REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2215 reports · page 18 of 56
talos · tlp:amber · 7/7/2026, 10:00:05 AM
UAT-7810 continues building ORB networks using new malware Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware. Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025. UAT-7810 is most likely tasked with …
Read original ↗https://blog.talosintelligence.com/uat-7810securityweek · tlp:amber · 7/7/2026, 10:00:00 AM
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems The 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek . Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Vi…
securityweek · tlp:amber · 7/7/2026, 9:30:00 AM
Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security The investment will accelerate Keyfactor's machine identity, PKI, and cryptographic security platform as enterprises prepare for AI-driven and post-quantum threats. The post Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security appeared first on SecurityWeek . Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webca…
Read original ↗https://www.securityweek.com/keyfactor-scores-1-billion-investment-for-ai-post-quantum-securitythe_hacker_news · tlp:amber · 7/7/2026, 9:10:51 AM
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, Suspec…
Read original ↗https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.htmlthe_hacker_news · tlp:amber · 7/7/2026, 6:40:47 AM
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. "An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process CERT/CC Warns of H…
Read original ↗https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.htmlthe_hacker_news · tlp:amber · 7/7/2026, 5:16:51 AM
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are listed below - CVE-2026-40138 (CVSS score: 9.2) - A pre-authentication vulnerability exists in the BeyondTrust Patches Criti…
Read original ↗https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.htmlarxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Swarm-Driven Multi-Agent Reasoning for Smart City Security arXiv:2607.03628v1 Announce Type: new Abstract: Modern smart cities are interconnected cyber-physical ecosystems where heterogeneous devices exchange data and control commands. Coordinated attacks may appear as weak and distributed indicators, including low-rate scanning, abnormal credential use, protocol misuse, or delayed lateral movement, with each signal remaining below local alert thresholds. Therefore, smart-ci…
Read original ↗https://arxiv.org/abs/2607.03628arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
The agent creates, we validate: A Lightweight Framework for Agentic Artifact Generation arXiv:2607.02615v1 Announce Type: new Abstract: Generating structured artifacts with Large Language Models - e.g. database queries, threat framework mappings, entity schemas - is relatively straightforward; however, making them reliable enough for production deployments presents challenges. We present a lightweight framework based on a core principle: LLMs generate, we validate. This refr…
Read original ↗https://arxiv.org/abs/2607.02615arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Execution Divergence Graphs:Effective Discovery of Control-Flows from Execution Traces as Fuzzing Feedback arXiv:2607.03396v1 Announce Type: new Abstract: Fuzz testing is a popular approach to the security testing of proprietary software. Efficient testing strategies rely on execution feedback to guide the input generation process, particularly when the basic blocks in the binary can be directly observed and instrumented. Unfortunately, collecting such feedback is impossible…
Read original ↗https://arxiv.org/abs/2607.03396arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Scalable Differentially Private Data Compression via Diffusion and Stochastic Codes arXiv:2607.03392v1 Announce Type: new Abstract: The ever-increasing collection of personal data has created mounting pressure to develop technologies that protect sensitive aspects of individual identity. Differential privacy (DP) provides a principled framework with strong formal guarantees and has already achieved practical success. However, releasing high-dimensional data, such as images, …
Read original ↗https://arxiv.org/abs/2607.03392arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
LLM-Enhanced Hierarchical Heterogeneous Graph Representation Learning for Malicious Python Package Detection arXiv:2607.03350v1 Announce Type: new Abstract: Malicious Python packages have become a major threat to software supply chain ecosystems due to the widespread adoption of open-source repositories such as PyPI. Existing learning-based detection methods struggle to capture the hierarchical organization and heterogeneous interactions among different program entities. Alt…
Read original ↗https://arxiv.org/abs/2607.03350arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
RES-DARE: Failure-Aware Expert Adaptation and Rollback-Safe Self-Repair for Intrusion Detection arXiv:2607.02687v1 Announce Type: new Abstract: Intrusion detection systems are often trained under static benchmark conditions, although deployed network environments are affected by traffic drift, sensor noise, changing workloads, and evolving attack behaviour. Under such distribution shifts, static detectors may produce confident but incorrect predictions, leading to silent and…
Read original ↗https://arxiv.org/abs/2607.02687arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Security Analysis for SCONE Logic Locking arXiv:2607.03288v1 Announce Type: new Abstract: SCONE [DAC'25] expands a logic locking interface with additional encoded inputs derived from the original primary inputs, and admits two realizations: a \textit{with-ES} variant, where the critical encoding stage is implemented in hardware, and a \textit{without-ES} variant, where the locked design directly exposes an encoded interface of width $n+m$. We show that both realizations are …
Read original ↗https://arxiv.org/abs/2607.03288arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Rotation-Optimal Noncommutative Prefix Scans in Bit-Reversed Homomorphic Layouts arXiv:2607.03631v1 Announce Type: new Abstract: Packed homomorphic encryption evaluates slotwise operations in parallel, but nonlocal communication is realized by cyclic rotations whose cost depends on the physical slot layout. We study ordered prefix computation on $n=2^m$ elements of an associative, possibly noncommutative monoid stored in bit-reversed order. A direct transported-predecessor s…
Read original ↗https://arxiv.org/abs/2607.03631arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Agentic and Generative AI for Open-Source Intelligence and Cyber Investigations: Taxonomy, Evaluation, Challenges, and Future Directions arXiv:2607.03233v1 Announce Type: new Abstract: The rapid growth of publicly available digital information has rendered manual open-source intelligence (OSINT) analysis insufficient for modern intelligence, cybersecurity, and cyber investigation. Large language models (LLMs) and agentic AI systems, capable of tool use, multi-step reasoning,…
Read original ↗https://arxiv.org/abs/2607.03233arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
CONTRA: Red-Teaming Configurations of Personalizable Agents arXiv:2607.03220v1 Announce Type: new Abstract: Recent tools such as OpenClaw have extended the capabilities of LLM-based agents from simple dialog-based systems to fully autonomous agents. These systems allow personalization of the agent through modifiable internal files and the installation of skills. While this enables deployment in a wide range of settings and the automation of diverse tasks, greater capability …
Read original ↗https://arxiv.org/abs/2607.03220arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Builder, Defender, Breaker: The Case Against Removing the Human from the AI-Driven Security Lifecycle arXiv:2607.03215v1 Announce Type: new Abstract: Artificial intelligence has spread across the whole of the security lifecycle. The same family of models now writes application code, hardens it, and probes it for weaknesses, so that a single generative substrate increasingly performs all three roles at once. Enthusiasm for this convergence tends to treat full autonomy as the …
Read original ↗https://arxiv.org/abs/2607.03215arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Not All Refusals Are Equal: How Safety Alignment Fails Cybersecurity at Scale arXiv:2607.02714v1 Announce Type: new Abstract: There is no doubt that safety alignment is an essential step in LLM training. However, conceptually it does not distinguish between various domains and the level of potential harm of a query, which creates significant complications in the fields like cyber security, where a model should not be constrained by its safety circuits to accomplish the goals…
Read original ↗https://arxiv.org/abs/2607.02714arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Vision Token Manipulation Attacks on Cloud-Edge Inference of Large Vision-Language Models arXiv:2607.02819v1 Announce Type: new Abstract: Cloud-edge Large Vision-Language Model (LVLM) inference enables efficient deployment by splitting computation between edge devices and cloud servers. In this process, intermediate vision tokens are transmitted from the edge to the cloud over a communication link, thereby exposing a new attack surface. We study vision token manipulation att…
Read original ↗https://arxiv.org/abs/2607.02819arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Enhanced Feature Extraction for IoT Network Intrusion Detection Using GNNs and KAN arXiv:2607.02981v1 Announce Type: new Abstract: Recent advancements in the Internet of Things (IoT) emphasize the urgent need for advanced network security, as IoT networks feature dynamic topologies, imbalanced traffic, and complex attack patterns. Unlike general IT networks, IoT environments exhibit extreme heterogeneity and sparse topologies. Traditional GNN-based intrusion detection method…
Read original ↗https://arxiv.org/abs/2607.02981arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies arXiv:2607.03423v1 Announce Type: new Abstract: Modern AI agent implementations such as frontier coding agents chain multiple tools at runtime that create a security surface that per-tool guardrails are unable to address, as individually permitted tools can violate organizational policies when composed. We propose the Dynamic Security Control Compositor (DSCC), a two-phase approach to composit…
Read original ↗https://arxiv.org/abs/2607.03423arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Git Hash Chain Malleability arXiv:2607.02820v1 Announce Type: new Abstract: Git commit signing is widely entrusted to serve as evidence that a commit hash uniquely and immutably identifies a specific piece of signed content. We show this invariant does not hold. Given any signed commit, an attacker without access to the signing key, and without breaking SHA2 can produce a second, distinct commit with an identical tree, identical metadata, a valid signature, and a ``Verified'…
Read original ↗https://arxiv.org/abs/2607.02820arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
JavaVulBench: A Java Vulnerability Benchmark with Realistic Splits, a Unified Multi-Backend Harness, and a Leakage-Aware Evaluation Mode arXiv:2607.02825v1 Announce Type: new Abstract: We release \textsc{JavaVulBench}, a benchmark dataset and evaluation harness for Java vulnerability detection. The dataset contains $\sim$30{,}600 Java methods spanning 1{,}740 CVEs and 700+ projects, labelled at both method and line granularity, with per-CVE publication dates and five realist…
Read original ↗https://arxiv.org/abs/2607.02825arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
PromptPET: Privacy-Utility Optimized Prompt Obfuscation arXiv:2607.02932v1 Announce Type: new Abstract: Privacy is an important challenge when users interact with AI chatbots, since users may share sensitive information, explicitly or implicitly, and AI chatbots can use this information for user profiling. In this paper, we aim to protect user privacy via a user-side mechanism that transforms sensitive information in a user prompt, while preserving enough information to elic…
Read original ↗https://arxiv.org/abs/2607.02932arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
TIER: Trajectory-Invariant Explanation Regularization for Membership Privacy arXiv:2607.02903v1 Announce Type: new Abstract: Explainability is central to building trustworthy AI, yet explanation interfaces can inadvertently provide adversaries with an expanded privacy-related attack surfaces. Recent studies show that advanced membership-inference attacks succeed by exploiting confidence-drop trajectories, induced through attribution-guided perturbations, as discriminative fe…
Read original ↗https://arxiv.org/abs/2607.02903arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
PPE-Bench: A Benchmark for Evaluating MLLM Unlearning under Private-Public Entanglement arXiv:2607.02897v1 Announce Type: new Abstract: Multimodal Large Language Models (MLLMs) have shown strong capabilities, but they may memorize private information from web data, raising privacy concerns. Machine unlearning offers a way to remove such private knowledge without retraining from scratch. However, existing MLLM unlearning benchmarks have two major limitations. First, they rely…
Read original ↗https://arxiv.org/abs/2607.02897arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Overprivilege Analysis of Security Policies in Serverless Cloud Applications arXiv:2607.02875v1 Announce Type: new Abstract: Serverless computing has seen rapid adoption in cloud deployments, yet the security implications of its service-oriented programming model remain poorly understood. Distributed, modular, and heterogeneous applications complicate the specification of precise security policies. Role-based access control solutions such as Identity and Access Management (I…
Read original ↗https://arxiv.org/abs/2607.02875arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents arXiv:2607.02857v1 Announce Type: new Abstract: LLM coding agents increasingly complete development tasks by issuing ordinary CLI commands. Following the Unix design, these commands cooperate through shared operating-system state: one command may write state that a later command reads. While this composition is benign and intended, it creates an overlooked exploit surface. Existing attacks and defen…
Read original ↗https://arxiv.org/abs/2607.02857arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
ShannonProver: Towards Automating Formal Cryptographic Proofs arXiv:2607.02847v1 Announce Type: new Abstract: Cryptographic proofs are produced at a scale that increasingly exceeds the community's ability to verify them manually. Machine-checked proofs offer a path toward scalable proof verification, but writing proof scripts for expressive proof assistants such as EasyCrypt remains a major bottleneck: even when the high-level proof plan is known, converting it into proof ta…
Read original ↗https://arxiv.org/abs/2607.02847arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
LeanDY: Type-Based and Trace-Based Symbolic Protocol Verification in Lean arXiv:2607.03406v1 Announce Type: new Abstract: Computer-aided formal verification is a widely used approach for the symbolic analysis of cryptographic protocols. However, many modern protocols rely on features that remain challenging for existing techniques. In particular, reasoning about state, time-dependent behavior, inductively defined data structures, unbounded executions, and conditional secrecy…
Read original ↗https://arxiv.org/abs/2607.03406arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Observer-Quotient Security: Composable Leakage Bounds for Hidden State Continuations arXiv:2607.03610v1 Announce Type: new Abstract: Observer-quotient security studies interactive cryptographic systems whose security depends on what an admissible observer can distinguish across transcripts, leakage traces, and hidden implementation continuations. The paper defines observer-indexed experiments with session identifiers, adaptive schedulers, oracle forwarding, simulators, ideal…
Read original ↗https://arxiv.org/abs/2607.03610huggingface_blog · tlp:amber · 7/7/2026, 12:00:00 AM
LeRobot v0.6.0: Imagine, Evaluate, Improve LeRobot v0.6.0: Imagine, Evaluate, Improve Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> LeRobot v0.6.0: Imagine, Evalu…
Read original ↗https://huggingface.co/blog/lerobot-release-v060chainalysis · tlp:amber · 7/6/2026, 9:03:39 PM
Breadth, Depth, And Quality: Why Comparing Blockchain Analytics Vendors by Cluster Count Is Only Part of the Calculation When compliance teams, regulators, or investigators evaluate blockchain analytics providers, the conversation almost always starts the same: How many services… The post Breadth, Depth, And Quality: Why Comparing Blockchain Analytics Vendors by Cluster Count Is Only Part of the Calculation appeared first on Chainalysis . Breadth, Depth, And Quality: …
Read original ↗https://www.chainalysis.com/blog/comparing-blockchain-analytics-vendorsthe_record · tlp:amber · 7/6/2026, 8:55:00 PM
Canadian spy agency reports hacking three criminal groups in 2025 A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communications Security Establishment. Canadian spy agency reports hacking three criminal groups in 2025 | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast…
Read original ↗https://therecord.media/canada-cse-2025-cyber-operations-ransomware-drugs-extremismsecurityweek · tlp:amber · 7/6/2026, 7:14:08 PM
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on SecurityWeek . Blogspot-Hosted Payloads Delivered in 'Veil#Drop' Attacks - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Web…
Read original ↗https://www.securityweek.com/blogspot-hosted-payloads-delivered-in-veildrop-attacksthe_hacker_news · tlp:amber · 7/6/2026, 6:34:26 PM
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research Ira…
Read original ↗https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.htmlthe_hacker_news · tlp:amber · 7/6/2026, 5:37:01 PM
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the researcher claims that a separate, unreleased expl…
Read original ↗https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.htmlthe_hacker_news · tlp:amber · 7/6/2026, 4:28:59 PM
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEBAUTH-USER" header from any source IP address, effectively allowing an unauthenticated internet client to get elevated Th…
Read original ↗https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.htmllwn_kernel · tlp:amber · 7/6/2026, 4:13:19 PM
OpenSSH 10.4 released OpenSSH 10.4 has been released. In addition to a number of security and bug fixes, there are a few notable changes; this release adds experimental support for a composite post-quantum signature scheme combining ML-DSA 44 and Ed25519 as described in this IETF draft . With 10.4, if OpenSSH is compiled with sandbox support it will fail on Linux systems that have not enabled SECCOMP or NO_NEW_PRIVS ; prior to this release, sshd would log an error but contin…
Read original ↗https://lwn.net/Articles/1081536microsoft_mstic · tlp:amber · 7/6/2026, 4:00:00 PM
5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management Read five key learnings from the Frost & Sullivan 2025 Frost Radar™ for CSPM to learn how CSPM is evolving from point-in-time compliance to continuous risk management. The post 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management appeared first on Microsoft Security Blog . Cloud security posture management (CSPM) is being redefined as two…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/06/5-insights-from-frost-sullivans-2025-frost-radar-for-cloud-security-posture-management