Daemon Tools Backdoored โ๏ธ, Robot Mower Hijacked ๐ , 38 OpenEMR CVEs Found ๐ฉบ
AI Summary
This edition covers multiple critical security vulnerabilities including 38 CVEs in OpenEMR affecting 100,000+ medical providers, a backdoored Daemon Tools installer affecting 100+ organizations, and a root-level exploit in a 4G industrial router. Additional coverage includes AI-generated password detection research, supply chain attack vectors via AI agent skill files, and new open-source security tools for AI infrastructure testing.
Key Facts
Author Takes
AI vibe-coding app security
Vibe-coding platforms like Replit, Lovable, and Base44 are producing insecure apps that leak sensitive data including hospital records and financial information with little or no authentication.
LLMs as password generators
LLMs should be prohibited as password generators because their statistical biases make outputs detectable and far more efficiently crackable than brute-force.
Contrarian Angle
AES-GCM replacing Traditional CBC encryption with static XOR key
Salesforce shipped AES-GCM to replace a legacy XOR scheme with a static repeating key after Searchlight Cyber demonstrated cross-tenant data exposure.
Engineers switching from Traditional CBC encryption with static XOR key to AES-GCM
More from TLDR
Opus 4.7 Fast โก, Qwen Image 2.0 ๐ผ๏ธ, serverless GPUs โจย ย
TLDR AI covers the launch of fast mode for Claude Opus 4.7 in research preview, Meta's Muse Spark model powering voice and glasses features, and Googl
CheckMarx Jenkins Hit โ๏ธ, OpenAI Daybreak ๐ค, Best Western Breached ๐จ
This cybersecurity newsletter covers a supply-chain attack on CheckMarx's Jenkins plugin by TeamPCP, a Shai-Hulud npm worm that compromised 42 @tansta
The Agent Mess Gets Real ๐ค, Cyber Gets Autonomous โ๏ธ, Cloudโs New Pitch ๐๏ธ
This TLDR IT edition covers OpenAI's new Daybreak cybersecurity initiative, a $125M Series B for AI security startup Exaforce, and GitLab's org restru