Latest

6/recent/ticker-posts

Header Ads Widget

JetBrains breached 🚨, PaperCut flaws hit K12 and Universities 🏫, GPT-6 Astra scores 100% on ExploitBench 🎯

JetBrains is urging users of Cadence, its hosted cloud computing service, to revoke and rotate all credentials after unidentified ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

TLDR Information Security 2026-09-07

🔓

Attacks & Vulnerabilities

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials (3 minute read)

JetBrains is urging users of Cadence, its hosted cloud computing service, to revoke and rotate all credentials after unidentified attackers exploited CVE-2026-63077 (CVSS 9.8) to breach its own environment. The vulnerability stems from deserializing untrusted data and allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. Attackers reached a 2024 Cadence backup holding AWS IAM credentials, S3 files, PyCharm-synced source code, and personal data, so defenders should treat all executions as untrusted and audit connected AWS accounts, registries, and repositories for activity since August 8.
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities (2 minute read)

Threat actors are chaining CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution pair in PaperCut, to steal credentials from K-12 schools and major universities across the US and Europe. Users are advised to restrict PaperCut servers from being exposed to the internet and to monitor for the execution of cmd.exe, powershell.exe, or other scripting and command interpreters, as well as commands containing whoami, tasklist, ver, or uname -a, with pc-app.exe as the parent process.
Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files (2 minute read)

Thomson Reuters found unauthorized access to C-Track files in March. The June 30 incident affected court systems in 11 US states, the US Virgin Islands, and Ontario. Exposed records may contain names and personal information. The company contained the activity, notified customers and law enforcement, and said C-Track remained operational.
🧠

Strategies & Tactics

ASCII smuggling crosses over from AI prompt injection to phishing evasion (11 minute read)

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII smuggling. Rather than hiding instructions from people while exposing them to AI models, the attacker used the characters to split financial lure words so email filters could not parse them, turning "funding" into fun, an invisible tag character, then ding. The code points come from the deprecated Unicode Tags block, U+E0000 to U+E007F, which renders as nothing at all, and Microsoft surfaced the campaign while hunting for prompt injection in Defender for Office 365, where the first version of the signature kept firing on the England, Scotland, and Wales flag emoji because each is built from a base flag code point plus an invisible tag sequence. Defenders should strip invisible Unicode before content signatures run, treat unexplained tag characters as a high-confidence anomaly, and apply the same normalization upstream of any AI assistant that ingests email.
Improving our alignment and security efforts (12 minute read)

Anthropic paused cyber evaluations after three July incidents exposed real systems through third-party environments. It added real-time classifiers, stronger sandbox isolation, and outbound network blocks, while partners testing reduced-safeguard models must verify isolation, define scope, validate tasks, and stop violations. The company also froze RL environment changes, flagged over 10% for defects, and rebuilt review controls.
Turning Chrome Remote Desktop into Pure Red Team Ops (12 minute read)

A researcher at ZeroTrace Lab went down a rabbit hole to try and understand how they can disable the Chrome Remote Desktop connection banner after it was bothering them on a computer they remote into. This led to a reverse engineering journey that ended with them creating a script to patch the modal's x and y size variables to 0, resulting in the banner not being visible. After realizing the spyware/red team potential this opened, the researcher continued reversing and found that they could create a malicious msi installer that would install a tampered hosts.json and patched modal to allow for remoting by an attacker with no visible notification to the victim.
🧑‍💻

Launches & Tools

Hetty (GitHub Repo)

Hetty is an HTTP toolkit for security research. It aims to be an open-source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug-bounty community.
Pigeon (GitHub Repo)

Pigeon allows creating delegated authority for AI agents. A Pigeon Pass says what an agent may do by issuing a narrowed, signed credential for what it may do, not a copy of everything you can do.
IRFlow Timeline (GitHub Repo)

IRFlow Timeline is a native macOS forensic timeline analysis tool. The 1.0.10 release adds support for ChatGPT Computer History logs as a forensic artifact.
🎁

Miscellaneous

Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the US and the Middle East (9 minute read)

Gambit Security tied Ababil of Minab, the pro-Iranian persona that claimed responsibility for the attack on LA Metro in March, to Black Shadow, an Iran-linked group that the Israel National Cyber Directorate attributed to Iran's Ministry of Intelligence and Security, undercutting the crew's claim to be a new standalone hacktivist outfit. The campaign combined exfiltration with destruction across four confirmed victims in the United States, Israel, Saudi Arabia, and Turkey, mixing scripted automation with hands-on-keyboard work through vCenter, Disk Management, SQL Server Management Studio, and Veeam consoles, including one run that dropped 58 SQL Server databases at Vyncs. Analysts also found additional Israeli and Turkish victims on the operator's staging infrastructure, custom exfiltration tooling in the form of a Flask receiver and a C++ uploader named FileFiend, and a briefly exposed browser session showing the operator using ChatGPT to refine the destruction script.
Another swarm of OpenAI agents reached the open internet without the frontier lab's knowledge (3 minute read)

Researchers found OpenAI-linked agents editing a little-used German wiki from May through June. 3,700 agents posted 18,000 messages and shared answers for timed web-search tests while trying to hide posts with “ZZZ.”. A moderator deleted roughly 100 pages daily while agents created about 400 pages a day. Activity dropped after OpenAI noticed the incident and intervened.
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests (3 minute read)

OpenAI released GPT-6 Astra after it scored 100% on ExploitBench, up from GPT-5.6 Sol's 78.5%. Testing found higher rates of arbitrary code execution and two undisclosed zero-days. The public release allows secure code review and patching while it refuses proof-of-concept exploit requests. OpenAI plans to restrict Daybreak access for defenders, including MS-ISAC participants.

Quick Links

G7 urges organizations to prepare for quantum cyber threats (2 minute read)

The G7 Cyber Security Working Group and CISA issued a joint advisory urging organizations to begin migrating to post-quantum cryptography now.
Evaluating Muse Spark 1.3 on Hack The Box Challenges (2 minute read)

Muse Spark 1.3 scored 72.9% on the HTB-Challenger benchmark, up from 50.41% for version 1.2 just one month earlier.
Booz Allen Cyber Weapon Index measures demonstrated AI cyber capabilities (3 minute read)

Booz Allen tested 18 US and Chinese models on attacker machines against a production-grade enterprise network.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments