REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 13 of 54
the_hacker_news · tlp:amber · 7/9/2026, 7:21:06 AM
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images," the social media giant said in a post. "Whether you want to design a custom event invitation…
Read original ↗https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.htmlsecurityweek · tlp:amber · 7/9/2026, 6:45:22 AM
8Layers Raises $2.9 Million for Identity Security Platform The Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform. The post 8Layers Raises $2.9 Million for Identity Security Platform appeared first on SecurityWeek . 8Layers Raises $2.9 Million for Identity Security Platform - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware &a…
the_hacker_news · tlp:amber · 7/9/2026, 5:15:02 AM
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthropic's Claude Code and OpenAI's Codex when either is running in an autonomous mode that approves its own Top …
Read original ↗https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.htmlsecurityweek · tlp:amber · 7/9/2026, 5:00:41 AM
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek . Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conf…
Read original ↗https://www.securityweek.com/unpatched-backdoor-in-tenda-firmware-grants-admin-access-to-devicesthe_hacker_news · tlp:amber · 7/9/2026, 4:27:18 AM
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.…
Read original ↗https://thehackernews.com/2026/07/ghostapproval-symlink-flaws-could-let.htmlthe_hacker_news · tlp:amber · 7/9/2026, 4:01:49 AM
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the Fake 7-Zip Insta…
Read original ↗https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.htmlarxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
PRoVeFL: Private Robust and Verifiable Aggregation in Federated Learning arXiv:2607.06612v1 Announce Type: new Abstract: Federated Learning (FL) enables multiple clients to collaboratively train machine learning models while retaining data locality, thereby enhancing user privacy. However, traditional FL frameworks rely on a centralized aggregation server and assume honest-but-curious clients, making them susceptible to both server-side inference and client-side poisoning at…
Read original ↗https://arxiv.org/abs/2607.06612arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe arXiv:2607.07209v1 Announce Type: new Abstract: Modern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor contin…
Read original ↗https://arxiv.org/abs/2607.07209arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Deanonymizing Monero Transactions in Tor Network arXiv:2607.07062v1 Announce Type: new Abstract: Monero is a privacy-focused cryptocurrency that deploys the Dandelion++ protocol and incorporates anonymity networks (such as Tor and I2P) to prevent malicious attackers from linking transactions with their source IPs. In this paper, we demonstrate that Monero's integration of the Tor network introduces a fundamental vulnerability: a Monero Tor node's originated transactions are …
Read original ↗https://arxiv.org/abs/2607.07062arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Security and Privacy in Agentic AI: Grand Challenges and Future Directions arXiv:2607.06608v1 Announce Type: new Abstract: We present key challenges and future research directions in the security and privacy of agentic AI, based on a horizon-scanning exercise that brought together thirty leading international experts from academia, industry, and government to engage in focused discussions and collaborative exercises on the emerging risks associated with the growing agency of…
Read original ↗https://arxiv.org/abs/2607.06608arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
The Power of Backdoor Absorption in Community Training arXiv:2607.06643v1 Announce Type: new Abstract: Backdoor attacks severely threaten large-scale AI models. When model owners delegate training to external compute providers within a decentralized training paradigm, adversaries can craft stealthy, low-frequency triggers to inject malicious behavior while evading standard audits. Traditionally, detecting these attacks requires a full re-computation of the training steps--a …
Read original ↗https://arxiv.org/abs/2607.06643arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
When Agents Go Rogue: Activation-Based Detection of Malicious Behaviors in Multi-Agent Systems arXiv:2607.06807v1 Announce Type: new Abstract: While enabling effective collaboration on complex tasks, LLM-based Multi-Agent Systems (MAS) face critical security challenges due to vulnerabilities at the agent and interaction levels. Most existing MAS security defenses are built upon two core assumptions: semantically-explicit malicious attacks and explicit graph-based modeling of…
Read original ↗https://arxiv.org/abs/2607.06807arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Is Randomness Necessary for Adaptive Data Analysis? arXiv:2607.07085v1 Announce Type: new Abstract: The Adaptive Data Analysis (ADA) problem formalizes the challenge of preventing false discovery and overfitting when a dataset is repeatedly reused. Formally, our input is a dataset containing $n$ i.i.d. samples from an unknown distribution $\mathcal{P}$ over a domain $\mathcal{X}$, and our goal is to answer a sequence of $k$ adaptively chosen statistical queries with respect …
Read original ↗https://arxiv.org/abs/2607.07085arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents arXiv:2607.06595v1 Announce Type: new Abstract: Personal AI agents powered by large language models can reason and act using available tools to access emails, manage calendars, and push code to remote repositories, all with minimal oversight. When augmented with long-term memory, an agent can recall specific details relevant to the current task, reducing the need for large context windows.…
Read original ↗https://arxiv.org/abs/2607.06595arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages arXiv:2607.06596v1 Announce Type: new Abstract: Trusted monitoring is a central defense in AI control: a cheaper trusted model scores an untrusted model's actions for sabotage, and the most suspicious are audited or deferred. Such monitors are evaluated against one or two untrusted models, and the accuracy is reported as a property of the monitor. We ask whether it is partly a property o…
Read original ↗https://arxiv.org/abs/2607.06596arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
SA-DRL: Security-Aware Deep Reinforcement Learning for Ransomware Detection with Asymmetric Reward Design arXiv:2607.06880v1 Announce Type: new Abstract: Ransomware detection is a security-critical task in which false negatives and false positives have unequal operational consequences. Conventional machine learning detectors often use symmetric objectives that penalize missed ransomware detections and benign false alarms equally, although a false negative can cause irreversi…
Read original ↗https://arxiv.org/abs/2607.06880arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
ORAN-DEFEND: Subspace Detection and Sanitization of Backdoor DRL xApps in Open RAN arXiv:2607.06647v1 Announce Type: new Abstract: Open Radio Access Networks (O-RAN) increasingly delegate near-real-time control to deep reinforcement learning (DRL) xApps obtained from third-party vendors, creating a new supply-chain attack surface. A backdoor policy behaves optimally until an adversary injects a covert trigger into the observed key performance indicator (KPI) telemetry, at wh…
Read original ↗https://arxiv.org/abs/2607.06647arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
POPS: Recovering Unlearned Multi-Modality Knowledge in MLLMs with Prompt-Optimized Parameter Shaking arXiv:2607.06649v1 Announce Type: new Abstract: Multimodal Large Language Models (MLLMs) have demonstrated impressive performance on cross-modal tasks by jointly training on large-scale textual and visual data, where privacy-sensitive examples could be unintentionally encoded, raising concerns about privacy or copyright violation. To this end, Multi-modality Machine Unlearnin…
Read original ↗https://arxiv.org/abs/2607.06649arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Thinking More, Harnessing Better: State Machine Guided Harness Automatic Generation with Project Digestion and Workflow Decomposition arXiv:2607.07007v1 Announce Type: new Abstract: High-quality fuzz harnesses are essential for effective gray-box fuzzing. While Large Language Models (LLMs) offer promise for automating this task, existing one-turn generation methods suffer from hallucinations and inadequate coverage due to coarse-grained function targeting and misaligned gene…
Read original ↗https://arxiv.org/abs/2607.07007arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Behavioral Privacy Leakage in Agentic Negotiation: Formalizing and Mitigating Inference Attacks via Randomized Policies arXiv:2607.06815v1 Announce Type: new Abstract: Autonomous negotiation agents are increasingly deployed in high-stakes settings such as insurance and procurement. While cryptographic techniques protect explicitly disclosed constraint values, they fail to address a subtler threat: behavioral privacy leakage, where an adversary infers private constraints from…
Read original ↗https://arxiv.org/abs/2607.06815arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Blockchain Attacks and Defenses: A Layered and Cross-Domain Survey arXiv:2607.06593v1 Announce Type: new Abstract: Blockchains have evolved from simple distributed ledgers into programmable platforms that process complex application logic and carry significant financial value. All modern Web3 systems share a common goal: providing secure, decentralized, and trustworthy execution in an increasingly interconnected environment. However, this evolution has shifted the attack sur…
Read original ↗https://arxiv.org/abs/2607.06593arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Cyber Dynamics I: Finite Macrostates for Behavioral Anomaly Detection in Network Telemetry arXiv:2607.07075v1 Announce Type: new Abstract: Entropy-based methods have long been used for network anomaly detection, but most existing approaches treat entropy as a scalar statistic on narrow observables rather than as part of a broader behavioral state-space for cyber systems. We propose a finite-dimensional macrostate framework for network telemetry, instantiated over the Canonic…
Read original ↗https://arxiv.org/abs/2607.07075arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
ECO/CPO-DAG: A Contradiction-Based Accountability Layer for Adversarial Supply Chains arXiv:2607.06804v1 Announce Type: new Abstract: We present ECO/CPO-DAG, a domain-specific accountability protocol for adversarial supply chains that formalizes contradiction detection as a supplemental validation layer rather than a consensus or truth-establishing mechanism. Participants publish signed Event Claim Objects (ECOs) into a causally ordered, append-only directed acyclic graph (D…
Read original ↗https://arxiv.org/abs/2607.06804arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Evaluating Endpoint Detection Robustness Against Genetic Algorithm Driven Code Transformations arXiv:2607.07191v1 Announce Type: new Abstract: Post-compromise test variants are widely used in controlled security evaluation and endpoint robustness benchmarking. However, modern Antivirus (AV) and Endpoint Detection and Response (EDR) systems increasingly combine signature- and behavior-based detection, challenging the reliability of conventional detection pipelines under adapt…
Read original ↗https://arxiv.org/abs/2607.07191arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies arXiv:2607.06963v1 Announce Type: new Abstract: Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated…
Read original ↗https://arxiv.org/abs/2607.06963arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
An Automated Framework for Generating Stealthy Cell-Embedded Hardware Trojans arXiv:2607.07049v1 Announce Type: new Abstract: Hardware Trojans (HTs) pose significant threats across the Integrated Circuit (IC) design lifecycle because they can be inserted by untrusted entities at different stages under the zero-trust model. When triggered under rare conditions, HTs can compromise the functionality, reliability, or security of the fabricated chip. HT assessment is typically pe…
Read original ↗https://arxiv.org/abs/2607.07049arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Auditable Machine Unlearning for Privacy-Compliant Ransomware Detection Using Multi-Shard SISA and Deep Reinforcement Learning arXiv:2607.06860v1 Announce Type: new Abstract: Ransomware poses an escalating cybersecurity threat as attackers continuously modify behavioral patterns to evade static defenses. Although existing machine learning-based detectors often achieve strong predictive performance, they generally assume fixed training data and do not support the selective re…
Read original ↗https://arxiv.org/abs/2607.06860arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Monitoring Vulnerabilities in Next-Generation Automotive Operating Systems arXiv:2607.07226v1 Announce Type: new Abstract: Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short i…
Read original ↗https://arxiv.org/abs/2607.07226arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
MoLIFE: Methodology, Technologies, and Challenges for Mobile Live Intelligent Forensics Examination arXiv:2607.07269v1 Announce Type: new Abstract: Nowadays, mobile forensics is less explored in Digital Forensics case analysis due to the increase in data protection mechanisms implemented by tech companies (i.e., Google for Android and Apple for iOS). For example, the physical acquisition or analysis of specific directories under super-user protection would corrupt the eviden…
Read original ↗https://arxiv.org/abs/2607.07269arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Safe2Hail: A Forensic-Driven Post-Trip Tracking Framework for Ride-Hailing Safety in Africa arXiv:2607.07271v1 Announce Type: new Abstract: Ride-hailing mobile apps have become an essential feature in the mobility ecosystem in Africa, offering much safer and much more affordable rides. Although user bases have increased and the number of daily trips has proliferated, reports of imminent safety threats, particularly after the cancellation of the ride or the ride is prematurel…
Read original ↗https://arxiv.org/abs/2607.07271arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Certifying Ghosts: How Cybersecurity AI Agents Break the EU Cyber Resilience Act arXiv:2607.07109v1 Announce Type: new Abstract: The EU Cyber Resilience Act (CRA) makes a smart bet. It does not demand that products be free of vulnerabilities, but only that manufacturers run a process: assess risk, handle flaws, ship updates. The bet pays off if four things about the world stay true: (P1) finding vulnerabilities is slow, skilled, human work; (P2) a product's exploitable flaws…
Read original ↗https://arxiv.org/abs/2607.07109lwn_kernel · tlp:amber · 7/9/2026, 1:12:33 AM
[$] LWN.net Weekly Edition for July 9, 2026 Inside this week's LWN.net Weekly Edition: Front : Cryptography API; Iomap explanation; Negative dentries; Faster RCUs and lockless allocation for BPF; Negative dentries; LLMs in memory-management code Briefs : Guix vulnerabilities; OpenSSH 10.4; trusted publishing; kernel archive; CalyxOS; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1080835
snyk_blog · tlp:amber · 7/9/2026, 12:00:00 AM
Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) A harmless-looking symlink in a Git repo can redirect a tool into reading or writing anywhere on your machine. That old trick is now showing up in AI coding assistants, with nasty results. Symlinks Are Still Scary — And Yes, Git Supports Them | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing Evo New EN Select your language English Deutsch Español França…
Read original ↗https://snyk.io/blog/symlinks-are-still-scarylwn_kernel · tlp:amber · 7/8/2026, 10:31:34 PM
OpenMandriva: Statement regarding attempted distribution sabotage Over on the OpenMandriva forum , the Linux distribution has reported sabotage of its repositories by a disgruntled contributor with administrative credentials. According to "AngryPenguin", an abusive incident in a distribution Matrix chat led to a user being kicked out of the chat; that " triggered a cascade of events ", which led to people resigning from the distribution. Eventually, one of those people used …
Read original ↗https://lwn.net/Articles/1081884the_record · tlp:amber · 7/8/2026, 8:20:00 PM
Greek victims file lawsuit against Intellexa over Predator spyware The use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff. Greek victims file lawsuit against Intellexa over Predator spyware | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Po…
Read original ↗https://therecord.media/greek-victims-file-lawsuit-against-intellexa-spywarethe_record · tlp:amber · 7/8/2026, 8:14:00 PM
Cash App owner to pay $45 million to settle allegations of lax security State attorneys general announced the bipartisan agreement with Block, Inc. on Wednesday, saying that the company incorrectly promised users that Cash App offered the same protections as a bank. Cash App owner to pay $45 million to settle allegations of lax security | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast G…
Read original ↗https://therecord.media/cash-app-owner-to-pay-45-million-security-allegationsars_security · tlp:amber · 7/8/2026, 7:01:19 PM
Google pays $250K for Linux vulnerability allowing guest VM escapes Both vulnerabilities allow untrusted users to gain root privileges. A Linux vulnerability that allows untrusted virtual machines to gain root access to host machines is one of two high-severity flaws to surface this week in the open source operating system. The vulnerability resides in KVM, which is, in essence, a virtual machine app included in the kernel of many Linux distributions. The vulnerability, tra…
Read original ↗https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-weekhuggingface_blog · tlp:amber · 7/8/2026, 5:16:05 PM
Data for Agents
Read original ↗https://huggingface.co/blog/nvidia/open-data-for-agentsthe_hacker_news · tlp:amber · 7/8/2026, 5:02:12 PM
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack. Decrypting browser credentials, listing what sits in Windows' credential store, AI C…
Read original ↗https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.htmlmicrosoft_mstic · tlp:amber · 7/8/2026, 5:00:00 PM
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud At Microsoft we encompass these security requirements, along with threat knowledge, and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like. But defining the requirements is only the start. Meeting the requirements means continuously evaluating our live services against them, at AI speed. The post Protecting Microsoft at AI speed: How SFI p…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/08/protecting-microsoft-at-ai-speed-how-sfi-proactively-hardens-our-cloud