REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2214 reports · page 17 of 56
arxiv_cs_cr · tlp:amber · 7/8/2026, 4:00:00 AM
Proof of Execution: Runtime Verification for Governed AI Agent Actions arXiv:2607.05397v1 Announce Type: new Abstract: Agent systems increasingly execute rather than advise. When an AI agent queries regulated data, invokes effectful tools, and mutates persistent state, correctness is not captured by whether a terminal output looks plausible. The operative questions are whether each step was authorized under a contract, whether the recorded history is tamper-evident, and whet…
Read original ↗https://arxiv.org/abs/2607.05397arxiv_cs_cr · tlp:amber · 7/8/2026, 4:00:00 AM
How Stable Is a PNT Resilience Score? Decision-Instability of Single-Number Resilience Ratings under Framework-Aligned Weighting arXiv:2607.05415v1 Announce Type: new Abstract: Authoritative positioning, navigation, and timing (PNT) resilience frameworks (the DHS Resilient PNT Conformance Framework, RPCF, and peers) define what resilience means but supply only self-attestation: a checklist or a maturity Level, with no engine and no measurement. We build the missing measureme…
arxiv_cs_cr · tlp:amber · 7/8/2026, 4:00:00 AM
Abductive Corroboration of Probabilistic AI Models for Forensic Synthetic Media Detection arXiv:2607.05434v1 Announce Type: new Abstract: Artificial Intelligence (AI) models, at their core, apply general learnings from broad datasets to individual circumstances using probabilistic behaviour. This inductive approach stands in contrast to deductive reasoning approaches which seek to prove conclusions from their premises. However, research has shown that deductive reasoning wit…
Read original ↗https://arxiv.org/abs/2607.05434arxiv_cs_cr · tlp:amber · 7/8/2026, 4:00:00 AM
Evaluating calibrated refusal and safe usefulness in dual-use biology settings arXiv:2607.05462v1 Announce Type: new Abstract: As AI agents are incorporated into life science workflows, the capabilities that speed discovery might also enable misuse. We present BioSecBench-Refusal, a benchmark for risk identification and refusal behavior for biological research tasks. The benchmark pairs 61 Routine tasks, legitimate analyses adapted from the published literature, with 46 Red-…
Read original ↗https://arxiv.org/abs/2607.05462arxiv_cs_cr · tlp:amber · 7/8/2026, 4:00:00 AM
ShadowProbe: Language-Extensible Detection of Hidden Algorithmic Complexity Vulnerabilities arXiv:2607.05474v1 Announce Type: new Abstract: Algorithmic Complexity Vulnerabilities (ACVs) arise when adversarial inputs trigger worst-case execution behavior, causing severe performance degradation or Denial-of-Service conditions. A key but underexplored source is shadow complexity: non-trivial computational costs hidden inside seemingly benign standard library APIs. Because these…
Read original ↗https://arxiv.org/abs/2607.05474arxiv_cs_cr · tlp:amber · 7/8/2026, 4:00:00 AM
Privilege and confidentiality in generative AI workflows arXiv:2607.05479v1 Announce Type: new Abstract: Generative AI (GenAI) systems store and process client data in three distinct ways: in the model's parameters through training and memorisation, in the context window during a live session, and in knowledge databases for retrieval-augmented generation (RAG). Each mode creates different and often counter-intuitive risks to confidentiality and legal professional privilege, …
Read original ↗https://arxiv.org/abs/2607.05479huggingface_blog · tlp:amber · 7/8/2026, 12:00:00 AM
Native-speed vLLM transformers modeling backend Native-speed vLLM transformers modeling backend Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> Native-spee…
Read original ↗https://huggingface.co/blog/native-speed-vllm-transformers-backendunit42 · tlp:amber · 7/7/2026, 10:00:21 PM
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42 . Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation Menu Tools ATOMs Security Consulting About Us Under Attack? Thre…
Read original ↗https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysishuggingface_blog · tlp:amber · 7/7/2026, 9:15:33 PM
From Hugging Face to Amazon SageMaker Studio in one click From Hugging Face to Amazon SageMaker Studio in one click Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> …
Read original ↗https://huggingface.co/blog/amazon/one-click-to-sagemaker-studiosecurityweek · tlp:amber · 7/7/2026, 5:31:54 PM
County Government Reportedly Paid $1 Million to Cyber Extortion Group The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek . County Government Reportedly Paid $1 Million to Cyber Extortion Group - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Event…
Read original ↗https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-groupsecurityweek · tlp:amber · 7/7/2026, 5:17:19 PM
Critical Gitea Flaw Under Active Exploitation, Researchers Warn Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek . Critical Gitea Flaw Under Active Exploitation, Researchers Warn - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual…
Read original ↗https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warnthe_hacker_news · tlp:amber · 7/7/2026, 5:10:15 PM
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool RedWing MaaS Pack…
Read original ↗https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.htmlthe_hacker_news · tlp:amber · 7/7/2026, 4:37:33 PM
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password. Security firm Varonis found it Rog…
Read original ↗https://thehackernews.com/2026/07/rogue-agent-flaw-could-have-let.htmlthe_record · tlp:amber · 7/7/2026, 4:05:00 PM
Supreme Court allows Texas app law requiring age verification to take effect A student advocacy organization and tech trade group had appealed to the high court to stay the Texas App Store Accountability Act on an emergency basis until the lower court rules. Supreme Court allows Texas app law requiring age verification to take effect | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go S…
Read original ↗https://therecord.media/supreme-court-allows-texas-app-law-age-verification-to-take-effectthe_record · tlp:amber · 7/7/2026, 3:31:00 PM
Britain plans to build autonomous AI 'Cyber Shield' to defend nation The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.” Britain plans to build autonomous AI 'Cyber Shield' to defend nation | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Techn…
Read original ↗https://therecord.media/britain-plans-autonomous-ai-cyber-shieldhuggingface_blog · tlp:amber · 7/7/2026, 3:20:06 PM
Hugging Face Models on Foundry Managed Compute
Read original ↗https://huggingface.co/blog/microsoft/foundry-managed-computethe_hacker_news · tlp:amber · 7/7/2026, 3:14:14 PM
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience, DEBULL …
Read original ↗https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.htmlthe_record · tlp:amber · 7/7/2026, 2:45:00 PM
Major Japanese telco says cyberattack exposed 12 million emails The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers. Major Japanese telco says cyberattack exposed 12 million emails | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free New…
Read original ↗https://therecord.media/major-japanese-telco-cyberattack-12-million-emailslwn_kernel · tlp:amber · 7/7/2026, 2:27:57 PM
Woodruff: You shouldn't trust trusted publishing William Woodruff, better known online as "yossarian", has published a blog post to make the case that users should not place their trust in trusted publishing : Trusted Publishing is a mechanism for establishing trust between an external machine identity (like a CI/CD workflow) and one or more projects on a package index/registry. The "trust" in "Trusted Publishing" refers to that trust relationship, and not to anything else. …
Read original ↗https://lwn.net/Articles/1081690the_hacker_news · tlp:amber · 7/7/2026, 2:04:50 PM
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones…
Read original ↗https://thehackernews.com/2026/07/public-github-issue-could-trick-github.htmlmandiant · tlp:amber · 7/7/2026, 2:00:00 PM
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021 , remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapilwn_kernel · tlp:amber · 7/7/2026, 1:39:34 PM
[$] Faster RCUs and lockless memory allocation Puranjay Mohan shared some of the work he's been doing recently on improving the performance of read-copy-update (RCU) at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit ; his talk would have been nice context to have earlier in the day when Harry Yoo and Alexei Starovoitov led a session about the new kmalloc_nolock() function that allows for lockless allocation from any kernel context, and which interacts …
Read original ↗https://lwn.net/Articles/1081009the_hacker_news · tlp:amber · 7/7/2026, 1:27:20 PM
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access during the May 2025 intrusion, then to online accounts prosecutors say belong to 19-year-old Peter Stokes. Stokes is…
Read original ↗https://thehackernews.com/2026/07/court-filing-reveals-windows-device-id.htmlthe_hacker_news · tlp:amber · 7/7/2026, 1:27:09 PM
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team. "An outsider could go from having no access to taking over any Writer AI Writer AI …
Read original ↗https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.htmlsecurityweek · tlp:amber · 7/7/2026, 1:13:02 PM
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises. The post CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws appeared first on SecurityWeek . CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws - Security…
Read original ↗https://www.securityweek.com/cisa-reportedly-using-anthropics-mythos-to-scan-government-software-for-flawsthe_record · tlp:amber · 7/7/2026, 1:10:00 PM
UK cyber pledge draws only a handful of top firms despite ministerial appeal Those that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as well as small cybersecurity consultancies. UK cyber pledge draws only a handful of top firms despite ministerial appeal | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Techn…
Read original ↗https://therecord.media/uk-cyber-pledge-draws-limited-partners-despite-ministerial-appeallwn_kernel · tlp:amber · 7/7/2026, 1:07:58 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (nodejs22 and nodejs24), Fedora (clamav, hplip, kernel, kernel-headers, librabbitmq, mingw-expat, mir, perl-Imager, podman-tui, prometheus-podman-exporter, python-rpds-py, rust-ashpd, rust-busd, rust-gtk4-macros, rust-inferno, rust-quick-xml, rust-reqsign-aws-v4, rust-wayland-scanner, and sandogasa), Oracle (container-tools:rhel8, kernel, mariadb:10.11, mariadb:11.8, nginx, perl:5.32, php, php:7.4, r…
Read original ↗https://lwn.net/Articles/1081644securityweek · tlp:amber · 7/7/2026, 12:38:34 PM
Critical Adobe ColdFusion Vulnerability Exploited in Attacks Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek . Critical Adobe ColdFusion Vulnerability Exploited in Attacks - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference M…
Read original ↗https://www.securityweek.com/critical-adobe-coldfusion-vulnerability-exploited-in-attackssecurityweek · tlp:amber · 7/7/2026, 12:21:56 PM
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks appeared first on SecurityWeek . Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtua…
Read original ↗https://www.securityweek.com/iran-linked-hackers-using-modular-cc-framework-in-cyberattackssecurityweek · tlp:amber · 7/7/2026, 12:00:00 PM
CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker appeared first on SecurityWeek . CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought L…
Read original ↗https://www.securityweek.com/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinkercisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Hitachi Energy e-mesh EMS View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following ver…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Hydro-Québec Le Circuit Electrique charging station backend View CSAF Summary Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack. The following versions of Hydro-Québec Le Circuit Electrique charging station backend are affected: Le Circuit Electrique charging station backend CVSS Vendor Equipment Vulnerabilities v3 9.8 Hydro-Québec Hydro-Québec Le Circuit Electrique charging station backend Improper A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Siemens Mendix Studio Pro View CSAF Summary Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versi…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Siemens SINEC OS View CSAF Summary SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version. The following versions of Siemens SINEC OS are affected: RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/<4.0 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SINEC OS Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shu…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Digi International PortServer TS, Digi One SP IA View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. The following versions of Digi International PortServer TS, Digi One SP IA are affected: PortServer TS Digi One SP Digi One SP IA Digi One IA CVSS Vendor Equipment Vulnerabilities v3 5.9 Digi International Digi Internationa…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Hitachi Energy PROMOD V View CSAF Summary Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access. The following versions of Hitachi Energy PROMOD V are affected: PROMOD V vers:PROMOD_V/<=1.0.10 CVSS Vendor Equipment Vulnerabilities…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
Labcenter Proteus 9 View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of Labcenter Proteus 9 are affected: Proteus 9.1_SP4_Build_42914 CVSS Vendor Equipment Vulnerabilities v3 7.8 Labcenter Electronics Labcenter Proteus 9 Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free Background Critical Infrastructure Sectors: C…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06cisa_alerts · tlp:amber · 7/7/2026, 12:00:00 PM
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability These typ…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalogthe_hacker_news · tlp:amber · 7/7/2026, 11:30:00 AM
What Changes When Your Software Supply Chain Includes AI Writing Your Code? Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives less in the code a What Chan…
Read original ↗https://thehackernews.com/2026/07/what-changes-when-your-software-supply.htmltalos · tlp:amber · 7/7/2026, 10:00:05 AM
UAT-7810 continues building ORB networks using new malware Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware. Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025. UAT-7810 is most likely tasked with …
Read original ↗https://blog.talosintelligence.com/uat-7810