REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
850 reports · page 19 of 22
arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Lightweight and Fast Backdoor Model Detection arXiv:2605.18907v1 Announce Type: new Abstract: Deep neural networks (DNN), despite their remarkable performance, are highly vulnerable to backdoor attacks. Existing defenses mainly rely on activation anomaly analysis or trigger reverse engineering and often require clean samples or prior knowledge of trigger patterns, resulting in limited efficacy, practicability, and generalizability. More critically, while advanced attacks can…
Read original ↗https://arxiv.org/abs/2605.18907arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Towards Zero Trust Architecture: A Pilot Study on Information Systems Security Readiness amongst Small and Medium Enterprises arXiv:2605.18901v1 Announce Type: new Abstract: Small and medium enterprises (SMEs) face growing cyber threats but often lack the resources and expertise needed to adopt Zero Trust Architecture (ZTA). This pilot study examines the drivers and barriers shaping SME perceptions of ZTA necessity and proposes an exploratory staged adoption path. Survey dat…
arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
GenAI-FDIA: Physics-Informed Generative Models for False Data Injection Attacks arXiv:2605.18873v1 Announce Type: new Abstract: Training and evaluating false data injection attack (FDIA) detectors for power systems is constrained by data scarcity. Operational grid measurements are commercially sensitive, and hand-crafted attacks fail to capture complex distributional structures imposed by network physics. We present \textsc{GenAI-FDIA}, a framework benchmarking a pool of $P{…
Read original ↗https://arxiv.org/abs/2605.18873arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
DarkLLM: Learning Language-Driven Adversarial Attacks with Large Language Models arXiv:2605.18868v1 Announce Type: new Abstract: While vision and multimodal foundation models underpin critical tasks from perception to complex reasoning, they remain highly vulnerable to adversarial attacks. However, traditional adversarial attacks are typically limited to single, predefined objectives, tightly coupling each attack to a specific model or task, which restricts their scalability…
Read original ↗https://arxiv.org/abs/2605.18868arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Decentralized autonomous organization and blockchain-based incentivization framework for community-based facilities management arXiv:2605.18773v1 Announce Type: new Abstract: Traditional facility management often relies on centralized decision-making structures that limit stakeholder participation, leading to misalignment with occupant needs and reduced satisfaction. This paper proposes a novel blockchain- and Decentralized Autonomous Organization (DAO)-based framework for c…
Read original ↗https://arxiv.org/abs/2605.18773arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
quantum-safe: Bridging the Post-Quantum Production Gap with a Hybrid-by-Default Python Cryptography Library arXiv:2605.17061v1 Announce Type: new Abstract: The August 2024 finalisation of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) closed the algorithmic gap in post-quantum cryptography (PQC). The production gap -- hybrid combiners, versioned key formats, protocol helpers, and migration tooling -- remains open. We present quantum-safe, a Python library that …
Read original ↗https://arxiv.org/abs/2605.17061arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Read This Paper to Get $50 Million:* An Analysis of Mobile Messaging Scams Using Reddit Data arXiv:2605.16656v1 Announce Type: new Abstract: Mobile messaging scams--fraudulent messages delivered over SMS and other mobile applications--have become a persistent and evolving security threat, yet the attributes underlying these campaigns remain unclear. This study seeks to address this gap by examining trends in mobile messaging scams and testing the effectiveness of commercial …
Read original ↗https://arxiv.org/abs/2605.16656arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Filter-then-Verify: A Multiphase GNN and ModernBERT Framework for Social Engineering Detection in Email Networks arXiv:2605.17201v1 Announce Type: new Abstract: Social engineering attacks exploit human trust rather than software vulnerabilities, making them difficult to detect using conventional filters. We propose a two-stage filter-then-verify framework combining inductive Graph Neural Networks (GNNs) for structural anomaly detection with a co-attention ModernBERT model fo…
Read original ↗https://arxiv.org/abs/2605.17201arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Securing LLM Agents Need Intent-to-Execution Integrity arXiv:2605.16976v1 Announce Type: new Abstract: This position paper argues that securing LLM agents requires first defining an end-to-end correctness property that specifies when an agent's execution faithfully reflects the user's intent. Modern LLM agents operate over an \emph{intent-to-execution pipeline}, where natural-language instructions are translated into concrete system operations such as tool calls, API request…
Read original ↗https://arxiv.org/abs/2605.16976arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
A Lightweight QR-assisted Zero-knowledge Identification Protocol For Secure Authentication arXiv:2605.16912v1 Announce Type: new Abstract: This study proposes a lightweight Zero-Knowledge authentication model supported by QR codes. The approach is based on the Schnorr authentication protocol and provides an additional security layer against replay attacks through nonce and timestamp mechanisms. The proof data generated by the prover is embedded within a QR code and transmitt…
Read original ↗https://arxiv.org/abs/2605.16912arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
SLEIGHT-Bench: A Benchmark of Evasion Attacks Against Agent Monitors arXiv:2605.16626v1 Announce Type: new Abstract: Since autonomous coding agents generate complex behaviors at high-volume, we may want to use other LLMs to monitor actions to reduce the risk from dangerous misaligned behavior. To better understand the limitations of such monitors against the diverse attack strategies that a coding agent could use, we present SLEIGHT-Bench (Subtle Low-itEration Insight-Guided…
Read original ↗https://arxiv.org/abs/2605.16626arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Universal Graph Backdoor Defense: A Feature-based Homophily Perspective arXiv:2605.16815v1 Announce Type: new Abstract: Graph neural networks (GNNs) have achieved remarkable success in relational learning. However, their vulnerability to graph backdoor attacks (GBAs) poses a significant barrier to broader adoption in high-stakes applications. Despite recent advances in graph backdoor defense (GBD), existing methods primarily focus on subgraph-based GBAs, relying on the assum…
Read original ↗https://arxiv.org/abs/2605.16815arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Public-Decay Homomorphic State Space Models for Private Sequence Inference arXiv:2605.16647v1 Announce Type: new Abstract: Fully homomorphic encryption (FHE) changes sequence-model design because rotations, encrypted products, ciphertext materialization, multiplicative depth, and bootstrapping pressure can dominate ordinary neural-network costs. This paper presents public-decay homomorphic state space models (HSSMs), recurrent/state-space blocks whose carried state is update…
Read original ↗https://arxiv.org/abs/2605.16647arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-demand Input Delivery arXiv:2605.16798v1 Announce Type: new Abstract: Firmware fuzzing has gained attention for identifying firmware bugs. However, current approaches often directly integrate fuzzing tools for general software. General software receives input as it encounters I/O functions, but firmware input can be received asynchronously and independently of the firmware's execution, with uncertain …
Read original ↗https://arxiv.org/abs/2605.16798arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Watermarks Attack Watermarks: Re-Watermarking as a Generic Removal Strategy arXiv:2605.16796v1 Announce Type: new Abstract: Watermarking combines an imperceptible change to an input image that will trigger a detector, to assert provenance and protect intellectual property. The literature has shown great interest in attacks on watermarking schemes: attackers are clearly motivated to steal copyrighted material or circumvent legislated deepfake protections. In this work, we mak…
Read original ↗https://arxiv.org/abs/2605.16796arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
MalwarePT: A Binary-Level Foundation Model for Malware Analysis arXiv:2605.16455v1 Announce Type: new Abstract: Automated malware analysis increasingly relies on machine learning, yet most existing methods remain task-specific and depend on handcrafted features or narrowly scoped models. Recent developments in binary-level foundation models suggest a path toward reusable program representations, but their application to malware analysis remains underexplored, and most still …
Read original ↗https://arxiv.org/abs/2605.16455arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
On-Device Interpretable Tsetlin Machine-Based Intrusion Detection for Secure IoMT arXiv:2605.16707v1 Announce Type: new Abstract: The rapid evolution of digital health technologies is redefining healthcare services worldwide. The integration of wireless communication and Internet-enabled medical devices within Internet of Medical Things (IoMT) networks enables continuous, real-time patient monitoring. However, this increased connectivity raises cybersecurity and patient safe…
Read original ↗https://arxiv.org/abs/2605.16707arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI arXiv:2605.16471v1 Announce Type: new Abstract: Generative AI systems are increasingly used not only to produce content but also to retrieve data, invoke tools, and execute actions. This work examines the security and safety implications of that shift across content-level, model-level, and agentic threats. We analyze how attacker access requirements, system autonomy, and the scope of po…
Read original ↗https://arxiv.org/abs/2605.16471arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment arXiv:2605.17163v1 Announce Type: new Abstract: Traditional cybersecurity methodologies target deterministic systems and fail to address the probabilistic nature of AI, leaving systems vulnerable to attack vectors such as model inversion, data poisoning, and prompt injection. Recent industry reports indicate that a majority of organizations deploying AI lack a dedicated security strategy, with adver…
Read original ↗https://arxiv.org/abs/2605.17163arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
New Wide-Net-Casting Jailbreak Attacks Risk Large Models arXiv:2605.17128v1 Announce Type: new Abstract: Jailbreak attacks on large models have drawn growing attention due to their close ties to societal safety. This work identifies a practical yet unexplored jailbreak scenario, the wide-net-casting scenario, where an adversary can query a group of large models instead of a single one to elicit harmful outputs. Our analysis reveals substantial yet previously overlooked safet…
Read original ↗https://arxiv.org/abs/2605.17128arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
A Method for Securely Transmitting Large Video Files Using Chaotic Compression and Encryption arXiv:2605.16563v1 Announce Type: new Abstract: Conventional techniques for compression and encryption are frequently laborious and resource-intensive, rendering them inappropriate for real-time applications. A plethora of research has been presented in the current literature to address these difficulties together; yet, it fails to propose any suitable strategy. Therefore, this stud…
Read original ↗https://arxiv.org/abs/2605.16563arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Simple Power Analysis on Post-Quantum Code Based Cryptosystems arXiv:2605.17116v1 Announce Type: new Abstract: Post-Quantum cryptography is about to substitute current cryptographic schemes as being resilient in attacks from quantum computers. McEleiece and Bit Flip Key Encapsulation (BIKE) are two delight representatives based on coding theory where classical structural attacks against these algorithms can be successfully phased out by selecting the appropriate key size. Us…
Read original ↗https://arxiv.org/abs/2605.17116arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
The End of Trust: How Agentic AI Breaks Security Assumptions arXiv:2605.16436v1 Announce Type: new Abstract: For decades, the security of digital interaction has rested on an unacknowledged economic constraint. Attackers faced a tradeoff between the fidelity of a deception and the scale at which it could be deployed. Convincing impersonation required sustained human effort and was confined to a narrow set of high-value targets, while mass-market attacks sacrificed plausibili…
Read original ↗https://arxiv.org/abs/2605.16436arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Post-Quantum Discovery as a Governance Capability: Evidence-Based Cryptographic Visibility and Exposure Prioritisation in a Critical Service Provider arXiv:2605.16549v1 Announce Type: new Abstract: Post Quantum Cryptography (PQC) readiness is increasingly constrained not by algorithm availability, but by cryptographic visibility, dependency complexity, and fragmented governance. This paper presents an anonymised case study of a large European critical service provider that i…
Read original ↗https://arxiv.org/abs/2605.16549arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
A Red Teaming Framework for Evaluating Robustness of AI-enabled Security Orchestration, Automation, and Response Systems arXiv:2605.17075v1 Announce Type: new Abstract: AI-enabled Security Orchestration, Automation, and Response (SOAR) systems increasingly employ autonomous agents for cyber defense, yet their resilience to adaptive adversaries is underexplored. We introduce an autonomous red teaming framework that integrates large language models (LLMs) with reinforcement le…
Read original ↗https://arxiv.org/abs/2605.17075arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort arXiv:2605.17062v1 Announce Type: new Abstract: Spracklen et al. (USENIX Security '25) showed that code-generating large language models hallucinate package names that do not exist on PyPI or npm at rates ranging from 5.2% on commercial models to 21.7% on open-source models, creating an attack surface for slopsquatting -- the registration of malicious packages un…
Read original ↗https://arxiv.org/abs/2605.17062arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Asking Back: Interaction-Layer Antidistillation Watermarks arXiv:2605.16462v1 Announce Type: new Abstract: Detecting unauthorized knowledge distillation from a deployed LLM API is hard because the defender controls neither the attacker's training pipeline nor the next-token logits. Existing defenses operate on the teacher's output tokens -- biasing the next-token distribution (green-list watermarks, cryptographic schemes, antidistillation sampling) or rewriting outputs after…
Read original ↗https://arxiv.org/abs/2605.16462arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
\textsc{PrivScope}: Task-scoped Disclosure Control for Hybrid Agentic Systems arXiv:2605.16630v1 Announce Type: new Abstract: Hybrid local--cloud agents enrich user requests with context from persistent working state before delegating capability-intensive subtasks to a cloud language model (CLM). While this enrichment can improve task success, it also exposes unnecessary information in the cloud-bound payload, including task-irrelevant context, carryover from prior workflows…
Read original ↗https://arxiv.org/abs/2605.16630arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
STRIKE: A Structured Taxonomy of Cybercrime for Risk, Impact, Knowledge, and Evolution arXiv:2605.16589v1 Announce Type: new Abstract: Cybercrime has grown exponentially in both scale and sophistication, posing significant threats. As attack methods evolve rapidly, traditional classification schemes often fail to capture the complexity and diversity of modern threats. To address this gap, we introduce STRIKE,a Structured Taxonomy for Risk, Impact, Knowledge, and Emerging Thr…
Read original ↗https://arxiv.org/abs/2605.16589arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Detecting Verbatim LLM Copy-Paste in Homework arXiv:2605.16336v1 Announce Type: new Abstract: Large language models (LLMs) have made fluent essay writing, code drafting, and quiz answering instantly available to students at every level, from secondary school through graduate study. Many educators do not object to LLM use \emph{per~se}; what they need to detect is the case in which a student pastes the assignment prompt into a chatbot and submits the model's reply verbatim, w…
Read original ↗https://arxiv.org/abs/2605.16336arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Privacy Auditing with Zero (0) Training Run arXiv:2605.14591v1 Announce Type: new Abstract: Privacy auditing provides empirical lower bounds on the differential privacy parameters of learning algorithms. Existing methods, however, require interventional access to the training pipeline, either to retrain multiple times or to randomize data inclusion. This is often infeasible for large deployed systems such as foundation models. We introduce Zero-Run privacy auditing, a post-h…
Read original ↗https://arxiv.org/abs/2605.14591arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections arXiv:2605.15030v1 Announce Type: new Abstract: Web agents can autonomously complete online tasks by interacting with websites, but their exposure to open web environments makes them vulnerable to prompt injection attacks embedded in HTML content or visual interfaces. Existing guard models still suffer from limited generalization to unseen domains and attack patterns, high false positive rates on beni…
Read original ↗https://arxiv.org/abs/2605.15030arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Toward Securing AI Agents Like Operating Systems arXiv:2605.14932v1 Announce Type: new Abstract: Autonomous agents based on large language models (LLMs) are rapidly emerging as a general-purpose technology, with recent systems such as OpenClaw extending their capabilities through broad tool use, third-party skills, and deeper integration into user environments. At the same time, these agentic systems introduce substantial security risks by combining unconstrained capabilitie…
Read original ↗https://arxiv.org/abs/2605.14932arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
PickleFuzzer: A Case Study in Fuzzing for Discrepancies Between Python Pickle Implementations arXiv:2605.15084v1 Announce Type: new Abstract: Python's native serialization protocol, pickle, is a powerful but insecure format for transferring untrusted data. It is frequently used, especially for saving machine learning models, despite known security challenges. While developers sometimes mitigate this risk by restricting imports during unpickling or using static and dynamic an…
Read original ↗https://arxiv.org/abs/2605.15084arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Do Coding Agents Understand Least-Privilege Authorization? arXiv:2605.14859v1 Announce Type: new Abstract: As coding agents gain access to shells, repositories, and user files, least-privilege authorization becomes a prerequisite for safe deployment: an agent should receive enough authority to complete the task, without unnecessary authority that exposes sensitive surfaces.To study whether current models can infer this boundary themselves, we first introduce permission-bound…
Read original ↗https://arxiv.org/abs/2605.14859arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces arXiv:2605.14786v1 Announce Type: new Abstract: As LLM-based agents increasingly browse the web on users' behalf, a natural question arises: can websites passively identify which underlying model powers an agent? Doing so would represent a significant security risk, enabling targeted attacks tailored to known model vulnerabilities. Across 14 frontier LLMs and four web environments spanning information re…
Read original ↗https://arxiv.org/abs/2605.14786arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
EVA: Editing for Versatile Alignment against Jailbreaks arXiv:2605.14750v1 Announce Type: new Abstract: Large Language Models (LLMs) and Vision Language Models (VLMs) have demonstrated impressive capabilities but remain vulnerable to jailbreaking attacks, where adversaries exploit textual or visual triggers to bypass safety guardrails. Recent defenses typically rely on safety fine-tuning or external filters to reduce the model's likelihood of producing harmful content. While…
Read original ↗https://arxiv.org/abs/2605.14750arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Adapting AlphaEvolve to Optimize Fully Homomorphic Encryption on TPUs arXiv:2605.14718v1 Announce Type: new Abstract: The deployment of Fully Homomorphic Encryption (FHE) at scale is hindered due to its heavy computational overhead. While specialized hardware accelerators like Google Tensor Processing Units (TPUs) can help, mapping complex cryptographic kernels onto such architectures remains a challenge. Efficient execution requires co-optimization between the systolic arra…
Read original ↗https://arxiv.org/abs/2605.14718arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Capacitive Touchscreens at Risk: A Practical Side-Channel Attack on Smartphones via Electromagnetic Emanations arXiv:2605.14633v1 Announce Type: new Abstract: Capacitive touchscreens in modern smartphones introduce severe side-channel vulnerabilities. However, existing attacks often require restrictive conditions or invasive measurements. This paper presents TESLA, a novel, contactless electromagnetic (EM) side-channel attack that exploits inherent EM emanations during touch…
Read original ↗https://arxiv.org/abs/2605.14633arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
One Step to the Side: Why Defenses Against Malicious Finetuning Fail Under Adaptive Adversaries arXiv:2605.14605v1 Announce Type: new Abstract: Model providers increasingly release open weights or allow users to fine-tune foundation models through APIs. Although these models are safety-aligned before release, their safeguards can often be removed by fine-tuning on harmful data. Recent defenses aim to make models robust to such malicious fine-tuning, but they are largely eval…
Read original ↗https://arxiv.org/abs/2605.14605