REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 3 of 21
arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
{\epsilon}-Indistinguishability In Moving Target Defense: Framework, Algorithms, And Cloud Case Studies arXiv:2607.13440v1 Announce Type: new Abstract: Moving Target Defense (MTD) assumes its pool of candidate configurations is safe to cycle among, i.e. latency and other observables do not trivially fingerprint the active choice, but this assumption has not been quantified at the pool level. We formalize this pool-safety problem as finding the largest $\varepsilon$-close sub…
Read original ↗https://arxiv.org/abs/2607.13440arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
To Play or Not to Play: Insights and Lessons Learned from 20 Years of CTFs with ENOFLAG arXiv:2607.13480v1 Announce Type: new Abstract: Security contests in the form of CTF (Capture The Flag) exercises are nowadays a common way to learn cyber security. 20 years ago at DIMVA 2006 the on-site CTF CIPHER II was one of the conference highlights and led to the foundation of the team ENOFLAG. In this poster, we reflect on the changes in the CTF gameplay and report on lessons learn…
arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Securing LLMs in the Wild: Privacy and Security Challenges at the Edge arXiv:2607.13088v1 Announce Type: new Abstract: Large Language Models (LLMs) are rapidly moving from research settings into the wild, deployed on enterprise infrastructure, personal devices, and edge platforms. While cloud deployments offer scalable compute, concerns over data sovereignty, compliance, latency, and third-party dependence are driving organizations toward edge and on-premise LLMs. This shift…
Read original ↗https://arxiv.org/abs/2607.13088arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Composable Trust for Language Models: A proven boundary and a measured defense arXiv:2607.13149v1 Announce Type: new Abstract: In a language model, instructions and data share one token stream, so nothing inside the model's generation can keep untrusted text from steering it. We develop a trust model that places the authority to act outside the model, in code: a source's standing, not its content, decides which operation runs and whether it acts. A lower-trust source may inf…
Read original ↗https://arxiv.org/abs/2607.13149arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
DREA: Decoupled Reasoning and Exploration Agents for Repository-Level Vulnerability Detection arXiv:2607.13439v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly applied to vulnerability detection due to their strong code comprehension capabilities, but most existing approaches rely on isolated functions or context extracted by fixed program-analysis rules. These methods cannot adaptively explore repository-level dependencies to gather sufficient co…
Read original ↗https://arxiv.org/abs/2607.13439arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
SingGuard-NSFA: Extensible Guardrails for Agentic AI via Generative Reasoning and Real-Time Classification arXiv:2607.13081v1 Announce Type: new Abstract: We present nsfaguard, a guardrail framework for securing agentic AI systems against operational threats, such as prompt injection, sensitive information extraction, malicious code requests, dangerous tool misuse, and resource exhaustion. We first introduce the NSFA taxonomy, which organizes 185 risk variants into a CIA-tri…
Read original ↗https://arxiv.org/abs/2607.13081arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Adversarial Prompting Framework for AI Safety Assessment arXiv:2607.13453v1 Announce Type: new Abstract: Artificial Intelligence (AI), especially Generative AI (GenAI), adoption has increased in industries significantly in recent years. However, the use of these models may also expose systems to new forms of cyberattacks by different malicious actors -- adversarial prompt attack (APA) being one of the most prominent examples of such threats. This paper presents the implement…
Read original ↗https://arxiv.org/abs/2607.13453arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
xChk: Bring Your Own Identity -- Heterogeneous Assurance with Verifier-Determined Sufficiency arXiv:2607.13369v1 Announce Type: new Abstract: We present xChk, a reference identity provider for Bring Your Own Identity (BYOI): users enroll via heterogeneous proofs (government KYC, corporate SSO, WebAuthn/FIDO2, professional networks, live verification, longitudinal activity, behavioral signals) and disclose them as portfolio claims in standard OAuth 2.0 / OpenID Connect (OIDC)…
Read original ↗https://arxiv.org/abs/2607.13369arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
The Refusal Residue: When Probes Catch Alignment Faking and When They Don't arXiv:2607.13346v1 Announce Type: new Abstract: Alignment faking is dangerous because a model can appear compliant under monitoring while preserving behavior it would reveal when unmonitored. When no scratchpad is visible, behavior alone cannot distinguish strategic from genuine compliance. We ask whether hidden states reveal what outputs hide. We run a 13-model sweep for naturally-emerging faking, t…
Read original ↗https://arxiv.org/abs/2607.13346arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Operational Evidence Gaps for LLMs in Fraud Detection and Trust-and-Safety Workflows arXiv:2607.13078v1 Announce Type: new Abstract: LLMs are now proposed for fraud detection, scam investigation, content moderation, and other trust-and-safety workflows. Much of the public literature still evaluates them as models, with less attention to their behavior as components in operational pipelines. This creates a practical evidence question: what would justify placing an LLM inside …
Read original ↗https://arxiv.org/abs/2607.13078arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Beyond AI-Generated Labels: Watermarking, Co-Creation, and Conflation of AI-Generation with Disinformation arXiv:2607.13082v1 Announce Type: new Abstract: Watermarking is often presented as a straightforward solution for distinguishing AI-generated from human-generated content, enabling platforms and regulators to trace synthetic content and detect AI-generated outputs at scale. This paper examines whether such mechanisms meaningfully address the epistemic and ethical challe…
Read original ↗https://arxiv.org/abs/2607.13082arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Evaluating Frontier AI Agents as Autonomous Clinical Security Auditors arXiv:2607.13411v1 Announce Type: new Abstract: Clinical AI models can expose patients to harm when adversarial vulnerabilities go undetected, yet formal security auditing requires statistical expertise, specialized tools, and significant time. We present an open evaluation task, built on METR Task Standard v0.3.0, that tests whether frontier AI agents can autonomously implement a structured clinical AI s…
Read original ↗https://arxiv.org/abs/2607.13411arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
The Entanglement Wall: Activation-Space Probes as Risk Detectors, Not Context Adjudicators arXiv:2607.13075v1 Announce Type: new Abstract: Context can change whether a request is harmful without changing its topic or surface form. We ask whether residual-stream probes distinguish harmful requests from surface-matched benign controls at a useful operating point. Across three 7-8B model families, an activation sensor blocks 95.5-97.7 percent of judge-classified compliant attac…
Read original ↗https://arxiv.org/abs/2607.13075arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software arXiv:2607.13206v1 Announce Type: new Abstract: Security patches for open-source software constitute a foundational resource for vulnerability remediation research and practice. However, analyzing and applying multiple patches remains challenging, especially when trying to determine at what point in a patch sequence a vulnerability is fully remediated. This…
Read original ↗https://arxiv.org/abs/2607.13206arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
BARS: Benign-Anchored Ranking and Selection for False Alarm Reduction in Network Intrusion Detection arXiv:2607.13203v1 Announce Type: new Abstract: False alarms remain a major barrier to deploying network intrusion detection systems (NIDS). In high-volume environments, even a sub-1% false positive rate can generate tens of thousands of daily alerts. Filter-based feature selection is attractive because it operates upstream of the classifier and adds no inference-time cost. H…
Read original ↗https://arxiv.org/abs/2607.13203arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Proof in a Bottle: Long-Lived Verifiable Secret Sharing via Pre-Quantum Commitment and Immutable Ledger Binding arXiv:2607.13235v1 Announce Type: new Abstract: Traditional secret sharing techniques such as Verifiable Secret sharing (VSS) are vulnerable to quantum attacks by a Cryptographically Relevant Quantum Computer (CRQC) running Shor's algorithm. We observe that the binding a VSS needs is required only at the moment of dealing, and this binding can be made before any CR…
Read original ↗https://arxiv.org/abs/2607.13235arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
ReBound: Reuse-Aware Privacy For Interactive Decision Support arXiv:2607.13441v1 Announce Type: new Abstract: Differentially private decision support frameworks answer complex aggregate threshold queries with formal bounds on false negative and false positive rates, but treat each query independently with no memory of past results. In practice, analysts work interactively, issuing sequences of related queries that refine bounds, adjust thresholds, or derive new functions fro…
Read original ↗https://arxiv.org/abs/2607.13441arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Privacy Preserving Recommender Systems Balancing Personalization with Privacy arXiv:2607.13328v1 Announce Type: new Abstract: Personalized recommendation systems are central to modern e-commerce and retail platforms, but they typically rely on centralized storage of detailed user interaction data, creating significant privacy and regulatory challenges. With increasing requirements from regulations such as GDPR, CCPA, and CPRA, organizations must develop recommendation system…
Read original ↗https://arxiv.org/abs/2607.13328arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Baselines Before Architecture: Evaluating Coding Agents for Autonomous Penetration Testing arXiv:2607.13085v1 Announce Type: new Abstract: Recent autonomous penetration testing papers report high benchmark scores while adding multi-component security harnesses around frontier LLMs. Because these systems often change both architecture and backbone model, it is difficult to tell how much performance comes from the harness rather than from the underlying model. This paper prese…
Read original ↗https://arxiv.org/abs/2607.13085arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
GDM AI Control Roadmap arXiv:2607.13087v1 Announce Type: new Abstract: AI agents are rapidly accelerating work at frontier AI companies, helping with AI R&D, cyber-defence, and advancing scientific discoveries. As these agents become more tightly integrated into our systems, unlocking their full potential requires rethinking how we do security. We should not assume that AI agents are always perfectly aligned, but should instead build in multiple layers of defence. We pre…
Read original ↗https://arxiv.org/abs/2607.13087arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Silent Alarm: A J-Space Protocol for Comparing Danger Recognition Across Models and Quantization Levels arXiv:2607.12792v1 Announce Type: new Abstract: Jailbreak-robustness research typically evaluates safety through generated responses using an LLM-as-judge approach. Such evaluations, however, are sensitive to the benchmark's grading procedure and capture only observed behavior on a given set of attacks, without directly revealing the hidden fragility of the underlying safe…
Read original ↗https://arxiv.org/abs/2607.12792arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Watermark Forensics for Generative Models: An Information-Theoretic Perspective arXiv:2607.13003v1 Announce Type: new Abstract: A watermark in a generative model's output is usually asked only whether a text is machine-made. The same mark can do more: attribute it to the user who produced it, extract a hidden payload, or localize the part that survives editing. These form a forensic ladder, and we ask what each rung costs in the sample length $n$. One object organizes the an…
Read original ↗https://arxiv.org/abs/2607.13003arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
A Scalable Cloud-Orchestrated and Service-Oriented Multi-Domain QKD Network with PQC Integration arXiv:2607.12765v1 Announce Type: new Abstract: Quantum key distribution (QKD) offers unconditional security but existing QKD networks remain difficult to scale across heterogeneous infrastructures and administrative domains due to vendor-specific interfaces, trusted-node constraints, and limited interoperability. This work presents a flexible multi-domain and multi-site quantum-…
Read original ↗https://arxiv.org/abs/2607.12765arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Representation and Reference Selection in Training-Free Synthetic Image Attribution arXiv:2607.12052v1 Announce Type: cross Abstract: Synthetic image attribution aims at identifying the generator responsible for a given AI-generated image. Training-free reference-based attribution methods are easily scalable, since newly emerging generators can be incorporated by adding source-specific references rather than retraining a task-specific classifier. Their performance depends on…
Read original ↗https://arxiv.org/abs/2607.12052arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Auditable and Transparent Fully Authenticated Disk Encryption via USB Storage Interposition arXiv:2607.12716v1 Announce Type: new Abstract: Full Disk Encryption (FDE) has become increasingly important in the last decades due to the evident confidentiality concerns. In most systems, encryption is provided by an operating system driver, through which the user can transparently access the encrypted disk after supplying the required keys (or the credentials from which those keys…
Read original ↗https://arxiv.org/abs/2607.12716arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Bulkhead: Automated Semantic Detection and Remediation of Container Escape Vulnerabilities arXiv:2607.12723v1 Announce Type: new Abstract: Filesystem isolation in container ecosystems is often weakened by cross-boundary path misresolution, causing path traversal (PaTra) vulnerabilities. These vulnerabilities stem from insecure host-container interactions and have become increasingly pervasive as cloud systems mount shared resources, such as GPUs and agent workspaces, into co…
Read original ↗https://arxiv.org/abs/2607.12723arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
PVDetector: Detecting Prompt Injection Attacks on Purpose-Specific LLM Agents through Policy-Violation Concept Analysis arXiv:2607.12624v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly deployed as purpose-specific agents to handle domain-specific tasks such as customer service and code generation. These agents are expected to comply with not only generic safety guardrails but also purpose-specific restrictions tailored to their designated roles. …
Read original ↗https://arxiv.org/abs/2607.12624arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Cross-Cutting Security Analysis of LLM-Generated Code via Metamorphic Testing and Association Rule Mining arXiv:2607.12089v1 Announce Type: new Abstract: Large language models (LLMs) frequently generate code with security vulnerabilities, yet these weaknesses are rarely isolated: they often span multiple concern areas simultaneously, reflecting the cross-cutting nature of security in software. We present a framework that combines security-oriented Metamorphic Relations (MRs)…
Read original ↗https://arxiv.org/abs/2607.12089arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Stability Buys Time: A Re-Keying Game for Encrypted Multi-Agent Control arXiv:2607.12742v1 Announce Type: new Abstract: Encrypted control lets a cloud coordinate a fleet of agents on fully homomorphically encrypted state, keeping their positions and commands private. The approximate scheme for real-valued control, CKKS, returns decryptions that carry the encryption noise, a key-recovery leak; the loop must decrypt to actuate, so the leak is unavoidable. Yet the security of a…
Read original ↗https://arxiv.org/abs/2607.12742arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
AutoTrace: From Patches to Triggers via Agentic Interprocedural Exploration arXiv:2607.12058v1 Announce Type: cross Abstract: Given a vulnerability-fixing commit, trigger localization asks which specific statement turns the vulnerable program state into a concrete unsafe operation. This question is harder than binary vulnerability detection because the answer demands interprocedural, causal reasoning: in a substantial fraction of real-world CVEs the triggering statement lies…
Read original ↗https://arxiv.org/abs/2607.12058arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
When Binaries Talk Back: Representation-Confusion Attacks on LLM-Assisted Reverse Engineering arXiv:2607.12507v1 Announce Type: new Abstract: LLM-assisted reverse-engineering (RE) systems analyze strings, decompiler output, and tool reports derived from ttacker-controlled binaries. A binary can make data look like instructions or records from one origin look like independent evidence. We call such failures Representation-Confusion Attacks in Reverse Engineering (RARE): the p…
Read original ↗https://arxiv.org/abs/2607.12507arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Open-Source Intelligence and Music Information Retrieval for Geographic Attribution of Musical Affect and the Ecological Limits of Population Inference arXiv:2607.12517v1 Announce Type: new Abstract: A common intuition holds that a region's music mirrors the temperament of its people, so that melancholic melodies mark melancholic populations. We test the measurable half of that intuition and reject the inferential half. Using the Essen Folksong Collection, a corpus of thousa…
Read original ↗https://arxiv.org/abs/2607.12517arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Open-Source Intelligence for Code Provenance and the Security Patterns that Separate Human and Large-Language-Model Implementations of Common Programming Tasks arXiv:2607.12524v1 Announce Type: new Abstract: Developers now draw code from two very different sources, the accumulated human answers on sites such as Stack Overflow and the output of large language models. We ask two questions about that split. First, can the provenance of a code snippet be recovered from the code …
Read original ↗https://arxiv.org/abs/2607.12524arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Antiproof: Synthesizing Vulnerability Detectors and Proofs of Exploitability arXiv:2607.12316v1 Announce Type: new Abstract: Discovering vulnerabilities before attackers exploit them requires high recall and reliable automatic validation, but existing approaches struggle to achieve both without prohibitive cost. We present Antiproof, an end-to-end vulnerability discovery system that combines neuro-symbolic detector synthesis for high-recall discovery with proof-of-exploitabi…
Read original ↗https://arxiv.org/abs/2607.12316arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Trust but Verify? Uncovering the Security Debt of Autonomous Coding Agents arXiv:2607.12428v1 Announce Type: new Abstract: The increasing adoption of autonomous coding agents accelerates software development but also introduces scoped security risks within high-impact file paths that can outpace traditional human review capacity. While prior research has primarily evaluated these systems in terms of functional correctness and productivity, this paper presents a large-scale e…
Read original ↗https://arxiv.org/abs/2607.12428arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
On the Security Implications of PQC in TLS: Handshake Exhaustion and IDS Degradation arXiv:2607.12504v1 Announce Type: new Abstract: Post-Quantum Cryptography (PQC) is increasingly being integrated into TLS 1.3 to enhance resilience against quantum-enabled attacks. However, the additional computational and communication overhead introduced by PQC primitives during the handshake phase may also amplify the impact of TLS handshake exhaustion attacks, leading to more severe Dist…
Read original ↗https://arxiv.org/abs/2607.12504arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
VanillaBench: The Hidden Accuracy Cost of Adversarial Robustness arXiv:2607.12545v1 Announce Type: new Abstract: Adversarial robustness research has produced hundreds of defended models over the past decade, yet the literature almost universally reports robustness results in isolation: standard (clean) accuracy and adversarial accuracy of the robust model are shown, but the gap to the corresponding vanilla model is rarely quantified. We introduce VanillaBench, a systematic b…
Read original ↗https://arxiv.org/abs/2607.12545arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Skills That Don't Exist: A Large-Scale Study of Hallucinated Skill Recommendation in LLM Agents arXiv:2607.12340v1 Announce Type: cross Abstract: LLM agents acquire new capabilities by downloading skills from open registries. Instead of browsing these catalogs manually, developers typically ask the agent to recommend and install a skill. This convenience hides a risk: agents frequently invent names for skills that exist in no registry. We term this flaw skill name hallucinat…
Read original ↗https://arxiv.org/abs/2607.12340arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
MindReader: Using LLMs to Encourage Memorable and Secure Password Replacement arXiv:2607.12148v1 Announce Type: new Abstract: We report on the design and evaluation of MindReader, a tool that helps a user replace her password when she is required to do so. Left to their own devices, users tend to replace their previous passwords with predictable variations of the original ones. MindReader leverages LLMs to suggest password variations that are chosen to be easy for the user t…
Read original ↗https://arxiv.org/abs/2607.12148arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
How Agentic Is Agentic Commerce? A Population-Scale Measurement of x402 Adoption and Authenticity arXiv:2607.12575v1 Announce Type: new Abstract: AI agents are said to be forming an economy in which they pay, on their own, for the data, APIs, and compute they consume. x402, which settles a stablecoin payment on-chain for each purchase, is the most widely deployed protocol for this, and its hundreds of millions of settlements are read as proof that the economy has arrived. We…
Read original ↗https://arxiv.org/abs/2607.12575