REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 11 of 21
arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Ghost Vectors: Soft-Deleted Embeddings Remain Reconstructible in HNSW Vector Databases arXiv:2606.18497v1 Announce Type: new Abstract: Retrieval-augmented generation (RAG) allows large language models to access external and private corpora for factual, domain-specific responses. Modern RAG pipelines use hierarchical navigable small world (HNSW) vector databases for efficient similarity search. When a user requests data deletion, the systems typically only mark the record as …
Read original ↗https://arxiv.org/abs/2606.18497arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks arXiv:2606.18710v1 Announce Type: new Abstract: Distributed large language model (LLM) inference frameworks connect isolated consumer-grade devices for large-scale model inference, substantially reducing hardware constraints. However, recent studies show that intermediate embeddings transmitted among participants can leak private prompts. As LLMs evolve into multimodal LLMs (MLLMs), this risk extend…
arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
A Predictive Neural Network Architecture for Early Detection of Low-Rate Cyberattacks arXiv:2606.18771v1 Announce Type: new Abstract: Low-Rate Denial of Service (LDoS) attacks pose a significant challenge to IoT networks due to their subtle and prolonged nature, often evading traditional intrusion detection systems. This paper presents IDQS (Intrusion Detection via QoS Prediction), a lightweight and proactive framework for early LDoS attack detection. IDQS integrates two new…
Read original ↗https://arxiv.org/abs/2606.18771arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
TRAP: Benchmark for Task-completion and Resistance to Active Privacy-extraction arXiv:2606.18996v1 Announce Type: new Abstract: Agents are increasingly deployed in document-intensive workflows where sensitive private information is not an edge case but a routine input, e.g., an agent booking a flight needs passport numbers. In such settings, the agent must use private information to complete tasks accurately while never exposing it in its responses, because it cannot verify …
Read original ↗https://arxiv.org/abs/2606.18996arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Lifecycle-Aware Dynamic Analysis for Secure ML Model Execution arXiv:2606.19023v1 Announce Type: new Abstract: The growing reliance on pre-trained Machine Learning (ML) models has introduced new attack surfaces. Recent vulnerabilities demonstrate that malicious behavior can be embedded within model artifacts, often bypassing existing defenses. Current model-scanning solutions primarily rely on static, format-specific rules or known attack signatures, which limit their abilit…
Read original ↗https://arxiv.org/abs/2606.19023arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
PYPILINE: Malicious PyPI Package Detection via Suspicious API Knowledge and Agent Workflow arXiv:2606.19063v1 Announce Type: new Abstract: The detection of malicious PyPI packages is crucial for maintaining the security of the open source software supply chain. Existing methods, which primarily rely on rules or traditional machine learning, suffer from poor interpretability and difficulty in adapting to novel attacks. To address this, we propose PYPILINE, a novel detection m…
Read original ↗https://arxiv.org/abs/2606.19063arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Compute-Budgeted Exploitability Evidence Graphs for Prospective Vulnerability Triage arXiv:2606.19076v1 Announce Type: new Abstract: Defenders cannot patch every newly disclosed vulnerability at once, so exploitability prediction must be evaluated prospectively rather than retrospectively. We study compute-budgeted vulnerability triage in which each CVE is scored only from public evidence visible by a fixed decision time. Advisories, exploit archives, fix commits, and hacker…
Read original ↗https://arxiv.org/abs/2606.19076arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Quantifying Compromise Risk in Exceptional Access Architectures Under Sparse and Indirect Evidence arXiv:2606.19106v1 Announce Type: new Abstract: Lawful exceptional access (EA) systems hold the cryptographic keys that decrypt protected communications for authorised parties. The debate over their risks has been long and qualitative, complicated by two problems: no public dataset of EA-specific compromise events exists, so assessment must use sparse, indirect evidence; and pr…
Read original ↗https://arxiv.org/abs/2606.19106arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Giskard : Byzantine Robust and Confidential Aggregation for Large-Scale Decentralized Learning arXiv:2606.19129v1 Announce Type: new Abstract: Dealing simultaneously with confidentiality and Byzantine behaviors in decentralized learning is a challenging problem. Indeed, in decentralized learning, clients train a machine learning model while keeping their data locally and share their model parameters or gradients with a set of neighbors. While enforcing confidentiality calls …
Read original ↗https://arxiv.org/abs/2606.19129arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Agentra: A Supervisable Multi-Agent Framework for Enterprise Intrusion Response arXiv:2606.18325v1 Announce Type: new Abstract: Enterprise intrusion response still depends on static playbooks and analyst-driven triage, creating delay between alert generation and containment. We present Agentra, a supervisable multi-agent Intrusion Response System (IRS) framework that converts alerts from IDS, EDR, and XDR platforms into structured incident response plans grounded in MITRE AT…
Read original ↗https://arxiv.org/abs/2606.18325arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems arXiv:2606.18310v1 Announce Type: new Abstract: Injecting malicious knowledge into retrieval-augmented generation (RAG) systems can manipulate retrieved evidence and mislead downstream generation, posing a serious security threat for AI applications. Existing RAG injection attacks mainly rely on manipulating external knowledge bases, such as crafting malicious corpus. However, the synth…
Read original ↗https://arxiv.org/abs/2606.18310arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
TIGER: Inverting Transformer Gradients via Embedding-Subspace Distance Optimization arXiv:2606.18312v1 Announce Type: new Abstract: Federated learning allows multiple clients to jointly train a shared model by sending gradient updates to a central server while keeping raw inputs local. However, prior gradient inversion attacks show that these updates can reveal enough information to reconstruct client inputs. Existing attacks on transformers either optimize dummy inputs to m…
Read original ↗https://arxiv.org/abs/2606.18312arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
TopVenues: A Reproducible Corpus and Tooling Substrate for Cybersecurity Literature Reviews arXiv:2606.18320v1 Announce Type: new Abstract: Cybersecurity literature reviews require a reproducible denominator: the set of papers that a protocol includes before screening and synthesis begin. Today, that denominator is often reconstructed from publisher portals, bibliographic indices, and scholarly application programming interfaces (APIs) whose coverage, formats, and query sema…
Read original ↗https://arxiv.org/abs/2606.18320arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents arXiv:2606.18356v1 Announce Type: new Abstract: Tool-using language-model agents introduce security failures that go beyond unsafe text: they can disclose protected objects, write persistent memory, send messages, modify databases, or trigger harmful code and tool effects. Existing evaluations often collapse these stages into a single attack success rate, making it difficult to tell…
Read original ↗https://arxiv.org/abs/2606.18356arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Evaluating the Effectiveness of LLMs in Aiding Compliance Testing of PKCS#1-v1.5 arXiv:2606.18405v1 Announce Type: new Abstract: Testing implementations of binary protocols for specification compliance requires inputs that satisfy both structural and semantic constraints. Purely random generation and primitive mutations are often insufficient for exploring semantically meaningful behaviors in protocols that rely on Type-Length-Value (TLV) encoding, yet domain-specific compli…
Read original ↗https://arxiv.org/abs/2606.18405arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Understanding the "Airport" Censorship Circumvention Ecosystem in China arXiv:2606.18427v1 Announce Type: new Abstract: In China, a burgeoning underground market sells citizens subscription-based censorship circumvention proxies known as ''airports''. We present the first systematic study of this ecosystem, combining user surveys, social media analysis, and active network measurements. We find that airports are by far the most popular off-the-shelf censorship circumvention t…
Read original ↗https://arxiv.org/abs/2606.18427arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Understanding and Mitigating Prompt Leaking Attacks in Real-World LLM-Based Applications arXiv:2606.18673v1 Announce Type: new Abstract: Large language model (LLM)-based applications rely on system prompts to encode core logic and developer-defined constraints, making these prompts important intellectual property. However, system prompts are vulnerable to prompt leaking attacks. Although prior work has shown such attacks in controlled settings, their prevalence, causes, and …
Read original ↗https://arxiv.org/abs/2606.18673arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
From Bits to Mixed-Radix Keys: Horner Decomposition, Uniform Sampling, and the Information-Theoretic QKD Interface of the MR-OTP arXiv:2606.18526v1 Announce Type: new Abstract: The Mixed-Radix One-Time Pad (MR-OTP) extends the classical OTP to heterogeneous alphabets while preserving perfect secrecy. We provide a practical, bias-free method to convert raw binary entropy from a QKD source into uniform mixed-radix keys by identifying Horner's method and its inverse as the natu…
Read original ↗https://arxiv.org/abs/2606.18526arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Evaluating Prompting-Based Defenses Against Domain-Camouflaged Injection Attacks arXiv:2606.18530v1 Announce Type: new Abstract: Domain-camouflaged injection attacks embed malicious instructions in retrieved content using domain-appropriate vocabulary, evading standard detectors that rely on syntactic injection markers. When detection fails, practitioners need to know which defense architectures reduce attack success. We evaluate five prompting-based defenses (spotlighting, …
Read original ↗https://arxiv.org/abs/2606.18530arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
AI Sandboxes: A Threat Model, Taxonomy, and Measurement Framework arXiv:2606.18532v1 Announce Type: new Abstract: AI systems are increasingly evaluated in bounded environments that combine isolation, simulation, instrumentation, supervision, and evidence capture. For physical AI, AIoT, and cyber-physical systems, this shift is not a matter of terminology: the system under test may sense, decide, actuate, communicate, and fail through physical processes, networked devices, an…
Read original ↗https://arxiv.org/abs/2606.18532arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Confident yet Concerned: Inconsistencies in Computing Students' Attitudes on Cybersecurity arXiv:2606.18541v1 Announce Type: new Abstract: Today's young adults are most immersed in technology, leading in feelings of powerlessness in managing online privacy across many platforms, and particularly susceptible to phishing attacks. This raises questions about their general, wide-ranging attitudes towards and management of cybersecurity. How do young, tech-savvy adults approach c…
Read original ↗https://arxiv.org/abs/2606.18541arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
The Gate Is Only as Honest as Its Contracts: ContractGuard for the Contract Layer of Risk-Aware Causal Gating arXiv:2606.18550v1 Announce Type: new Abstract: Risk-Aware Causal Gating (RACG) defends tool-augmented LLM agents against indirect prompt injection by removing dangerous tools from the agent's visible action space, so that even a fully injection-compliant agent cannot call a tool it cannot see. We make three points. First, this structural guarantee does not eliminate…
Read original ↗https://arxiv.org/abs/2606.18550arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
MIDS: Detecting Stealthy Masquerade and Tampering Attacks on CAN Bus via Bidirectional Mamba arXiv:2606.18599v1 Announce Type: new Abstract: The Controller Area Network (CAN) protocol is the primary communication standard for Electronic Control Units (ECUs) in modern vehicles, but its lack of encryption and authentication exposes it to a range of security threats. Existing intrusion detection systems are largely tuned to fabrication-style attacks (DoS, fuzzing, ID spoofing r…
Read original ↗https://arxiv.org/abs/2606.18599arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
Code-Augur: Agentic Vulnerability Detection via Specification Inference arXiv:2606.18619v1 Announce Type: new Abstract: The advent of agentic vulnerability detection is already becoming a watershed moment for software security. Audits conducted entirely by autonomous LLM agents are uncovering critical vulnerabilities in fundamental software underpinning digital society. Many of these vulnerabilities remained masked for years, surfacing only now with AI agents. Yet the reason…
Read original ↗https://arxiv.org/abs/2606.18619arxiv_cs_cr · tlp:amber · 6/18/2026, 4:00:00 AM
TGCM: Topic-Guided Generative Disentanglement of Interleaved APT Technique Sequences arXiv:2606.18651v1 Announce Type: new Abstract: In enterprise environments, multiple Advanced Persistent Threat (APT) campaigns often unfold concurrently, producing audit logs in which attack techniques across actors (sources) are interleaved over time. This setting naturally gives rise to an Unknown-K Interleaved Sequence Demixing (UKISD) problem: recovering multiple latent campaigns from a…
Read original ↗https://arxiv.org/abs/2606.18651arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
LineageMark: Multi-user White-box Watermarking for Contribution Tracing in Model Derivation Chains arXiv:2606.17123v1 Announce Type: new Abstract: In open large language model (LLM) ecosystems, models are frequently adapted across multiple domains and applications, forming multi-stage derivation chains. Consequently, tracking and verifying historical contributions is essential for model provenance and intellectual property protection. However, existing watermarking methods a…
Read original ↗https://arxiv.org/abs/2606.17123arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Bifrost: Hybrid TEE-FHE Inference for Privacy-Preserving Transformer and LLM Serving arXiv:2606.17421v1 Announce Type: new Abstract: Cloud-hosted transformer and large language model (LLM) inference creates a direct confidentiality problem: user prompts may contain sensitive code, business data, personal information, or regulated documents, yet remote serving exposes intermediate state to the cloud software stack and accelerator runtime. Fully homomorphic encryption (FHE) ke…
Read original ↗https://arxiv.org/abs/2606.17421arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Children Are Not the Enemy: Child-Fit Security as an Alternative to Bans and Surveillance arXiv:2606.17957v1 Announce Type: new Abstract: Digital technologies are now central to children's learning, play, communication, identity formation, and social participation. Yet dominant approaches to children's online safety often rely on containment mechanisms, including bans, age gates, parental controls, monitoring, and screen-time restrictions. These approaches can be useful in s…
Read original ↗https://arxiv.org/abs/2606.17957arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Beyond Native Success: Auditing Deployment-Interface Exposure of CLIP Backdoors arXiv:2606.17815v1 Announce Type: new Abstract: Contrastive Language-Image Pre-training models are widely reused across downstream interfaces, including feature extraction, retrieval, reranking, and selection. Existing CLIP backdoor, however, usually validate attacks on a small attack-native task, leaving unclear whether the same poisoned checkpoint remains exposed, weakens, or becomes not applic…
Read original ↗https://arxiv.org/abs/2606.17815arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios arXiv:2606.17114v1 Announce Type: new Abstract: AI agents are increasingly being adopted in enterprise and personal settings with access to emails, databases, documents, and other tools where they can read, update, and disseminate sensitive information. Much of prior research on data leakage risks in agents has focused on adversarial data exfiltration through prompt injections and jailbreaks.…
Read original ↗https://arxiv.org/abs/2606.17114arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Anywhere, Any-Stymie: Remote Activation of Trojan Malware on LiDAR with Modulated Signals arXiv:2606.17562v1 Announce Type: new Abstract: LiDAR sensors are widely deployed in autonomous systems for 3D perception and safety-critical decision-making. We identify a previously unexplored attack surface in which dormant malware embedded in the LiDAR sensing pipeline remains inactive during normal operation and can be externally triggered after deployment, without requiring access…
Read original ↗https://arxiv.org/abs/2606.17562arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
An AI Security Agent for Banking: Multi-Vector Fraud and AML Detection Across Retail and Corporate Accounts arXiv:2606.17555v1 Announce Type: new Abstract: Banks simultaneously face signature-based fraud (card-not-present attacks, account takeover, ATM cloning) and behavioural financial crime (structuring, layering, mule networks, business email compromise) -- two threat families with fundamentally different detection requirements. Static rule engines that reliably catch bru…
Read original ↗https://arxiv.org/abs/2606.17555arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
SNAS: A Multi-Layer Defense-in-Depth Architecture for Secure Egress in Sandboxed Workloads arXiv:2606.17533v1 Announce Type: new Abstract: Snowpark enables data engineering and AI/ML workloads in Snowflake by executing user-defined functions in secure sandboxes. Many of these workloads require external connectivity to access cloud APIs, external databases, or feature stores, creating a dependability challenge: how to provide transparent network access while preserving strict…
Read original ↗https://arxiv.org/abs/2606.17533arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents arXiv:2606.17467v1 Announce Type: new Abstract: Prompt injection defenses evaluated on synthetic benchmarks do not generalize to real enterprise documents, which are longer, denser, and interleave legitimate authority language with factual content. We demonstrate this gap with a real-document benchmark of 122 tasks across five professional domains (financial, legal, medical, scientific, DevOps)…
Read original ↗https://arxiv.org/abs/2606.17467arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
OTRO: Oblivious Tokenization Path with Square-Root ORAM arXiv:2606.17358v1 Announce Type: new Abstract: The CPU-side large language model (LLM) tokenizer is a critical security gap in LLM serving through a confidential computing stack with CPU and GPU trusted execution environments (TEEs). Tokenizers converts the prompts through table-driven lookups, and the resulting memory access patterns are a powerful source of side-channel leakage. Recent work demonstrates end-to-end re…
Read original ↗https://arxiv.org/abs/2606.17358arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Quantifying quantum risk: a measure of crypto agility arXiv:2606.17116v1 Announce Type: new Abstract: Because of their ability to enable new forms of cryptanalysis, quantum computers pose a threat to the cryptographic algorithms that are widely used to secure contemporary computer systems. A practical quantum computer may emerge within the next ten years or so, but due to theorised "harvest now, decrypt later" style attacker behaviour, mitigations are necessary today. Recent…
Read original ↗https://arxiv.org/abs/2606.17116arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
ARVO: Atlas of Reproducible Vulnerabilities for Open-Source Software arXiv:2606.17283v1 Announce Type: new Abstract: Achieving reproducibility, quantity, and diversity in vulnerability datasets has long been viewed as an inherent three-way trade-off, where improving one dimension often comes at the cost of the others. In practice, reproducibility has been the dimension most often neglected. This has limited what can be automatically extracted from historical bug datasets, an…
Read original ↗https://arxiv.org/abs/2606.17283arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Security and Human-Centered Assessment of BACnet-Controlled DALI Infrastructure in an Educational Building Automation Testbed arXiv:2606.17089v1 Announce Type: new Abstract: Building automation and control systems integrate heating, ventilation, air conditioning, lighting, sensing, and management functions through specialized communication protocols. While this integration enables flexible building operation, it also creates complex cyber-physical environments that are diffi…
Read original ↗https://arxiv.org/abs/2606.17089arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Securing Multi-Agent GIS Systems: Risk Evaluation and Prompt Hardening Optimization arXiv:2606.17092v1 Announce Type: new Abstract: Agentic systems are increasingly integrated with geographic information systems (GIS), where multi-agent coordination enables complex conversational and spatial analysis but introduces security risks. This work presents a security-oriented framework for risk identification, evaluation, and mitigation in a multi-agent GIS system while maintaining…
Read original ↗https://arxiv.org/abs/2606.17092arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Timestamp-Aware Spatio-Temporal Graph Contrastive Learning for Network Intrusion Detection arXiv:2606.17109v1 Announce Type: new Abstract: Given their effectiveness in modeling the relational structure among network traffic flows, graph neural networks (GNNs) have been widely adopted in network intrusion detection systems (NIDSs). However, most existing GNN-based NIDS approaches focus on the relational structure of traffic flows, and treat them as temporally independent, whi…
Read original ↗https://arxiv.org/abs/2606.17109