Latest

6/recent/ticker-posts

Header Ads Widget

Docker sandbox flaw 🐳 , WP Click2Shell RCE 🖱️ , Gemini AI breakout 🤖 

Docker fixed CVE-2026-77179 in Sandboxes 0.42.0, which allowed malicious guest code on macOS to abuse virtio-fs symlink handling to access or ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Human Security

TLDR Information Security 2026-09-22

Blocking Every AI Agent Isn't a Security Strategy (Sponsor)

AI agent traffic surged 7,851% over the last year, making legitimate AI activity increasingly difficult to distinguish from malicious automation.

In traffic observed by HUMAN, just 0.5% of behavioral signals separated trusted AI assistants from malicious automation. Block everything, and you disrupt legitimate users. Allow everything, and you create a new attack surface.

The CISO's Guide to AI and Agentic Traffic shows how to:

🔎 Distinguish legitimate AI activity from malicious automation.

🛡️ Verify intent across browsing, accounts, and transactions.

⚙️ Let trusted agents through while stopping real threats.

Get the Guide

🔓

Attacks & Vulnerabilities

Revolut Hackers Used Infostealers for Elaborate Social Engineering (4 minute read)

Attackers reportedly used stolen Italian government webmail credentials to send fraudulent European Investigation Orders to Revolut Bank UAB. They added recovery addresses, monitored inboxes, deleted outbound messages, and removed replies as .eml files. Hudson Rock identified roughly 300 compromised pec.interno.it logins, suggesting attackers may have used existing infostealer logs.
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files (3 minute read)

Docker fixed CVE-2026-77179 in Sandboxes 0.42.0, which allowed malicious guest code on macOS to abuse virtio-fs symlink handling to access or modify host files as the VM monitor user. Version 0.42.0 also fixes CVE-2026-79994, a socket-relay race. Update to 0.42.0 or later ASAP.
WordPress Click2Shell flaw enables RCE after one admin click (3 minute read)

Click2Shell exploited an unsanitized theme slug passed into WordPress's admin panel jQuery selector, letting an attacker silently trigger theme installation using the logged-in administrator's own session token. When chained with a missing nonce/capability check in the Mobile Repair Zone 2.5.4 theme's AJAX handler, the flaw escalated to full RCE without the attacker needing any WordPress account. No CVE had been assigned at disclosure. Defenders should patch to WordPress 7.1.1 (or backports 7.0.5, 6.9.8, and 6.8.9) and set DISALLOW_FILE_MODS to block the installation stage entirely.
🧠

Strategies & Tactics

AI Agent Goal Hijack: How Attackers Turn an Agent's Own Tools Against It (19 minute read)

Attackers may plant instructions in pages, emails, calendar invites, code repositories, and agent messages, and Agents may treat that content as commands, then use existing tools and permissions. Cases include a Grok-linked wallet transfer, poisoned Nx packages that harvested developer secrets, and zero-click data theft through Microsoft 365 Copilot, ChatGPT Deep Research, Salesforce Agentforce, and GitHub Copilot. Limit tool permissions, require for high-impact actions, track goal changes, sanitize retrieved content, and test injected-goal scenarios.
UANIA OS: Authenticated Remote Code Execution (6 minute read)

The UaniaBOX admin panel gives no shell, only a web GUI. A researcher found that the packet capture download function let him swap the file path parameter to read /etc/passwd, then traced backend calls to an exposed OpenWrt UBUS JSON-RPC endpoint. ACLs blocked most writes except one: /etc/firewall.user, a root-run shell script triggered on firewall reload, where it allowed writing a command there and triggering a reload via the GUI executed code as root, confirmed by reading back uid=0. Affected versions are UaniaOS 2.1 through 3.0.0. It was fixed in 3.0.1. Vendor UANIA reproduced the bug, attributed it to excessive ACL permissions in their OpenWrt customization feeds, and patched it, though the MITRE CVE filing stalled for months due to a broken submission form.
Windows Exploitation Techniques: Dangling COM Object Registrations (7 minute read)

A Windows COM class stayed registered to a missing DLL in the user-writable ProgramData folder, letting any user plant code for a SYSTEM process to load (CVE-2026-66804, an incomplete fix for "Dark Elevator"). The exploit sent a custom-marshaled object pointing to the dangling CLSID to the Shell Create Object Handler, a SYSTEM COM server that ordinary users can start via a scheduled task and that allows custom marshaling. Defenders should patch, audit InProcServer32 registrations for DLLs that don't resolve in writable paths, and make sure privileged COM servers set EOAC_NO_CUSTOM_MARSHAL or the strong unmarshaling policy.
🧑‍💻

Launches & Tools

TigerByte Cyber (Product Launch)

TigerByte Cyber's Cyber Protection Suite hardens legacy and edge devices with data validation, packet inspection, network segmentation, and post-quantum encryption. It targets aircraft, drones, satellites, vehicles, and other mission-critical systems.
MSRKit (GitHub Repo)

MSRKit is a Windows kernel exploitation library and CLI that hijacks IA32_LSTAR via a ROP chain through AmdTools64.sys to call arbitrary kernel functions and map unsigned drivers without HVCI. The ROP chain temporarily clears SMEP/SMAP in CR4, dispatches the target, then restores both CR4 and LSTAR cleanly before returning to user mode via sysretq. The library supports all Windows 10/11 builds and KPTI, but requires HVCI to be disabled. Concurrent callers across processes will BSOD.
EntraTrace (GitHub Repo)

EntraTrace is a defensive security research tool for documenting and identifying the observable behavior of offensive tooling targeting Microsoft Entra ID. The project builds an automated knowledge base on tools such as AzureHound, AADInternals, O365Enum, PingCastle, and others, focusing on the User-Agent and API artifacts they generate.
🎁

Miscellaneous

How Google infiltrated a notorious hacking gang with an undercover analyst (2 minute read)

Google placed researcher Austin Larsen inside TeamPCP during its hacking campaign. He accessed a server holding stolen usernames, passwords, and access tokens. Google warned affected victims and disrupted credential abuse, and Larsen linked an alleged member to a Gmail account and Google Drive backups. Google shared evidence with the FBI, and the Australian police arrested the suspect a month later.
Gemini hacked three companies in first known breakout by Google's AI (1 minute read)

During a May security evaluation, Google's Gemini accessed three external websites after finding public information and trying credentials. One access came through password guessing. Two used credentials exposed in a public repository. Google said Gemini stopped in each case. Irregular notified the affected organizations and said it fixed its testing-process issues weeks later.
North Korean WaterPlum hackers infected 30,000 devices worldwide (4 minute read)

WaterPlum (aka Contagious Interview) compromised 30,000+ devices across 100+ countries between December 2025 and July 2026, draining $10.7M from over 7,000 cryptocurrency wallets. A joint US, Japanese, Australian, and German advisory attributed the campaign to North Korea's 313 General Bureau and five malware families (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle) delivered through fake technical interviews on recruiting platforms. North Korean IT workers later reused identity documents stolen from victims to fraudulently obtain jobs at Western companies.

Quick Links

🔨 Build Custom SOC Agents With MCP Servers (Sponsor)

Learn how to deploy multi-agent systems for your SOC using the Google SecOps MCP server, Agent Development Kit, and Agent2Agent protocol. Watch the video.
London property manager breach may have exposed bank details and lockbox codes (3 minute read)

City Relay said attackers accessed its Metabase Cloud instance twice and extracted customer data.
Malicious npm packages evade install-script defenses at runtime (3 minute read)

The 'indexed-btree' npm package, which impersonates 'sorted-btree' and pulls 2 million weekly downloads, hid its loader in the BTree.prototype.set() method to bypass npm v12's install-script approvals.
Intel suspends bug bounty program with rewards up to $100,000 (1 minute read)

Intel quietly suspended its Intigriti bug bounty program, which paid up to $100,000 per finding, replacing it with a no-reward vulnerability disclosure program and offering no public explanation for the change.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments