Latest

6/recent/ticker-posts

Header Ads Widget

Pentagon 3M data leak ๐Ÿช–, MCP Python SDK flaw ๐Ÿ, JadePuffer hits Azure ๐Ÿ’ฅ

The Defense Manpower Data Center exposed unencrypted personal data through a vulnerable file-sharing server. Unauthorized users accessed ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With FortiGate

TLDR Information Security 2026-09-30

One firewall dashboard for your entire hybrid network (Sponsor)

Hybrid environments mean more flexibility — and more consoles, more policies to sync, and more gaps to miss. This technical article shows how Gateway Load Balancer and FortiGate Next-Generation Firewall consolidate it all into a single dashboard.

See how the deployment works:

  • Gateway Load Balancer integration: Route traffic to a FortiGate security VPC for unified inspection
  • Unified security profiles: Configure routing tables and shared policies across cloud and on-premises
  • Real-time detection and response: Monitor threats and take action from a single FortiGate dashboard

Get the technical article →

๐Ÿ”“

Attacks & Vulnerabilities

Pentagon Personnel Agency Data Breach Impacts 3 Million People (1 minute read)

The Defense Manpower Data Center exposed unencrypted personal data through a vulnerable file-sharing server. Unauthorized users accessed files between October 2025 and July 16, 2026. Records included Social Security numbers, names, birth dates, contact details, demographic data, and military specialties. The breach affects 2.76 million living people and 294,000 deceased individuals.
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials (2 minute read)

A high-severity flaw in the official MCP Python SDK let malicious MCP servers redirect OAuth token requests to attacker-controlled endpoints. Affected 1.x (1.9.1–1.29.1) and 2.x (2.0.0–2.1.1) clients sent the client secret, authorization code, and PKCE proof key to the attacker, enabling full account takeover with the app's granted permissions. Fixes are in 1.30.0 and 2.2.0. ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider also require passing issuer= to pin the expected login service.
Automated AI Agent Used to Bread Cybersecurity Nonprofit DIVD (2 minute read)

The Dutch Institute for Vulnerability Defense (DIVD) reported that they suffered an AI-driven breach. The organization said that the breach was “loud and very, very messy” with the agent working autonomously and over explaining itself in comments, allowing the DIVD to easily reverse-engineer its attack. The threat actor exploited a vulnerability in a vulnerability in an undisclosed software that the organization stated was not Citrix NetScaler.
๐Ÿง 

Strategies & Tactics

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (15 minute read)

Sponsored Google results led victims to "Plus 5.6," a Custom GPT on chatgpt.com that answered every prompt with a fake outage notice pointing to a Google Sites ClickFix lure, and Huntress tied at least 40 incidents to the campaign. The eight-stage chain sideloaded malicious DLLs through Canon-signed (later Stardock-signed) binaries, hid its loader inside a WAV file and a NuGet package. It then unpacked a full-featured RAT from a custom encrypted file system that located its C2 over DNS-over-HTTPS. The signed hosts change with each wave, so defenders should detect behaviors instead: PowerShell spawning msiexec on GUID-named MSIs in %TEMP%, signed apps running from fake %LOCALAPPDATA%\Programs folders, and self-restoring Run key and scheduled task pairs, which require killing the process before removing persistence.
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations (14 minute read)

NeedyMantis is a modular post-compromise malware family deployed since at least October 2025 by China-based actors, including Storm-3069 from the DAEMON Tools supply chain compromise, against telecoms, universities, intergovernmental organizations, and government contractors. It was sideloaded as fake DLLs alongside legitimate software like Poedit, curl, Vim, and TightVNC, then unpacked from custom XOR-encrypted archives through shellcode loaders into a stripped-down PE format, and communicated over WebSockets with RC4-encrypted traffic and loadable modules. Defenders should hunt for spoofed DLLs such as WinSparkle.dll or libcurl.dll in unusual ProgramData paths, the hard-coded "firefox/21.0" user agent, and connections to corp.tripswithengine[.]com.
AI Agents Are Privileged Users; Who Is Auditing Their Access? (4 minute read)

Enterprises monitor human logins closely but often grant autonomous AI agents broad production access via long-lived service accounts and API tokens. These agents can initiate, approve, and execute high-value actions end-to-end, collapsing segregation of duties. The piece lays out six controls: isolate agent identities, scope permissions to the minimum needed, assign a business owner, log prompts and tool calls, run periodic access reviews, and build an out-of-band kill switch.
๐Ÿง‘‍๐Ÿ’ป

Launches & Tools

Tailscale PAM: credential-free access to your most sensitive infrastructure (Sponsor)

Standing credentials are a liability. Every shared password or SSH key is one more thing an attacker can steal.

Tailscale PAM grants access by identity instead, letting engineers reach databases and clusters without touching a secret. Sessions are logged. No jump hosts, no vaults.

[Join the Tailscale PAM beta waitlist]

Rig Security (Product Launch)

Rig Security provides an identity protection platform for agentic AI. It maps identity dependencies across providers, cloud, on-prem, network edges, and endpoints. A lightweight sensor distinguishes AI agent sessions from human sessions and enforces policy at runtime, and the system blocks risky agent actions without disabling the human account.
Malicious Drivers (Web App)

A searchable list of tracked, signed, and abused kernel drivers.
cryptoptic (GitHub Repo)

cryptoptic is a tool that uses CodeQL, orchestrated via GitHub Actions, to scan a repository or entire GitHub organization and produce an inventory of every cryptographic function in use, the library it comes from, and when it gets called.
๐ŸŽ

Miscellaneous

24-Year-Old Arrested in Dutch Investigation Into ShinyHunters (4 minute read)

Dutch police arrested a 24-year-old Amsterdam man, identified by multiple sources as Pepijn van der Stap (aka “Umbreon”), in connection with the ShinyHunters hacking group. He previously served time for extorting over a dozen companies, earning €1.5–2.7 million, and was released in December while still facing civil suits.
FBI reportedly declares ‘cyber security incident' after hackers steal agents' personal data (4 minute read)

The FBI told staff that a hack of its FBIJobs.gov portal exposed agents' and applicants' names, addresses, job titles, Social Security numbers, and some medical records, including blood and urine samples and psychiatric reports. ShinyHunters says it exploited an Oracle PeopleSoft vulnerability and is not demanding money, but wants the bureau to correct an earlier report about its activities. The portal remains offline, and the bureau has not publicly confirmed whether the breach meets the legal threshold for a “major incident” requiring notification to Congress.
⚡

Quick Links

OpenAI scraps rollout of new AI model over safety concerns (3 minute read)

OpenAI will not release GPT-6.1 Astra after tests found problems with scope, authorisation, and reporting completed work.
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources (4 minute read)

Microsoft linked Storm-3168, the actor behind JadePuffer (the first documented agentic ransomware), to an 18-hour June attack in which two hijacked Azure service principals were used for reconnaissance and then destruction, likely after an employee exposed client secrets in a public GitHub issue.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? ๐Ÿ“ฐ

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? ๐Ÿ’ผ

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments