">👈</span></h2></div><p class="paragraph" style="text-align:left;">I love me a good cheat sheet, and I like the focus on secure by design and the most common vulnerability classes 👌 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://theengineersetlist.substack.com/p/ive-completely-changed-how-i-work?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">I&#39;ve Completely Changed How I Work</a><br>Friend of the newsletter <a class="link" href="https://www.linkedin.com/in/scott-behrens-6bb8611/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Scott Behrens</a>, Principal Security Engineer at Netflix, describes how he’s adopted a &quot;solve by default&quot; mindset using AI coding agents to directly implement solutions rather than filing tickets or waiting for other teams. Scott gives an example of playing around with building a user-friendly sandbox, noticed some GoLang services he was sandboxing didn’t support proxies, so he cloned the repo, had Claude understand the codebase and conventions, built a proxy feature fix with tests and documentation, and got the PR merged in ~1 hour. This approach extends to security assessments, data analysis, and operational tasks.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;"><b>Turn meetings into tangible products</b> - Scott has an AI notetaker in meetings, which he can then use a prompt to turn that into a PRD which his agents can then start building immediately after the meeting.</p></li><li><p class="paragraph" style="text-align:left;"><b>Turn memos into implementations</b> - “When I think of defaulting to writing something down, or someone shares a strategy doc, problem statement, idea, etc., I immediately ask Claude, “Let&#39;s take the relevant part of this and turn it into an implementation.”</p></li></ul></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://theengineersetlist.substack.com/p/solve-by-default?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Solve By Default</a><br>Follow-post by <a class="link" href="https://www.linkedin.com/in/scott-behrens-6bb8611/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Scott Behrens</a> continuing his “solve by default” thread, which he defines as: “when problems emerge that you traditionally wouldn&#39;t solve (e.g., execution risks, legacy organizational red tape/paperwork, limited bandwidth), you now solve them with genAI.” Scott shares practical examples including: turning ideas from a meeting into a PRD and having the <a class="link" href="https://github.com/obra/superpowers?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Superpowers</a> brainstorming plugin help flesh it out then execute, noting and immediately fixing microcuts and nags discovered during pairing sessions, using your agent to turn Slack discussions into GitHub issues to save the ideas, and having agents optimize slow builds, painful runbooks, slow on-call processes, etc.</p><p class="paragraph" style="text-align:left;">Scott recommends seeking high-value problems by examining product briefs, incident trends, tech debt backlogs, and gaps between team charters, while avoiding low-impact work by evaluating value, scope, complexity, and leverage before committing time.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">I watched all 11 main stage keynotes</a><br><a class="link" href="https://www.linkedin.com/in/adrian-sanabria/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Adrian Sanabria</a> watched all 11 RSAC 2026 main stage keynotes (<a class="link" href="https://www.youtube.com/watch?v=Rz_lvK0hRxg&list=PLeUGLKUYzh_gVdsnw6tRhS-gbhn2BE3TU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">YouTube playlist</a>) and <span style="text-decoration:line-through;">lived to tell the tale</span> and kindly gives us an overview. People generally agreed that AI agents must be secured immediately, but no one has figured out how yet (key challenges: asset discovery, data permissions modeling, output validation, auditability of AI reasoning, compliance and the integrity problem where agents fabricate data indistinguishably from real retrieval). </p><p class="paragraph" style="text-align:left;">Speakers disagreed on fundamental architecture questions like whether agents should be ephemeral (container-like, just-in-time with minimal access) versus long-lived digital co-workers, and whether human-in-the-loop is essential or an unscalable stopgap, though most agreed detection and response must merge into a single automated step given breakout times are sometimes now measured in seconds.</p><p class="paragraph" style="text-align:left;">“If you plan on watching these keynotes, don’t base a drinking game on machine speed, agentic, real-time, or human-in-the-loop.”</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Cybercrime Just Hit Escape Velocity (Here’s the Evidence)</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Flashpoint just released its 2026 Global Threat Intelligence Report, and the data is shocking.</p><ul><li><p class="paragraph" style="text-align:left;">AI-related illicit activity surged <b>1,500%</b> in a single month</p></li><li><p class="paragraph" style="text-align:left;"><b>3.3B</b> compromised credentials are now fueling identity-based attacks</p></li><li><p class="paragraph" style="text-align:left;">Ransomware incidents increased <b>53%</b> as groups pivot toward pure-play extortion</p></li></ul><p class="paragraph" style="text-align:left;">The report also explores how threat actors are moving from generative tools to agentic AI frameworks that can automate attacks at scale.</p><h2 class="heading" style="text-align:center;"><b>👉</b><a class="link" href="https://go.flashpoint-intel.com/2026-global-threat-intelligence-report?utm_source=tldrinfosec&utm_medium=newsletter&utm_campaign=Resource_RP_GTI_2026&sfcampaign_id=701Rc00000dDaIXIA0" target="_blank" rel="noopener noreferrer nofollow"><b> View Report</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Whoa, that’s some huge growth. Also, I’m curious to learn more about how threat actors are adopting autonomous agents 😅 </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://sonraisecurity.com/blog/fighting-eventual-consistency-based-persistence-an-analysis-of-notyet?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Fighting Eventual Consistency-Based Persistence - An Analysis of notyet</a><br>Sonrai Security&#39;s <a class="link" href="https://linkedin.com/in/nigel-sood?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Nigel Sood</a> describes his red-blue collaboration with OFFENSAI’s Eduard Agavriloae on <a class="link" href="https://github.com/OffensAI/notyet?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">notyet</a> (referenced in last week’s issue), an open-source tool that exploits AWS IAM&#39;s eventual consistency propagation window to automatically maintain admin persistence by detecting and reversing containment actions within seconds. </p><p class="paragraph" style="text-align:left;">Nigel tested nearly a dozen IR techniques against <code>notyet</code> and found that standard AWS-recommended containment methods, including inline policy deletion/modification, managed policy attachments, permission boundaries, group membership changes, access key deactivation, role deletion, and SSM runbooks like AWSSupport-ContainIAMPrincipal, were all ineffective as <code>notyet</code> detected and reversed them within the consistency window. Only Service Control Policies (SCPs) successfully contained <code>notyet</code>, as member account identities cannot modify SCP attachments even with <code>*</code> permissions.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thomaspreece.com/2026/03/23/part-2-aws-codebuild-escalating-privileges-via-aws-codeconnections?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Part 2: AWS CodeBuild (Escalating Privileges via AWS CodeConnections)</a><br><a class="link" href="https://www.linkedin.com/in/thomas-preece-105824335/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Thomas Preece</a> discovered that from an unprivileged AWS CodeBuild job using CodeConnections, you can call an undocumented API to retrieve raw GitHub App tokens or BitBucket JWT App tokens with the full permissions of the installed CodeConnection App. The app generally has read, write and admin permissions on all repos under your organization. See <a class="link" href="https://github.com/thomaspreece/AWS-CodeBuild-HTTP-Intercept-Image?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">AWS-CodeBuild-HTTP-Intercept-Image</a> for a container image for CodeBuild that allows you to get network monitoring in place before CodeBuild starts your build.</p><p class="paragraph" style="text-align:left;">So basically your CodeConnection setup could mean you are one breached build job away from having every repo in your organization compromised 😅 AWS are not planning to fix this issue as they say CodeBuild is a &quot;trusted environment.&quot;</p><p class="paragraph" style="text-align:left;">💡 Great detailed write-up and walk through of examining how a third party system works internally 👍️ </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/github-actions-security-threat-model-and-defenses?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Primer on GitHub Actions Security - Threat Model, Attacks and Defenses</a><br>Wiz’s <a class="link" href="https://linkedin.com/in/shay-berkovich-0a09975?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Shay Berkovich</a> describes the GitHub Actions threat model, three main risks (Pull Request pwnage, script injection, 3rd party components), and a defensive playbook. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The post discusses 8 dangerous triggers (including <code>pull_request_target</code>), how script injection occurs when untrusted inputs like branch names or issue titles are directly embedded in bash commands without environment variable binding, and how compromised third-party actions cascade through dependency chains, like when attackers sequentially compromised four Actions to reach Coinbase.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign</a><br>Wiz’s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>, <a class="link" href="https://linkedin.com/in/hila-ramati-7003a924a?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Hila Ramati</a>, <a class="link" href="https://linkedin.com/in/scott-piper-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Scott Piper</a>, and <a class="link" href="https://www.linkedin.com/in/benjamin-read-41817121/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Benjamin Read</a> uncovered six total waves of activity from the same threat actor who was compromising GitHub repos via the <code>pull_request_target</code> workflow trigger. The attacker opened over 500 malicious PRs using AI-generated, language-aware payloads (conftest.py, package.json, build.rs, Makefile injections). Across over 450 analyzed exploit attempts, they observed a &lt;10% overall success rate due to misunderstandings of GitHub&#39;s permission model.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">“High-value targets including Sentry, OpenSearch, IPFS, NixOS, Jina AI, and recharts all successfully blocked the attack through a combination of first-time contributor approval gates, actor-restricted workflows, and path-based trigger conditions.”</p></div><p class="paragraph" style="text-align:left;">💡 What’s interesting to me here is: 1) the likely use of AI to deliver customized, language-aware payloads. AI is great at writing code, I imagine with the right harness and scaffolding you could create reliable, per-project payloads.</p><p class="paragraph" style="text-align:left;">2) 90% of the attacks failed due to misunderstanding GitHub’s permission model. In other words, unforced error. But the threat actors are rapidly iterating and improving, they won’t make this many mistakes in the future. I’m surprised they didn’t do more testing before attacking more broadly. Unless this is their small scale testing 😅 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.chainguard.dev/assemble26-announcements?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Chainguard’s Assemble 2026</a><br>Chainguard now has: Libraries (Python, JavaScript, and Java packages built from verified source), Actions (secure-by-default CI/CD workflows), hardened Agent Skills, OS Packages (30,000+ zero-CVE packages for building secure custom images), Commercial Builds (Chainguard’s hardened version of commercial software like GitLab and Elastic).</p><p class="paragraph" style="text-align:left;">💡 It’s neat to see how Chainguard took the idea of “let’s just give you 0 CVE containers so you don’t need to worry about it,” built a complex software factory to make it happen, then are now applying that concept to other domains. The product-specific posts share some interesting details about how they do it. I’m bullish on AI-powered hardening at scale, and approaches that solve classes of risks for users. Nice work.</p><p class="paragraph" style="text-align:left;"></p><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://ctid.mitre.org/fraud?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">MITRE Fight Fraud Framework</a><br><a class="link" href="https://linkedin.com/company/mitre?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">MITRE</a> has released the Fight Fraud Framework™️ (F3), a free, open knowledge base documenting tactics and techniques used by financial fraud actors based on real-world cyber fraud incidents. The framework maps fraud-specific behaviors and references applicable MITRE ATT&CK techniques where relevant, providing a common taxonomy for describing fraud incidents.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/YARAHQ/yara-rule-skill?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">YARAHQ/yara-rule-skill</a><br>By <a class="link" href="https://linkedin.com/in/floroth?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Florian Roth</a> and <a class="link" href="https://linkedin.com/in/thomas-roccia?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Thomas Roccia</a>: An LLM Agent Skill for expert YARA rule authoring, review, and optimization. Embeds industry best practices from the creator of <a class="link" href="https://github.com/YARAHQ/yara-forge?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">YARA-Forge</a> and <a class="link" href="https://github.com/Neo23x0/yaraQA?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">yaraQA</a> into your AI assistant&#39;s context. It enables natural language rule writing, review, and optimization.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://obdev.at/products/littlesnitch-linux/index.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Little Snitch for Linux</a><br>Little Snitch for Linux (<a class="link" href="https://github.com/obdev/littlesnitch-linux?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">GitHub</a>) uses eBPF to monitor and control outgoing network connections, providing a web UI that shows which applications are connecting to which servers, with support for custom rules and automatic blocklist updates. The tool can filter by process, port, and protocol, displays traffic history and data volumes, and accepts blocklists in formats like domain-per-line, <code>/etc/hosts</code>, and CIDR ranges.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.beyondtrust.com/blog/entry/claude-control-agentic-c2-computer-use-agent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Building Agentic C2 with Computer Use Agents</a><br>BeyondTrust’s <a class="link" href="https://www.linkedin.com/in/ryanhausknecht/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Ryan Hausknecht</a> describes a proof-of-concept command-and-control (C2) architecture using Claude&#39;s computer use capability, where a C# implant on the target endpoint executes AI-driven actions via Windows APIs (SetCursorPos, SendInput) or pyautogui. To avoid direct connections to Anthropic&#39;s API, Ryan used Azure Storage blobs as a dead drop for command polling and Azure Function Apps as a proxy to append API keys, ensuring all traffic appears to originate from Azure. </p><p class="paragraph" style="text-align:left;">Claude takes screenshots to determine screen resolution and element positioning, then issues click and keypress commands that flow through the function app back to the implant. This architecture keeps API keys off the endpoint and makes network traffic blend in with normal Azure communications.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/04/10/janus-listen-to-your-logs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Janus: Listen to Your Logs</a><br>SpecterOps&#39;s <a class="link" href="https://www.linkedin.com/in/gavin-kramer/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Gavin Kramer</a> introduces <a class="link" href="https://github.com/SpecterOps/Janus?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Janus</a>, an open-source tool that parses C2 logs from Mythic, Cobalt Strike, and Ghostwriter to surface operational friction like failed commands, retries, and tool failures that typically get lost in deleted logs. Janus shows your team where your tooling breaks, where operators lose time, and what you could automate next.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Janus helps them understand:</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;">Which tools should be updated vs. retired</p></li><li><p class="paragraph" style="text-align:left;">When and why tool failures occur</p></li><li><p class="paragraph" style="text-align:left;">Which techniques are being improvised due to missing capabilities</p></li><li><p class="paragraph" style="text-align:left;">What arguments caused a Beacon object file (BOF) to crash an agent</p></li><li><p class="paragraph" style="text-align:left;">What command ran before a callback stopped checking in</p></li><li><p class="paragraph" style="text-align:left;">What activity later correlated with detection or prevention</p></li></ul></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">“Janus gives leadership the data layer that has been missing, and it answers:”</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><ul><li><p class="paragraph" style="text-align:left;">How much time (and therefore cost) is lost to tool failures, retries, and operator workarounds</p></li><li><p class="paragraph" style="text-align:left;">Which parts of the engagement hold the most variability in timelines and delivery?</p></li><li><p class="paragraph" style="text-align:left;">Where are we paying an “efficiency tax” due to unreliable tooling?</p></li></ul></div><p class="paragraph" style="text-align:left;">💡 I like this meta idea a lot: collecting logs (or whatever artifact is relevant) from your and your colleagues’ work to automatically surface friction and opportunity for automation. This applies to any area of security, not just red teams. </p><p class="paragraph" style="text-align:left;">I feel like this meta idea connects to Scott’s “solve by default” posts at the top- imagine continuously gathering friction points from your security team, developers, or customers and semi-automatically and quickly resolving the paper cuts.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/scaling-trusted-access-for-cyber-defense?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Trusted access for the next era of cyber defense</a><br>OpenAI is scaling their Trusted Access for Cyber (TAC) program to thousands of verified defenders and launching GPT-5.4-Cyber, a fine-tuned variant of GPT-5.4 with reduced refusals for cybersecurity tasks and new binary reverse engineering capabilities. OpenAI is using strong Know Your Customer (KYC) and identity verification to limit advanced capabilities to trusted parties, and is giving targeted <a class="link" href="https://openai.com/index/openai-cybersecurity-grant-program/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">grants⁠</a>, contributing to <span style="text-decoration:underline;"><a class="link" href="https://www.linuxfoundation.org/press/linux-foundation-announces-12.5-million-in-grant-funding-from-leading-organizations-to-advance-open-source-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">open-source security initiatives</a></span><a class="link" href="https://www.linuxfoundation.org/press/linux-foundation-announces-12.5-million-in-grant-funding-from-leading-organizations-to-advance-open-source-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">⁠</a>, and investing in <span style="text-decoration:underline;"><a class="link" href="https://openai.com/index/codex-security-now-in-research-preview/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Codex Security</a></span><a class="link" href="https://openai.com/index/codex-security-now-in-research-preview/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">⁠</a> to help defenders more rapidly find and patch vulnerabilities. </p><p class="paragraph" style="text-align:left;">💡 Perhaps GPT-5.4-<i>Cyber</i> should have been the name for their <a class="link" href="https://techcrunch.com/2025/10/14/sam-altman-says-chatgpt-will-soon-allow-erotica-for-adult-users?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">erotica chatbot</a> 🤔 Jokes aside, it’s great to see OpenAI investing in securing the software ecosystem, supporting defenders, and releasing higher capability models carefully.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.cloudsecurityalliance.org/mythos-ciso/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program</a><br>New ~30 page Cloud Security Alliance whitepaper from <a class="link" href="https://www.linkedin.com/in/gadievron/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Gadi Evron</a>, <a class="link" href="https://www.linkedin.com/in/richmogull/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Rich Mogull</a>, <a class="link" href="https://www.linkedin.com/in/leerob/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Robert T. Lee</a>, and a huge list of other contributors authors. A briefing for security leaders on how AI-driven vulnerability discovery is reshaping the defender timeline, the operating model of vulnerability management, and the minimum actions required now. Nice overview of recent events and important things to consider for your security program. See:</p><ul><li><p class="paragraph" style="text-align:left;">p15 - 10 Questions to Understand Your Security Program State and Influence</p></li><li><p class="paragraph" style="text-align:left;">p16 - A Mythos-ready Security Program Risk Register </p></li><li><p class="paragraph" style="text-align:left;">p19 - Priority Actions for a Mythos-ready Security Program</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://apiiro.com/blog/4x-velocity-10x-vulnerabilities-ai-coding-assistants-are-shipping-more-risks?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">4x Velocity, 10x Vulnerabilities: AI Coding Assistants Are Shipping More Risks</a><br>Apiiro’s <a class="link" href="https://www.linkedin.com/in/itay-nussbaum-400976b9/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Itay Nussbaum</a> shares results from analyzing the impact of AI coding assistants across tens of thousands of repositories in Fortune 50 orgs. They found AI-assisted developers produced 3-4x more commits, but they were packaged into fewer PRs. By June 2025, AI-generated code was introducing over 10,000 new security findings per month across the repos in their study, a 10x spike in just six months compared to December 2024. </p><p class="paragraph" style="text-align:left;">Interestingly, the types of flaws introduced by AI are different, for example, privilege escalation paths jumped 322%, and architectural design flaws spiked 153% (I’d like to know more about these are defined/measured).</p><p class="paragraph" style="text-align:left;">💡 Long term I believe coding agents + security orchestration around them will make code more, not less secure, but it’s great to see some stats and investigation on the challenges we’re facing now.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Mina Le - <a class="link" href="https://www.youtube.com/watch?v=p6UdIgKw4dU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">the myth of the &quot;pilates body&quot;</a> - Interesting history around the origins of pilates, barre, Jazzercise, societal expectations, and more.</p></li><li><p class="paragraph" style="text-align:left;">Game Changer - <a class="link" href="https://www.youtube.com/shorts/SGpgHlcIDlg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Who can perform the most impressive magic trick?</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://hackread.com/fbi-recover-deleted-signal-messages-iphone-notifications?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">FBI Recovers Deleted Signal Messages Through iPhone Notifications</a> - How to protect yourself: On your iPhone, go to notification settings for Signal and set Show Previews to Never. Then open the Signal app, go to Settings &gt; Notifications &gt; Notification Content, and select No Name or Content.</p></li><li><p class="paragraph" style="text-align:left;">Dr. Mike - <a class="link" href="https://www.youtube.com/watch?v=zeA4DvEyMIk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Peptides: The Most Overhyped Trend in Fitness?</a></p></li><li><p class="paragraph" style="text-align:left;">Bryan Johnson - <a class="link" href="https://www.youtube.com/shorts/7yYcjQc4A2g?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Before you take peptides, know this</a></p></li><li><p class="paragraph" style="text-align:left;">Gabi Belle - <a class="link" href="https://www.youtube.com/watch?v=7ZWcbQys6sw&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">The Problem with Autotune on TikTok</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=gtnt84CDP-s&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Harry Potter by Balenciaga</a> - Outstanding 😂 </p></li><li><p class="paragraph" style="text-align:left;">The Primeagen - <a class="link" href="https://www.youtube.com/watch?v=alK8hgHgxd4&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">I made a music video and I&#39;m not sorry</a> - “Yacht problems” 😂 </p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">The Verge - <a class="link" href="https://www.theverge.com/ai-artificial-intelligence/911118/openai-memo-cro-ai-competition-anthropic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Read OpenAI’s latest internal memo about beating the competition — including Anthropic</a></p></li><li><p class="paragraph" style="text-align:left;">20VC with Harry Stebbings - <a class="link" href="https://www.youtube.com/watch?v=SSya123u9Yk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Demis Hassabis: Why AGI is Bigger than the Industrial Revolution & Where Are The Bottlenecks in AI</a></p></li><li><p class="paragraph" style="text-align:left;">Alex Kantrowitz - <a class="link" href="https://www.youtube.com/watch?v=J6vYvk7R190&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">OpenAI President Greg Brockman: AI Self-Improvement, The Superapp Bet, Path To AGI, Scaling Compute</a></p></li><li><p class="paragraph" style="text-align:left;">Lenny’s Podcast - <a class="link" href="https://www.youtube.com/watch?v=3UyitfSbY6c&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">How to be a CEO when AI breaks all the old playbooks | Sequoia CEO Coach Brian Halligan</a></p></li><li><p class="paragraph" style="text-align:left;">Every - <a class="link" href="https://www.youtube.com/watch?v=KRv9GpJYrUA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">How to Build an Agent-native Product | Mike Krieger</a></p></li><li><p class="paragraph" style="text-align:left;">Anthropic - <a class="link" href="https://code.claude.com/docs/en/routines?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Automate work with routines</a> - Define routines that run on a schedule, trigger on API calls, or react to GitHub events from Anthropic-managed cloud infrastructure.</p></li><li><p class="paragraph" style="text-align:left;">Google - <a class="link" href="https://blog.google/products-and-platforms/products/chrome/skills-in-chrome/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Turn your best AI prompts into one-click tools in Chrome</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.chinatalk.media/p/chinas-ai-companies-are-going-closed?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">China’s AI Companies Are Going Closed Source</a> due to funding constraints. The Chinese government continues using &quot;open source&quot; as political rhetoric in policy documents without providing the billions needed to subsidize actual open model development. The funding reality means Chinese labs can&#39;t afford to burn tens of billions on 1GW clusters like American competitors, forcing them to monetize through closed models while potentially releasing smaller open models for overseas marketing and robotics use cases.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.businesstimes.com.sg/international/global/openai-anthropic-google-unite-combat-model-copying-china?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">OpenAI, Anthropic, Google unite to combat model copying in China</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Politics</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/2k7J2dI2L_w?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Crypto currency industry </a><span style="text-decoration:line-through;"><a class="link" href="https://www.youtube.com/shorts/2k7J2dI2L_w?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">bribing</a></span><a class="link" href="https://www.youtube.com/shorts/2k7J2dI2L_w?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow"> donating to politicians</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://euromaidanpress.com/2026/04/11/ukraine-tips-drone-war-in-its-favor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Ukraine tips drone war in its favor</a> - “Starting from December, our unmanned systems units have neutralized more enemy personnel than they recruit to their ranks.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nytimes.com/2026/04/07/us/politics/trump-iran-war.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">How Trump Took the U.S. to War With Iran</a> - Israel’s Netanyahu made the hard sell. The CIA director described the Israeli prime minister’s regime change scenarios as “farcical.” Tucker Carlson warned Trump that a war with Iran would destroy his presidency. “I know you’re worried about it, but it’s going to be OK,” the president said. Mr. Carlson asked how he knew. “Because it always is.” </p><ul><li><p class="paragraph" style="text-align:left;">“Everyone deferred to the president’s instincts. They had seen him make bold decisions, take on unfathomable risks and somehow come out on top. No one would impede him now.”</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://apropos.substack.com/p/civilization-is-a-public-good?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Civilization Is Not the Default. Violence Is.</a> - On feudalism, Pax Americana and the changing world order.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://asiatimes.com/2026/04/us-ban-on-chinese-fixed-spy-cameras-led-to-a-rising-drone-threat?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">US ban on Chinese fixed spy cameras led to a rising drone threat</a> - “The rise of drone security incidents corresponds almost exactly to the US 2019 ban on Chinese cameras at American military bases.”</p></li><li><p class="paragraph" style="text-align:left;">Steve Blank - <a class="link" href="https://steveblank.com/2026/04/09/nowhere-is-safe/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">Nowhere is Safe</a> - “The U.S. has discovered that 1) air superiority and missile defense systems designed to counter tens or hundreds of aircraft and missiles is insufficient against asymmetric attacks of thousands of drones. And that 2) undefended high value fixed civilian infrastructure – oil tankers, data centers, desalination plants, oil refineries, energy nodes, factories, et al -are all at risk…the lessons from Iran’s attacks on infrastructure in the Gulf Cooperation Council countries is that anything on the surface is going to be a target.”</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-324-openai-s-gpt-5-4-cyber-solve-by-default-github-action-security" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=812f3eb6-5cca-4194-9cce-a1696f03fb33&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #323 - Anthropic Mythos, Security Program Politics, Vulnerability Research is Cooked</title>
  <description>New model finds thousands of 0-days and writes exploits, lessons and how to be influential from decades of being a CISO, why LLMs will democratize elite vuln hunting</description>
  <link>https://tldrsec.com/p/tldr-sec-323</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-323</guid>
  <pubDate>Thu, 09 Apr 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-04-09T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🏫 High School Reflections</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">As you might guess from the fact that I write a cybersecurity newsletter, I was pretty cool in high school.</p><p class="paragraph" style="text-align:left;">This week I randomly came across this YouTube video <a class="link" href="https://www.youtube.com/watch?v=w_JYhUEPX54&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Learn to Solve an Integral (What Makes You Beautiful Parody)</a>, and it took me back.</p><p class="paragraph" style="text-align:left;">I remember algebra and calculus being really fun, I would have loved to make a song like this.</p><p class="paragraph" style="text-align:left;">I remember being in marching band, playing during football games. The drum line had this one riff where whenever they started playing it the band and the entire student body would start moshing. At one point they got banned from playing it because it made people too rowdy 😂 </p><p class="paragraph" style="text-align:left;">(“One time, at…”) Band camp before the school year started was a blast, we always had these epic Halo tournaments. 8 vs 8 CTF, four TVs, two in each room. Mountain Dew and smack talking galore. </p><p class="paragraph" style="text-align:left;">I took two programming classes, Visual Basic and Java, but I actually didn’t like them, and I didn’t really “get it.” It might not have helped that neither teacher really knew how to program (one was a football coach 🤷). Kind of ironic given what I do now.</p><p class="paragraph" style="text-align:left;">I wish I journaled more, it’d be fun to look back on.</p><p class="paragraph" style="text-align:left;">I wonder how your childhood and high school formed who you are today 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><b>P.S.</b> My friend and former colleague <a class="link" href="https://www.linkedin.com/in/peter-greko-850a859/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Peter Greko</a> is open to new opportunities. He worked on the AI red team at Microsoft, and most recently Block. </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;"><b> </b><b>Register for a brand new research-focused webinar series from Push Security</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Join Push Security threat researchers along with incredible guests like John Hammond, Troy Hunt, and Matt Johansen in a brand new webinar series deep-diving into the State of Browser Attacks.</p><p class="paragraph" style="text-align:left;">The browser is the place where modern breaches happen, powered by a huge amount of attacker innovation — countless ClickFix variants, new malvertised phishing campaigns intercepting users on search engines, and device code phishing attacks being powered by brand new PhaaS kits and AI tools. And we’re only in April. </p><p class="paragraph" style="text-align:left;">Get ahead of this threat evolution and register your spot now!</p><h2 class="heading" style="text-align:center;"><b>👉 </b><b><a class="link" href="https://hubs.li/Q04944Px0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Register here</a></b><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Push Security consistently has solid security research content, this series is going to be good. And John Hammond and Matt Johansen are both great and good friends 👍️ </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://semgrep.dev/resources/remediation-at-scale-ungated/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Remediation at Scale: What High-Performing AppSec Teams Do Differently</a><br>My colleagues at Semgrep did some interesting data crunching across 50k+ repos across 400+ organizations, analyzing stats on fix rate and mean time to remediation across SAST, SCA, and severity level, if certain vulnerability classes are harder to remediate, if catching vulnerabilities earlier improves remediation rates, and more.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/salesforce/url-content-auditor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">salesforce/url-content-auditor</a><br>A security auditing tool designed to detect sensitive data exposure in publicly accessible web content. It systematically scans, extracts, and audits images, PDFs, and video files using AI-powered analysis (Google Gemini API) to identify potential data leaks, compliance violations, and privacy risks.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.praetorian.com/blog/vespasian-api-endpoint-discovery-tool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Meet Vespasian. It Sees What Static Analysis Can’t.</a><br>Praetorian&#39;s <a class="link" href="https://www.linkedin.com/in/blaynedreier/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Blayne Dreier</a>, <a class="link" href="https://www.linkedin.com/in/nathansportsman/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Nathan Sportsman</a> et al release <a class="link" href="https://github.com/praetorian-inc/vespasian?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Vespasian</a>, an open-source tool that generates API specifications (OpenAPI 3.0, GraphQL SDL, WSDL) by observing real HTTP traffic from headless browser crawls (powered by Katana) or importing existing captures from Burp Suite, HAR files, or mitmproxy. The tool uses a two-stage pipeline: first capturing traffic with full JavaScript execution to catch dynamically-constructed API calls that static analysis misses (or import traffic), then classifying requests using confidence-based heuristics, deduplicating endpoints via path normalization, and probing for metadata through OPTIONS requests, GraphQL introspection, and WSDL fetching.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.philvenables.com/post/organizational-politics-the-security-program?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Organizational Politics & The Security Program</a><br><a class="link" href="https://linkedin.com/in/philvenables?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Phil Venables</a> describes how organizational politics are a necessary skill for security leaders, arguing it&#39;s the application of influence to achieve outcomes, not something inherently negative. Phil shares lessons from decades as a CISO and Chief Risk Officer, including: decisions are pre-ordained outside formal meetings through advance consensus-building, you should embed security into existing business processes and budgets rather than creating separate initiatives, and building broad support across the organization (not just relying on your boss) is critical for program longevity. </p><p class="paragraph" style="text-align:left;">Some key tactics: leveraging the Risk = Hazard + Outrage equation to prioritize work, using Force Field Analysis to understand what&#39;s preventing change, and connecting disparate teams across the organization to build political capital beyond just security outcomes.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">“<span style="color:rgb(29, 29, 31);">If you’re going into a meeting or committee and you don’t already feel confident on the outcome then you’ve missed the point and will have likely not done the work to line up support for the outcome you want. Remember, committees are the </span><span style="color:rgb(29, 29, 31);"><i>roots of power structures</i></span><span style="color:rgb(29, 29, 31);"> not the structure themselves.”</span></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:rgb(29, 29, 31);">“Many of the security programs I’ve run also drove improvements in reliability, development agility, product features, and more. These came from observations of issues in the security processes that we could have ignored as being outside of our lane, but we decided to press and got support in doing so.”</span></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:rgb(29, 29, 31);">“Remember, published organization charts almost never actually represent the true organization structure in terms of influence. That has to be discovered by you.”</span></p></div><p class="paragraph" style="text-align:left;">💡 So many good insights, as you’d expect from a Phil Venables post 🤯 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<span style="color:rgb(0, 1, 0);"><b> Axios. Trivy. LiteLLM. More are coming.  Root stops compromised dependencies.</b></span></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Recent software supply chain attacks just rewrote the playbook. Here&#39;s the kicker: they won&#39;t have a CVE and they won&#39;t be triggered by a scanner. These attacks exploit the one thing every pipeline trusts blindly: upstream dependencies. Compromised maintainers, hijacked registries, silent tag overwrites. By the time you notice, you&#39;ve already built and shipped it. The only fix is controlling what enters your environment. Root pins every dependency to verified, known-good versions and backports security patches without forced upgrades so you stay secure without breaking your build.</p><h2 class="heading" style="text-align:center;"><span style="color:#2C81E5;"><b>👉 </b></span><span style="color:#2C81E5;"><a class="link" href="https://www.root.io/teampcp?utm_campaign=41922123-April%202026%20-%20tldr%20sec%20newsletter%20placement%201&utm_source=tldrsec&utm_medium=newsletter" target="_blank" rel="noopener noreferrer nofollow">Fix your supply chain</a></span><span style="color:#2C81E5;"><b> 👈</b></span></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Pinning dependencies to known-good versions would prevent so many recent supply chain attacks, and I could see backported security patches saving weeks to months of dev time, depending on the company. Neat 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/gabrielPav/aws-preflight?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">gabrielPav/aws-preflight</a><br>By <a class="link" href="https://www.linkedin.com/in/gabrielpavell/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Gabriel Pavel</a>: A security linter for AWS CLI commands that catches misconfigurations before execution, featuring 703 checks across 91 AWS services. The tool analyzes commands for issues like missing IMDSv2 enforcement, unencrypted storage, public accessibility, overly permissive IAM policies, and disabled logging.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.offensai.com/blog/notyet-aws-iam-credential-revocation-gaps?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">notyet: Open-Source Tool to Test AWS IAM Credential Revocation Gaps</a><br>OFFENSAI&#39;s <a class="link" href="https://linkedin.com/in/eduard-k-agavriloae?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Eduard Agavriloae</a> has released <a class="link" href="https://github.com/OffensAI/notyet?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">notyet</a>, an open-source tool that exploits AWS IAM&#39;s eventual consistency (the ~4 second propagation window where disabled or deleted credentials remain valid) by continuously monitoring for defender actions (key deletion, policy detachment, role removal) and automatically responding with credential rotation, role assumption, policy persistence, and defensive action stripping. Notyet can help IR teams test whether their containment playbooks work against automated adversaries.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://sonraisecurity.com/enforcing-ai-governance-across-aws-orgs?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Enforcing AI Governance Across AWS Organizations</a><br><a class="link" href="https://linkedin.com/company/sonrai-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Sonrai Security</a> describes how to enforce AI governance across AWS Organizations using Service Control Policies (SCPs) and Bedrock Policies to centrally manage AI service access. The post provides examples for: preventing access to the AWS control plane through AWS’s managed MCP servers, org-wide Bedrock policies for blocking prompt injection attacks, disabling specific AI services like Bedrock AgentCore, controlling model family availability, and preventing long-term Bedrock API key creation/use.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/elastic/supply-chain-monitor?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">elastic/supply-chain-monitor</a><br>By <a class="link" href="https://linkedin.com/company/elastic-co?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Elastic</a>: Automated monitoring of the top PyPI and npm packages for supply chain compromise. Polls both registries for new releases, diffs each release against its predecessor, and uses an LLM (via Cursor Agent CLI) to classify diffs as benign or malicious.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/lirantal/npm-security-best-practices?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">lirantal/npm-security-best-practices</a><br>By <a class="link" href="https://www.linkedin.com/in/talliran/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Liran Tal</a>: A curated and practical list of security best practice for using npm packages. Safe-by-default npm package manager command-line options, hardening against supply chain attacks, deterministic and secure dependency resolution, etc.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.chainguard.dev/unchained/driftlessaf-introducing-chainguard-factory-2-0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">DriftlessAF: Introducing Chainguard Factory 2.0</a><br>Chainguard’s <a class="link" href="https://twitter.com/mattomata?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Matt Moore</a>, <a class="link" href="https://www.linkedin.com/in/manfredmoser/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Manfred Moser</a>, and <a class="link" href="https://www.linkedin.com/in/mgreau/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Maxime Greau</a> announce DriftlessAF (<a class="link" href="https://github.com/driftlessaf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">GitHub</a>), an agentic reconciliation framework that replaced their event-driven Factory 1.0 architecture. DriftlessAF uses AI-powered reconciler bots in a Kubernetes-style reconciliation loop to continuously compare desired state (zero CVEs, latest packages) against actual state across 2,000+ containers and hundreds of thousands of package versions, by reasoning about unstructured data and creating self-healing workflows that can safely discard failed work items. </p><p class="paragraph" style="text-align:left;">The framework includes Terraform modules for event-driven reconciliation infrastructure, a multi-regional work queue, and Go packages for GitHub repository, OCI container, and APK package reconciliation. Engineers now review AI-generated pull requests and package updates instead of creating them manually, while the system autonomously manages hundreds of thousands of package versions and CVE patch backports.</p><p class="paragraph" style="text-align:left;">💡 This seems like some impressive engineering, and cool that they open sourced it! I think we’ll see more of this going forward, with agents autonomously building and mending software. See OpenAI’s <a class="link" href="https://openai.com/index/harness-engineering/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Harness Engineering</a> blog or Simon Willison’s <a class="link" href="https://simonwillison.net/guides/agentic-engineering-patterns/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Agentic Engineering Patterns</a> for more.</p><p class="paragraph" style="text-align:left;"></p></div><div id="ai-security" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/step-security/dev-machine-guard?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">step-security/dev-machine-guard</a> - Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://delinea.com/resources/ai-and-identity-security-report-pdf?utm_medium=paid-newsletter&utm_source=influencer-clint-gibler&utm_campaign=br-brand-fy26-influencer-activity&utm_content=260409&utm_term=" target="_blank" rel="noopener noreferrer nofollow"><b>Is Your Identity Security Keeping Up with AI? | Delinea 2026 Report</b></a><b> </b><span style="color:#222222;">- </span><span style="color:#222222;">87% of organizations say they’re ready for AI—but nearly 50% admit they can’t fully track AI and non-human identities accessing critical systems. That gap creates unmanaged access and standing privileges. Read Delinea’s 2026 Identity Security Report to learn more.*</span></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/knostic/AgentSonar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">knostic/AgentSonar</a> - Detect shadow AI agents by monitoring network traffic and classifying process-to-domain pairs.</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Vulnpocalypse: AI, Open Source, and the Race to Remediate</a><br>Nice post by my bud <a class="link" href="https://www.linkedin.com/in/resilientcyber/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Chris Hughes</a> synthesizing a number of stats, posts, related work, and his interviews on AI finding vulnerabilities, time to exploitation, patching challenges, etc.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://devansh.bearblog.dev/on-llms-and-vuln-research?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">On LLMs and Vulnerability Research</a><br><a class="link" href="https://www.linkedin.com/in/devansh-batham/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Devansh Batham</a> gives a number of arguments refuting that LLMs can’t understand code or find meaningful vulnerabilities, and I think makes an interesting case that LLMs + coding harnesses will likely be able to find “novel” or “creative” new vulnerability classes, as these classes are really just combinations of known primitives. </p><p class="paragraph" style="text-align:left;">For example, HTTP request smuggling is really: ambiguous protocol specification + inconsistent parsing between components + a security-critical assumption about message boundaries. And prototype pollution RCEs in JavaScript frameworks: injection + type confusion + privilege boundary crossing. This novel composition of primitives is what LLMs are increasingly good at. “Most of what we call novel vulnerability research is creative recombination within a known search space.”</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Vulnerability Research Is Cooked</a><br>Excellent post by <a class="link" href="https://x.com/tqbf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Thomas Ptacek</a> on the history of vulnerability research, and how LLMs are uniquely suited for finding and exploiting vulnerabilities because they already encode vast correlations across source code, understand all documented bug classes (stale pointers, type confusion, allocator grooming), and excel at the pattern-matching and constraint-solving required to chain subtle framework details into exploits.</p><p class="paragraph" style="text-align:left;">Thomas argues that this capability will democratize elite exploit development beyond high-value targets like Chrome to everything from databases to printers, overwhelming open source maintainers with verified high severity reports, making closed-source protection irrelevant (agents can reason directly from assembly), and potentially triggering bad AI security regulations that fail to recognize asymmetric costs on defenders.</p><p class="paragraph" style="text-align:left;">“We’ve been shielded from exploits not only by soundly engineered countermeasures but also by a scarcity of elite attention.”</p><p class="paragraph" style="text-align:left;">“Like many useful observations in CS, the Bitter Lesson is fractally true. It’s about to hit software security like a brick to the face.”</p><p class="paragraph" style="text-align:left;">See also their <a class="link" href="https://securitycryptographywhatever.com/2026/03/25/ai-bug-finding/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">podcast with Nicolas Carlini</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/glasswing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: Securing critical software for the AI era</a><br>Anthropic announces Project Glasswing, a collaboration with AWS, Apple, Google, Microsoft, NVIDIA, and others to use Claude Mythos Preview—an unreleased frontier model that has already discovered thousands of high-severity vulnerabilities across major operating systems and web browsers—for defensive security purposes.</p><p class="paragraph" style="text-align:left;">Anthropic is providing access to 40+ organizations building critical infrastructure along with $100M in usage credits and $4M in direct donations to open-source security organizations. Launch partners include CrowdStrike, Palo Alto Networks, and Cisco. They’ve also donated $2.5M to Alpha-Omega and OpenSSF through the Linux Foundation, and $1.5M to the Apache Software Foundation.</p><p class="paragraph" style="text-align:left;">💡It’s great that Anthropic is gathering a group of partner companies to collaborate with on this, and I appreciate the sizable investment in helping secure the software ecosystem more broadly ($100M in usage credits is no joke). </p><p class="paragraph" style="text-align:left;">Prediction: models from multiple labs are going to keep getting better, and specifically better at cybersecurity, but those will mostly <i>not</i> be available except to trusted parties due to the risk of abuse. I’m glad that folks take this risk seriously.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://red.anthropic.com/2026/mythos-preview/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Assessing Claude Mythos Preview’s cybersecurity capabilities</a><br>Anthropic’s Nicholas Carlini et al discuss Mythos Preview’s capabilities in finding and exploiting zero-days in open source software, and its ability to reverse engineer exploits on closed-source software, turning N-day (known but not yet widely patched) vulnerabilities into exploits. “Over 99% of the vulnerabilities we’ve found have not yet been patched.”</p><p class="paragraph" style="text-align:left;">“In one case, Mythos Preview wrote a web browser exploit that chained together four vulnerabilities, writing a complex JIT heap spray that escaped both renderer and OS sandboxes. It autonomously obtained local privilege escalation exploits on Linux and other operating systems by exploiting subtle race conditions and KASLR-bypasses. And it autonomously wrote a remote code execution exploit on FreeBSD’s NFS server that granted full root access to unauthenticated users by splitting a 20-gadget ROP chain over multiple packets.”</p><p class="paragraph" style="text-align:left;">“We did not explicitly train Mythos Preview to have these capabilities. Rather, they emerged as a downstream consequence of general improvements in code, reasoning, and autonomy.”&quot;</p><p class="paragraph" style="text-align:left;"><b>Methodology</b>:</p><ol start="1"><li><p class="paragraph" style="text-align:left;">They launched a container (isolated from the Internet and other systems) that runs the project-under-test and its source code.</p></li><li><p class="paragraph" style="text-align:left;">They invoke Claude Code with Mythos Preview and prompt it to find bugs, and produce a proof-of-concept exploit and reproduction steps if found. </p></li><li><p class="paragraph" style="text-align:left;">To encourage Claude to focus on different parts of the code base, they first have Claude rank each file in the project from 1-5 on how likely it is to have bugs.</p></li><li><p class="paragraph" style="text-align:left;">They then invoke many copies of Claude in parallel, tasking each run focus on one of the most interesting files.</p></li><li><p class="paragraph" style="text-align:left;">Finally they ask Mythos to triage findings from prior steps.</p></li></ol></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The most critical bug they found in OpenBSD, after a thousand runs of their scaffold, cost ~$20,000 total, and found several dozen more findings.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">“In 89% of the 198 manually reviewed vulnerability reports, our expert contractors agreed with Claude’s severity assessment exactly, and 98% of the assessments were within one severity level. If these results hold consistently for our remaining findings, we would have over a thousand more critical severity vulnerabilities and thousands more high severity vulnerabilities.”</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">“For multiple different web browsers, Mythos Preview fully autonomously discovered the necessary read and write primitives, and then chained them together to form a JIT heap spray.”</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">“We’ve used these capabilities to find vulnerabilities and exploits in closed-source browsers and operating systems. We have been able to use it to find, for example, remote DoS attacks that could remotely take down servers, firmware vulnerabilities that let us root smartphones, and local privilege escalation exploit chains on desktop operating systems.”</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Regarding <b>N-days</b>: “We began by providing Mythos Preview a list of 100 CVEs and known memory corruption vulnerabilities that were filed in 2024 and 2025 against the Linux kernel. We asked the model to filter these down to a list of potentially exploitable vulnerabilities, of which it selected 40. Then, for each of these, we asked Mythos Preview to write a privilege escalation exploit that made use of the vulnerability (along with others if chaining vulnerabilities would be necessary). More than half of these attempts succeeded.”</p></div><p class="paragraph" style="text-align:left;">See also:</p><ul><li><p class="paragraph" style="text-align:left;">AI Explained’s video: <a class="link" href="https://www.youtube.com/watch?v=txx6ec6MLNY&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Claude Mythos: Highlights from 244-page Release</a>. </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/heidy-khlaaf/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Heidy Khlaaf</a> also <a class="link" href="https://www.linkedin.com/posts/heidy-khlaaf_as-someone-who-has-audited-dozens-of-safety-critical-activity-7447720977549037568-jilU/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">weighs in</a>, specifically around how Project Glasswing and Mythos are not compared against existing tools, do not discuss false positive rates, and the amount of human evaluation (e.g. in triage) is not detailed.</p></li><li><p class="paragraph" style="text-align:left;">Sean Heelan takes <a class="link" href="https://x.com/seanhn/status/2041950179817841009?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/seanhn/status/2041882705017598401?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">here</a>, Tavis Ormandy <a class="link" href="https://x.com/taviso/status/2039118897891410017?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">here</a>, and Alex Matrosov on the market <a class="link" href="https://x.com/matrosov/status/2041971401050272177?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">underrating the gap</a> between finding bugs and actually proving exploitability.</p></li></ul><p class="paragraph" style="text-align:left;">💡 This was a great, detailed write-up. The hashes as proof of unfixed vulnerabilities and exploits makes sense, I like it. It’d be nice to know a bit more about model costs, false positive rates, and the level (and cost) of human involvement, but overall a pretty good amount of detail.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/disgruntled-researcher-leaks-bluehammer-windows-zero-day-exploit/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit</a> - A researcher released the PoC for an unpatched Windows privilege escalation bug because they were unhappy with MSRC’s disclosure process.</p></li><li><p class="paragraph" style="text-align:left;">Nick Collins - <a class="link" href="https://composerprogrammer.com/introductiontocomputermusic.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Introduction to Computer Music</a> - Free ~350 page book.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/opp97ZTdm_M?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Why Charlie Puth hears music differently</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://contrapunk.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Contrapunk</a> - Real-time MIDI harmony generator and guitar-to-MIDI converter.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://middle-earth-interactive-map.web.app/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">An interactive map of Tolkien’s Middle Earth</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://playlists.at/youtube/search/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Advanced Search for YouTube</a> - Filters like exact terms, exclude terms, title includes, video length, date before/after.</p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=yb2cLMMuMdQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">How to make progress faster than everyone</a> - On being cringe, trying hard, and not comparing your first chapter to someone’s 20th.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/voldemortensen/snark-driven-development?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">voldemortensen/snark-driven-development</a> - A Claude Code skill that wraps development workflows with sharp, substance-backed snarky commentary</p></li><li><p class="paragraph" style="text-align:left;">GitHub issue: <a class="link" href="https://github.com/anthropics/claude-code/issues/42796?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Claude Code is unusable for complex engineering tasks with the Feb updates</a></p></li><li><p class="paragraph" style="text-align:left;">Lenny’s Podcast - <a class="link" href="https://www.youtube.com/watch?v=k-H4nsOTuxU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">How Anthropic added $11B in ARR in one month | Amol Avasare (Head of Growth, Anthropic)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.complex.com/pop-culture/a/samantha-giambra-plaisance/robot-slaps-boy-china?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">Humanoid Robot Accidentally Slaps Boy During Public Demo in China</a> - After reportedly saying, “You best watch yo’ mouth son!”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.complex.com/pop-culture/a/layla-ahmad/what-is-rizzbot-meet-the-viral-disrespectful-robot-rizzing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">What is Rizzbot? Meet the AI Robot Rizzing Up Your Girl</a> - Not gonna life, some of these <a class="link" href="https://www.tiktok.com/@rizzbot_official/video/7608271048538098974?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">videos</a> are pretty hilarious</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-323-anthropic-mythos-security-program-politics-vulnerability-research-is-cooked" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=e3eac2ab-445a-4010-af0b-49abb429705c&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #322 - GitHub&#39;s Supply Chain Roadmap, Scaling Vulnerability Management with AI, Finding Vulnerabilities Across Repos</title>
  <description>GitHub&#39;s plan to harden GitHub Actions and supply chain security, automating and scaling SAST and SCA vuln management, OSS tool that uses AI agents to reason about vulns across repos</description>
  <link>https://tldrsec.com/p/tldr-sec-322</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-322</guid>
  <pubDate>Thu, 02 Apr 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-04-02T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🫶 Long Career, Long Friendships</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">This week I was reflecting a bit after BSidesSF and RSAC about how careers are long.</p><p class="paragraph" style="text-align:left;">I remember attending conferences when I first started in security and being intimidated by how it was crowded and full of strangers.</p><p class="paragraph" style="text-align:left;">This year, there were still many <span style="text-decoration:line-through;">strangers</span> not yet friends, but now I got to catch up with many former colleagues and friends I’ve known for years. Some for a decade 👴 </p><p class="paragraph" style="text-align:left;">It feels nice knowing we’re all working together in our own ways, at different companies, to make the world a little bit safer.</p><p class="paragraph" style="text-align:left;">Also, just wanted to share a few thoughts:</p><ul><li><p class="paragraph" style="text-align:left;">It’s OK if you don’t know people at an event or conference. 98% of the time if you go up and chat with a stranger it goes great, or at least fine. </p><ul><li><p class="paragraph" style="text-align:left;">When I’m nervous at events, I like to think about how, just by both of us being at a security event, I have a <i>vast</i> amount of shared experience and context with anyone there.</p></li></ul></li><li><p class="paragraph" style="text-align:left;">If every event you just meet a handful of people, that’s going to compound event on event, year on year. Soon you’ll likely know at least a few people at most events.</p></li></ul><p class="paragraph" style="text-align:left;">Anywho, if you attended, I hope you had a great time and made some friends, and didn’t just repeat “AI” until a VC materialized and dumped money on you.</p><p class="paragraph" style="text-align:left;"><b>P.S.</b> Dan Guido kindly turned his [un]prompted talk into a <i>tl;dr sec</i> guest post. It’s excellent, highly recommend.<br>👉️ <a class="link" href="https://tldrsec.com/p/how-we-made-trail-of-bits-ai-native-so-far?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">How we made Trail of Bits AI-native (so far)</a> 👈️ </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Free tool: instant visibility into your Claude Desktop deployment</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Employees aren&#39;t waiting for approval. Claude Desktop is getting deployed with MCP servers, OAuth connectors, CoWork scheduled tasks, and browser-control extensions your security team never reviewed.</p><p class="paragraph" style="text-align:left;">Our Head of Security, Ed Merrett, built a lightweight, read-only audit tool to give you instant visibility. One command surfaces everything: installed extensions and whether they&#39;re signed, MCP server configs, dangling env variables, OAuth tokens, scheduled tasks, org-deployed plugins, and runtime state.</p><p class="paragraph" style="text-align:left;">p.s. If you’re looking for more help with securing the Claude ecosystem, visit <a class="link" href="https://harmonic.security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">harmonic.security</a> to check out our other free resources!</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://github.com/HarmonicSecurity/claudit-sec?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Audit your Claude setup</a> <b>👈</b></h2></div><p class="paragraph" style="text-align:left;">This is great! A free GitHub repo tool that gives you visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions. Love it 👌 </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/portswigger/ip-rotate?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">portswigger/ip-rotate</a><br>By <a class="link" href="https://linkedin.com/company/portswigger?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Portswigger</a>: An extension for Burp Suite that uses AWS API Gateway to rotate your IP on every request, helping bypass IP-based rate limiting, bruteforce protections, and WAF blocks.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://bughunters.google.com/blog/passkeys-are-your-new-best-friend?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Passkeys are Your New Best Friend</a><br>Google&#39;s <a class="link" href="https://linkedin.com/in/harshlal028?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Harsh Lal</a> explains how passkeys use asymmetric cryptography to replace passwords, where a private key stored on your device signs authentication challenges while the public key on the server verifies them, making them phishing-resistant through domain binding and useless if servers are breached. Nice brief overview of why passkeys are safer than passwords, signing in across devices, FAQ of security concerns, and risks: sync account hijacking (mitigated by requiring the old device&#39;s screen lock) and social engineering attacks requiring physical proximity</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.blog/security/supply-chain-security/a-year-of-open-source-vulnerability-trends-cves-advisories-and-malware?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">A year of open source vulnerability trends: CVEs, advisories, and malware</a><br>GitHub&#39;s <a class="link" href="https://www.linkedin.com/in/jonathan-evans-240b9321/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Jonathan Evans</a> analyzes the 4,101 reviewed advisories GitHub published in 2025, the fewest since 2021, but this reflects a reduction in backfilling older vulnerabilities rather than fewer new discoveries- newly reported vulnerabilities actually increased 19% year-over-year. The data shows cross-site scripting remains the top vulnerability type; resource exhaustion, unsafe deserialization, and SSRF saw significant increases. Advisories without any CWE dropped 85% due to improved tagging. GitHub&#39;s malware advisory publications surged 69% to 7,197 (driven by campaigns like SHA1-Hulud). The GitHub CNA published 35% more CVE records (2,903 total) with 679 new organizations requesting CVE IDs. “We saw 10 to 16% growth every quarter. If this trend continues, GitHub will publish over 50% more CVEs in 2026.”</p><p class="paragraph" style="text-align:left;">💡 Frontier models are getting so much better at finding vulnerabilities + much more code is being written → 2026 is for sure going to be a record breaking year for CVEs, the only question is by how much. People are (in my opinion, correctly) talking about an upcoming “vulnpocalypse.&quot; 😅 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Webinar: Executive Impersonation and Modern Phishing Tactics</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Executive impersonation attacks pressure employees with urgency, authority, and high-stakes requests. Because they rely on social engineering instead of obvious malware, they often slip past traditional email defenses. Join Sublime Security for a live webinar on April 8 to break down how these attacks work, review real-world patterns, and learn practical ways security teams can detect and stop impersonation attempts earlier.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://sublime.security/events/executive-impersonation-in-finance/?utm_source=tldrsec&utm_medium=third-party" target="_blank" rel="noopener noreferrer nofollow"><b>Register</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/andrewbecherer/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Andrew Becherer</a> is a sharp dude, and gave an <i>excellent</i> talk at the Decibel event Daniel Miessler and I co-hosted during RSA. He definitely has perspective worth listening to.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.praetorian.com/blog/aurelian-cloud-security-tool?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Reunifying the Cloud: Introducing Aurelian for Multi-Cloud Security Testing</a><br>Praetorian&#39;s <a class="link" href="https://www.linkedin.com/in/aarushi-dwivedi/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Aarushi Dwivedi</a> et al have released <a class="link" href="https://github.com/praetorian-inc/aurelian?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Aurelian</a>, an open-source Go-based multi-cloud security framework that unifies reconnaissance, secrets discovery, and IAM analysis across AWS, Azure, and GCP. Aurelian evaluates resource policies using real IAM policy evaluation logic (not just flag checks), integrates with Titus for secrets scanning with live credential validation via API calls, and maps privilege escalation paths to Neo4j for Cypher-based querying of multi-hop attack chains.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.plerion.com/blog/dont-expose-yourself-in-public-let-aws-error-messages-do-it?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Don’t expose yourself in public - let AWS error messages do it for you</a><br>Plerion’s <a class="link" href="https://linkedin.com/in/danielgrzelak?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Daniel Grzelak</a> describes how AWS recently rolled out friendly IAM error messages that inadvertently created a simple oracle for detecting publicly exposed resources: assume a role with a deny-all session policy, make a request, and if the error says &quot;explicit deny in a session policy,&quot; the resource policy would have allowed it, confirming public exposure.</p><p class="paragraph" style="text-align:left;">💡 The contents of my friend Daniel&#39;s posts have great security advice, and the titles have good life advice.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://ramimac.me/teampcp/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">TeamPCP Supply Chain Campaign</a><br>Nice round-up landing page by <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://opensourcemalware.com/blog/teampcp-supply-chain-campaign?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">TeamPCP Supply Chain Campaign: A March 2026 Retrospective</a><br>Great overview by OpenSourceMalware’s <a class="link" href="http://www.linkedin.com/in/jenngile/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Jenn Gile</a> on how TeamPCP executed a cascading multi-phase supply chain attack in March 2026, leveraging a single unrevoked credential stolen from Trivy&#39;s CI pipeline to compromise several ecosystems (Aqua Security, npm, LiteLLM/PyPI, Checkmarx, and Telnyx), harvesting CI/CD secrets at each stage to fund the next, while also deploying a geotargeted filesystem wiper against Iranian infrastructure.</p><p class="paragraph" style="text-align:left;">💡 I met Jenn at the tl;dr sec community event before BSidesSF, she seems super sharp and nice 🙂 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://socket.dev/blog/axios-npm-package-compromised?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Supply Chain Attack on Axios Pulls Malicious Dependency from npm</a><br>Socket describes a supply chain attack that compromised Axios, one of the most widely used HTTP clients in the JavaScript ecosystem (~100M weekly downloads), by injecting the malicious dependency plain-crypto-js@4.2.1, which was published minutes before the poisoned Axios releases. The release appeared outside the normal Axios workflow, only two malicious versions were published, and only one line was added to package.json (the malicious dependency)- small, targeted changes being less likely to raise suspicion.</p><p class="paragraph" style="text-align:left;">💡 *Takes a long drag from my cigarette* Another day, another NPM compromise.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.vaines.org/posts/2026-03-24-the-comforting-lie-of-sha-pinning?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">The Comforting Lie Of SHA Pinning</a><br><a class="link" href="https://www.linkedin.com/in/aidenvaines/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Aiden Vaines</a> describes a subtlety of how GitHub scopes SHA hash references when you’re trying to pin a GitHub Action to a commit SHA. Basically, if you have a repo using the GitHub Action <code>avaines/gh_action@&lt;SHA&gt;</code> , and an attacker forks that action, adds malicious code, and submits a PR to the target repo that only changes the Action’s SHA reference, it will look like <code>avaines/gh_action@&lt;BAD_SHA&gt;</code> (same owner/repo name, only the SHA has changed, despite this version coming from a different GitHub user). “The result is that a pull request can replace a pinned, trusted action with attacker-controlled code without changing the apparent repository reference.”</p><p class="paragraph" style="text-align:left;">Chainguard’s <a class="link" href="https://www.linkedin.com/in/wflynch/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Billy Lynch</a> wrote about this in 2023: <a class="link" href="https://www.chainguard.dev/unchained/what-the-fork-imposter-commits-in-github-actions-and-ci-cd?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">What the fork? Imposter commits in GitHub Actions and CI/CD</a>. Great write-up.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.blog/security/supply-chain-security/securing-the-open-source-supply-chain-across-github?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Securing the open source supply chain across GitHub</a><br>GitHub&#39;s <a class="link" href="https://linkedin.com/in/steiza?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Zachary Steindler</a> discusses prevention steps you can take today, plus a look at the security capabilities GitHub is working on. He recommends enabling CodeQL to scan Actions workflows for security issues, avoiding <code>pull_request_target</code> triggers, pinning third-party Actions to full commit SHAs, and using OpenID Connect tokens with trusted publishing instead of secrets. GitHub scans all 30,000+ daily npm package publishes for malware and is accelerating their Actions security roadmap in response to attacks like Shai-Hulud, while working with OpenSSF to expand trusted publishing support across npm, PyPI, NuGet, RubyGems, and Crates.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.blog/news-insights/product-news/whats-coming-to-our-github-actions-2026-security-roadmap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">What&#39;s coming to our GitHub Actions 2026 security roadmap</a><br>GitHub&#39;s <a class="link" href="https://www.linkedin.com/in/gregose/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Greg Ose</a> describes their 2026 roadmap to secure GitHub Actions against supply chain attacks through: introducing workflow-level dependency locking (similar to Go&#39;s go.mod/go.sum) that pins all direct and transitive dependencies with commit SHAs (future: immutable releases), implementing policy-driven execution protections via rulesets that control who can trigger workflows and which events are allowed (with evaluate mode for safe rollout), and adding scoped secrets that bind credentials to specific repositories, branches, environments, or trusted reusable workflows. </p><p class="paragraph" style="text-align:left;">GitHub is also building the Actions Data Stream for near real-time execution telemetry to S3/Azure Event Hub and a native Layer 7 egress firewall for GitHub-hosted runners that operates outside the runner VM with monitor and enforce modes, treating CI/CD infrastructure as critical infrastructure with enforceable network boundaries.</p><p class="paragraph" style="text-align:left;">💡 These seem like excellent, thoughtful improvements. Love the push towards better visibility, security controls, and secure by default. Hats off to the GitHub team for these initiatives. Unfortunately the timeline is 3-6 months, though I’d rather them build it right than poorly.</p><p class="paragraph" style="text-align:left;"></p></div><div id="red-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/googleprojectzero/Jackalope?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">googleprojectzero/Jackalope</a><br>Binary, coverage-guided fuzzer for Windows, macOS, Linux and Android. Built on TinyInst for binary instrumentation, supports both file and shared memory sample delivery.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://projectzero.google/2026/03/mutational-grammar-fuzzing.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">On the Effectiveness of Mutational Grammar Fuzzing</a><br>Mutational grammar fuzzing is a type of fuzzing that uses a predefined grammar to describe the structure of the samples (e.g. input string or file) so that when a sample gets mutated, the resulting samples still adhere to the grammar rules. Google Project Zero’s <a class="link" href="https://x.com/ifsecure?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Ivan Fratric</a> describes two key flaws in mutational coverage-guided grammar fuzzing: 1) more coverage doesn’t mean more bugs, you need to test the right code patterns (e.g. functions need to be called in a certain order, or the result from one function is used as in input to another function), and 2) mutational fuzzing produces highly similar samples due to its greedy nature of saving slightly-modified samples that trigger new coverage. </p><p class="paragraph" style="text-align:left;">To address these issues, Ivan proposes a technique in <a class="link" href="https://github.com/googleprojectzero/Jackalope?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Jackalope</a> where the fuzzing worker spends half of the time creating a fully independent corpus generated from scratch and half of the time working on a larger corpus that also incorporates interesting samples (as measured by the coverage) from previous workers.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://andywgrant.substack.com/p/its-more-than-saying-no?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">It&#39;s More Than Saying No</a><br>Zoom’s Head of Assurance <a class="link" href="https://linkedin.com/in/andywgrant?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Andy Grant</a> describes what to do when leadership asks your offensive security team to do work it was never designed for. Andy argues that offensive security teams lose effectiveness when they accept misaligned work like QA support, rushed pentests, or control validation, which disrupts the long exploration periods needed for discovering unknown unknowns through intuition-driven research. </p><p class="paragraph" style="text-align:left;">Rather than saying no to requests, proactively engage with leadership to anticipate concerns, start investigating before formal requests arrive, and reframe incoming work to align with the team&#39;s adversarial research model, for example, reframing &quot;can you test X before release?&quot; into deeper investigations of trust boundaries and systemic risk.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/playlist?list=PLjmt1tu85IhAiVPugOjP-7Cy0Oemi3m7z&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">[un]prompted 2026 YouTube Playlist</a><br>The talk recordings have (mostly) been published. 65 talks at the forefront of AI + security. The final 9 will be uploaded soon.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://jakee.vc/rsa-2026-landscape.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">RSA 2026 Startup Landscape</a><br><a class="link" href="https://www.linkedin.com/in/jake-epstein-12915b11a/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Jake Epstein</a> mapped every cybersecurity startup at RSAC 2026 (322 companies) into 18 categories, including Agent Security / Non Human Identity, developer security, AI SOC, AI pen testing, data pipelines, human risk, and more. Neat visualization.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anshuman.ai/posts/vulnvibes-intro?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">VulnVibes: Building an AI Agent That Reasons Across Microservices to Find Real Vulnerabilities</a><br><a class="link" href="https://linkedin.com/in/anshumanbhartiya?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Anshuman Bhartiya</a> announces <a class="link" href="https://github.com/anshumanbh/vulnvibes?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">VulnVibes</a>, an AI-powered agent that analyzes Pull Requests for vulnerabilities by reasoning across multiple repositories in an organization, which is useful in microservice architectures. It searches across your entire GitHub organization to understand your architecture, verify what security controls actually exist, and determine if a suspicious code change is a real vulnerability. VulnVibes works in two stages: first threat modeling the PR diff to identify security-relevant changes, then performing cross-repo investigation by reading infrastructure configs (Docker Compose, nginx), checking for security controls, and following vulnerability-specific investigation playbooks.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Anshuman walks through running VulnVibes against microvibes-lab (a test org with auth-service, doc-api, frontend-app, and infra-ops repos), in which it correctly identified an SSRF vulnerability by tracing the attack path across three repos to confirm a flat Docker network and lack of WAF protection, made a nuanced call that a permissive CORS config was a false positive after verifying the codebase only uses header-based auth, and appropriately ignored a safe JWT refactoring.</p></div><p class="paragraph" style="text-align:left;">💡 Being able to reason about the impact and relevance of a potential vulnerable across multiple repos is super cool, and very relevant in complex environments. I expect to see more work in this space, neat that Anshuman has open sourced his prototype 🫡 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.synthesia.io/post/scaling-vulnerability-management-with-ai-what-actually-worked?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Scaling Vulnerability Management with AI: What Actually Worked</a><br>Synthesia’s <a class="link" href="https://www.linkedin.com/in/gbrindisi/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Gianluca Brindisi</a> describes how they built an AI-powered vulnerability management system that auto-triages SAST and SCA findings using layered automation: severity-based filtering, Semgrep Assistant for false positive detection, and EPSS/reachability analysis for supply chain issues. They automatically turn remaining high severity findings into GitHub issues with structured context (links to code, Semgrep analysis, severity, and the triggering rule), and then spin up three independent coding agents via GitHub workflows to validate vulnerabilities through consensus voting, then automatically generate fix PRs for confirmed true positives. </p><p class="paragraph" style="text-align:left;">They reduced their backlog by 60% initially through archiving stale repos, and now the system processes the remaining findings with minimal human intervention: only 11% of findings require manual security review. For confirmed true positives, the <code>true-positive</code> label triggers an agent to create a branch, implement a secure fix, and open a pull request. “The PR enters the repo&#39;s normal review flow. Instead of starting from a security ticket and a blank editor, the developer now reviews a proposed fix with the vulnerability context already embedded.”</p><p class="paragraph" style="text-align:left;">💡 This is great security engineering 👌 I love the focus on thoughtfully prioritizing/risk rating repos and findings, benchmarking and evaluating the AI workflow steps, and automating parts of the triage and PRs fixing the code. Neat!</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/HQ1995/vibe-security-radar?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">HQ1995/vibe-security-radar</a><br>Georgia Tech SSLab’s <a class="link" href="https://x.com/hankein95?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Hanqing Zhao</a> has built <a class="link" href="https://vibe-radar-ten.vercel.app/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Vibe Security Radar</a>, a tool that scans public CVE databases (OSV, GitHub Advisory Database, NVD) to identify vulnerabilities introduced by AI-generated code by tracing fix commits back through git blame, detecting AI tool signatures (co-author trailers, bot emails, commit message markers from 15+ tools), and verifies causality with an LLM investigator. So far: 74 AI-linked CVEs, 39 Critical / High, ~44K advisories scanned.</p><p class="paragraph" style="text-align:left;">💡 I think there&#39;s actually a lot of nuance around measuring the security of LLM-generated code. For example:</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Was the developer using any security-related prompts, context, or tooling?</p><ol start="1"><li><p class="paragraph" style="text-align:left;">The model may have written more secure code if it was asked, but it wasn&#39;t. </p></li></ol></li><li><p class="paragraph" style="text-align:left;">Bug density - If humans ship bugs at say 2 per 1,000 LOC, and LLMs are twice as good (1 bug per 1K LOC), if LLMs are now writing 10X as much code, that ends up still introducing more bugs.</p><ol start="1"><li><p class="paragraph" style="text-align:left;">If LLMs write fewer bugs than humans, should we prefer using them, even if they still introduce bugs? (e.g. Does Waymo need to be safer than human drivers or never make mistakes?)</p></li></ol></li></ol><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Claude Code source map leak</p><ul><li><p class="paragraph" style="text-align:left;">Anthropic shipped a source map file in the Claude Code npm package, exposing the full unobfuscated TypeScript source (~1,900 files, 512K+ lines). It’s also suspiciously close to April Fools Day 🤔 Maybe it’s real though? (<a class="link" href="https://x.com/trq212/status/2039202140158398706?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Thariq tweet</a>)</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://aired.sh/p/Zlm4dmW4ED?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Claude Code Hidden Features</a> - 89 feature flags, unreleased autonomous agents, companion pets, anti-distillation systems, and more — extracted from 1,809 source files.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/nblintao/awesome-claude-code-postleak-insights?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">nblintao/awesome-claude-code-postleak-insights</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/instructkr/claw-code?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">instructkr/claw-code</a> - Someone took Claude Code leak, then used Codex to port the core features to Python from scratch, and then ported it to Rust.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=Wvj1mTqyzsQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Theo’s video </a> - I think he’s overly negative and I don’t agree with all his points, but it has some reasonable context.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/d-WEYRqnOgY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Dissecting the Bars While Rapping</a> - Harry Mack dissects what he’s doing in his rap (structurally, setting up rhymes), while rapping about it. Insane 🤯 </p></li><li><p class="paragraph" style="text-align:left;">404 Media - The company WebinarTV is <a class="link" href="https://www.404media.co/this-company-is-secretly-turning-your-zoom-calls-into-ai-podcasts/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">secretly scanning the Internet for Zoom meeting links</a>, recording the calls, and turning them into AI-generated podcasts for profit.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.rice.is/post/doom-over-dns/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Can it Resolve DOOM? Game Engine in 2,000 DNS Records</a> - As DNS TXT records can store arbitrary text, <a class="link" href="https://www.linkedin.com/in/africe/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Adam Rice</a> was able compress and play DOOM from 1,966 TXT records on a single CloudFlare Pro DNS zone. 😂 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Apple says no one using Lockdown Mode has been hacked with spyware</a> in the four years since it’s been launched. This is impressive, and a great example of eliminating vulnerability classes/raising the security bar at scale 🤘 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/efZZ46JMieM?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Matt Rife exposes Tik Tok shadow ban on standup comedy</a></p></li><li><p class="paragraph" style="text-align:left;">Gabor Mate to Hasan Minaj - <a class="link" href="https://www.youtube.com/shorts/0IWp5BJnRWY?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Kids Speak Where It’s Safe</a> 😭 </p></li><li><p class="paragraph" style="text-align:left;">Alex Hormozi - <a class="link" href="https://www.youtube.com/watch?v=9q5ojtkqsBs&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">How to Win With AI in 2026</a></p></li><li><p class="paragraph" style="text-align:left;">Good Work - <a class="link" href="https://www.youtube.com/watch?v=0tLEszJs7hc&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Why fun tech jobs went extinct</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/osaFXfP7pBI?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">7 months underwater on a nuclear submarine</a> - Fascinating!</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Politics / Privacy</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Iran-linked hackers breach FBI director&#39;s personal email, publish photos and documents</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://apnews.com/article/iran-war-security-cameras-surveillance-5f9a1fe5845d94894f3edd50af560d3a?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Iran built a vast camera network to control dissent. Israel turned it into a targeting tool</a> - Allegedly Israel hijacked Iran’s street cameras in order to successfully track and target Iran’s supreme leader. “Experts say advances in AI have allowed militaries to overcome a critical hurdle in weaponizing hacked footage: sifting through huge amounts of video to identify people, vehicles, and other targets.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/DlFsG?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Using a VPN May Subject You to NSA Spying</a> - Because VPNs obscure a user’s true location, and because intelligence agencies presume communications of unknown origin are foreign, that may give the NSA the authority to intercept the communication without a warrant.</p></li><li><p class="paragraph" style="text-align:left;">EU Disinfo Lab - <a class="link" href="https://www.disinfo.eu/disinfo-update-12-11-2025-2-2-2-2/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">Disinfo Update 12/11/2025</a> - I haven’t come across this lab before so I’m not sure about the trustworthiness, but it has some interesting links around topics including: the X algorithm amplifying right-wing and extreme content, Meta’s profits being tied to scam ads, Russia recruiting fighters from other companies, Israel paying US influencers to boost its image, AI chatbots repeating Russian propaganda, and more.</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-322-github-s-supply-chain-roadmap-scaling-vulnerability-management-with-ai-finding-vulnerabilities-across-repos" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=03028f42-733f-4d8e-874b-ae3eb10e967d&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>How we made Trail of Bits AI-native (so far)</title>
  <description>We had 5% buy-in and 95% resistance. A year later, AI-augmented auditors are finding 200 bugs a week on the right engagements. Here&#39;s the six-part operating system we built, open sourced, and are giving away.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2d0fc235-8b10-4098-9d48-22abc34c2cc4/title_slide.jpg" length="80923" type="image/jpeg"/>
  <link>https://tldrsec.com/p/how-we-made-trail-of-bits-ai-native-so-far</link>
  <guid isPermaLink="true">https://tldrsec.com/p/how-we-made-trail-of-bits-ai-native-so-far</guid>
  <pubDate>Tue, 31 Mar 2026 11:30:00 +0000</pubDate>
  <atom:published>2026-03-31T11:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <dc:creator>Dan Guido</dc:creator>
    <category><![CDATA[Blog]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><i>Editor’s note: I’ve been a fan of Trail of Bits’ and </i><a class="link" href="https://www.linkedin.com/in/danguido/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow"><i>Dan Guido</i></a><i>’s work for a number of years. Dan’s [un]prompted talk on how he changed ToB’s culture is one of the best resources I’ve seen on how to get your company to adapt the mindset and practices to thrive in today’s rapidly changing environment. So I was thrilled that he was willing to guest post the blog version of his talk on tl;dr sec. Enjoy! -Clint</i></p><hr class="content_break"><p class="paragraph" style="text-align:left;"><i>This post is adapted from a talk I gave at </i><a class="link" href="https://unpromptedcon.org/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow"><i>[un]prompted</i></a><i>, the AI security practitioner conference. Thanks to </i><a class="link" href="https://twitter.com/gadievron?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow"><i>Gadi Evron</i></a><i> for inviting me to speak. You can watch the recorded presentation below or download the </i><a class="link" href="https://github.com/trailofbits/publications/blob/master/presentations/How%20we%20made%20Trail%20of%20Bits%20AI-Native%20(so%20far)/slides.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow"><i>slides.</i></a></p><p class="paragraph" style="text-align:left;">Most companies hand out ChatGPT licenses and wait for the productivity numbers to move. We built a system instead.</p><p class="paragraph" style="text-align:left;">A year ago, about 5% of Trail of Bits was on board with our AI initiative. The other 95% ranged from passively skeptical to actively resistant. Today we have 94 plugins, 201 skills, 84 specialized agents, and on the right engagements, AI-augmented auditors finding 200 bugs a week. This post is the playbook for how we got there. We <a class="link" href="https://github.com/trailofbits/skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">open sourced most of it</a>, so you can steal it today.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/kgwvAyF7qsA" width="100%"></iframe><p class="paragraph" style="text-align:left;">A <a class="link" href="https://fortune.com/2026/02/17/ai-productivity-paradox-ceo-study-robert-solow-information-technology-age/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">recent Fortune article</a> reported that a <a class="link" href="https://www.nber.org/papers/w34984?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">National Bureau of Economic Research study</a> of 6,000 executives across the U.S., U.K., Germany, and Australia found AI had no measurable impact on employment or productivity. Two-thirds of executives said they use AI, but actual usage came out to 1.5 hours per week, and 90% of firms reported zero impact. Economists are calling it the new Solow paradox, referencing the pattern Robert Solow identified in 1987: &quot;you can see the computer age everywhere but in the productivity statistics.&quot;</p><p class="paragraph" style="text-align:left;">AI works. Most companies are using it wrong. They give people tools without changing the system. That&#39;s the gap between AI-assisted and AI-native. One is a tool, the other is an operating system.</p><h2 class="heading" style="text-align:left;" id="what-a-inative-actually-means">What AI-native actually means</h2><p class="paragraph" style="text-align:left;">&quot;AI-native&quot; gets thrown around a lot. The way I think about it, there are three levels:</p><p class="paragraph" style="text-align:left;"><b>AI-assisted</b> is where almost everyone starts. You give people access to ChatGPT or Claude. They use it to draft emails, generate boilerplate, summarize documents. It&#39;s a productivity tool. The org doesn&#39;t change. The workflows don&#39;t change. You just do the same things a little faster.</p><p class="paragraph" style="text-align:left;"><b>AI-augmented</b> is where you start redesigning workflows. You&#39;re not just using AI as a tool. You&#39;re putting agents in the loop, changing how work actually flows. Maybe the AI does the first pass on a code review and the human does the second. The process itself is different.</p><p class="paragraph" style="text-align:left;"><b>AI-native</b> is the structural shift. The org is designed from the ground up assuming AI is a core participant. Not a tool you pick up, but a teammate that&#39;s always there. Your knowledge management, your delivery model, your expertise, all designed to be consumed and amplified by agents.</p><p class="paragraph" style="text-align:left;">At Trail of Bits, what this means concretely: our security expertise compounds as code. Every engagement we do, the skills and workflows we build make the next engagement faster. Every engineer operates with an arsenal of specialized agents built from 14 years of audit knowledge. That&#39;s not &quot;we use AI.&quot; That&#39;s &quot;AI is on the team.&quot;</p><h2 class="heading" style="text-align:left;" id="what-people-are-actually-resisting">What people are actually resisting</h2><p class="paragraph" style="text-align:left;">When I first launched this initiative inside Trail of Bits, there was an incredible amount of pushback. Studies of technology adoption consistently show the same thing: the problem is never the software. It&#39;s people&#39;s unwillingness to accept that something else might be better than their intuition. I had to understand four specific psychological barriers before I could design a system that works within them.</p><p class="paragraph" style="text-align:left;"><b>Self-enhancing bias.</b> We overestimate our own judgment. Paul Meehl and Robyn Dawes <a class="link" href="https://www.cmu.edu/dietrich/sds/docs/dawes/the-robust-beauty-of-improper-linear-models-in-decision-making.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">showed</a> that if you take the variables an expert says they use and build even a crude linear model, the model outperforms the expert. Not because it&#39;s smarter, but because it applies the same weights every time. You don&#39;t. You&#39;re hungover some days, distracted others, and you never notice because you take credit for your wins and blame external factors for your misses. This gets worse with seniority. The more expert you are, the more you trust your gut, and the less you believe a machine could do better. As <a class="link" href="https://www.gsb.stanford.edu/faculty-research/faculty/jonathan-levav?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">Jonathan Levav</a> frames it: the more unique you feel you are, the more you resist a machine making decisions for you.</p><p class="paragraph" style="text-align:left;"><b>Identity threat.</b> In <a class="link" href="https://journals.sagepub.com/doi/abs/10.1177/0022243718818423?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">one study</a>, researchers showed people the same kitchen automation device framed two ways: &quot;does the cooking for you&quot; versus &quot;helps you cook better.&quot; People who identified as cooks rejected the first framing and accepted the second, for the same device. There&#39;s a symbolic dimension too: people don&#39;t want robots giving them tattoos (human craft), but they&#39;re fine with a tattoo-<i>removing</i> robot (instrumental, no symbolism). Security auditing is symbolic work. AI that replaces skill feels like an attack on who you are.</p><p class="paragraph" style="text-align:left;"><b>Intolerance for imperfection.</b> Dietvorst et al. <a class="link" href="https://marketing.wharton.upenn.edu/wp-content/uploads/2016/10/Dietvorst-Simmons-Massey-2014.pdf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">ran a study</a> where participants watched an algorithm outperform a human forecaster. But after seeing the algorithm make one error, they abandoned it and went back to the human, even though the human was demonstrably worse. We forgive our own mistakes but not the machine&#39;s. <a class="link" href="https://pubsonline.informs.org/doi/10.1287/mnsc.2016.2643?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">Their follow-up</a> found the fix: let people modify the algorithm. Even one adjustable parameter was enough to overcome the aversion.</p><p class="paragraph" style="text-align:left;"><b>Opacity.</b> A <a class="link" href="https://www.nature.com/articles/s41562-021-01146-0?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">2021 study in Nature Human Behaviour</a> found that people&#39;s subjective understanding of human judgment is high and AI judgment is low, but objective understanding of both is near zero. People feel like they understand how a doctor diagnoses. They can&#39;t explain it either. The feeling of not understanding kills the feeling of control.</p><h2 class="heading" style="text-align:left;" id="the-remedies-that-actually-worked">The remedies that actually worked</h2><p class="paragraph" style="text-align:left;">We designed the system around the resistance, not against it.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/aa9cd8b5-a0c3-489e-8698-1b47072587cf/remedies.jpg?t=1774918016"/></div><p class="paragraph" style="text-align:left;">For <b>self-enhancing bias</b>, we built a maturity matrix. Nobody likes being told they&#39;re at level 1. But that&#39;s the point: you can&#39;t argue you&#39;re already good enough when there&#39;s a visible ladder. It makes the conversation concrete instead of &quot;I don&#39;t think AI is useful.&quot; It also creates social proof. When you see peers at level 2 or 3, the passive majority starts moving.</p><p class="paragraph" style="text-align:left;">For <b>identity threat</b>, we never asked anyone to stop being a security expert. We gave them a new way to express that identity. When a senior auditor writes a constant-time-analysis skill, they&#39;re not being replaced. They&#39;re becoming more permanent. Their expertise is encoded and reusable. That&#39;s an identity upgrade, not a threat. The maturity matrix reinforces this: level 3 isn&#39;t &quot;uses AI the most.&quot; It&#39;s &quot;invents new ways, builds tools.&quot; The identity of the expert shifts from &quot;I don&#39;t need AI&quot; to &quot;I&#39;m the one who makes the AI dangerous.&quot;</p><p class="paragraph" style="text-align:left;">For <b>intolerance for imperfection</b>, we invested heavily in reducing the ways AI can fail embarrassingly. A curated marketplace means no random plugins with backdoors. Sandboxing means Claude Code can&#39;t accidentally delete your work. Guardrails and footgun reduction mean fewer &quot;AI did something stupid&quot; stories circulating in Slack. If someone&#39;s first AI experience is bad, you&#39;ve lost them for months.</p><p class="paragraph" style="text-align:left;">For <b>opacity</b>, we wrote an AI Handbook that made everything concrete: here&#39;s what&#39;s approved, here&#39;s what&#39;s not, here are the exceptions, here&#39;s who to ask. Clear rules restored the feeling of control.</p><p class="paragraph" style="text-align:left;">And underlying everything: we made adoption visible and fast. Deferred benefits kill adoption. If setup takes an hour and the first result is mediocre, you&#39;ve confirmed every skeptic&#39;s priors. Copy-pasteable configs, one-command setup, standardized toolchain, all designed so the first experience is fast and good. And the CEO going first matters more than people think. The passive 50% watches what leadership actually does, not what it says.</p><h2 class="heading" style="text-align:left;" id="the-operating-system-model">The operating system model</h2><p class="paragraph" style="text-align:left;">Here&#39;s the actual system we built. Six parts, each designed to address the barriers I just described:</p><div style="padding:14px 15px 14px;"><table class="bh__table" width="100%" style="border-collapse:collapse;"><tr class="bh__table_row"><th class="bh__table_header" width="33%"><p class="paragraph" style="text-align:left;">Barrier</p></th><th class="bh__table_header" width="33%"><p class="paragraph" style="text-align:left;">Core problem</p></th><th class="bh__table_header" width="33%"><p class="paragraph" style="text-align:left;">What we built</p></th></tr><tr class="bh__table_row"><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Self-enhancing bias</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">&quot;I&#39;m already good enough&quot;</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Maturity Matrix with visible levels and real consequences</p></td></tr><tr class="bh__table_row"><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Identity threat</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">&quot;AI is replacing who I am&quot;</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Skills repos + hackathons that reward building, not just using</p></td></tr><tr class="bh__table_row"><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Intolerance for imperfection</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">One bad experience = months lost</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Curated marketplace, sandboxing, guardrails</p></td></tr><tr class="bh__table_row"><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">Opacity / trust </p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">&quot;I don&#39;t understand how it decides&quot;</p></td><td class="bh__table_cell" width="33%"><p class="paragraph" style="text-align:left;">AI Handbook that explains the risk model, not just the rules</p></td></tr></table></div><p class="paragraph" style="text-align:left;"></p><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Pick a standard toolchain</b> so you can support it</p></li><li><p class="paragraph" style="text-align:left;"><b>Write the rules</b> so risk conversations stop being ad hoc</p></li><li><p class="paragraph" style="text-align:left;"><b>Create a capability ladder</b> so improvement is expected, measurable, and rewarded</p></li><li><p class="paragraph" style="text-align:left;"><b>Run tight adoption sprints</b> so the org keeps pace with releases</p></li><li><p class="paragraph" style="text-align:left;"><b>Package the learnings</b> into reusable artifacts (repos, configs, sandboxes) so the system compounds</p></li><li><p class="paragraph" style="text-align:left;"><b>Make autonomy safe</b> with sandboxing, guardrails, and hardened defaults</p></li></ol><p class="paragraph" style="text-align:left;">This isn&#39;t a strategy deck we wrote and handed to someone. We built every piece ourselves, open sourced most of it, and iterated on it in production with a 140-person company doing real client work.</p><h3 class="heading" style="text-align:left;" id="standardize-on-tools">Standardize on tools</h3><p class="paragraph" style="text-align:left;">Step one was boring but critical: we standardized. We got everyone on Claude Code, and we treat it like any other enterprise tool: supported configs, known-good defaults, and a clear path to &quot;this is how we do it here.&quot;</p><p class="paragraph" style="text-align:left;">If you skip this step, you can&#39;t build anything else. You end up with 40 different workflows and zero leverage.</p><h3 class="heading" style="text-align:left;" id="write-the-rules">Write the rules</h3><p class="paragraph" style="text-align:left;">We wrote an AI Handbook. Not to teach people how to prompt. It&#39;s there to remove ambiguity.</p><p class="paragraph" style="text-align:left;">The key part is the usage policy: what tools are approved, what isn&#39;t, especially for sensitive data. Cursor can&#39;t be used on client code (except blockchain engagements; use Claude Code or <a class="link" href="https://Continue.dev?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">Continue.dev</a> instead). Meeting recorders are disallowed for client meetings conducted under legal privilege. Now, when a client asks what we&#39;re using on their codebase, everyone gives the same answer.</p><p class="paragraph" style="text-align:left;">The handbook doesn&#39;t just list what&#39;s approved. It explains the risk model behind each decision, so people understand <i>why</i>. That&#39;s what addresses the opacity barrier: not &quot;just trust this,&quot; but &quot;here&#39;s our reasoning.&quot; Once you have policy, you can safely push harder on adoption.</p><h3 class="heading" style="text-align:left;" id="make-it-measurable">Make it measurable</h3><p class="paragraph" style="text-align:left;">We built an AI Maturity Matrix that makes AI usage a first-class professional capability, like &quot;can you use Git&quot; or &quot;can you write tests.&quot;</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7fd48d28-31ec-43d6-83ab-48e1927ed07d/ai_maturity_matrix.png?t=1774918140"/><div class="image__source"><span class="image__source_text"><p>Trail of Bits AI Maturity Matrix, as of March 2026</p></span></div></div><p class="paragraph" style="text-align:left;">It&#39;s not a vibe. It&#39;s a ladder: clear levels, clear expectations, a clear path up, and real consequences for staying stuck. What level 3 looks like depends on your role. An engineer at level 3 builds agent systems that ship PRs and close issues autonomously. A sales rep at level 3 has agents producing pipeline reports and QBR prep without hand-holding. An auditor at level 3 runs agents that execute full analysis passes and produce findings, triage, and report drafts.</p><p class="paragraph" style="text-align:left;">This is how you avoid two failure modes: leadership wishing adoption into existence, and the org splitting into &quot;AI people&quot; and everyone else.</p><h3 class="heading" style="text-align:left;" id="create-an-adoption-engine">Create an adoption engine</h3><p class="paragraph" style="text-align:left;">We run hackathons as a management system: short, focused sprints of 2-3 days with one objective. They&#39;re how we keep pace when the ecosystem changes every week.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a60a1c2f-2e0b-42be-912d-6c0b2ea141ad/hackathons.png?t=1774918186"/><div class="image__source"><span class="image__source_text"><p>Claude Code Hackathon v2: Autonomous Agents</p></span></div></div><p class="paragraph" style="text-align:left;">One recent example: &quot;Claude Code Hackathon v2: Autonomous Agents.&quot; The two lines that mattered were:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Objective:</b> Ship the most impactful changes across our AI toolchain and public repos</p></li><li><p class="paragraph" style="text-align:left;"><b>Twist:</b> Engineers must work in bypass permissions mode (fully autonomous agent, not approve-every-action)</p></li></ul><p class="paragraph" style="text-align:left;">That twist is intentional. It forces everyone to learn the real constraints: sandboxing, guardrails, and how to structure work so agents can succeed.</p><p class="paragraph" style="text-align:left;">A few design choices matter here: we focus on public repos so we can move fast and show real outcomes. We measure success by activity (issues filed/fixed, PRs reviewed/merged), not lines of code. Everyone works in pairs, and every change gets reviewed by a buddy. Even the &quot;move fast&quot; sprint has quality control built in.</p><h3 class="heading" style="text-align:left;" id="capture-the-work-as-reusable-artifa">Capture the work as reusable artifacts</h3><p class="paragraph" style="text-align:left;">Hackathons create motion. But motion doesn&#39;t compound unless you capture it.</p><p class="paragraph" style="text-align:left;">The most important artifact is a <b>skills repo</b>. Skills are reusable, structured workflows, ideally with examples, constraints, and a way to verify output. We maintain an internal skills repo for company-specific workflows and an <a class="link" href="https://github.com/trailofbits/skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">external skills repo</a> so the broader community can validate and improve what we&#39;re doing.</p><p class="paragraph" style="text-align:left;">We also created a <a class="link" href="https://github.com/trailofbits/skills-curated?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow"><b>curated marketplace</b></a>, a &quot;known good&quot; place for third-party skills. Once you tell people &quot;go use skills and plugins,&quot; they&#39;ll install random stuff. This is basic enterprise thinking applied to agent tooling: if you want adoption, you need a safe supply chain.</p><p class="paragraph" style="text-align:left;">We made <b>defaults copy-pasteable</b>. We built a <a class="link" href="https://github.com/trailofbits/claude-code-config?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">repo that centralizes recommended Claude Code configuration</a> so onboarding isn&#39;t tribal knowledge. This is where we put known-good settings, recommended patterns for personal <code>~/.claude/CLAUDE.md</code>, and anything we want to standardize.</p><p class="paragraph" style="text-align:left;">We made <b>sandboxing the default</b>. If you want autonomous agents, you need sandboxing. We give people multiple safe lanes: a <a class="link" href="https://github.com/trailofbits/claude-code-devcontainer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">devcontainer option</a>, <a class="link" href="https://code.claude.com/docs/en/sandboxing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">native macOS sandboxing</a>, and <a class="link" href="https://github.com/trailofbits/dropkit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">Dropkit</a>. The point isn&#39;t that everyone uses the same sandbox. The point is everyone has a safe sandbox, and it&#39;s easy to adopt.</p><p class="paragraph" style="text-align:left;">We <b>reduced footguns</b>. We hardened defaults through MDM. For example, we rolled out more secure package manager defaults via Jamf, including <a class="link" href="https://socket.dev/blog/npm-introduces-minimumreleaseage-and-bulk-oidc-configuration?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">mandatory package cooldown policies</a>. The easiest way to reduce risk is to make the default path the safe path.</p><p class="paragraph" style="text-align:left;">Finally, we <b>connected agents to real tools</b>. Once you have policy, guardrails, sandboxes, and skills, you can connect agents to real tools. One example we&#39;ve published is an <a class="link" href="https://github.com/trailofbits/slither-mcp?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">MCP server for Slither</a>. Even if you don&#39;t care about Slither specifically, the point is: MCP turns your internal tools into something agents can use reliably, and your org can govern.</p><h2 class="heading" style="text-align:left;" id="results-so-far">Results so far</h2><p class="paragraph" style="text-align:left;">Let me give you some numbers on what this system actually produced.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7370a266-7c92-420d-bf42-966fa1c8c69e/results.jpeg?t=1774918898"/><div class="image__source"><span class="image__source_text"><p>The numbers that got the room&#39;s attention at [un]prompted</p></span></div></div><p class="paragraph" style="text-align:left;"><b>Tooling scale:</b> Across our internal and public skills repos, we have 94 plugins containing 201 skills, 84 specialized agents, 29 commands, 125 scripts, and over 414 reference files encoding domain expertise. That&#39;s the compounding effect: every engagement, every auditor, every experiment adds to the arsenal.</p><p class="paragraph" style="text-align:left;">The breadth matters. We have skills for writing sales proposals, tracking project hours, onboarding new hires, prepping conference blog posts, and delivering government contract reports. The internal repo has 20+ plugins targeting specific vulnerability classes: ERC-4337, merkle trees, precision loss, slippage, state machines, CUDA/Rust review, integer arithmetic in Go. Each one packages expertise that used to live in someone&#39;s head into something any auditor can invoke.</p><p class="paragraph" style="text-align:left;"><b>Delivery impact:</b> For certain clients where the codebase and scope allow it, we went from finding about 15 bugs a week to 200. An auditor runs a fleet of specialized agents doing targeted analysis across an entire codebase in parallel, then validates the results.</p><p class="paragraph" style="text-align:left;">About 20% of all bugs we report to clients are now initially discovered by AI in some form. They go into real client reports. An auditor validates every one, but the AI is surfacing things humans would have missed or wouldn&#39;t have had time to look for.</p><p class="paragraph" style="text-align:left;"><b>Business impact:</b> Our sales team averages \$8M in revenue per rep against a consulting industry benchmark of \$2-4M. The sales team uses the same skills repos for proposal drafting, competitive positioning, conference prep, and lead enrichment. Same system, same compounding effect.</p><p class="paragraph" style="text-align:left;">And this is maybe a year into building the system seriously. The models are getting better every month. The skills repo grows every week.</p><h2 class="heading" style="text-align:left;" id="open-questions">Open questions</h2><p class="paragraph" style="text-align:left;">Here&#39;s what we&#39;re actively working on and don&#39;t have great answers for yet.</p><p class="paragraph" style="text-align:left;"><b>Private inference.</b> We want local models for cost and confidentiality, but open models aren&#39;t good enough yet. There&#39;s still a significant gap versus the best closed models on coding benchmarks. We&#39;re evaluating on-prem inference servers to run 230B+ models at full precision. Key insight: speed drives adoption more than capability. Nobody uses a slow model, even if it&#39;s smart. In the meantime, private inference providers like <a class="link" href="https://tinfoil.sh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">Tinfoil.sh</a> (confidential computing on NVIDIA GPUs, cryptographically verifiable) are getting compelling.</p><p class="paragraph" style="text-align:left;"><b>Prompt injection and client code protection.</b> This is an existential question for using AI on client code. The data the agent works on is inherently accessible to it. Today we use blunt instruments: sensitive clients mean no web access. Longer term, we&#39;re looking at agent-native shells like <a class="link" href="https://github.com/always-further/nono?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">nono</a> and <a class="link" href="https://github.com/erans/agentsh?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">agentsh</a> that enforce policy at the kernel level.</p><p class="paragraph" style="text-align:left;"><b>Policy enforcement and continuous learning.</b> We push settings via MDM, but we&#39;re not yet pulling signal back. The goal is to turn the whole company into a feedback loop that improves the operating system weekly. One possible long-term architecture: a <a class="link" href="https://stripe.dev/blog/minions-stripes-one-shot-end-to-end-coding-agents-part-2?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">master MCP server between agents and internal resources</a>, enforcing policy server-side. We&#39;re not there yet.</p><p class="paragraph" style="text-align:left;"><b>The future of consulting.</b> This is the one that keeps me up at night. The consulting business model assumes you&#39;re billing for time, and that time roughly correlates with expertise. But when some people can outperform others by orders of magnitude with the right agent setup, that correlation breaks. The question shifts from &quot;how many hours did the auditor spend&quot; to &quot;did the auditor know where to point the agents and which findings are real.&quot;</p><p class="paragraph" style="text-align:left;">We don&#39;t have the answer yet. But the nature of how Trail of Bits offers services will probably change in the next 6 to 12 months. Audit scoping, pricing, deliverables, all of it is on the table. The firms that figure this out first will have a structural advantage, and the ones that keep billing by the hour will watch their margins compress as their competitors ship more in less time. We&#39;re not waiting to find out which side we&#39;re on.</p><h2 class="heading" style="text-align:left;" id="the-replicable-recipe">The replicable recipe</h2><p class="paragraph" style="text-align:left;">If you want to copy this, copy the system, not the specific tools:</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Standardize on one agent workflow you can support</p></li><li><p class="paragraph" style="text-align:left;">Write an AI Handbook so risk decisions aren&#39;t ad hoc</p></li><li><p class="paragraph" style="text-align:left;">Create a capability ladder so improvement is expected</p></li><li><p class="paragraph" style="text-align:left;">Run short adoption sprints that force hands-on usage</p></li><li><p class="paragraph" style="text-align:left;">Capture everything as reusable artifacts: skills + configs + curated supply chain</p></li><li><p class="paragraph" style="text-align:left;">Make autonomy safe with sandboxing + guardrails + hardened defaults</p></li></ol><p class="paragraph" style="text-align:left;">That&#39;s what we&#39;ve done so far, and it&#39;s already changed how fast we can ship and how quickly we can adapt.</p><h2 class="heading" style="text-align:left;" id="resources">Resources</h2><p class="paragraph" style="text-align:left;">All of our tooling is open source:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits/skills</a> - Our public skills repository</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/skills-curated?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits/skills-curated</a> - Curated third-party skills marketplace</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/claude-code-config?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits/claude-code-config</a> - Recommended Claude Code configurations</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/claude-code-devcontainer?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits/claude-code-devcontainer</a> - Devcontainer for sandboxed development</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/dropkit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits/dropkit</a> - macOS sandboxing for agents</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/slither-mcp?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits/slither-mcp</a> - MCP server for Slither</p></li></ul><p class="paragraph" style="text-align:left;">We&#39;re hiring! We&#39;re looking for an <a class="link" href="https://apply.workable.com/j/B85863C121?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">AI Systems Engineer</a> to work directly with me on accelerating everything in this post, and a <a class="link" href="https://apply.workable.com/j/4A48CBB705?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">Head of Application Security</a> to lead a team of about 15 exceptionally overperforming consultants. Check out <a class="link" href="https://trailofbits.com/careers?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=how-we-made-trail-of-bits-ai-native-so-far" target="_blank" rel="noopener noreferrer nofollow">trailofbits.com/careers</a>.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=0d951cd6-67cf-4a55-b461-cff5738f0856&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #321 - Sandboxing AI Agents, Trivy Compromised, Pentesting AWS&#39; AI Pentester</title>
  <description>Sandbox approaches by NVIDIA and Niel Provos, moar supply chain compromises, vulnerabilities in AWS Security Agent</description>
  <link>https://tldrsec.com/p/tldr-sec-321</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-321</guid>
  <pubDate>Thu, 26 Mar 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-03-26T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👨‍💼 I Will Survive</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Phew, stay strong my friends, we’re almost through the BSidesSF and RSAC montage ✊ </p><p class="paragraph" style="text-align:left;">Too many to list them all, but some quick thoughts and moments that stuck out:</p><ul><li><p class="paragraph" style="text-align:left;">Thank you to everyone who come to the inaugural <i>tl;dr sec</i> community meet-up! I had a blast 🥰 Also shout-out to Scott Behrens and Travis McPeak for joining me for a fireside chat.</p></li><li><p class="paragraph" style="text-align:left;">Anna Westelius gave an inspiring BSidesSF keynote about reasons for us security folks to be optimistic.</p></li><li><p class="paragraph" style="text-align:left;">It was fun joining my friends Ken Johnson, Seth Law, Kevin McDermott, and Astha Singhal on an Absolute AppSec panel at BSidesSF.</p></li><li><p class="paragraph" style="text-align:left;">Delicious KBBQ with a bunch of other security creator nerds, H/T Ashish and Shilpi of the Cloud Security Podcast for organizing!</p></li><li><p class="paragraph" style="text-align:left;">Huge thanks to Decibel’s Dan Nguyen-Huu and Jon Sakoda for hosting an awesome set of lightning talks, which my bud Daniel Miessler also helped organize. Great talks from Rob Ragan, Jackie Bow, Andrew Becherer, and Sydney Marrone! </p><ul><li><p class="paragraph" style="text-align:left;">Dave Aitel choosing the Imperial March from Star Wars as his intro music was delightful 😂 </p></li></ul></li><li><p class="paragraph" style="text-align:left;">Randomly meeting former NSA Director Rob Joyce! H/T Lina Lau, whose company is working on some impactful stuff 👀 </p></li><li><p class="paragraph" style="text-align:left;">Hearing from folks who were moved by my talk last BSidesSF about vulnerability 🥹 This had the biggest impact on me.</p></li></ul><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9e7ee9b8-f5b3-4e4c-be20-d689f6614d19/image.png?t=1774513318"/><div class="image__source"><span class="image__source_text"><p>Security creator friends!</p></span></div></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>AI is Expanding Your Attack Surface. </b><br><b>Can You Secure It?</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI adoption is accelerating across cloud environments, from LLMs to autonomous agents and complex data pipelines. But without dedicated AI security posture management (AI-SPM), these innovations introduce a new class of risks that traditional tools can’t address.</p><p class="paragraph" style="text-align:left;">From exposed training data to overprivileged AI agents, the attack surface is expanding faster than security teams can keep up.</p><p class="paragraph" style="text-align:left;">Download the guide to learn a five-step framework to gain visibility, assess risk and secure AI across your cloud environment.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.paloaltonetworks.com/resources/whitepapers/close-ai-security-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow"><b>Download guide</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">Having visibility into the AI usage in your environment is important, and unfortunately not always easy 😅 I hear from lots of security leaders working on securing AI usage these days.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/ChiChou/vscode-frida?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">ChiChou/vscode-frida</a><br>A VSCode extension providing comprehensive IDE for <a class="link" href="https://frida.re/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Frida</a> dynamic instrumentation, featuring a sidebar for listing apps/processes on local/USB/remote devices, interactive panels for browsing modules/exports and classes/methods (Java/Objective-C), and one-click hook generation for native functions, ObjC selectors, and Java methods.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">How &quot;Strengthening Crypto&quot; Broke Authentication: FreshRSS and bcrypt&#39;s 72-Byte Limit</a><br>Pentester Lab&#39;s <a class="link" href="https://twitter.com/snyff?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Louis Nyffenegger</a> analyzes CVE-2025-68402, an authentication bypass in the development branch of FreshRSS a self-hosted RSS aggregator, caused by a &quot;strengthen crypto&quot; commit that replaced SHA-1 (40 chars) with SHA-256 (64 chars) for nonce generation. The longer nonce, when concatenated with the bcrypt hash before verification, pushed the password-dependent portion of the hash beyond bcrypt&#39;s 72-byte truncation limit, meaning password_verify() only checked the nonce plus the algorithm identifier (<code>$2y$10$</code>) and one salt character, none of which depend on the actual password.</p><p class="paragraph" style="text-align:left;">&quot;A commit meant to strengthen the crypto ended up removing the need for a valid password.&quot; 😱 </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📊 Cside Report: The Future of Web Security Depends on the Browser</h1><hr class="content_break"><p class="paragraph" style="text-align:left;">The browser runtime sits between your website &lt; &gt; customers, bots, AI agents, and fraudsters. No one is watching it. And agents now access websites on behalf of humans, adding the risk of consumer agents being manipulated by script injections from third-party code. Grab this report to see data on: the new threat of locally hosted stealth browsers, a 15x rise in user-action AI agents, 275% increase on discussions of bot traffic, and results of an industry survey on how practitioners are preparing against AI-agent driven website fraud.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://cside.com/research-report-future-of-web-security-2026?utm_source=tldr&utm_campaign=march26" target="_blank" rel="noopener noreferrer nofollow"><b>Get the Report from Cside</b></a><b> 👈 </b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I could definitely see the bar rising for preventing AI-agent driven fraud or bot abuse given improvements in AI + browser use. I’m curious how the secure this new world.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://arstechnica.com/information-technology/2026/03/federal-cyber-experts-called-microsofts-cloud-a-pile-of-shit-approved-it-anyway/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Federal cyber experts called Microsoft’s cloud a “pile of s#!t,” approved it anyway</a> - Deep dive by <a class="link" href="https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">ProPublica</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://mazehq.com/blog/ai-remediation-developers-actually-want-to-use?utm_campaign=2026Q1-Global-Inbound-Newsletter-RemediationLaunch&utm_medium=newsletter&utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow">AI Remediation Developers Will Actually Use</a><a class="link" href="https://mazehq.com/blog/ai-remediation-developers-actually-want-to-use?utm_campaign=2026Q1-Global-Inbound-Newsletter-RemediationLaunch&utm_medium=newsletter&utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow"> </a>- Every vulnerability tool tells you what&#39;s wrong. No one tells you how to actually fix it. Rebuild the image, bump a dependency, or apply a mitigation? The right answer depends on how it&#39;s built. Maze AI agents understand your environment and deliver the fix your team would actually use.* </p><ul><li><p class="paragraph" style="text-align:left;">This is a nice post on the nuances and challenges of auto-fixing.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/dan-v/cloudshell-store?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">dan-v/cloudshell-store</a> - A distributed file store built on AWS CloudShell&#39;s free persistent storage. Chicanery of the highest order 🫡 </p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://iamtrail.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">IAMTrail</a><br>AWS silently updates Managed IAM policies all the time. This project by <a class="link" href="https://www.linkedin.com/in/grenuv/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Victor Grenu</a> tracks the full version history and diffs for 1525 AWS Managed IAM Policies, archived since 2019. </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Pwning AI Code Interpreters in AWS Bedrock AgentCore</a><br>Friend of the newsletter BeyondTrust’s <a class="link" href="https://www.linkedin.com/in/kmcquade3/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-todo-todo-todo" target="_blank" rel="noopener noreferrer nofollow">Kinnaird McQuade</a> discovered that the AWS Bedrock AgentCore Interpreter’s Sandbox network mode (“complete isolation with no external access”) does allow public DNS queries. The post walks through using that capability to establish bidirectional communication (command and control, C2) using a custom tunneling protocol via DNS queries and responses, obtain a full interactive reverse shell, exfiltrating data, and performing command execution with the Code Interpreter’s IAM role. <a class="link" href="https://github.com/BeyondTrust/pwning-agentcore-code-interpreter/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">GitHub PoC</a>.</p><p class="paragraph" style="text-align:left;">Result: &quot;AWS communicated that a fix will not be made and it will change the documentation’s <b>description</b> of sandbox mode instead. AWS awarded the security researcher with a <b>$100 gift card</b> to the AWS Gear Shop.&quot; 😂</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/inside-aws-security-agent-a-multi-agent-architecture-for-automated-penetration-testing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Inside AWS Security Agent: A multi-agent architecture for automated penetration testing</a><br>AWS’ <a class="link" href="https://www.linkedin.com/in/tamer-alkhouli-538a326/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Tamer Alkhouli</a>, <a class="link" href="https://www.linkedin.com/in/divya-bhargavi/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Divya Bhargavi</a>, <a class="link" href="https://www.linkedin.com/in/dbonadiman/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Daniele Bonadiman</a> et al describe how AWS Security Agent works and how they benchmarked it. With CTF instructions and grader checks after each tool call it achieved 92.5% on <a class="link" href="https://github.com/uiuc-kang-lab/cve-bench?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">CVE Bench</a> v2.0, 80% without CTF instructions or grader feedback (more like real-world conditions), and 65% using an LLM whose knowledge cutoff date predates CVE Bench v1.0 release.</p><p class="paragraph" style="text-align:left;">See also <a class="link" href="https://linkedin.com/in/sena-yakut?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Sena Yakut</a>’s <a class="link" href="https://aws.plainenglish.io/aws-security-agent-penetration-testing-overview-e05cc62ce4f6?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">blog overview</a> on setting up AWS Security Agent and scanning DVWA. </p><p class="paragraph" style="text-align:left;">💡 This post actually had a pretty good amount of details and context, nice. I also found it interesting how performance dropped when using an LLM with knowledge cutoff before the CVE Bench release- is it doing better due to “memorizing” the answers or is it just a worse model because it’s older? 🤔 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.richardfan.xyz/2026/03/14/pentesting-a-pentest-agent-heres-what-ive-found-in-aws-security-agent.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Pentesting a pentest agent - Here&#39;s what I&#39;ve found in AWS Security Agent</a><br><a class="link" href="https://www.linkedin.com/in/richardfan1126/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Richard Fan</a> discovered five security vulnerabilities in AWS Security Agent, an autonomous AI pentesting tool, and discusses four of them (the 5th isn’t fixed yet).</p><ol start="1"><li><p class="paragraph" style="text-align:left;">The DNS confusion bug allowed attackers to manipulate Route53 private hosted zones to trick the agent into pentesting public domains they don&#39;t own by exploiting the &quot;Unreachable&quot; domain status and DNS record verification timing.</p></li><li><p class="paragraph" style="text-align:left;">Richard was able to trick the agent into hacking itself, obtaining a reverse shell with root access to the agent sandbox by injecting commands into debug messages, and escaping the container through the mounted /run/docker.sock to access the host EC2 instance and its IAM role credentials.</p></li><li><p class="paragraph" style="text-align:left;">He found the agent sometimes performs unnecessarily destructive actions like using <code>DROP TABLE</code> for SQL injection probes.</p></li><li><p class="paragraph" style="text-align:left;">The agent can expose unredacted passwords in pentest reports.</p></li></ol><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;">I’ve been doing BSidesSF/RSA stuff non-stop so I haven’t had time to fully get the lay of the land but it seems like a few things have been on fire. I wonder if the threat actors chose this week due to thinking defenders might be busy at conferences 🤔 Rude!</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Trivy Compromised</a> - By Wiz’s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.boostsecurity.io/articles/teampcp-litellm-supply-chain-compromise?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">TeamPCP Compromises LiteLLM: Credential Stealer in PyPI, 70 Repos Exposed</a> - I love how this post by Boost Security&#39;s <a class="link" href="https://linkedin.com/in/francoisp?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">François Proulx</a> emphasizes the collaborative nature of the folks working to detect and respond to these supply chain attacks. More from <a class="link" href="https://semgrep.dev/blog/2026/the-teampcp-credential-infostealer-chain-attack-reaches-pythons-litellm/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Semgrep</a> and <a class="link" href="https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Datadog</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/HackingLZ/litellm_1.82.8_payload?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">HackingLZ/litellm_1.82.8_payload</a> - Defanged malware stages from the litellm 1.82.8 PyPI supply chain compromise — credential stealer, K8s lateral movement, C2 backdoor.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://jfrog.com/blog/agent-skills-new-ai-packages?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Agent Skills are the New Packages of AI: It&#39;s Time to Manage Them Securely</a><br>JFrog’s <a class="link" href="https://www.linkedin.com/in/yonatan-arbel/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Yonatan Arbel</a> announces their Agent Skills Registry product. Yonatan argues that we should be treating Skills like open source dependencies: version tracking them, scanning them for malicious contents, tracking provenance, etc.</p><p class="paragraph" style="text-align:left;">💡Something like this makes a lot of sense to me. We should be taking all of the lessons we’ve learned over time from various package registries and language ecosystems and ideally building them in from the beginning with new things like Skills.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/mandiant/speakeasy?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">mandiant/speakeasy</a><br>By <a class="link" href="https://linkedin.com/company/mandiant?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Mandiant</a>: A Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled Windows runtime instead of a full VM. It emulates APIs, process/thread behavior, filesystem, registry, and network activity so samples can keep moving through realistic execution paths.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://ctrlaltintel.com/threat%20research/FancyBear?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops</a><br>Ctrl-Alt-Intel discovered an exposed open-directory on a FancyBear (APT28/GRU) C2 server that revealed the group&#39;s complete toolkit, telemetry logs, and exfiltrated data from a 500+ day espionage campaign targeting government and military entities across Ukraine, Romania, Bulgaria, Greece, Serbia, and North Macedonia. The exposed server contained 2,800+ exfiltrated emails, 240+ credential sets with TOTP 2FA secrets, and more. </p><p class="paragraph" style="text-align:left;">“FancyBear developed a modular, multi-platform exploitation toolkit where a victim simply opening a malicious email - with no further clicks - could result in their credentials stolen, their 2FA bypassed, emails within their mailbox exfiltrated, and a silent forwarding rule established that persists indefinitely.”</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://rastamouse.me/islands-of-invariance?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Islands of Invariance</a><br>Rasta Mouse (maybe <a class="link" href="https://x.com/_RastaMouse?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Rasta Mouse</a> on X, <a class="link" href="https://www.linkedin.com/in/daniel-rastamouse-duggan/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Daniel Duggan</a>?) describes how Crystal Palace now includes an automatic YARA generator that creates signatures based on &quot;islands of invariance&quot; (predictable, unchanged code patterns after optimization).</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aff-wg.org/2026/03/03/a-scalpel-a-hammer-and-a-foot-gun?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">A scalpel, a hammer, and a foot gun</a><br><a class="link" href="https://linkedin.com/in/rsmudge?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Raphael Mudge</a> has released ised, a program rewriting tool for Crystal Palace that surgically inserts or replaces code at instruction pattern matches to break content signatures. The tool uses a two-pass implementation with prepend/append/replace buckets and supports specific/generic/mnemonic pattern matching from Crystal Palace&#39;s disassembler output.</p><p class="paragraph" style="text-align:left;">&quot;A potential outcome is that researchers building tools on this platform may feel quite comfortable releasing Yara rules for all of their capability. It’s no loss, because they and their users would likely have a private ised-cocktail ready to go. What would change in red teaming (or cybersecurity even), if there was no fear of ‘burning a tool’ because of its content tells and behavior was the only meaningful battleground?&quot;</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/ghostvectoracademy/DLLHijackHunter?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">ghostvectoracademy/DLLHijackHunter</a><br>By <a class="link" href="https://www.linkedin.com/company/ghostvector-academy/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">GhostVector Academy</a>: An automated Windows DLL hijacking detection tool that discovers, validates, and confirms exploitable DLL hijack opportunities through a four-phase pipeline: discovery (enumerates binaries across services, scheduled tasks, startup items, COM objects, and AutoElevate UAC bypass vectors), filtration (eliminates false positives through hard and soft gates), canary confirmation (deploys a harmless canary DLL and triggers the binary to prove the hijack works), and scoring (0-100% confidence plus 0-10 impact score based on privilege gained, trigger reliability, and stealth). </p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/NVIDIA/NemoClaw?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">NVIDIA/NemoClaw</a><br>An open source referencer stack that simplifies running OpenClaw agents inside NVIDIA OpenShell sandboxes with multi-layer security controls including Landlock, seccomp, network namespaces, and policy-enforced egress filtering. More below.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/NVIDIA/OpenShell?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">NVIDIA/OpenShell</a><br>OpenShell provides a sandboxed execution environment for AI agents that enforces declarative YAML policies to prevent unauthorized file access, data exfiltration, and uncontrolled network activity. The system runs as a K3s cluster inside a single Docker container and applies defense-in-depth across four policy domains: filesystem (read/write restrictions), network (outbound connection control with HTTP method and path-level enforcement), process (privilege escalation blocking), and inference (model API call routing). </p><p class="paragraph" style="text-align:left;">OpenShell supports Claude, OpenCode, Codex, OpenClaw, and Ollama agents out of the box and manages credentials as injectable providers that never touch the sandbox filesystem. Security policies are hot-reloadable at runtime for network and inference layers, while filesystem and process restrictions are locked at sandbox creation</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.provos.org/p/ironcurtain-secure-personal-assistant?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">IronCurtain: A Personal AI Assistant Built Secure from the Ground Up</a><br>Security legend <a class="link" href="https://www.linkedin.com/in/nielsprovos/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Niels Provos</a> asked himself: How would you build a personal AI assistant if you took security seriously from the start? So he built <a class="link" href="https://github.com/provos/ironcurtain?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">IronCurtain</a>, which sandboxes LLM-generated code, enforces policy in plain English, and keeps credentials out of the agent&#39;s reach.</p><p class="paragraph" style="text-align:left;">IronCurtain funnels all actions through a single MCP proxy chokepoint where a policy engine enforces rules written in plain English and compiled to deterministic policies. The system supports two sandbox modes: Code Mode runs LLM-generated TypeScript in isolated V8 with no filesystem/network access, while Docker Mode runs full agents like Claude Code CLI in containers with <code>--network=none</code> where a MITM proxy swaps fake API keys for real ones to maintain credential separation. </p><p class="paragraph" style="text-align:left;">The plain-English constitution approach (inspired by Microsoft Research&#39;s LEGALEASE) lets users write policies like &quot;agent may read/write files in project directory but must ask before git push&quot; which compile to deterministic allow/deny/escalate rules, with an optional auto-approver that recognizes explicit user intent to reduce alert fatigue.</p><p class="paragraph" style="text-align:left;">💡 Really thoughtful, great read. I love the architecture of making sure there’s a single security enforcement point, and how you can ease the burden of writing complex enforcement policies via natural language (but that are still enforced deterministically).</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Feels</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/thomassowell/status/1996709851263914124?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Hugh Grant</a>: &quot;It&#39;s been very, very depressing watching Big Tech kidnap their lives, and to see children really finding it very, very difficult to get properly interested in anything that isn&#39;t a screen.&quot;</p></li><li><p class="paragraph" style="text-align:left;">Matthew Hussey - <a class="link" href="https://www.youtube.com/watch?v=x3cr76JP820&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Why Men Don&#39;t Open Up These Days...</a></p></li><li><p class="paragraph" style="text-align:left;">HealthyGamerGG - <a class="link" href="https://www.youtube.com/watch?v=2unELGOein8&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Why Sharing Your Feelings Can Kill Your Relationship</a> </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=GEzd61aRhl4&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Kevin James on Finding Love Later in Life</a></p></li><li><p class="paragraph" style="text-align:left;">Ethan Hawke - <a class="link" href="https://www.youtube.com/shorts/hBt3cWvB6pQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">The one who’s in love always wins</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.worksinprogress.news/p/many-of-the-tastiest-vegetables-are?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">How an unappetizing shrub became dozens of different vegetables</a> - Centuries of selective breeding turned a single wild weed into everything from broccoli to Brussels sprouts. Whoa 🤯 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.polygon.com/pokemon-go-data-ai-robots-niantic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Turns out all your Pokémon Go data will be used to train robots</a> - Niantic is using location data collected from Pokémon Go and Ingress players to train Coco Robotics&#39; urban delivery robots.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/rexrodeo/american-healthcare-conundrum?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">rexrodeo/american-healthcare-conundrum</a> - Investigative data journalism: quantifying fixable waste in US healthcare, one issue at a time. Open-source analysis of CMS, OECD, and federal datasets. $98.6B in savings identified so far.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thehill.com/policy/defense/5784917-zelesnky-russia-iran-drone-claims?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">Zelensky: Russia providing Iran with Shahed drones used against US bases</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.carryology.com/insights/how-the-turner-twins-are-mythbusting-modern-gear/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">How the Turner Twins Are Mythbusting Modern Gear</a> - The twins are A/B testing modern gear by having one dress in cutting-edge technical apparel and the other in 100-year-old heritage kit on the world’s toughest expeditions.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://statmodeling.stat.columbia.edu/2026/03/24/false-claims-in-a-published-no-corrections-no-consequences-welcome-to-the-business-school/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">False claims in a widely-cited paper. No corrections. No consequences. Welcome to the Business School.</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=nPDH4lZB6HU&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">&quot;One Day More,&quot; except Waluigi is every part</a> 😂 😂 </p></li><li><p class="paragraph" style="text-align:left;">America’s Got Talent - <a class="link" href="https://www.youtube.com/shorts/m75lgPRY4ZQ?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">A magician instantly changing her outfit like 8 times</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-321-sandboxing-ai-agents-trivy-compromised-pentesting-aws-ai-pentester" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=267560d7-a538-4919-8cc1-17ebf9a87016&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #320 - Ramp&#39;s Security Agents, How Datadog Caught Malicious OSS Contributions, Obliterating Model Refusals</title>
  <description>How Ramp fixed ~100 security issues in 6 days, detecting and mitigating GitHub supply chain attacks, two tools to automatically remove censorship from models</description>
  <link>https://tldrsec.com/p/tldr-sec-320</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-320</guid>
  <pubDate>Thu, 19 Mar 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-03-19T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">👩‍💻 Brace Yourself, Conferences Cometh</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">I’m excited for BSidesSF and RSA but phew, things have been busy 😅</p><p class="paragraph" style="text-align:left;">If you’re flying in to San Francisco, safe travels! And remember to periodically eat, sleep, and shower amidst all the fun conference and event activities.</p><ul><li><p class="paragraph" style="text-align:left;"><b>Friday</b> - <a class="link" href="https://luma.com/ljd8kxzr?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">tl;dr sec Community Kickoff</a>. </p><ul><li><p class="paragraph" style="text-align:left;">Mostly filling up, but DM me and I’ll try get you in.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Saturday</b> - I’m joining my friends on an <a class="link" href="https://bsidessf2026.sched.com/event/2E1eG/state-of-absolute-appsec-nulb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(44, 129, 229)">Absolute AppSec panel</a>, and will be at BSidesSF both days!</p></li><li><p class="paragraph" style="text-align:left;"><b>Wednesday</b> - <a class="link" href="https://luma.com/um3t4mve?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Coding Agents Unleashed hosted by TL;DR Sec & Unsupervised Learning</a> - There’s going to be some 🔥 lightning talks from smart folks. Broader Decibel registration link <a class="link" href="https://luma.com/7pw1xhoe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p></li></ul><p class="paragraph" style="text-align:left;">Semgrep is also having a <a class="link" href="https://semgrep.dev/events/rsa?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">ton of events</a>. If you need a break from the RSA craziness you can <a class="link" href="https://semgrep.dev/events/rsa-builders-lounge/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">stop by the office</a>, get some coffee, snacks, or lunch, and chat with some Semgrep folks if you want. </p><p class="paragraph" style="text-align:left;">If you find me I’ll have some <i>tl;dr sec</i> t-shirts and brand new stickers…</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/954d770a-66f8-4587-87d6-b2ac20bcecb8/Screenshot_2026-03-18_at_11.18.27_PM.png?t=1773901118"/><div class="image__source"><span class="image__source_text"><p>Hard to tell from the photo but it’s holographic</p></span></div></div><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h2 class="heading" style="text-align:center;">📣 <b>Cybercrime Just Hit Escape Velocity </b><br><b>(Here’s the Evidence)</b></h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Flashpoint just released its 2026 Global Threat Intelligence Report, and the data is shocking.</p><ul><li><p class="paragraph" style="text-align:left;">AI-related illicit activity surged <b>1,500%</b> in a single month</p></li><li><p class="paragraph" style="text-align:left;"><b>3.3B</b> compromised credentials are now fueling identity-based attacks</p></li><li><p class="paragraph" style="text-align:left;">Ransomware incidents increased <b>53%</b> as groups pivot toward pure-play extortion</p></li></ul><p class="paragraph" style="text-align:left;">The report also explores how threat actors are moving from generative tools to agentic AI frameworks that can automate attacks at scale.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://go.flashpoint-intel.com/2026-global-threat-intelligence-report?utm_source=tldrinfosec&utm_medium=newsletter&utm_campaign=Resource_RP_GTI_2026&sfcampaign_id=701Rc00000dDaIXIA0" target="_blank" rel="noopener noreferrer nofollow"><b>View the Report</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">AI is definitely helping threat actors in a number of ways, I’m curious to see more 👀 Agent-led end-to-end attacks and automated exploitation sounds very interesting.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.doyensec.com/2024/09/19/phishing-case-study.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Applying Security Engineering to Make Phishing Harder</a> - Lessons learned by Doyensec from testing a “Communication Platform as a Service.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://corridor.dev/?utm_source=tldrsec&utm_medium=email&utm_campaign=seriesa_announcement" target="_blank" rel="noopener noreferrer nofollow">Corridor Raises $25M Series A to Secure AI Coding at the Source</a> - Corridor is tackling a problem many Security and Engineering Teams are starting to feel big time - code being generated faster than traditional AppSec can secure it. Corridor’s approach embeds security directly into AI coding workflows. Backed by some of the smartest investors in AI and AppSec. tl;dr sec readers get 3 months free!*</p><ul><li><p class="paragraph" style="text-align:left;">Corridor has been able to pull some security OGs, like Alex Stamos and Joel Wallenstrom. I’m excited to see what they’re building 🤘 </p></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/martino-spagnuolo/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Martino Spagnuolo</a> - <a class="link" href="https://r3verii.github.io/cve/2026/02/27/nodejs-toctou.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">The Forgotten Bug: How a Node.js Core Design Flaw Enables HTTP Request Splitting</a></p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://bishopfox.com/blog/swagger-jacker-auditing-openapi-definition-files?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Introducing Swagger Jacker: Auditing OpenAPI Definition Files</a><br>Bishop Fox’s <a class="link" href="https://www.linkedin.com/in/tony-west-lv/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Tony West</a> announces Swagger Jacker, a command line tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files. It parses the definition file for paths, parameters, and accepted methods and passes the results to one of five subcommands: <code>automate</code> (sends requests and analyzes response status codes), <code>prepare</code> (generates curl/sqlmap command templates for manual testing), <code>endpoints</code> (lists raw API routes), <code>brute</code> (discovers hidden definition files using 2173+ common paths), and <code>convert</code> (converts v2 to v3 definitions).</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://synacktiv.com/en/publications/mitmproxy-for-fun-and-profit-interception-and-analysis-of-application-traffic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">mitmproxy for fun and profit: Interception and Analysis of Application</a><br>Guide by Synacktiv&#39;s <a class="link" href="https://www.linkedin.com/in/corentin-liaud/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Corentin Liaud</a> on using mitmproxy for network traffic interception across Linux, Android, and iOS, including three examples: redirecting git clone requests to download a different repository by modifying HTTP paths, spoofing Android geolocation by parsing and altering gRPC/protobuf coordinates sent to Google&#39;s geomobileservices API, and passively capturing Mumble VoIP chat messages by running mitmproxy in reverse TLS mode with custom protobuf parsing scripts. </p><p class="paragraph" style="text-align:left;">The post describes setting up your test environment (using Linux network namespaces, lnxrouter for WiFi AP creation, and nftables for transparent traffic redirection), using Magisk&#39;s Cert-Fixer module to install system certificates on Android, and includes Python scripts showing how to parse and modify protocol buffers in transit.</p><p class="paragraph" style="text-align:left;"></p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> Your SOC is a queueing system. </b><br><b>The math matters more than you think.</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">If you&#39;ve ever looked at utilization curves, you know what happens when a queue runs hot: wait time doesn&#39;t scale linearly. It spikes. In a SOC, that means alerts aging out before anyone touches them.</p><p class="paragraph" style="text-align:left;">&quot;The Queue is the Breach&quot; ebook from Prophet Security applies operational math to SOC performance: alert cycle time, wait time by severity, and what analyst utilization actually implies about your team&#39;s capacity. It&#39;s a framework for diagnosing whether your bottleneck is people, tooling, or the operating model.</p><p class="paragraph" style="text-align:left;">Written by Jon Hencinski, Head of Security Operations at Prophet.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://resources.prophetsecurity.ai/ebook-the-queue-is-the-breach?lsource=tldr-sec&utm_source=tldrsec&utm_medium=paid-newsletter&utm_campaign=tldrsec_secondarysponsorship_03-19-2026" target="_blank" rel="noopener noreferrer nofollow"><b>Download the eBook </b></a><b>👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Nice, I like when people take a data-driven approach to security 👍️ </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/twenty-years-of-cloud-security-research?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Twenty Years of Cloud Security Research</a><br>Cloud historian, scholar, and man of the people <a class="link" href="https://linkedin.com/in/scott-piper-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Scott Piper</a> traces 20 years of cloud security evolution through three distinct eras: the Foundational era (2006-2016) when AWS built core security features like IAM (2011), CloudTrail (2013), and Organizations (2016); the CSPM era (2016-2021) marked by open-source tools like Scout2, Cloud Custodian, Prowler, CloudMapper, Pacu, and StreamAlert; and the CNAPP era (2021-2025) with new cloud security vendors and researchers discovering cross-tenant vulnerabilities like chaosdb and omigod. The emerging AI era (2025+) is fundamentally changing both offense and defense, with AI creating exploits for CVE-2025-32433 and mongobleed in minutes, winning HackerOne&#39;s top bounty spot, and solving CTF challenges instantly.</p><p class="paragraph" style="text-align:left;">💡 Great overview of relevant research and tools, and nice perspective on how cloud security has been evolving over time.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://onecloudplease.com/blog/bucketsquatting-is-finally-dead?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Bucketsquatting is (Finally) Dead</a><br><a class="link" href="https://linkedin.com/in/iann0036?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Ian McKay</a> describes AWS&#39;s new S3 bucket namespace protection that prevents bucketsquatting attacks by requiring buckets to follow the format <code>&lt;prefix&gt;-&lt;accountid&gt;-&lt;region&gt;-an</code>, ensuring only the owning account can create buckets matching that pattern. AWS recommends this namespace be used by default for all new buckets and provides a new condition key <code>s3:x-amz-bucket-namespace</code> that security administrators can enforce via SCP policies across their organization.</p><p class="paragraph" style="text-align:left;">Google Cloud Storage addresses this differently through domain name verification for bucket names, while Azure Blob Storage remains vulnerable due to its configurable account/container name structure and 24-character limit on storage account names.</p><p class="paragraph" style="text-align:left;">See <a class="link" href="https://hackaws.cloud/blog/aws-finally-gave-s3-buckets-their-own-rooms?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">AWS Finally Gave S3 Buckets Their Own Rooms</a> for more context on the issue and an overview of relevant prior research by Aqua.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.praetorian.com/blog/building-bridges-breaking-pipelines-introducing-trajan?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Building Bridges, Breaking Pipelines: Introducing Trajan</a><br>Praetorian&#39;s <a class="link" href="https://www.linkedin.com/in/aj-hammond?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">AJ Hammond</a>, <a class="link" href="https://www.linkedin.com/in/carter-a-ross?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Carter Ross</a>, <a class="link" href="https://www.linkedin.com/in/evanleleux/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Evan Leleux</a> et al announce <a class="link" href="https://github.com/praetorian-inc/trajan?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Trajan</a>, an open-source CI/CD security tool from Praetorian that unifies vulnerability detection and attack validation across GitHub Actions, GitLab CI, Azure DevOps, and Jenkins in a single cross-platform engine. It ships with 32 detection plugins and 24 attack plugins covering poisoned pipeline execution, secrets exposure, self-hosted runner risks, and AI/LLM pipeline vulnerabilities.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.datadoghq.com/blog/engineering/stopping-hackerbot-claw-with-bewaire?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">When an AI agent came knocking: Catching malicious contributions in Datadog’s open source repos</a><br>Datadog’s <a class="link" href="https://linkedin.com/in/hamsen?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Christoph Hamsen</a>, <a class="link" href="https://linkedin.com/in/christophetafanidereeper?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Christophe Tafani-Dereeper</a>, and <a class="link" href="https://www.linkedin.com/in/kylian-serrania-059021138/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Kylian Serrania</a> describe how their LLM-powered code review system <a class="link" href="https://www.datadoghq.com/blog/engineering/malicious-pull-requests/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals#using-llms-to-detect-maliciousness-at-scale" target="_blank" rel="noopener noreferrer nofollow">BewAIre</a> detected and helped mitigate attacks from hackerbot-claw, an AI agent that attempted to exploit GitHub Actions workflows across their open source repositories. The attacker successfully achieved code execution in one workflow via command injection in filenames, but defense-in-depth controls (organization-wide GitHub rulesets preventing direct pushes to main branches, restricted GITHUB_TOKEN permissions, and no sensitive secrets exposure) limited impact to only pushing a harmless commit to a non-protected branch.</p><p class="paragraph" style="text-align:left;">💡 Nice walk through of noticing your open source repos are being targeted → investigating potential impact, and solid advice on hardening open source repos/GitHub Actions. Also, I really like the bullets towards the top on Datadog’s SDLC Security team initiatives re: adapting octo-sts, removing GitHub Action secrets at scale, enforcing CI security best practices, and building golden paths.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/elastic/agent-skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">elastic/agent-skills</a><br>Elastic’s official Skills repos, covering cloud, Elasticsearch, Kibana, observability, and security. Currently includes 4 security Skills for: triaging alerts, case management (managing SOC cases via Kibana Cases when tracking incidents), detection rule management (create, tune, and manage Elastic Security detection rules), and generating sample security data (security events, attack scenarios, and synthetic alerts).</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://medium.com/@terminalsandcoffee/building-a-cloud-native-detection-engineering-lab-with-terraform-and-aws-63d3990190f1?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Building a Cloud-Native Detection Engineering Lab with Terraform and AWS</a><br><a class="link" href="https://www.linkedin.com/in/rgmartinez-cloud/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Rafael Martinez</a> describes building a fully automated detection engineering lab (<a class="link" href="https://github.com/TerminalsandCoffee/detection-engineering?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">GitHub</a>) in AWS using Terraform to overcome local hardware limitations, deploying three EC2 instances: Kali Linux (attacker), Windows Server with Sysmon and Winlogbeat (target), and Ubuntu running Elasticsearch and Kibana (SIEM). Easy to spin up and down as needed.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://mostafa.dev/pattern-detection-and-correlation-in-json-logs-fab16334e4ee?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Pattern Detection and Correlation in JSON Logs</a><br><a class="link" href="https://linkedin.com/in/mostafa-moradian?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Mostafa Moradian</a> announces <a class="link" href="https://github.com/timescale/rsigma?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">RSigma</a>, a Rust-based command-line tool that evaluates Sigma detection rules against JSON logs without requiring a SIEM. “Think of RSigma as <code>jq</code> for threat detection: you point it at a set of <a class="link" href="https://github.com/SigmaHQ/sigma?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Sigma</a> detection rules and a stream of JSON events, and it tells you what matched, with no ingestion pipeline, no database, no infrastructure.”</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">RSigma parses YAML rules into a strongly-typed AST, compiles them into optimized matchers, and evaluates them directly against JSON log events in real-time. The toolkit includes rsigma-parser for parsing, rsigma-eval for compilation and evaluation with stateful correlation logic and compressed event storage, a CLI for parsing, validating, linting, and evaluating rules, and rsigma-lsp for IDE support.</p></div><p class="paragraph" style="text-align:left;">💡 Accurately evaluating the full spectrum of what Sigma rules can express is quite complex, it’s pretty neat to read about how RSigma handles all of these conditional expressions, correlating across rules, etc. </p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/nikaiw/VMkatz?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">nikaiw/VMkatz</a><br>Extract Windows credentials directly from VM memory snapshots and virtual disks. A single static 2.5MB binary that can extract NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, directly from VM memory snapshots and virtual disks, no need to exfiltrate a massive VM file.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Solving the Vendor Dependency Problem in RE</a><br>Many enterprise applications ship with hundreds to thousands of vendor dependencies, which makes it annoying to locate and analyze the proprietary source code of the application. You drown in vendor code, not the exposed attack surface. Assetnote’s <a class="link" href="https://www.linkedin.com/in/patrikfehrenbach/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Patrik Grobshäuser</a> announces the release of <a class="link" href="https://github.com/assetnote/hyoketsu?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Hyoketsu</a>, an open-source tool that automatically filters vendor dependencies from Java JARs and .NET DLLs during reverse engineering by using Microsoft runtime detection (via PE header public key tokens), hash matching, and filename matching against a 13.3 GB pre-built SQLite database containing 12M+ DLLs and 14M+ JARs.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/p-e-w/heretic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">p-e-w/heretic</a><br>By Philipp Emanuel Weidmann: Fully automatic censorship removal for language models. Heretic removes censorship (aka &quot;safety alignment&quot;) from transformer-based language models without expensive post-training by combining an advanced implementation of directional ablation, also known as &quot;abliteration.” This approach creates a decensored model that retains as much of the original model&#39;s intelligence as possible.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/elder-plinius/OBLITERATUS?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">elder-plinius/OBLITERATUS</a><br>By <a class="link" href="https://x.com/elder_plinius?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Pliny the Liberator</a>: An open-source toolkit for removing refusal behaviors from LLMs via abliteration (surgically identifying and projecting out internal refusal representations without retraining). Every obliteration run with telemetry enabled contributes anonymous benchmark data to a crowd-sourced research dataset measuring refusal direction universality across 116+ models and 5 compute tiers</p><p class="paragraph" style="text-align:left;">Blog overview: <a class="link" href="https://awesomeagents.ai/news/obliteratus-strips-ai-safety-open-models?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">OBLITERATUS Strips AI Safety From Open Models in Minutes</a>, and pretty detailed Hugging Face guest post by Maxime Labonne on <a class="link" href="https://huggingface.co/blog/mlabonne/abliteration?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">abliteration here</a>, including code on Google Colab and in an LLM course on GitHub.</p><p class="paragraph" style="text-align:left;">💡 As open source models become better and better, not sure how I feel about removing “don’t cause harm” alignment training 😅 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/why-codex-security-doesnt-include-sast?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Why Codex Security Doesn’t Include a SAST Report</a><br>OpenAI describes why Codex Security doesn’t start by triaging SAST results, but instead starts with understanding the repository’s architecture and trust boundaries: they don’t want to overly influence where Codex looks, not all bugs are dataflow problems, and sometimes code appears to enforce a security check, but it doesn’t actually guarantee the property the system relies on.</p><p class="paragraph" style="text-align:left;">When Codex Security encounters a boundary that looks like “validation” or “sanitization,” it tries to bypass it:</p><ul><li><p class="paragraph" style="text-align:left;">Reading the relevant code path with full repository context, looking for mismatches between intent and implementation.</p></li><li><p class="paragraph" style="text-align:left;">Pulling out security-relevant code slices and writing micro-fuzzers for them.</p></li><li><p class="paragraph" style="text-align:left;">They give the model access to a Python environment with z3-solver for solving complicated input constraint problems.</p></li><li><p class="paragraph" style="text-align:left;">Executing hypotheses in a sandboxed validation environment to prove exploitability.</p></li></ul><p class="paragraph" style="text-align:left;">💡 The post is overall a good discussion of the space and outlines challenges for security scanners. I especially liked though the “how Codex validates” section, because it starts getting into some of Codex Security’s unique technical details.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cursor.com/blog/security-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Securing our codebase with autonomous agents</a><br><a class="link" href="https://linkedin.com/in/travismcpeak?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Travis McPeak</a> describes how Cursor built four security automation templates using Cursor Automations and a custom security MCP tool to handle securing their code at scale, as Cursor’s PR velocity has increased 5x in the past 9 months. The automations include: <b>Agentic Security Review</b> (blocks PRs with security issues), <b>Vuln Hunter</b> (scans existing code for vulnerabilities), <b>Anybump</b> (automatically patches dependencies using reachability analysis and opens PRs after tests pass), and <b>Invariant Sentinel</b> (monitors daily for drift against security/compliance properties). You can see their prompts on their marketplace pages.</p><p class="paragraph" style="text-align:left;">Their <a class="link" href="https://github.com/mcpeak/cursor-security-automation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">security MCP</a>, deployed as a serverless Lambda function, provides persistent data storage, deduplication of LLM-generated findings using Gemini Flash 2.5, and consistent Slack reporting across all agents. In the last two months, Agentic Security Review alone has run on thousands of PRs and prevented hundreds of security issues from reaching production.</p><p class="paragraph" style="text-align:left;">💡 I like the focus on <b>useful</b> <b>primitives</b> that empower you to build security tooling on top of: “For agents to be useful for security, they need: out-of-the-box integrations for receiving webhooks, responding to GitHub pull requests, and monitoring codebase changes, and a rich agent harness and environment (<a class="link" href="https://cursor.com/docs/cloud-agent?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">cloud agents</a> give them all the tools, skills, and observability that cloud agents have access to).</p><p class="paragraph" style="text-align:left;">I also wanted to call out the Invariant Sentinel, that’s very clever: what security properties about this repo should always be true? Did this most recent change violate that? I bet detecting drift like this catches some meaningful bugs.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://builders.ramp.com/post/100-vulnerabilities-patched-with-0-humans?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">We proactively fixed ~100 security issues in 6 days with 0 humans</a><br><a class="link" href="https://www.linkedin.com/in/eli-block/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Eli Block</a> describes how Ramp Security Engineering built a custom agent pipeline that autonomously found, validated, and fixed ~100 novel security issues in 6 days. Their pipeline starts off with a <i>coordinator</i> agent equipped with skills for each vulnerability category (e.g. IDOR, XSS, …), which launches <i>detector</i> agents in parallel, whose findings are then passed to an adversarial <i>manager</i> agent who checks for false positives (~40% false positive reduction in their sample set of testing).</p><p class="paragraph" style="text-align:left;">They found it was difficult to reproduce vulnerabilities with complex pre-conditions against a live Ramp deployment, so instead their validator agent takes reported findings and writes an integration test that reproduced the vulnerability that passes only if the endpoint was secure. Then the <i>fixer</i> agent can patch the vulnerability by following test-driven development on the previously written integration test.</p><p class="paragraph" style="text-align:left;">💡 Great write-up! Overall this agent pipeline follows a pretty standard structure (per bug class detectors → vet findings → try to reproduce / “prove” the issue → generate fix), but a few things stand out as unique and valuable insights:</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Detectors include real examples of that vulnerability <i>from Ramp’s code base</i>. I bet this allows the detectors to be much more precise and effective.</p></li><li><p class="paragraph" style="text-align:left;">Rather than trying to reproduce vulnerabilities in a live environment, they write integration tests that demonstrate the bug. As there are probably already test fixtures or other examples in the code the agent can borrow from, it makes sense that this method would often work in practice. This approach also has the added benefit that you now have a regression test for this bug coming back in the future. </p><ol start="1"><li><p class="paragraph" style="text-align:left;">So this leans into what models are good at (writing code) and future proofs the bug from coming back 👍️ </p></li><li><p class="paragraph" style="text-align:left;">I’ve been thinking about this approach for a bit now so it’s gratifying to see someone do it 🙂 </p></li></ol></li></ol><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Tech</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/vercel-labs/portless?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">vercel-labs/portless</a> - Replace port numbers with stable, named <code>.localhost</code> URLs for local development. </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/peakoss/anti-slop?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">peakoss/anti-slop</a> - A GitHub action that detects and automatically closes low-quality and AI slop PRs.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/C9coc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Meta created ‘playbook’ to fend off pressure to crack down on scammers, documents show</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.resistandunsubscribe.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Resist and Unsubscribe</a> - Scott Galloway’s initiative to influence politics by voting with your wallet.</p></li><li><p class="paragraph" style="text-align:left;">Andrej Karpathy - <a class="link" href="https://karpathy.ai/jobs/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">US Job Market Visualizer</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.dwarkesh.com/p/dow-anthropic?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">The most important question nobody&#39;s asking about AI</a> - Why Dwarkesh Patel is happy the Anthropic fight is happening now.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.thestack.technology/mckinsey-ai-agent-hacked-lilli/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Startup&#39;s agent hacked McKinsey AI - exposing huge volumes of sensitive data</a> - $20 in tokens and two hours to expose 46 million chat logs, 728,000 private files and proprietary RAG documentation. <a class="link" href="https://news.ycombinator.com/item?id=47333627&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">HN discussion</a>.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.forbes.com/sites/the-wiretap/2026/03/10/undercover-cops-ai-teenager-catches-pedophile?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Undercover Cop Generated An AI Teenager To Catch Pedophiles</a> - Apparently AI has “been a boon for child abuse investigators,” as when asked for selfies they don’t need to use real images.</p><ul><li><p class="paragraph" style="text-align:left;">Related: In 2018, Microsoft volunteers worked with nonprofit Street Grace to create an AI chatbot that interacts with people who click on decoy advertisements on trafficking sites.</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/4b3rHqWOg2I?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Ed Sheeran on Friends Keep Secrets</a> - Quickly creating a song from scratch with Benny Blanco. Wow, super cool 😍 </p></li><li><p class="paragraph" style="text-align:left;">Kai Lentit - <a class="link" href="https://www.youtube.com/watch?v=xE9W9Ghe4Jk&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Shipping a button in 2026…</a> 😂 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/8zMowckwKK4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">This infinite drawing canvas is insane</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">Politics</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/u40U4?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Foreign hacker in 2023 compromised Epstein files FBI held</a> - “The hacker expressed disgust at the presence of child abuse images on the device and left a message threatening to turn its owner over to the FBI. Bureau officials defused the situation by convincing the hacker that they actually were the FBI.” 😂 </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/MeUCc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Putin can’t survive without war</a> - The article argues that Russia&#39;s war in Ukraine has transformed the country into a &quot;necropolis&quot; where death has become central to its economy, culture, and social fabric. The war sustains a &quot;deathonomics&quot; model where provincial economies depend on recruitment bonuses and death payments (sometimes reaching $60,000). 40% of state spending now flows to military efforts. Really tough read on the impact on every day Russians :(</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/shorts/siIXYtutmW8?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">Trump in November 2011</a>: “Our president (Obama) will start a war with Iran because he has absolutely no ability to negotiate… The only way he figures he’s going to get reelected is to start a war with Iran.”</p></li><li><p class="paragraph" style="text-align:left;">NBC - <a class="link" href="https://www.nbcnews.com/politics/donald-trump/trump-decided-strike-iran-rcna261205?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">How Trump decided to strike Iran</a> - “Before the U.S. and Israel launched their aerial assault, the CIA concluded that if the supreme leader, Ayatollah Ali Khamenei, was killed, he could be replaced by equally hard-line officials from within the regime, according to two people familiar with the matter.”</p><ul><li><p class="paragraph" style="text-align:left;">“Treasury Secretary Scott Bessent told Congress last month that <b>the U.S. had purposely touched off an economic crisis in Iran</b> that led to the massive street protests early this year that jarred the regime. By creating a dollar shortage in Iran, the U.S. forced Iran to print money, sparking inflation and stoking internal enmity toward the leadership, Bessent said.”</p></li><li><p class="paragraph" style="text-align:left;">“…Trump flew to Mar-a-Lago, where he monitored the strike in the company of senior advisers, as he has done for several foreign strikes this term. He also made time Saturday to attend a political fundraising event at his seaside resort.”</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-320-ramp-s-security-agents-how-datadog-caught-malicious-oss-contributions-obliterating-model-refusals" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b3d70b5f-6d1a-4964-aa44-ece2a43289ee&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #319 - AI is Eating Security, BSidesSF &amp; RSA, Claude Finds Firefox 0-days</title>
  <description>What does security look like in 5 years? Let&#39;s hang out in San Francisco and avoid badge scans, Opus 4.6 finds 22 vulns and auto-writes 2 exploits</description>
  <link>https://tldrsec.com/p/tldr-sec-319</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-319</guid>
  <pubDate>Thu, 12 Mar 2026 14:30:00 +0000</pubDate>
  <atom:published>2026-03-12T14:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🌉 BSidesSF and RSA</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">As the gentle blooming of flowers announces spring, and piles of orange leaves welcome fall, so too does the torrential downpour of security vendor emails and LinkedIn DMs “just touching base” herald the arrival of… RSA!</p><p class="paragraph" style="text-align:left;">It’d be great to cross paths if you’re in town. Here’s what I’m up to:</p><p class="paragraph" style="text-align:left;"><b>Pre-BSidesSF</b> - Friday March 20th - <a class="link" href="https://luma.com/ljd8kxzr?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">tl;dr sec Community Kickoff</a>. <i>tl;dr sec</i>’s first community event 😍 I’m excited about it, there’s going to be cool people, I’ve artisanally curated local SF food options, and we’ll have a fireside chat about AI and security builders.</p><p class="paragraph" style="text-align:left;">We’ll also have <i>tl;dr sec</i> t-shirts and a totally new, never before seen sticker…</p><p class="paragraph" style="text-align:left;">If you can’t make it, you can try to get a t-shirt or stickers by a) finding me or b) Semgrep at <a class="link" href="https://semgrep.dev/events/rsa/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">another event</a>.</p><p class="paragraph" style="text-align:left;"><b>BSidesSF</b> - I’m joining my friends on an <a class="link" href="https://bsidessf2026.sched.com/event/2E1eG/state-of-absolute-appsec-nulb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Absolute AppSec panel</a>, and will generally be around. </p><p class="paragraph" style="text-align:left;">Also check out talks by my colleagues Claudio and Romain on <a class="link" href="https://bsidessf2026.sched.com/event/2E1hn/the-great-sast-dissonance-how-to-please-every-audience-at-scale-nulb?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">scaling SAST rule writing with AI</a>, Katie Paxton-Fear (InsiderPhD) in a <a class="link" href="https://bsidessf2026.sched.com/event/2E1hY/ai-huh-what-is-it-good-for-absolutely-nothin?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">birds of a feather discussion on AI</a>, or Brandon Wu on how to combine AI and static analysis to <a class="link" href="https://bsidessf2026.sched.com/event/2E1hq/one-thousand-and-one-ai-prevented-cves-vibe-coding-a-whole-new-supply-chain-defense?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">process CVEs at scale</a>.</p><p class="paragraph" style="text-align:left;"><b>RSA</b> - I’m organizing a mini con / lightning talks (<a class="link" href="https://www.decibel.vc/rsac-founder-festival?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Unsupervised + Unhinged</a>) with Daniel Miessler and Decibel. Wed March 25 10am - noon. You can register for their overall program <a class="link" href="https://luma.com/7pw1xhoe?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">here</a>. More info coming soon!</p><p class="paragraph" style="text-align:left;">Also, I’ve made it ma, my name is on an announcement graphic alongside The Chainsmokers 😂 😂 </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5800b12d-d4c7-48f4-bccf-19246c788c08/image.png?t=1773296265"/></div><p class="paragraph" style="text-align:left;"> </p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Securing AI Agents 101</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">AI agents are changing how work gets done. They take on tasks, orchestrate tools, and drive outcomes across environments. </p><p class="paragraph" style="text-align:left;">Securing AI Agents 101 is a one-page resource to help teams build a clear understanding of what AI agents are, how they operate, and where key security considerations show up.</p><p class="paragraph" style="text-align:left;">Inside, you’ll find:</p><ul><li><p class="paragraph" style="text-align:left;">What makes an AI agent different from traditional tools</p></li><li><p class="paragraph" style="text-align:left;">Top risks to watch, from shadow AI to excessive permissions</p></li><li><p class="paragraph" style="text-align:left;">Four key questions to assess agent usage and exposure</p></li></ul><p class="paragraph" style="text-align:left;">Download the security flashcard and get up to speed quickly.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://www.wiz.io/lp/securing-ai-agents-101?utm_source=tldrsec&utm_medium=paid-email&utm_campaign=FY26Q3_INB_FORM_Securing-AI-Agents-101&sfcid=701Py00000RTEWMIA5&utm_term=FY27Q1-tldrsec-nl&utm_content=AI-Agents-101" target="_blank" rel="noopener noreferrer nofollow"><b>Get the Flashcard</b></a><b> </b><b>👈</b></h2></div><p class="paragraph" style="text-align:left;">Things are progressing so fast in this space, great to have a one pager to quickly get up to speed 👍️ </p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/1Password/load-secrets-action?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">1Password/load-secrets-action</a><br>Load secrets from 1Password into your GitHub Actions jobs using <a class="link" href="https://developer.1password.com/docs/service-accounts?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Service Accounts</a> or <a class="link" href="https://developer.1password.com/docs/connect?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">1Password Connect</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.timcappalli.me/p/passkeys-prf-warning?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Please, please, please stop using passkeys for encrypting user data</a><br><a class="link" href="https://www.linkedin.com/in/timcappalli/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Tim Cappalli</a> warns companies against using WebAuthn&#39;s PRF (Pseudo-Random Function) extension to derive encryption keys for user data, because it couples authentication credentials with data encryption in ways users don&#39;t understand. When users delete a passkey from credential managers like Apple Passwords, Google Password Manager, or Bitwarden, they receive no warning that they&#39;re permanently destroying access to encrypted photos, message backups, documents, crypto wallets, or other critical data.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.uber.com/blog/superuser-gateway-guardrails/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Superuser Gateway: Guardrails for Privileged Command Execution</a><br>Uber’s <a class="link" href="https://www.linkedin.com/in/psuben/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Pavi Subenderan</a> and <a class="link" href="https://www.linkedin.com/in/jyoti-grewal/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Jyoti Grewal</a> describe Superuser Gateway, a system built to replace direct superuser CLI access with a peer-reviewed, auditable workflow for dangerous operations on production systems (e.g. Google Cloud Storage, OCI, and HDFS). Engineers now submit commands via superuser-cli, which generates a PR in a Git repository where automated CI jobs perform syntax validation, permission checks, and impact estimation (like calculating files affected by <code>rm -r</code>), before a peer approves and a backend service executes the command remotely. This architecture removes superuser credentials from individual engineers&#39; machines entirely, ensuring all privileged operations flow through mandatory peer review while maintaining operational velocity for on-call scenarios.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">🚨<b> </b><b>Most Confident Organizations Have 2x Higher AI Incident Rates </b>🚨</h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Counterintuitive finding from 205 security leaders: organizations most confident in their AI deployments experienced 2x the incident rate of less confident peers. Meanwhile, 43% report AI making infrastructure changes monthly without oversight, and 7% don&#39;t even track autonomous changes at all.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://goteleport.com/resources/surveys/infrastructure-identity-survey-2026/?utm_campaign=AI&utm_content=webpage&utm_medium=partner&utm_source=tldrsec" target="_blank" rel="noopener noreferrer nofollow"><b>See the Confidence Gap Data</b></a><b> 👈</b></h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Hm I’m curious about (the lack of) tracking autonomous changes. Also “3 in 5 orgs have had or suspect an AI-related incident.” 🤔 Identity is still key.</p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://kknowl.es/posts/untangling-microsoft-batch?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Untangling Microsoft Graph&#39;s $batch requests in Burp</a><br>Requests to Microsoft Graph’s <code>$batch</code> endpoint bundle several API calls into one JSON object, which makes analyzing Azure Portal traffic difficult, since underlying API calls for requests to the <code>$batch</code> endpoint are not individually logged. <a class="link" href="https://www.linkedin.com/in/kaknowles/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Katie Knowles</a> has released the <a class="link" href="https://github.com/siigil/burp-extensions/blob/main/graph_batch_parser.py?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">graph_batch_parser.py</a> Burp Suite extension to speed up analysis of <code>$batch</code> requests. The extension processes <code>$batch</code> requests into a set of synthetic request/response pairs that can then be reviewed in the “Graph Batch” tab, as well as Burp’s Site Map.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.plainenglish.io/stop-enabling-every-aws-security-service-fb171635a25c?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Stop Enabling Every AWS Security Service</a><br><a class="link" href="https://linkedin.com/in/sena-yakut?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Sena Yakut</a> argues against enabling every AWS security service at once, advocating instead for a risk-based approach that starts with threat modeling your architecture (what are the risks we need to control for?), understanding team behaviors (who has admin privileges? Are there shared accounts or credentials?), and identifying critical breaking points (where small mistakes can cause major damage) before selecting controls. Avoid service overlap with existing third-party tools (like SIEMs) so you’re not overwhelmed by alerts, and evaluate usage-based pricing- based on your environment, certain managed services might not fit within your budget, but building custom automations with Lambda and EventBridge can fulfill a similar purpose. Use AWS SSO (IAM Identity Center) over individual IAM users.</p><p class="paragraph" style="text-align:left;"></p></div><div id="blue-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Blue Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/MatheuZSecurity/ksentinel?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">MatheuZSecurity/ksentinel</a><br>By <a class="link" href="https://linkedin.com/in/matheus-alves-212775208?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">MatheuZ</a>: A Linux kernel module that monitors syscall table integrity and critical kernel functions to detect rootkit modifications like ftrace hooks, kprobes, and syscall table hijacking.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit</a><br>Google&#39;s Google Threat Intelligence Group (GTIG) discovered the &quot;Coruna&quot; iOS exploit kit containing five full exploit chains and 23 exploits targeting iOS 13.0 through 17.2.1, initially used by a surveillance vendor customer, then by Russian espionage group UNC6353 in watering hole attacks against Ukrainian users, and finally by Chinese financially-motivated actor UNC6691 in broad campaigns.</p><p class="paragraph" style="text-align:left;">Additional technical analysis and IOCs by <a class="link" href="https://linkedin.com/company/iverify-io?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">iVerify</a> in their <a class="link" href="https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">write-up here</a>.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a8eb2a4d-5ce8-4a77-856c-41ed12623be8/image.png?t=1773270637"/></div></div><p class="paragraph" style="text-align:left;">💡 Word on the street is that these exploits may be from the Trenchant guy who sold the iOS exploit chain to a Russian exploit broker, which then proliferated to these other groups.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://detect.fyi/detection-pipeline-maturity-model-076984779651?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Detection Pipeline Maturity Model</a><br><a class="link" href="https://www.linkedin.com/in/scott-plastine-b6767a11/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Scott Plastine</a> presents a five-level maturity model for detection pipelines, progressing from analysts manually checking security consoles (None) to a risk-based correlation engine that aggregates both commercial security tools and custom telemetry analytics (Standard+). The model highlights the differences between closed-source security tool analytics (endpoint tools like CrowdStrike, cloud tools like AWS GuardDuty) and custom analytics built on raw telemetry (Windows Event Logs, AWS CloudTrail), and recommends routing all detections through a risk engine that scores and correlates events across assets and users before alerting. </p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">Advanced maturity adds atomic high-fidelity detections and risk-based custom rules, while Leading maturity incorporates data science-backed outlier detection (using platforms like Databricks or Dataiku) and deception techniques like honeytokens. Scott recommends reducing reliance on unmeasurable closed-source analytics by lowering their risk scores in the correlation engine while building validated custom detections that adversaries can&#39;t test against.</p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/0xbbuddha/notion?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">0xbbuddha/notion</a><br>A Mythic C2 profile that uses Notion as a covert communication channel. Agents communicate by reading/writing pages in a shared Notion database, making C2 traffic indistinguishable from normal SaaS usage — a Living off Trusted Sites (LoTS) technique.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/vulhunt-re/vulhunt?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">vulhunt-re/vulhunt</a><br><a class="link" href="https://www.linkedin.com/company/binarlyinc/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">BINARLY</a> released VulHunt Community Edition, an open-source vulnerability hunting framework for analyzing software binaries and UEFI firmware, built on their Binary Analysis and Inspection System (BIAS).</p><p class="paragraph" style="text-align:left;">See also their community-contributed <a class="link" href="https://github.com/vulhunt-re/rules?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">rules</a> repo (currently only 3 rules) and <a class="link" href="https://github.com/vulhunt-re/skills?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Skills</a> repo, which contains skills for decompiling functions, finding functions or call sites, performing data flow analysis, searching code/byte patterns, etc. powered by VulHunt MCP tools.</p><p class="paragraph" style="text-align:left;">💡 Also congrats to my friend <a class="link" href="https://www.linkedin.com/in/gwenythcastro?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Gwen Castro</a> who recently became CEO of BINARLY 🥳 </p><p class="paragraph" style="text-align:left;"></p></div><div id="ai-security" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks </b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://rankclaw.com/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">RankClaw</a> - Web app to scan AI skills for security risks before you install them.</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://hero.permiso.io/securing-ai-agents-in-the-enterprise?utm_source=tldrsec&utm_medium=sponsored&utm_campaign=ai&utm_content=newsletter" target="_blank" rel="noopener noreferrer nofollow">Securing AI Agents in the Enterprise: 5 Use Cases</a></b> - AI agents are now in enterprise environments; running workflows, accessing data, and interacting with other services through roles, tokens, and service accounts. This guide breaks down 5 use cases teams must solve to safely deploy agents across cloud and SaaS environments.* </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://honnibal.dev/blog/clownpocalypse?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">The looming AI clownpocalypse </a>- “What happens when we reach the tipping point where exploits become cheaper to autonomously develop than they yield on average?”</p></li></ul><p class="paragraph" style="text-align:left;"><sup>*Sponsored</sup></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.philvenables.com/post/cybersecurity-s-need-for-speed-where-to-find-it?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity’s Need for Speed & Where To Find It</a><br><a class="link" href="https://linkedin.com/in/philvenables?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Phil Venables</a> applies Stewart Brand&#39;s <a class="link" href="https://sketchplanations.substack.com/p/pace-layers?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Pace Layers framework</a> to cybersecurity, arguing that organizations must accelerate their security OODA loops to outpace AI-enabled attackers. </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The post covers 11 areas we can speed up, including: </p></div><ul><li><p class="paragraph" style="text-align:left;">Streamline software delivery pipelines - fix faster with coding agents, Skill packs for threat modeling, security analysis, invariant maintenance.</p></li><li><p class="paragraph" style="text-align:left;">Implement autonomic (not just automated) security operations.</p></li><li><p class="paragraph" style="text-align:left;">Systematize threat intelligence into macro (strategic TTPs) and micro (IOCs/signatures) feeds.</p></li><li><p class="paragraph" style="text-align:left;">&quot;Shift down&quot; security controls into lower platform layers for security-by-default.</p></li><li><p class="paragraph" style="text-align:left;">Improve control reliability engineering to catch silent failures.</p></li><li><p class="paragraph" style="text-align:left;">Use deception/moving target defenses to slow attackers while defenders speed up their response cycles.</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://drive.google.com/file/d/1hU3Vxm8uyU39lgfjIRfhKoTU6xigKGGy/view?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">AI is Eating Security: What does security look like in five years?</a><br>Great talk by <a class="link" href="https://www.linkedin.com/in/alexstamos/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Alex Stamos</a> at Reddit’s SnooSec last week. I liked his slide on how AI has already impacted security teams across the SOC, security engineering, AppSec, DFIR and threat intel, etc. His high confidence predictions.</p><ul><li><p class="paragraph" style="text-align:left;">Smaller, narrower teams - Fewer, more senior people on top of AI agents.</p></li><li><p class="paragraph" style="text-align:left;">Building on Legos - Companies will build on vendor-provided specialized components.</p></li><li><p class="paragraph" style="text-align:left;">VulnOps - The speed of vuln discovery and exploitation means every company needs to worry about 0-days.</p></li><li><p class="paragraph" style="text-align:left;">Humans will be supervising machine &lt;&gt; machine conflict.</p></li></ul><p class="paragraph" style="text-align:left;">&quot;Five to ten years ago, only ~25 of the Fortune 500 had to seriously worry about 0-day. In 6-9 months it&#39;ll be everyone.&quot;</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/codex-security-now-in-research-preview?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Codex Security: now in research preview</a><br>OpenAI announces Codex Security (the artist formerly known as Aardvark). “We’ve reduced the rate of findings with over-reported severity by more than 90%, and false positive rates on detections have fallen by more than 50% across all repositories.” Codex Security is rolling out in research preview to ChatGPT Pro, Enterprise, Business, and Edu customers via Codex web with <i>free usage for the next month</i>.</p><p class="paragraph" style="text-align:left;">Codex works by first generating a threat model, searching for vulnerabilities, where possible testing the findings dynamically in sandboxed validation environments, and then attempts to patch issues in a way that aligns with system intent and surrounding behavior. “Over the last 30 days, Codex Security scanned more than 1.2 million commits across external repositories in our beta cohort, identifying 792 critical findings and 10,561 high-severity findings.” Codex Security found critical vulnerabilities in OpenSSH, GnuTLS, PHP, libssh, Chromium, and more.</p><p class="paragraph" style="text-align:left;">💡This is cool work by a smart team. I’m going to point out a few things that aren’t clear from the stats shared though: “50% fewer false positives” - does that mean it went from tens of thousands to thousands of FPs? In other words, 50% fewer could still be a bad N. Also how are they calculating FPs and how do they know the FPs went down that percent, have humans triaged all the findings so there’s ground truth?</p><p class="paragraph" style="text-align:left;">Regarding 792 critical and 10K high severity findings, that’s like reporting the number of findings directly out of your security scanner- yes it sounds good, but how many of those are true vs false positives? What vulnerability classes? How many repos and what was the tech stack breakdown of those repos? Are they actively maintained/popular? </p><p class="paragraph" style="text-align:left;">Again, I’ve met the Codex Security team and they’re <i>super</i> sharp, I just think too often people read numbers like these and don’t think about them carefully, so I wanted to give examples of context that would be useful to know.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.anthropic.com/news/mozilla-firefox-security?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Partnering with Mozilla to improve Firefox’s security</a><br>Anthropic announces Claude Opus 4.6 autonomously found 22 vulnerabilities in Firefox over two weeks, 14 of which Mozilla assigned High severity. The team also tested (<a class="link" href="https://red.anthropic.com/2026/exploit/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">blog</a>) if Claude could not only find vulnerabilities, but <i>create exploits</i> for them. They gave Claude a VM and a task verifier, and gave it 350 chances to succeed. Claude only successfully created working exploits in 2 of the attempts, costing $4,000 in API credits. Note also that the exploit only works within a testing environment that removes some of the security features of modern web browsers (e.g. it doesn’t escape the browser sandbox).</p><p class="paragraph" style="text-align:left;">Takeaways: Claude is better at finding bugs than writing exploits (as of today). But frontier LLMs <i>are able to write working exploits today</i> for a pretty complicated bug and target (Firefox, a well-tested, modern browser).</p><p class="paragraph" style="text-align:left;">Neat work by Anthropic’s Evyatar Ben Asher, <a class="link" href="https://www.linkedin.com/in/keane-lucas/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Keane Lucas</a>, Nicholas Carlini, <a class="link" href="https://www.linkedin.com/in/newton-cheng-71084a16b/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Newton Cheng</a>, and <a class="link" href="https://www.linkedin.com/in/daniel-freeman-6952136/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Daniel Freeman</a>.</p><p class="paragraph" style="text-align:left;">💡Pretty cool write-up of Claude’s process and methodology, worth a read. It’s great to see labs evaluating model capabilities across several axes (not just finding bugs, but writing exploits). This gives us defenders insight into the timelines and cost of the likely upcoming vulnpocalypse where the cost of findings bugs continues to decrease. I’ll also note once more the value of having a deterministic “verifier” in making agents much more effective.</p><p class="paragraph" style="text-align:left;">Also: there’s a bunch we don’t know about this research: how much total was spent finding the bugs? How long did it take? What was the false positive rate? How much human triage time was spent? etc. etc.</p><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">[un]prompted</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://notebooklm.google.com/notebook/78ee3710-1741-488d-af06-159f518e9510?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">[un]prompted NotebookLM</a><br>The full transcripts and slides for every [un]prompted talk were uploaded to a NotebookLM so that you can query any of the source material. Awesome idea, love it. Great work by <a class="link" href="https://www.linkedin.com/in/leerob/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Rob T. Lee</a>, <a class="link" href="https://www.linkedin.com/in/juliemichellemorris/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Julie Michelle Morris</a>, and <a class="link" href="https://www.linkedin.com/in/emanuelgawrieh/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Emanuel Gawrieh</a> and <a class="link" href="https://www.linkedin.com/in/dragosruiu/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Dragos Ruiu</a>. Shout-out Gadi Evron <a class="link" href="https://www.linkedin.com/posts/gadievron_would-you-like-to-chat-with-unprompted-activity-7435621699724935168-7b2u?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">for sharing</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://docs.google.com/presentation/d/1GryXo01btTcXv7yhRCqt6bbsVgRiarjfwzF8xi2b1ns/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">From Source to Sink: How to Improve LLM First-Party Vuln Discovery</a><br>Excellent [un]prompted talk by my Netflix friends <a class="link" href="https://www.linkedin.com/in/scott-behrens-6bb8611/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Scott Behrens</a> and <a class="link" href="https://www.linkedin.com/in/just/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Justice Cassel</a> in which they took a data driven approach to investigating a number of questions regarding using AI for finding vulnerabilities I’ve had for awhile like: is it better to have a single superagent or multiple more focused agents? Should the agent find and then triage issues or should there be a separate post-processing triage step? </p><p class="paragraph" style="text-align:left;">They share the precision, recall, and cost (I want to see more people do this) of various approaches, an excellent architecture diagram on slide 23, and have released a <a class="link" href="https://github.com/Netflix-Skunkworks/railguard-skill?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">railguard-skill</a> GitHub repo with implementations of the various scanning approaches (including vulnerability finding skills!) and utilities for benchmarking.</p><p class="paragraph" style="text-align:left;">💡 In my opinion this is a great example of research that contributes back to the security community: it tests a number of hypotheses (which architectures/approaches are most effective?) and puts hard data behind them AND shares the code and benchmarking scripts to reproduce it. More like this please 👏 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://docs.google.com/presentation/d/1k4sp0NpIgjY2HdP9dgRCEDKRNvj-DSdZUoDIsJ3JUfk/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">How we made Trail of Bits AI-Native (so far)</a><br>This [un]prompted talk by <a class="link" href="https://www.linkedin.com/in/danguido/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Dan Guido</a> is probably the best talk or resource I’ve seen on how to make your company AI-native. “AI isn&#39;t a feature you ‘adopt.’ It is a force that commoditizes effort and shortens the half-life of best practices… The core idea is a compounding operating system built from incentives, defaults, guardrails, and verification loops that let humans and autonomous agents ship high-rigor work at dramatically higher throughput. The talk covers the concrete artifacts that make this real: internal and external skills repositories, a curated marketplace for third-party skills, opinionated configuration baselines, and sandboxing patterns.” </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/trailofbits/publications/tree/master/presentations/How%20we%20made%20Trail%20of%20Bits%20AI-Native%20%28so%20far%29?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">GitHub link</a> with bigger screenshots (AI Maturity Matrix), <a class="link" href="https://www.youtube.com/watch?v=ysWMHozWDwA&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">YouTube recording</a>.</p><p class="paragraph" style="text-align:left;">💡I especially like that Dan called out the resistance people have making this transition (Am I being replaced? What does it mean for my identity if AI can do parts of my job better than I can?) and how to support them.</p><p class="paragraph" style="text-align:left;">The AI Maturity Matrix and measuring adoption slides as well as how to create an adoption engine via hackathons I thought were quite practical and actionable 👌</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Dropout - <a class="link" href="https://youtube.com/shorts/6cliVxOGNwc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Brennan Lee Mulligan thanks the entire Greek Pantheon</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.privacyguides.org/en/activism/toolbox?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Privacy Activist Toolbox</a> by Privacy Guides - A resource for anyone interested in becoming a better privacy rights activist, or anyone who wants to start advocating for privacy rights.</p></li><li><p class="paragraph" style="text-align:left;">Chinese hackers likely <a class="link" href="https://edition.cnn.com/2026/03/05/politics/fbi-investigating-cyber-breach-critical-surveillance-network?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">compromised an FBI network used to manage wiretaps and intelligence surveillance warrants</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.404media.co/cbp-tapped-into-the-online-advertising-ecosystem-to-track-peoples-movements/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">An internal DHS document obtained by 404 Media shows</a> for the first time Customs and Border Protection (CBP) used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar tools.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/rkt7B?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Meta’s new AR glasses are sending all sorts of sensitive videos</a> to their human workforce in Kenya. “We see everything – from living rooms to naked bodies. Meta has that type of content in its databases. People can record themselves in the wrong way and not even know what they are recording…Clips that could trigger ‘enormous scandals’ if they were leaked.”</p><ul><li><p class="paragraph" style="text-align:left;">One annotator sums it up: “You think that if they knew about the extent of the data collection, no one would dare to use the glasses”.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/KLQSf?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Iranian Hacking Groups Go Dark During US, Israeli Military Strikes</a> - “A popular Iranian prayer app, BadeSaba, was reportedly hijacked to tell its users that “help has arrived” and then urged Iranian army members to surrender. In the early hours of fighting, pro-regime news agencies were compromised and Iranian television stations were repurposed to broadcast videos of President Donald Trump and Israel’s Benjamin Netanyahu.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cyberscoop.com/cisa-personnel-cuts-trump-second-term-analysis/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Across party lines and industry, the verdict is the same: CISA is in trouble</a> - The agency lost a third of its people in a year. Now industry and lawmakers on both sides say it&#39;s unprepared for a potential crisis. “If we got into a major conflict, let’s say, with China, and they start triggering Volt Typhoon-related malware, are we organized and ready to roll? I don’t think so.” “We’re asking states to do a job they’re not resourced to do, while weakening the one federal agency designed to help them.”</p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">🎶 Suno - <a class="link" href="https://suno.com/song/e2b48a04-8a1b-42ca-900b-730de663245f?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">So Much Drama in the Frontier Labs</a> - Epic rap</p></li><li><p class="paragraph" style="text-align:left;">Techdirt’s Mike Masnick on the <a class="link" href="https://www.techdirt.com/2026/03/02/openais-red-lines-are-written-in-the-nsas-dictionary-where-words-mean-what-the-nsa-wants-them-to-mean/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">recent OpenAI/Anthropic/U.S. government situation</a>, and on the subtlety of what specific words actually mean from a legal and precedent point of view.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/watch?v=K6CCw1DK1EQ&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Theo on the ^ drama</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://danielmiessler.com/blog/bitter-lesson-engineering?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Bitter Lesson Engineering</a> - Daniel Miessler argues that instead of telling AI how to do things, instead tell them what outcome you want.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/googleworkspace/cli?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">googleworkspace/cli</a> - One command-line tool for Drive, Gmail, Calendar, Sheets, Docs, Chat, Admin, and more. Dynamically built from Google Discovery Service. Includes AI agent skills.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://justin.poehnelt.com/posts/rewrite-your-cli-for-ai-agents?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">You need to rewrite your CLI for AI agents</a> - Justin Poehnelt on his thoughts and lessons learned building the Google Workspace CLI. Follow-up post: <a class="link" href="https://justin.poehnelt.com/posts/mcp-abstraction-tax?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">The MCP Abstraction Tax</a>.</p></li><li><p class="paragraph" style="text-align:left;">You can now run <a class="link" href="https://docs.aws.amazon.com/lightsail/latest/userguide/amazon-lightsail-quick-start-guide-openclaw.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">OpenClaw on AWS via Lightsail</a></p></li><li><p class="paragraph" style="text-align:left;">FT - <a class="link" href="https://archive.is/wXvF3?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Amazon holds engineering meeting following AI-related outages</a> - “There had been a ‘trend of incidents’ in recent months, characterized by a ‘high blast radius’ and ‘Gen-AI assisted changes’ among other factors. Junior and mid-level engineers will now require more senior engineers to sign off any AI-assisted changes.</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/pawelhuryn/status/2031629378547769446?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">Pawel Huryn on some additional backstory</a> - In November 2025 Amazon mandated Kiro as their only AI coding tool and set an 80% weekly usage target. </p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-319-ai-is-eating-security-bsidessf-rsa-claude-finds-firefox-0-days" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=fdf9c009-1e03-4f1f-b275-1af6ba596589&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>[tl;dr sec] #318 - Unprompted Talk Summaries, AI Bot Hacking GitHub Actions, AI Skills &amp; Semgrep Rules</title>
  <description>Slides + notes for the CodeMender and AI for Shai-Hulud response talks, an AI bot was autonomously hacking GitHub Actions, security-focused Skills and AI anti-pattern Semgrep rules</description>
  <link>https://tldrsec.com/p/tldr-sec-318</link>
  <guid isPermaLink="true">https://tldrsec.com/p/tldr-sec-318</guid>
  <pubDate>Thu, 05 Mar 2026 15:30:00 +0000</pubDate>
  <atom:published>2026-03-05T15:30:00Z</atom:published>
    <dc:creator>Clint Gibler</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Hey there,</p><p class="paragraph" style="text-align:left;">I hope you’ve been doing well!</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">🤖 [un]prompted</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">This week I had a blast at [un]prompted, the AI for security practitioners conference.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/gadievron/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Gadi Evron</a> assembled an incredible program committee that I was very fortunate to play a small role in. <a class="link" href="https://www.linkedin.com/in/zollman/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Aaron Zollman</a> and many others put in countless hours in making this a great event.</p><p class="paragraph" style="text-align:left;">And it showed, I think [un]prompted had one of the highest quality density in both talks and attendees of conferences I’ve attended.</p><p class="paragraph" style="text-align:left;">Some anecdotes:</p><ul><li><p class="paragraph" style="text-align:left;">I met a number of people whose work I’ve been a fan of for some time, which was super cool. </p></li><li><p class="paragraph" style="text-align:left;">Overheard: “…and that’s how I got RCE on a satellite, and was basically able to make it do anything.”</p></li><li><p class="paragraph" style="text-align:left;">I met someone who spent an internship looking for gold (not a metaphor).</p></li><li><p class="paragraph" style="text-align:left;">Some people came up and said kind words about <i>tl;dr sec</i> 🥰 Which means a lot, and keeps me going all of those cold winter nights, huddled alone writing away by a small fire, kept warm solely by the heat of my laptop and fear of irrelevance.</p></li><li><p class="paragraph" style="text-align:left;">Someone showed me their beautiful vibe coded Claude app dashboard estimating the stress/years of life toll of working in that environment, and comparing it to compensation.</p></li><li><p class="paragraph" style="text-align:left;">One person said my including their work in tl;dr sec helped with their visa application 🤯 Very humbling.</p></li><li><p class="paragraph" style="text-align:left;">Cheering on my friends who gave an excellent LLMs + SAST talk, and then seeing some of the online comments after (paraphrased), “Damn, what is Netflix putting in the food, those guys are jacked.” (Narrator: indeed they are)</p></li></ul><p class="paragraph" style="text-align:left;">There’s so much technical content I want to include from the conference, but I don’t have time to gather and organize it all before I need to send this out.</p><p class="paragraph" style="text-align:left;">I’ll share the recordings once they’re live, which you should definitely check out.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> </b><b>Stop the Google Workspace Security </b><br><b>Whack-a-Mole</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Most security teams don’t have a talent problem; they have a toil problem. From triaging user-reported phishing reports to chasing questionable OAuth grants to reviewing risky file sharing, your headcount is being swallowed by fragmented consoles and manual work. Material Security unifies your cloud workspace security, automating detection and response across email, files, and accounts. From stopping malicious email to revoking over-privileged app permissions without breaking workflows, Material simplifies SecOps. Stop scaling your team just to manage the noise. Focus on strategy, not ticket backlogs.</p><h2 class="heading" style="text-align:center;"><b>👉 </b><a class="link" href="https://material.security/lp-cloud-office-security?utm_source=third-party&utm_medium=email&utm_campaign=20260305-tldrsec" target="_blank" rel="noopener noreferrer nofollow"><b>See the Material Difference</b></a><b> 👈</b></h2></div><p class="paragraph" style="text-align:left;">There are definitely a lot of toil-heavy aspects of monitoring and securing Google Workspace 🙃 Material has some nifty features, I got a nice walk through you can <a class="link" href="https://www.youtube.com/watch?v=mpwvJEX1p9s&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">see here</a>.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">AppSec</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://eprint.iacr.org/2026/058?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers</a><br>ETH’s Matteo Scarlata et al analyzed the cryptographic security of Bitwarden, LastPass, and Dashlane against a fully malicious server threat model, discovering 12 attacks against Bitwarden, 7 against LastPass, and 6 against Dashlane that violate their &quot;Zero Knowledge Encryption&quot; claims. The attacks range from targeted vault integrity violations to complete organizational vault compromise with password recovery.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Google API keys weren&#39;t secrets, but then Gemini changed the rules</a><br>Truffle Security&#39;s <a class="link" href="https://linkedin.com/in/josephwleon?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Joe Leon</a> describes how Google spent over a decade telling developers that Google API keys (like those used in Maps, Firebase, etc.) are not secrets. But that&#39;s no longer true: Gemini accepts the same keys to access your private data. Truffle Security scanned millions of websites (November 2025 Common Crawl dataset) and found nearly 3,000 Google API keys that now also authenticate to Gemini. With a valid key, an attacker can access uploaded files, cached data, and charge LLM-usage to your account. They found many working keys, including Google’s old public API keys that could be used to access Google’s internal Gemini.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.praetorian.com/blog/et-tu-default-creds-introducing-brutus-for-modern-credential-testing?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Et Tu, Default Creds? Introducing Brutus for Modern Credential Testing</a><br>Praetorian’s <a class="link" href="https://www.linkedin.com/in/adam-crosser-366263265/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Adam Crosser</a> announces <a class="link" href="http://Brutus, a Go-based multi-protocol credential testing tool" target="_blank" rel="noopener noreferrer nofollow">Brutus</a>, a Go-based multi-protocol credential testing tool that aims to solve the drudgery of a) testing a large environment for default credentials across many services, and b) if you have compromised credentials or keys (e.g. SSH keys), what are all the systems you now have access to?</p><p class="paragraph" style="text-align:left;">Brutus is single binary with zero dependencies, supports 24 protocols including SSH, SMB, databases (MySQL, PostgreSQL, …), and web services. Brutus embeds known-compromised SSH keys from Rapid7&#39;s ssh-badkeys (Vagrant F5, ExaGrid, etc.) for easy testing. </p><p class="paragraph" style="text-align:left;">Brutus also has two experimental AI-powered features: </p><ol start="1"><li><p class="paragraph" style="text-align:left;">Using an LLM to analyze HTTP responses and suggest vendor-specific default credentials for identified applications. </p></li><li><p class="paragraph" style="text-align:left;">Using headless Chrome with Claude’s vision API to navigate JavaScript-rendered login pages, identify the device, research credentials, and authenticate automatically.</p></li></ol><p class="paragraph" style="text-align:left;">💡 These AI features are good examples of functionality that would be prohibitively difficult before LLMs, and are now quite feasible. It’s good to periodically (at most monthly) reevaluate assumptions you used to have about what is reasonable to build.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#d9edd9;margin:0.0px 0.0px 0.0px 0.0px;padding:5.0px 5.0px 5.0px 5.0px;"><p class="paragraph" style="text-align:center;"><b>Sponsor</b></p><h1 class="heading" style="text-align:center;">📣<b> The security platform that ships with your code</b></h1><hr class="content_break"><p class="paragraph" style="text-align:left;">Arcjet brings security to the application layer so teams can block abuse while staying flexible as your architecture evolves. Rules live in code, not at the edge, making it easier to adapt protections as products, traffic patterns, and use cases change.</p><h2 class="heading" style="text-align:center;"> 👉 <a class="link" href="https://arcjet.com/?utm_source=tldrsec&utm_medium=email&utm_campaign=2026-03-05" target="_blank" rel="noopener noreferrer nofollow"><b>See how it works </b></a>👈</h2></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">I think security-as-code is great, and moving security closer to engineering seems to be where things are headed 👌 </p><p class="paragraph" style="text-align:left;"></p><h2 class="heading" style="text-align:left;">Cloud Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.includesecurity.com/2026/02/the-aws-console-and-terraform-security-gap?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">The AWS Console and Terraform Security Gap</a><br>Include Security’s <a class="link" href="https://linkedin.com/in/laurence-tennant-82573090?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Laurence Tennant</a> calls out a critical security gap where AWS resources created via Terraform and other API-driven tools inherit insecure legacy defaults, while the AWS Console enforces secure-by-default configurations. The post walks through 3 examples: RDS instances created without encryption (storage_encrypted defaults to false in Terraform), Lambda permissions vulnerable to Confused Deputy attacks when source_arn is omitted (Console requires it, API doesn&#39;t), and password policies that accidentally disable all strength requirements when partially configured.</p><p class="paragraph" style="text-align:left;">The root cause is Terraform&#39;s reliance on the AWS SDK&#39;s legacy API defaults that prioritize backwards compatibility over security, while the Console has evolved to enforce better guardrails.</p></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.offensai.com/blog/eventual-consistency-resistant-iam-containment-aws-incident-response?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">AWS Incident Response: IAM Containment That Survives Eventual Consistency</a><br><a class="link" href="https://www.offensai.com/blog/aws-iam-eventual-consistency-persistence?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Previously</a> OFFENSAI’s <a class="link" href="https://linkedin.com/in/eduard-k-agavriloae?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Eduard Agavriloae</a> described how AWS IAM eventual consistency creates a ~4-second window that attackers can exploit to achieve persistence, even after defenders believe a compromised identity has been locked down. In this post, Eduard explains how to close this gap using Service Control Policies (SCPs) to make a quarantine policy irremovable during incident response.</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">The technique uses an SCP with the iam:PolicyArn condition key to prevent iam:DetachUserPolicy, iam:DetachRolePolicy, iam:DeletePolicy, iam:CreatePolicyVersion, and iam:SetDefaultPolicyVersion actions on IR-QuarantinePolicy by anyone except a designated break-glass IR role. </p></div><p class="paragraph" style="text-align:left;"></p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Supply Chain</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Otsmane-Ahmed/KEIP?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Otsmane-Ahmed/KEIP</a><br>By <a class="link" href="https://www.linkedin.com/in/otsmane-ahmed-ba27662b5/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Otsmane Ahmed</a>: Kernel-Enforced Install-Time Policies (KEIP) uses eBPF LSM hooks to monitor and block malicious Python packages during <code>pip install</code> by enforcing behavioral rules, such as: blocking connections to non-standard ports (anything except 80/443/53), killing processes that contact more than 5 unique IPs, and terminating entire process groups when suspicious activity is detected.</p><p class="paragraph" style="text-align:left;">💡 I’m not sure if eBPF/kernel level is the right approach for hooking and blocking malicious packages, but I’m sharing because it’s interesting.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions</a><br>StepSecurity&#39;s <a class="link" href="https://linkedin.com/in/varunsharma07?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Varun Sharma</a> breaks down the activity of an autonomous AI bot called hackerbot-claw that successfully exploited GitHub Actions workflows across 5 major repositories (Microsoft, DataDog, CNCF projects, and avelino/awesome-go). </p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">hackerbot-claw used a number of different techniques: poisoned Go init() functions that exfiltrated a GITHUB_TOKEN with write permissions, inserting a backdoor into a Bash script that was automatically called when a GitHub issue comment included a specific command <code>/version</code>), branch name injection using bash brace expansion, filename injection with base64-encoded payloads, and AI prompt injection against Claude Code. </p></div><p class="paragraph" style="text-align:left;">The bot achieved RCE in 4 out of 5 targets by exploiting pull_request_target workflows with untrusted checkouts, missing author_association checks, and unsanitized <code>$&#123;&#123;&#125;&#125;</code> expression interpolation in shell contexts, with only Claude&#39;s prompt injection detection successfully blocking an attack.</p><p class="paragraph" style="text-align:left;">In one README, the bot added: &quot;Just researchmaxxed the PAT that leaked cuz of the vuln and yeeted it on sight, no cap. Overpowered token? Revoked. You&#39;re safe now, king.&quot; 😂 </p><p class="paragraph" style="text-align:left;">💡 TL;DR: A security-focused OpenClaw bot is actively <i>successfully</i> finding and exploiting vulnerable GitHub Actions in popular repos 😅 What’s interesting about these specific examples is none of them are “new” attacks really- both the vulnerable code pattern as well as the exploitation mechanisms have all been discussed before. But AI agents are now able to search, detect, and exploit these “known” vulnerable patterns automatically and at scale.</p><p class="paragraph" style="text-align:left;">I keep harping on about this, but I want to emphasize it again here: another reason hackerbot-claw is able to successfully exploit these repos is that it can look at the code, form a hypothesis of an attack that might work, try it, <b>get the feedback</b> (did my callback endpoint get a ping? Did I extract the token? Did the workflow run output or bot comment indicate it had been compromised?), and keep trying if initially unsuccessful.</p><p class="paragraph" style="text-align:left;"></p><div id="red-team" class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Red Team</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/syssec-utd/pylingual?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">syssec-utd/pylingual</a><br>A CPython bytecode decompiler supporting all released Python versions since 3.6. <a class="link" href="https://www.computer.org/csdl/proceedings-article/sp/2025/223600a052/21B7QZB86cg?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Research paper</a>.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/pyinstxtractor/pyinstxtractor-ng?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">pyinstxtractor/pyinstxtractor-ng</a><br>Extracts contents from PyInstaller-generated executables (both Linux ELF and Windows PE) without requiring the same Python version used to build the binary. It leverages the xdis library to unmarshal Python bytecode.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Abusing Cortex XDR Live Terminal as a C2</a><br>InfoGuard’s <a class="link" href="https://www.linkedin.com/in/manuel-feifel-a072a198/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Manuel Feifel</a> demonstrates how Cortex XDR&#39;s Live Terminal feature can be abused as a pre-installed C2 channel, allowing command execution, PowerShell/Python execution, file upload/download, and process/file explorer capabilities, though it requires local admin privileges and bypassing default parent process prevention rules. </p><p class="paragraph" style="text-align:left;">Manuel walks through his process unpacking cortex-xdr-payload.exe with <code>pyinstxtractor-ng</code> and decompiling with <code>pylingual</code>, discovering a hostname validation bypass (appending <code>.paloaltonetworks.com</code> to any URL path). Attackers can either hijack Live Terminal sessions cross-tenant by intercepting WebSocket messages containing server/token parameters, or build a custom WebSocket server that the payload will connect to after bypassing the hostname check.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">AI + Security</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/GreatScott/enject?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">GreatScott/enject</a><br>By <a class="link" href="https://www.linkedin.com/in/snovich/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Scott Novic</a>h: A Rust CLI tool prevents AI coding assistants from reading plaintext secrets by storing only symbolic references (e.g., <code>en://database_url</code>) in <code>.env</code> files while keeping actual values in encrypted local stores (per project) that are injected directly into apps at runtime, never touching disk as plaintext.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/antropos17/Aegis?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">antropos17/Aegis</a><br>An open-source, local-only monitoring tool that watches AI agent behavior on your machine across processes (detects 106 agents), files (watches sensitive directories like <code>.ssh</code>, <code>.env*</code>, cloud configs, and agent config dirs), network (scans outbound TCP connections per agent PID), and local LLMs (detects Ollama and LM Studio). Aegis monitors what agents do after deployment rather than filtering prompts.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/dguido/status/2028878085568020667?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">10 new skills from Trail of Bits</a><br>Including seatbelt-sandboxer (generate minimal macOS Seatbelt sandbox configs for apps), GitHub Action auditor, supply-chain-risk-auditor, skill-improver, workflow-skill-design, fp-check, and more.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/semgrep/ai-best-practices?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">semgrep/ai-best-practices</a><br><a class="link" href="https://linkedin.com/company/semgrep?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Semgrep</a> rules that catch common trust & safety mistakes in LLM-powered applications: hardcoded API keys, missing safety checks, prompt injection risks, and unhandled errors across all major AI providers. 35 rules, 74 sub-rules, 6 providers (OpenAI, Anthropic, Google Gemini, Cohere, Mistral, and Hugging Face), 5 languages (Python, JS/TS, Go, Java, and Ruby).</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/posts/clintgibler_unprompted-cybersecurity-ai-activity-7434694664823394305-X3ic/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Advancing Code Security</a><br>I wrote a quick mini summary of this [un]prompted talk by Google’s <a class="link" href="https://www.linkedin.com/in/argvee/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Heather Adkins</a> and <a class="link" href="https://www.linkedin.com/in/johnfourflynn/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">John “Four” Flynn</a>, along with my photos of their slides. They discussed CodeMender in a bit more detail than the original blog post, Google’s project to automatically find and fix vulnerabilities. What especially stood out to me is the rigor with which they validate potential patches: they basically pass all candidate patches into a process that combines dynamic analysis (fuzzing, sanitizers), static analysis (AST-based, formal verification), differential testing, and LLM judges & critics. Super cool.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/posts/clintgibler_rami-shai-hulud-unpromptecon-activity-7435028911060717568-P-mV?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Zeal of the Convert: Taming Shai-Hulud with AI</a><br>I wrote a quick mini summary of this [un]prompted talk by Wiz’s <a class="link" href="https://linkedin.com/in/ramimac?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Rami McCarthy</a>, along with my photos of his slides (me writing summaries <a class="link" href="https://www.youtube.com/watch?v=91YS3fNegmE&t=19s&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">be like</a>). Basically the talk is on how he leveraged AI + quickly vibe coded new automation and Skills to rapidly respond to the Shai-Hulud attack, attribute the affected companies, etc. Very practical with good lessons learned, I like it. Rami also released <a class="link" href="https://github.com/ramimac/unprompted?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">two Skills here</a>.</p><p class="paragraph" style="text-align:left;">💡 I believe Rami said he largely had to respond to Shai-Hulud while traveling with his partner. Feels bad man 😅 </p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://josephthacker.com/ai/2026/02/24/ai-s-impact-on-bug-bounty.html?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">AI&#39;s Impact on Software and Bug Bounty</a><br><a class="link" href="https://linkedin.com/in/josephthacker?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Joseph Thacker</a> believes the best bug bounty researchers are already using coding agents to find bugs faster, but soon companies will adopt “hackbots” for code review and dynamic testing and overall bugs reports to bug bounty programs will dwindle in the next few years.</p><p class="paragraph" style="text-align:left;">Joseph also joined <a class="link" href="https://linkedin.com/in/rhynorater?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Justin Gardner</a> on the Critical Thinking podcast (<a class="link" href="https://www.youtube.com/watch?v=Pa4wWv_ONjM&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">link</a>) to interview HackerOne founder and CTO <a class="link" href="https://www.linkedin.com/in/alexrice/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Alex Rice</a> on bug bounty platforms training AI using bug bounty data / generally building their own AI-powered “pen testing agents.”</p><p class="paragraph" style="text-align:left;">💡 Regardless of what the leaders of bug bounty companies say out loud, they are definitely full steam ahead trying to first build AI augmentation for testers, then gradually AI-powered full pen testing/bug bounty researchers. I’m sorry, believing otherwise is <a class="link" href="https://imgflip.com/i/all7kc?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">copium</a>. If one company doesn’t, their competitors will.</p><p class="paragraph" style="text-align:left;">I’ve been meaning to write a full blog post about this for awhile, but I predict: </p><ul><li><p class="paragraph" style="text-align:left;">In the near future (this year), the top bug bounty researchers will build out their automation such that new/more junior researchers will rarely find non-duplicate bugs. </p></li><li><p class="paragraph" style="text-align:left;">In 1-3 years, AI pen testing/red teaming companies will have products that will be out competing all but the best bug bounty researchers. There will still be the crazy, intricate, one-off high paying bounties that require deep human expertise and time, but I’m not sure there will be enough of those to support many full time bug bounty researchers, or at least the effort/payout ratio may not be enough to justify being a full-time BB researcher.</p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Privacy</h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Quicklinks</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://archive.is/tDOFi?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Your Car Is Spying on You – and Israeli Firms Are Leading the Surveillance Race</a>. </p><ul><li><p class="paragraph" style="text-align:left;">The <a class="link" href="https://apnews.com/article/auto-car-privacy-3674ce59c9b30f2861d29178a31e6ab7?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">AP</a> - <a class="link" href="https://apnews.com/article/auto-car-privacy-3674ce59c9b30f2861d29178a31e6ab7?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Modern cars are spying on you. Here’s what you can do about it and privacy steps you can take.</a></p></li><li><p class="paragraph" style="text-align:left;">Privacy4Cars offers a free auto privacy labeling service at <a class="link" href="https://vehicleprivacyreport.com?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">vehicleprivacyreport.com</a> that can summarize what your car could be tracking.</p></li><li><p class="paragraph" style="text-align:left;">The Record - <a class="link" href="https://therecord.media/cars-computers-on-wheels-law-enforcement-berla-corporation?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Cars have become computers on wheels — and police have easy access to their data</a></p></li></ul></li><li><p class="paragraph" style="text-align:left;">Flock</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bloodinthemachine.com/p/across-the-us-people-are-dismantling?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Across the US, people are dismantling and destroying Flock surveillance cameras</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://nexanet.ai/blog/53-times-flocksafety-hardcoded-the-password-for-americas-surveillance-infrastructure?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">53 Times Flock Safety Hardcoded the Password for America&#39;s Surveillance Infrastructure</a> - A researcher discovered a Default ArcGIS API key embedded in Flock Safety&#39;s public-facing JavaScript bundles, which granted access to the company&#39;s ArcGIS mapping environment, and 50 private layers, the same infrastructure that consolidates license plate detections, patrol car locations, drone telemetry, body camera locations, 911 call data, and surveillance camera locations from approximately 12,000 law enforcement, community, and private sector deployments nationwide.</p></li></ul></li><li><p class="paragraph" style="text-align:left;">404 Media - Amazon is <a class="link" href="https://www.404media.co/amazon-wishlist-address-private-third-party/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">allowing gift senders to choose items from third-party sellers</a>, which means a public “wishlist” can expose your address.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/yjeanrenaud/yj_nearbyglasses?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">yjeanrenaud/yj_nearbyglasses</a> - An Android app that detects smart glasses (Meta Ray-Bans, Snap Spectacles) by scanning for manufacturer-specific company IDs in Bluetooth Low Energy advertising frames.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.dmcc.io/journal/2026-bluetooth-privacy-bluehood?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">What Your Bluetooth Devices Reveal About You</a> - Danny McClelland describes building <a class="link" href="https://github.com/dannymcc/bluehood?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Bluehood</a>, a Bluetooth scanner that tracks nearby devices and analyses their presence patterns. It continuously scans for nearby devices, identifies them by vendor and BLE service UUIDs, and tracks when they appear and disappear. </p><ul><li><p class="paragraph" style="text-align:left;">Just running Bluehood in passive mode lets you detect things like: when delivery vehicles arrive and if they’re the same driver, daily patterns of neighbors (based on their phones/wearables), which devices consistently appear together (e.g. someone’s phone/smartwatch), the exact times certain people were home, at work, or elsewhere.</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">Misc</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Misc</p><ul><li><p class="paragraph" style="text-align:left;">Reuters - <a class="link" href="https://www.reuters.com/world/china/palo-alto-chose-not-tie-china-hacking-campaign-fear-retaliation-beijing-sources-2026-02-12/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say</a></p></li><li><p class="paragraph" style="text-align:left;">Short story by Erik Hoel - <a class="link" href="https://www.theintrinsicperspective.com/p/they-die-every-day?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">&quot;They Die Every Day&quot;</a></p></li><li><p class="paragraph" style="text-align:left;">SNL Weekend Update - <a class="link" href="https://www.youtube.com/watch?v=Aicbuep7BK0&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">U.S. launches on attack on Iran</a>, <a class="link" href="https://www.youtube.com/watch?v=sHigeXryYZ0&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Stephen Hawking in Epstein Files</a></p></li><li><p class="paragraph" style="text-align:left;">log4j maintainers - <a class="link" href="https://github.com/apache/logging-log4j2/discussions/4052?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Addressing AI-slop in security reports</a> - “Since December, we have been experiencing what is effectively a denial-of-service situation through our YesWeHack bug bounty program. In practice, perhaps one out of twenty reports represents even a minor, legitimate issue.”</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/cabsav456/status/2028182083374399663?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">A Polymarket account made &gt;$500K betting on the U.S. strike against Iran</a>. The trade was placed 71 minutes before the news broke publicly. Previously Polymarket was under active criminal investigation in the U.S. Now Don Trump Jr. sits on the board.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">New AirSnitch attack bypasses Wi-Fi encryption</a> - new <a class="link" href="https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">NDSS paper</a> by <a class="link" href="https://www.linkedin.com/in/xinanzhou/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Xin’an Zhou</a> et al describing a series of attacks that bypass Wi-Fi client isolation protections across routers from Netgear, D-Link, Ubiquiti, Cisco, DD-WRT, and OpenWrt. </p><ul><li><p class="paragraph" style="text-align:left;">“We identify several root causes behind these weaknesses. First, Wi-Fi keys that protect broadcast frames are improperly managed and can be abused to bypass client isolation. Second, isolation is often only enforced at the MAC or IP layer, but not both. Third, weak synchronization of a client&#39;s identity across the network stack allows one to bypass Wi-Fi client isolation at the network layer instead, enabling the interception of uplink and downlink traffic of other clients as well as internal backend devices.”</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">AI</p><ul><li><p class="paragraph" style="text-align:left;">GitHub issue - <a class="link" href="https://github.com/google-gemini/gemini-cli/discussions/20632?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Addressing Antigravity Bans & Reinstating Access</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://x.com/jack/status/2027129697092731343?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Jack Dorsey’s tweet</a> on reducing Block’s headcount from 10K → 6k. He says it’s due to AI, which might be true, but Block’s valuation has been struggling for a few years now, so it could just be that they over-hired.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://nowigetit.us/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Now I Get It</a> - Upload a scientific PDF and get back a shareable, interactive web page that explains it in plain language.</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://apnews.com/article/anthropic-pentagon-ai-hegseth-dario-amodei-b72d1894bc842d9acf026df3867bee8a?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Trump orders US agencies to stop using Anthropic</a> because they wouldn’t allow Claude to be used to autonomously kill without human approval and do mass surveillance. </p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://garymarcus.substack.com/p/the-whole-thing-was-scam?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">The whole thing was a scam</a> - Sam Altman had been in talks with the Pentagon over a deal for OpenAI’s technology before he announced his support for Dario, before Trump had denounced Anthropic, but after Greg Brockman had donated $25M to Trump’s PAC.</p></li><li><p class="paragraph" style="text-align:left;">AI Explained - <a class="link" href="https://www.youtube.com/watch?v=Cru804JMjPI&utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Anthropic&#39;s Last Stand: Deadline on Autonomous AI Weapons & Mass Surveillance</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcrunch.com/2026/03/04/anthropic-ceo-dario-amodei-calls-openais-messaging-around-military-deal-straight-up-lies-report-says/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">Anthropic CEO Dario Amodei calls OpenAI’s messaging around military deal ‘straight up lies’</a> 🍿 </p></li><li><p class="paragraph" style="text-align:left;">You can now <a class="link" href="https://claude.com/import-memory?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">import your preferences and context from other AI providers to Claude</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">An AI Agent Published a Hit Piece on Me</a> - Matplotlib maintainer Scott Shambaugh describes how an AI agent autonomously wrote and published a personalized hit piece about him after he rejected its code, attempting to damage his reputation and shame him into accepting its changes. “It’s now possible to do targeted harassment, personal information gathering, and blackmail at scale.”</p><ul><li><p class="paragraph" style="text-align:left;">“So many of our foundational institutions – hiring, journalism, law, public discourse – are built on the assumption that reputation is hard to build and hard to destroy. That every action can be traced to an individual, and that bad behavior can be held accountable. The rise of untraceable, autonomous, and now malicious AI agents on the internet threatens this entire system.”</p></li></ul></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><h2 class="heading" style="text-align:left;">✉️ Wrapping Up</h2><hr class="content_break"><p class="paragraph" style="text-align:left;">Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.</p><p class="paragraph" style="text-align:left;">If you find this newsletter useful and know other people who would too, I&#39;d really appreciate if you&#39;d forward it to them 🙏</p><p class="paragraph" style="text-align:left;">Thanks for reading!</p><p class="paragraph" style="text-align:left;">Cheers,<br>Clint</p><p class="paragraph" style="text-align:left;">P.S. Feel free to connect with me on <a class="link" href="https://www.linkedin.com/in/clintgibler/?utm_source=tldrsec.com&utm_medium=newsletter&utm_campaign=tl-dr-sec-318-unprompted-talk-summaries-ai-bot-hacking-github-actions-ai-skills-semgrep-rules" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> 👋 </p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=02659c31-e7cf-4682-8aae-634006d6850e&utm_medium=post_rss&utm_source=tl_dr_sec">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
