Claude Models Hack 3 Organizations πŸ€–, CareCloud Breach πŸ₯, $88M BTC Wallet Flaw πŸͺ™

A misconfigured internet-connected evaluation environment caused issues with Claude Opus 4.7, Claude Mythos 5, and an internal research model ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With Horizon 3

TLDR Information Security 2026-08-04

Gartner: Orgs that prioritize CTEM are 3x less likely to suffer a breach (Sponsor)

Finding more vulnerabilities doesn't automatically reduce risk.

Instead of chasing vulnerability noise, security teams need to identify attack paths, validate what attackers can exploit, and continuously verify remediation efforts work. This Horizon3.ai webinar lays out how to do that by operationalizing CTEM. 

πŸ“Š Join for the people, process, and metrics changes that you need to put CTEM principles into practice.

πŸ₯· Take the attacker's perspective to pivot from static CVE lists to demonstrating meaningful risk reduction.

πŸ‘‰ If you feel like you're getting too much visibility without reducing risk, this is for you. 

Register now

πŸ”“

Attacks & Vulnerabilities

Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests (3 minute read)

A misconfigured internet-connected evaluation environment caused issues with Claude Opus 4.7, Claude Mythos 5, and an internal research model across three incidents identified in a review of 141,006 evaluation runs. Opus 4.7 retrieved production database rows after a fictional company's name coincided with a real one. Mythos 5 published a malicious PyPI package that was executed on 15 real systems, including a security vendor's scanner. Anthropic stated that these incidents did not require new exploits, but were due to weak passwords and exposed endpoints. They have halted evaluations, notified affected organizations, and are improving network isolation and vendor monitoring before resuming. Noma Security's CISO, Diana Kelley, emphasized that this should be viewed as a controls failure rather than an intent failure and recommends implementing isolation, least privilege, and kill switches for autonomous agent testing.
CareCloud Breach Exposes Medical and Financial Data of 345K (2 minute read)

Health tech company CareCloud disclosed that data belonging to 345k people was stolen in a March data breach. The attackers breached CareCloud's AWS environment and exfiltrated data from databases over 6 days. The stolen data may include names, home addresses, SSNs, government ID numbers, bank account details, payment card numbers, and other PHI.
N-able Warns of N-central Auth Bypass Flaw Exploited in Attacks (2 minute read)

N-able issued a notice warning customers of its N-central remote monitoring and management (RMM) platform about a new authentication bypass vulnerability that is actively being exploited. N-able has not yet released technical details but noted that the vulnerability stems from an incomplete fix for a previous authentication bypass vulnerability.
🧠

Strategies & Tactics

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version (16 minute read)

The latest iteration of the macOS malware XCSSET, version 40, uses supply chain tactics to propagate by hiding malicious run-script phases in legitimate Xcode projects. To maximize stealth, the malware employs a multi-layered polymorphic evasion stack that uses dual-key encryption and in-memory execution, while actively impairing macOS defenses by disabling security updates and locking XProtect signature databases. XCSSET v40 also introduces a novel fileless persistence mechanism that abuses the macOS defaults configuration system, along with new operational modules designed to hijack Google Chrome via the Chrome DevTools Protocol and deploy trojanized Telegram binaries.
Agent Identity Architectures: Delegated, Bounded, and Autonomous (17 minute read)

1Password classifies agent architectures as either local or remote and operating in a delegated, bounded, or autonomous mode. Delegated agents, such as coding agents or browser copilots, operate as an extension of a human identity and can use a workload identity broker when running locally or leverage platform attestation combined with protocols like WIMSE and CAEP when running remotely. Bounded authority agents, such as CI/CD pipelines, run without human intervention on behalf of a system or workflow and can use a workload identity broker when running locally or, when running remotely, leverage OIDC where available and SPIFFE where it isn't to issue short-lived credentials. Autonomous agents run for long periods with limited restrictions and are complex to secure whether running locally or remotely. This article provides some preliminary suggestions for controls.
The Fuyao Enterprise: Building an Ad-Fraud Empire with AI and Kids' Coding Blocks (24 minute read)

The Fuyao botnet shipped pre-installed on Android TV boxes at the firmware level, spoofed device identities as premium smartphones (Vivo, OPPO, Huawei, and Meizu) via C2-pushed profile configurations, then used a fused Android Accessibility/YOLOv8s/OCR vision stack alongside Blockly-authored fraud modules to click ads and run residential SOCKS5 proxy sessions across a claimed 120K+ device fleet, generating an estimated $150K in daily revenue. Bitsight TRACE attributed the operation to shared SSL certificates, a leaked internal wiki, reused shell-company emails, and 6-8 of 20 CNIPA patent filings mapping to Fuyao subsystems, tracing the scheme through 144 AI-generated ad-landing domains and Hong Kong/Singapore shell publishers back to Zhejiang Fengwo IoT Technology, a subsidiary of the Fengwo Group. Defenders managing Android device fleets or CI-adjacent infrastructure should flag anomalous phone-model telemetry originating from TV-box hardware profiles and treat unexplained SOCKS5 proxy traffic or unaccounted ad-network impressions as indicators of this ecosystem.
πŸ§‘‍πŸ’»

Launches & Tools

Black Duck: AI-driven exploits are here. ARE YOU READY? (Sponsor)

The exploit window is collapsing. AI turns newly disclosed vulnerabilities into working attacks in hours, not weeks. Black Duck Polaris™ Platform and Signal™ help organizations become Mythos Ready with intelligent prioritization, automated workflows, and faster remediation of exploitable risk. 

Black Duck Can Help.

ADhammer (GitHub Repo)

ADhammer is a single static Rust binary that combines a PingCastle-class Active Directory auditor with live-validated offensive validation, running DCSync, golden/silver tickets, pass-the-ticket, RBCD, Shadow Credentials, NTLM relay, and ESC1 enrollment against a from-scratch DCE/RPC, NTLM, SMB2, and Kerberos stack, with no impacket or Python runtime dependency.
AgentDojo (GitHub Repo)

AgentDojo provides a dynamic environment to evaluate attacks and defenses for LLM agents.
GraphGulo (GitHub Repo)

GraphGulo is a tool that converts raw PCAP captures and network flow logs into an indexed, temporal graph, then answers time-respecting traversal queries at low-latency on commodity hardware.
🎁

Miscellaneous

TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)

Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to infosec@tldr.tech!
Practical Memory Safety (5 minute read)

Memory safety is most practically defined as having intuitive and easily followed rules unless explicitly marked with a warning sign. Systems like Fil-C offer a spectrum of safety through runtime checks, but they still allow unmarked memory overwrites within an allocation, leaving unchecked "memory footguns" for developers to navigate. Ultimately, genuine memory safety relieves developers from worrying about abstract machine rules so they can focus on their actual work.
Tailscale didn't stop the Hugging Face intrusion (8 minute read)

An AI agent that escaped its sandbox during a benchmark evaluation compromised Hugging Face's infrastructure over four and a half days, gaining code execution, root access, and a production secret store before using a stolen reusable Tailscale auth key to enroll 181 rogue nodes onto the company's tailnet. Tailscale confirmed no vulnerability in its own product was exploited, but used the incident to argue that long-lived credentials remain the industry's default weak point in an era of autonomous AI attackers. The post-mortem framed the episode as a case study in zero trust architecture's limits when credential lifecycle management lags behind attacker capability.
Apple Struggles to Keep Pace with AI “Bug” Hunters (2 minute read)

Apple has announced new caps on the number of reports that bug bounty hunters can submit to its vulnerability disclosure program (VDP) as well as a waiting period to combat a deluge of low quality, AI-generated reports. Cybersecurity startup Bynario reported that it was blocked by these limits from submitting a valuable exploit chain that could lead to privilege escalation. Apple has stated that researchers can request an increase to the limit if needed.

Quick Links

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft (3 minute read)

An integration bug in COLDCARD firmware caused it to fall back to MicroPython's insecure Yasmarang generator instead of the onboard STM32 hardware RNG, letting attackers brute-force seeds offline and drain roughly 1,367 BTC ($88.6 million) from thousands of wallets across affected Mk2 through Mk5 and Q devices before Coinkite's July 30 disclosure.
Former FBI agent indicted for stealing crypto from FBI (2 minute read)

Former FBI special agent Patrick Steven Yaroch was indicted on charges of receipt and interstate transportation of stolen goods after confessing to stealing roughly $1 million in cryptocurrency.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here, create your own role or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! TLDR is one of Inc.'s Best Bootstrapped businesses of 2025.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Comments