REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 36 of 57
checkpoint_research · tlp:amber · 6/8/2026, 2:47:59 PM
8th June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked exfiltrated data. Analysts assessed that 2.6 million accounts were exposed, including names, emails, […] The post 8th June – Threat Intelligence Report app…
Read original ↗https://research.checkpoint.com/2026/8th-june-threat-intelligence-reportlwn_kernel · tlp:amber · 6/8/2026, 2:23:23 PM
rsync 3.4.4 released with regression fixes Andrew Tridgell has announced the release of rsync 3.4.4 with fixes for the regressions introduced in the 3.4.3 release. He also notes there will be an rsync 3.5.0 soon, with many more security updates: As part of the 3.5.0 release update I have created a rsync-security@lists.samba.org mailing list for anyone who is willing to do testing of the 3.5.0 release. The idea is to try to reduce the chance of more regressions by expanding t…
lwn_kernel · tlp:amber · 6/8/2026, 1:32:33 PM
Security updates for Monday Security updates have been issued by AlmaLinux (bind, bind9.16, frr, kernel, kernel-rt, libexif, mysql, php, and unbound), Debian (apache2, chromium, glibc, gsasl, jackson-core, libxml2, nginx, request-tracker4, request-tracker5, tomcat10, tomcat11, and tomcat9), Fedora (chromium, firefox, haveged, keylime, libinput, libssh2, nasm, perl-CryptX, rust, thunderbird, and webkitgtk), Mageia (cockpit, golang-x-crypto, golang-x-sys-devel, kernel, kmod-vi…
Read original ↗https://lwn.net/Articles/1076983huggingface_blog · tlp:amber · 6/8/2026, 1:10:48 PM
The crash that vanished: control and emergence in a five-model economy The crash that vanished: control and emergence in a five-model economy Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Bac…
Read original ↗https://huggingface.co/blog/build-small-hackathon/thousand-token-wood-sim-v3cisa_alerts · tlp:amber · 6/8/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. …
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/08/cisa-adds-two-known-exploited-vulnerabilities-catalogarxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Blockchain Infrastructure for Intelligent Cyber--Physical--Social Systems:Post-Quantum Security, Interoperability, and Trustworthy Data Economies in the Era of Embodied AI arXiv:2606.06895v1 Announce Type: new Abstract: The deployment of embodied artificial intelligence via world-model-based robotics presents a transformative opportunity for blockchain infrastructure, establishing urgent demand for trustworthy data provenance, cross-organizational governance, and incentive-c…
Read original ↗https://arxiv.org/abs/2606.06895arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
FDM: A Framework for Decision-making to build ML-based Malware detection systems arXiv:2606.06894v1 Announce Type: new Abstract: Selecting appropriate machine learning (ML) configurations for malware detection is a complex, multi-criteria problem. Model choice, feature engineering, and update mechanisms must jointly satisfy operational constraints that vary across deployment contexts. This paper proposes the Framework for Decision-making (FDM) to build ML-based malware detec…
Read original ↗https://arxiv.org/abs/2606.06894arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
DPAgent-in-the-Middle: Agentic Defense and Repair Against AI-Groomed Deceptive Patterns arXiv:2606.06914v1 Announce Type: new Abstract: Privacy deceptive patterns in web interfaces systematically manipulate users into disclosing personal data, yet existing defenses are fragmented, static, and increasingly vulnerable to manipulation by large language models. Moreover, data voids, areas of information scarcity within the web ecosystem, create fertile ground for adversaries to …
Read original ↗https://arxiv.org/abs/2606.06914arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
On the Incentive Compatibility of Block Propagation in Bitcoin arXiv:2606.06860v1 Announce Type: new Abstract: Bitcoin is permissionless and does not rely on any central administrator, which gives it strong censorship resistance. At the same time, it is important to incentivize miners to behave in ways that align with the interests of the system as a whole. This paper asks whether miners are individually incentivized to propagate blocks, one of the most fundamental processes…
Read original ↗https://arxiv.org/abs/2606.06860arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
HAVE: Host Active Verification Engine for Closing the Contextual Reality Gap in Security Digital Twins arXiv:2606.06968v1 Announce Type: new Abstract: Security Digital Twins (SDTs) provide continuously updated virtual replicas of infrastructure for threat simulation, yet they rely on theoretical CVSS scores to assign lateral-movement probabilities -- creating the Contextual Reality Gap: risk is overestimated where unacknowledged mitigations neutralize exploits, and drastical…
Read original ↗https://arxiv.org/abs/2606.06968arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Verifiable and Confidential DNN Inference on Low-End Edge Devices arXiv:2606.07470v1 Announce Type: new Abstract: Deploying deep neural network (DNN) inference on low-end edge devices raises two key challenges: protecting model confidentiality against a potentially compromised edge system and enabling verifiable inference without incurring prohibitive overhead. Existing approaches either house partial models and inference software within trusted execution environments (TEEs)…
Read original ↗https://arxiv.org/abs/2606.07470arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
The Sound of Malware: A Memory Forensics Approach for Android Malware Analysis via Audio Signals arXiv:2606.07005v1 Announce Type: new Abstract: Android malware analysis is currently facing increasing challenges in achieving robust classification and detecting stealth attacks. Modern threats employ advanced evasion strategies such as code obfuscation, dynamic loading, packing, and even steganographic manipulation of traditional static and dynamic features. These techniques r…
Read original ↗https://arxiv.org/abs/2606.07005arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
AMD-FCG: An Enhanced Function Call Graph Dataset with Integrated Topological Features for Malware Detection and Classification arXiv:2606.06815v1 Announce Type: new Abstract: As malware illustrates a complex structure and behavior, detection of these has been a significant challenge in the domain of cybersecurity along with related services in daily life. So, it becomes crucial to have a reliable and adaptive solution to address the issue. Among the several detection methods…
Read original ↗https://arxiv.org/abs/2606.06815arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
What Your Posts Reveal: A Benchmark and Agentic Framework for User-Level Privacy Leakage on Social Media arXiv:2606.06784v1 Announce Type: new Abstract: Public social media posts can reveal private information through weak cues scattered across text, images, or metadata. Such leakage is often cumulative and cross-post: cues that appear harmless in isolation may jointly expose a user's home, workplace, or routine. However, current research lacks a unified benchmark for user-l…
Read original ↗https://arxiv.org/abs/2606.06784arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
The Custody Envelope Threshold: Authority-Scaled Admission of External Artifacts in Institutional Infrastructure arXiv:2606.06767v1 Announce Type: new Abstract: Modern infrastructure depends on externally maintained artifacts such as package-registry dependencies, CI/CD actions, container images, Terraform providers and modules, developer extensions, model artifacts, and AI tool servers. These artifacts are easy to fetch but difficult for institutions to admit, govern, and r…
Read original ↗https://arxiv.org/abs/2606.06767arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Fast Bounded-Independence Functions and Their Duals arXiv:2606.07009v1 Announce Type: new Abstract: We continue the study of {\em fast} functions, computable by linear-size circuits, that share useful properties of random functions. Motivated by cryptographic applications, we generalize and improve on previous results in this area, obtaining the following results: - For any constant $t$, we construct a fast $t$-wise independent hash function with algebraic degree $\log_2 t$ …
Read original ↗https://arxiv.org/abs/2606.07009arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
AgileOS: A GPU Operating System Layer for Protected CUDA Services arXiv:2606.06697v1 Announce Type: new Abstract: Modern GPU applications increasingly interact with storage systems, network devices, vendor libraries, and GPU-resident services rather than executing only isolated compute kernels. This shift creates a need for operating-system-like protection around GPU services, where service metadata, device queues, memory-mapped I/O regions, and library-internal state should…
Read original ↗https://arxiv.org/abs/2606.06697arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Lost in Migration: Exposing Android Framework Vulnerabilities in Parallel Java-Kotlin Implementations arXiv:2606.07420v1 Announce Type: new Abstract: Android has adopted Kotlin alongside Java across apps and core system components. During this shift, we observe parallel implementations in the Android Open Source Project (AOSP) where the same component is implemented in both Java and Kotlin. In principle, their functional purposes are identical. In practice, subtle semantic d…
Read original ↗https://arxiv.org/abs/2606.07420arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
MalTree: Tracing Malware Evolution from Embeddings at Scale arXiv:2606.06570v1 Announce Type: new Abstract: Malware detection remains largely reactive: machine learning models trained on known samples degrade as threats evolve. Understanding evolutionary relationships among malware families can inform proactive defense, but traditional reverse engineering can take months to years to uncover such lineage relationships. We propose MalTree, a framework that applies bioinformati…
Read original ↗https://arxiv.org/abs/2606.06570arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Subtle Injection for Ground-truth Inference of LLM Training Data arXiv:2606.06502v1 Announce Type: new Abstract: As large language models (LLMs) are increasingly trained on scraped web corpora without authorisation, content owners require forensic methods to prove that their documents were included in a model's training set. We propose \textbf{SIGIL} (\textbf{S}ubtle \textbf{I}njection for \textbf{G}round-truth \textbf{I}nference of \textbf{L}LM training data), a framework t…
Read original ↗https://arxiv.org/abs/2606.06502arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
MalSkillBench: A Runtime-Verified Benchmark of Malicious Agent Skills arXiv:2606.07131v1 Announce Type: new Abstract: AI coding agents such as Claude Code and Gemini CLI increasingly extend themselves with third-party skills: markdown packages bundling natural-language instructions, executable scripts, and tool permissions. Because a skill is at once code and agent-facing instruction, it introduces a supply chain dependency whose risk is neither pure code nor pure prompt. De…
Read original ↗https://arxiv.org/abs/2606.07131arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Enhancing Malware Detection with Generative AI: Using Variational Autoencoders to Boost Machine Learning Classifiers' Performance arXiv:2606.06501v1 Announce Type: new Abstract: The advancement of malware poses obstacles for cybersecurity, necessitating the development of advanced detection techniques. This paper proposes an approach to enhance malware detection through the use of a generative artificial intelligence model. Specifically, variational autoencoders (VAEs) are u…
Read original ↗https://arxiv.org/abs/2606.06501arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
From Privacy to Workflow Integrity: Communication-Graph Metadata in Autonomous Agent Interoperability arXiv:2606.07150v1 Announce Type: new Abstract: Agent-interoperability protocols such as A2A and MCP standardize what agents say to one another, but assume address-based transport over HTTP(S). Such transports protect message content, increasingly with end-to-end encryption. What they leave in the clear is the communication graph: which agent contacts which, when, and how of…
Read original ↗https://arxiv.org/abs/2606.07150arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Synthetic APTs: the Collapse of TTP-Based Attribution arXiv:2606.07158v1 Announce Type: new Abstract: Cyber Threat Intelligence CTI attribution relies on identifying the Tactics, Techniques, and Procedures TTPs that distinguish one threat actor from another. This approach presupposes that each adversary leaves a recognizable operational fingerprint. This work investigates whether AI driven adversary emulation challenges that presupposition. We deploy agents from our Cybersec…
Read original ↗https://arxiv.org/abs/2606.07158arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Rethinking IoT Intrusion Detection: Augmenting Routing Metrics with Radio Features arXiv:2606.07282v1 Announce Type: new Abstract: Machine learning-based intrusion detection systems (IDS) for RPL-based IoT networks often rely solely on routing layer features, which provide only a partial view of network behaviour. In this work, we investigate whether incorporating Transmit (TX) and Receive (RX) radio features alongside the standard RPL feature set can improve detection perfo…
Read original ↗https://arxiv.org/abs/2606.07282arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Authorized and Verifiable Searchable Encryption Based on Public Key Equality Test for Cloud Storage arXiv:2606.07319v1 Announce Type: new Abstract: Cloud storage revolutionizes data management but raises conflicts between functionality and privacy. Public Key Encryption with Equality Test (PKEET), an advanced cryptographic technique, can enable multi-user searchable encryption (SE) through cross-key ciphertext comparison without shared keys. However, existing PKEET-based SE …
Read original ↗https://arxiv.org/abs/2606.07319arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Defending Jailbreak Attacks on Large Language Models via Manifold Trajectory Kinetics arXiv:2606.07335v1 Announce Type: new Abstract: Jailbreak prompts can bypass alignment guardrails in large language models (LLMs) and elicit unsafe outputs, making reliable deployment-time detection critical. Prior detection approaches largely rely on a fixed metric space, e.g., raw inputs, gradients, or hidden features, in which benign and jailbreak prompts are linearly separable. We show …
Read original ↗https://arxiv.org/abs/2606.07335arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Online Safety Regulation Increases Privacy Risk: Evidence from the UK Online Safety Act arXiv:2606.05273v1 Announce Type: cross Abstract: Governments worldwide are increasingly regulating digital platforms to reduce online harms, particularly those affecting children. However, access restrictions can alter user behaviour and introduce new privacy and security risks. The UK Online Safety Act (OSA), passed in October 2023, illustrates this trend: it extends age-assurance and s…
Read original ↗https://arxiv.org/abs/2606.05273arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Empirical Evaluation of Large Language Models for Migration of Code Fragments to Post-Quantum Cryptography arXiv:2606.07341v1 Announce Type: new Abstract: The transition to post-quantum cryptography (PQC) requires not only replacing vulnerable cryptographic primitives, but also refactoring the surrounding software logic. While existing PQC migration frameworks provide organizational guidance, practical code-level remediation remains largely manual and error-prone. This paper…
Read original ↗https://arxiv.org/abs/2606.07341arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
On the Shoulders of Giants: Empowering Automated Smart Contract Auditing via the GiAnt Corpus arXiv:2606.07363v1 Announce Type: new Abstract: High-quality smart contract auditing datasets are crucial for evaluating security tools and advancing smart contract security research. Two major limitations of existing datasets are the manual-induced scalability bottleneck and the deficiency in data granularity and diversity. To address these limitations, we propose GiANT, an automat…
Read original ↗https://arxiv.org/abs/2606.07363lwn_kernel · tlp:amber · 6/8/2026, 12:28:06 AM
Kernel prepatch 7.1-rc7 The 7.1-rc7 kernel prepatch is out for testing. Linus said: " Anyway, as things look now this is the last rc. Something can obviously always come up and force us to change that, but please give rc7 a whirl and keep testing for one more week. " Kernel prepatch 7.1-rc7 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe…
Read original ↗https://lwn.net/Articles/1076835trend_micro · tlp:amber · 6/8/2026, 12:00:00 AM
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exploited entry point open long after the fix ships. Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open | Trend Micro (US) search close About Mission and Culture …
Read original ↗https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.htmlhuggingface_blog · tlp:amber · 6/8/2026, 12:00:00 AM
The Open Source Community is backing OpenEnv for Agentic RL The Open Source Community is backing OpenEnv for Agentic RL Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles The Open…
Read original ↗https://huggingface.co/blog/openenv-agentic-rlhuggingface_blog · tlp:amber · 6/7/2026, 7:44:27 PM
Amazing Digital Dentures (a failed project) Amazing Digital Dentures (a failed project) Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Amazing Digital Dentures (a failed proje…
Read original ↗https://huggingface.co/blog/build-small-hackathon/amazingdigitaldenturesars_security · tlp:amber · 6/5/2026, 9:00:29 PM
How a USB-connected speaker can infect a PC without ever being touched Seller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability. Operating system makers take many steps to prevent their wares from accepting commands from remote devices. The safeguards, designed to thwart malicious attacks, typically require hackers to jump through all kinds of hoops to bypass the measures. But what if remote code execution were as simple as being within Bluetooth…
Read original ↗https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devicesmicrosoft_mstic · tlp:amber · 6/5/2026, 4:46:47 PM
Securing CI/CD in an agentic world: Claude Code Github action case Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows. The post Securing CI/CD in an agentic world: Claude Code Github action case appeared first on Mic…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-caselwn_kernel · tlp:amber · 6/5/2026, 2:06:43 PM
[$] Moving beyond fork() + exec() Since the earliest days of Unix, two of the core process-oriented system calls have been fork() , which creates a child process as a copy of the parent, and exec() , which runs a new program in the place of the current one. In Linux kernels, those system calls are better known as clone() and execve() , but the core functionality remains the same. While there is elegance to this process-creation model, there are shortcomings as well. A recent…
Read original ↗https://lwn.net/Articles/1076018unit42 · tlp:amber · 6/5/2026, 2:05:42 PM
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42 . Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center High Profile Threats Vulnerabilities Vulnerabilities Threat Brief: Active Exploitation of PAN-…
Read original ↗https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257mandiant · tlp:amber · 6/5/2026, 2:00:00 PM
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United Stat…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firmslwn_kernel · tlp:amber · 6/5/2026, 12:57:00 PM
Ruby's Bundler adds a cooldown feature Version 4.0.13 of Ruby's Bundler package-manager has added dependency cooldowns in order to help mitigate the effect of supply-chain attacks: Most supply-chain attacks against RubyGems exploit a narrow window: an account is compromised, a malicious version ships, and any bundle install in the minutes that follow resolves straight to it. Bundler 4.0.13 introduces cooldown, a time-based filter that refuses to resolve to a version unt…
Read original ↗https://lwn.net/Articles/1076526