REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 37 of 57
lwn_kernel · tlp:amber · 6/5/2026, 12:56:47 PM
Security updates for Friday Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, ru…
Read original ↗https://lwn.net/Articles/1076605cisa_alerts · tlp:amber · 6/5/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk…
lwn_kernel · tlp:amber · 6/4/2026, 10:22:17 PM
Dave Airlie on Linux Kernel Maintenance (SE Radio) The Software Engineering Radio podcast has put up an interview with graphics maintainer Dave Airlie . Much of what is in there will not be news to LWN readers, but it is an interesting overview of the life of a large-subsystem maintainer. I was talking to a few of the Rust people, and I thought: these are very young people, these are a group of people in their 20s, maybe 30s, they are a younger cohort of developers than the …
Read original ↗https://lwn.net/Articles/1076478ars_security · tlp:amber · 6/4/2026, 8:02:04 PM
Dashlane explains how attackers managed to download encrypted password vaults By targeting large numbers of users, attackers increased their chances of success. Dashlane said that attackers mounted a coordinated hacking campaign against a large base of its users in an attempt to recover as many encrypted password vaults as possible. The password manager provider said fewer than 20 personal user vaults were downloaded before it shut down the operation. In a campaign that sta…
Read original ↗https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaultsmicrosoft_mstic · tlp:amber · 6/4/2026, 7:14:42 PM
Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seven new failure modes, from supply chain compromise to goal hijacking, and the practical mitigations teams need now. The post Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-ushuggingface_blog · tlp:amber · 6/4/2026, 6:57:45 PM
Nemotron 3.5 Content Safety: Customizable Multimodal Safety for Global Enterprise AI Nemotron 3.5 Content Safety: Customizable Multimodal Safety for Global Enterprise AI Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storag…
Read original ↗https://huggingface.co/blog/nvidia/nemotron-3-5-content-safetytalos · tlp:amber · 6/4/2026, 6:00:59 PM
Reporting from Vegas: Networking, AI, and good boys Joe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation. Welcome to this week’s edition of the Threat Source newsletter.  Howdy friends, and hello from Cisco Live U.S., here in sunny (and very hot) Las Vegas!   An interesting quirk of being sent to one of these events is you learn to understand your…
Read original ↗https://blog.talosintelligence.com/reporting-from-vegas-networking-ai-and-good-boyslwn_kernel · tlp:amber · 6/4/2026, 4:22:46 PM
[$] Splicing out vmsplice() The splice() and vmsplice() system calls are meant to improve performance for certain data-movement tasks by minimizing (or avoiding altogether) system calls and the copying of data. They also have a long history of security problems. The recent flood of LLM-discovered vulnerabilities has drawn attention, once again, to splice() and vmsplice() ; as a result, they may end up being removed altogether.
Read original ↗https://lwn.net/Articles/1075838lwn_kernel · tlp:amber · 6/4/2026, 2:53:00 PM
One step forward, two steps back on CA age bill (EFF Deeplinks Blog) The EFF has a blog post looking at a new bill in California that would exempt open-source operating systems from the Digital Age Assurance Act passed last year, but has problems of its own: While the open source exemption, if passed, would improve the law, the remaining amendments proposed by AB 1856 would require all web browsers and websites to request and collect users' ages. This is an expansion of last…
Read original ↗https://lwn.net/Articles/1076377lwn_kernel · tlp:amber · 6/4/2026, 1:17:19 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), Debian (ceph and sudo), Fedora (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), Mageia (lxc), Oracle (expat, gnutls, kernel, php:8.2, thunderbird, and uek-kernel), Slackware (httpd, net, proftpd, tigervnc, and xorg), SUSE (apache-sshd, app…
Read original ↗https://lwn.net/Articles/1076364huggingface_blog · tlp:amber · 6/4/2026, 12:24:58 PM
EVA-Bench Data 2.0: 3 Domains, 121 Tools, 213 Scenarios EVA-Bench Data 2.0: 3 Domains, 121 Tools, 213 Scenarios Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles EVA-Bench Data 2…
Read original ↗https://huggingface.co/blog/ServiceNow-AI/eva-bench-datatalos · tlp:amber · 6/4/2026, 12:05:31 PM
Winning the cyber marathon with Tony Giandomenico Tony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons. In the high-speed world of cybersecurity, the difference between a breach and a breakthrough often comes down to endurance. Tony Giandomenico, Senior Director of Product Management with Cisco Talos, joins me to discuss h…
Read original ↗https://blog.talosintelligence.com/winning-the-cyber-marathon-with-tony-giandomenicotalos · tlp:amber · 6/4/2026, 12:05:05 PM
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds. By Ron Scott-Adams Most security tools operate on a simple principle: If a known-bad pattern appears, fire an alert. This works well enough for many threats, but it fails against adversaries who closely stu…
Read original ↗https://blog.talosintelligence.com/hypotheses-telemetry-and-human-judgment-inside-cisco-talos-threat-huntingcisa_alerts · tlp:amber · 6/4/2026, 12:00:00 PM
NAVTOR NavBox View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to gain unauthorized access to SOAP methods, resulting in a disruption of operations. The following versions of NAVTOR NavBox are affected: NavBox 4.16.1.20 (CVE-2026-21404) CVSS Vendor Equipment Vulnerabilities v3 6.3 NAVTOR NAVTOR NavBox Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-01cisa_alerts · tlp:amber · 6/4/2026, 12:00:00 PM
B&R PPT30 Operating System View CSAF Summary B&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product inaccessible. The following versions of B&R PPT30 Operating System are affected: PPT30 Operating System <1.8.0, 1.8.0 (CVE-2025-11482) CVSS Vendor Equipment Vulnerabilities v3 7.5 B&R Industrial Automation GmbH B&R PPT30 O…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03cisa_alerts · tlp:amber · 6/4/2026, 12:00:00 PM
Hitachi Energy ITT600 Explorer View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. The vulnerabilities only affect Hitachi Energy Integrated Testing Tool ITT600 SA Explorer without affecting IEC 61850 system endpoints. Please refer to the Recommended Immediate Actions for information about the mitiga…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-02cisa_alerts · tlp:amber · 6/4/2026, 12:00:00 PM
Hitachi Energy RTU500 View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. If exploited, these vulnerabilities primarily impact product availability, with potential secondary impacts on confidentiality and integrity. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy RTU500 are affected: RTU500 series CMU Firmware vers…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04cisa_alerts · tlp:amber · 6/4/2026, 12:00:00 PM
Hitachi Energy MACH HiDraw View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects MACH HiDraw product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following v…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-05chainalysis · tlp:amber · 6/4/2026, 11:55:25 AM
The $100 Million Crypto “Looksmaxxing” Boom: How Chinese Cartel Suppliers Pivoted to the Gray-Market Peptide Ecosystem Summary A $100 Million Shadow Economy: The on-chain gray-market peptide industry has experienced a breakout, surging past a $100 million… The post The $100 Million Crypto “Looksmaxxing” Boom: How Chinese Cartel Suppliers Pivoted to the Gray-Market Peptide Ecosystem appeared first on Chainalysis . Inside the $100M Gray Market Peptide Crypto Boom - Chai…
Read original ↗https://www.chainalysis.com/blog/gray-market-peptide-crypto-boomlwn_kernel · tlp:amber · 6/4/2026, 1:31:14 AM
[$] LWN.net Weekly Edition for June 4, 2026 Inside this week's LWN.net Weekly Edition: Front : MeshCore; x32 ABI; Open-source security; Package-manager metadata; More LSFMM+BPF coverage; Loadable crypto module. Briefs : Lightwell; jqwik protestware; RedHat package compromise; DistroWatch; Fedora election; Rust 1.96.0; rsync; Vim Classic 8.3; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1074950snyk_blog · tlp:amber · 6/4/2026, 12:00:00 AM
So You Have an AI Security Budget. Now what? An AI security budget should fund more than visibility. The real priority is unified governance and enforcement across agentic development and production apps. So You Have an AI Security Budget. Now What? | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applications DeepCode AI…
Read original ↗https://snyk.io/blog/ai-security-budgetsnyk_blog · tlp:amber · 6/4/2026, 12:00:00 AM
Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers. Node-gyp Supply Chain Compromise | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in…
Read original ↗https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gypsnyk_blog · tlp:amber · 6/4/2026, 12:00:00 AM
Type Level Security: The future of secure AI code generation? Secure-by-design types can turn common bugs into compile-time errors. This post explores how type-level security could help prevent entire classes of AI-generated vulnerabilities. Type Level Security for Secure AI Code Generation | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven wo…
Read original ↗https://snyk.io/blog/type-level-securityhuggingface_blog · tlp:amber · 6/4/2026, 12:00:00 AM
Designing the hf CLI as an agent-optimized way to work with the Hub Designing the hf CLI as an agent-optimized way to work with the Hub Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to A…
Read original ↗https://huggingface.co/blog/hf-cli-for-agentsars_security · tlp:amber · 6/3/2026, 7:53:14 PM
Can't make sense of Dashlane's vault theft notification? You're not alone. Security advisory leaves out key details. Dashlane maintains complete silence. There’s a lot that doesn’t add up in a security advisory password manager Dashlane published Monday, warning that attackers managed to obtain 20 encrypted user vaults. “Starting on Sunday, May 31, 2026, an external party launched a brute force attack against certain Dashlane user accounts,” the company said . “The goal of …
Read original ↗https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolenlwn_kernel · tlp:amber · 6/3/2026, 3:02:35 PM
[$] Open-source security is not a solo activity Over time, many open-source maintainers face the same problem: they lack the time to do all of the work that their project needs, and no one else is stepping up to provide adequate help. Maintainers, though, are often reluctant to throw in the towel. The result is suboptimal all around; the maintainer is stressed out, project quality suffers, and users face security risks that they may not be fully aware of. At the 2026 Open So…
Read original ↗https://lwn.net/Articles/1075741checkpoint_research · tlp:amber · 6/3/2026, 1:21:44 PM
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, because official project sites tend to rank highest and appear near the top of the results. After landing on a site with a professional design and […] The post Impersonation, Click Hijacking, and …
Read original ↗https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystemlwn_kernel · tlp:amber · 6/3/2026, 1:14:39 PM
[$] BPF in the agentic era Alexei Starovoitov gave " less of a presentation, more of a scream of realization " at the BPF track of the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit . He shared a set of ideas for how BPF could change to avoid being swept away by the sea-change in programming represented by modern large language models (LLMs) and the coding agents based on them. In a follow-up session, the discussion covered more problems with how coding ag…
Read original ↗https://lwn.net/Articles/1075067lwn_kernel · tlp:amber · 6/3/2026, 1:00:46 PM
Tridgell: rsync and outrage Andrew Tridgell has written a blog post responding to complaints that he has begun using LLM tools in his work maintaining rsync : Like many developers of open source packages I've been hit by a flood of security reports lately in my role as the rsync maintainer. Many of those reports are AI generated (not all though, there are some notable ones with very careful and high quality manual analysis). As this flood started to get more intense I realis…
Read original ↗https://lwn.net/Articles/1076040lwn_kernel · tlp:amber · 6/3/2026, 12:59:17 PM
Security updates for Wednesday Security updates have been issued by Debian (php-twig), Fedora (hplip, python-wsgidav, roundcubemail, and xorg-x11-server), Oracle (compat-openssl10, httpd:2.4, and kernel), Red Hat (osbuild-composer), SUSE (busybox, cloudflared, cockpit, cups, ffmpeg-4, gnutls, google-osconfig-agent, helm, hplip, kernel, kubelogin, libjxl, libsoup, libunbound8, LibVNCServer-devel, mapserver, nvidia-open-driver-G06-signed, nvidia-open-driver-G07-signed, openssh…
Read original ↗https://lwn.net/Articles/1076117huggingface_blog · tlp:amber · 6/3/2026, 12:55:11 PM
Direct Preference Optimization Beyond Chatbots Direct Preference Optimization Beyond Chatbots Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Direct Preference Optimization Bey…
Read original ↗https://huggingface.co/blog/Dharma-AI/direct-preference-optimization-beyond-chatbotscisa_alerts · tlp:amber · 6/3/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Red…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalogchainalysis · tlp:amber · 6/3/2026, 11:55:38 AM
Agentic Payments Cross the Threshold: Inside x402’s Path to Meaningful Adoption This blog is a preview of our report, “The New Rails: How Digital Assets Are Reshaping the Foundations of Finance.”… The post Agentic Payments Cross the Threshold: Inside x402’s Path to Meaningful Adoption appeared first on Chainalysis . Inside x402: 100M Agentic Payments on Base - Chainalysis Chainalysis Products Crypto Investigations Investigations Solutions Reactor Investiga…
Read original ↗https://www.chainalysis.com/blog/x402-agentic-payments-adoptiontrail_of_bits · tlp:amber · 6/3/2026, 11:00:00 AM
The sorry state of skill distribution Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of tools designed to detect malicious skills before they’re installed. But we tested them, and they don’t work. We recently bypassed ClawHub’s malicious skill detector , Cisco’s agent skill scanner , and all three of the scanners…
Read original ↗https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distributioneset · tlp:amber · 6/3/2026, 8:50:00 AM
Lessons for life: Why children’s data is a long-term identity risk Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe. Lessons for life: Why children’s data is a long-term identity risk Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White paper…
Read original ↗https://www.welivesecurity.com/en/kids-online/lessons-life-childrens-data-long-term-identity-riskmicrosoft_mstic · tlp:amber · 6/3/2026, 4:45:06 AM
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaignchainalysis · tlp:amber · 6/3/2026, 12:38:00 AM
OFAC Sanctions Nobitex and Major Iranian Cryptocurrency Exchanges in Sweeping Evasion Crackdown Summary The Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated four major Iranian cryptocurrency exchanges: Nobitex, Bitpin,… The post OFAC Sanctions Nobitex and Major Iranian Cryptocurrency Exchanges in Sweeping Evasion Crackdown appeared first on Chainalysis . OFAC Sanctions Nobitex and Iranian Cryptocurrency Exchanges Chainalysis Products Cry…
Read original ↗https://www.chainalysis.com/blog/ofac-sanctions-iranian-crypto-exchanges-june-2026snyk_blog · tlp:amber · 6/3/2026, 12:00:00 AM
The New Security Risks of the Agentic Development Lifecycle AI agents are changing how software gets built, and with it, where security risk begins. Learn why securing the process matters as much as securing the code. The New Security Risks of Agentic Development | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applicatio…
Read original ↗https://snyk.io/blog/agentic-development-lifecyclehuggingface_blog · tlp:amber · 6/3/2026, 12:00:00 AM
Adding MCP Tools to Reachy Mini Adding MCP Tools to Reachy Mini Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Adding MCP Tools to Reachy Mini Published June 3, 2026 Update on…
Read original ↗https://huggingface.co/blog/adding-mcp-tools-to-reachy-minilwn_kernel · tlp:amber · 6/2/2026, 6:35:52 PM
[$] Caching for extended attributes Extended attributes (xattrs) provide a way to attach key/value metadata to inodes—files, directories, and the like—in a filesystem. As with many Linux filesystems, the FUSE filesystem supports xattrs. In a filesystem-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , FUSE maintainer Miklos Szeredi led a discussion about caching xattrs in kernel memory; he would like to create some common infrastructure…
Read original ↗https://lwn.net/Articles/1074919