TLDR Information Security 2026-07-29
Bank of Baroda Leak ๐ฆ, Alibaba NPM RAT ๐ฆ, Claude FakeAgent ๐ค
๐
Attacks & Vulnerabilities
Customer Data from India's Bank of Baroda Leaked Online (2 minute read)
India's state-run Bank of Baroda disclosed that customer data was stolen via a breach of an employee's email. The bank has stated that no core banking systems were accessed. The breached data includes customer details, ID numbers, loan papers, and internal audit data.
Australia's Origin Energy Flags Possible Data Exposure of About 900K Customers (2 minute read)
Australia's top electricity and gas supplier, Origin Energy, disclosed that data linked to about 900k current and former customers had been accessed in a cybersecurity incident. Origin didn't disclose the precise data accessed but stated that it could include financial data such as the last few digits of customers' credit card numbers or bank account numbers.
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers (8 minute read)
Socket uncovered a three-month stealth campaign involving 18 npm packages that split loader functions across dependencies, making malicious intent hard to detect. They used unscoped lures impersonating Alibaba's @ali scope, pulling in smart-config-manager, which depends on cloud-config-fetcher and local-config-parser to retrieve attacker rules from GitHub and escape the Node.js vm sandbox via items.constructor.constructor. The staged aone-cli payload, a cross-platform RAT, supports command execution, file transfer, screenshots, an encrypted reverse TCP proxy, and DingTalk lateral movement. It persists through a ~/.zshrc entry, a 10-minute macOS Launch Agent, a trojanized Windows app.asar, and a Linux binary in /tmp, with C2 traffic masked by spoofed headers. Affected hosts should be treated as compromised. Reset secrets from clean systems and hunt for Python files with the identifier above.
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability (10 minute read)
Lava researchers scanned UDP port 623 and found 36,872 internet-exposed IPMI hosts, of which 24,650 returned a password-derived HMAC-SHA1 hash during the RAKP authentication exchange before login completed due to CVE-2013-4786, letting an unauthenticated party crack passwords offline. More than half of responding devices were Supermicro systems whose post-2019 unique ten-character factory passwords (a 26^10 keyspace) could still be exhausted in about an hour on an eight-GPU rig, while HPE iLO's eight-character factory format cracked in roughly 32 seconds per captured response. The team also found a live iLO 4 interface defaced with a ransom note demanding 0.3 BTC, evidence that this exposure is already being exploited rather than theoretical, and disclosed the Supermicro password-recovery timeline to the vendor in June, who confirmed it as plausible and is reviewing longer default password formats. Operators should block UDP port 623 at the network edge, rotate factory-issued BMC credentials during provisioning, disable IPMI 1.5, cipher suite 0, and NONE authentication, and isolate BMC access behind a dedicated management VLAN, bastion host, or VPN rather than exposing IPMI or Redfish directly to the internet.
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT (13 minute read)
A Bing search for "claude desktop app" returned a sponsored link pointing at a genuine claude[.]ai artifact URL, and that user-generated page redirected through claude.ai.download-app[.]us and downloading-api.it[.]com to a ClaudeDesktop.exe that was really JetBrains jcef_helper.exe sideloading a tampered libcef.dll, packed with VMProtect and pulling its next stage from an Ethereum BSC contract using the EtherHiding technique, while a second persistence path dropped a signed IBM SPSS binary as sslconf.exe alongside a malicious tempdir.dll that gated execution on DXGI adapter IDs, sub-1GB VRAM, and compute shader timing to defeat sandboxes, then decrypted its payload with a DirectX shader running a modified AES-256-CTR rather than any hookable crypto API. Huntress traced the resulting SectopRAT build to C2 at 2.24.131[.]246, tied the registrant of download-app[.]us to ten domains going back to December 2025, and matched the tradecraft to a fake Docker Desktop campaign in April that used the same libcef.dll sideloading pattern against 29 organizations between July 21 and 22. Hunt for ClaudeDesktop.exe and DockerDesktop.exe writes, scheduled tasks pointing into %APPDATA%\Roaming\Microsoft\EdgeUpdate\Install, and Defender exclusions added around software installs, block the listed C2 range and the two BSC contracts as pivot indicators, and treat vendor domains as untrusted download sources when the landing page is a user-generated artifact, since the Anthropic disclaimer that artifact content is unverified was the only signal separating this page from a real one before takedown at 7,100 views.
๐งโ๐ป
Launches & Tools
6,000+ "guardrail-free" AI models. One download away. (Sponsor)
AI-powered cybercrime is no longer just a future risk.
ThreatDown's new research found it's already here, hiding in plain sight on infrastructure organizations already trust.
ThreatDown researchers assess that AI capable of exploiting vulnerabilities at scale could reach criminal marketplaces within roughly six months. Read the
Cybercrime in the age of AI report.
Project Incantation (GitHub Repo)
Project Incantation is a defensive security toolkit for generating adversarial honeydocuments.
Privacy-focused search engine NeoSearch open-sources code to promote decentralized web search (2 minute read)
NeoSearch has open-sourced its codebase under the Apache License 2.0, letting anyone inspect, modify, or self-host the ad-free, no-tracking search engine, which uses AI to downrank SEO-driven and affiliate content in favor of independent and authoritative sources while grouping and rewriting result snippets through its Lenses interface.
FENGARDE (GitHub Repo)
FENGARDE is an open source (Apache-2.0) SIEM aimed at European industrial Mittelstand operators, normalizing 16 parsers spanning Cisco ASA, Windows Event Log, Sysmon, Kubernetes audit, CloudTrail, Modbus/TCP, OPC UA, n8n, and MCP tool-call audit logs into OCSF, running 27 correlation rules over a sliding window into OpenSearch, and rendering alerts as draft NIS2 Article 23 and ยง32 BSIG incident notifications with every entity-specific fact left as an explicit analyst placeholder rather than fabricated. Triage runs against a local Ollama instance with a documented passthrough stub, so alert data never reaches a third-party LLM API, and the whole detection path is demonstrable without Docker through a zero-infra acceptance test.
OpenAI's Agent Didn't Go Rogue. Its Governance Did (6 minute read)
The recent incident where an unreleased and unguardrailed OpenAI model autonomously hacked Hugging Face is commonly portrayed as an incident of a model going rogue. This is the wrong framing. The agent stayed aligned with its objective of finding a solution to the ExploitGym benchmark but wasn't given the guardrails or governance to understand that trying to steal the solution wasn't an acceptable attack path. The situation is also complicated by the fact that frontier labs are not incentivized to reduce their models' capabilities in tests and the fact that this incident was almost an advertisement for OpenAI.
TLDR is hiring a curator for TLDR Infosec! (TLDR Curator, ~5 hrs/week)
Over 400,000 subscribers read TLDR Infosec to stay on top of the latest in cybersecurity, vulnerabilities, breaches, threat research, and security tools. If you work in security and want to help curate it, send your LinkedIn or resume to
infosec@tldr.tech!
The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes (22 minute read)
Silent Signal reverse-engineered IBM i's QSYRUPWD API by tracing SCV 10 CIPHER calls through disassembly and live memory patching, mapping how the system chains SHA-1, MD5, AES-128, and Rijndael-256 operations to protect password verifiers once QPWDLVL moves past the legacy DES/SHA-1 modes. The team reconstructed the full decryption chain and confirmed it recovers crackable DES, SHA-1, and NT hash material even at QPWDLVL 4, despite the API requiring *ALLOBJ and *SECADM authority to call.
Some People's Chats with Claude AI Found to be Publicly Available Online (2 minute read)
Users of claude.ai recently discovered that shared chats were indexed by search engines and could be viewed in search results. Anthropic has responded that these chats were shared publicly by users via the option to make them available to anyone with the link. Despite this, some users were surprised to find that they were indexed by search engines.
Curated news ๐ฐ, research ๐งโ๐ฌ, and tools ๐ for information security professionals
Join 400,000 readers for
one daily email