REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 42 of 57
cisa_alerts · tlp:amber · 5/21/2026, 12:00:00 PM
ABB Terra AC Wallbox View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior. The following versions of ABB Terra AC Wallbox are affected: Terra AC wallbox (JP) <=1.8.33, 1.8.36 (CVE-2025…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-05cisa_alerts · tlp:amber · 5/21/2026, 12:00:00 PM
ABB B&R PCs View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. A network attacker could exploit the vulnerabilities to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information. The following versions of ABB B&R PCs are affected: APC4100 <1.09, 1.09 (CVE-2023-45229, CVE-2023-45230, CVE-2…
cisa_alerts · tlp:amber · 5/21/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. B…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalogsnyk_blog · tlp:amber · 5/21/2026, 5:00:00 AM
Securing The AI Revolution: How Snyk And Our Partners Are Scaling For The Future AI is accelerating code creation. Learn how Snyk is scaling its AI Security Platform and investing in new partner programs to help enterprises govern AI-generated code at scale. Securing the AI Revolution with Snyk Partners | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows…
Read original ↗https://snyk.io/blog/securing-ai-revolution-snyk-partnersarxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
An IoT-Enabled Smart Home Automation System for Energy Efficiency with Web-Based Control arXiv:2605.20981v1 Announce Type: new Abstract: This paper illustrates the design and implementation of a smart home automation system for the conservation of energy and user control with the help of environmental sensors and Raspberry Pi 5. It monitors real-time conditions like motion, temperature, humidity, light and smoke to automatically control the device's behavior and save energy.…
Read original ↗https://arxiv.org/abs/2605.20981arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Artificial Pancreas Implantables -- How Healthcare Professionals May Deal With DIY Bio Cases arXiv:2605.20208v1 Announce Type: new Abstract: Automated insulin delivery (AID) and artificial pancreas systems increasingly serve as safety-critical cyber-physical technologies in clinical care, integrating sensors, algorithms, software, and insulin-delivery hardware to automate a life-sustaining therapy. While regulated commercial systems are supported by formal approval pathways,…
Read original ↗https://arxiv.org/abs/2605.20208arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Adaptive Probe-based Steering for Robust LLM Jailbreaking arXiv:2605.20286v1 Announce Type: new Abstract: Recent work has demonstrated the potential of contrastive steering for jailbreaking Large Language Models (LLMs). However, existing methods rely on limited and inherently biased contrastive prompts and require laborious manual tuning of steering strength, limiting their robustness and effectiveness. In this paper, we leverage the idea of model extraction to guide the lea…
Read original ↗https://arxiv.org/abs/2605.20286arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Pramana: A Protocol-Layer Treatment of Claim Verification in Autonomous Agent Networks arXiv:2605.20312v1 Announce Type: new Abstract: Autonomous agents deployed in regulated domains must produce a verification artifact per consequential output: a record an auditor can re-execute offline, capturing what was claimed, against what source, by whom, when, and how. Production verification today splits into two unstandardized halves. Probabilistic verdict patterns (self-consistenc…
Read original ↗https://arxiv.org/abs/2605.20312arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Refusal Evaluation in Coding LLMs and Code Agents: A Systematic Review of Thirteen Malicious-Code Prompt Corpora (2023-2025) arXiv:2605.20351v1 Announce Type: new Abstract: The evaluation of large language model refusal on malicious-coding tasks now spans at least thirteen publicly released prompt corpora (AdvBench, the CyberSecEval family, RMCBench, RedCode, MCGMark, JailbreakBench, CySecBench, MalwareBench, CIRCLE, MOCHA, ASTRA, Scam2Prompt / Innoc2Scam-bench, and JAWS-Ben…
Read original ↗https://arxiv.org/abs/2605.20351arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Security Document Classification with a Fine-Tuned Local Large Language Model: Benchmark Data and an Open-Source System arXiv:2605.20368v1 Announce Type: new Abstract: Organizations that scan documents for sensitive information face a practical problem. Cloud services require data to be sent to external infrastructure, while rule-based tools often miss threats that depend on context. This study presents TorchSight, an open-source local system for security document classifica…
Read original ↗https://arxiv.org/abs/2605.20368arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Latent Geometry as a Structural Monitor: Eigenspace Alignment for Anomaly Detection in Anonymity Networks arXiv:2605.20391v1 Announce Type: new Abstract: Traditional anomaly detection marks events when measured signals cross predefined thresholds. This captures the moment of transition but not the structural pressure that precedes it. We propose treating large behavioral populations as geometric energy landscapes whose deformation can be measured before and during major tran…
Read original ↗https://arxiv.org/abs/2605.20391arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Detecting Data Exfiltration through I2P Anonymity Networks: A Two-Phase Machine Learning Approach arXiv:2605.20546v1 Announce Type: new Abstract: The Invisible Internet Project (I2P) provides strong anonymity through garlic routing and distributed network architecture, making it attractive for legitimate privacy needs. Nevertheless, the same properties can be exploited by malicious actors to steal sensitive information from corporate networks without detection. Current netwo…
Read original ↗https://arxiv.org/abs/2605.20546arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs arXiv:2605.20641v1 Announce Type: new Abstract: Inference optimization is a vital technique for deploying LLMs at scale. Compilation is the most widely adopted optimization technique for LLMs. While it assumes semantic equivalence between the original and compiled graphs, we first uncover its numerical side effects can be maliciously exploited to implant stealthy backdoors in LLMs. We…
Read original ↗https://arxiv.org/abs/2605.20641arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Heartbeat-Bound Hierarchical Credentials: Cryptographic Revocation for AI Agent Swarms arXiv:2605.20704v1 Announce Type: new Abstract: Autonomous AI agents that spawn sub-agent swarms create a safety gap: existing credential revocation mechanisms, OAuth~2.0 introspection, OCSP, and W3C Status Lists, require network connectivity to a central authority, leaving ``zombie agents'' executing privileged operations for minutes to hours after operator shutdown. We present Heartbeat-…
Read original ↗https://arxiv.org/abs/2605.20704arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
An Application-Layer Multi-Modal Covert-Channel Reference Monitor for LLM Agent Egress arXiv:2605.20734v1 Announce Type: new Abstract: A large language model (LLM) agent that sends messages can leak data inside them. Destination allowlists and content scanners do not police whether an otherwise-benign payload is itself a covert channel: a compromised agent encodes bits in zero-width characters, homoglyphs, whitespace, base64, JavaScript Object Notation (JSON) key ordering, m…
Read original ↗https://arxiv.org/abs/2605.20734arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Rethinking Fraud Safety Evaluation: Multi-Round Attacks Reveal Safety-Utility Tradeoffs in Graph-Context LLM Defenders arXiv:2605.20759v1 Announce Type: new Abstract: Single-turn safety evaluation is a poor proxy for real fraud defense, where attackers escalate across multiple rounds. This paper evaluates fraud defenders under replay and adaptive multi-round attacks and measures when a defender refuses, not just whether it eventually refuses. On a frozen multi-round suite bu…
Read original ↗https://arxiv.org/abs/2605.20759arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
GenAI-Driven Threat Detection with Microsoft Security Copilot arXiv:2605.20896v1 Announce Type: new Abstract: Defending against today's increasingly sophisticated cyberattacks requires security analysts to continuously translate evolving attacker tradecraft into detection logic. This places defenders in a reactive posture, requiring constantly updated expertise across an increasingly fragmented security landscape. We introduce the Dynamic Threat Detection Agent (DTDA), an al…
Read original ↗https://arxiv.org/abs/2605.20896arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Domijn: The Security of Domain Registrars and the Risk of a Domain Name Takeover arXiv:2605.20984v1 Announce Type: new Abstract: Domain names are key assets for organisation. They anchor an organisation's online presence and reputation, and serve as linking pin for web services and, e.g., email. Consequently, a malicious takeover of a domain can lead to significant damages. Organisations register domain names through so-called registrars, a type of business that plays a key …
Read original ↗https://arxiv.org/abs/2605.20984arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Verifiable Provenance and Watermarking for Generative AI: An Evidentiary Framework for International Operational Law and Domestic Courts arXiv:2605.21002v1 Announce Type: new Abstract: Generative artificial intelligence now synthesizes photorealistic imagery, audio, and video at a cost that defeats traditional forensic intuition. The legal consequences span three regimes studied so far in isolation: international operational law, domestic procedure, and product regulation. T…
Read original ↗https://arxiv.org/abs/2605.21002arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
An Evidence-driven Protocol for Trustworthy CI Pipelines arXiv:2605.21089v1 Announce Type: new Abstract: Enterprise software supply chains are increasingly vulnerable to infrastructure attacks, resulting in financial and reputational damage. Ensuring the integrity and provenance of software artifacts remains a significant challenge, where re-execution of the build and tests by every consumer to guarantee provenance produces a verification bottleneck and credibility reduction…
Read original ↗https://arxiv.org/abs/2605.21089arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Image Encryption via Data-Identified Discrete Chaotic Maps arXiv:2605.21118v1 Announce Type: new Abstract: In this work, we propose a data-driven image encryption framework that identifies chaotic maps directly from data using the SINDy-PI algorithm. Unlike conventional encryption schemes relying on predefined maps, our method learns the full explicit dynamics -- including cross-terms and higher-order nonlinearities -- from observational data. The validity of this approach i…
Read original ↗https://arxiv.org/abs/2605.21118arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Detecting Trojaned DNNs via Spectral Regression Analysis arXiv:2605.21146v1 Announce Type: new Abstract: Modern DNNs are repeatedly fine-tuned to incorporate new data and functionality. This evolutionary workflow introduces a security risk when updated data cannot be fully trusted, as adversaries may implant Trojans during fine-tuning. We present MIST, a Trojan detection approach that analyzes how a model's internal representations change during fine-tuning. Rather than atte…
Read original ↗https://arxiv.org/abs/2605.21146arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Information Leakage Envelopes arXiv:2605.21185v1 Announce Type: new Abstract: We study privacy guarantees in the framework of pointwise maximal leakage (PML) that satisfy two requirements: they are robust under post-processing and upper bound the failure probability, i.e., the probability that the information leakage exceeds a given threshold. We first examine two candidate definitions inspired by (approximate) differential privacy and show that neither one satisfies both re…
Read original ↗https://arxiv.org/abs/2605.21185arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Profiling User Vulnerability to Phishing Through Psychological and Behavioral Factors arXiv:2605.21246v1 Announce Type: new Abstract: Phishing remains one of the most pervasive cybersecurity threats, shifting the focus from technological vulnerabilities to human cognitive and psychological factors. In coherence with the trend of studies on phishing to increasingly focus on human aspects and vulnerable users profiling, this study investigates the multidimensional nature of us…
Read original ↗https://arxiv.org/abs/2605.21246arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Onion-Routed Multi-Circuit Key Establishment for Quantum-Resilient Sessions arXiv:2605.21349v1 Announce Type: new Abstract: Public-key primitives that today anchor session-key establishment - RSA, Diffie-Hellman, and elliptic-curve cryptography - reduce to integer factorization or discrete logarithm and are therefore vulnerable to Shor's algorithm on a sufficiently capable quantum computer. The harvest-now, decrypt-later (HNDL) threat model turns this future capability into …
Read original ↗https://arxiv.org/abs/2605.21349arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks arXiv:2605.21378v1 Announce Type: new Abstract: Since 2016, Apple has claimed that device analytics collected to improve user experience are protected by differential privacy (DP). Apple's DifferentialPrivacy.framework is deployed across its operating systems and handles sensitive signals such as Safari domains, keyboard events, photo attributes, and health-related rep…
Read original ↗https://arxiv.org/abs/2605.21378arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers arXiv:2605.21392v1 Announce Type: new Abstract: Model Context Protocol (MCP) has emerged as a standard interface for connecting LLM agents to external tools. Because MCP servers expose privileged operations such as shell execution, network access, and file-system manipulation to agent-driven invocation, implementation flaws in tool handlers can create a direct path from natural-…
Read original ↗https://arxiv.org/abs/2605.21392arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
It Takes Two: Complementary Self-Distillation for Contextual Integrity in LLMs arXiv:2605.20258v1 Announce Type: cross Abstract: Contextual Integrity (CI) defines privacy not merely as keeping information hidden, but as governing information flows according to the norms of a given context. As large language models are increasingly deployed as personal agents handling sensitive workflows, adhering to CI becomes critical. However, even frontier models remain unreliable in maki…
Read original ↗https://arxiv.org/abs/2605.20258arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Causal Unlearning in Collaborative Optimization: Exact and Approximate Influence Reversal under Adversarial Contributions arXiv:2605.20341v1 Announce Type: cross Abstract: Federated learning systems must support data deletion requests to comply with privacy regulations, yet retraining from scratch after each deletion is computationally prohibitive. We present HF-KCU, a method that removes a client's contribution by approximating the influence function through conjugate gradi…
Read original ↗https://arxiv.org/abs/2605.20341lwn_kernel · tlp:amber · 5/21/2026, 2:27:57 AM
[$] LWN.net Weekly Edition for May 21, 2026 Inside this week's LWN.net Weekly Edition: Front : OpenSUSE site age restrictions; Lots of LSFMM+BPF coverage; The tenth OpenPGP email summit. Briefs : Firefox 151.0; pgBackRest funding; RIP Peter G. Neumann; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1072730chainalysis · tlp:amber · 5/20/2026, 11:36:03 PM
OFAC Sanctions Sinaloa Cartel Fentanyl Trafficking and Crypto Laundering Network Summary The Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned more than a dozen individuals and entities… The post OFAC Sanctions Sinaloa Cartel Fentanyl Trafficking and Crypto Laundering Network appeared first on Chainalysis . OFAC Sanctions Fentanyl Trafficking and Crypto Laundering Network Chainalysis Products Crypto Investigations Investigations Solutions…
Read original ↗https://www.chainalysis.com/blog/sinaloa-cartel-fentanyl-trafficking-crypto-laundering-may-2026ars_security · tlp:amber · 5/20/2026, 7:10:36 PM
Google publishes exploit code threatening millions of Chromium users Google publishes exploit code before patch, reported 29 months earlier, is fixed. Google on Wednesday published exploit code for an unfixed vulnerability in its Chromium browser codebase that threatens millions of people using Chrome, Microsoft Edge, and virtually all other Chromium-based browsers. The proof-of-concept code exploits the Browser Fetch programming interface, a standard that allows long video…
Read original ↗https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-usersmicrosoft_mstic · tlp:amber · 5/20/2026, 5:48:44 PM
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms. The post Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft appeared first on Microsoft Security Blog . Micro…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theftmicrosoft_mstic · tlp:amber · 5/20/2026, 4:00:00 PM
Securing the gaming culture of cultures Read about the unique challenges and rewards of securing gaming platforms and how to better protect gaming communities. The post Securing the gaming culture of cultures appeared first on Microsoft Security Blog . The Deputy CISO blog series is where Microsoft Deputy Chief Information Security Officers (CISOs) share their thoughts on what is most important in their respective domains. In this series, you will get prac…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/20/securing-the-gaming-culture-of-culturesmicrosoft_mstic · tlp:amber · 5/20/2026, 3:00:00 PM
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing your email, retrieving records from your CRM, writing and executing code, and taking actions on your behalf across dozens of connected systems. The post Introducing RAMPART and Cl…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/20/introducing-rampart-and-clarity-open-source-tools-to-bring-safety-into-agent-development-workflowlwn_kernel · tlp:amber · 5/20/2026, 1:14:51 PM
[$] What is to be done about MGLRU? "Reclaim" is the task of finding memory that can be taken away from its current user and put to better uses within the system; it is a core part of the memory-management picture. The addition of the multi-generational LRU (MGLRU) was meant to provide a better reclaim implementation than the "traditional LRU" that preceded it, but MGLRU has complicated the situation instead. No fewer than three memory-management-track sessions at the 2026 L…
Read original ↗https://lwn.net/Articles/1072866lwn_kernel · tlp:amber · 5/20/2026, 1:04:17 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), Debian (gnutls28 and linux-6.1), Fedora (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-rpki, rust-sevctl, and rust-tealdeer), Mageia (bind), Oracle (bind, giflib, gimp:2.8, kernel, libpng, rsync, ruby, and vim), Slackware (haveged and moz…
Read original ↗https://lwn.net/Articles/1073713cisa_alerts · tlp:amber · 5/20/2026, 12:00:00 PM
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability CVE…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalogchainalysis · tlp:amber · 5/20/2026, 11:55:18 AM
How Blockchain Intelligence Uncovered a Million-Euro Bitcoin Ordinals Tax Fraud Scheme Summary Criminals are increasingly turning to novel digital asset classes, like Bitcoin Ordinals and BRC-20 tokens, to generate and conceal… The post How Blockchain Intelligence Uncovered a Million-Euro Bitcoin Ordinals Tax Fraud Scheme appeared first on Chainalysis . How Blockchain Intelligence Uncovered a Bitcoin Ordinals Scheme Chainalysis Products Crypto Investigations Investiga…
Read original ↗https://www.chainalysis.com/blog/italy-guardia-di-finanza-bitcoin-ordinals-tax-fraud-schemelwn_kernel · tlp:amber · 5/20/2026, 11:00:15 AM
[$] The tenth OpenPGP email summit The OpenPGP Email Summit is an annual meeting for those who work on encrypted email and related topics. The tenth installment of this meeting took place in March 2026 and the minutes have now been published. As usual, a wide range of topics were discussed. Highlights included support for post-quantum cryptography (PQC) with multiple actors planning rollouts within this year, a promising new approach for making email signatures ubiquitous wi…
Read original ↗https://lwn.net/Articles/1072870