REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 39 of 57
checkpoint_research · tlp:amber · 6/1/2026, 2:43:11 PM
1st June – Threat Intelligence Report For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Carnival Corporation, a global cruise line operator, has confirmed a data breach affecting nearly 6 million people after attackers used social engineering to compromise an employee account. Exposed information may include names, contact […] The post 1st June – Threat Intelligence Report a…
Read original ↗https://research.checkpoint.com/2026/1st-june-threat-intelligence-reportlwn_kernel · tlp:amber · 6/1/2026, 2:39:35 PM
DistroWatch turns 25 The DistroWatch site is celebrating its 25th anniversary . " All in all, it has been an incredible ride. Many of you who read these pages regularly know that downloading and testing distributions is a highly addictive pastime. I have been an avid distro-hopper for the last 25 years and I don't see myself abandoning this activity for many more years to come. " Congratulations to Ladislav Bodnar and all the others who have kept that resource going for so l…
lwn_kernel · tlp:amber · 6/1/2026, 2:22:19 PM
[$] Reconsidering x32 — again The x32 ABI was meant to be the best of both worlds, providing the expanded registers and instruction set of the x86-64 architecture while preserving the lower memory use of 32-bit systems. The Linux kernel has supported x32 since the 3.4 release in 2012. The initial excitement around x32 did not last, though, and kernel developers are considering removing that support — and not for the first time. Even the most unloved features tend to have a f…
Read original ↗https://lwn.net/Articles/1074897lwn_kernel · tlp:amber · 6/1/2026, 2:05:04 PM
Multiple redhat-cloud-services npm packages compromised (StepSecurity Blog) StepSecurity is reporting that a number of npm packages in the @redhat-cloud-services scope include malware that runs automatically on every npm install : The payload is a multi-stage credential harvester that sweeps GitHub Actions secrets along with AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm, and CircleCI tokens, and it is purpose-built to evade detection, including an explicit attempt to byp…
Read original ↗https://lwn.net/Articles/1075742huggingface_blog · tlp:amber · 6/1/2026, 1:51:18 PM
Beyond LLMs: Why Scalable Enterprise AI Adoption Depends on Agent Logic Beyond LLMs: Why Scalable Enterprise AI Adoption Depends on Agent Logic Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up B…
Read original ↗https://huggingface.co/blog/ibm-research/agent-logic-and-scalable-ai-adoptionlwn_kernel · tlp:amber · 6/1/2026, 1:20:00 PM
Fedora F44 election interviews published The Fedora Project has published interviews with candidates running for the open seats on the Fedora Council , Fedora Engineering Steering Committee , Fedora Mindshare Committee , and EPEL Steering Committee . Voting is open through Friday, June 12 at 23:59 UTC. Fedora F44 election interviews published [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FA…
Read original ↗https://lwn.net/Articles/1075736lwn_kernel · tlp:amber · 6/1/2026, 1:04:09 PM
Security updates for Monday Security updates have been issued by AlmaLinux (.NET 10.0, .NET 9.0, firefox, flatpak, httpd, and thunderbird), Debian (chromium, corosync, cyborg, dovecot, exim4, git-lfs, imagemagick, kernel, keystone, linux-6.1, php-twig, python-aiohttp, sentry-python, swift, and symfony), Fedora (chromium, djvulibre, docker-compose, giflib, haveged, libsoup3, libssh2, mingw-objfw, netatalk, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more,…
Read original ↗https://lwn.net/Articles/1075733cisa_alerts · tlp:amber · 6/1/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2024-21182 Oracle WebLogic Server Unspecified Vulnerability This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of …
Read original ↗https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-cataloghuggingface_blog · tlp:amber · 6/1/2026, 4:44:55 AM
Welcome NVIDIA Cosmos 3: The First Open Omni-model for Physical AI Reasoning and Action Welcome NVIDIA Cosmos 3: The First Open Omni-model for Physical AI Reasoning and Action Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints …
Read original ↗https://huggingface.co/blog/nvidia/cosmos-3-for-physical-aiarxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
LLM Anonymization Against Agentic Re-Identificatio arXiv:2605.30848v1 Announce Type: new Abstract: Agentic LLMs with web search change the threat model for text anonymization: weak contextual cues can become cross-referenceable evidence for re-identification, yet those same details also carry downstream analytic value of the text. Existing defenses either remove explicit identifiers, perturb text for formal privacy, or test rewritten text against non-web inference models, le…
Read original ↗https://arxiv.org/abs/2605.30848arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking arXiv:2605.30883v1 Announce Type: new Abstract: The rise of LLM agents introduces a new threat by enabling planning, coding, and even end-to-end execution of expert-level attack workflows. However, this threat remains underexplored and underestimated since (i) safety alignment prevents LLMs from directly generating harmful instructions, and (ii) most existing jailbreak methods cannot consistently induce agents to …
Read original ↗https://arxiv.org/abs/2605.30883arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
A Core-Structure-Based Automated Analysis Tool for Commercial Virtualization Obfuscation Deobfuscation arXiv:2605.30902v1 Announce Type: new Abstract: Virtualization obfuscation is a more powerful obfuscation technique compared to other obfuscation methods, and as it is increasingly being applied to malware, it demands significant effort and time from analysts. This study analyzes virtualization obfuscation and proposes a tool called VMPredator that automatically extracts se…
Read original ↗https://arxiv.org/abs/2605.30902arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors arXiv:2605.30614v1 Announce Type: new Abstract: With the rise of AI-generated audio, watermarking has become widely used for detecting misuse and protecting intellectual property. However, adversaries may try to remove these watermarks, making it critical to evaluate how well watermarking schemes withstand removal attacks. Existing attacks are often impractical: they either noticeably degrade perceptual qu…
Read original ↗https://arxiv.org/abs/2605.30614arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
CacheProbe: Auditing Prompt Cache Isolation in Gateway APIs arXiv:2605.30613v1 Announce Type: new Abstract: Over the past year, prompt caching in Large Language Models (LLMs) has become increasingly more popular across inference APIs. Prompt caching helps save precious compute resources and speeds up response times by reusing parts of the KV cache of a specific prompt for another request. However, many implementations of prompt caching are not secure against timing attacks o…
Read original ↗https://arxiv.org/abs/2605.30613arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
An Organization-Scoped LLM Agent Runtime Architecture for Regulated Cybersecurity Operations arXiv:2605.30604v1 Announce Type: new Abstract: Regulated cybersecurity workflows lack a runtime substrate that enforces organization-level scope across retrieval, tool calls, memory, findings, reports, and audit while remaining model-agnostic and locally deployable. Recent large language model (LLM) agent systems report strong results on isolated cybersecurity tasks, yet they do not…
Read original ↗https://arxiv.org/abs/2605.30604arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
AdvScene: Rethinking Adversarial Patch Evaluation Through Scene Robustness arXiv:2605.30578v1 Announce Type: new Abstract: Adversarial patches are physical patterns attached to real objects to mislead AI vision systems. Their real-world risk is not determined by a single successful prediction, but by whether they remain effective after deployment under changing viewpoints, distances, and scene conditions. We refer to this property as scene robustness, the effectiveness of a …
Read original ↗https://arxiv.org/abs/2605.30578arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Strengthening Polymorphic Prompt Assembling: Dynamic Separator Generation Against Emerging Prompt Injection Attacks arXiv:2605.30534v1 Announce Type: new Abstract: Polymorphic Prompt Assembling (PPA) defends LLM agents against prompt injections by randomly selecting separator pairs from a fixed pool to isolate user input from system instructions. Although effective, static pool reuse exposes a blast-radius vulnerability: once a separator leaks, it can be exploited in future …
Read original ↗https://arxiv.org/abs/2605.30534arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
The Surface You Test Is Not the Surface That Breaks arXiv:2605.30454v1 Announce Type: new Abstract: Tool-augmented LLM agents are vulnerable to prompt injection: a third party who controls part of the agent's context can plant instructions that the agent then executes as if they came from the user. Current evaluations report a single attack success rate per model on one channel, the tool output and treat that number as the model's vulnerability. But tool descriptions, which …
Read original ↗https://arxiv.org/abs/2605.30454arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Escaping the Linearity Trap: Manifold Detours for Black-Box Adversarial Attacks on Singing Audio Deepfake Detection arXiv:2605.30366v1 Announce Type: new Abstract: Recent Singing Voice Synthesis (SVS) advances enable highly realistic but potentially malicious AI covers, making singing voice deepfake detection (SVDD) crucial. Self-Supervised Learning (SSL)-based detectors achieve state-of-the-art performance by fine-tuning speech SSL backbones to capture singing-specific spoo…
Read original ↗https://arxiv.org/abs/2605.30366arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Investigating Detection and Obfuscation of Prompt Injection Attacks Against Software Reverse Engineering AI Agents arXiv:2605.30677v1 Announce Type: new Abstract: Agentic software reverse engineering systems are vulnerable to prompt injection attacks placed into the source code of executable binary files. This research demonstrates defensive tactics for detecting the presences of prompt injection strings in the decompiler output of adversarial example programs. Methods for o…
Read original ↗https://arxiv.org/abs/2605.30677arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity arXiv:2605.30686v1 Announce Type: new Abstract: ReAct agents that interleave chain-of-thought reasoning with tool calls are increasingly deployed for real tasks such as scheduling, file retrieval, and data access. Their tool observation loop creates a direct attack surface: an adversary who controls any tool's return value can embed instructio…
Read original ↗https://arxiv.org/abs/2605.30686arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Triaging Threats to Specialized Guardrails arXiv:2605.30693v1 Announce Type: new Abstract: Building robust safety guardrails is essential for deploying Large Language Models across diverse real-world applications. However, this goal remains challenging because safety risks span heterogeneous threat domains, while existing datasets cover only fragmented risk subsets and rely on inconsistent taxonomies. Consequently, it remains unclear whether current guardrails can generalize…
Read original ↗https://arxiv.org/abs/2605.30693arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech arXiv:2605.30650v1 Announce Type: new Abstract: Artificial intelligence is now embedded as a primary decision engine in continuously operated financial AI pipelines spanning training and updating, deployment and inference, and operation with monitoring and feedback. The automation and scale that make these pipelines effective also create novel attack surfaces, where small algorithmic perturbations can amplify i…
Read original ↗https://arxiv.org/abs/2605.30650arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
FASR: Automated Identification of Unsafe Control Actions in STPA arXiv:2605.30697v1 Announce Type: new Abstract: The System-Theoretic Process Analysis (STPA) is a well-established hazard analysis technique that has been applied to a wide range of safety-critical systems. Despite its popularity, there is relatively little automation support for STPA, and most of its steps are carried out manually by a human analyst, which can be time consuming and error prone. This paper inve…
Read original ↗https://arxiv.org/abs/2605.30697arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt Learning arXiv:2605.31246v1 Announce Type: new Abstract: Prompt learning is a new machine learning paradigm that has attracted ample attention due to its simplicity and proven efficacy. Despite its growing adoption, the security vulnerabilities associated with this paradigm remain underexplored. In this work, we take the first step to propose BadBone, a stealthy and adaptive backdoor attack against prompt lea…
Read original ↗https://arxiv.org/abs/2605.31246arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
MAECO-Lite: Modular Ontology for Dynamic Malware Analysis arXiv:2605.31199v1 Announce Type: new Abstract: Capturing dynamic malware behavior in a practical but still semantically precise manner remains a significant challenge in cyber threat intelligence. While standards such as MAEC and STIX provide widely adopted vocabularies for describing malware artifacts and observations, they represent data with considerable complexity in structures that often obscure important ontolo…
Read original ↗https://arxiv.org/abs/2605.31199arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
EvoDefense: Co-Evolving Black-Box Defense with Large Language Models arXiv:2605.31140v1 Announce Type: new Abstract: Large Language Models (LLMs) remain highly vulnerable to diverse attacks, particularly in black-box settings where the internals of target models are inaccessible. Existing black-box defenses typically rely on pre-defined filtering heuristics, which often fail to generalize to unseen attack types and target model architectures. We introduce EvoDefense, an expe…
Read original ↗https://arxiv.org/abs/2605.31140arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge arXiv:2605.31135v1 Announce Type: new Abstract: The misuse of Java security APIs is a serious security problem in software development. Research in 2024 has shown that this problem is widespread in LLM-generated code. However, it remains unclear whether this phenomenon persists in current models and how external security knowledge affects it. This pa…
Read original ↗https://arxiv.org/abs/2605.31135arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors arXiv:2605.31042v1 Announce Type: new Abstract: LLM agents are evolving from conversational chatbots to operational tools in real-world workspaces. In local agentic harnesses, an LLM can read and write files, call tools, and reuse workspace state across sessions. While such capabilities enhance utility, they also expose a new attack surface for attackers. Attackers can embed a pro…
Read original ↗https://arxiv.org/abs/2605.31042arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Thou Shall Not Pass: Gatekeeping Outbound TLS Connections arXiv:2605.31020v1 Announce Type: new Abstract: Despite the widespread use of Transport Layer Security (TLS), its security guarantees are frequently compromised by outdated versions and misconfigurations. To analyze this problem, we collected more than 50 million TLS handshakes over a two-week period at our research institution, Fondazione Bruno Kessler, and analyzed three server-selected parameters against the recomm…
Read original ↗https://arxiv.org/abs/2605.31020arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Free-Riding in the AI Economy: Demystifying Logic Flaws in x402-Enabled Payment Systems arXiv:2605.30998v1 Announce Type: new Abstract: The agentic economy demands programmatic financial rails, positioning the x402 protocol as the de facto standard for machine-to-machine payments. However, bridging synchronous HTTP requests with asynchronous blockchain finality introduces profound state synchronization challenges. In this work, we perform the first comprehensive security ana…
Read original ↗https://arxiv.org/abs/2605.30998arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Automatically Attacking Software Reverse Engineering AI Agents arXiv:2605.30667v1 Announce Type: new Abstract: Software tools for reverse engineering executable binary files, such as Ghidra, enable malware analysts to safely conduct robust static analysis without having access to original source code. Coupled with the analytic power of large language models (LLM), agentic systems enabled with tools, such as GhidraMCP, can allow analysts to automate a previously human driven …
Read original ↗https://arxiv.org/abs/2605.30667arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Differentially Private Preference Data Synthesis for Large Language Model Alignment arXiv:2605.30808v1 Announce Type: new Abstract: Preference alignment is a crucial post-training step for large language models (LLMs) to ensure their outputs align with human values. However, post-training on real human preference data raises privacy concerns, as these datasets often contain sensitive user prompts and human judgments. To address this, we propose DPPrefSyn, a novel algorithm f…
Read original ↗https://arxiv.org/abs/2605.30808arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Send a SCOUT First: Pre-hoc Reasoning for Adaptive Detector Allocation in Prompt-Injection Defense arXiv:2605.30837v1 Announce Type: new Abstract: Prompt-injection detectors are heterogeneous: each is strong on a different slice of attacks, and none is always reliable. Yet existing systems still treat detection as a fixed single-detector pipeline, committing every request to one detector's blind spots. We reframe defense as detector allocation: given a heterogeneous pool, de…
Read original ↗https://arxiv.org/abs/2605.30837lwn_kernel · tlp:amber · 6/1/2026, 3:26:17 AM
Kernel prepatch 7.1-rc6 The 7.1-rc6 kernel prepatch is out for testing. Linus said: " Well, I wouldn't call this 'small', but it is certainly smaller than rc5 was. And I don't think there's anything particularly scary here, so maybe we're still on track for a normal release cycle. Let's see. " Kernel prepatch 7.1-rc6 [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Passw…
Read original ↗https://lwn.net/Articles/1075575trend_micro · tlp:amber · 6/1/2026, 12:00:00 AM
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet 47 zero-days fell at Pwn2Own Berlin 2026 for US$1,298,250 in payouts. TrendAI™ was on the ground all three days — here's what we saw. Pwn2Own Berlin 2026: On the Ground with ZDI's Biggest AI Showdown Yet | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focus…
Read original ↗https://www.trendmicro.com/en_us/research/26/f/pwn2own-berlin-2026.htmlsnyk_blog · tlp:amber · 6/1/2026, 12:00:00 AM
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages. Miasma Attack Hits Red Hat npm Packages | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a si…
Read original ↗https://snyk.io/blog/miasma-supply-chain-attack-malicious-code-redhat-cloud-services-npm-packagesmicrosoft_mstic · tlp:amber · 5/30/2026, 12:06:20 AM
Malicious npm packages abuse dependency confusion to profile developer environments A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related activity. The post Malicious npm packages abuse dependency confusion to profile developer environments appeared first o…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environmentsars_security · tlp:amber · 5/29/2026, 6:46:33 PM
Botnet of more than 17 million devices dismantled The botnet was reportedly tied to a Russia-based residential proxy network. Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center. The action, announced Thursday , came about after a security researcher reported the sprawling network to authorities. The host infrastructu…
Read original ↗https://arstechnica.com/security/2026/05/botnet-of-more-than-17-million-devices-dismantledlwn_kernel · tlp:amber · 5/29/2026, 4:41:06 PM
[$] A trademark dispute over MeshCore MeshCore is a relatively new project, started in January 2025, that aims to build a scalable mesh network using low-power long-distance radios. While many other projects of the same general nature have been tried before, MeshCore grew quickly because of its more efficient message routing and enthusiastic community. In early 2026, an early proponent of the project made a sudden shift that left the rest of the community stunned and embroil…
Read original ↗https://lwn.net/Articles/1070218