REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 35 of 57
lwn_kernel · tlp:amber · 6/9/2026, 1:37:36 PM
[$] BPF loop verification with scalar evolution The BPF verifier has, in the course of wrestling with the difficult problem of statically analyzing loops, grown special support for many kinds of loops over its history, but its fundamental approach to simple for loops has not changed. When it encounters a loop, it evaluates it, iteration by iteration, until reaching an exit condition — a process that can cause the verifier to mistakenly hit the limit on the number of allowed …
Read original ↗https://lwn.net/Articles/1076121lwn_kernel · tlp:amber · 6/9/2026, 1:03:24 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (bind and libyang), Debian (keystone and openssl), Fedora (mingw-objfw, objfw, sentencepiece, and tailscale), Mageia (packagekit and suricata), Oracle (bind, bind9.16, go-toolset:ol8, ImageMagick, kernel, samba, and vim), SUSE (apache-commons-lang3, apache-commons-text, apache-commons- configuration2, apache-commons-cli, apache-commons-io, apache-commons-codec, avahi, busybox, chromedriver, chromium,…
Read original ↗lwn_kernel · tlp:amber · 6/9/2026, 12:52:58 PM
Linux App Summit 2026 (Heise) Heise is carrying a report from the Linux App Summit , held in Berlin in May. The slightly more than a dozen talks were symbolically framed between the opening keynote by systemd creator Lennart Poettering and the closing talk by Jorge Castro, initiator of the Universal Blue project, from which the modern Linux systems Bluefin and Bazzite emerged. Both Castro and Poettering call for a fundamental rethink of how Linux operating systems are delive…
Read original ↗https://lwn.net/Articles/1077084cisa_alerts · tlp:amber · 6/9/2026, 12:00:00 PM
Siemens KACO Blueplanet Inverters View CSAF Summary KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access. KACO new energy GmbH has released new versions for several affected products and recommends to update to the latest versions. KACO new energy GmbH is preparing further fix versions and recommends countermeasures for products where fixes …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-02cisa_alerts · tlp:amber · 6/9/2026, 12:00:00 PM
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability …
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 6/9/2026, 12:00:00 PM
Schneider Electric EcoStruxure Panel Server View CSAF Summary Schneider Electric is aware of its vulnerability in its EcoStruxure Panel Server offer. The EcoStruxure Panel Server is a high performance, modular gateway with enhanced cybersecurity that provides easy and fast connections to multiple concurrent edge control or cloud applications. Failure to apply the remediations provided below may risk unauthorized authentication, which could lead to access to sensitive informa…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-03cisa_alerts · tlp:amber · 6/9/2026, 12:00:00 PM
Schneider Electric Modicon Network Managed Switches View CSAF Summary Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product. The Modicon Network Managed Switch product provides connectivity for multiple Ethernet devices, network management, enhanced cyber security and more advanced switching features. Failure to apply the mitigation provided below may risk forgery attacks in RADIUS Protocol, which could result in …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-01lwn_kernel · tlp:amber · 6/9/2026, 11:44:19 AM
Three stable kernels for Tuesday Greg Kroah-Hartman has announced the release of the 7.0.12 , 6.18.35 , and 6.12.93 stable kernels. Each contains important fixes throughout the tree. Users are advised to upgrade. Three stable kernels for Tuesday [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Three stable kernels for Tuesday […
Read original ↗https://lwn.net/Articles/1077078huggingface_blog · tlp:amber · 6/9/2026, 10:46:19 AM
How an Agent Built a 3D Paris Gallery by Chaining Two Hugging Face Spaces How an Agent Built a 3D Paris Gallery by Chaining Two Hugging Face Spaces Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign …
Read original ↗https://huggingface.co/blog/mishig/spaces-agents-mdhuggingface_blog · tlp:amber · 6/9/2026, 9:04:58 AM
NeuroBait: I fine-tuned a model to spark dopamine for ADHD brain NeuroBait: I fine-tuned a model to spark dopamine for ADHD brain Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Article…
Read original ↗https://huggingface.co/blog/build-small-hackathon/neurobait-adhdeset · tlp:amber · 6/9/2026, 8:50:00 AM
Cybercriminals: the 'auditors' you never hired Every organisation gets audited. The question is who does the auditing. Cybercriminals: the 'auditors' you never hired Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security resource center WeLiveP…
Read original ↗https://www.welivesecurity.com/en/business-security/cybercriminals-auditors-never-hiredarxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
POISE: Position-Aware Undetectable Skill Injection on LLM Agents arXiv:2606.07943v1 Announce Type: new Abstract: Agent skills provide a lightweight mechanism for extending general-purpose agents, but their open format exposes them to skill-poisoning attacks. A practically dangerous injection must stay invisible: if executing the payload derails the user's legitimate task, the resulting failure signal invites inspection of the skill. We therefore evaluate attacks by Attack Su…
Read original ↗https://arxiv.org/abs/2606.07943arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Quantum-Inspired Reinforcement Learning for Low-Latency Intrusion Detection in V2X and Internet-of-Vehicles Networks arXiv:2606.07804v1 Announce Type: new Abstract: Smart cities increasingly depend on dense edge, IoT, and vehicular networks to deliver critical urban services, including traffic control, connected mobility, infrastructure monitoring, and energy management. In this ecosystem, the Internet of Vehicles (IoV) is central to intelligent transportation, enabling cont…
Read original ↗https://arxiv.org/abs/2606.07804arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
An AI Security Agent for University ACMIS: Multi-Vector Threat Detection and Automated Response arXiv:2606.08270v1 Announce Type: new Abstract: University Academic Management Information Systems (ACMIS) are high-value targets for a wide spectrum of security threats including brute-force login attacks, payment fraud, privilege escalation, insider data theft, and academic integrity violations. Traditional rule-based intrusion detection systems are inadequate because many malic…
Read original ↗https://arxiv.org/abs/2606.08270arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Collective Hallucination in Multi-Agent LLMs:Modeling and Defense arXiv:2606.07941v1 Announce Type: new Abstract: Hallucinations in large language models (LLMs) create heightened risks in multi-agent settings, where recursive agent interactions can propagate, reinforce, and amplify unsupported claims. This paper models hallucination as a system-level, time-evolving process across a network of interacting LLM agents, where nodes represent agents and edges encode information e…
Read original ↗https://arxiv.org/abs/2606.07941arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Ternary public-key cryptosystem arXiv:2606.07832v1 Announce Type: new Abstract: Public-key cryptosystems eliminate the requirement for pre-shared secret keys by enabling encryption with a publicly disclosed key and decryption with a corresponding private key. In this article we generalize the public-key cryptosystems to ternary algebraic structures, with particular attention to ElGamal as a representative family. We introduce the necessary algebraic background for nonderived…
Read original ↗https://arxiv.org/abs/2606.07832arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
RecurGuard: Runtime Monitoring for Reasoning-Token Consumption Attacks arXiv:2606.07968v1 Announce Type: new Abstract: Reasoning-capable large language models can be induced to spend their generation budget on injected decoy tasks rather than answering the user's question, causing denial of service when no final answer is produced and denial of wallet when excess output tokens are billed. Input-side safety classifiers often miss these attacks because the injected prompts can…
Read original ↗https://arxiv.org/abs/2606.07968arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
MOLOT System Card: Malicious Operational Logic Observation Transformer arXiv:2606.07792v1 Announce Type: new Abstract: MOLOT (Malicious Operational Logic Observation Transformer) is a static malicious-code detection system designed for SAST setup where package metadata, maintainer history, and dynamic execution traces may be unavailable or unreliable. The system represents source code as behavior sequences derived from static call graphs, includes an explanation stage that r…
Read original ↗https://arxiv.org/abs/2606.07792arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Belief-Space Quantum-Inspired Reinforcement Learning for Partially Observable Autonomous Cyber Defense in the Internet of Vehicles arXiv:2606.07796v1 Announce Type: new Abstract: The Internet of Vehicles (IoV) faces a dynamic, adversarial security environment where attackers adapt to defenses. Existing intrusion detection systems rely on static classifiers that fail to capture sequential decision-making, attacker adaptation, and uncertainty. We formulate IoV security as a se…
Read original ↗https://arxiv.org/abs/2606.07796arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
ScaleDisturb: Exploiting Temporal Asymmetry to Amplify Read Disturbance in Modern DRAM Chips arXiv:2606.07761v1 Announce Type: new Abstract: DRAM suffers from read disturbance phenomena (e.g., RowHammer and RowPress), where repeatedly accessing or continuously keeping open a DRAM row (aggressor row) induces bitflips in other physically nearby unaccessed rows (victim rows). The disturbance mechanism is practically exploitable from the software stack and worsens across generat…
Read original ↗https://arxiv.org/abs/2606.07761arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Policy Description Language for Authorization using Logic-Based Programming arXiv:2606.08119v1 Announce Type: new Abstract: Recently, with the impossibility of eradicating the vulnerabilities of information systems, we must prepare for the occurrence of the security incident by the multi-layer defense called the Defense-in-Depth strategy. In the multi-layer defense, it is important to authorize accesses in fine-grained granularity to compose each layer effectively, and many …
Read original ↗https://arxiv.org/abs/2606.08119arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Closing the Sim-to-Real Gap: An Evaluation Framework for Autonomous Cyber Defense Configuration of Commercial EDR arXiv:2606.08168v1 Announce Type: new Abstract: Leading commercial endpoint detection and response (EDR) products have shifted from operator-configured rule sets to multi-component systems where autonomous AI components operate alongside, and increasingly in place of, operator-deployed policies. Autonomous defense agents using commercial EDR as their hardening to…
Read original ↗https://arxiv.org/abs/2606.08168arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
The Dodona Protocol: A Living Design Science Experiment in Oracle Design arXiv:2606.08012v1 Announce Type: new Abstract: The oracle problem, broadly understood as the difficulty of reliably incorporating external information into blockchain-based systems, has been widely examined by scholars and practitioners. Recent comparative research has shown that several challenges of modern blockchain oracles, including attributability, accountability, integrity, and query design, mir…
Read original ↗https://arxiv.org/abs/2606.08012arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
AI-Native Closed-Loop Security for 6G-Enabled Cyber-Physical Systems: From Edge Detection to Network-Wide Mitigation arXiv:2606.08173v1 Announce Type: new Abstract: In sixth-generation (6G) networks, billions of cyber-physical systems (CPSs) - autonomous vehicles, smart grids, industrial robots, and remote-surgical equipment - will run over ultra-reliable low-latency slices, collapsing the gap between a remote breach and physical harm to milliseconds, a budget perimeter fire…
Read original ↗https://arxiv.org/abs/2606.08173arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
SHIELD-IDS: Structurally Heterogeneous Ensemble with Integrated Layered Defense for Intrusion Detection Systems arXiv:2606.07716v1 Announce Type: new Abstract: Adversarial attacks pose a serious and growing threat to Machine Learning (ML)-based Intrusion Detection Systems (IDS), where imperceptible perturbations to network flow features can systematically mislead classifiers into accepting malicious traffic as benign. The IDS-Anta framework partially addresses this through Z…
Read original ↗https://arxiv.org/abs/2606.07716arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Model Multiplicity for Adversarial Detection in Small Language Model Training on Edge Devices arXiv:2606.07857v1 Announce Type: new Abstract: The rise of edge-based machine learning has enabled distributed adaptation of language models across mobile and IoT devices, offering privacy preservation and real-time responsiveness. However, distributed fine-tuning of language models on untrusted or heterogeneous edge nodes introduces new vulnerabilities. Compromised or unreliable d…
Read original ↗https://arxiv.org/abs/2606.07857arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
MLingualFC: Evaluating Jailbreak Vulnerabilities in Multilingual Vision-Language Models arXiv:2606.07706v1 Announce Type: new Abstract: Vision-Language Models (VLMs) have demonstrated strong performance across multimodal tasks, yet their safety robustness remains an open challenge. While prior work has shown that structured visual prompts such as flowcharts can effectively jailbreak VLMs, existing studies are largely limited to English-centric settings. In this paper, we int…
Read original ↗https://arxiv.org/abs/2606.07706arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
SoK: Reconstruction Attacks on Synthetic Tabular Data (Insights from Winning the NIST CRC) arXiv:2606.08372v1 Announce Type: new Abstract: Synthetic data is increasingly promoted as a privacy-preserving substitute for releasing sensitive tabular records, yet its central adversarial threat ("reconstruction", the recovery of an individual's hidden attribute values from a synthetic release and a handful of known quasi-identifiers) has been studied only in scattered, hard-to-com…
Read original ↗https://arxiv.org/abs/2606.08372arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Detecting Aimbot Cheaters in MOGs arXiv:2606.07650v1 Announce Type: new Abstract: Multiplayer Online Games have become a multibillion dollar industry in the entertainment sector. However, the presence of cheaters undermines the experience of honest players and devalues the effort of game developers, as it directly affects player retention, competitive integrity, the legitimacy and trustworthiness of a game, and most importantly the overall revenue streams. Among various chea…
Read original ↗https://arxiv.org/abs/2606.07650arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
SGTO-MAS: Secure Gorilla Troops Optimization for Multi-Agent LLM Systems arXiv:2606.07940v1 Announce Type: new Abstract: Multi-agent large language model (LLM) systems offer strong capabilities for complex reasoning and decision-making, yet coordination across agents introduces error propagation, security risks, and inefficient use of resources. Existing methods often rely on heuristic, static strategies and lack a principled mechanism for balancing performance, security, an…
Read original ↗https://arxiv.org/abs/2606.07940arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Quantifying and Defending against the Privacy Risk in Logit-based Federated Learning arXiv:2606.08252v1 Announce Type: new Abstract: Federated learning aims to protect data privacy by collaboratively learning a model without sharing private data among clients. Unlike traditional parameter-based FL methods that exchange model weights or gradients during training, emerging logit-based FL approaches share model outputs (logits) on public data. This strategy promotes model heter…
Read original ↗https://arxiv.org/abs/2606.08252arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Hallucination Cascade: Analyzing Error Propagation in Multi-Agent LLM Systems arXiv:2606.07937v1 Announce Type: new Abstract: Large Language Models (LLMs) generate fluent text but remain vulnerable to hallucinations, producing unsupported, inconsistent, and factually incorrect claims. Most prior work treats hallucination as a static property of isolated outputs. In multi-agent LLM systems, however, responses are exchanged across agents, revised through sequential stages, and…
Read original ↗https://arxiv.org/abs/2606.07937arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
DP4SQL: Differentially Private SQL with Flexible Privacy Policies arXiv:2606.07883v1 Announce Type: new Abstract: The plausible deniability model of differential privacy for single-table datasets is well-understood. However, applying differential privacy to relational databases is much trickier: each application needs flexibility in specifying the pieces of information about an entity, spread across multiple relations, that require plausible deniability guarantees. Existing …
Read original ↗https://arxiv.org/abs/2606.07883arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Beyond Pass/Fail: Using Process Mining to Understand How LLMs Resist (and Fail) Red Team Attacks arXiv:2606.07833v1 Announce Type: new Abstract: Standard AI red teaming evaluations reduce adversarial campaigns to a single binary outcome, attack success rate (ASR), not taking into account the sequential structure of how models resist or yield to attacks. We propose applying process mining, a discipline for discovering and analyzing process models from event logs, to red teami…
Read original ↗https://arxiv.org/abs/2606.07833arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
Demand-Driven Vulnerability Detection for Cloud Security Posture Management: Removing Human Rule Authoring from the Disclosure-to-Protection Critical Path arXiv:2606.07957v1 Announce Type: new Abstract: Cloud Security Posture Management (CSPM) systems detect known vulnerabilities by maintaining a rule set, distributing it to customers, and evaluating it against periodically-collected asset inventories. To our knowledge, in publicly documented architectures the rule set is en…
Read original ↗https://arxiv.org/abs/2606.07957arxiv_cs_cr · tlp:amber · 6/9/2026, 4:00:00 AM
LPOR: A Layered Proof of Reserves Framework for Usable and Publicly Auditable Solvency Verification arXiv:2606.08211v1 Announce Type: new Abstract: Proof of Reserves (PoR) enables centralized crypto exchanges to demonstrate that on-chain reserves are sufficient to cover customer liabilities. However, existing approaches, including Merkle-tree-based proofs and zero-knowledge PoR systems, remain difficult for everyday users to verify in practice, resulting in limited participa…
Read original ↗https://arxiv.org/abs/2606.08211unit42 · tlp:amber · 6/8/2026, 11:00:45 PM
When “Hi, This Is IT” Comes Through Microsoft Teams Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42 . When “Hi, This Is IT” Comes Through Microsoft Teams Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General When “Hi, This Is IT…
Read original ↗https://unit42.paloaltonetworks.com/microsoft-teams-phishingars_security · tlp:amber · 6/8/2026, 6:34:23 PM
For the 2nd time in weeks, Microsoft packages laced with credential stealer 73 packages run self-replicating stealer as soon as they're opened by an AI agent. Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents. In all, multiple researchers said , 73 packages were flagged as malicious when automated systems on GitHu…
Read original ↗https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealermicrosoft_mstic · tlp:amber · 6/8/2026, 4:00:00 PM
AI brands as bait: How threat actors are using the AI hype in social engineering As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog . In this article ChatGPT-themed lure leads to phishing kit collecting credit card data Claude-themed phishin…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineeringlwn_kernel · tlp:amber · 6/8/2026, 3:35:10 PM
[$] An update on fanotify In a filesystem-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , Amir Goldstein updated attendees on the fanotify filesystem-event monitoring subsystem. He wanted to describe changes that had come in the last year or so, as well as upcoming features and some remaining challenges in his efforts to use fanotify for hierarchical storage management (HSM). Fanotify is the user-space API for monitoring files, direct…
Read original ↗https://lwn.net/Articles/1075829