REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2218 reports · page 26 of 56
cisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
Hubbell Aclara Metrum Cellular Web Interface View CSAF Summary Successful exploitation of this vulnerability could allow attackers to manipulate critical device settings and repeatedly disrupt operations, potentially causing a loss of communications to the device. The following versions of Hubbell Aclara Metrum Cellular Web Interface are affected: Aclara Metrum Cellular Web Interface CVSS Vendor Equipment Vulnerabilities v3 7.5 Hubbell Hubbell Aclara Metrum Cellular Web Inte…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07cisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
ABB Freelance Security Lock View CSAF Summary Successful exploitation of this vulnerability could allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permissions. The following versions of ABB Freelance Security Lock are affected: ABB System Version (<=Freelance 2013) installed with ABB Freelance Security Lock(All versions) vers:all/* ABB System Version (Freelance 2013 SP1) installed with ABB F…
cisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
Impact of Linux Kernel vulnerabilities on B&R products View CSAF Summary B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advi…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06cisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
Siemens SIPROTEC 5 Using DIGSI5 Protocol View CSAF Summary SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, users of the CP050 and CP150 device models are advised to upgrade to version 9.90 or later. For CP300 device models, devices 7ST85 and 7ST86 are advised to upgrad…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02cisa_alerts · tlp:amber · 6/23/2026, 12:00:00 PM
Siemens SINEC INS View CSAF Summary SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version. The following versions of Siemens SINEC INS are affected: SINEC INS vers:intdot/<1.0.2.6 CVSS Vendor Equipment Vulnerabilities v3 8.8 Siemens Siemens SINEC INS Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Path Trav…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04snyk_blog · tlp:amber · 6/23/2026, 5:00:00 AM
When a vendor's breach becomes yours: lessons from the Klue incident A forgotten credential at vendor Klue let attackers reach customers' Salesforce data. How modern SaaS breaches cascade, and the keys you should audit. When a vendor's breach becomes yours: lessons from the Klue incident | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven …
Read original ↗https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incidentchainalysis · tlp:amber · 6/23/2026, 12:27:35 AM
OFAC Sanctions ISIS Operators for Financing Terror Group with Crypto Summary OFAC designated three individuals and six entities across Europe, the Middle East, and West Africa for facilitating financial transactions… The post OFAC Sanctions ISIS Operators for Financing Terror Group with Crypto appeared first on Chainalysis . OFAC Sanctions ISIS Financial Facilitators Chainalysis Products Crypto Investigations Investigations Solutions Reactor Investigate and trace fund…
Read original ↗https://www.chainalysis.com/blog/ofac-sanctions-isis-financial-facilitators-june-2026trend_micro · tlp:amber · 6/23/2026, 12:00:00 AM
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application infrastructure for their next foothold. From Langflow to Monero: Inside CVE-2026-33017 Cryptominer | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive …
Read original ↗https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.htmlhuggingface_blog · tlp:amber · 6/23/2026, 12:00:00 AM
Shipping huggingface_hub every week with AI, open tools, and a human in the loop Shipping huggingface_hub every week with AI, open tools, and a human in the loop Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Bucket…
Read original ↗https://huggingface.co/blog/huggingface-hub-release-ciunit42 · tlp:amber · 6/22/2026, 10:00:04 PM
The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42 . The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Menu Tools ATOMs Se…
Read original ↗https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-riskslwn_kernel · tlp:amber · 6/22/2026, 8:25:07 PM
GIMP 0.54.1 in a Flatpak The GIMP project reports that GNOME contributor "balooii" has worked to package GIMP 0.54.1—released in 1996—as a Flatpak that will build and run on modern 64-bit Linux systems. This is a Motif -based version, and the same version that was used by Larry Ewing to create Tux. While not likely to be useful for serious graphics work today, it should be interesting for users who would like to see what a 30-year-old version of GIMP was capable …
Read original ↗https://lwn.net/Articles/1078969ars_security · tlp:amber · 6/22/2026, 7:16:52 PM
Following user outcry, AMD reinstates memory encryption in consumer CPUs Critics saw the move as an underhanded way to steer them toward more costly chips. Consumer AMD CPUs will once again offer encryption protections against physical attacks after facing user backlash for silently removing the feature. As Ars reported last week, AMD stripped the protection, known as TSME , from consumer Ryzen processors. Short for Transparent Secure Memory Encryption, TSME encrypts the en…
Read original ↗https://arstechnica.com/security/2026/06/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpusmicrosoft_mstic · tlp:amber · 6/22/2026, 7:07:28 PM
Guarding AI memory What happens when threat actors target what AI remembers? Microsoft breaks down the risks and the defenses. The post Guarding AI memory appeared first on Microsoft Security Blog . In this article What AI memory is (and why it matters) What is an agent memory attack? How Microsoft approaches memory security in Microsoft 365 A guiding framework for building safe AI memory Key takeaways Learn more AI memory transforms an AI system from a stateless tool into …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/22/guarding-ai-memorytrail_of_bits · tlp:amber · 6/22/2026, 4:50:00 PM
Introducing Patch the Planet What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we can report that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects (with many more still undergoing coor…
Read original ↗https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planetcheckpoint_research · tlp:amber · 6/22/2026, 4:00:02 PM
22nd June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for […] The post 22nd June – Threat Intelligence …
Read original ↗https://research.checkpoint.com/2026/22nd-june-threat-intelligence-reportmicrosoft_mstic · tlp:amber · 6/22/2026, 4:00:00 PM
One intrusion, two cyberattackers: Uncovering parallel threat activity Ransomware case reveals two parallel threat actors, blending tactics and evasion—showing why isolated signals can often miss modern, overlapping cyberattacks. The post One intrusion, two cyberattackers: Uncovering parallel threat activity appeared first on Microsoft Security Blog . What began as a routine ransomware investigation quickly revealed something far more complex. In this ninth cyberattack seri…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/22/one-intrusion-two-cyberattackers-uncovering-parallel-threat-activitylwn_kernel · tlp:amber · 6/22/2026, 3:26:54 PM
[$] Free-threaded Python: past, present, and future Probably the biggest change for Python over the last five years or so is the advent of the "free-threaded" version of the language, which removes the global interpreter lock (GIL) and allows multiple threads to run in parallel in the interpreter. At PyCon US 2026 , held in Long Beach, California in mid-May, longtime CPython core developer (and current steering council member) Thomas Wouters gave a talk about the feature. He…
Read original ↗https://lwn.net/Articles/1078367lwn_kernel · tlp:amber · 6/22/2026, 1:44:52 PM
First preview release of Xfce's Wayland compositor Brian Tarricone has announced the first preview release of xfwl4, a Wayland compositor for the Xfce desktop environment. After close to six months of work, I feel like it's ready to get some wider use, even though of course there will be bugs and missing features. Think of this as an alpha release. [...] The end goal of xfwl4 is to behave as closely as possible to an Xfce desktop running on an X server. Ideally a user could …
Read original ↗https://lwn.net/Articles/1078942lwn_kernel · tlp:amber · 6/22/2026, 1:26:14 PM
[$] Reports from OSPM 2026, day one The Power Management and Scheduling in the Linux Kernel Summit , which still goes by the historical acronym OSPM, was held in Cambridge, UK, in mid-April. As has become traditional, the presenters at that event have since written summaries of their sessions, and this work has kindly been made available to LWN for publication. The first day's sessions covered a wide range of topics, including idle-state selection, user-space schedulers with…
Read original ↗https://lwn.net/Articles/1077759huggingface_blog · tlp:amber · 6/22/2026, 1:18:56 PM
PP-OCRv6 on Hugging Face: 50-Language OCR from 1.5M to 34.5M Parameters PP-OCRv6 on Hugging Face: 50-Language OCR from 1.5M to 34.5M Parameters Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up B…
Read original ↗https://huggingface.co/blog/PaddlePaddle/pp-ocrv6lwn_kernel · tlp:amber · 6/22/2026, 1:06:55 PM
Security updates for Monday Security updates have been issued by AlmaLinux (389-ds:1.4, kernel, and kernel-rt), Debian (gst-libav1.0, gst-plugins-good1.0, imagemagick, kernel, libconfig-inifiles-perl, libgd-perl, libhttp-daemon-perl, mediawiki, pillow, and squid), Fedora (389-ds-base, alertmanager, ansible-core, buildah, chromium, erlang-cowboy, erlang-cowlib, erlang-gun, freerdp, kubernetes1.33, kubernetes1.34, kubernetes1.35, mingw-SDL2_image, ongres-scram, ongres-stringpr…
Read original ↗https://lwn.net/Articles/1078922unit42 · tlp:amber · 6/20/2026, 2:05:33 AM
Threat Brief: Mitigating Large-Scale Credential Attacks We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42 . Threat Brief: Mitigating Large-Scale Credential Attacks Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats General General Th…
Read original ↗https://unit42.paloaltonetworks.com/large-scale-credential-attackslwn_kernel · tlp:amber · 6/19/2026, 6:56:33 PM
Systemd v261 released Systemd v261 has been released with a long list of changes, including a new cloud "Instance Metadata Service" (IMDS) subsystem, "boot secret" functionality for use on systems that lack a physical TPM, as well as support for the kernel's Live Update Orchestration (LUO) / Kexec Handover (KHO) systems when they are present and enabled. See the release notes for the full list of changes. Systemd v261 released [LWN.net] LWN .net News from the source Content…
Read original ↗https://lwn.net/Articles/1078708lwn_kernel · tlp:amber · 6/19/2026, 3:55:23 PM
[$] Suspending and resuming BPF programs BPF programs can be used to extend many aspects the Linux kernel, but BPF programs must run to completion in the same context that they began. Kumar Kartikeya Dwivedi is working on changing that by allowing BPF programs to be expressed as coroutines. He spoke about his work at the 2026 Linux Storage, Filesystem, Memory-Management and BPF Summit . While still experimental, the change promises to make long-running BPF tasks significantl…
Read original ↗https://lwn.net/Articles/1076210lwn_kernel · tlp:amber · 6/19/2026, 2:40:59 PM
[$] AURpocalypse now: a look at the recent AUR attacks The Arch User Repository (AUR) has been subjected to a sustained attack recently. The attacker, or attackers, have spun up a series of new accounts then used them to adopt orphaned packages and push malicious updates that would install malware on users' systems. It is unclear how many users were compromised in the attack, but the maintainers were playing Whac-A-Mole for several days to respond to each newly compromised p…
Read original ↗https://lwn.net/Articles/1077619lwn_kernel · tlp:amber · 6/19/2026, 1:24:01 PM
Security updates for Friday Security updates have been issued by AlmaLinux (dracut), Debian (chromium, firefox-esr, and thunderbird), Fedora (chromium, firefox, nss, ocserv, ongres-scram, ongres-stringprep, perl-Archive-Tar, perl-GD, perl-HTTP-Daemon, perl-Net-Statsd, restic, singularity-ce, util-linux, and vorbis-tools), Mageia (gstreamer1.0-*, libupnp, luajit, opensc, and ruby-rack), SUSE (curl, dnsmasq, ffmpeg-4, frr, google-osconfig-agent, java-1_8_0-ibm, kernel, krb5, k…
Read original ↗https://lwn.net/Articles/1078662lwn_kernel · tlp:amber · 6/19/2026, 12:34:38 PM
Eight new stable kernels for Friday Greg Kroah-Hartman has announced the release of the 7.1.1 , 7.0.13 , 6.18.36 , 6.12.94 , 6.6.143 , 6.1.176 , 5.15.210 , and 5.10.259 stable kernels. As usual, each contains important fixes. Users are advised to upgrade. Eight new stable kernels for Friday [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe…
Read original ↗https://lwn.net/Articles/1078590arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Low-Cost Multi-Precision Systolic Arrays for Accelerating FHE NTTs on AI ASICs arXiv:2606.19866v1 Announce Type: new Abstract: Fully Homomorphic Encryption (FHE) ensures robust data privacy but suffers from prohibitive computational overhead. Accelerating FHE on AI hardware like Tensor Processing Units (TPUs) is promising, yet fundamentally limited by a precision mismatch: TPUs are optimized for 8-bit arithmetic, whereas FHE and its critical parts such as the Number Theoreti…
Read original ↗https://arxiv.org/abs/2606.19866arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
LLM agent safety, multi-turn red-teaming, jailbreak benchmarks, adversarial robustness, safety-critical systems arXiv:2606.20408v1 Announce Type: new Abstract: Large language model (LLM) agents are increasingly proposed as supervisory components for safety-critical systems, yet their robustness under sustained, adaptive adversarial pressure remains poorly characterized. We present NRT-Bench, a benchmark for multi-turn red-teaming of LLM agents acting as operators of a safety…
Read original ↗https://arxiv.org/abs/2606.20408arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Heterogeneous LLM Debate Under Adversarial Peers: Honest Gains, Replacement Costs, and Resilience arXiv:2606.19826v1 Announce Type: new Abstract: Heterogeneous LLM debate is motivated by the promise that diverse peers correct one another, but the same exchange that carries correction also carries adversarial influence. We measure which dominates by tracking how a heterogeneous peer changes the honest agents' revision behavior: how often they change their answer, and whether …
Read original ↗https://arxiv.org/abs/2606.19826arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Efficient and Sound Probabilistic Verification for AI Agents arXiv:2606.20510v1 Announce Type: new Abstract: Securing AI agents that operate in complex digital environments has become a critical need, and runtime monitoring approaches that formulate and enforce policies expressed in a formal language like Datalog offer a promising solution. However, existing approaches are restricted to deterministic policies. In many practical applications of AI agents, there is a need to e…
Read original ↗https://arxiv.org/abs/2606.20510arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Analyzing Defensive Misdirection Against Model-Guided Automated Attacks on Agentic AI Systems arXiv:2606.20470v1 Announce Type: new Abstract: Agentic AI systems increasingly rely on language-model components to interpret instructions, process external data, invoke tools, and coordinate with other agents. These capabilities make prompt-injection and jailbreak attacks more consequential, especially as attackers adopt model-guided automation to scale probing, prompt refinement,…
Read original ↗https://arxiv.org/abs/2606.20470arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
DISARM: Target Electronic Device Informed Mitigation of Software Runtime Side-Channel Vulnerabilities arXiv:2606.19807v1 Announce Type: new Abstract: Program runtime or timing attacks exploit variations in a program's execution times to extract sensitive information from the program (e.g. encryption keys, sensitive variable data, intellectual property). State-of-the-art solutions to runtime side-channel attacks attempt to balance the execution time of the sensitive code for …
Read original ↗https://arxiv.org/abs/2606.19807arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
SafeSpec: Fast and Safe LLM via Dynamic Reflective Sampling arXiv:2606.19755v1 Announce Type: new Abstract: Speculative inference accelerates large language model (LLM) decoding but provides no inherent safety guarantees. Existing safety defenses are largely incompatible with speculative inference: they either introduce additional computation or disrupt the draft-verify mechanism, negating acceleration benefits. This reveals a fundamental incompatibility between current safe…
Read original ↗https://arxiv.org/abs/2606.19755arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
When Global Gating Is Enough: Admission-Time Hubness Control in Anisotropic Vector Retrieval Systems arXiv:2606.19692v1 Announce Type: new Abstract: Vector hubness, where a few points become nearest neighbors of many queries, creates a poisoning risk in retrieval-augmented generation (RAG): one injected document can influence unrelated requests. Existing defenses use periodic reverse-kNN scans, leaving an exposure window and repeated corpus-wide work. We study admission-time…
Read original ↗https://arxiv.org/abs/2606.19692arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Calibration Without Comprehension: Diagnosing the Limits of Fine-Tuning LLMs for Vulnerability Detection in Systems Software arXiv:2606.20502v1 Announce Type: new Abstract: Whether LLMs scoring well on vulnerability benchmarks genuinely reason about security or merely pattern-match on contaminated data remains unresolved. We present CWE-Trace, a framework for LLM vulnerability detection built from 834 manually curated Linux kernel samples spanning 74 CWEs. The framework enfo…
Read original ↗https://arxiv.org/abs/2606.20502arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots arXiv:2606.19660v1 Announce Type: new Abstract: Prompt injection is ranked as the most critical vulnerability in large language model (LLM) deployments by the OWASP Top 10 for LLM Applications, yet existing defenses operate at isolated pipeline stages and remain incomplete. Input filters cannot inspect retrieved documents, while output monitors cannot prevent malicious payloads from reaching the mode…
Read original ↗https://arxiv.org/abs/2606.19660arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
FFinRED: An Expert-Guided Benchmark Generation and Evaluation Framework for Financial LLM Red-Teaming arXiv:2606.19887v1 Announce Type: new Abstract: Existing safety benchmarks target general adversarial scenarios but miss finance-specific risks. Financial LLMs face regulatory compliance violations, fraud facilitation, and systemic trust erosion that require targeted evaluation. We introduce FinRED, an expert-guided red-teaming framework for financial LLM safety evaluation d…
Read original ↗https://arxiv.org/abs/2606.19887arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
TrustMix: How to Mix Messages in a Mobile Ad-hoc Network arXiv:2606.20251v1 Announce Type: new Abstract: Mix networks are a highly effective way to achieve anonymity, defending against a wide range of traffic-analysis attacks. However, mix networks are usually designed for infrastructure networks and cannot be directly applied in the context of mobile ad hoc networks (MANETs). The few existing solutions for MANETs require advance knowledge of the topology or a trusted centra…
Read original ↗https://arxiv.org/abs/2606.20251arxiv_cs_cr · tlp:amber · 6/19/2026, 4:00:00 AM
Accelerating Trust Convergence in IIoT: A ML Approach for Dynamic Network Conditions arXiv:2606.20214v1 Announce Type: new Abstract: In Industrial Internet of Things (IIoT) environments, trust management plays a vital role in securing systems, especially when dealing with resource-constrained devices. Traditional trust models often overlook the impact of fluctuating network quality, leading to slower trust convergence and inaccurate assessments. In this paper, we propose a d…
Read original ↗https://arxiv.org/abs/2606.20214