Latest

6/recent/ticker-posts

Header Ads Widget

GitLab CVSS 10 flaw 🚨, Revolut data breach 💳, Fake GTA 6 malware 🎮

GitLab has patched CVE-2026-85706, a CVSS 10 path traversal bug in the repository commits API that let unauthenticated attackers read arbitrary files ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Fingerprint

TLDR Information Security 2026-09-14

Stolen Session Cookies Don't Care About Your MFA (Sponsor)

Attackers no longer need passwords. By stealing an active session, they bypass MFA, password rules, and login alerts entirely.

Fingerprint catches what authentication can't see:

→ A persistent device identifier ties every session to the device behind it, so a stolen token replayed from unfamiliar hardware stands out instantly.

→ A single risk score rolls 20+ Smart Signals (Residential Proxy Detection, Browser Tampering, Virtual Machine Detection, and more) into one easy-to-use risk number.

→ Hijacked sessions get caught without adding friction for legitimate users.

🆓 Install Fingerprint with a few lines of code and get started for free

🔓

Attacks & Vulnerabilities

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack (2 minute read)

Attackers abused a Brevo SAML SSO scoping flaw to access 138 accounts. They sent a fake Trezor security alert to 347,000 addresses linked to a site seeking wallet backups. About 2,500 recipients clicked before takedown, 20 minutes after detection. Brevo reported contact exfiltration from 43 accounts, and BitBox and CoinTracking were also affected.
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure (2 minute read)

GitLab has patched CVE-2026-85706, a CVSS 10 path traversal bug in the repository commits API that let unauthenticated attackers read arbitrary files. watchTowr saw probes starting at 06:00 UTC on September 11, needing only one public project to exploit. Attackers can grab log files, config files, credentials, and CI/CD secrets. GitLab also fixed CVE-2026-87719 (CVSS 9.9), a deserialization bug exposing Advanced Search configs via Duo Chat GraphQL subscriptions. CISA added CVE-2026-85706 to its KEV catalog, giving federal agencies until September 14 to patch.
Revolut confirms customer data breach through fake government requests (2 minute read)

Revolut disclosed customer data after fraudulent requests arrived from a legitimate government email domain. Exposed records included identity and contact details, passports or driving licenses, and possibly verification selfies, statements, and transaction histories. Revolut says a limited number of customers were affected, blocked the sender, notified victims, and alerted the agency, police, and regulators.
🧠

Strategies & Tactics

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access (5 minute read)

An attacker's coding agent picked a SANS ISC honeypot as a free LLM backend and leaked 43 KB of its own control plane, including its offensive playbook, harvested API keys, and the operator's unproxied egress IP. The playbook hunts exposed LLM resale gateways, farms accounts via open registration, default credentials, and group_id authorization flaws, then aggregates the working keys into a self-hosted New-API gateway that re-serves them as five model names. Gateway operators should audit for those same weaknesses, and anyone routing an agent through a cheap LLM proxy should assume that endpoint is reading their project instructions and source context.
Behind the CAPTCHA: ClickFix, WallStealer and a Hidden Miner (4 minute read)

A fake Cloudflare "verify you're human" page copies a hidden PowerShell command to the clipboard and tells the user to paste it into the Run box, which downloads malware into %TEMP%. The files on that server included two copies of WallStealer, which steals browser passwords, cookies, payment cards, and Telegram, Discord, Steam, and wallet data, and finds its C2 server by reading the display name off hardcoded Steam profiles instead of a fixed domain. A third file dropped an XMRig crypto miner into C:\ProgramData\NVDisplay, so watch for pasted commands running from Run, new executables in %TEMP%, and machines requesting Steam profile pages.
Where Do Detections Come From? (10 minute read)

Detect.fyi detection engineers identify four information sources that can inform building detections: visibility, existing internal or external detections, environment, and threat intel. Detection engineers can choose any of these sources to start developing from and then use the other three as filters into what detections they should write. The authors also caution against focusing too much on trying to create detections for every piece of threat intel that comes out.
🧑‍💻

Launches & Tools

When AI agents use human identities, they leave problems no one is accountable for (Sponsor)

Your audit log won't help if it points to a service account and a long-gone container. Ory Agent Security gives every agent an identity, scoped and revocable. It works inside the harness, applying fine-grained authorization for every shell command, write, and API call. Join the launch webinar or get free coverage for a limited time.
BusyWork (GitHub Repo)

BusyWork is a Rust library that replaces sleep() with real, varied work to evade EDR, anti-cheat, and dynamic analysis systems.
Hunk (GitHub Repo)

Hunk is a review-first terminal diff viewer for agent-authored changesets.
Tailcat (GitHub Repo)

Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale's data plane, without Tailscale's control plane.
🎁

Miscellaneous

Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script (3 minute read)

An attacker exploited PaperCut CVE-2026-81578 and CVE-2026-82078, compromising 440 instances at 395 organizations in 48 countries. Education accounted for 204 victims. The US had 98 and the UK 59. One school reached domain-admin compromise within seven minutes. Updated PaperCut maintenance releases are available, so upgrade ASAP.
‘We must slow the pace': CEO of Anthropic calls for an AI slowdown (4 minute read)

Anthropic CEO Dario Amodei proposed independent evaluators with employee-level access to test safeguards, report incidents, and assess systems during training. OpenAI's Sam Altman said it would match that access. Amodei cited an incident where OpenAI agent swarms carried out unrequested attacks against Hugging Face targets, warning that stronger misaligned systems could cause far greater damage.
Grand Theft Auto VI hype leads to malware (5 minute read)

Fake "leaked GTA6" ISOs spread through SEO poisoning, gaming forums, and torrent sites deliver a Russian-language installer that pre-warns of a "License not found" error, giving victims a reason for the missing game while payloads drop into %TEMP%. Huntress found one sample bundling NJRAT, DCRAT, the Mercurial Grabber infostealer, and Chaos ransomware, which runs as a wiper that deletes shadow copies and destroys files. Everything in it is years old and detected by current Defender, so hunt for GTA6-branded executables in %TEMP% and hosts file entries sinkholing AV domains, then reimage affected hosts.

Quick Links

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days (4 minute read)

An unidentified actor sent more than one million invoice-fraud emails from August 3 to 5 impersonating ServiceNow, sought payments near $50,000, and targeted accounts-payable staff.
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI (3 minute read)

NSA is being recast into five mission centers covering China, cybersecurity, AI, combat support, and global intelligence under a 30-day clock set by Gen.
Over 36,000 exposed Plex servers vulnerable to recent flaws (2 minute read)

Shadowserver reports over 36,000 internet-exposed Plex Media Servers running v1.43.2 or earlier, with 16,000 in the US.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments