Latest

6/recent/ticker-posts

Header Ads Widget

Vercel KVM 0-day escape 💻, 543k GitHub keys leaked 🔑, DeepSeek agent hijack 🤖

A KVM zero-day reported by researcher Paulos Yibelo reportedly allowed guest code to gain root on the host, breaking the Firecracker microVM ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

TLDR Information Security 2026-10-05

🔓

Attacks & Vulnerabilities

Warlock Ransomware Hits Large Spanish, Portuguese Orgs (3 minute read)

Warlock, also tracked as Longlegs and Storm-2603, targeted four Spanish- or Portuguese-speaking organizations within two months: a water utility, telecom provider, regional government, and university. The group exploits Microsoft SharePoint flaws, then uses DLL sideloading, vulnerable drivers, VS Code remote tunnels, and SYSVOL replication to spread ransomware through Active Directory.
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data (3 minute read)

The Pentagon says a months-long intrusion exposed records for 2.8 million living people. Stolen Defense Manpower Data Center data included Social Security numbers, addresses, demographics, and military specialties. ShinyHunters also claimed FBI employee records, including roles investigating China and Russia. Officials have not disclosed the Pentagon entry point, attacker contact, ransom demands, or evidence supporting claims of no misuse.
Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000 (3 minute read)

A KVM zero-day reported by researcher Paulos Yibelo reportedly allowed guest code to gain root on the host, breaking the Firecracker microVM boundary Vercel Sandbox uses to isolate untrusted workloads and AI agents. Vercel CEO Guillermo Rauch confirmed the bug and that the $50,000 maximum bounty was awarded, but no CVE, affected kernel versions, exploit chain, or patch have been disclosed. Operators relying on KVM for multi-tenant isolation should watch for Vercel's promised write-up and Linux vendor advisories, and should not assume the unrelated Januscape fix covers this flaw.
🧠

Strategies & Tactics

GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them (12 minute read)

Truffle Security scanned 224 million public GitHub repositories and verified 543,699 working credentials in July. The median credential had been exposed for 784 days. The oldest dated to 2009. GitHub's push protection reduced leaks of recognized token types by about 53%, yet missed connection strings, private keys, and Google API keys. These accounted for 51.8% of live credentials. Revocation separated outcomes sharply: only one npm token remained active, while 11,465 Postgres strings and 69,041 Google Cloud credentials still worked.
How we release Fastify packages without npm tokens (8 minute read)

Fastify moved about 100 repositories from manual laptop releases to GitHub Actions using npm Trusted Publishers, which replace long-lived npm tokens with short-lived OIDC tokens bound to a specific repo, workflow, and environment. Releases are triggered manually via workflow_dispatch and wait for approval from the fastify/release team in a release environment restricted to main, then published with provenance through a SHA-pinned reusable workflow. Maintainers can script the same setup with npm trust github (npm 11.15.0+) and the GitHub environments API, then remove non-admin npm publish rights.
DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent (7 minute read)

ConfigPoisoning (CVE-2026-102437) ran attacker commands when a developer viewed a file diff in DeepSeek-Reasonix Studio, because a .gitattributes entry pointed the file at a command in a poisoned .git/config that the tool's hardened git wrapper never overrode. Since .git/config does not survive a clone, delivery needed an archive, synced folder, or CI cache, or a prompt-injected agent writing it into an already-cloned repo, and GitLab reports the same flaw class in several other coding agents under coordinated disclosure. Users should update to Studio 2.21.0 or npm 1.39.3, and builders of git-wrapping tools should override every command-executing config key on each call or read blobs with git cat-file and diff in-process.
🧑‍💻

Launches & Tools

Osavul (Product Launch)

Osavul analyzes open and privileged data to identify hostile intent targeting people, facilities, and supply chains. Analyst-reviewed assessments trace supporting evidence and run on-premises within sovereign infrastructure, keeping sensitive customer data inside customer systems.
Keymaker (GitHub Repo)

A local web interface to inventory, audit, revoke, and create OVHcloud API keys.
Apex Flash-1 (8 minute read)

Apex Flash-1 is an open-weights security research model from Cantina and Yeta Labs, a GLM-5.3-Flash fine-tune trained with GRPO reinforcement learning on 150 tasks built from 50 real vulnerability cases. It solved 40 of 60 tasks on Cantina's internal held-out eval versus 36 for the base model and 43 for Claude Opus 5 High, at an estimated $2.38 per run against $74.68, though each model ran the set only once. It is built as a worker model orchestrated by a larger one, and ships with an abliterated variant for teams running self-hosted security agents.
🎁

Miscellaneous

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing (3 minute read)

Proofpoint linked TA419 to credential-phishing campaigns against US policy specialists. The group spoofed Lynne Edwards Parker, Heidi Crebo-Rediker, and an Anthropic employee. Emails offered committee roles or report work, then sent victims to Cloudflare-protected pages mimicking OneDrive. Evilginx-based Browser-in-the-Browser pages targeted Microsoft 365 credentials and session cookies.
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers (3 minute read)

Spanish police arrested a 16-year-old in Alicante, suspected of administering KillSec. Operations across Spain, Greece, the UK, and Romania seized its leak site, five domains, five servers, and at least 110 TB of data. Investigators link KillSec to about 1,000 suspected attacks, including 500 confirmed compromises.
Apple's New macOS Controls Are the First OS-Level Move Specifically Targeting AI Agent Risks (4 minute read)

Apple announced that macOS will require very explicit user action to grant Full Disk Access, citing the risk of autonomous AI agents holding a permission that bypasses per-app TCC controls. The change tightens consent rather than banning FDA, and follows a disputed report of Meta's Muse agent reading a user's Messages and a ChatGPT Mac app flaw found by Objective-See. No macOS version or ship date was given for a change that touches agents like ChatGPT, Claude for Mac, and OpenClaw, which commonly request FDA.
⚡

Quick Links

Google's SOC Agent Investigated 5M Alerts, But Can Anyone Verify It? (Sponsor)

Thirty-minute triage now takes 60 seconds, but a verdict nobody can check is just a suggestion. Daniel Miessler discusses the context layer that makes agent findings auditable. Read here
Medical records giant Epic pauses product development to fix security bugs that risk patients' data (3 minute read)

Epic paused most product work for about six weeks after testing found MyChart flaws.
Federal judge calls Flock 'indiscriminate mass surveillance' (2 minute read)

A federal judge ruled that a Tulsa sheriff's deputy violated the Fourth Amendment by searching Flock's license plate database without a warrant, suppressing the resulting evidence in a non-binding ruling that is among the first to find a Flock search unconstitutional.
Citrix patches NetScaler SAML zero-day exploited in attacks (5 minute read)

Citrix released NetScaler ADC and Gateway 14.1-73.41 and 13.1-64.28 to fix CVE-2026-88779, an exploited SAML memory overflow that it classifies as a denial of service, though researchers found a patched honeypot running downloaded malware.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? 💼

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments