Latest

6/recent/ticker-posts

Header Ads Widget

Meta Muse AI 0-day 🤖, ShinyHunters hacks Clop 🏴‍☠️, EU's $463M Google Fine 💸

A zero-day allows any local macOS app or terminal command to redirect Muse transcription to an attacker-controlled server. The server receives ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Flashpoint

TLDR Information Security 2026-09-23

Flashpoint just named a Customer Favorite in the 2026 Forrester Wave™ for Threat Intelligence. (Sponsor)

Based on outstanding customer feedback in the all new Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. Flashpoint also received the highest scores possible for the Fraud Intelligence, Executive Protection, and Pricing Flexibility and Transparency criteria. 

Access the report to see how top vendors scored across 23 criteria and learn why Flashpoint is ideal for customers seeking primary source access intelligence.

Access the full report

🔓

Attacks & Vulnerabilities

TanStack NPM Supply Chain Attack Exposes 170 Private CrowdSec GitHub Repositories (2 minute read)

Attackers used a former CrowdSec employee's GitHub OAuth token following the May TanStack compromise. On May 22, they cloned about 170 private repositories within nine minutes. The leaked archive contained private code and contact data for 83 users. Investigators found no code changes, CI/CD access, or AWS access. The attackers tested one scoped SNS credential, but IAM permissions blocked it.
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day (3 minute read)

A zero-day allows any local macOS app or terminal command to redirect Muse transcription to an attacker-controlled server. The server receives the account token, enabling control over Muse and its connected email, WhatsApp, calendar, social accounts, microphone, camera, and files. Researcher Patrick Wardle demonstrated prompts that write files or take photos. Amazon also blocked Muse shopping requests as unauthorized.
ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang (2 minute read)

The ShinyHunters ransomware gang hacked the Clop ransomware gang's data leak site on Tor, defaced it, and claimed to have stolen server data and private keys for its onion service. The ShinyHunters claim to have exploited an unauthenticated file upload vulnerability in Grav CMS to breach the site. This appears to be the latest escalation in an ongoing feud between the two ransomware gangs.
🧠

Strategies & Tactics

A Scenario to Evaluate Your Agentic SOC (20 minute read)

A SOC investigation loop requires assembling a full attack chain from various different signals that may look benign or unrelated, which traditional, deterministic playbooks may miss. The authors built a set of scenarios to evaluate agentic SOC's investigative ability and built their own harness (called Tengu). Their scenario involves a GitHub workflow vulnerability that leads to full Kubernetes cluster compromise, which then is escalated to full AWS account compromise. Of the models tested on a naive prompt, only Opus 5 managed to identify the alert as a true positive without the Tengu harness
Infostealers Have Found a New Target: Your AI Agent (10 minute read)

Researchers from Gen have observed multiple new infostealers that harvest credentials, context, and local data from AI agents. Users and security teams should inventory what gets cached locally, keep secrets out of prompts and history, limit what connectors can do, and continue securing endpoints. Agent providers should also share the burden by providing more secure default behaviors.
The Closed Quorum: Inside the first reported autonomous AI C2 implant (9 minute read)

CLOSEDQUORUM, a Go-based Windows implant, uses DeepSeek, Qwen, Mistral, and Gemini as its C2. Every 5 to 15 minutes, the models vote through a constrained JSON schema on whether to steal LSASS, browser, and crypto wallet credentials, inject shellcode, or persist via Run keys, scheduled tasks, and WMI. Talos hasn't seen it in the wild, and the public build is an inert template, but it points to a credentials-as-a-service model where each operator gets a custom build and never needs to be online. Its dependence on commercial APIs brings refusals, rate limits, and a deterministic DeepSeek tiebreak, so defenders should correlate multi-provider LLM traffic from unexpected executables with LSASS access, suspended-process injection, WMI persistence, and Discord webhook exfil instead of blocking domains.
🧑‍💻

Launches & Tools

Add TLDR InfoSec to your Cybersecurity Awareness Month plan (Sponsor)

Your prospects will see cybersecurity ad after cybersecurity ad on social this October. In TLDR InfoSec, your ad reaches 410K cybersecurity professionals and is one of just three ads per issue. Learn more about our special Cybersecurity Awareness Month ad packages.
HelmGuard (Product Launch)

HelmGuard provides governance, risk, compliance, and security software. It gathers evidence from source systems, documents, and unstructured data, then automates risk assessments, assurance tasks, and control-gap reviews.
askWAM (GitHub Repo)

askWAM is a tool to request Microsoft Entra access tokens silently through Windows Web Account Manager (WAM).
DARKCLOAK (GitHub Repo)

DARKCLOAK chains the manipulation of all userspace-visible identity sources into an 11-phase sequential pipeline that progressively transforms a process until it becomes indistinguishable from the impersonated one to userspace monitoring tools.
🎁

Miscellaneous

Anthropic-linked CVEs pile up, attackers mostly shrug (2 minute read)

VulnCheck's Patrick Garrity tracked 225 CVEs tied to Anthropic's Project Glasswing, which gives partners access to the Claude Mythos Preview model for bug-hunting. Only one, a critical SQL injection in Ghost (CVE-2026-26980), has been exploited in the wild. Garrity says that historically 1-2% of vulnerabilities are weaponized, so this rate isn't unusual. AI models are uncovering more bugs, driving recent record patch counts from Microsoft, Apple, and Palo Alto Networks, but fixing bugs remains weak: 1Password found that Opus 4.8 and ChatGPT-5.5 fully resolved vulnerabilities in only 26% of 6,080 patches tested, and Veracode measured a 56% average security pass rate across 100+ models.
Google hit with $463 million fine for EU location data rule breach (2 minute read)

Ireland's Data Protection Commission fined Google 403 million euros for GDPR breaches involving location data. The probe covered Web & App Activity, Location History, and Android's Location Accuracy feature from 2018 through February 2020. Regulators found the processing unlawful, unfair, or opaque, even though Google said it changed its policies and released new location-management tools in 2019.
ShinyHunters Claims FBI Hack, Data Theft in PeopleSoft Zero-Day Breach (3 minute read)

The ShinyHunters claim to have breached the FBI's job site and networks using a zero-day in Oracle PeopleSoft. The ransomware gang claims to have stolen 2-3TB of data, including PII and PHI of current and former FBI employees and job seekers, as well as other internal records. The hackers said they carried out the attack in retaliation for an FBI FLASH report on ShinyHunters.
⚡

Quick Links

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites (1 minute read)

Attackers exploited Brevo SAML SSO handling, accessed 138 accounts, and later used a stolen Cloudflare API key.
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root (2 minute read)

Check Point patched CVE-2026-91843, a CVSS 9.8 login stack overflow.
glibc ld.so TOCTOU lets local users hijack $ORIGIN on setuid binaries (1 minute read)

A race in glibc's ld.so (CVE-2026-86805, versions 2.14 through 2.44) lets local users hardlink a setuid binary whose $ORIGIN RPATH uses ".." traversal and swap in a symlink to load attacker code with elevated privileges.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments