tl;dr sec logo
tl;dr sec
Guides
Subscribe
  • tl;dr sec
  • Topics
  • Newsletter

Newsletter

NewsletterSummaryBlogPodcast
NewsletterNewsletter
[tl;dr sec] #345 - Bug Rumors → Exploits, Version Control DFIR, Agentic Worms
Sep 10, 2026

[tl;dr sec] #345 - Bug Rumors → Exploits, Version Control DFIR, Agentic Worms

A bug description is sufficient for AI to find it and write an exploit, cheat sheet on doing DFIR for GitHub, GitLab and more, and a paper on self-replicating, open weight agentic worms

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #344 - VMs won't contain Cyber-capable Agents, AWS AI Security Analyst, Decompilers vs LLMs
Sep 08, 2026

[tl;dr sec] #344 - VMs won't contain Cyber-capable Agents, AWS AI Security Analyst, Decompilers vs LLMs

Model finds 0-days to escape a QEMU/KVM VM, how to build a $500/month threat hunting agent, a decompiler benchmark and an experimental, LLM-written decompiler

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #343 - Hugging Face Technical Report, AWSHound, OWASP Agentic Skills Top 10
Aug 27, 2026

[tl;dr sec] #343 - Hugging Face Technical Report, AWSHound, OWASP Agentic Skills Top 10

Full 38 page report from OpenAI on the incident, map your AWS environment, top 10 agent skill no no's

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #342 - Figma's Agentic Detection, Agent Identity, Uber's Agent-(E)DR
Aug 20, 2026

[tl;dr sec] #342 - Figma's Agentic Detection, Agent Identity, Uber's Agent-(E)DR

How Figma scales their detection and response, 1Password and Cloudflare on least privilege and identity for Agents, Uber's paper and OSS repo on monitoring and securing enterprise AI agents

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements
Aug 13, 2026

[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements

Deep dive and timeline of HF from OpenAI, Portswigger shows how CSS in webmail clients can be weaponized, GitHub's platform improvements

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning
Aug 07, 2026

[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning

Anthropic and Meta models hacked third parties during testing, #collab-ing with an agent in an IR notebook, deep dive post on Figma's AI-powered code scanning

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #339 - Hugging Face's Incident Report, Context Bombs, AI does Cryptanalysis
Jul 30, 2026

[tl;dr sec] #339 - Hugging Face's Incident Report, Context Bombs, AI does Cryptanalysis

HF does a detailed play-by-play of the incident with a neat visualization, stopping AI attackers via content that triggers their guardrails, Mythos finds attacks on HAWK and AES

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis
Jul 23, 2026

[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis

When models decide to find 0-days instead of solving a benchmark, using LLMs to extract EDR logic, Google's AI security review skills and pipeline

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity
Jul 16, 2026

[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity

Survey for AI-powered vulnerability finding harnesses, programmatically build complex decoy cloud environments, building hackbots

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?
Jul 09, 2026

[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?

An MCP powered system that's continuously finding and reproducing vulns, improvements to Datadog's OSS malware hunting tool, Hakluke muses on the future of bug bounty

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec
Jul 02, 2026

[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec

Interesting paper, LLM-powered hardening of the PHP ecosystem, security implications of the new MCP spec

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #334 - Thinkst's Package Proxy, OpenAI Daybreak, AI Agents & Canaries
Jun 25, 2026

[tl;dr sec] #334 - Thinkst's Package Proxy, OpenAI Daybreak, AI Agents & Canaries

OSS tool to prevent supply chain attacks without client-side firewalls, OpenAI announces new GPT-5.5-Cyber, Codex Security plugin updates, and more, can AI agents compromise an AWS cyber range without tripping canaries?

Clint Gibler
Clint Gibler
The best way to keep up with cybersecurity research. Join >90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.

tl;dr sec

The best way to keep up with cybersecurity research. Join >90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.

Home

Posts

Authors

Guides

Guides

Ā© 2026 tl;dr sec.

Powered by beehiiv