REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 34 of 57
arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
IDP-Bench: Benchmarking ability of LLMs to protect personal information in interdependent privacy contexts arXiv:2606.09908v1 Announce Type: new Abstract: Large language models (LLMs) are becoming widely deployed as personal AI assistants with access to sensitive user data, making privacy a major challenge for their design and evaluation. Prior work focuses mainly on individual-level risks, overlooking \textbf{interdependent privacy (IDP)}--where one person's data may be rev…
Read original ↗https://arxiv.org/abs/2606.09908arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Linux IOCTL Census: A Source-Derived Database of the Linux Kernel Control-Code Surface arXiv:2606.10290v1 Announce Type: new Abstract: The ioctl system call is Linux's catch-all device-control interface. A userspace program opens a device node and hands the driver a numeric command code and an argument buffer, and the driver does whatever that code means, whether configuring hardware, reading back state, or moving data into and out of the kernel. Drivers define these com…
arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
A Deployment-Oriented Framework for Explainable AI-Assisted eBPF/XDP Mitigation at the IoT Edge arXiv:2606.10508v1 Announce Type: new Abstract: Internet of Things (IoT) deployments combine heterogeneous, resource-constrained devices with weak security configurations, exposed services, limited logging, patching constraints, and long lifecycles. Signature- and threshold-based controls remain useful baselines, but they are insufficient as standalone mechanisms in dynamic IoT ne…
Read original ↗https://arxiv.org/abs/2606.10508arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
A Hybrid Edge-Cloud Architecture for Low-Latency Entitlement Verification in Resource-Constrained Devices arXiv:2606.10536v1 Announce Type: new Abstract: As digital media consumption shifts toward large-scale Over-the-Top (OTT) platforms, the efficiency of the control plane, specifically entitlement and identity verification, has become a critical factor in user experience. Current architectures often rely on synchronous cloud-tethered validation flows that introduce signifi…
Read original ↗https://arxiv.org/abs/2606.10536arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT arXiv:2606.10097v1 Announce Type: new Abstract: Attackers often identify DNS traffic to disrupt or compromise Internet services. While prior work has focused on encrypting queries using DNS over TLS, HTTPS, or QUIC to counter such attacks, we consider IETF protocols designed for resource-constrained IoT devices and empirically analyze the potential of obfuscating DNS traffic in addition to encryption. …
Read original ↗https://arxiv.org/abs/2606.10097arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
RECON: An LLM-Enhanced Backward Constraint Analysis Framework arXiv:2606.10264v1 Announce Type: new Abstract: While traditional techniques, such as symbolic execution, provide a principled foundation for precise constraint reasoning in program analysis, they struggle to scale to modern software systems mainly due to path explosion, the need for function modeling, and the loss of semantic intent at low-level program representations. In complex execution environments such as A…
Read original ↗https://arxiv.org/abs/2606.10264arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
SoK: Colluding Adversaries in Machine Learning Pipelines arXiv:2606.10091v1 Announce Type: new Abstract: Machine learning (ML) models are susceptible to various security, privacy, and fairness risks. Adversaries with different characteristics (i.e., objectives, knowledge, and capabilities) can collude by executing one attack to amplify others. Existing work lacks a systematic framework to explore collusion among adversaries, and to study the implications of the adversaries' …
Read original ↗https://arxiv.org/abs/2606.10091arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
HE-DAP: Homomorphic Encryption-based Dynamic Adaptive Parameter Optimization for Statistical Computation arXiv:2606.10477v1 Announce Type: new Abstract: Homomorphic encryption (HE) enables privacy-preserving analytics but remains hindered by high computational overhead. We find that the inverse square root-a key primitive in many statistical and machine learning workloads-exhibits inconsistent and often suboptimal performance across HE libraries and hardware. This stems from…
Read original ↗https://arxiv.org/abs/2606.10477arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke Inference arXiv:2606.10148v1 Announce Type: new Abstract: In today's digitally connected world, keyboards remain the primary interface for inputting sensitive information, making them a persistent target for eavesdropping attacks. While prior keystroke inference techniques have exploited side-channel signals such as acoustics and vibrations, they typically rely on conspicuous, short-range sensors and requ…
Read original ↗https://arxiv.org/abs/2606.10148arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Distributed Detectability Band Against Marginal-Preserving Attacks arXiv:2606.10456v1 Announce Type: new Abstract: AI-control monitors score individual agent actions to detect misbehavior, but real harm can be distributed across many benign-looking steps, each individually below any per-step alarm. We construct a marginal-preserving, correlation-encoded distributed-sabotage attack using a Gaussian-copula AR(1) construction: the per-step monitor-score marginal is held exa…
Read original ↗https://arxiv.org/abs/2606.10456arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Semantic Multi-Agent Intrusion Detection for IoT:Zero-Day and Adversarial Threats with Risk-Aware Reasoning arXiv:2606.10323v1 Announce Type: new Abstract: The rapid proliferation of Internet of Things (IoT) devices has enabled unprecedented automation and connectivity, but it has also substantially increased the attack surface, exposing networks to sophisticated cyber threats, including zero-day and adversarial intrusions. Traditional Intrusion Detection Systems (IDS) strug…
Read original ↗https://arxiv.org/abs/2606.10323arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments arXiv:2606.10484v1 Announce Type: new Abstract: Autonomous AI agents have driven the transition from conversation to task execution, shifting security failures from textual deception to system compromise. Although security evaluation is crucial for proactive risk prevention, prior work is constrained by fundamental bottlenecks, including fragmented risk coverage, static or l…
Read original ↗https://arxiv.org/abs/2606.10484arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs arXiv:2606.10322v1 Announce Type: new Abstract: Large Language Models (LLMs) in multi-turn interactions maintain evolving context rather than generating isolated responses, making them vulnerable to prompt-injection and context-poisoning attacks in which locally plausible adversarial fragments gradually distort reasoning trajectories. Existing defenses mainly filter individual outputs and often ignore…
Read original ↗https://arxiv.org/abs/2606.10322arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems arXiv:2606.10163v1 Announce Type: new Abstract: The globalization of the integrated circuit (IC) supply chain increases the risk of security threats, such as hardware Trojans (HTs) and the theft of intellectual property (IP). Graph Neural Networks (GNNs), among the most powerful deep learning methods for processing graph-structured data, have been widely adopted to detect such threats. However, …
Read original ↗https://arxiv.org/abs/2606.10163arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
When VR Meets BCI: (Un)Observable Brainwave-aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion Sensors arXiv:2606.10502v1 Announce Type: new Abstract: Metaverse devices, such as virtual reality (VR), have seen substantial development and widespread applications in numerous areas. Although recent studies have revealed privacy leakages in VR, these vulnerabilities were limited in the scope of observable behaviors in virtual scenes (e.g., what a user …
Read original ↗https://arxiv.org/abs/2606.10502arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Local Is Not a Sufficient Privacy Boundary: Governing OS-Integrated On-Device AI arXiv:2606.10173v1 Announce Type: new Abstract: As AI systems move into operating systems, privacy no longer turns only on whether a model runs locally. A local assistant may assemble email, calendar entries, files, screenshots, notifications, and app intents; retain embeddings or summaries; invoke tools; emit telemetry; or route difficult requests to cloud infrastructure. Local inference reduce…
Read original ↗https://arxiv.org/abs/2606.10173arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Proof of Source of Funds: Efficient On-chain Provenance of Cryptoassets arXiv:2606.10172v1 Announce Type: new Abstract: Regulatory compliance is increasingly mandatory for decentralized finance and privacy-enhancing technologies. Current approaches rely on binary inclusion/exclusion lists or retroactive graph analysis by centralized blockchain intelligence firms. This approach strips honest users of their financial privacy, leads to false positives and negatives, and forces …
Read original ↗https://arxiv.org/abs/2606.10172arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines arXiv:2606.09935v1 Announce Type: new Abstract: AI-powered agents are increasingly embedded in continuous integration and continuous delivery/deployment (CI/CD) pipelines to autonomously review pull requests (PRs), triage issues, and maintain codebases. These agents ingest untrusted content while operating with elevated repository permissions, making them a natural target for prompt injection attack…
Read original ↗https://arxiv.org/abs/2606.09935arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization arXiv:2606.09909v1 Announce Type: new Abstract: With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent …
Read original ↗https://arxiv.org/abs/2606.09909arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Assessing Automated Prompt Injection Attacks in Agentic Environments arXiv:2606.10525v1 Announce Type: new Abstract: Indirect prompt injection poses a critical threat to LLM agents that interact with untrusted external data, yet automated attack methods--proven effective for jailbreaking--remain underexplored in realistic agentic settings. We present a comprehensive empirical evaluation of automated prompt injection attacks against LLM agents, adapting both white-box (GCG) a…
Read original ↗https://arxiv.org/abs/2606.10525arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Human Vulnerabilities & Exploits (HVE) Framework arXiv:2606.10083v1 Announce Type: new Abstract: The cybersecurity community has invested over two decades in building standardized frameworks, the Common Vulnerabilities and Exposures (CVE) system, the Common Vulnerability Scoring System (CVSS), and the Common Weakness Enumeration (CWE) to identify, classify, and remediate threats to digital infrastructure. However, an emerging body of research reveals that a vast majority…
Read original ↗https://arxiv.org/abs/2606.10083arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
The Chronicles of Radio Frequency Fingerprinting arXiv:2606.10031v1 Announce Type: new Abstract: Radio Frequency Fingerprinting (RFF) has evolved from an early idea for radar emitter identification into a broad research field for wireless device identification and spectrum monitoring for security. Rather than presenting a conventional literature survey, this work provides a critical historical analysis of RFF organized around the field's major conceptual paradigm shifts from…
Read original ↗https://arxiv.org/abs/2606.10031arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations arXiv:2606.10281v1 Announce Type: new Abstract: This paper presents AuditBench, a new benchmark dataset for evaluating the capabilities of LLMs at investigating security-related system audit logs. We design and use this benchmark to explore the performance of LLMs on four log-investigation tasks that incident response teams commonly perform, ranging from triaging alerts generated by detectors to id…
Read original ↗https://arxiv.org/abs/2606.10281arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
Safecloud: A Distributed, Encrypted Storage Cloud for Streaming arXiv:2606.09870v1 Announce Type: new Abstract: We present Safecloud, a distributed, encrypted, self-pricing storage and streaming network whose storage and routing nodes never see plaintext and never hold keys. Each file is split into chunks, encrypted on the owner's device, and distributed across Drops (browser tabs storing ciphertext in IndexedDB) and Jets (federated routing servers). Only the owner, or an au…
Read original ↗https://arxiv.org/abs/2606.09870arxiv_cs_cr · tlp:amber · 6/10/2026, 4:00:00 AM
From Data Heterogeneity to Convergence: A Data-Centric Review of Federated Learning arXiv:2606.10595v1 Announce Type: new Abstract: Federated Learning (FL) has emerged as a promising solution for data hunger in centralized learning. This paradigm enables privacy with multiple clients to train a shared-task model collaboratively without exposing their local data. While being a key component in any learning system, data is also a primary source of vulnerabilities and challenge…
Read original ↗https://arxiv.org/abs/2606.10595trend_micro · tlp:amber · 6/10/2026, 12:00:00 AM
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 This year’s Pwn2Own competition in Berlin revealed just how much of the AI stack remains exposed -- and the gap between what these tools promise and what they can withstand point to the fragile security foundations underneath. GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/pwn2own-genai.htmlchainalysis · tlp:amber · 6/9/2026, 11:59:10 PM
Chainalysis and the Korean National Police Agency (KNPA) Sign MoU to Strengthen Virtual Asset Investigation Capabilities In April 2026, Chainalysis signed a Memorandum of Understanding (MoU) with the Korean National Police Agency (KNPA) to deepen cooperation… The post Chainalysis and the Korean National Police Agency (KNPA) Sign MoU to Strengthen Virtual Asset Investigation Capabilities appeared first on Chainalysis . Chainalysis and KNPA Sign MoU Chainalysis Products…
Read original ↗https://www.chainalysis.com/blog/chainalysis-and-the-korean-national-police-agency-knpa-sign-mou-to-strengthen-virtual-asset-investigation-capabilitieschainalysis · tlp:amber · 6/9/2026, 11:59:00 PM
체이널리시스와 대한민국 경찰청(KNPA), 디지털 자산 수사 역량 강화를 위한 양해각서(MoU) 체결 오늘 체이널리시스는 대한민국 경찰청(KNPA)과 디지털 자산 범죄 수사 협력을 강화하기 위한 양해각서(MoU)를 체결했습니다. 이번 협약은 교육, 인증, 실무형 수사 프로그램… The post 체이널리시스와 대한민국 경찰청(KNPA), 디지털 자산 수사 역량 강화를 위한 양해각서(MoU) 체결 appeared first on Chainalysis . Chainalysis and KNPA Sign MoU Chainalysis Products Crypto Investigations Investigations Solutions Reactor Investigate and trace funds across blockchains Wallet Scan Check recovery seeds for seizable crypto Rapid Instan…
Read original ↗https://www.chainalysis.com/blog/korean-national-police-agency-mou-virtual-asset-investigation-krkrebs_on_security · tlp:amber · 6/9/2026, 10:07:28 PM
A Record-Breaking Patch Tuesday for June 2026 Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available. Microsoft today released software updates to plug nearly 200 …
Read original ↗https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026unit42 · tlp:amber · 6/9/2026, 10:00:21 PM
Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion. The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42 . Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility Menu Tools ATOMs Security Consu…
Read original ↗https://unit42.paloaltonetworks.com/cloud-logging-defense-evasiontalos · tlp:amber · 6/9/2026, 9:21:00 PM
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft Patch Tuesday details for June 2026. Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”.  Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsof…
Read original ↗https://blog.talosintelligence.com/microsoft-patch-tuesday-for-june-2026-snort-rules-and-prominent-vulnerabilitiesars_security · tlp:amber · 6/9/2026, 8:56:52 PM
Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed A separate zero-day also disclosed by Nightmare Eclipse appears to be patched as well. Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant. Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-day…
Read original ↗https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosedhuggingface_blog · tlp:amber · 6/9/2026, 7:38:28 PM
Can Voice Agents Handle Bilingual Customers? Benchmarking Frontier ASR on Code-Switched Speech Can Voice Agents Handle Bilingual Customers? Benchmarking Frontier ASR on Code-Switched Speech Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Infere…
Read original ↗https://huggingface.co/blog/ServiceNow-AI/code-switchinglwn_kernel · tlp:amber · 6/9/2026, 6:00:16 PM
Future of Ubuntu MATE Thomas Ward has published an update about the future of the Ubuntu MATE project, which did not have a 26.04 release with the other Ubuntu flavors in April: There is a new team working on Ubuntu MATE who have stepped up to help take over flavor management. They haven't formally introduced themselves yet, but I can safely say that other developers HAVE stepped up for the future of the MATE flavor, despite its prior team lead having stepped down. [...…
Read original ↗https://lwn.net/Articles/1077221lwn_kernel · tlp:amber · 6/9/2026, 5:50:49 PM
[$] Eliminating long-lived credentials with trusted publishing Trusted publishing is an authentication mechanism that relies on short-lived credentials to reduce the risk of supply-chain attacks. At the 2026 Open Source Summit North America , Mike Fiedler walked the audience through why trusted publishing exists, how it works, and made the case for its adoption. It is not a silver bullet against all attacks, but it does offer protection against theft of long-lived credential…
Read original ↗https://lwn.net/Articles/1076205chainalysis · tlp:amber · 6/9/2026, 5:35:21 PM
The Hidden Code Problem: How Unverified Smart Contracts Are Becoming a Preferred Target for Attackers Summary In the last six months, at least $36.7 million has been stolen from protocols whose source code was never… The post The Hidden Code Problem: How Unverified Smart Contracts Are Becoming a Preferred Target for Attackers appeared first on Chainalysis . Unverified Smart Contracts Are a Preferred Target for Attackers Chainalysis Products Crypto Investigations Inves…
Read original ↗https://www.chainalysis.com/blog/attackers-exploiting-unverified-smart-contractsmicrosoft_mstic · tlp:amber · 6/9/2026, 5:35:06 PM
Reconstructing AI activity in investigations Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity in investigations appeared first on Microsoft Security Blog . AI systems are now part of everyday work. Investigators need a consistent way to reconstru…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/09/reconstructing-ai-activity-investigationshuggingface_blog · tlp:amber · 6/9/2026, 3:56:23 PM
Introducing North Mini Code: Cohere’s First Model For Developers Introducing North Mini Code: Cohere’s First Model For Developers Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Article…
Read original ↗https://huggingface.co/blog/CohereLabs/introducing-north-mini-codears_security · tlp:amber · 6/9/2026, 3:12:43 PM
High-severity vulnerability in Linux caused by a single faulty character Use-after-free bug can be exploited to evade sandbox defenses. Researchers have analyzed a high-severity vulnerability in Linux that’s able to escalate untrusted users to root by exploiting a bug you don't often see: a single errant character inside the kernel. The vulnerability, tracked as CVE-2026-23111 , is located in nf_tables, a subsystem of the Linux kernel that provides packet filtering capabili…
Read original ↗https://arstechnica.com/security/2026/06/a-single-errant-character-in-the-linux-kernel-allows-attacker-to-gain-rootlwn_kernel · tlp:amber · 6/9/2026, 2:30:25 PM
Asahi Linux warns users not to upgrade to macOS 27 beta The Asahi Linux project, which brings Linux support to Apple Arm-based Macs, has warned its users not to upgrade to the macOS 27 "Golden Gate" beta. Apple has changed how the boot picker and Startup Disk applications detect valid OS boot volumes. When using either from macOS 27, your Asahi partition will not be visible! We believe this to be a bug, and have filed a report (FB22994760). If you have already upgr…
Read original ↗https://lwn.net/Articles/1077209