REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 3 of 54
arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior arXiv:2607.15286v1 Announce Type: new Abstract: We investigate whether harmful chain-of-thought (CoT) traces from compromised language models can transfer unsafe behaviour and be distilled into reusable jailbreak attacks. Using an emergent-misalignment organism and a refusal-ablated jailbroken organism, we transplant harmful CoTs into $29$ open-source and $5$ closed-source targets. Transferred…
Read original ↗https://arxiv.org/abs/2607.15286arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Vogls: a Fast Interactive Full-timing Simulator for Pre-silicon Power Side-Channel Analysis arXiv:2607.15782v1 Announce Type: new Abstract: Designing hardware circuits resistant to side-channel attacks increasingly relies on simulation to predict device leakage before fabrication. Current functional verification simulators are designed for extended correctness-checking runs and are ill-suited for producing large numbers of short trace collections with slight input variants n…
arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR arXiv:2607.16102v1 Announce Type: new Abstract: The 3rd Generation Partnership Project (3GPP)'s Fifth Generation New Radio (5G NR) is critical to supporting mission-critical services. However, 5G systems are vulnerable to smart jamming attacks that can propagate to applications running on top of these networks (i.e., cross-layer). The 5G gNB broadcasts resource scheduling information fo…
Read original ↗https://arxiv.org/abs/2607.16102arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Code-Poisoning Property Inference Attacks arXiv:2607.15970v1 Announce Type: new Abstract: The flourishing code hosting platforms and coding agents enable even beginners with private data to build tailored Machine Learning (ML) models using available code quickly. The training data for ML models, often regarded as private property (e.g., clinical records, transaction information), is at significant risk of information leakage. Property Inference Attacks (PIAs), as a significa…
Read original ↗https://arxiv.org/abs/2607.15970arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Ciphertext- and Polynomial-Level Optimization for Fully Homomorphic Encryption arXiv:2607.15750v1 Announce Type: new Abstract: Fully homomorphic encryption (FHE) schemes such as RNS-CKKS enable privacy-preserving services by allowing direct computation on encrypted data. While recent FHE compilers optimize FHE programs, they operate at the coarse-grained ciphertext level, where each ciphertext operation comprises a sequence of polynomial operations. At this granularity, the …
Read original ↗https://arxiv.org/abs/2607.15750arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Lazy Arithmetic using Systolic Arrays for Closing the Verification Gap on Embedded Systems arXiv:2607.15328v1 Announce Type: new Abstract: Complex algorithms such as deep neural networks are increasingly being deployed on embedded, resource constrained platforms. However, existing hardware and software schemes for implementing these models on the edge fall short, particularly for safety-critical applications such as medical devices. First, hardware such as GPUs, NPUs and TPU…
Read original ↗https://arxiv.org/abs/2607.15328arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Intentional Electromagnetic Interference Attacks on Facial Recognition arXiv:2607.15512v1 Announce Type: cross Abstract: Attacks on general computer vision algorithms are often relegated to the digital domain, with the optimization performed purely in the digital world and then translated to physical mediums for implementation. In the field of biometrics, including facial recognition, physical presentation attacks targeting biometric sensors are dominant and present signific…
Read original ↗https://arxiv.org/abs/2607.15512arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure arXiv:2607.15754v1 Announce Type: new Abstract: Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interaction…
Read original ↗https://arxiv.org/abs/2607.15754arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation arXiv:2607.16010v1 Announce Type: new Abstract: Governments are increasingly mandating that LLM-generated content carry watermarks. The EU AI Act calls for markings that are "sufficiently reliable and robust." California's SB 942 requires disclosure that is "permanent or extraordinarily difficult to remove." Both mandates rest on an untested assumption: that watermark detection yields evidence reliable e…
Read original ↗https://arxiv.org/abs/2607.16010arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Beyond Detection: Agentic Attack Synthesis and Simulation for Smart Contracts arXiv:2607.15673v1 Announce Type: new Abstract: Smart contract vulnerabilities pose severe financial risks, yet existing security tools largely stop at vulnerability detection, offering limited support for explaining whether reported flaws are exploitable, how attacks unfold, and what concrete damage they cause. To bridge this gap, we propose KASS (Knowledge-Augmented Attack Synthesis and Simulatio…
Read original ↗https://arxiv.org/abs/2607.15673arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Do Agents Dream of False Memories? Black-box Visual Attacks on Long-term Memory in Multimodal AI Agents arXiv:2607.15657v1 Announce Type: new Abstract: Multimodal AI agents increasingly rely on persistent long-term memory to ground generation in past visual and textual episodes. We show that unconditional trust in visual data creates a critical vulnerability. We propose Lucid, a black-box adversarial framework that compromises multimodal memory pipelines under a strictly ima…
Read original ↗https://arxiv.org/abs/2607.15657lwn_kernel · tlp:amber · 7/19/2026, 10:11:57 PM
Kernel prepatch 7.2-rc4 The 7.2-rc4 kernel prepatch is out for testing. Linus said: " This whole week I had the feeling that people were starting to go on summer vacation, but running the numbers shows that I must have been wrong - it all looks pretty normal. " Kernel prepatch 7.2-rc4 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Reg…
Read original ↗https://lwn.net/Articles/1083543
the_hacker_news · tlp:amber · 7/19/2026, 8:42:49 PM
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of…
Read original ↗https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
the_hacker_news · tlp:amber · 7/19/2026, 1:30:55 PM
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's UAC-0145 Uses …
Read original ↗https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
the_hacker_news · tlp:amber · 7/19/2026, 1:18:56 PM
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this SonicWall SMA…
Read original ↗https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.htmllwn_kernel · tlp:amber · 7/18/2026, 4:52:04 PM
"Half a Second" — a book on the XZ backdoor Adrian Mastronardi has released a book called Half a Second ; it is a detailed look into the XZ backdoor attempt of 2024. The book is freely available under a (non-free) noncommercial, no-derivatives CC license. Half a Second tells that story as one continuous narrative: the burned-out volunteer who maintained the code alone and was patiently, expertly manipulated into giving it up; the engineer whose half-second of curiosity caugh…
Read original ↗https://lwn.net/Articles/1083466lwn_kernel · tlp:amber · 7/18/2026, 4:41:27 PM
Three stable kernel updates The 7.1.4 , 6.18.39 , and 6.12.96 stable kernel updates have been released; each contains a fairly large set of important fixes. Three stable kernel updates [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Three stable kernel updates [Posted July 18, 2026 by corbet] The 7.1.4 , 6.18.39 , and 6.12.96 …
Read original ↗https://lwn.net/Articles/1083462
the_hacker_news · tlp:amber · 7/17/2026, 9:20:10 PM
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported New wp2s…
Read original ↗https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
the_hacker_news · tlp:amber · 7/17/2026, 8:20:53 PM
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the OpenSSL…
Read original ↗https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
the_hacker_news · tlp:amber · 7/17/2026, 6:54:51 PM
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Seven Malic…
Read original ↗https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
the_hacker_news · tlp:amber · 7/17/2026, 5:12:23 PM
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter …
Read original ↗https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.htmllwn_kernel · tlp:amber · 7/17/2026, 5:03:50 PM
Building an Arch Linux aarch64 port for Holo Core (Collabora blog) Collabora has published a blog post about its work with Valve on Holo Core, which is a port of Arch Linux to aarch64 to be used as the the operating system on Valve's 64-bit Arm Steam Frame gaming system. Collabora has released the sources , binary packages , and a container image for aarch64 devices. The post describes some of the challenges in porting Arch Linux to a new architecture, and what remains to be…
Read original ↗https://lwn.net/Articles/1083392
the_hacker_news · tlp:amber · 7/17/2026, 4:39:16 PM
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using Golde…
Read original ↗https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.htmlmicrosoft_mstic · tlp:amber · 7/17/2026, 4:00:00 PM
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog . In this article Weston on the future of defense Our latest intelligence (and response) on npm supp…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/17/microsoft-at-black-hat-usa-2026-defending-trust-in-the-age-of-ai-and-supply-chain-attackslwn_kernel · tlp:amber · 7/17/2026, 3:58:17 PM
[$] Securing BPF LSMs against tampering Since 2020, BPF programs have been able to act as Linux security modules (LSMs). Several projects, including systemd, have been working to use that capability to provide more security to users. Christian Brauner spoke at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit about some of the limitations of using BPF in this way, and the changes he would like to see for systemd's use. In particular, he would like a way t…
Read original ↗https://lwn.net/Articles/1082111huggingface_blog · tlp:amber · 7/17/2026, 3:57:54 PM
Fine-tune video and image models at scale with NVIDIA NeMo Automodel and 🤗 Diffusers Fine-tune video and image models at scale with NVIDIA NeMo Automodel and 🤗 Diffusers Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoin…
Read original ↗https://huggingface.co/blog/nvidia/scale-diffusers-finetuning-nemo-automodelsecurityweek · tlp:amber · 7/17/2026, 2:27:54 PM
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek . In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Bluepri…
Read original ↗https://www.securityweek.com/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint
the_hacker_news · tlp:amber · 7/17/2026, 1:48:56 PM
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Fake Codi…
Read original ↗https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
the_record · tlp:amber · 7/17/2026, 1:40:00 PM
Dairy company Fairlife suspends production in US after cyber incident Fairlife’s U.S. operation includes plants in Michigan, New York and Arizona, and the company's retail sales passed $1 billion in 2022. Dairy company Fairlife suspends production in US after cyber incident | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter Image: Natalie Behn…
Read original ↗https://therecord.media/dairy-company-fairlife-suspends-production-us-cyber-incidentlwn_kernel · tlp:amber · 7/17/2026, 1:06:22 PM
Security updates for Friday Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Oracle (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kern…
Read original ↗https://lwn.net/Articles/1083388
the_record · tlp:amber · 7/17/2026, 12:50:00 PM
Zelensky appoints Ukraine's acting security service chief as acting defense minister Yevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine's new acting defense minister. Zelensky appoints Ukraine's acting security service chief as acting defense minister | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podc…
Read original ↗https://therecord.media/ukraine-acting-defense-minister-yevhenii-khmarasecurityweek · tlp:amber · 7/17/2026, 12:11:22 PM
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive (Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek . Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive - SecurityWeek Virtual Event Today: Cloud & Data Security Summi…
Read original ↗https://www.securityweek.com/podcast-broken-governance-agentic-ai-and-the-mindstone-agent-exclusive
the_hacker_news · tlp:amber · 7/17/2026, 11:44:41 AM
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at …
Read original ↗https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.htmlsecurityweek · tlp:amber · 7/17/2026, 11:43:36 AM
Beacon Security Raises $13 Million for Security Data Platform The startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek . Beacon Security Raises $13 Million for Security Data Platform - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecurity News Webcasts V…
Read original ↗https://www.securityweek.com/beacon-security-raises-13-million-for-security-data-platform
the_hacker_news · tlp:amber · 7/17/2026, 11:30:00 AM
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the tr…
Read original ↗https://thehackernews.com/2026/07/the-race-to-field-military-autonomy-is.htmlsecurityweek · tlp:amber · 7/17/2026, 11:08:04 AM
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek . Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Even…
Read original ↗https://www.securityweek.com/industry-reactions-to-pentagon-suspending-cmmc-phase-2-feedback-friday
the_hacker_news · tlp:amber · 7/17/2026, 10:53:31 AM
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a s…
Read original ↗https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html
unit42 · tlp:amber · 7/17/2026, 10:00:24 AM
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 . Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research …
Read original ↗https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilitiessecurityweek · tlp:amber · 7/17/2026, 9:06:27 AM
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei The company disconnected its systems on July 13 and is starting to gradually restore operations. The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek . Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecurity …
Read original ↗https://www.securityweek.com/cyberattack-disrupts-operations-of-japanese-frozen-food-giant-nichirei
the_hacker_news · tlp:amber · 7/17/2026, 8:56:39 AM
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the …
Read original ↗https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html