REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 12 of 54
arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
KS-CFA: Control-Flow Attestation via Symbolic Replay Against Control-Flow Bending Attacks arXiv:2607.07926v1 Announce Type: new Abstract: Control-flow attestation (CFA) enables a remote entity to verify program execution on a target device by monitoring control-flow behaviour at runtime. However, control-flow bending (CFB) attacks remain difficult to detect, where an adversary steers execution along legal edges of the program's control-flow graph by corrupting branch flags, …
Read original ↗https://arxiv.org/abs/2607.07926arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Controllability-Aware Adversarial Examples Against LLM-Based Network Traffic Classifiers arXiv:2607.07739v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly explored as network intrusion detection classifiers, but their adversarial robustness under realistic attacker constraints remains unclear. We present a controllability-aware black-box transfer framework for LLM-based network traffic classifiers. The framework partitions flow features into direc…
arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
TRACE: A Two-Channel Robust Attribution Watermark via Complementary Embeddings for LLM-Agent Trajectories arXiv:2607.08400v1 Announce Type: new Abstract: LLM agents reach users through resellers, who may rebrand a developer's agent or substitute a cheaper model. When provenance is disputed, attribution rests on the trajectory log (the record of tool calls, observations, and executed actions, not the model's reasoning), which the reseller stores and processes to meter usage. …
Read original ↗https://arxiv.org/abs/2607.08400arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Mechanistic Interpretability of LLM Jailbreaks via Internal Attribution Graphs arXiv:2607.07903v1 Announce Type: new Abstract: Large language models (LLMs) exhibit remarkable capabilities but remain highly vulnerable to adversarial prompts and jailbreak attacks. Existing approaches primarily analyze these failures through input-output behaviors or attribution methods, offering limited insight into how adversarial perturbations alter the model's internal reasoning. Consequent…
Read original ↗https://arxiv.org/abs/2607.07903arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Forensic Schema for Psychological Manipulation in Cyber Fraud: LLM-Driven Victim Reports Analysis arXiv:2607.07751v1 Announce Type: new Abstract: Existing cybercrime classification schemas capture contact metadata and financial transactions but omit the psychological manipulation techniques perpetrators employ. We present a forensic schema (four categories, 35 questions) adding 11 manipulation indicators and cryptocurrency evidence fields to established forensic foundations.…
Read original ↗https://arxiv.org/abs/2607.07751arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis arXiv:2607.08232v1 Announce Type: new Abstract: Mini-programs have become a dominant paradigm for lightweight application deployment within super apps such as WeChat. To support seamless integration, super apps provide OAuth mechanisms for user login. However, improper integration of OAuth-based Authentication (OBA) flows by third-party developers can lead to crit…
Read original ↗https://arxiv.org/abs/2607.08232arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Open Models, Open Risks: Measuring Unsafe Generation in Text-to-Image Models In the Wild arXiv:2607.07827v1 Announce Type: new Abstract: Existing safety studies on text-to-image (T2I) jailbreaks are largely conducted in controlled in-the-lab settings, typically on a small number of canonical models. As a result, the current safety status of the rapidly growing in-the-wild T2I ecosystem remains unclear. This uncertainty is amplified by two factors: existing detector-based met…
Read original ↗https://arxiv.org/abs/2607.07827arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure arXiv:2607.08288v1 Announce Type: new Abstract: In critical infrastructure, operational technology environments often cannot be actively scanned, and yet active system feedback is needed for risk assessment and compliance. This paper presents a non-invasive, MCP-grounded multi-agent pipeline that converts natural-language system descriptions in…
Read original ↗https://arxiv.org/abs/2607.08288huggingface_blog · tlp:amber · 7/10/2026, 12:00:00 AM
Profiling in PyTorch (Part 3): Attention is all you profile Profiling in PyTorch (Part 3): Attention is all you profile Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles…
Read original ↗https://huggingface.co/blog/torch-attention-profile
ars_security · tlp:amber · 7/9/2026, 8:52:55 PM
Patch for Windows Defender 0-day could allow attackers to fill hard disk The feud between NightmareEclipse and Microsoft shows no signs of resolving soon. A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said. RoguePlanet, tracked as CVE-2026-50656, came to public notice in June when …
Read original ↗https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk
talos · tlp:amber · 7/9/2026, 6:52:29 PM
WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy .  For Cisco Talos’ Vulnerability Discovery & Research team recently disclos…
Read original ↗https://blog.talosintelligence.com/wolfssl-vulnerabilities
the_hacker_news · tlp:amber · 7/9/2026, 6:38:49 PM
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal Dormant …
Read original ↗https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html
the_hacker_news · tlp:amber · 7/9/2026, 6:08:07 PM
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that scrambles files with a key it never saves N…
Read original ↗https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html
talos · tlp:amber · 7/9/2026, 6:00:06 PM
Winning 54% of the time With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time." Welcome to this week’s Threat Source newsletter.  There’s a fairly cliché phrase in cybersecurity that I’m sure our audience is familiar with: Attackers only need to be right once, whereas defenders need to be right 100% of the time.   I guess it captures th…
Read original ↗https://blog.talosintelligence.com/winning-54-of-the-time
the_hacker_news · tlp:amber · 7/9/2026, 4:49:02 PM
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in - allowScripts defaults to off, meaning npm 12 Disables…
Read original ↗https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html
the_hacker_news · tlp:amber · 7/9/2026, 3:09:28 PM
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global ThreatsDay: …
Read original ↗https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.htmlsecurityweek · tlp:amber · 7/9/2026, 3:03:51 PM
QIZ Security Raises $17 Million for Cryptographic Governance Platform The Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek . QIZ Security Raises $17 Million for Cryptographic Governance Platform - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Mal…
Read original ↗https://www.securityweek.com/qiz-security-raises-17-million-for-cryptographic-governance-platformmicrosoft_mstic · tlp:amber · 7/9/2026, 3:00:00 PM
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders detect and defend against similar threats. The post GigaWiper: Anatomy of a destructive backdoor assembled from multiple mal…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malwarelwn_kernel · tlp:amber · 7/9/2026, 2:25:18 PM
[$] Kitty chases the mouse Kitty is a terminal emulator that runs on Linux, macOS, and the BSDs, which is notable for its speed and features such as image support and advanced font handling. It is under active development; a recent major release adds a new level of mouse support. Here, we will look at some of those features and show how the program can also be used as platform for text-based applications. Kitty is free software, released under the GPLv3.
Read original ↗https://lwn.net/Articles/1080821
the_record · tlp:amber · 7/9/2026, 2:20:00 PM
Latvian forestry company still restoring systems weeks after ransomware attack A foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said. Latvian forestry company still restoring systems weeks after ransomware attack | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Fre…
Read original ↗https://therecord.media/latvia-state-owned-foresty-company-lvm-ransomwaresecurityweek · tlp:amber · 7/9/2026, 2:19:53 PM
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek . UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS…
Read original ↗https://www.securityweek.com/uk-government-rolls-out-agentic-ai-defense-plan-alongside-industry-pledgesecurityweek · tlp:amber · 7/9/2026, 1:49:42 PM
Palo Alto Networks Patches 13 Vulnerabilities Buffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek . Palo Alto Networks Patches 13 Vulnerabilities - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats Cyberwarfare Cybercri…
Read original ↗https://www.securityweek.com/palo-alto-networks-patches-13-vulnerabilities
the_record · tlp:amber · 7/9/2026, 1:20:00 PM
NSA revives 'Tailored Access Operations' name for elite hacking unit NSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the broader digital community for a group with roots in the early 1990s. NSA revives 'Tailored Access Operations' name for elite hacking unit | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence …
Read original ↗https://therecord.media/nsa-revives-tao-name-for-elite-hacking-unitlwn_kernel · tlp:amber · 7/9/2026, 1:19:01 PM
Rust 1.97.0 released Version 1.97.0 of the Rust programming language has been released. Changes include using a new symbol-mangling scheme by default, support for denying warnings in Cargo, and an end to the practice of hiding the linker's output after a successful build. Rust 1.97.0 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscri…
Read original ↗https://lwn.net/Articles/1082032
the_record · tlp:amber · 7/9/2026, 1:10:02 PM
EU takes member states to court over unimplemented cybersecurity law Ireland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 Directive for the cybersecurity of critical infrastructure. EU takes member states to court over unimplemented cybersecurity law | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter …
Read original ↗https://therecord.media/eu-cyber-filing-ireland-spain-france-netherlands-nis2lwn_kernel · tlp:amber · 7/9/2026, 1:00:11 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (389-ds-base, aardvark-dns, buildah, compat-openssl10, freeipmi, frr, gnutls, grafana, grafana-pcp, kernel, kernel-rt, libyang, nginx, openexr, pcs, perl-HTTP-Daemon, postgresql:18, python3.14-pip, skopeo, tomcat9, and wireshark), Debian (chromium and pgextwlist), Fedora (openssh, opkssh, perl-CSS-Minifier-XS, python-jiter, python-nh3, python-pendulum, rust-jiter, and upower), Mageia (openvpn and vi…
Read original ↗https://lwn.net/Articles/1082030
sentinelone · tlp:amber · 7/9/2026, 12:55:00 PM
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security. Executive Summary SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026. All these actors converged on Balochistan Police ov…
Read original ↗https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement
the_hacker_news · tlp:amber · 7/9/2026, 12:26:58 PM
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven AI …
Read original ↗https://thehackernews.com/2026/07/ai-attacks-move-in-minutes-join-this.htmlsecurityweek · tlp:amber · 7/9/2026, 12:18:46 PM
12 Million Impacted by Data Breach at Japanese Telco KDDI Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek . 12 Million Impacted by Data Breach at Japanese Telco KDDI - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats Cyberwarfare Cyberc…
Read original ↗https://www.securityweek.com/12-million-impacted-by-data-breach-at-japanese-telco-kddicisa_alerts · tlp:amber · 7/9/2026, 12:00:00 PM
OpenPLC v3 View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user. The following versions of OpenPLC v3 are affected: OpenPLC v3 CVSS Vendor Equipment Vulnerabilities v3 9.9 OpenPLC OpenPLC v3 External Control …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01cisa_alerts · tlp:amber · 7/9/2026, 12:00:00 PM
Schneider Electric PowerChute Serial Shutdown View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdow…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02cisa_alerts · tlp:amber · 7/9/2026, 12:00:00 PM
Schneider Electric Easergy MiCOM Px40 Series View CSAF Summary Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk una…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03securityweek · tlp:amber · 7/9/2026, 11:52:35 AM
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek . 15-Year-Old Linux Vulnerability 'GhostLock' Earns Researchers $92k From Google - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webca…
Read original ↗https://www.securityweek.com/15-year-old-linux-vulnerability-ghostlock-earns-researchers-92k-from-google
the_hacker_news · tlp:amber · 7/9/2026, 11:00:00 AM
Summer of Clearinghouses Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking us to. We only announced it now because everyone else started announcing theirs, Summer of Clearinghouses #1 Trusted Cybersecurity News…
Read original ↗https://thehackernews.com/2026/07/summer-of-clearinghouses.html
the_hacker_news · tlp:amber · 7/9/2026, 10:43:09 AM
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, GodDamn Ransomwar…
Read original ↗https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.htmlsecurityweek · tlp:amber · 7/9/2026, 10:28:35 AM
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek . Microsoft Patches Defender 'RoguePlanet' Vulnerability - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Ma…
Read original ↗https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerabilitysecurityweek · tlp:amber · 7/9/2026, 10:06:18 AM
Mount Royal University Confirms Data Stolen in Ransomware Attack Hackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data. The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek . Mount Royal University Confirms Data Stolen in Ransomware Attack - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference M…
Read original ↗https://www.securityweek.com/mount-royal-university-confirms-data-stolen-in-ransomware-attacksecurityweek · tlp:amber · 7/9/2026, 8:52:21 AM
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique Wiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval. The post AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique appeared first on SecurityWeek . AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cy…
Read original ↗https://www.securityweek.com/ai-coding-tools-tricked-into-hacking-developer-machine-via-decades-old-technique
the_hacker_news · tlp:amber · 7/9/2026, 8:48:48 AM
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities for its antivirus and Microsoft Pat…
Read original ↗https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.htmlsecurityweek · tlp:amber · 7/9/2026, 7:27:59 AM
Chrome 150 Update Patches 27 Vulnerabilities The security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google. The post Chrome 150 Update Patches 27 Vulnerabilities appeared first on SecurityWeek . Chrome 150 Update Patches 27 Vulnerabilities - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats Cyberwarfare Cybercrime Data Breaches Fraud & Identi…
Read original ↗https://www.securityweek.com/chrome-150-update-patches-27-vulnerabilities