REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2218 reports · page 30 of 56
cisa_alerts · tlp:amber · 6/16/2026, 12:00:00 PM
Rockwell Automation FactoryTalk Analytics PavilionX View CSAF Summary Successful exploitation of this vulnerability could result in an attacker executing privileged operations. The following versions of Rockwell Automation FactoryTalk Analytics PavilionX are affected: FactoryTalk Analytics PavilionX <7.01 (CVE-2025-14272) CVSS Vendor Equipment Vulnerabilities v3 7 Rockwell Automation Rockwell Automation FactoryTalk Analytics PavilionX Missing Authorization Background Crit…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-01cisa_alerts · tlp:amber · 6/16/2026, 12:00:00 PM
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP View CSAF Summary Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF). The following versions of Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP are affected: CompactLogix 5370 <=34.016 (CVE-2026-11317) Compact GuardLogix 5370 <=35.015 (CVE-2026-…
cisa_alerts · tlp:amber · 6/16/2026, 12:00:00 PM
Rockwell Automation CompactLogix View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix are affected: CompactLogix 5370 L1 CompactLogix 5370 L2 CompactLogix 5370 L3 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation CompactLogix Improper Validation of Integrity Check Value, Exposure of Sensitive System Inform…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-04cisa_alerts · tlp:amber · 6/16/2026, 12:00:00 PM
Rockwell Automation RSLinx View CSAF Summary Successful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on its own. The following versions of RSLinx Classic Third-Party Vulnerability are affected: RSLinx Classic <=4.50.00 (CVE-2020-13573) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation RSLinx Classic Third-Party Vulnerability Out-of-bounds Read Background Critical Infr…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-02cisa_alerts · tlp:amber · 6/16/2026, 12:00:00 PM
Rockwell Automation FLEX I/O EtherNet/IP Adapters View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, account takeover, and cause loss of availability. The following versions of Rockwell Automation FLEX I/O EtherNet/IP Adapters are affected: 1794-AENTR V2.012 (CVE-2026-0646, CVE-2026-0647) 1794-AENTRXT V2.012 (CVE-2026-0646, CVE-2026-0647) CVSS Vendor Equipment Vulnerabilities v3 9.4 Rockwell Automation Rock…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05ars_security · tlp:amber · 6/16/2026, 11:15:46 AM
Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and over. Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible t…
Read original ↗https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-usersunit42 · tlp:amber · 6/16/2026, 10:00:29 AM
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42 . Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Menu Tools ATOMs Security Consulting About Us Under Attack? Threat R…
Read original ↗https://unit42.paloaltonetworks.com/hijacking-vertex-ai-modeleset · tlp:amber · 6/16/2026, 8:54:04 AM
FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness FishMonger’s arsenal upgraded: SprySOCKS for Windows Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveSc…
Read original ↗https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windowschainalysis · tlp:amber · 6/16/2026, 8:32:24 AM
How Ghana’s EOCO and the UK NCA are Using Blockchain Analysis to Return $15 Million to Fraud Victims When an e‑commerce “investment” platform promising high-yield returns began circulating in Ghana, thousands of people signed up to run online… The post How Ghana’s EOCO and the UK NCA are Using Blockchain Analysis to Return $15 Million to Fraud Victims appeared first on Chainalysis . Ghana and the UK Recovered $15 Million via Blockchain Chainalysis Products Crypto Inve…
Read original ↗https://www.chainalysis.com/blog/ghana-eoco-uk-nca-blockchain-analysis-casearxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Fuzzy PSI from Symmetric Primitives with Exact Logarithmic Dependence on Distance Threshold arXiv:2606.15093v1 Announce Type: new Abstract: Previous FPSI works have demonstrated a linear scaling with the distance threshold $\delta$, while some recent works have achieved a poly-logarithmic dependence on $\delta$. However, these protocols either support only the $L_\infty$ distance, or they support general $L_{p\in[1,\infty]}$ distances but rely on expensive additive homomorph…
Read original ↗https://arxiv.org/abs/2606.15093arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Semantic Integrity Failures in Document-to-LLM Supply Chains arXiv:2606.15020v1 Announce Type: new Abstract: Document-to-LLM applications typically read uploaded PDFs by first translating them into text through a hidden extraction layer that users cannot observe or audit. We show that this layer enables split-view PDFs: one document can have two semantic views before model reasoning. By mining specification-permitted or implementation-tolerated representation gaps at the PDF…
Read original ↗https://arxiv.org/abs/2606.15020arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
FragFuse: Bypassing Access Control of Large Language Model Agents via Memory-Based Query Fragmentation and Fusion arXiv:2606.15609v1 Announce Type: new Abstract: Large language model (LLM) agents increasingly rely on long-term memory to support complex task execution, user personalization, and domain adaptation. Meanwhile, emerging access-control mechanisms for LLM agents are being explored to block policy-violating requests and prevent misuse. We reveal a novel attack surfa…
Read original ↗https://arxiv.org/abs/2606.15609arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Robust and Precise Application Fingerprinting on 5G Physical Uplink Channel arXiv:2606.15221v1 Announce Type: new Abstract: Air fingerprinting infers application activity by sniffing metadata from cellular control channels. 5G encrypts these channels, breaking the attack chain that prior attacks depend on. This paper reveals a physical-layer side channel that bypasses encryption: under the link adaptation mandated by the cellular communication standard, the uplink Modulation…
Read original ↗https://arxiv.org/abs/2606.15221arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AnonShield: Scalable On-Premise Pseudonymization for CSIRT Vulnerability Data arXiv:2606.15650v1 Announce Type: new Abstract: We present AnonShield, a high-throughput, on-premise pseudonymization system that combines GPU-accelerated NER, streaming processing, caching, and schema-aware configuration. Evaluated on datasets up to 550 MB (70,951 records), AnonShield reduces processing time from over 92 hours to under 10 minutes (up to 738x speedup) while achieving up to 94.2% F1…
Read original ↗https://arxiv.org/abs/2606.15650arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Security Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary Violations arXiv:2606.15008v1 Announce Type: new Abstract: Agentic large language model (LLM) systems can now execute actions, not only produce text. When model outputs trigger privileged operations such as shell commands, browser automation, or external tool calls, the security problem shifts from alignment alone to system configuration and structural design. We analyze OpenClaw, a self-…
Read original ↗https://arxiv.org/abs/2606.15008arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Odds Law: The Decomposition Algebra On How Intelligence Organizes Itself to Solve Difficult Problems Reliably arXiv:2606.15712v1 Announce Type: new Abstract: We ask a structural question: given unreliable elementary problem-solvers, what organizations of them solve hard problems reliably, and what are the limits? We develop a $decomposition~algebra$: elementary solvers are morphisms in a stochastic category, and four combinators (sequential composition, parallel ensembling, …
Read original ↗https://arxiv.org/abs/2606.15712arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
LLM: LSTM Look-Ahead Moving Target Defense Based on Historical Malicious Scan arXiv:2606.15229v1 Announce Type: new Abstract: Network scanning is a critical preliminary step for most adversaries to gain essential information before launching cyber attacks. Moving Target Defense (MTD) based on IP shuffling has emerged as a proactive defense strategy to counteract these reconnaissance efforts. Unlike static, reactive defense techniques, IP shuffling introduces randomness by dy…
Read original ↗https://arxiv.org/abs/2606.15229arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Let Them Steal: Trapping Large Language Model Extraction Attacks with Knowledge Honeypot arXiv:2606.15810v1 Announce Type: new Abstract: Large language models deployed as commercial APIs are vulnerable to model extraction attacks, while existing defenses either act too late or degrade utility for legitimate users. We propose \textbf{Knowledge Trap}, a defense that redirects extraction attacks toward low-transferability knowledge through a \emph{Honeypot Knowledge Graph} (HKG…
Read original ↗https://arxiv.org/abs/2606.15810arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
VLALeaks: Membership Inference Attacks against Vision-Language-Action Models arXiv:2606.15165v1 Announce Type: new Abstract: Vision-Language-Action (VLA) models enable end-to-end robot control and have garnered widespread attention. However, the memorization of training data inherent to VLA, coupled with the high cost of robotic data acquisition, raises serious concerns regarding data privacy leakage and intellectual property infringement. Membership inference attacks (MIAs)…
Read original ↗https://arxiv.org/abs/2606.15165arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Continual Backdoor Training in IoT/CPS arXiv:2606.14987v1 Announce Type: new Abstract: Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility. While continual adaptation is essential for long-lived IoT deployments where data patterns evolve, it also introduces new security vulnerabilities. In particular, backdoor attack…
Read original ↗https://arxiv.org/abs/2606.14987arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Multi-tier Differential Private Query Release arXiv:2606.15543v1 Announce Type: new Abstract: Answering statistical queries over sensitive data under differential privacy (DP) is a common task in many settings, including databases, mobile computing, and data markets. In these scenarios, multiple analysts may issue the same query, while receiving answers generated under different privacy budgets due to differences in trust levels or willingness to pay. Existing approaches for…
Read original ↗https://arxiv.org/abs/2606.15543arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
CmdNeedle: Measuring the Incompleteness of Command Denylists for AI Agents arXiv:2606.15549v1 Announce Type: new Abstract: The adoption of AI agents is increasing rapidly. Terminal AI agents, i.e., AI agents that run in terminal environments, are a widely used type of AI agents. Terminal AI agents rely heavily on shell command execution to interact with the host systems. They adopt a three-list command-gating mechanism to mitigate security risks introduced by command executi…
Read original ↗https://arxiv.org/abs/2606.15549arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
The Audit Gap in Blockchain Security: A Four-Year Empirical Study of Public Audit Findings and Real-World Exploit Incidents arXiv:2606.15465v1 Announce Type: new Abstract: This paper presents an empirical analysis of the Web3 security landscape over the four-year and three-month period from 1 January 2022 to 27 March 2026. The dataset combines 23,818 public audit findings produced by 22 independent security firms with 218 real-world exploit incidents documented by rekt.news,…
Read original ↗https://arxiv.org/abs/2606.15465arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Defending against Adaptive Prompt Injection Attacks via Reasoning-enabled Task Alignment arXiv:2606.15441v1 Announce Type: new Abstract: Indirect prompt injection attacks hijack LLM-based agents by embedding malicious instructions in third-party data that the agent retrieves during task execution. Existing defenses report near-zero attack success rate on static benchmarks, yet recent adaptive evaluations show that these results collapse once the attacker is allowed to optimi…
Read original ↗https://arxiv.org/abs/2606.15441arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AttackonCTF: Defending Hardware Security Competition Benchmarks in the Age of LLMs arXiv:2606.15809v1 Announce Type: new Abstract: Hardware security competitions such as HackTheSilicon serve as benchmarking platforms for evaluating vulnerability detection methods and for training humans and AI. However, our study reveals that LLMs threaten their validity. Instead of genuine security reasoning, detectors exploit a diff-style syntactic comparison, achieving an 83% detection ra…
Read original ↗https://arxiv.org/abs/2606.15809arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Data-Centric Benchmarking of Exploit Generation in LLMs: Understanding the Impact of Fine-Tuning arXiv:2606.15123v1 Announce Type: new Abstract: We study the task of CVE-conditioned exploit generation, where a model drafts proof-of-concept (PoC) exploits given software vulnerability context. We adopt a data-centric approach, constructing a high-quality dataset via multi-stage preprocessing and introducing a scalable evaluation framework with LLM-as-judge and fine-grained rub…
Read original ↗https://arxiv.org/abs/2606.15123arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Is Your Agent Playing Dead? Deployed LLM Agents Exhibit Constraint-Evasive Fabrication and Thanatosis arXiv:2606.14831v1 Announce Type: new Abstract: This paper presents and characterizes a spectrum of previously unreported behaviours we term Constraint-Evasive Fabrication (CEF): when an LLM agent operates under irreconcilable constraints (where no response can simultaneously satisfy all active rules) it spontaneously fabricates plausible external obstacles and presents them…
Read original ↗https://arxiv.org/abs/2606.14831arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? arXiv:2606.15762v1 Announce Type: new Abstract: We ran 300 repeated vulnerability-finding scans to measure how repeatable agentic large language model (LLM) security review is on the same JavaScript code, prompt, and benchmark harness. The headline result is that LLM security findings were unevenly repeatable: reference-matched findings were stable, but extra model reports varied heavily from run to run. Across 250 mo…
Read original ↗https://arxiv.org/abs/2606.15762arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Benign in Isolation, Harmful in Composition: Security Risks in Agent Skill Ecosystems arXiv:2606.15242v1 Announce Type: new Abstract: Skills are becoming the capability layer through which LLM agents turn plans into actions, but their use introduces security risks such as data leakage, unauthorized operations, and tool misuse. Existing vetting usually evaluates each skill in isolation, while real agent tasks often invoke multiple skills in a shared execution context. This cr…
Read original ↗https://arxiv.org/abs/2606.15242arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
BT-MTD: Bus Traversal-based Moving Target Defense for Smart Grid arXiv:2606.15047v1 Announce Type: new Abstract: Moving Target Defense (MTD) is a proactive security strategy designed to enhance cyber-resilience by dynamically altering system parameters, thereby preventing adversaries from acquiring the critical information needed to execute stealth attacks. In this paper, we consider the case in which the operator modifies the admittance of branches to enable MTD, and focus …
Read original ↗https://arxiv.org/abs/2606.15047arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AutoDojo: Adaptive Attacks Expose Superficial Defenses and User-Underspecification Limits in LLM Agents arXiv:2606.15057v1 Announce Type: new Abstract: Indirect prompt injection (IPI) is a major security threat to LLM-powered agents. Thus, a growing body of work have proposed a variety of defensive approaches against IPI. These can be grouped into three broad categories: 1) prompt-based (using prompting as a way to prevent agents from following malicious instructions), 2) de…
Read original ↗https://arxiv.org/abs/2606.15057arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
GAS-Leak-LLM: Genetic Algorithm-Based Suffix Optimization for Black-Box LLM Jailbreaking arXiv:2606.15788v1 Announce Type: new Abstract: Large Language Models (LLMs) constitute pivotal components within the AI-dominated information technology ecosystem. To mitigate risks associated with harmful or policy-violating outputs, commercial systems employ advanced alignment strategies and multi-layered content moderation mechanisms. Despite these safeguards, recent research has dem…
Read original ↗https://arxiv.org/abs/2606.15788arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Censorship-Resistant Sealed-Bid Auctions on Blockchains arXiv:2606.14939v1 Announce Type: new Abstract: Auctions are now central to blockchain markets, settling NFT sales, token launches, DeFi liquidations, and arbitrage opportunities. Each on-chain bid is a public transaction whose inclusion is decided by a single consensus proposer per block. The proposer can observe pending bids, exclude competitors, and submit bids of their own, breaking the fairness guarantees of classi…
Read original ↗https://arxiv.org/abs/2606.14939arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
A Security Analysis of Long-Horizon Agentic AI Systems: Threats, Evaluation, and Framework Development arXiv:2606.14816v1 Announce Type: new Abstract: This paper presents a structured analysis of security challenges in long-horizon agentic AI systems. The study reviews existing threats, evaluation approaches, attack propagation mechanisms, and security frameworks. A taxonomy of security threats and a framework for analyzing attack propagation are proposed to support future r…
Read original ↗https://arxiv.org/abs/2606.14816unit42 · tlp:amber · 6/15/2026, 11:00:19 PM
Inside the Modern SOC: The 72-Minute Race Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42 . Inside the Modern SOC: The 72-Minute Race Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights Inside the Modern SOC Inside the Moder…
Read original ↗https://unit42.paloaltonetworks.com/soc-72-minute-racears_security · tlp:amber · 6/15/2026, 5:55:46 PM
Users cry foul after AMD stripped memory crypto from its consumer CPUs AMD's stripping of TSME from consumer CPUs appears to be a deliberate, covert move. A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire contents stored in memory, making the data useless …
Read original ↗https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpuslwn_kernel · tlp:amber · 6/15/2026, 4:36:39 PM
[$] Development statistics for the 7.1 kernel Linus Torvalds released the 7.1 kernel as expected on June 14. This development cycle brought in a lot of new features — and a lot of new developers as well. The time has come for our traditional look at where the changes in 7.1 came from, with a digression into how our community may be changing in general.
Read original ↗https://lwn.net/Articles/1077425microsoft_mstic · tlp:amber · 6/15/2026, 4:00:00 PM
Microsoft Defender email security benchmarking: Key insights from one year of data See how Microsoft Defender performed in one year of real-world email security benchmarking against SEG and ICES vendors. The post Microsoft Defender email security benchmarking: Key insights from one year of data appeared first on Microsoft Security Blog . Microsoft publishes quarterly email security benchmarking data comparing Microsoft Defender against secure email gateway (SEG) and integra…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-datamandiant · tlp:amber · 6/15/2026, 2:00:00 PM
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromis…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-researchcheckpoint_research · tlp:amber · 6/15/2026, 1:40:44 PM
15th June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, […] The post 15th June – Threat Intelligence Report app…
Read original ↗https://research.checkpoint.com/2026/15th-june-threat-intelligence-report