REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2218 reports · page 29 of 56
lwn_kernel · tlp:amber · 6/17/2026, 1:26:41 PM
FairScan 2.0 released Version 2.0 of the FairScan document-scanning app for Android has been released. The headline feature for this release is the addition of optical-character-recognition (OCR) support using Tesseract to produce PDFs with searchable text from scans. FairScan developer Pierre-Yves Nicolas has written a detailed blog about adding the feature and explaining why it had not been added previously. That looks nice, so why didn't FairScan have it before? That's be…
Read original ↗https://lwn.net/Articles/1078242lwn_kernel · tlp:amber · 6/17/2026, 1:25:51 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (hplip, kernel, kernel-rt, libpng12, libpng15, libxml2, libxslt, mysql:8.0, mysql:8.4, opencryptoki, openssl, postfix, postgresql:15, rsync, and webkit2gtk3), Debian (asterisk, atril, gsasl, and libreoffice), Fedora (ack, bird, chromium, firefox, ldns, librabbitmq, nextcloud, nss, openslide, perl-Protocol-HTTP2, tig, vorbis-tools, and xen), Mageia (coturn, log4cxx, and python-tornado), SUSE (389-ds…
Read original ↗https://lwn.net/Articles/1078339chainalysis · tlp:amber · 6/17/2026, 11:56:07 AM
Approval Phishing: From Just One Case to Full-Scale Disruption Chain of Thought is our new expert-hosted webinar series, taking you behind the scenes of real investigations, emerging typologies and… The post Approval Phishing: From Just One Case to Full-Scale Disruption appeared first on Chainalysis . What Is Approval Phishing? Detect & Disrupt Crypto Scams at Scale Chainalysis Products Crypto Investigations Investigations Solutions Reactor Investigate and trace f…
Read original ↗https://www.chainalysis.com/blog/what-is-approval-phishingars_security · tlp:amber · 6/17/2026, 11:15:17 AM
Windows and Linux users: The deadline to update Secure Boot keys is near What you need to know about the expiration of keys securing your machine's boot sequence. The clock is ticking for Windows and Linux users to update cryptographic keys that protect their systems against firmware-based UEFI infections, a pernicious form of malware that loads before operating system and anti-malware protections start. Beginning June 24, three certificates that cryptographically verify th…
Read original ↗https://arstechnica.com/security/2026/06/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-nearhuggingface_blog · tlp:amber · 6/17/2026, 10:18:05 AM
From the Hugging Face Hub to robot hardware with Strands Agents and LeRobot From the Hugging Face Hub to robot hardware with Strands Agents and LeRobot Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In S…
Read original ↗https://huggingface.co/blog/amazon/strands-lerobot-hub-to-hardwarehuggingface_blog · tlp:amber · 6/17/2026, 9:01:25 AM
GLM-5.2: Built for Long-Horizon Tasks GLM-5.2: Built for Long-Horizon Tasks Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> GLM-5.2: Built for Long-Horizon Tasks Te…
Read original ↗https://huggingface.co/blog/zai-org/glm-52-blogeset · tlp:amber · 6/17/2026, 8:45:00 AM
Protecting legacy OT systems against modern cyberthreats Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks. Cybersecurity for the long haul: Protecting legacy OT systems Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Th…
Read original ↗https://www.welivesecurity.com/en/critical-infrastructure/protecting-legacy-ot-systems-modern-threatsarxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
An Empirical Analysis of AI Slop in Music Streaming arXiv:2606.18052v1 Announce Type: new Abstract: Generative AI models lower the bar for content creation, making it easy for any user to create professional-looking images, text and music with minimal effort. This has enabled a new cottage industry around creation of "AI slop" mass quantities of mediocre content produced to generate revenue, often through misrepresentation as human-authored content, or scams involving automa…
Read original ↗https://arxiv.org/abs/2606.18052arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
OTRO: Oblivious Tokenization Path with Square-Root ORAM arXiv:2606.17358v1 Announce Type: new Abstract: The CPU-side large language model (LLM) tokenizer is a critical security gap in LLM serving through a confidential computing stack with CPU and GPU trusted execution environments (TEEs). Tokenizers converts the prompts through table-driven lookups, and the resulting memory access patterns are a powerful source of side-channel leakage. Recent work demonstrates end-to-end re…
Read original ↗https://arxiv.org/abs/2606.17358arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
ShellGames: Speculative LLM-Driven SSH Deception arXiv:2606.17986v1 Announce Type: new Abstract: Cyber deception and Moving Target Defense are promising strategies that aim to disrupt adversaries by increasing uncertainty. However, sustaining long-lived, credible interactive sessions with adversaries remains an open challenge. Large Language Models (LLMs) offer a promising path toward more dynamic deception systems, but suffer from key limitations that fundamentally limit th…
Read original ↗https://arxiv.org/abs/2606.17986arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Quantifying quantum risk: a measure of crypto agility arXiv:2606.17116v1 Announce Type: new Abstract: Because of their ability to enable new forms of cryptanalysis, quantum computers pose a threat to the cryptographic algorithms that are widely used to secure contemporary computer systems. A practical quantum computer may emerge within the next ten years or so, but due to theorised "harvest now, decrypt later" style attacker behaviour, mitigations are necessary today. Recent…
Read original ↗https://arxiv.org/abs/2606.17116arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
SoK: AI-Augmented Binary Reversing arXiv:2606.17398v1 Announce Type: new Abstract: Binary reversing is fundamental to software understanding, vulnerability discovery, malware investigation, and firmware auditing. However, it remains inherently challenging due to the irreversible loss of semantic information during compilation. Recent advances in machine learning, large language models (LLMs), and agentic AI systems have accelerated the adoption of AI-augmented binary reversi…
Read original ↗https://arxiv.org/abs/2606.17398arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Children Are Not the Enemy: Child-Fit Security as an Alternative to Bans and Surveillance arXiv:2606.17957v1 Announce Type: new Abstract: Digital technologies are now central to children's learning, play, communication, identity formation, and social participation. Yet dominant approaches to children's online safety often rely on containment mechanisms, including bans, age gates, parental controls, monitoring, and screen-time restrictions. These approaches can be useful in s…
Read original ↗https://arxiv.org/abs/2606.17957arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
LineageMark: Multi-user White-box Watermarking for Contribution Tracing in Model Derivation Chains arXiv:2606.17123v1 Announce Type: new Abstract: In open large language model (LLM) ecosystems, models are frequently adapted across multiple domains and applications, forming multi-stage derivation chains. Consequently, tracking and verifying historical contributions is essential for model provenance and intellectual property protection. However, existing watermarking methods a…
Read original ↗https://arxiv.org/abs/2606.17123arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Beyond Native Success: Auditing Deployment-Interface Exposure of CLIP Backdoors arXiv:2606.17815v1 Announce Type: new Abstract: Contrastive Language-Image Pre-training models are widely reused across downstream interfaces, including feature extraction, retrieval, reranking, and selection. Existing CLIP backdoor, however, usually validate attacks on a small attack-native task, leaving unclear whether the same poisoned checkpoint remains exposed, weakens, or becomes not applic…
Read original ↗https://arxiv.org/abs/2606.17815arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Anywhere, Any-Stymie: Remote Activation of Trojan Malware on LiDAR with Modulated Signals arXiv:2606.17562v1 Announce Type: new Abstract: LiDAR sensors are widely deployed in autonomous systems for 3D perception and safety-critical decision-making. We identify a previously unexplored attack surface in which dormant malware embedded in the LiDAR sensing pipeline remains inactive during normal operation and can be externally triggered after deployment, without requiring access…
Read original ↗https://arxiv.org/abs/2606.17562arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
SNAS: A Multi-Layer Defense-in-Depth Architecture for Secure Egress in Sandboxed Workloads arXiv:2606.17533v1 Announce Type: new Abstract: Snowpark enables data engineering and AI/ML workloads in Snowflake by executing user-defined functions in secure sandboxes. Many of these workloads require external connectivity to access cloud APIs, external databases, or feature stores, creating a dependability challenge: how to provide transparent network access while preserving strict…
Read original ↗https://arxiv.org/abs/2606.17533arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Safety, Security, and Cognitive Risks in Neuro-Symbolic AI arXiv:2606.17223v1 Announce Type: new Abstract: Neuro-symbolic AI (NeSy) pairs neural perception with symbolic reasoning, making it attractive for high-stakes domains where explainability and structured inference are required. However, this hybrid architecture introduces an enlarged attack surface spanning five layers: neural perception, symbolic knowledge bases, reasoning engines, agentic orchestration, and data sto…
Read original ↗https://arxiv.org/abs/2606.17223arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Fractional Verkle Trees: A Hypertree Decomposition and Verified Proof Serialization Architecture for High-Performance Blockchain State Accumulators arXiv:2606.17111v1 Announce Type: new Abstract: Modern blockchain state management faces a critical scalability bottleneck: maintaining cryptographic commitments over hundreds of millions of entries becomes computationally prohibitive. Ethereum's transition to Verkle Trees: polynomial commitment accumulators reducing proof sizes …
Read original ↗https://arxiv.org/abs/2606.17111arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Cache to the Future: A Distributed Webpage Archive for Internet Blackouts arXiv:2606.17245v1 Announce Type: new Abstract: Internet blackouts, occurring due to technological mishaps or intentional governmental action, prevent citizens from accessing the internet. Citizens in regions where internet blackouts are common have utilized blackout-resistant technologies to maintain communication. Such technologies often rely on mobile mesh networks to provide limited messaging servi…
Read original ↗https://arxiv.org/abs/2606.17245arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios arXiv:2606.17114v1 Announce Type: new Abstract: AI agents are increasingly being adopted in enterprise and personal settings with access to emails, databases, documents, and other tools where they can read, update, and disseminate sensitive information. Much of prior research on data leakage risks in agents has focused on adversarial data exfiltration through prompt injections and jailbreaks.…
Read original ↗https://arxiv.org/abs/2606.17114arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Structural Role Injection in Handlebars-Templated LLM Prompts: Triple-Brace Interpolation, Delimiter Family, and the Limits of HTML Auto-Escaping arXiv:2606.18120v1 Announce Type: new Abstract: Large language model applications build prompts from templates, and Handlebars is a widely used templating engine and the default prompt-template format in Microsoft Semantic Kernel. Its double-brace {{x}} expression HTML-escapes the interpolated value and is documented as the safe de…
Read original ↗https://arxiv.org/abs/2606.18120arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
ARVO: Atlas of Reproducible Vulnerabilities for Open-Source Software arXiv:2606.17283v1 Announce Type: new Abstract: Achieving reproducibility, quantity, and diversity in vulnerability datasets has long been viewed as an inherent three-way trade-off, where improving one dimension often comes at the cost of the others. In practice, reproducibility has been the dimension most often neglected. This has limited what can be automatically extracted from historical bug datasets, an…
Read original ↗https://arxiv.org/abs/2606.17283arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
TrustErase: Auditable Instant Machine Unlearning with Passport-Embedded Representations arXiv:2606.17122v1 Announce Type: new Abstract: The demand for privacy-compliant AI has amplified the need for machine unlearning; yet, existing retraining or distillation-based methods remain unverifiable and computationally costly. We introduce TrustErase, a verifiable, data-free unlearning framework leveraging passport-embedded representations for instant, modular, and auditable forget…
Read original ↗https://arxiv.org/abs/2606.17122arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Graph neural networks at war: integrating cybersecurity and drone intelligence in the Israeli-Iranian conflict arXiv:2606.17119v1 Announce Type: new Abstract: Physical cyber systems have brought about new threats and challenges in detection and immediate response. This study examines how Graph Neural Networks (GNNs) can be used to aid cybersecurity and drone management in a physical cyber system comprising of cyber intrusions and unmanned aerial vehicles (UAVs). By providing…
Read original ↗https://arxiv.org/abs/2606.17119arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents arXiv:2606.17467v1 Announce Type: new Abstract: Prompt injection defenses evaluated on synthetic benchmarks do not generalize to real enterprise documents, which are longer, denser, and interleave legitimate authority language with factual content. We demonstrate this gap with a real-document benchmark of 122 tasks across five professional domains (financial, legal, medical, scientific, DevOps)…
Read original ↗https://arxiv.org/abs/2606.17467arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Bifrost: Hybrid TEE-FHE Inference for Privacy-Preserving Transformer and LLM Serving arXiv:2606.17421v1 Announce Type: new Abstract: Cloud-hosted transformer and large language model (LLM) inference creates a direct confidentiality problem: user prompts may contain sensitive code, business data, personal information, or regulated documents, yet remote serving exposes intermediate state to the cloud software stack and accelerator runtime. Fully homomorphic encryption (FHE) ke…
Read original ↗https://arxiv.org/abs/2606.17421arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
An AI Security Agent for Banking: Multi-Vector Fraud and AML Detection Across Retail and Corporate Accounts arXiv:2606.17555v1 Announce Type: new Abstract: Banks simultaneously face signature-based fraud (card-not-present attacks, account takeover, ATM cloning) and behavioural financial crime (structuring, layering, mule networks, business email compromise) -- two threat families with fundamentally different detection requirements. Static rule engines that reliably catch bru…
Read original ↗https://arxiv.org/abs/2606.17555arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Loss Landscape Poisoning: Targeted Extraction of Unseen Training Data from LLMs arXiv:2606.17110v1 Announce Type: new Abstract: Large Language Models are increasingly trained on proprietary or sensitive data, from private healthcare and financial records to user conversations containing secrets. Ensuring the privacy of such data against extraction attacks has become a central concern. In this paper, we ask whether an attacker who can poison a portion of the training data can…
Read original ↗https://arxiv.org/abs/2606.17110arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Timestamp-Aware Spatio-Temporal Graph Contrastive Learning for Network Intrusion Detection arXiv:2606.17109v1 Announce Type: new Abstract: Given their effectiveness in modeling the relational structure among network traffic flows, graph neural networks (GNNs) have been widely adopted in network intrusion detection systems (NIDSs). However, most existing GNN-based NIDS approaches focus on the relational structure of traffic flows, and treat them as temporally independent, whi…
Read original ↗https://arxiv.org/abs/2606.17109arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Securing Multi-Agent GIS Systems: Risk Evaluation and Prompt Hardening Optimization arXiv:2606.17092v1 Announce Type: new Abstract: Agentic systems are increasingly integrated with geographic information systems (GIS), where multi-agent coordination enables complex conversational and spatial analysis but introduces security risks. This work presents a security-oriented framework for risk identification, evaluation, and mitigation in a multi-agent GIS system while maintaining…
Read original ↗https://arxiv.org/abs/2606.17092arxiv_cs_cr · tlp:amber · 6/17/2026, 4:00:00 AM
Security and Human-Centered Assessment of BACnet-Controlled DALI Infrastructure in an Educational Building Automation Testbed arXiv:2606.17089v1 Announce Type: new Abstract: Building automation and control systems integrate heating, ventilation, air conditioning, lighting, sensing, and management functions through specialized communication protocols. While this integration enables flexible building operation, it also creates complex cyber-physical environments that are diffi…
Read original ↗https://arxiv.org/abs/2606.17089trend_micro · tlp:amber · 6/17/2026, 12:00:00 AM
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Cybercriminals hijacked Google Ads searches for popular AI developer tools to funnel over 2,000 victims toward malicious download pages before quietly moving their operation onto claude.ai's own platform, turning the trusted domain into a delivery mechanism for credential-stealing malware. Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US) search close A…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.htmlsnyk_blog · tlp:amber · 6/16/2026, 11:00:00 PM
A Day in the Life of an AI Engineer in Snyk's Lisbon Office Explore a day in the life of an AI Engineer at Snyk's Lisbon office. See what it's like building AI-powered security tools, collaborating globally, and enjoying the vibrant culture of Portugal's capital city. A Day in the Life of an AI Engineer in Snyk's Lisbon Office | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a sing…
Read original ↗https://snyk.io/blog/a-day-in-the-life-of-an-ai-engineer-in-snyks-lisbon-officesnyk_blog · tlp:amber · 6/16/2026, 9:00:00 PM
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate. Mastra npm Scope Takeover | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security…
Read original ↗https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scopelwn_kernel · tlp:amber · 6/16/2026, 5:22:38 PM
The LWN public topics list Part of running LWN is keeping a list of potentially interesting topics that may merit the effort to turn into articles. As an experiment, we are now exposing that list to our subscribers at the Project Leader and Supporter levels. The hope is that this list will provide useful insights into what is on our radar and which might be coming to LWN in the near future. With this feature, we hope to give our most committed subscribers a look behind the c…
Read original ↗https://lwn.net/Articles/1078039lwn_kernel · tlp:amber · 6/16/2026, 3:31:20 PM
[$] The state of Fedora in 2026 On June 15 at Fedora's Flock conference, held in Prague, Fedora Project Leader (FPL) Jef Spaleta delivered a short "State of Fedora" keynote that provided a bit of insight into the status of the project. Topics included the overall growth for Fedora usage, ways to increase contributions, and an alarming decline in the number of active packagers working on the project.
Read original ↗https://lwn.net/Articles/1077832lwn_kernel · tlp:amber · 6/16/2026, 2:18:07 PM
Firefox 152.0 released Version 152.0 of the Firefox web browser has been released. Notable changes in this release include a brand-new look for the Firefox Settings interface, the ability to disable tracker blocking in private browsing tabs, a feature to mute browser sound from the address bar, experimental support for the JPEG XL image format, and more. Firefox 152.0 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Eve…
Read original ↗https://lwn.net/Articles/1078191lwn_kernel · tlp:amber · 6/16/2026, 1:22:04 PM
KDE Plasma 6.7 released Version 6.7 of KDE's Plasma desktop has been released. Notable changes in this release include per-screen virtual desktops, faster desktop switching, introduction of the Union theming system as a tech preview, as well as many other improvements and bug fixes. The release is dedicated to Eric Laffoon, a longtime KDE supporter, who passed away in May. See the KDE wiki for a full list of new features, and the Changelog for a list of all commits in this r…
Read original ↗https://lwn.net/Articles/1078160lwn_kernel · tlp:amber · 6/16/2026, 1:05:20 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (mod_http2, postfix, and webkit2gtk3), Debian (bird2, libgd-perl, and libreoffice), Fedora (7zip, ack, hugo, and perl-Mojo-JWT), Mageia (atril, evince, xreader, emacs, lcms2, libgcrypt, libinput, libsndfile, putty, and sudo), Red Hat (openssl and osbuild-composer), SUSE (cheat, chromedriver, containerized-data-importer, cyrus-imapd, freeipmi, graphicsmagick, java-11-openj9, java-17-openj9, kitty, kub…
Read original ↗https://lwn.net/Articles/1078158