REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2218 reports · page 24 of 56
arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Fortress and Gatekeeper: Theorizing Transitive Trust in Third-Party Cybersecurity Risk Governance arXiv:2606.26866v1 Announce Type: new Abstract: Third-party vendors, such as analytics platforms, cloud services, identity providers, and software suppliers, are increasingly embedded in digital service delivery. While these arrangements enable scale and specialization, they also move customer data and security-relevant practices into environments that customers rarely see, sele…
Read original ↗https://arxiv.org/abs/2606.26866arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
MIRROR: Novelty-Constrained Memory-Guided MCTS Red-Teaming for Agentic RAG arXiv:2606.26793v1 Announce Type: new Abstract: Multimodal agentic retrieval-augmented generation (RAG) systems expand the attack surface beyond prompt injection to include text poisoning, image injection, direct-query attacks, and orchestrator-level tool manipulation. Existing red-teaming approaches are typically surface-specific and often recycle known attack templates; on text-poisoning benchmarks …
arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Jailbreaking for the Average Jane: Choosing Optimal Jailbreaks via Bandit Algorithms for Automatically Enhanced Queries arXiv:2606.26936v1 Announce Type: new Abstract: With a profusion of jailbreaks for LLMs now widely known, a growing concern is that non-expert malicious actors ("the average Jane") could elicit actionable responses to malicious requests. In this work, we examine whether this concern is justified. A non-expert malicious actor requires two ingredients for a s…
Read original ↗https://arxiv.org/abs/2606.26936arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
TESLA-for-5G: Broadcast Authentication for 5G Networks Using TESLA arXiv:2606.26528v1 Announce Type: new Abstract: 5G base stations broadcast unauthenticated system information (SI) that every user equipment (UE) reads during cell selection. This enables attackers to broadcast forged SI from a fake base station (FBS), deceiving UEs into camping on it. Prior approaches require UEs to authenticate System Information Block 1 (SIB1) using digital signatures. This necessitates co…
Read original ↗https://arxiv.org/abs/2606.26528arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
What Browsers Do in the Shaders: A Measurement Study of WebGPU Privacy arXiv:2606.26412v1 Announce Type: new Abstract: WebGPU lets ordinary web pages run GPU workloads through a validated programming model. Validation protects memory safety, but shared browser, driver, OS, and GPU state can still expose privacy-relevant signals. We present WGPULens, a framework for measuring those signals across controlled scenarios, browser-native co-residency, a participant field study, pu…
Read original ↗https://arxiv.org/abs/2606.26412arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
SpikeTimer: Exploring Active Copyright Protection in Spiking Neural Networks via Temporal Backdoor Regularization arXiv:2606.26841v1 Announce Type: new Abstract: Spiking Neural Networks (SNN) have emerged as a revolutionary paradigm compared to traditional Deep Neural Networks (DNN) in energy-efficient computing, showcasing exceptional capabilities in processing event-driven sensory data for real-time applications like robotics and edge AI systems. However, unlike extensive …
Read original ↗https://arxiv.org/abs/2606.26841huggingface_blog · tlp:amber · 6/26/2026, 12:00:00 AM
Run a vLLM Server on HF Jobs in One Command Run a vLLM Server on HF Jobs in One Command Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> Run a vLLM Server on HF Jobs…
Read original ↗https://huggingface.co/blog/vllm-jobsmicrosoft_mstic · tlp:amber · 6/25/2026, 10:30:29 PM
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node.js implant and evade detection. The post Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access app…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-accessunit42 · tlp:amber · 6/25/2026, 10:00:52 PM
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42 . CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Menu Tools ATOMs Security Consulting About Us Under At…
Read original ↗https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoortalos · tlp:amber · 6/25/2026, 6:00:26 PM
Beyond IOCs: AI-enabled threat intelligence In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports. Welcome to this week’s Threat Source newsletter.  The issue of AI in cybersecurity is often portrayed as a binary choice: either a force multiplier for our adversaries, or a tool bringing professional obsolescence. The reality is more nuanced. While AI certainly brings so…
Read original ↗https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligencelwn_kernel · tlp:amber · 6/25/2026, 5:40:13 PM
[$] A look at MinIO alternatives: Ceph and Garage MinIO is a popular object-storage server that offered compatibility with the Amazon Simple Storage Service (S3) API. In December 2025, the company behind the project (also named MinIO) announced that the project was in maintenance mode and would not accept new changes; it was archived completely in February 2026. MinIO users have been hunting for alternatives since then, but the array of choices can be baffling. While many ot…
Read original ↗https://lwn.net/Articles/1077739lwn_kernel · tlp:amber · 6/25/2026, 4:33:29 PM
Podman 6.0 released Version 6.0.0 of the Podman container-management tool has been released. Notable new features include the ability to set multiple static IP addresses for containers, improvements in network isolation that make Podman more compatible with Docker, changes to the way Quadlet commands function, many new options for many existing podman commands, and a rewrite of Podman's configuration file handling . There are many breaking changes; see the release notes for …
Read original ↗https://lwn.net/Articles/1079600huggingface_blog · tlp:amber · 6/25/2026, 4:11:42 PM
Which tokens does a hybrid model predict better? Which tokens does a hybrid model predict better? Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> Which tokens does …
Read original ↗https://huggingface.co/blog/allenai/hybrid-token-predictionmicrosoft_mstic · tlp:amber · 6/25/2026, 4:00:00 PM
Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms Microsoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories. The post Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms appeared first on Microsoft Security Blog . The endpoint management category is being redefined in real time. Organizations no longer need tools that only …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/25/microsoft-a-leader-in-the-forrester-wave-for-endpoint-management-platformslwn_kernel · tlp:amber · 6/25/2026, 2:02:39 PM
[$] Hardening the kernel with allocation tokens and bootpatch-SLR There is a lot of work going into eliminating exploitable bugs from the kernel and preventing the addition of new ones. Even if this work is maximally successful, though, there is no chance that the kernel will be free of these bugs anytime soon. Thus, there is also ongoing interest in hardening the kernel to make the existing bugs more difficult to exploit. The upcoming 7.2 kernel release will include a chang…
Read original ↗https://lwn.net/Articles/1078699mandiant · tlp:amber · 6/25/2026, 2:00:00 PM
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military or…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gatheringlwn_kernel · tlp:amber · 6/25/2026, 1:13:31 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (libpng, libsolv, libtasn1, libxml2, libxslt, python3.14, tigervnc, and vim), Debian (cloud-init, postgresql-13, and yelp), Mageia (nats-server), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind9.18, cockpit, compat-openssl11, dnsmasq, dovecot, evince, expat, flatpak, freerdp, gimp, golang, grafana, grafana-pcp, httpd, jmc, jq, kernel, libsndfile, libsoup, libtiff, mod_http2, mysql:8.0, nginx, nginx:1.24…
Read original ↗https://lwn.net/Articles/1079551cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
Schneider Electric PowerLogic P7 View CSAF Summary Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical network applications. Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or loss of HMI operability and configuration functionality, which could result in loss of control over system operations and…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
H.VIEW HV-500S6 IP Camera View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device. The following versions of H.VIEW HV-500S6 IP Camera are affected: H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229 CVSS Vendor Equipment Vulnerabilities v3 7.2 H.VIEW H.VIEW HV-500S6 IP Camera Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectio…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
pydicom pynetdicom Library View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths. The following versions of pydicom pynetdicom Library are affected: pynetdicom >=v1.0.0|<v3.0.4 CVSS Vendor Equipment Vulnerabilities v3 9.1 pydicom pydicom pynetdicom Library Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Healthcare…
Read original ↗https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-01cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
EVoke Systems Charging Station Management System View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of EVoke Systems Charging Station Management System are affected: EVoke CSMS vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.4 EVoke Systems EVoke Systems Charging…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
Horner Automation Cscape View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code. The following versions of Horner Automation Cscape are affected: Cscape <10.2_SP3 CVSS Vendor Equipment Vulnerabilities v3 7.8 Horner Automation Horner Automation Cscape Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-03cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose si…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
Yokogawa FAST/TOOLS and CI Server View CSAF Summary Successful exploitation of this vulnerability may return a response containing the CI Server setting information. The following versions of Yokogawa FAST/TOOLS and CI Server are affected: FAST/TOOLS >=R9.01|<=R10.04 Collaborative Information Server (CI Server) >=R1.01|<=R1.04 CVSS Vendor Equipment Vulnerabilities v3 7.5 Yokogawa Yokogawa FAST/TOOLS and CI Server Cleartext Transmission of Sensitive Informat…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
OHIF Viewers DICOM View CSAF Summary Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link. The following versions of OHIF Viewers DICOM are affected: OHIF DICOM Web Viewer Framework <=v3.12.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 Open Health Imaging Foundation (OHIF) OHIF Viewers DICOM Server-Side Request Forgery (SSRF) Background Critical Infrastructure …
Read original ↗https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-02cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
Delta Electronics DTM Soft View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code. The following versions of Delta Electronics DTM Soft are affected: DTMSoft vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 Delta Electronics Delta Electronics DTM Soft Deserialization of Untrusted Data Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarte…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-06cisa_alerts · tlp:amber · 6/25/2026, 12:00:00 PM
Daktronics Controller Firmware View CSAF Summary Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system. The following versions of Daktronics Controller Firmware are affected: VFC-DMP-5000 <v8.117.x.x VFC-DMP-5000 <v9.43.x.x VFC-DMP-5000 <v10.34.x.x DMP-5000 <v10.34.x.x DMP-5000 <v8.117.x.x DMP-5000 <v9.43.x.x DMP-8000 <v10.34.x.x DMP-8000 <v8.117.x.x DMP-8…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04talos · tlp:amber · 6/25/2026, 10:00:26 AM
Introduction to COM usage by Windows threats Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors. Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation&#x…
Read original ↗https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threatseset · tlp:amber · 6/25/2026, 8:45:00 AM
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY…
Read original ↗https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliancesarxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
What Does It Mean to Break a Distillation Defense? arXiv:2606.25059v1 Announce Type: new Abstract: Black-box LLMs (accessible only via API) are vulnerable to distillation attacks, in which an attacker queries the model and trains a student on its outputs. A recent line of work proposes output perturbation defenses that modify the teacher's output to reduce student performance while preserving utility for legitimate users. As a relatively new family of approaches, output pert…
Read original ↗https://arxiv.org/abs/2606.25059arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
General Techniques for Reducing Key-Switching Overhead in Privacy-Preserving Two-Party Transformer Inference arXiv:2606.25349v1 Announce Type: new Abstract: In secure two-party Transformer inference, linear layers are typically evaluated using Fully Homomorphic Encryption (FHE) through plaintext-ciphertext or ciphertext-ciphertext matrix multiplications, where key switching primarily occurs and dominates computational overhead in both FHE-based and hybrid FHE-MPC systems. Ex…
Read original ↗https://arxiv.org/abs/2606.25349arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Representation Matters: An Empirical Study of Program Representations for LLM Vulnerability Reasoning arXiv:2606.25356v1 Announce Type: new Abstract: Large Language Models (LLMs) are increasingly used for automated vulnerability detection, but it remains unclear how program structure and semantics should be represented for LLM-based reasoning. Most prompting-based approaches provide raw source code, implicitly assuming that more source-level context gives the model better ev…
Read original ↗https://arxiv.org/abs/2606.25356arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Decoupling Reconnaissance and Exploitation: Measuring the Capability Boundaries of LLM-Based Web Penetration Testing arXiv:2606.25332v1 Announce Type: new Abstract: Large Language Models (LLMs) have shown promise for automated penetration testing, yet existing end-to-end black-box evaluations are highly susceptible to error cascading: failures in early reconnaissance can mask an agent's actual ability to exploit vulnerabilities. To more accurately characterize these capabili…
Read original ↗https://arxiv.org/abs/2606.25332arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
SoK: AI Secure Code Generation: Progress, Pitfalls, and Paths Forward arXiv:2606.25195v1 Announce Type: new Abstract: The increasing use of AI systems for code generation raises a central security question: what can today's models and coding agents actually do to produce secure code, where do they still fail, and what would move the field forward? Existing work has explored prompting, fine-tuning, reinforcement learning, and agentic workflows for secure code generation, but …
Read original ↗https://arxiv.org/abs/2606.25195arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Security and Privacy in Retrieval-Augmented Generation: Architectures, Threats, Defenses, and Future Directions for Building Trustworthy Systems arXiv:2606.25533v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) has emerged as a dominant paradigm for enhancing large language models with external knowledge. By coupling retrieval mechanisms with generative models, RAG systems improve factual grounding and adaptability across domains. However, integrating retr…
Read original ↗https://arxiv.org/abs/2606.25533arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
CrypFormBench: Benchmarking Formal Analysis Capability of Large Language Models for Cryptographic Schemes arXiv:2606.25561v1 Announce Type: new Abstract: Manual formal analysis of cryptographic schemes is labor-intensive and requires substantial expertise. While model-checking tools (e.g., Scyther and Tamarin) and computational-security tools (e.g., CryptoVerif and EasyCrypt) improve the automation of security proofs, they still rely on experts to abstract schemes and write …
Read original ↗https://arxiv.org/abs/2606.25561arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Unprivileged Topology Certificates for Cloud GPU Attestation arXiv:2606.24934v1 Announce Type: new Abstract: Cloud GPU tenants receive a model name and a region, but cannot directly inspect the physical accelerator that runs their job. We present a software-only attestation primitive for this setting. A CUDA probe measures an SM-by-memory-region latency matrix using physical SM labels and dependent global loads. A streaming reducer commits sufficient statistics, configuratio…
Read original ↗https://arxiv.org/abs/2606.24934arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Homomorphic Encryptions for Privacy Preserving Vision arXiv:2606.25216v1 Announce Type: new Abstract: Legal requirements might prevent organizations from sharing sensitive data like medical or financial details of consumers which prevents them from leveraging cloud based ML-as-a-service solutions provided by third party providers, which are quickly gaining popularity these days. In this project, we aim to perform inference tasks in Computer Vision in a privacy-preserving man…
Read original ↗https://arxiv.org/abs/2606.25216arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
An Approach for a Supporting Multi-LLM System for Automated Certification Based on the German IT-Grundschutz arXiv:2606.25608v1 Announce Type: new Abstract: This paper presents a novel approach to perform semi-automated BSI IT-Grundschutz certification using a MultiLarge Language Model system (MLS) with Hybrid RetrievalAugmented Generation (HybridRAG). Facing the challenges of the Network and Information Security Directive 2 (NIS2) directive, a shortage of specialists, and h…
Read original ↗https://arxiv.org/abs/2606.25608arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Quantum-Resilient Decentralized AI Economies: Proof-of-Useful-Work and Post-Quantum Security arXiv:2606.24942v1 Announce Type: new Abstract: Proof-of-Work blockchains secure consensus through hash puzzles, producing no external value. In this research, we propose a decentralized AI economy where nodes are rewarded for useful machine-learning work, i.e., inference and training, instead of ineffective hashing method. Our proposed three-layer architecture separates compute, val…
Read original ↗https://arxiv.org/abs/2606.24942