REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 11 of 54

the_hacker_news · tlp:amber · 7/10/2026, 3:57:14 PM
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device S…
Read original ↗https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html[$] An update on the scraper situation Our article " Fighting the AI scraper bot scourge ", published in early 2025, discussed the problem of widespread scraping of web sites in search of training data for large language models and related projects. This activity overwhelms sites with traffic. Over a year after that article is published, the problem is still growing. The hammering of sites by shadowy actors has reached new heights, and the open web is becoming increasingly d…
securityweek · tlp:amber · 7/10/2026, 3:01:19 PM
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops appeared first on SecurityWeek . In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Di…
Read original ↗https://www.securityweek.com/in-other-news-dhs-database-hacked-adobe-boosts-patch-cadence-canada-disrupts-ransomware-ops
the_hacker_news · tlp:amber · 7/10/2026, 2:51:49 PM
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is not an emergency for most owners. The attack needs Laser A…
Read original ↗https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html
the_hacker_news · tlp:amber · 7/10/2026, 2:19:50 PM
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows - GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system Researcher D…
Read original ↗https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.htmllwn_kernel · tlp:amber · 7/10/2026, 1:50:40 PM
[$] QBE 1.3: metaprogramming, performance, and cross-platform support QBE , a compact compiler backend developed by Quentin Carbonneaux, is a lightweight alternative to larger compiler backends such as LLVM and GCC. Designed to be small enough for a single developer to understand, QBE uses a static single-assignment (SSA) intermediate representation (IR), supports the C ABI, and serves as the backend for projects such as Hare and the cproc C11 compiler. Frontends emit the te…
Read original ↗https://lwn.net/Articles/1080519lwn_kernel · tlp:amber · 7/10/2026, 1:41:03 PM
Security updates for Friday Security updates have been issued by AlmaLinux (aardvark-dns, cups, edk2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, oci-seccomp-bpf-hook, python-urllib3, and tomcat), Debian (rlottie), Fedora (c-ares, k9s, kind, libXfont2, nmap, pam, perl-DBI, php, python-pendulum, tmux, and xorg-x11-server-Xwayland), Mageia (7zip and ack), Slackware (tigervnc), S…
Read original ↗https://lwn.net/Articles/1082272
the_record · tlp:amber · 7/10/2026, 1:20:00 PM
China, India ran separate spying campaigns against same Pakistani police force The activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency. China, India ran separate spying campaigns against same Pakistani police force | The Record from Recorded Future News Leadership Cybercrime Nation-state I…
Read original ↗https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-forcethe_hacker_news · tlp:amber · 7/10/2026, 1:15:23 PM
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational New MODBEACON RAT Uses…
Read original ↗https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.htmlsecurityweek · tlp:amber · 7/10/2026, 12:58:39 PM
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. The post Third US Security Expert Sentenced to Prison for Helping Ransomware Gang appeared first on SecurityWeek . Third US Security Expert Sentenced to Prison for Helping Ransomware Gang - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity C…
Read original ↗https://www.securityweek.com/third-us-security-expert-sentenced-to-prison-for-helping-ransomware-gangcisa_alerts · tlp:amber · 7/10/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant r…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalogsecurityweek · tlp:amber · 7/10/2026, 11:55:11 AM
China, India-Linked Hackers Both Targeted Same Pakistani Police Force Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Same Pakistani Police Force appeared first on SecurityWeek . China, India-Linked Hackers Both Targeted Same Pakistani Police Force - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecuri…
Read original ↗https://www.securityweek.com/china-india-linked-hackers-both-targeted-same-pakistani-police-force
the_hacker_news · tlp:amber · 7/10/2026, 11:47:43 AM
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server Unpatched XRI…
Read original ↗https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html
the_hacker_news · tlp:amber · 7/10/2026, 11:39:40 AM
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a single view, and every downstream security program inherits whatever the inventory gets wrong. Lumen Technol…
Read original ↗https://thehackernews.com/2026/07/from-17000-to-11-million-assets-how.html
the_hacker_news · tlp:amber · 7/10/2026, 11:30:02 AM
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside. The operation, now tracked as …
Read original ↗https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.htmlsecurityweek · tlp:amber · 7/10/2026, 11:06:36 AM
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek . Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats Cyb…
Read original ↗https://www.securityweek.com/okta-warns-of-vishing-attacks-targeting-microsoft-365-customers
the_hacker_news · tlp:amber · 7/10/2026, 10:56:23 AM
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been installed more than 2.4 billion times. The problems are basic, not sophisticated. 29 apps let user traffic leak outsid…
Read original ↗https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html
the_hacker_news · tlp:amber · 7/10/2026, 10:30:20 AM
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-UNC-066, has deployed a panel-controlled phishing kit that's capable of targeting the passkey enrollment process. The …
Read original ↗https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.htmlsecurityweek · tlp:amber · 7/10/2026, 9:12:08 AM
GigaWiper Combines Multiple Malware for System-Level Sabotage The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek . GigaWiper Combines Multiple Malware for System-Level Sabotage - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware &…
Read original ↗https://www.securityweek.com/gigawiper-combines-multiple-malware-for-system-level-sabotage
the_hacker_news · tlp:amber · 7/10/2026, 9:00:05 AM
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. Coinspect has confirmed one coordinated sw…
Read original ↗https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.htmlsecurityweek · tlp:amber · 7/10/2026, 8:32:33 AM
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek . 'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual E…
Read original ↗https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism
the_hacker_news · tlp:amber · 7/10/2026, 8:10:12 AM
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023. In a sentencing memorandum, federal prosecutors described Martino as a " Ransomwa…
Read original ↗https://thehackernews.com/2026/07/ransomware-negotiator-gets-70-months-in.htmlsecurityweek · tlp:amber · 7/10/2026, 8:00:14 AM
Network of 200 GitHub Repositories Used for Malware Infection A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek . Network of 200 GitHub Repositories Used for Malware Infection - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Thr…
Read original ↗https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infectionarxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
MLQENABLER: Enabling Secure Machine Learning Queries over Encrypted Database in Cloud Computing arXiv:2607.08197v1 Announce Type: new Abstract: In cloud computing, the public cloud service providers (CSPs) can provide cloud storage as the primary service while providing additional machine learning (ML)-based services by using the clients' data in storage. This business model extends the border of cloud computing services and brings in new business growth possibilities. Altho…
Read original ↗https://arxiv.org/abs/2607.08197arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Forensic Schema for Psychological Manipulation in Cyber Fraud: LLM-Driven Victim Reports Analysis arXiv:2607.07751v1 Announce Type: new Abstract: Existing cybercrime classification schemas capture contact metadata and financial transactions but omit the psychological manipulation techniques perpetrators employ. We present a forensic schema (four categories, 35 questions) adding 11 manipulation indicators and cryptocurrency evidence fields to established forensic foundations.…
Read original ↗https://arxiv.org/abs/2607.07751arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Threshold Authorization Without Threshold Signatures: Signature-Agnostic MPC Custody arXiv:2607.08226v1 Announce Type: new Abstract: Digital-asset custody has been built on threshold multi-party approval: no operation proceeds unless $t$ of $n$ parties approve, and fewer than t compromised parties can neither authorize nor learn the authorization secret. Threshold signature schemes (TSS) have been the standard mechanism, but the post-quantum transition disrupts this model: s…
Read original ↗https://arxiv.org/abs/2607.08226arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Multi-Agent Firewall Architecture for Privacy Protection of Sensitive Data in Interactions with Language Models arXiv:2607.08282v1 Announce Type: new Abstract: While Large Language Models (LLMs) have become essential productivity tools, their integration into workflows without adequate safeguards creates significant risks. This paper proposes an open-source, privacy-focused, user-facing firewall designed to secure both web-based and programmatic LLM interactions. The archite…
Read original ↗https://arxiv.org/abs/2607.08282arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
zkComposer: Decomposing Proof Construction to Scale zkML arXiv:2607.08095v1 Announce Type: new Abstract: Zero-knowledge machine learning (zkML) enables a server to perform verifiable inference while keeping model parameters private from the client. However, existing zkML systems incur prohibitive proof-generation costs. We observe that proof generation exhibits limited parallelism; that is, prover time does not decrease significantly as the number of threads increases. This …
Read original ↗https://arxiv.org/abs/2607.08095arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure arXiv:2607.08288v1 Announce Type: new Abstract: In critical infrastructure, operational technology environments often cannot be actively scanned, and yet active system feedback is needed for risk assessment and compliance. This paper presents a non-invasive, MCP-grounded multi-agent pipeline that converts natural-language system descriptions in…
Read original ↗https://arxiv.org/abs/2607.08288arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Mechanistic Interpretability of LLM Jailbreaks via Internal Attribution Graphs arXiv:2607.07903v1 Announce Type: new Abstract: Large language models (LLMs) exhibit remarkable capabilities but remain highly vulnerable to adversarial prompts and jailbreak attacks. Existing approaches primarily analyze these failures through input-output behaviors or attribution methods, offering limited insight into how adversarial perturbations alter the model's internal reasoning. Consequent…
Read original ↗https://arxiv.org/abs/2607.07903arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
KS-CFA: Control-Flow Attestation via Symbolic Replay Against Control-Flow Bending Attacks arXiv:2607.07926v1 Announce Type: new Abstract: Control-flow attestation (CFA) enables a remote entity to verify program execution on a target device by monitoring control-flow behaviour at runtime. However, control-flow bending (CFB) attacks remain difficult to detect, where an adversary steers execution along legal edges of the program's control-flow graph by corrupting branch flags, …
Read original ↗https://arxiv.org/abs/2607.07926arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
TRACE: A Two-Channel Robust Attribution Watermark via Complementary Embeddings for LLM-Agent Trajectories arXiv:2607.08400v1 Announce Type: new Abstract: LLM agents reach users through resellers, who may rebrand a developer's agent or substitute a cheaper model. When provenance is disputed, attribution rests on the trajectory log (the record of tool calls, observations, and executed actions, not the model's reasoning), which the reseller stores and processes to meter usage. …
Read original ↗https://arxiv.org/abs/2607.08400arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Controllability-Aware Adversarial Examples Against LLM-Based Network Traffic Classifiers arXiv:2607.07739v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly explored as network intrusion detection classifiers, but their adversarial robustness under realistic attacker constraints remains unclear. We present a controllability-aware black-box transfer framework for LLM-based network traffic classifiers. The framework partitions flow features into direc…
Read original ↗https://arxiv.org/abs/2607.07739arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Who Broke the System? Failure Localization in LLM-Based Multi-Agent Systems arXiv:2607.07989v1 Announce Type: new Abstract: Large language model (LLM) based multi-agent systems enable complex problem solving through coordinated reasoning and action, but their distributed structure also introduces new challenges in diagnosing system-level failures. When an execution fails, identifying which agent is responsible and at what point the trajectory first becomes irreversibly misdi…
Read original ↗https://arxiv.org/abs/2607.07989arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents arXiv:2607.08395v1 Announce Type: new Abstract: Persistent AI agents extend large language models (LLMs) beyond single-turn interaction into long-lived software systems. Unlike traditional chat assistants, unsafe content in these agents can propagate through persistent state, reusable skills, and tool-mediated interactions, creating a substantially larger semantic attack surface. We observe that most sec…
Read original ↗https://arxiv.org/abs/2607.08395arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Beware What You Autocomplete: Forensic Attribution of Backdoored Code Completions arXiv:2607.08011v1 Announce Type: new Abstract: Large language models have enabled powerful code completion systems that assist developers by predicting subsequent lines of code. However, these models remain vulnerable to backdoor attacks, where malicious fine-tuning data covertly implants unsafe behaviors. Despite advances in defensive techniques, adaptive and sophisticated backdoor attacks st…
Read original ↗https://arxiv.org/abs/2607.08011arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
TRM-Raft: A Byzantine-Resistant Raft Consensus via Integrated Trust and Reputation Model arXiv:2607.08666v1 Announce Type: new Abstract: Internetware envisions autonomous software entities collaborating over the open Internet. Raft consensus is widely adopted for its simplicity and performance in distributed coordination, e.g., service registries and blockchains. However, Raft assumes crash faults only, making it vulnerable to Byzantine behaviors like election forgery and lo…
Read original ↗https://arxiv.org/abs/2607.08666arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Degree-Constrained Interval Optimization for Minimax Polynomial Approximation in Homomorphic Encryption arXiv:2607.08042v1 Announce Type: new Abstract: Homomorphic encryption (HE) enables privacy-preserving inference under arithmetic constraints that restrict encrypted evaluation to additions and multiplications. As a result, non-polynomial activation functions must be replaced by polynomial approximations. Among polynomial approximation methods, minimax approximation, typic…
Read original ↗https://arxiv.org/abs/2607.08042arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Prismata: Confining Cross-Site Prompt Injection in Web Agents arXiv:2607.08147v1 Announce Type: new Abstract: Autonomous web agents promise to automate everyday browsing tasks, but inherit one of the web's oldest attack surfaces. Cross-Site Scripting proved that mixing trusted and untrusted content is dangerous, even on benign pages. Agents resurface this risk by interpreting natural language as instructions, allowing third-party and user-generated content to hijack the agen…
Read original ↗https://arxiv.org/abs/2607.08147arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Securing Autonomous Vehicle Systems via Twin-Aware Federated Reinforcement Learning arXiv:2607.08137v1 Announce Type: new Abstract: Federated reinforcement learning (FRL) is crucial for enabling collaborative learning across multiple agents without sharing raw data, thereby enhancing privacy and scalability in the decision-making process within dynamic vehicular environments. However, poisoning attacks pose a significant threat to the security and reliability of FRL-based sy…
Read original ↗https://arxiv.org/abs/2607.08137