REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2217 reports · page 20 of 56
arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Cognitive Firewall: A Proactive, Zero-Trust, Multi-Gate Framework for LLM Safety arXiv:2607.01277v1 Announce Type: new Abstract: Large language models (LLMs) can be induced to produce harmful content through multi turn strategies in which no single user message appears clearly unsafe. Existing runtime safeguards commonly evaluate prompts or responses as isolated messages, which limits their ability to recover ac-cumulated intent, verify asserted authority, or detect harmful …
Read original ↗https://arxiv.org/abs/2607.01277arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Embedding Inference Attack arXiv:2607.01276v1 Announce Type: new Abstract: Embedding models are essential components of modern Information Retrieval (IR) systems, yet they are typically hidden behind APIs. Recent works have shown that dense IR system can lead to security vulnerabilities such as embedding inversion attacks. However, such attacks usually require that the attacker knows the embedding model for the attack to be applicable. In this paper, we study IR systems unde…
Read original ↗arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
AgentFlow: Building Agent Dependency Graphs for Static Analysis of Agent Programs arXiv:2607.01640v1 Announce Type: cross Abstract: LLM agents are increasingly developed as source-code applications built on agent frameworks. These agent programs combine conventional host-language code with framework-defined semantics for models, prompts, tools, memory, and multi-agent orchestration logic. As a result, their behavior depends not only on traditional control and data flows, but…
Read original ↗https://arxiv.org/abs/2607.01640arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Janus: a Playground for User-Involved Agentic Permission Management arXiv:2607.01510v1 Announce Type: cross Abstract: AI agents that autonomously execute tool calls on a user's behalf raise pressing questions about permission management: what role could users play, and what role should they play? Despite many proposed approaches, the user's role in agentic permission management remains under explored. We introduce Janus, a playground system for implementing and evaluating us…
Read original ↗https://arxiv.org/abs/2607.01510arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Black-Box Inference of LLM Architectural Properties with Restrictive API Access arXiv:2607.01313v1 Announce Type: cross Abstract: In practice, most commercial LLM providers do not publicly release details of underlying LLM architectures. However, prior work has shown that given limited API access to an LLM (namely, top-$k$ logits and/or a logit bias function), one can recover certain architectural details of an LLM, such as the hidden dimension of the feed-forward network. P…
Read original ↗https://arxiv.org/abs/2607.01313arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Pmeta-TLA: Backdoor Attacks for Speech Classification Models via Meta-Learning with Timbre Leakage Attack arXiv:2607.01702v1 Announce Type: new Abstract: Recently, speech classification methods have gained widespread adoption in intelligent gadgets. Current study indicates that backdoor attacks provide a substantial security concern to these models, underscoring the pressing necessity to investigate additional potential attack techniques to expose and prevent such risks. Thi…
Read original ↗https://arxiv.org/abs/2607.01702arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Unveiling the Non-Monotonic Effect of Privacy on Generalization under Byzantine Robustness arXiv:2607.01492v1 Announce Type: cross Abstract: Recent work has established a fundamental trilemma between Byzantine robustness, local differential privacy (LDP), and optimization error in distributed learning. We show that this trilemma does not universally extend to generalization error, but instead depends critically on the privacy regime. Specifically, in the high-noise regime (s…
Read original ↗https://arxiv.org/abs/2607.01492arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Has This Checkpoint Been Abliterated? A Two-Signal Audit and Its Failure Map arXiv:2607.01854v1 Announce Type: new Abstract: Can a platform tell, before deployment, whether an open-weight checkpoint has had its refusal mechanism stripped? Runtime guards cannot: they score generations, not the artifact. We combine two cheap internal signals, a reference-anchored activation refusal-gap and a weight-recovery energy of the base-to-candidate weight difference, into a threshold-fr…
Read original ↗https://arxiv.org/abs/2607.01854arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Behind the Refusal: Determining Guardrail Activation via Behavioral Monitoring arXiv:2607.02121v1 Announce Type: new Abstract: As Large Language Models (LLMs) and agentic systems become integrated into real-world applications, ensuring their safety and security is critical. Guardrail systems that detect and block malicious instructions sent to and from an LLM are an essential component of AI security. However, researchers conducting black-box adversarial emulation against pr…
Read original ↗https://arxiv.org/abs/2607.02121arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware arXiv:2607.02357v1 Announce Type: new Abstract: LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-…
Read original ↗https://arxiv.org/abs/2607.02357arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors arXiv:2607.02451v1 Announce Type: new Abstract: Cybersecurity incident response has emerged as a critical area of interest for both researchers and practitioners. The corpus of literature on cybersecurity incident response is expanding, yet a unified framework for systematically organizing the accumulated knowledge remains absent. The aspects of incident response span multiple domains, including technology…
Read original ↗https://arxiv.org/abs/2607.02451unit42 · tlp:amber · 7/2/2026, 10:00:39 PM
How We Added WebAuthn to a Browser-Based RDP Client A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42 . How We Added WebAuthn to a Browser-Based RDP Client Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General How We Added WebAuthn to a Browser-Based RDP C…
Read original ↗https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdplwn_kernel · tlp:amber · 7/2/2026, 8:58:45 PM
CalyxOS is back In August 2025, the CalyxOS privacy-focused Android distribution announced that it was pausing all releases while it reworked its release process, security protocols, and changed its signing keys following the departure of one of its founders. The project has now announced that it is " officially back from the hiatus " with the 7.2.2.0 release. CalyxOS 7.2.2.0 is signed by us using a new HSM-based, open-source signing solution we designed to enhance the secur…
Read original ↗https://lwn.net/Articles/1081038ars_security · tlp:amber · 7/2/2026, 7:38:57 PM
Newly discovered PamStealer isn't your typical macOS malware The discovery underscores the increased effort being poured into Mac infostealers. Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code. The malware is delivered in two stages. The first is distributed in a disk image that masquerades as Maccy , a clipboard manager for Macs. It’s compile…
Read original ↗https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthykrebs_on_security · tlp:amber · 7/2/2026, 7:27:33 PM
FBI Seizes NetNut Proxy Platform, Popa Botnet The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two …
Read original ↗https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnettalos · tlp:amber · 7/2/2026, 6:00:34 PM
Catan and Mouse What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill. Welcome to this week’s edition of the Threat Source newsletter.   “I do not know everything; still many things I understand.” ― Madeleine L'Engle, A Wrinkle in Time  “Don't try to comprehend with y…
Read original ↗https://blog.talosintelligence.com/catan-and-mouselwn_kernel · tlp:amber · 7/2/2026, 4:39:26 PM
Kernel archive /pub tree restoring A few astute observers have noticed that some content on kernel.org had disappeared and were understandably concerned. Konstantin Ryabitsev has provided an update via social.kernel.org: There was an unfortunate error while changing the kernel.org primary/secondary mirroring infrastructure, which resulted in the /pub tree suddenly becoming empty. No data was lost, just public mirror copies. Everything is now being restored, but deletes are f…
Read original ↗https://lwn.net/Articles/1081015lwn_kernel · tlp:amber · 7/2/2026, 4:20:33 PM
Spoofed email from LWN We were made aware today of an email sent to a reader that was spoofed to appear to be from LWN. The message claimed, among other things, that we were providing personal information about the reader to another site user. As is explained in our privacy policy we do not, and would not, provide such information. If any other readers have received an odd message from LWN, it is an attempt at a hoax; if in doubt, please check the DKIM header of the email. A…
Read original ↗https://lwn.net/Articles/1081012lwn_kernel · tlp:amber · 7/2/2026, 4:05:34 PM
Fedora Council proposes pausing Community Initiatives Aoife Moloney has, on behalf of the Fedora Council , posted an announcement that the Fedora Council is " proposing we pause the Community Initiatives process as an official project process " because it has decided the current process is ineffective. It is also closing discussion regarding the AI developer desktop initiative covered by LWN in May. The Fedora Objectives/Initiatives framework was never intended as a mandator…
Read original ↗https://lwn.net/Articles/1081013microsoft_mstic · tlp:amber · 7/2/2026, 4:00:00 PM
Improving security posture across the Microsoft partner ecosystem Read how Microsoft strengthens partner ecosystem security with CSP vetting, least privilege access, monitoring, and risk management best practices. The post Improving security posture across the Microsoft partner ecosystem appeared first on Microsoft Security Blog . The Deputy CISO blog series is where Microsoft Deputy Chief Information Security Officers (CISOs) share their thoughts o…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/02/improving-security-posture-across-the-microsoft-partner-ecosystemlwn_kernel · tlp:amber · 7/2/2026, 2:06:08 PM
[$] Two LLM-assisted memory-management patch sets The kernel community (like many other free-software projects) has recently seen a large influx of patches developed with the assistance of large language models (LLMs). Those patches tend to come from developers who were previously unknown to the community. At the moment, though, the memory-management developers are evaluating two large patch sets, developed with LLM assistance, that were submitted by established and well-res…
Read original ↗https://lwn.net/Articles/1080162mandiant · tlp:amber · 7/2/2026, 2:00:00 PM
Google’s Continued Disruption of Malicious Residential Proxy Networks Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networkslwn_kernel · tlp:amber · 7/2/2026, 1:17:54 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (giflib, kernel, mariadb:10.11, mod_http2, php, rrdtool, ruby, ruby:3.3, and ruby:4.0), Debian (jq and node-lodash), Fedora (caddy, hut, ipp-usb, kernel, opkssh, rclone, thunderbird, and transmission), SUSE (389-ds, 7zip, alsa, amazon-ecs-init, avahi, cadvisor, cosign, cups, dnsdist, docker, dracut, firefox, firewalld, giflib, glib-networking, glycin-loaders, google-cloud-sap-agent, google-guest-age…
Read original ↗https://lwn.net/Articles/1080956sentinelone · tlp:amber · 7/2/2026, 1:00:02 PM
Context Engineering | Compaction & Agent Memory for Automated Malware Analysis Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection. Executive Summary Compaction is a context-management pattern used across agent systems to compress prior context into a denser working state for long-running tasks. SentinelLABS evaluated OpenAI’s native Responses API implementation against our automated mal…
Read original ↗https://www.sentinelone.com/labs/context-engineering-compaction-agent-memory-for-automated-malware-analysiscisa_alerts · tlp:amber · 7/2/2026, 12:00:00 PM
ST Engineering iDirect iQ-Series Terminals View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 9‑Series terminals <=4.5.…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01cisa_alerts · tlp:amber · 7/2/2026, 12:00:00 PM
Gardyn IoT Hub View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affected: Home Firmware Studio Firmware Cloud API <2.12.2026 (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477) CVSS Vendor Equipment Vulnerabilities v3 10 Gardyn Gardyn IoT Hub Use of Hard-coded Credentials, Exposure of Sensitive System Information to an Unauthorized C…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03cisa_alerts · tlp:amber · 7/2/2026, 12:00:00 PM
CubeSpace CW0057 Reaction Wheel View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device. The following versions of CubeSpace CW0057 Reaction Wheel are affected: CW0057 Reaction Wheel CVSS Vendor Equipment Vulnerabilities v3 6.1 CubeSpace CubeSpace CW0057 Reaction Wheel Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Communications Countries/Areas …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02trail_of_bits · tlp:amber · 7/2/2026, 11:00:00 AM
Field reports from Patch the Planet We’re running Patch the Planet , an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon create a firehose of bug reports, and OSS maintainers are already spread thin. Our plan is to point OpenAI’s latest models at real codebases, find the security bug…
Read original ↗https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planetarxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Safe Alone, Unsafe Together: Safeguarding Against Implicit Toxicity When Benign Images Combine arXiv:2607.00576v1 Announce Type: cross Abstract: Multi-image content has become an increasingly prevalent form of visual communication in social media, giving rise to a new safety issue, multi-image implicit toxicity (MIIT), where each image appears benign in isolation, but harmful semantics emerge when the images are interpreted jointly. MIIT is particularly challenging for exist…
Read original ↗https://arxiv.org/abs/2607.00576arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
ES-Fuzz: Adaptive Modeling of MMIO Data Chunks for Firmware Fuzzing arXiv:2403.06281v4 Announce Type: replace Abstract: Fuzzing has been widely used for testing embedded-system firmware in a fully rehosted environment without real peripherals, native system supports, or access to the source code and specifications. Some fuzzers emulate the MMIO behavior of missing peripherals based on the firmware binaries to boost code coverage. They emulate each individual MMIO read in the…
Read original ↗https://arxiv.org/abs/2403.06281arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
No Country for Old Privacy: The Evolving Challenges of Anonymity in Bitcoin arXiv:2607.00772v1 Announce Type: new Abstract: We present a longitudinal measurement study on the adoption of detectable, second-generation anonymisation protocols in the Bitcoin network, including CoinJoin, CoinSwap, CoinShuffle and Stealth Addresses. By implementing and refining a suite of heuristic filters, we identify over 5.94 million CoinJoin and 23.3 million CoinSwap transactions. Besides, th…
Read original ↗https://arxiv.org/abs/2607.00772arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Cross-Domain Generalization Failure in Lightweight Intrusion Detection Models for IIoT Networks arXiv:2607.00553v1 Announce Type: new Abstract: Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment. Most reported results evaluate these models only within their training network, leaving behavior on unseen networks unverified. This …
Read original ↗https://arxiv.org/abs/2607.00553arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
The Rise and Fall of Google's Privacy Sandbox arXiv:2607.00693v1 Announce Type: new Abstract: On October 17th, 2025, Google announced the retirement of most Privacy Sandbox APIs, concluding nearly five years of experimentation with its alternative to privacy-invasive data collection on the Web. Designed to balance privacy with advertising functionality and cross-site tracking, the initiative faced repeated redesigns and limited ecosystem support. In this work, we present the…
Read original ↗https://arxiv.org/abs/2607.00693arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Know Thy Neighbor: Cross-TEE Mutual Attestation arXiv:2607.00695v1 Announce Type: new Abstract: Cloud services are composed of multiple heterogeneous distributed components and instances that communicate with one another. This occurs both in applications and services running in traditional execution environments and in trusted applications (TAs) running in trusted execution environments (TEEs). TA instances use attestation before exchanging information to ensure all parties …
Read original ↗https://arxiv.org/abs/2607.00695arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Forensic-Oriented Intrusion Detection Using Synthetic Network Traffic Data and Explainable Artificial Intelligence arXiv:2607.00763v1 Announce Type: new Abstract: Digital forensic investigations of network intrusions require analytical outputs that are traceable, reproducible, and court-defensible - requirements existing machine learning pipelines do not satisfy, since they treat original evidence as training data and produce opaque classifications without instance-level jus…
Read original ↗https://arxiv.org/abs/2607.00763arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
A Non-Line-of-Sight, Multi-Modality-based Side-Channel IP Theft Attack on Additive Manufacturing Using Dual Smartphones arXiv:2607.00186v1 Announce Type: new Abstract: Additive Manufacturing (AM) has revolutionized major sectors, including aerospace, automotive, and healthcare, by enabling adjustable production. As the usage of AM increases, so does the risk of Intellectual Property (IP) leakage during the printing process due to unintended side-channel emissions. Current st…
Read original ↗https://arxiv.org/abs/2607.00186arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
The Binary Tree Mechanism is Optimal for Approximate Differentially Private Continual Counting arXiv:2607.00876v1 Announce Type: cross Abstract: Private continual counting is a fundamental problem in differential privacy: given a binary stream of length $n$, where each $1$ corresponds to the contribution of one individual, the goal is to release all running counts while protecting the privacy of each individual. The standard algorithm is the binary tree mechanism, whose Gaus…
Read original ↗https://arxiv.org/abs/2607.00876arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Minos: A Multi-Agent Collaborative Framework for Provenance-Based Backward Tracking arXiv:2607.00440v1 Announce Type: new Abstract: Sophisticated cyber attacks, particularly Advanced Persistent Threats (APTs), require effective post-intrusion forensic analysis. Provenance-based backward tracking reconstructs attack scenarios by tracing causality from security alerts, but existing methods rely on low-level statistical features and rigid traversal strategies, limiting their ab…
Read original ↗https://arxiv.org/abs/2607.00440arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Antaeus: Hunting Repository-Level Logic Vulnerabilities via Context-Grounded LLM Reasoning arXiv:2607.01138v1 Announce Type: new Abstract: LLM-based vulnerability detectors have shown promising results in identifying memory-safety bugs and vulnerability classes whose violations can often be expressed through established security properties. Logic vulnerabilities, however, pose a different challenge, as their identification requires inferring application-specific security inv…
Read original ↗https://arxiv.org/abs/2607.01138arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems arXiv:2607.00422v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to poisoning attacks that inject malicious documents into the retrieval process to manipulate model outputs. Recent Agentic RAG systems are more robust to such attacks because they iteratively perform retrieval and reasoning, allowing them to ignore weakly relevant p…
Read original ↗https://arxiv.org/abs/2607.00422