REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 12 of 21
arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Structural Role Injection in Handlebars-Templated LLM Prompts: Triple-Brace Interpolation, Delimiter Family, and the Limits of HTML Auto-Escaping arXiv:2606.18120v1 Announce Type: new Abstract: Large language model applications build prompts from templates, and Handlebars is a widely used templating engine and the default prompt-template format in Microsoft Semantic Kernel. Its double-brace {{x}} expression HTML-escapes the interpolated value and is documented as the safe de…
Read original ↗https://arxiv.org/abs/2606.18120arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Graph neural networks at war: integrating cybersecurity and drone intelligence in the Israeli-Iranian conflict arXiv:2606.17119v1 Announce Type: new Abstract: Physical cyber systems have brought about new threats and challenges in detection and immediate response. This study examines how Graph Neural Networks (GNNs) can be used to aid cybersecurity and drone management in a physical cyber system comprising of cyber intrusions and unmanned aerial vehicles (UAVs). By providing…
arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
TrustErase: Auditable Instant Machine Unlearning with Passport-Embedded Representations arXiv:2606.17122v1 Announce Type: new Abstract: The demand for privacy-compliant AI has amplified the need for machine unlearning; yet, existing retraining or distillation-based methods remain unverifiable and computationally costly. We introduce TrustErase, a verifiable, data-free unlearning framework leveraging passport-embedded representations for instant, modular, and auditable forget…
Read original ↗https://arxiv.org/abs/2606.17122arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Loss Landscape Poisoning: Targeted Extraction of Unseen Training Data from LLMs arXiv:2606.17110v1 Announce Type: new Abstract: Large Language Models are increasingly trained on proprietary or sensitive data, from private healthcare and financial records to user conversations containing secrets. Ensuring the privacy of such data against extraction attacks has become a central concern. In this paper, we ask whether an attacker who can poison a portion of the training data can…
Read original ↗https://arxiv.org/abs/2606.17110arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
SoK: AI-Augmented Binary Reversing arXiv:2606.17398v1 Announce Type: new Abstract: Binary reversing is fundamental to software understanding, vulnerability discovery, malware investigation, and firmware auditing. However, it remains inherently challenging due to the irreversible loss of semantic information during compilation. Recent advances in machine learning, large language models (LLMs), and agentic AI systems have accelerated the adoption of AI-augmented binary reversi…
Read original ↗https://arxiv.org/abs/2606.17398arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
An Empirical Analysis of AI Slop in Music Streaming arXiv:2606.18052v1 Announce Type: new Abstract: Generative AI models lower the bar for content creation, making it easy for any user to create professional-looking images, text and music with minimal effort. This has enabled a new cottage industry around creation of "AI slop" mass quantities of mediocre content produced to generate revenue, often through misrepresentation as human-authored content, or scams involving automa…
Read original ↗https://arxiv.org/abs/2606.18052arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
ShellGames: Speculative LLM-Driven SSH Deception arXiv:2606.17986v1 Announce Type: new Abstract: Cyber deception and Moving Target Defense are promising strategies that aim to disrupt adversaries by increasing uncertainty. However, sustaining long-lived, credible interactive sessions with adversaries remains an open challenge. Large Language Models (LLMs) offer a promising path toward more dynamic deception systems, but suffer from key limitations that fundamentally limit th…
Read original ↗https://arxiv.org/abs/2606.17986arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Cache to the Future: A Distributed Webpage Archive for Internet Blackouts arXiv:2606.17245v1 Announce Type: new Abstract: Internet blackouts, occurring due to technological mishaps or intentional governmental action, prevent citizens from accessing the internet. Citizens in regions where internet blackouts are common have utilized blackout-resistant technologies to maintain communication. Such technologies often rely on mobile mesh networks to provide limited messaging servi…
Read original ↗https://arxiv.org/abs/2606.17245arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Fractional Verkle Trees: A Hypertree Decomposition and Verified Proof Serialization Architecture for High-Performance Blockchain State Accumulators arXiv:2606.17111v1 Announce Type: new Abstract: Modern blockchain state management faces a critical scalability bottleneck: maintaining cryptographic commitments over hundreds of millions of entries becomes computationally prohibitive. Ethereum's transition to Verkle Trees: polynomial commitment accumulators reducing proof sizes …
Read original ↗https://arxiv.org/abs/2606.17111arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Safety, Security, and Cognitive Risks in Neuro-Symbolic AI arXiv:2606.17223v1 Announce Type: new Abstract: Neuro-symbolic AI (NeSy) pairs neural perception with symbolic reasoning, making it attractive for high-stakes domains where explainability and structured inference are required. However, this hybrid architecture introduces an enlarged attack surface spanning five layers: neural perception, symbolic knowledge bases, reasoning engines, agentic orchestration, and data sto…
Read original ↗https://arxiv.org/abs/2606.17223arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Fuzzy PSI from Symmetric Primitives with Exact Logarithmic Dependence on Distance Threshold arXiv:2606.15093v1 Announce Type: new Abstract: Previous FPSI works have demonstrated a linear scaling with the distance threshold $\delta$, while some recent works have achieved a poly-logarithmic dependence on $\delta$. However, these protocols either support only the $L_\infty$ distance, or they support general $L_{p\in[1,\infty]}$ distances but rely on expensive additive homomorph…
Read original ↗https://arxiv.org/abs/2606.15093arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
The Audit Gap in Blockchain Security: A Four-Year Empirical Study of Public Audit Findings and Real-World Exploit Incidents arXiv:2606.15465v1 Announce Type: new Abstract: This paper presents an empirical analysis of the Web3 security landscape over the four-year and three-month period from 1 January 2022 to 27 March 2026. The dataset combines 23,818 public audit findings produced by 22 independent security firms with 218 real-world exploit incidents documented by rekt.news,…
Read original ↗https://arxiv.org/abs/2606.15465arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
FragFuse: Bypassing Access Control of Large Language Model Agents via Memory-Based Query Fragmentation and Fusion arXiv:2606.15609v1 Announce Type: new Abstract: Large language model (LLM) agents increasingly rely on long-term memory to support complex task execution, user personalization, and domain adaptation. Meanwhile, emerging access-control mechanisms for LLM agents are being explored to block policy-violating requests and prevent misuse. We reveal a novel attack surfa…
Read original ↗https://arxiv.org/abs/2606.15609arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AnonShield: Scalable On-Premise Pseudonymization for CSIRT Vulnerability Data arXiv:2606.15650v1 Announce Type: new Abstract: We present AnonShield, a high-throughput, on-premise pseudonymization system that combines GPU-accelerated NER, streaming processing, caching, and schema-aware configuration. Evaluated on datasets up to 550 MB (70,951 records), AnonShield reduces processing time from over 92 hours to under 10 minutes (up to 738x speedup) while achieving up to 94.2% F1…
Read original ↗https://arxiv.org/abs/2606.15650arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Is Your Agent Playing Dead? Deployed LLM Agents Exhibit Constraint-Evasive Fabrication and Thanatosis arXiv:2606.14831v1 Announce Type: new Abstract: This paper presents and characterizes a spectrum of previously unreported behaviours we term Constraint-Evasive Fabrication (CEF): when an LLM agent operates under irreconcilable constraints (where no response can simultaneously satisfy all active rules) it spontaneously fabricates plausible external obstacles and presents them…
Read original ↗https://arxiv.org/abs/2606.14831arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Censorship-Resistant Sealed-Bid Auctions on Blockchains arXiv:2606.14939v1 Announce Type: new Abstract: Auctions are now central to blockchain markets, settling NFT sales, token launches, DeFi liquidations, and arbitrage opportunities. Each on-chain bid is a public transaction whose inclusion is decided by a single consensus proposer per block. The proposer can observe pending bids, exclude competitors, and submit bids of their own, breaking the fairness guarantees of classi…
Read original ↗https://arxiv.org/abs/2606.14939arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Continual Backdoor Training in IoT/CPS arXiv:2606.14987v1 Announce Type: new Abstract: Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility. While continual adaptation is essential for long-lived IoT deployments where data patterns evolve, it also introduces new security vulnerabilities. In particular, backdoor attack…
Read original ↗https://arxiv.org/abs/2606.14987arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Security Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary Violations arXiv:2606.15008v1 Announce Type: new Abstract: Agentic large language model (LLM) systems can now execute actions, not only produce text. When model outputs trigger privileged operations such as shell commands, browser automation, or external tool calls, the security problem shifts from alignment alone to system configuration and structural design. We analyze OpenClaw, a self-…
Read original ↗https://arxiv.org/abs/2606.15008arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Semantic Integrity Failures in Document-to-LLM Supply Chains arXiv:2606.15020v1 Announce Type: new Abstract: Document-to-LLM applications typically read uploaded PDFs by first translating them into text through a hidden extraction layer that users cannot observe or audit. We show that this layer enables split-view PDFs: one document can have two semantic views before model reasoning. By mining specification-permitted or implementation-tolerated representation gaps at the PDF…
Read original ↗https://arxiv.org/abs/2606.15020arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
BT-MTD: Bus Traversal-based Moving Target Defense for Smart Grid arXiv:2606.15047v1 Announce Type: new Abstract: Moving Target Defense (MTD) is a proactive security strategy designed to enhance cyber-resilience by dynamically altering system parameters, thereby preventing adversaries from acquiring the critical information needed to execute stealth attacks. In this paper, we consider the case in which the operator modifies the admittance of branches to enable MTD, and focus …
Read original ↗https://arxiv.org/abs/2606.15047arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AutoDojo: Adaptive Attacks Expose Superficial Defenses and User-Underspecification Limits in LLM Agents arXiv:2606.15057v1 Announce Type: new Abstract: Indirect prompt injection (IPI) is a major security threat to LLM-powered agents. Thus, a growing body of work have proposed a variety of defensive approaches against IPI. These can be grouped into three broad categories: 1) prompt-based (using prompting as a way to prevent agents from following malicious instructions), 2) de…
Read original ↗https://arxiv.org/abs/2606.15057arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Odds Law: The Decomposition Algebra On How Intelligence Organizes Itself to Solve Difficult Problems Reliably arXiv:2606.15712v1 Announce Type: new Abstract: We ask a structural question: given unreliable elementary problem-solvers, what organizations of them solve hard problems reliably, and what are the limits? We develop a $decomposition~algebra$: elementary solvers are morphisms in a stochastic category, and four combinators (sequential composition, parallel ensembling, …
Read original ↗https://arxiv.org/abs/2606.15712arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Data-Centric Benchmarking of Exploit Generation in LLMs: Understanding the Impact of Fine-Tuning arXiv:2606.15123v1 Announce Type: new Abstract: We study the task of CVE-conditioned exploit generation, where a model drafts proof-of-concept (PoC) exploits given software vulnerability context. We adopt a data-centric approach, constructing a high-quality dataset via multi-stage preprocessing and introducing a scalable evaluation framework with LLM-as-judge and fine-grained rub…
Read original ↗https://arxiv.org/abs/2606.15123arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Multi-tier Differential Private Query Release arXiv:2606.15543v1 Announce Type: new Abstract: Answering statistical queries over sensitive data under differential privacy (DP) is a common task in many settings, including databases, mobile computing, and data markets. In these scenarios, multiple analysts may issue the same query, while receiving answers generated under different privacy budgets due to differences in trust levels or willingness to pay. Existing approaches for…
Read original ↗https://arxiv.org/abs/2606.15543arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
VLALeaks: Membership Inference Attacks against Vision-Language-Action Models arXiv:2606.15165v1 Announce Type: new Abstract: Vision-Language-Action (VLA) models enable end-to-end robot control and have garnered widespread attention. However, the memorization of training data inherent to VLA, coupled with the high cost of robotic data acquisition, raises serious concerns regarding data privacy leakage and intellectual property infringement. Membership inference attacks (MIAs)…
Read original ↗https://arxiv.org/abs/2606.15165arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
CmdNeedle: Measuring the Incompleteness of Command Denylists for AI Agents arXiv:2606.15549v1 Announce Type: new Abstract: The adoption of AI agents is increasing rapidly. Terminal AI agents, i.e., AI agents that run in terminal environments, are a widely used type of AI agents. Terminal AI agents rely heavily on shell command execution to interact with the host systems. They adopt a three-list command-gating mechanism to mitigate security risks introduced by command executi…
Read original ↗https://arxiv.org/abs/2606.15549arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Let Them Steal: Trapping Large Language Model Extraction Attacks with Knowledge Honeypot arXiv:2606.15810v1 Announce Type: new Abstract: Large language models deployed as commercial APIs are vulnerable to model extraction attacks, while existing defenses either act too late or degrade utility for legitimate users. We propose \textbf{Knowledge Trap}, a defense that redirects extraction attacks toward low-transferability knowledge through a \emph{Honeypot Knowledge Graph} (HKG…
Read original ↗https://arxiv.org/abs/2606.15810arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AttackonCTF: Defending Hardware Security Competition Benchmarks in the Age of LLMs arXiv:2606.15809v1 Announce Type: new Abstract: Hardware security competitions such as HackTheSilicon serve as benchmarking platforms for evaluating vulnerability detection methods and for training humans and AI. However, our study reveals that LLMs threaten their validity. Instead of genuine security reasoning, detectors exploit a diff-style syntactic comparison, achieving an 83% detection ra…
Read original ↗https://arxiv.org/abs/2606.15809arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Robust and Precise Application Fingerprinting on 5G Physical Uplink Channel arXiv:2606.15221v1 Announce Type: new Abstract: Air fingerprinting infers application activity by sniffing metadata from cellular control channels. 5G encrypts these channels, breaking the attack chain that prior attacks depend on. This paper reveals a physical-layer side channel that bypasses encryption: under the link adaptation mandated by the cellular communication standard, the uplink Modulation…
Read original ↗https://arxiv.org/abs/2606.15221arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
GAS-Leak-LLM: Genetic Algorithm-Based Suffix Optimization for Black-Box LLM Jailbreaking arXiv:2606.15788v1 Announce Type: new Abstract: Large Language Models (LLMs) constitute pivotal components within the AI-dominated information technology ecosystem. To mitigate risks associated with harmful or policy-violating outputs, commercial systems employ advanced alignment strategies and multi-layered content moderation mechanisms. Despite these safeguards, recent research has dem…
Read original ↗https://arxiv.org/abs/2606.15788arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
A Security Analysis of Long-Horizon Agentic AI Systems: Threats, Evaluation, and Framework Development arXiv:2606.14816v1 Announce Type: new Abstract: This paper presents a structured analysis of security challenges in long-horizon agentic AI systems. The study reviews existing threats, evaluation approaches, attack propagation mechanisms, and security frameworks. A taxonomy of security threats and a framework for analyzing attack propagation are proposed to support future r…
Read original ↗https://arxiv.org/abs/2606.14816arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
LLM: LSTM Look-Ahead Moving Target Defense Based on Historical Malicious Scan arXiv:2606.15229v1 Announce Type: new Abstract: Network scanning is a critical preliminary step for most adversaries to gain essential information before launching cyber attacks. Moving Target Defense (MTD) based on IP shuffling has emerged as a proactive defense strategy to counteract these reconnaissance efforts. Unlike static, reactive defense techniques, IP shuffling introduces randomness by dy…
Read original ↗https://arxiv.org/abs/2606.15229arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Benign in Isolation, Harmful in Composition: Security Risks in Agent Skill Ecosystems arXiv:2606.15242v1 Announce Type: new Abstract: Skills are becoming the capability layer through which LLM agents turn plans into actions, but their use introduces security risks such as data leakage, unauthorized operations, and tool misuse. Existing vetting usually evaluates each skill in isolation, while real agent tasks often invoke multiple skills in a shared execution context. This cr…
Read original ↗https://arxiv.org/abs/2606.15242arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Defending against Adaptive Prompt Injection Attacks via Reasoning-enabled Task Alignment arXiv:2606.15441v1 Announce Type: new Abstract: Indirect prompt injection attacks hijack LLM-based agents by embedding malicious instructions in third-party data that the agent retrieves during task execution. Existing defenses report near-zero attack success rate on static benchmarks, yet recent adaptive evaluations show that these results collapse once the attacker is allowed to optimi…
Read original ↗https://arxiv.org/abs/2606.15441arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? arXiv:2606.15762v1 Announce Type: new Abstract: We ran 300 repeated vulnerability-finding scans to measure how repeatable agentic large language model (LLM) security review is on the same JavaScript code, prompt, and benchmark harness. The headline result is that LLM security findings were unevenly repeatable: reference-matched findings were stable, but extra model reports varied heavily from run to run. Across 250 mo…
Read original ↗https://arxiv.org/abs/2606.15762arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Side-Channel Attacks Bypass Protection in 3D Printers arXiv:2606.13952v1 Announce Type: new Abstract: Active Motor Noise Cancellation (AMNC) ships in commercial fused deposition modeling (FDM) 3D printers as a hardware countermeasure against acoustic side-channel attacks that target intellectual property (IP). We present the first empirical evaluation of a deployed AMNC countermeasure, using a public dataset of synchronized acoustic and vibration recordings from two AMNC-equ…
Read original ↗https://arxiv.org/abs/2606.13952arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Crypto x AI, AI x Crypto: A Survey arXiv:2606.13892v1 Announce Type: new Abstract: The intersection of crypto x AI is spawning papers, products, online posts, and companies. All the surrounding buzz, though, obscures what exactly has been done, what the opportunities and challenges are, and what open questions deserve attention. This survey paper asks what AI can do for blockchain-based technologies (broadly construed as "crypto") (crypto x AI), and vice versa (AI x crypto).…
Read original ↗https://arxiv.org/abs/2606.13892arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
RTL-Arrow: Hardware-to-Cloud Bridge arXiv:2606.13865v1 Announce Type: new Abstract: Hardware Security at Willamette is a Willamette University affiliated research group studying the hardware-software interface of security critical services. Within our program, we noticed many researchers spent considerable development time learning to understand and manually parse traces-of-execution of hardware designs which are used to identifying whether vulnerabilities or weaknesses aris…
Read original ↗https://arxiv.org/abs/2606.13865arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Security in a Workflow: Exploring Role-Based Agentic Architectures for Vulnerability Handling arXiv:2606.14261v1 Announce Type: new Abstract: Secure software engineering in practice is a multi-stage workflow involving vulnerability analysis, remediation, and fix verification. However, current LLM-based software security approaches often focus on isolated tasks such as detection or patch generation, with limited attention to agentic architectures reflecting industrial workflo…
Read original ↗https://arxiv.org/abs/2606.14261arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Information Flow Paths from RTL Traces arXiv:2606.13860v1 Announce Type: new Abstract: Security validation is an important yet challenging part of the hardware design process, yet, by convention, validation engineers are tasked with defining the threat model, specifying the relevant security properties, detecting any violations of those properties, and assessing the consequences to system security, each of which is manually intensive and may introduce errors. The combined te…
Read original ↗https://arxiv.org/abs/2606.13860