REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2217 reports · page 19 of 56
lwn_kernel · tlp:amber · 7/6/2026, 4:13:19 PM
OpenSSH 10.4 released OpenSSH 10.4 has been released. In addition to a number of security and bug fixes, there are a few notable changes; this release adds experimental support for a composite post-quantum signature scheme combining ML-DSA 44 and Ed25519 as described in this IETF draft . With 10.4, if OpenSSH is compiled with sandbox support it will fail on Linux systems that have not enabled SECCOMP or NO_NEW_PRIVS ; prior to this release, sshd would log an error but contin…
Read original ↗https://lwn.net/Articles/1081536microsoft_mstic · tlp:amber · 7/6/2026, 4:00:00 PM
5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management Read five key learnings from the Frost & Sullivan 2025 Frost Radar™ for CSPM to learn how CSPM is evolving from point-in-time compliance to continuous risk management. The post 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management appeared first on Microsoft Security Blog . Cloud security posture management (CSPM) is being redefined as two…
securityweek · tlp:amber · 7/6/2026, 3:20:42 PM
The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek . The Shift Toward Business-Aligned Risk Management - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats …
Read original ↗https://www.securityweek.com/the-shift-toward-business-aligned-risk-managementlwn_kernel · tlp:amber · 7/6/2026, 2:37:34 PM
[$] The kernel's iomap layer Conversations about the kernel's filesystem implementations often involve a layer called "iomap", but relatively few people can reliably say what iomap actually is. That is just the kind of gap that LWN exists to fill. In short, iomap handles the mapping between data in the filesystem space (identified by a file of interest, and an offset within that file) and in the storage space (which may be a memory location, or a set of blocks on a storage d…
Read original ↗https://lwn.net/Articles/1079415lwn_kernel · tlp:amber · 7/6/2026, 1:13:57 PM
Security updates for Monday Security updates have been issued by AlmaLinux (container-tools:rhel8, grafana, grafana-pcp, kernel, ruby:2.5, and ruby:3.3), Debian (bird3, chromium, kernel, linux-6.1, mediawiki, nginx, openvpn, php-phpseclib, php8.2, php8.4, and sympa), Fedora (7zip, buildah, chromium, clamav, freerdp, leptonica, mariadb10.11, mariadb11.8, nextcloud, nsd, openqa, openvpn, os-autoinst, pdns, pdns-recursor, perl-Crypt-ScryptKDF, podman, python-jupyter-server, and…
Read original ↗https://lwn.net/Articles/1081495the_hacker_news · tlp:amber · 7/6/2026, 1:01:14 PM
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems trusted the wrong instructions. Same soft spot throug…
Read original ↗https://thehackernews.com/2026/07/monday-recap-proxy-botnets-browser.htmlcheckpoint_research · tlp:amber · 7/6/2026, 12:25:02 PM
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig […] The post Cavern Manticore…
Read original ↗https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-frameworkcheckpoint_research · tlp:amber · 7/6/2026, 12:01:54 PM
6th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found […] The post 6th July – Threat Intelligence Report appeared first on Check Po…
Read original ↗https://research.checkpoint.com/2026/6th-july-threat-intelligence-report-2the_hacker_news · tlp:amber · 7/6/2026, 11:30:02 AM
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, triage, investigation, and response on their own data foundation. Whether a platform will mater…
Read original ↗https://thehackernews.com/2026/07/how-to-evaluate-ai-soc-platform-in-2026.htmlthe_hacker_news · tlp:amber · 7/6/2026, 10:58:16 AM
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation DragonReturn by Seqrite Labs, involves sending spear-phishing emails impersonating the Income Tax Department of India. …
Read original ↗https://thehackernews.com/2026/07/suspected-china-nexus-hackers-use-fake.htmlthe_hacker_news · tlp:amber · 7/6/2026, 8:50:54 AM
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode. But TrojPix works only once malware is already on the target machine, so it N…
Read original ↗https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.htmlthe_hacker_news · tlp:amber · 7/6/2026, 8:13:33 AM
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for one month to $1,200 for lifetime access. Other subscription tiers include $300 for New Java-Base…
Read original ↗https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.htmlthe_hacker_news · tlp:amber · 7/6/2026, 7:27:50 AM
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user's full Gmail address from a single visit, with no click. Opera has patched the flaw and says it found no evidence t…
Read original ↗https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.htmlthe_hacker_news · tlp:amber · 7/6/2026, 6:33:56 AM
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped past every scanner tested more than 90% of the time, and the same team built a runtime checker that catches …
Read original ↗https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.htmllwn_kernel · tlp:amber · 7/6/2026, 1:53:49 AM
Kernel prepatch 7.2-rc2 The 7.2-rc2 kernel prepatch is out for testing. Linus said: " It's Sunday afternoon, and rc2 is out. Things look very normal - it's not a small rc2, but it's in line with recent releases, and slightly smaller than rc2 was in 7.1. Let's see how that all continues, but so far so good. " Kernel prepatch 7.2-rc2 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for…
Read original ↗https://lwn.net/Articles/1081367huggingface_blog · tlp:amber · 7/6/2026, 12:00:00 AM
🤗 Kernels: Major Updates 🤗 Kernels: Major Updates Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> 🤗 Kernels: Major Updates Published July 6, 2026 Update on GitHub U…
Read original ↗https://huggingface.co/blog/revamped-kernelslwn_kernel · tlp:amber · 7/4/2026, 4:46:31 PM
Seven stable kernels for Saturday including two security fixes Greg Kroah-Hartman has announced the release of the 7.1.3 , 6.18.38 , 6.12.95 , 6.6.144 , 6.1.177 , 5.15.211 , and 5.10.260 stable kernels. Several kernels in this batch include a fix for a vulnerability introduced in the 6.0 kernel in IPv6 ( CVE-2026-53362 ), which could allow an attacker to escape a container and gain root access . There is also a fix for a use-after-free bug in KVM ( CVE-2026-53359 ) that was …
Read original ↗https://lwn.net/Articles/1081230the_hacker_news · tlp:amber · 7/4/2026, 12:47:53 PM
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no sign that it ever locked a single U.S. G…
Read original ↗https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.htmlthe_hacker_news · tlp:amber · 7/4/2026, 11:17:24 AM
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer acc…
Read original ↗https://thehackernews.com/2026/07/north-korean-hackers-publish-108.htmlthe_hacker_news · tlp:amber · 7/3/2026, 8:19:31 PM
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and other devices built on …
Read original ↗https://thehackernews.com/2026/07/unpatched-flaws-disclosed-in-filesystem.htmlthe_hacker_news · tlp:amber · 7/3/2026, 7:40:01 PM
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code where Anthropic's most powerful AI model, Mythos, recently found a different bug. The AI caught one flaw and missed Ne…
Read original ↗https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.htmlthe_hacker_news · tlp:amber · 7/3/2026, 6:55:24 PM
New Avalon Malware Framework Packs CrownX Ransomware Capabilities Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one New Avalon Malware Frame…
Read original ↗https://thehackernews.com/2026/07/new-avalon-malware-framework-packs.htmllwn_kernel · tlp:amber · 7/3/2026, 3:54:01 PM
Four vulnerabilities in Guix The GNU Guix project has announced three vulnerabilities in the guix substitute utility as well as a fourth that affects the guix pull and guix time-machine commands. The impact of the vulnerabilities ranges from remote privilege escalation to local disclosure of sensitive files. The remote exploitation of guix substitute only requires that the vulnerable system attempt to download a binary substitute. Any configured substitute server, including …
Read original ↗https://lwn.net/Articles/1081199lwn_kernel · tlp:amber · 7/3/2026, 2:10:03 PM
[$] Limiting negative dentries A number of problems related to negative directory entries (dentries) were the topic of a filesystem-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit . Negative dentries are used to indicate that a file of a given name does not exist in a directory; it is an optimization that short-circuits the lookup of the file name when the answer is already known. Miklos Szeredi led a session that discussed some problem…
Read original ↗https://lwn.net/Articles/1079407lwn_kernel · tlp:amber · 7/3/2026, 1:03:41 PM
Security updates for Friday Security updates have been issued by AlmaLinux (389-ds-base, bind9.18, evince, fence-agents, freerdp, frr, frr10, gimp, gnutls, hplip, jmc, mariadb:11.8, mysql:8.4, php:7.4, postgresql-jdbc, postgresql:15, postgresql:16, valkey, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (fastnetmon), Fedora (7zip, apptainer, cpp-httplib, mysql8.4, and nmap), Oracle (freerdp, giflib, glib2, glibc, kernel, libreoffice, libvirt, mariadb:10.11, postgresql…
Read original ↗https://lwn.net/Articles/1081187eset · tlp:amber · 7/3/2026, 12:36:41 PM
Cyber readiness for SMBs: Getting the basics right AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps Cyber readiness for SMBs: Getting the basics right Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Di…
Read original ↗https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-rightarxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
ElephantAgent: Contextual State Continuity in Agentic Systems arXiv:2607.01919v1 Announce Type: cross Abstract: Agentic systems enhance their capabilities by invoking external tools and maintaining persistent memory. However, these external dependencies introduce novel attack surfaces. Recent tool and memory poisoning attacks show that maliciously crafted tool descriptors and poisoned memory can covertly bias agent behavior. These threats reflect a deeper issue: the lack of …
Read original ↗https://arxiv.org/abs/2607.01919arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Beyond Gradient-Based Attacks: Adversarial Robustness and Explainability Stability in Cybersecurity Classifiers arXiv:2607.01679v1 Announce Type: new Abstract: Adversarial attacks on cybersecurity classifiers pose a dual threat: degrading predictions and destabilising the SHAP-based explanations that security analysts rely on to understand and triage alerts. We extend our prior MLP conference study to Random Forest and XGBoost across four tabular security datasets (phishing …
Read original ↗https://arxiv.org/abs/2607.01679arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design arXiv:2607.01711v1 Announce Type: new Abstract: Modern systems use format-, protocol-, and signature-based mechanisms before accepting artifacts across trust boundaries. These mechanisms are necessary: they show that an artifact is well formed, protocol-compliant, or properly authenticated. They do not, however, show that the artifact satisfies the semantic security properties re…
Read original ↗https://arxiv.org/abs/2607.01711arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification arXiv:2607.01668v1 Announce Type: new Abstract: Hardware security verification is a multi-stage process in which engineers must navigate complex design analyses, threat considerations, and verification strategies. They often need security-focused guidance, yet current verification environments provide little structured support for such assistance. Although conversational AI could offer such o…
Read original ↗https://arxiv.org/abs/2607.01668arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Sign in the Air to Unlock: An Interface for authentication in Virtual and Augmented Reality Powered by Point-Voxel Cross-Attention Network arXiv:2607.01435v1 Announce Type: cross Abstract: Significant advancement of immersive technologies such as Virtual and Augmented Reality (VR/AR) and their integration into diverse aspects of modern life need authentication interfaces that are secure, intuitive, and compatible with embodied interaction. Traditional methods such as passwor…
Read original ↗https://arxiv.org/abs/2607.01435arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Resilient Liquid Democracy: Mitigating Voting Power Imbalances via Secure Delegation Networks arXiv:2607.01730v1 Announce Type: new Abstract: Liquid democracy promises to improve collective decision-making by allowing voters to vote directly, delegate their voting power to trusted participants, or combine both approaches through fallback mechanisms. However, existing deployments typically rely on transparent delegation, which exposes voters to popularity-driven herding, make…
Read original ↗https://arxiv.org/abs/2607.01730arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
LIB-TRAP: Standard Cell Library Hardware Trojan Risk Assessment and Prevention arXiv:2607.01526v1 Announce Type: new Abstract: Vulnerabilities inherent to the fabless semiconductor manufacturing model have significantly increased the risk of malicious Hardware Trojan (HT) insertion, posing severe threats to hardware security. Several HT mitigation and detection strategies have been developed, and existing works explore the insertion of HTs in the space between standard cells…
Read original ↗https://arxiv.org/abs/2607.01526arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Overthink-Triggered Slowdown Attacks on LVLM-Based Robotic Systems arXiv:2607.01518v1 Announce Type: new Abstract: Large Vision-Language Models (LVLMs) have been increasingly integrated into robotic systems. However, these models may exhibit overthinking behaviors, where they generate excessively long reasoning traces, incurring an excessive inference time. This overthinking behavior poses a serious risk to robotic systems, as the adversary can deliberately trigger overthink…
Read original ↗https://arxiv.org/abs/2607.01518arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Hamm-Grams: An Algorithm for Mining Regular Expressions of Bytes arXiv:2607.01445v1 Announce Type: new Abstract: Malware poses a critical and ever-evolving threat, and robust and effective systems for detecting and classifying malware are of essential importance. $n$-grams features are among the common static features used in effective machine learning systems for malware, but these features are inherently brittle. We propose an algorithm for constructing more robust feature…
Read original ↗https://arxiv.org/abs/2607.01445arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Knowledge Over Parameters: Evolving Smart Contract Vulnerability Detection arXiv:2607.01742v1 Announce Type: new Abstract: Smart contract vulnerabilities are predominantly logic bugs whose detection requires structured, step-by-step procedural knowledge of attack patterns and contract semantics. Existing LLM-based methods struggle to generate this knowledge automatically: prompt-based methods rely on manually crafted detection rules, while fine-tuning requires massive labele…
Read original ↗https://arxiv.org/abs/2607.01742arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
From Forgeries to Foundation Models: A Systematic Survey of Identity Document Attack and Detection arXiv:2607.01442v1 Announce Type: new Abstract: Identity document forgery has undergone a fundamental capability shift: generative AI tools now enable high-fidelity document synthesis and field-level manipulation with minimal technical expertise, while detection methods remain constrained by benchmarks that do not reflect this threat. The resulting attack surface spans physical…
Read original ↗https://arxiv.org/abs/2607.01442arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Chameleon: Recovering Cyber-Physical Systems from Memory Corruption Attacks via ML Surrogates arXiv:2607.01356v1 Announce Type: new Abstract: Cyber-physical systems (CPSs) are increasingly deployed in every aspect of our lives and can be compromised through memory corruption vulnerabilities, allowing attackers to hijack the control flow and take over the system. Existing techniques mostly focus on detecting such attacks but respond by terminating or halting execution upon at…
Read original ↗https://arxiv.org/abs/2607.01356arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
An alternative approach towards attacks against fully-split PLWE instances arXiv:2607.01340v1 Announce Type: new Abstract: In the present work we address some key questions regarding the generalization of root-based attacks presented in a recent work by the authors. In particular, we analyze potential root-based attacks extensions via the construction of explicit isomorphisms from vulnerable instances, and provide a formal proof that this approach will not yield any new vuln…
Read original ↗https://arxiv.org/abs/2607.01340arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Generative AI and Federated Learning for Intrusion Detection Systems: A Survey arXiv:2607.01305v1 Announce Type: new Abstract: Intrusion Detection Systems (IDSs) are essential for monitoring network traffic and identifying malicious activities in modern cyber-physical, Internet of Things (IoT), enterprise, and distributed network environments. However, developing reliable IDS models remains challenging because attack behaviors evolve over time, realistic datasets are difficu…
Read original ↗https://arxiv.org/abs/2607.01305