tl;dr sec logo
tl;dr sec
Guides
Subscribe
  • tl;dr sec
  • Topics
  • Newsletter

Newsletter

NewsletterSummaryBlogPodcast
NewsletterNewsletter
[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements
Aug 13, 2026

[tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements

Deep dive and timeline of HF from OpenAI, Portswigger shows how CSS in webmail clients can be weaponized, GitHub's platform improvements

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning
Aug 07, 2026

[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning

Anthropic and Meta models hacked third parties during testing, #collab-ing with an agent in an IR notebook, deep dive post on Figma's AI-powered code scanning

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #339 - Hugging Face's Incident Report, Context Bombs, AI does Cryptanalysis
Jul 30, 2026

[tl;dr sec] #339 - Hugging Face's Incident Report, Context Bombs, AI does Cryptanalysis

HF does a detailed play-by-play of the incident with a neat visualization, stopping AI attackers via content that triggers their guardrails, Mythos finds attacks on HAWK and AES

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis
Jul 23, 2026

[tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis

When models decide to find 0-days instead of solving a benchmark, using LLMs to extract EDR logic, Google's AI security review skills and pipeline

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity
Jul 16, 2026

[tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity

Survey for AI-powered vulnerability finding harnesses, programmatically build complex decoy cloud environments, building hackbots

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?
Jul 09, 2026

[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?

An MCP powered system that's continuously finding and reproducing vulns, improvements to Datadog's OSS malware hunting tool, Hakluke muses on the future of bug bounty

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec
Jul 02, 2026

[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec

Interesting paper, LLM-powered hardening of the PHP ecosystem, security implications of the new MCP spec

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #334 - Thinkst's Package Proxy, OpenAI Daybreak, AI Agents & Canaries
Jun 25, 2026

[tl;dr sec] #334 - Thinkst's Package Proxy, OpenAI Daybreak, AI Agents & Canaries

OSS tool to prevent supply chain attacks without client-side firewalls, OpenAI announces new GPT-5.5-Cyber, Codex Security plugin updates, and more, can AI agents compromise an AWS cyber range without tripping canaries?

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #333 - Perplexity's Bumblebee, Evading Cloud Logging, AI Vuln Hunting Spec
Jun 18, 2026

[tl;dr sec] #333 - Perplexity's Bumblebee, Evading Cloud Logging, AI Vuln Hunting Spec

OSS tool to scan packages, agent configs, editors, and browser extensions for malware, tactics for evading cloud logging, a specification to generate your own custom agentic AI security scanning system

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security
Jun 11, 2026

[tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security

Why I joined OpenAI to lead Cyber efforts, playlist of the latest cloud security talks, AWS' supply chain best practices

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #331 - How Adversaries Use AI, Skill Issues, Using IDEs for C2
Jun 04, 2026

[tl;dr sec] #331 - How Adversaries Use AI, Skill Issues, Using IDEs for C2

Google's deep dive on how threat actors are using AI, bypassing malicious skill scanning, using VS Code dev tunnels for command and control

Clint Gibler
Clint Gibler
NewsletterNewsletter
[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates
May 28, 2026

[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates

100+ intentionally vulnerable AWS environments for practicing cloud attack paths, how OpenAI deploys Codex internally, Anthropic's update on bugs found and their open sourced harness

Clint Gibler
Clint Gibler
The best way to keep up with cybersecurity research. Join >90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.

tl;dr sec

The best way to keep up with cybersecurity research. Join >90,000 security professionals getting the best tools, talks, and resources right in their inbox for free.

Home

Posts

Authors

Guides

Guides

Ā© 2026 tl;dr sec.

Privacy policy

Terms of use

Powered by beehiiv