REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2218 reports · page 25 of 56
arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Probabilistic Agents in Deterministic Audits: Evaluating Multi-Agent Systems for Automated Audits Based on the German IT-Grundschutz arXiv:2606.25622v1 Announce Type: new Abstract: The NIS-2 Directive mandates robust Risk Management from thousands of small and medium enterprises. To ensure compliance, companies rely on established standards such as the German IT-Grundschutz (IT-GS) of the Federal Office for Information Security. However, IT-GS certification is resource-inten…
Read original ↗https://arxiv.org/abs/2606.25622arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Taxonomy of Risks on Automated Fact-Checking Systems Considering its Propagation arXiv:2606.25645v1 Announce Type: new Abstract: In recent years, the posting of fake news including disinformation and misinformation on social networking services (SNS) has become a social problem. To combat this fake news, fact-checking that is the process of assessing the veracity of posts on SNS has become increasingly important. While fact-checking is currently performed by fact-checking or…
arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Speculative Decoding at Temperature Zero: A Scoped Safety-Invariance Screen with a 48,072-Sample Expansion arXiv:2606.25097v1 Announce Type: cross Abstract: Speculative decoding accelerates inference by letting a draft model propose tokens for a target model to verify, raising a concrete safety question: at temperature zero, can draft-side behavior leak into safety-scored outputs? We answer with Typical-Acceptance Invariance Screen (TAIS), a behavioral-equivalence screen tha…
Read original ↗https://arxiv.org/abs/2606.25097arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Tracing Target Answers in Poisoned Retrieval Corpora via Token Influence Attribution arXiv:2606.25721v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to corpus poisoning attacks that manipulate model outputs through malicious retrieved documents. Existing detection methods typically rely on auxiliary classifiers or additional LLM-based verification, introducing substantial computational overhead. We present TRACE, a lightweight dete…
Read original ↗https://arxiv.org/abs/2606.25721arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Sponsored Group Signature and its Application to Privacy-preserving Guest Access in Smart Environments arXiv:2606.25248v1 Announce Type: new Abstract: Group signatures are privacy preserving signature schemes in which a group member can anonymously sign messages on behalf of the group, while providing accountability, by allowing the signature of a misbehaving group member be ``opened'' and the identity of the signer be revealed. In group signature members are admitted to the…
Read original ↗https://arxiv.org/abs/2606.25248arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Certification of Machine Learning Models via Directional Sharpness arXiv:2606.25004v1 Announce Type: cross Abstract: In machine learning, model certification has been identified as an important method for gaining assurance about a model's trustworthiness and quality. A model's quality is largely determined by its ability to generalize, i.e., to perform well on data beyond what it was trained on. It is not possible to certify generalization directly, however, as it depends on…
Read original ↗https://arxiv.org/abs/2606.25004arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Shoot the Honey, Cloak the Player: Towards Zero-Runtime-Overhead Proactive Defense and Detection for Visual Game Cheating arXiv:2606.25734v1 Announce Type: new Abstract: Visual aimbots have emerged as a serious cheating threat in first-person shooter (FPS) games, as they evade existing anti-cheat defenses by operating only on rendered frames rather than game memory. However, existing defenses fail to provide an end-to-end solution: post-hoc behavior detectors cannot protect …
Read original ↗https://arxiv.org/abs/2606.25734arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem arXiv:2606.26028v1 Announce Type: new Abstract: As autonomous AI agents increasingly transact across organizational boundaries, a fundamental trust challenge emerges: how can an agent assess whether an unknown counterpart is trustworthy? The ERC-8004 protocol addresses this challenge with the first permissionless trust layer for AI agent economies, built around three on-chain…
Read original ↗https://arxiv.org/abs/2606.26028arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Privacy Vulnerabilities of Attention Layers in Tabular Foundation Models and Protection of High-Risk Queries arXiv:2606.26021v1 Announce Type: new Abstract: Tabular foundation models are commonly assumed to present limited privacy concerns as they are often pre-trained on large collections of synthetic data. However, these models leverage in-context learning, where sensitive records may be provided directly at inference time as labelled context examples. In this paper, we de…
Read original ↗https://arxiv.org/abs/2606.26021arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
BlowLive: Blow-Based Multi-Factor Biometrics with Liveness Detection and Revocability arXiv:2606.25998v1 Announce Type: new Abstract: Biometric authentication systems are increasingly deployed in security-critical applications, yet existing physiological and behavioral biometrics suffer from fundamental limitations: 1) they are vulnerable to spoofing attacks due to unreliable liveness detection, 2) biometric templates may leak privacy-sensitive information 3) intra-user vari…
Read original ↗https://arxiv.org/abs/2606.25998arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Do (Not) Tell Me About My Insecurities: Assessing the Status Quo of Coordinated Vulnerability Disclosure in Germany Amid New EU Cybersecurity Regulations arXiv:2606.25950v1 Announce Type: new Abstract: In our increasingly interconnected world, good IT security practices are necessary to prevent vulnerabilities and data breaches. Providing security contacts, e.g., via Coordinated Vulnerability Disclosure (CVD) programs or security.txt files, is an important practice for busin…
Read original ↗https://arxiv.org/abs/2606.25950arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
RAS: Measuring LLM Safety Through Refusal Alignment arXiv:2606.25750v1 Announce Type: new Abstract: Safety evaluation of large language models (LLMs) is commonly performed by querying models with unsafe or jailbreak prompts and judging whether their outputs violate a safety policy. Although useful, output-level evaluation is expensive, sensitive to judge choice, and easily tied to fixed question banks. We propose **SafeVec**, a white-box evaluation procedure that measures sa…
Read original ↗https://arxiv.org/abs/2606.25750arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
A Tattered Cloak of Invisibility: Measuring Anonymity Loss in Railgun on Ethereum arXiv:2606.25926v1 Announce Type: new Abstract: From a user's perspective, perhaps the most significant difference between traditional banking services and widely used blockchain-based financial systems is that, in the latter, transactions and, either directly or indirectly, account balances and transaction histories are publicly observable. Therefore, a growing number of cryptographic solution…
Read original ↗https://arxiv.org/abs/2606.25926arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Color Matters: Trigger Color Affects Success in Federated Backdoor Attacks arXiv:2606.25858v1 Announce Type: new Abstract: Federated learning is vulnerable to backdoor attacks in which malicious clients inject poisoned updates while preserving benign-task performance. In this paper, we study a semantics-driven backdoor mechanism in which attackers use natural visual accessories as triggers and manipulate only the trigger color while keeping the attack pipeline fixed. Our fra…
Read original ↗https://arxiv.org/abs/2606.25858lwn_kernel · tlp:amber · 6/25/2026, 12:54:46 AM
[$] LWN.net Weekly Edition for June 25, 2026 Inside this week's LWN.net Weekly Edition: Front : Free-threaded Python; AUR attacks; Fedora 2FA; 7.2 merge window; BPF arenas; BPF coroutines; BPF JIT; RMR and BRMR; OSPM. Briefs : Tor deprecations; GIMP 0.54.1 flatpak; Mastodon 4.6; Systemd v261; Xfce on Wayland; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1078380snyk_blog · tlp:amber · 6/25/2026, 12:00:00 AM
NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context. NVD in the AI Era: Multi-Source Vulnerability Intelligence | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing…
Read original ↗https://snyk.io/blog/nvd-multi-source-vulnerability-intelligencears_security · tlp:amber · 6/24/2026, 9:03:34 PM
One-two punch delivered in global operation disrupts cybercrime "assembly line" "Operation Endgame" simultaneously disrupts two widely used crime tools. International authorities and a raft of private technology companies say they have disrupted a cybercrime “assembly line” that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means. The crux of the operation was the simultaneous targeting of …
Read original ↗https://arstechnica.com/security/2026/06/one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-linemicrosoft_mstic · tlp:amber · 6/24/2026, 6:00:00 PM
CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog . Cloud security is shifting from visibility to context-aware risk reduction, helping security teams…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/24/cnapp-evolution-how-microsoft-aligns-with-leading-cloud-risk-management-platformslwn_kernel · tlp:amber · 6/24/2026, 5:01:53 PM
[$] Fedora: 2FA, or not 2FA, that is the question Compromised accounts are one of the most common ways that attackers can sneak malware into the open-source supply chain. One way to reduce account compromise is for projects to require two-factor authentication (2FA) or multi-factor authentication (MFA), but that is easier said than done. However, Fedora is currently discussing putting 2FA requirements in place soon, following an an alleged account compromise that led to an A…
Read original ↗https://lwn.net/Articles/1078964lwn_kernel · tlp:amber · 6/24/2026, 4:46:52 PM
[$] A helper library for BPF arenas BPF arenas are areas of memory (potentially shared with user space) where programs have free reign to build their own data structures, unburdened by the verifier's bounds checks. Many of those data structures are potentially usable in multiple programs. Emil Tsalapatis brought his work on libarena, a library containing generic utilities for use in BPF arenas, to the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit . Althou…
Read original ↗https://lwn.net/Articles/1078526huggingface_blog · tlp:amber · 6/24/2026, 4:00:13 PM
Accelerating Transformers Fine-Tuning with NVIDIA NeMo AutoModel Accelerating Transformers Fine-Tuning with NVIDIA NeMo AutoModel Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Article…
Read original ↗https://huggingface.co/blog/nvidia/accelerating-fine-tuning-nvidia-nemo-automodellwn_kernel · tlp:amber · 6/24/2026, 2:18:37 PM
[$] Reports from OSPM 2026, day two The Power Management and Scheduling in the Linux Kernel Summit , which still goes by the historical acronym OSPM, was held in Cambridge, UK, in mid-April. As has become traditional, the presenters at that event have since written summaries of their sessions, and this work has kindly been made available to LWN for publication. The second day's sessions covered a wide range of topics, including device frequency scaling, using time-slice dura…
Read original ↗https://lwn.net/Articles/1078696lwn_kernel · tlp:amber · 6/24/2026, 1:13:54 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (corosync, firefox, kernel, kernel-rt, libpq, memcached, postgresql, postgresql16, postgresql:13, postgresql:16, python-urllib3, python3.14-urllib3, redis:6, skopeo, and vim), Debian (beets, gst-plugins-bad1.0, imagemagick, libmatio, python-urllib3, and u-boot), Fedora (chromium, coturn, frr, grout, materialx, perl-Crypt-DSA, and yt-dlp), Mageia (opensc, perl-Archive-Tar, and podofo), Oracle (fence…
Read original ↗https://lwn.net/Articles/1079365snyk_blog · tlp:amber · 6/24/2026, 1:00:00 PM
A Note to Our Customers and Partners A note to our customers and partners about Snyk's AI transformation and organizational changes. A Note to Our Customers and Partners | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Resources Company Pricing Evo New EN Select your language English Deutsch Español Français 日本語 Português Login Free and Team Plan Customers Snyk app.snyk.io Enterprise Plan Customers 🇺🇸 Snyk US - 1 app.snyk.io 🇺🇸 Snyk US - 2…
Read original ↗https://snyk.io/blog/a-note-to-our-customers-and-partnerseset · tlp:amber · 6/24/2026, 12:35:24 PM
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights ESET takes part in Operation Endgame to disrupt Amadey and Stealc Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH A…
Read original ↗https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealcmicrosoft_mstic · tlp:amber · 6/24/2026, 12:30:00 PM
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a technical breakdown of StealC and Amadey. The post StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them appeared first on Microsoft Security Blog . …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-themcisa_alerts · tlp:amber · 6/24/2026, 12:00:00 PM
Using SASE in a Modern TIC 3.0 Solution Using SASE in a Modern TIC 3.0 Solution CISA’s guidance, The Journey to Zero Trust – Using Secure Access Service Edge in a Modern TIC 3.0 Solution , details how the Trusted Internet Connections (TIC) 3.0 initiative is helping agencies modernize the way their users connect to applications, data and services. While federal agencies are the target audience, any organization looking to modernize its perimeter-based architectures, advance z…
Read original ↗https://www.cisa.gov/resources-tools/resources/using-sase-modern-tic-30-solutionmandiant · tlp:amber · 6/24/2026, 11:00:00 AM
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability ( CVE-2026-20245 ) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-managerhuggingface_blog · tlp:amber · 6/24/2026, 12:00:00 AM
Introducing the FFASR Leaderboard: Benchmarking ASR in the Real World Introducing the FFASR Leaderboard: Benchmarking ASR in the Real World Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back …
Read original ↗https://huggingface.co/blog/ffasr-leaderboardars_security · tlp:amber · 6/23/2026, 10:30:57 PM
White House drastically shortens deadline for dropping quantum-vulnerable crypto Order warns of national security risks if post-quantum cryptography isn't adopted in time. The White House is drastically shortening the deadline for government agencies and organizations to adopt new quantum-resistant encryption systems that will withstand attacks that use quantum computers, as the federal government seeks to protect decades’ worth of secrets belonging to militaries, banks, go…
Read original ↗https://arstechnica.com/information-technology/2026/06/executive-order-bumps-up-deadline-to-move-off-quantum-vulnerable-cryptounit42 · tlp:amber · 6/23/2026, 10:00:51 PM
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42 . OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Cente…
Read original ↗https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risksentinelone · tlp:amber · 6/23/2026, 9:59:42 PM
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox DPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath. Executive Summary SentinelLABS has analyzed a Rust macOS implant that embeds a 3.5 KB prompt-injection payload of 38 fabricated “system” messages, built to steer an LLM-assisted triage pipeline into aborting or refusing its analysis. Command-and…
Read original ↗https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandboxkrebs_on_security · tlp:amber · 6/23/2026, 4:12:49 PM
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial. Two men plead…
Read original ↗https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-triallwn_kernel · tlp:amber · 6/23/2026, 3:53:01 PM
[$] KASAN for JIT-compiled BPF code Alexis Lothoré has been working to add support for the kernel's memory-access checker, KASAN , to just-in-time-compiled BPF code. He spoke about that work at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit . KASAN support is needed, he said, to help catch bugs in the BPF just-in-time (JIT) compiler. KASAN is a great tool for catching memory-management problems in the kernel, but only in code that can be monitored by i…
Read original ↗https://lwn.net/Articles/1077740lwn_kernel · tlp:amber · 6/23/2026, 1:56:01 PM
Sunsetting Tor 0.4.8 The Tor Project has announced that it is planning to actively stop supporting Tor 0.4.8 and earlier C Tor versions soon. Usually, we try not to break existing releases, even if they are unsupported, unless we have a pretty good reason. In this case, we have several reasons. [...] The most important reason is this: in 0.4.9, we have made some former fields in our directory data obsolete -- specifically, TAP onion keys and family lines . Removing these fie…
Read original ↗https://lwn.net/Articles/1079119lwn_kernel · tlp:amber · 6/23/2026, 1:09:28 PM
Security updates for Tuesday Security updates have been issued by Debian (ffmpeg), Fedora (erlang, ffmpeg, prometheus, python-scrapy, python3-docs, python3.14, thorvg, tigervnc, and vips), Mageia (mumble and sslh), Oracle (389-ds:1.4, dracut, firefox, hplip, kernel, openssh, postgresql:15, redis:6, and uek-kernel), Red Hat (delve, gvisor-tap-vsock, nginx, nginx:1.24, nginx:1.26, osbuild-composer, podman, rhc, skopeo, and yggdrasil), SUSE (containerized-data-importer, graphit…
Read original ↗https://lwn.net/Articles/1079083huggingface_blog · tlp:amber · 6/23/2026, 12:51:55 PM
Build real agentic apps using CUGA: two dozen working examples on a lightweight harness Build real agentic apps using CUGA: two dozen working examples on a lightweight harness Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints …
Read original ↗https://huggingface.co/blog/ibm-research/cuga-appscisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
Siemens WinCC Certificate Manager View CSAF Summary WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens WinCC Certificate Manager are affected: SIM…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01cisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability These typ…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
Siemens Products using OpenSSL View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-03