REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2217 reports · page 22 of 56
cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
XZ Utils vulnerability impacting B&R Products View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or corrupt memory data. The following versions of XZ Utils vulnerability impacting B&R Products are affected: PPC3100 <1.8.1, 1.8.1 (CVE-2025-31115) C50 <1.8.0, 1.8.0 (CVE-2025-31115) C80 <1.8.0, 1.8.0…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-05cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
Delta Electronics DVP12SE PLC View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely issue commands, modify operational values, interfere with control logic, and alter device behavior without authentication or privilege enforcement. The following versions of Delta Electronics DVP12SE PLC are affected: DVP12SE PLC vers:all/* (CVE-2026-12819, CVE-2026-12818) CVSS Vendor Equipment Vulnerabilities v3 9.8 Delta Electronics Delta Ele…
cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
Schneider Electric EasyLogic T150 and Saitel DP RTU View CSAF Summary Successful exploitation of these vulnerabilities can allow an attacker to cause unauthorized access and exposure of sensitive information when the unauthenticated attacker accesses credentials stored within firmware or system files. The following versions of Schneider Electric EasyLogic T150 and Saitel DP RTU are affected: EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller <=11.06…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-04cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
Frangoteam FUXA SCADA/HMI View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to enumerate all user accounts and role assignments on a FUXA SCADA/HMI instance. The following versions of Frangoteam FUXA SCADA/HMI are affected: FUXA SCADA/HMI <=1.3.1 (CVE-2026-13207) CVSS Vendor Equipment Vulnerabilities v3 7.5 Frangoteam Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing Background Critical Infrastructure …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-02cisa_alerts · tlp:amber · 6/30/2026, 12:00:00 PM
Schneider Electric EcoStruxure IT Data Center Expert View CSAF Summary Schneider Electric is aware of a vulnerability in its EcoStruxure™ IT Data Center Expert. The EcoStruxure™ IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment. Failure to apply the remediation provided below may risk information disclosure. The following versions of Schneider Elect…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-03trail_of_bits · tlp:amber · 6/30/2026, 11:00:00 AM
Shipping post-quantum cryptography to Python Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography . On June 22, 2026, the White House ordered the U.S. government to accelerate its transition to post-quantum cryptography. The order says l…
Read original ↗https://blog.trailofbits.com/2026/06/30/shipping-post-quantum-cryptography-to-pythonhuggingface_blog · tlp:amber · 6/30/2026, 12:00:00 AM
Featuring Every Eval Ever Results on Hugging Face Model Pages Featuring Every Eval Ever Results on Hugging Face Model Pages Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:h…
Read original ↗https://huggingface.co/blog/eee-community-evalsars_security · tlp:amber · 6/29/2026, 10:05:33 PM
US offers $10 million for info on group behind Signal and WhatsApp hacking spree Operation by two Russia-state groups has been ongoing since at least March. Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees. The operation has been active since at l…
Read original ↗https://arstechnica.com/information-technology/2026/06/us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spreelwn_kernel · tlp:amber · 6/29/2026, 8:22:59 PM
Git 2.55.0 released Git maintainer Junio Hamano has announced Git 2.55.0, which has non-merge commits from 100 people; 33 of those are first-time contributors to the project. LWN recently covered some of the noteworthy changes in 2.55, including new features for the experimental " git history " command, addition of the Git fsmonitor daemon for Linux systems, and more. Git 2.55.0 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Ker…
Read original ↗https://lwn.net/Articles/1080188huggingface_blog · tlp:amber · 6/29/2026, 6:02:48 PM
DiScoFormer: One transformer for density and score, across distributions DiScoFormer: One transformer for density and score, across distributions Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up…
Read original ↗https://huggingface.co/blog/allenai/discoformermicrosoft_mstic · tlp:amber · 6/29/2026, 4:27:46 PM
Chromium extension uses AI‑related branding to redirect browser search A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure. The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft Security Blog . In this article Extension overview Key indicators of malicious behavior Dynamic analysis findings Mitigation a…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-searchlwn_kernel · tlp:amber · 6/29/2026, 3:50:33 PM
[$] The rest of the 7.2 merge window Linus Torvalds released 7.2-rc1 and closed the 7.2 merge window on June 28; by that time, 13,412 non-merge commits had found their way into the mainline. That makes this the busiest merge window since the 6.7 development cycle in 2024 (15,418 commits, including 2,800 for the entire bcachefs development history). Just under half of those commits arrived after LWN's summary of the first half of the merge window was written. As usual, t…
Read original ↗https://lwn.net/Articles/1078539lwn_kernel · tlp:amber · 6/29/2026, 3:13:09 PM
[$] Xsnow "protestware" in Debian The xsnow application, which generates an animated snowfall effect (and other pleasant diversions) for X11 desktops, does not seem like an obvious channel for political statements. Nevertheless, xsnow's maintainer seems to have included a political protest in the program: an Easter egg that is triggered when the program's language is set to Russia ("ru"). One user has complained that this functionality should be removed from the Debian xsnow…
Read original ↗https://lwn.net/Articles/1079385lwn_kernel · tlp:amber · 6/29/2026, 3:01:17 PM
Open source maintainership in the age of AI (Kubernetes blog) The Kubernetes project has published a blog post explaining its AI policy : The main problem is that AI has made generating code fast but there has been very little improvement in maintaining code bases. In this post, we will highlight the ways the Kubernetes community is adapting to the world of AI assisted coding. The first step of this journey was to develop an AI policy. This seems mundane and bureaucratic but…
Read original ↗https://lwn.net/Articles/1080144chainalysis · tlp:amber · 6/29/2026, 3:00:43 PM
An Ontology for Accountability: Defining What Data Quality Means in Blockchain Analytics We built this to be questioned Before I came to blockchain analytics, I spent years in academia studying the formal… The post An Ontology for Accountability: Defining What Data Quality Means in Blockchain Analytics appeared first on Chainalysis . An Ontology for Accountability: Defining What Data Quality Means in Blockchain Analytics - Chainalysis Chainalysis Products Crypto Inves…
Read original ↗https://www.chainalysis.com/blog/ontology-data-quality-blockchain-analyticschainalysis · tlp:amber · 6/29/2026, 3:00:13 PM
10 Questions to Ask Your Blockchain Analytics Provider about Data Quality Blockchain analytics tools provide critical intelligence to compliance teams, regulators, and investigators. These professionals use that intelligence to uncover illicit… The post 10 Questions to Ask Your Blockchain Analytics Provider about Data Quality appeared first on Chainalysis . 10 Questions to Ask Your Blockchain Analytics Provider Chainalysis Products Crypto Investigations Investigations…
Read original ↗https://www.chainalysis.com/blog/10-questions-blockchain-analytics-data-qualitylwn_kernel · tlp:amber · 6/29/2026, 2:50:50 PM
Mageia 10 released Mageia 10 has been released with the 6.18 Linux kernel, DNF 5.4.0, RPM 4.20.1, and an increase in hardware requirements for x86 32-bit systems; users now need a CPU with SSE2 features. See the release notes for a full list of updates, and the errata page for known problems. Mageia 10 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us Us…
Read original ↗https://lwn.net/Articles/1080143checkpoint_research · tlp:amber · 6/29/2026, 2:06:59 PM
29th June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor breach led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent […] The post 29th June – Threat Intel…
Read original ↗https://research.checkpoint.com/2026/29th-june-threat-intelligence-report-2mandiant · tlp:amber · 6/29/2026, 2:00:00 PM
The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to m…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-influence-ecosystemlwn_kernel · tlp:amber · 6/29/2026, 1:16:41 PM
Security updates for Monday Security updates have been issued by AlmaLinux (containernetworking-plugins, golang, kernel, libpng, libpng15, nginx, opencryptoki, perl-IO-Compress, thunderbird, and tigervnc), Debian (chromium, gdcm, incus, libhtml-parser-perl, lxd, openvpn, tor, and xorg-server), Fedora (chromium, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, krita, ldns, libssh2, liferea, lighttpd, mariadb10.11, mariadb11.8, moby-engine, nginx, nginx-mod-br…
Read original ↗https://lwn.net/Articles/1080075cisa_alerts · tlp:amber · 6/29/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48558 SimpleHelp Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk esta…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/29/cisa-adds-one-known-exploited-vulnerability-catalogeset · tlp:amber · 6/29/2026, 8:50:00 AM
Inside the inbox: Why cybercriminals want to break into your email account Your inbox is an identity system all of its own: whoever owns it may own a lot more Inside the inbox: Why cybercriminals want to break into your email account Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScienc…
Read original ↗https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-accountarxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
How Humans, Bots, and Agents Communicate About Vulnerabilities in Pull Requests arXiv:2606.28125v1 Announce Type: cross Abstract: Developers may reference vulnerabilities in pull request discussions through both explicit identifiers, such as CVEs or GHSAs, and implicit security-related language (e.g., "unauthorized access" or "SQL injection"). Prior work has primarily focused on explicit identifiers, potentially overlooking vulnerability discussions that lack formal referenc…
Read original ↗https://arxiv.org/abs/2606.28125arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
A Plug-and-Play Method for Improving Imperceptibility and Capacity in Practical Generative Text Steganography arXiv:2412.19652v5 Announce Type: replace Abstract: Linguistic steganography embeds secret information into seemingly innocuous text to safeguard privacy under surveillance. Generative linguistic steganography leverages the probability distributions of language models (LMs) and applies steganographic algorithms during generation, and has attracted increasing attentio…
Read original ↗https://arxiv.org/abs/2412.19652arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Quantum Multi-Party Threshold Private Set Intersection with Explicit Cardinality Testing arXiv:2606.27996v1 Announce Type: cross Abstract: Threshold private set intersection (TPSI) allows parties to reveal their intersection only when its cardinality reaches a prescribed threshold. Existing quantum TPSI protocols typically rely on a third party (TP) to interpret the final results, which deviates from the cardinality-testing paradigm of TPSI. In this paper, we propose a quant…
Read original ↗https://arxiv.org/abs/2606.27996arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Verifiable and Collusion-Resistant Multi-Party Quantum Private Set Operations arXiv:2606.27994v1 Announce Type: cross Abstract: Threshold private set intersection (TPSI) allows parties to reveal their intersection only when its cardinality reaches a prescribed threshold. Existing quantum TPSI protocols typically rely on a third party (TP) to interpret the final results, which deviates from the cardinality-testing paradigm of TPSI. In this paper, we propose a quantum multipar…
Read original ↗https://arxiv.org/abs/2606.27994arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Transversal Difference Numbers in Finite Abelian Quotients arXiv:2606.27961v1 Announce Type: cross Abstract: Given \(H\leq G\) finite abelian groups, a transversal \(T\subseteq G\) for \(G/H\) has fixed size \(|G/H|\), but its ambient difference support \(D(T)=T-T\) can vary with the embedding of \(H\) in \(G\). We call $ \delta(G,H)=\min_T |D(T)| $ the transversal difference number of the pair \((G,H)\). This invariant is related to finite abelian factorisation, tiling comp…
Read original ↗https://arxiv.org/abs/2606.27961arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
RAMSES: Secure high-performance computing for sensitive data arXiv:2606.27919v1 Announce Type: cross Abstract: Traditionally, the architecture of high-performance computing (HPC) systems is tailored for speed, while highly secure computer systems must sacrifice speed for security. However, a wide range of scientific domains, such as the life sciences, call for a combination of performance and security to allow processing sensitive data at scale. Here, we present RAMSES (Rese…
Read original ↗https://arxiv.org/abs/2606.27919arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
ToE: A Hierarchical and Explainable Claim Verification Framework with Dynamic Multi-source Evidence Retrieval and Aggregation arXiv:2606.27736v1 Announce Type: cross Abstract: The rapid spread of fake news poses increasing threats to information ecosystems, especially as AI-generated misinformation under Generative Engine Optimization (GEO) poisoning allows adversarially crafted content to be systematically surfaced by retrieval systems, contaminating LLM reasoning. In this …
Read original ↗https://arxiv.org/abs/2606.27736arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
What Was That Again? Certified Robustness for Automatic Speech Recognition arXiv:2606.27698v1 Announce Type: cross Abstract: Automatic Speech Recognition systems are notoriously both sensitive to adversarial and benign perturbations. While this has been repeatedly demonstrated using reference datasets, detecting such behaviors in deployed systems is incredibly challenging, due to the absence of oracle knowledge of the true transcription. We demonstrate that employing a certi…
Read original ↗https://arxiv.org/abs/2606.27698arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Halt Fast! Early Stopping for Certified Robustness arXiv:2606.27694v1 Announce Type: cross Abstract: Randomized Smoothing (RS) provides rigorous robustness guarantees for neural networks without architectural constraints, yet its adoption is limited by extreme computational costs. Standard RS requires tens of thousands of model evaluations per input and forces practitioners to commit to fixed sample sizes a priori. In this work, we present a novel meta-learning framework for…
Read original ↗https://arxiv.org/abs/2606.27694arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Productionized Fairness Measurement Under Privacy Constraints arXiv:2606.27558v1 Announce Type: cross Abstract: Fairness measurements in the form of disaggregated evaluations often rely on demographic signals that are legally constrained or culturally sensitive. Race and ethnicity signals are among the more difficult signals to curate and use for this task. This paper presents Privacy-Preserving Probabilistic Race/Ethnicity Estimation (PPRE) as a method for enabling fairness…
Read original ↗https://arxiv.org/abs/2606.27558arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Robust Harmful Features Under Jailbreak Attacks: Mechanistic Evidence from Attention Head Specialization in Large Language Models arXiv:2606.28153v1 Announce Type: new Abstract: Jailbreak attacks bypass LLM safety alignment, yet their mechanisms remain poorly understood. We provide evidence that attacks do not comprehensively eliminate safety features, but instead selectively suppress specific attention heads. We identify two functionally differentiated types: Adversarially …
Read original ↗https://arxiv.org/abs/2606.28153arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
GTI-mSEMP Framework : A Proposed Framework to Stimulate Malware Propagation with Inclusion of Attacker-Defender Strategy arXiv:2606.28079v1 Announce Type: new Abstract: The rapid proliferation of automated, multi-vector malware threats poses a significant risk to heterogeneous, resource constrained cyber-physical networks. Conventional epidemiological models often treat security defenses as static parameters, failing to capture the strategic, asymmetric maneuvers between an …
Read original ↗https://arxiv.org/abs/2606.28079arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
ToolPrivacyBench: Benchmarking Purpose-Bound Privacy in Tool-Using LLM Agents arXiv:2606.28061v1 Announce Type: new Abstract: Large language models (LLMs) have increasingly moved from standalone text generation systems to agents that invoke external tools, access environments, and execute multi-step tasks. However, conventional function-calling benchmarks mainly evaluate task completion and API correctness, while privacy evaluation benchmarks typically focus on final respons…
Read original ↗https://arxiv.org/abs/2606.28061arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots arXiv:2606.28006v1 Announce Type: new Abstract: Cyber deception research has focused on improving honeypot deception capabilities to increase attacker engagement and extend their interactions to collect more and better intelligence. For SSH honeypots, this relies on the assumption that attackers log in, open a shell, and type. We tested whether this still held by deploying eleven SSH honeypots that serve…
Read original ↗https://arxiv.org/abs/2606.28006arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH Deception arXiv:2606.27990v1 Announce Type: new Abstract: LLM-based SSH honeypots can generate believable interactions, but evaluations indicate they remain somewhat identifiable to determined attackers, indicating the need for a better scaffolding. We present a new LLM-based honeypot design that uses a multi-agent, multi-LLM architecture to address the limitations of the previous shelLM LLM honeypot. Our honeypot, …
Read original ↗https://arxiv.org/abs/2606.27990arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
SHARD: cell-keyed residual splitting for alignment-resistant private dense retrieval arXiv:2606.27976v1 Announce Type: new Abstract: Dense embeddings underpin semantic search and RAG, yet a leaked vector store hands much of the underlying text back to whoever holds it. The attacks that make this possible (few-shot alignment, zero-shot inversion, unsupervised cross-space translation) share one weakness: the protected store is a single global geometry that can be aligned to a …
Read original ↗https://arxiv.org/abs/2606.27976arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK arXiv:2606.27966v1 Announce Type: new Abstract: Cyber deception research often assumes that a decoy can be placed wherever there is attacker behavior. This work tests that assumption across MITRE ATT&CK v18.1. We introduce a four-criterion rubric for infrastructure deception and apply it to all 250 ATT&CK techniques. The rubric evaluates whether a defender-controlled decoy can be placed, wheth…
Read original ↗https://arxiv.org/abs/2606.27966arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Agentic AI-Powered Re-Identification: An Emerging, Scalable Threat to Mobility Microdata Privacy arXiv:2606.27936v1 Announce Type: new Abstract: The widespread collection of fine-grained location data by commercial data brokers creates a re-identification risk that is not widely recognised by the public. While prior research has established that mobility traces are highly unique and that individuals can, in principle, be identified from a handful of spatio-temporal points, s…
Read original ↗https://arxiv.org/abs/2606.27936