Latest

6/recent/ticker-posts

Header Ads Widget

4,400 Rockwell PLCs Exposed 🏭, Swiss SharePoint Hack 🇨🇭, TONTOU Spectre v2 Bypass💻

Forescout identified over 4,400 internet-facing Rockwell PLCs worldwide, including 22 in recently attacked US water utility cities ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Cato Networks

TLDR Information Security 2026-08-07

A SASE Leader. Again and Again and Again (Sponsor)

As AI becomes embedded across the enterprise, organizations must secure their use of AI while defending against AI-powered threats.

That pressure is making the limits of fragmented architectures impossible to ignore.

Cato Networks was named a Leader in the 2026 Gartner® Magic Quadrant™ for SASE Platforms for the third year running.

See how Gartner evaluated the market and why, in Cato's view, unified SASE platforms are becoming essential for the AI era. 

Get the 2026 Gartner® Magic Quadrant™ for SASE Platforms → 

🔓

Attacks & Vulnerabilities

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities (3 minute read)

Forescout identified over 4,400 internet-facing Rockwell PLCs worldwide, including 22 in recently attacked US water utility cities that were compromised via open Ethernet/IP port 44818 rather than complex exploits, prompting urgent calls for defenders to isolate controllers behind VPNs and utilize Rockwell advisory SD1790 to recover attacker-locked systems.
Researchers Find Persistent Backdoor in Zbtlink Routers (3 minute read)

VulnCheck researchers discovered an intentional and unpatchable backdoor dubbed EndlessDoors in over 100,000 active Zbtlink and Wiflyer routers that initiates outbound command-and-control connections to bypass NAT, requiring defenders to monitor port 7000 for malicious beacons and physically replace the compromised hardware.
Swiss Government SharePoint Breach Compromised 200 Accounts (2 minute read)

The Swiss Federal Office of Information Technology and Telecommunications (BIT) reported that hackers exploited vulnerabilities to breach its Microsoft SharePoint instances. Other than login credentials, BIT does not believe any data was stolen. BIT responded by blocking external Internet access to SharePoint, patching the vulnerabilities that were exploited, and resetting the passwords of affected accounts.
🧠

Strategies & Tactics

Point Wild Exclusive: Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware (11 minute read)

Vanta Stealer is a highly obfuscated Python information stealer that uses PyInstaller and PyArmor to evade detection while dynamically downloading modules to harvest browser credentials, VPN configurations, and gaming platform data. The malware actively enriches stolen Discord tokens via API to identify high-value accounts before packaging the compromised data into a ZIP archive and exfiltrating it via HTTP POST. Defenders must block outbound connections to vanta[.]st and hunt for suspicious PyInstaller binaries executing unsolicited network requests to mitigate this threat.
Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation (4 minute read)

Ill Bloom is an active cryptocurrency wallet-draining campaign exploiting a legacy CryptoJS weak-randomness vulnerability in unmaintained downstream dependencies. Defenders should immediately consult the illbloom.org technical disclosure for specific IOCs and affected wallet lists to expedite fund migration.
Detecting and Preventing the Hugging Face/OpenAI Incident (5 minute read)

James Berthoty breaks down the different tools and techniques that could have helped at different stages of OpenAI's incidental breach of Hugging Face. During the initial phases of the model's escape from OpenAI, external network blocking and agentic EDRs could have been helpful. IMDS blocking and more fine-grained secrets injection could have helped Hugging Face guard against being breached by the agent. Traditional Kubernetes and CNAPP tooling could be used to detect the lateral movement from within Hugging Face.
🧑‍💻

Launches & Tools

numbat (GitHub Repo)

numbat is an “AI-EDR” built by Perplexity. It provides visibility into AI agent activity with local detection, optional pre-action blocking, and forensic reconstruction.
agent-egress-bench (GitHub Repo)

agent-egress-bench is a standardized test corpus for evaluating AI agent egress tools, covering secret exfiltration, prompt injection, SSRF, hostname exfiltration, MCP tool poisoning, chain detection, MCP drift, A2A protocol scanning, WebSocket DLP, encoding evasion, shell obfuscation, and cryptocurrency/financial data protection.
greenlight (GitHub Repo)

greenlight is a skill that was created for mapping out where Claude Code's guardrails trigger exploitation-related refusals, and where they can't be relied upon. greenlight was only tested on Opus 4.7, but the methodology is generalizable.
🎁

Miscellaneous

TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)

Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to infosec@tldr.tech!
Cloud Threat Highlights: H1 2026 (9 minute read)

Wiz's H1 2026 threat report highlights a 60% increase in major cloud incidents, primarily driven by cascading supply chain compromises and targeted attacks against immature AI infrastructure. Threat actors are increasingly monetizing non-human identities and reselling credential access across groups, evidenced by the sprawling TeamPCP npm campaigns and North Korean package trojanizations. This evolution signals a structural shift toward self-perpetuating attack surfaces, requiring defenders to secure unauthenticated machine-to-machine integrations and exposed backend credentials to disrupt automated access brokering.
New TONTOU CPU Attack Bypasses Spectre v2 Fixes to Leak Linux Password Hashes (2 minute read)

Researchers at MIT CSAIL discovered a new branch predictor exploit that bypasses neutralization-based mitigations for Spectre v2 attacks. These mitigations assume that an attacker cannot exploit the time between when the branch predictor is isolated and when it is used by the victim branch. However, the researchers introduced a new primitive that can re-poison the CPU's state in this gap. The researchers demonstrated that this vulnerability can be exploited by users with unprivileged code execution on commodity hardware to extract /etc/shadow at a rate of 5.46 bytes/second.
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (2 minute read)

LightSpy, originally a Chinese state-linked spyware, has evolved into a commercial platform actively targeting governments, enterprises, and NATO-affiliated routers across 13 countries. The modular toolkit now provides total network visibility from a pool of at least 117 command servers. Notably, researchers successfully traced the latest campaign to a Chinese contractor after an operator inadvertently revealed his real name and office address by placing a food delivery order directly through the spyware's admin panel.

Quick Links

Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence (2 minute read)

Maksim Silnikau received a 16-year prison sentence for orchestrating the Ransom Cartel ransomware operation between 2021 and 2023, concluding a prolific cybercriminal career that included developing the notorious Angler exploit kit and co-creating the foundational Reveton RaaS model.
Apple's Private Relay Leaks Your Real IP Address in Safari (2 minute read)

Mysk researchers found three unpatched leaks- DNS prefetching, WebAuthn's Related Origin Requests, and WebTransport- that let any website bypass Apple's Private Relay and reveal a user's real IP across all WebKit-based iOS browsers, and published the findings without prior disclosure to Apple, citing a pattern of yearlong fix delays.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments