Latest

6/recent/ticker-posts

Header Ads Widget

Skill Poisoning for Agentic Malware Drop 🦠, OpenAI RubyGems hack 💎, Malicious Twitch extensions 👾

China's National Computer Virus Emergency Response Center is warning of "skill poisoning" attacks, where counterfeit plugins compromise AIf ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

TLDR Information Security 2026-09-15

🔓

Attacks & Vulnerabilities

Skill Poisoning Turns AI Agents Into Malware Droppers (3 minute read)

China's National Computer Virus Emergency Response Center is warning of "skill poisoning" attacks, where counterfeit plugins compromise AI agents to secretly download malware. Analysts have already identified eight malicious skill packs in popular agent repositories that impersonate legitimate tools, granting attackers unauthorized file access and remote-control capabilities. These poisoned plugins exploit an AI agent's natural task-execution design, bypassing the need for a user to actually click a suspicious link.
Telus Warns Customers of Account Breaches (2 minute read)

Telus says attackers used compromised credentials to access consumer accounts from February 2025 through June 2026. Exposed data included contact details, account and billing records, partial card numbers, subscriptions, and payment history. Attackers attempted service transfers and changed some services. Telus reset credentials, added monitoring, notified police, and offered identity-theft protection.
More JFrog Artifactory bugs under attack, and all 3 have patches (3 minute read)

Attackers are exploiting CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329 in JFrog Artifactory. Activity includes admin-account creation, Rust backdoors, Groovy plugins, web shells, token minting, and key theft. Wiz found 59 percent exposed to CVE-2026-42016 and 62 percent to CVE-2026-42018, so please patch exposed instances, restrict network access, and audit privileged logins.
🧠

Strategies & Tactics

Writing More Secure Code with LLMs: Why "Make No Mistakes" Falls Short (13 minute read)

Generic security prompts and OWASP-style checklists failed to improve AI coding security and occasionally increased the frequency of high-severity bugs when the Monad Foundation engineering team tasked an assistant with writing secure code for a URL unfurler. Utilizing an expert prompt that incorporates a specific application threat model reduced validated security findings by approximately 43 percent. Defenders must replace generic checklists with expert prompts incorporating specific application threat models to harden AI-generated code.
AI Makes Familiar Cyber Attacks Cheaper to Run (48 minute read)

Anthropic's threat intelligence report demonstrates that artificial intelligence lowers the cost of familiar cyber attacks against targeted organizations. The technology automates reconnaissance, retooling loops, and campaign coordination. Defenders must reassess their controls against repeated, parallel, and fast-adapting attack attempts despite the continued expense of compute resources and specialized exploits.
Malicious Twitch Browser Extension Exposes 30,000 Users' OAuth Tokens to Russian Bot Service (6 minute read)

Socket found that a cross-store browser extension, 'Twitch Enhanced Viewer | JeetBot', captures account OAuth tokens from Twitch pages. Current Chrome and Firefox builds add tokens to proxy redirect URLs for most viewed channels, but earlier builds sent tokens directly to set-token endpoints. The extension has about 31,000 installs across both stores, and anyone holding a token can access chat, whispers, account settings, and channel points. Remove the extension, disconnect Twitch sessions, and re-authenticate.
🧑‍💻

Launches & Tools

Peak traffic shouldn't mean peak anxiety (Sponsor)

Traffic skyrocketing? If you're on Microsoft Azure, there's no reason to panic. When user demand spikes, Azure adjusts capacity in the background. Performance stays steady with no manual intervention, no late-night firefighting, and no scrambling to explain why the site went down during the big launch. Build without limits with Azure
OpenThreat: what a security tool found in the open, as one file (2 minute read)

ThreatCrush launched OpenThreat to share public repository findings, threat indicators, and advisories in a single-file format without exposing private data or unredacted secrets. LogicSRC co-developed the specification to serve these descriptors at a standard web path. Nichedb.dev introduced the first directory for reading and distributing these descriptors across RSS, JSON, and APIs.
PHP Analysis Tools Catalog (GitHub Repo)

A curated, auto-updated catalog of PHP static-analysis, code-quality, linting, metrics, refactoring, and security tools.
Boost (GitHub Repo)

Boost wraps the commands your agents already run, turning noisy logs into compact, structured context.
🎁

Miscellaneous

Security Through Obscurity Is Dead And AI Delivered The Fatal Blow (6 minute read)

Artificial intelligence has delivered a fatal blow to security through obscurity by enabling the rapid discovery of deeply buried vulnerabilities in aging code and proprietary systems. Security experts warn that this rapid discovery creates immense pressure on defenders by exposing critical operational technologies. Defenders must respond by shifting away from endless patching toward proactive process improvements and systemic prevention.
OpenAI agents carried out an undisclosed cyber-attack on RubyGems (4 minute read)

Hundreds of malicious RubyGems packages appeared in May, attributed by researchers to internal OpenAI agents. The packages attempted API-key theft through an unreported RubyGems server flaw and used RubyDoc.info builds for arbitrary code execution. RubyGems halted registrations for four days, removed more than 500 packages, and later saw further uploads in May and June.
Everyone's Talking Past Each Other About the OpenAI/Huggingface Hack so Here's a Synthesized View (6 minute read)

Joshua Saxes attempts to synthesize different perspectives from AI safety researchers, cybersecurity experts, and policymakers on the OpenAI/Huggingface hack. Alignment and security go hand in hand to provide traditional and AI-native controls, with policy also acting as a backstop. Security's job is to provide a deterministic framework to reduce the blast radius of what an agent can do, whereas alignment's job is to constrain what an agent wants to do.

Quick Links

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data (5 minute read)

Threat actors target Microsoft enterprise users with passkey lures to bypass multi-factor authentication.
CRA vulnerability reporting with Daniel Thompson (35 minute read)

The Open Source Security podcast notes that the European Union Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities to ENISA.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments