tl;dr sec logo
tl;dr sec
Guides
Subscribe
  • tl;dr sec
  • Topics
  • Newsletter

Newsletter

NewsletterSummaryBlogPodcast
NewsletterNewsletter
[tl;dr sec] #347 - AI Agents Hacking Companies for $25, Threat Hunter's Guide to GitHub, Finding Gadgets Like it’s 2026
1 hour ago

[tl;dr sec] #347 - AI Agents Hacking Companies for $25, Threat Hunter's Guide to GitHub, Finding Gadgets Like it’s 2026

Threat actor using open source harnesses to hack companies, how to use GitHub logs to find baddies, using LLMs to find novel Java deserialization gadgets

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #346 - Can AI Do Novel Security Research?, Anthropic's Threat Intel Report, How Cloudflare Enforces Engineering Standards
Sep 17, 2026

[tl;dr sec] #346 - Can AI Do Novel Security Research?, Anthropic's Threat Intel Report, How Cloudflare Enforces Engineering Standards

Portswigger's James Kettle's HTTP Terminator, pretty crazy report about how threat actors were abusing Claude, how Cloudflare enforces code quality at scale

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #345 - Bug Rumors β†’ Exploits, Version Control DFIR, Agentic Worms
Sep 10, 2026

[tl;dr sec] #345 - Bug Rumors β†’ Exploits, Version Control DFIR, Agentic Worms

A bug description is sufficient for AI to find it and write an exploit, cheat sheet on doing DFIR for GitHub, GitLab and more, and a paper on self-replicating, open weight agentic worms

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #344 - VMs won't contain Cyber-capable Agents, AWS AI Security Analyst, Decompilers vs LLMs
Sep 08, 2026

[tl;dr sec] #344 - VMs won't contain Cyber-capable Agents, AWS AI Security Analyst, Decompilers vs LLMs

Model finds 0-days to escape a QEMU/KVM VM, how to build a $500/month threat hunting agent, a decompiler benchmark and an experimental, LLM-written decompiler

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #343 - Hugging Face Technical Report, AWSHound, OWASP Agentic Skills Top 10
Aug 27, 2026

[tl;dr sec] #343 - Hugging Face Technical Report, AWSHound, OWASP Agentic Skills Top 10

Full 38 page report from OpenAI on the incident, map your AWS environment, top 10 agent skill no no's

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #342 - Figma's Agentic Detection, Agent Identity, Uber's Agent-(E)DR
Aug 20, 2026

[tl;dr sec] #342 - Figma's Agentic Detection, Agent Identity, Uber's Agent-(E)DR

How Figma scales their detection and response, 1Password and Cloudflare on least privilege and identity for Agents, Uber's paper and OSS repo on monitoring and securing enterprise AI agents

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements
Aug 13, 2026

[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements

Deep dive and timeline of HF from OpenAI, Portswigger shows how CSS in webmail clients can be weaponized, GitHub's platform improvements

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning
Aug 07, 2026

[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning

Anthropic and Meta models hacked third parties during testing, #collab-ing with an agent in an IR notebook, deep dive post on Figma's AI-powered code scanning

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #339 - Hugging Face's Incident Report, Context Bombs, AI does Cryptanalysis
Jul 30, 2026

[tl;dr sec] #339 - Hugging Face's Incident Report, Context Bombs, AI does Cryptanalysis

HF does a detailed play-by-play of the incident with a neat visualization, stopping AI attackers via content that triggers their guardrails, Mythos finds attacks on HAWK and AES

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis
Jul 23, 2026

[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis

When models decide to find 0-days instead of solving a benchmark, using LLMs to extract EDR logic, Google's AI security review skills and pipeline

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity
Jul 16, 2026

[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity

Survey for AI-powered vulnerability finding harnesses, programmatically build complex decoy cloud environments, building hackbots

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?
Jul 09, 2026

[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?

An MCP powered system that's continuously finding and reproducing vulns, improvements to Datadog's OSS malware hunting tool, Hakluke muses on the future of bug bounty

Clint Gibler
Clint Gibler
The best way to keep up with cybersecurity research. Join >90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.

tl;dr sec

The best way to keep up with cybersecurity research. Join >90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.

Home

Posts

Authors

Guides

Guides

Β© 2026 tl;dr sec.

Powered by beehiiv