REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2278 reports · page 44 of 57
arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Towards Zero Trust Architecture: A Pilot Study on Information Systems Security Readiness amongst Small and Medium Enterprises arXiv:2605.18901v1 Announce Type: new Abstract: Small and medium enterprises (SMEs) face growing cyber threats but often lack the resources and expertise needed to adopt Zero Trust Architecture (ZTA). This pilot study examines the drivers and barriers shaping SME perceptions of ZTA necessity and proposes an exploratory staged adoption path. Survey dat…
Read original ↗https://arxiv.org/abs/2605.18901arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
ESLD (External Surrogate Latent Defense): A Latent-Space Architecture for Faster, Stronger Prompt-Injection Defense arXiv:2605.18918v1 Announce Type: new Abstract: Modern AI assistants are agentic. To answer a single user request, the underlying language model pulls in information from many sources, such as web searches, retrieved documents, tool outputs, and user follow-ups, and reasons over them across several steps. Any of these inputs can carry malicious content. This op…
arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
DMN: A Compositional Framework for Jailbreaking Multimodal LLMs with Multi-Image Inputs arXiv:2605.18915v1 Announce Type: new Abstract: Multimodal Large Language Models (MLLMs) are vulnerable to jailbreak attacks, which can elicit harmful responses from MLLMs. Many MLLMs support multi-image inputs, inadvertently introducing new vulnerabilities due to less efforts on multi-image safety alignment. Previous MLLM jailbreak methods only uses a single image, which restricts the at…
Read original ↗https://arxiv.org/abs/2605.18915arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
SCAFDS: Edge-Feature Graph Attention for Interbank Fraud Detection with Attribution-Grounded SAR Generation arXiv:2605.18913v1 Announce Type: new Abstract: The U.S. financial system processes approximately 1.3 million interbank transactions daily, yet no system in the reviewed literature models fraud propagation across the interbank network using fraud co-occurrence edge features. Prior interbank GNN architectures model credit contagion using credit distress supervision sign…
Read original ↗https://arxiv.org/abs/2605.18913arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Fast and Lightweight Backdoor Detection via Head Random Probing arXiv:2605.18908v1 Announce Type: new Abstract: Deep neural networks (DNNs) remain critically vulnerable to backdoor attacks. Existing post-training detectors often require clean or surrogate data, gradients, or iterative trigger reconstruction, leading to high computational costs and limited robustness under practical model-auditing scenarios. In this paper, we propose HTell, a fast and lightweight data-free ba…
Read original ↗https://arxiv.org/abs/2605.18908arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Decentralized autonomous organization and blockchain-based incentivization framework for community-based facilities management arXiv:2605.18773v1 Announce Type: new Abstract: Traditional facility management often relies on centralized decision-making structures that limit stakeholder participation, leading to misalignment with occupant needs and reduced satisfaction. This paper proposes a novel blockchain- and Decentralized Autonomous Organization (DAO)-based framework for c…
Read original ↗https://arxiv.org/abs/2605.18773arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
DarkLLM: Learning Language-Driven Adversarial Attacks with Large Language Models arXiv:2605.18868v1 Announce Type: new Abstract: While vision and multimodal foundation models underpin critical tasks from perception to complex reasoning, they remain highly vulnerable to adversarial attacks. However, traditional adversarial attacks are typically limited to single, predefined objectives, tightly coupling each attack to a specific model or task, which restricts their scalability…
Read original ↗https://arxiv.org/abs/2605.18868arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Lightweight and Fast Backdoor Model Detection arXiv:2605.18907v1 Announce Type: new Abstract: Deep neural networks (DNN), despite their remarkable performance, are highly vulnerable to backdoor attacks. Existing defenses mainly rely on activation anomaly analysis or trigger reverse engineering and often require clean samples or prior knowledge of trigger patterns, resulting in limited efficacy, practicability, and generalizability. More critically, while advanced attacks can…
Read original ↗https://arxiv.org/abs/2605.18907arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
GenAI-FDIA: Physics-Informed Generative Models for False Data Injection Attacks arXiv:2605.18873v1 Announce Type: new Abstract: Training and evaluating false data injection attack (FDIA) detectors for power systems is constrained by data scarcity. Operational grid measurements are commercially sensitive, and hand-crafted attacks fail to capture complex distributional structures imposed by network physics. We present \textsc{GenAI-FDIA}, a framework benchmarking a pool of $P{…
Read original ↗https://arxiv.org/abs/2605.18873arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
High-Rate Public-Key Pseudorandom Codes for Edit Errors arXiv:2605.19402v1 Announce Type: new Abstract: Pseudorandom codes (PRCs), introduced by Christ and Gunn (CRYPTO '2024), are error-correcting codes whose codewords are computationally indistinguishable from uniformly random strings, while still being decodable by someone holding the key. They provide a natural primitive for robust and undetectable watermarking, particularly in applications to AI-generated content. Altho…
Read original ↗https://arxiv.org/abs/2605.19402arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Locked Out at 8,000 Miles: Why UK-China Partnership Students Are Suffering arXiv:2605.19367v1 Announce Type: new Abstract: University cybersecurity protocols have intensified dramatically in response to rising threats of data breaches, ransomware, and credential theft. While necessary, these measures have created a parallel crisis of accessibility - even for students physically on campus. This paper argues that domestic, on-campus students already face significant barriers: …
Read original ↗https://arxiv.org/abs/2605.19367arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
RoboJailBench: Benchmarking Adversarial Attacks and Defenses in Embodied Robotic Agents arXiv:2605.19328v1 Announce Type: new Abstract: Recent advances in Vision-Language Models (VLMs) facilitate a new class of embodied AI systems, where these models are integrated into physical platforms, e.g. robots and autonomous vehicles, to interpret visual scenes and execute natural language commands in diverse environments. Previous research has introduced jailbreak attacks and defens…
Read original ↗https://arxiv.org/abs/2605.19328arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Exploring and Developing a Pre-Model Safeguard with Draft Models arXiv:2605.19321v1 Announce Type: new Abstract: Large Language Model (LLM) alignment remains vulnerable to jailbreak attacks that elicit unsafe responses, motivating pre-model and post-model guards. Pre-model guards audit the safety of prompts before invoking target models. However, relying solely on the prompt often leads to high false-negative rates (i.e., jailbreak attacks go undetected). Post-model guards a…
Read original ↗https://arxiv.org/abs/2605.19321arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
MultiBallot: Verifiable and privacy-preserving E-Collecting in the Swiss setting arXiv:2605.19312v1 Announce Type: new Abstract: As part of the political process, citizens may participate in signature collections to influence policy changes. In Switzerland, this even results in legally binding acts, similar to an election system. In this work, we first derive a realistic setting for e-collecting in Switzerland, based on the setting established for e-voting. Then, we propose …
Read original ↗https://arxiv.org/abs/2605.19312arxiv_cs_cr · tlp:amber · 5/20/2026, 4:00:00 AM
Detecting and Mitigating Backdoor Attacks in OTA-FL Systems: A Two-Stage Robust Aggregation Scheme arXiv:2605.19253v1 Announce Type: new Abstract: Over-the-air federated learning (OTA-FL) improves communication efficiency by exploiting the superposition property of wireless channels, but this same property also creates a critical security vulnerability: the parameter server (PS) cannot access individual local updates, making it difficult to identify and exclude poisoned grad…
Read original ↗https://arxiv.org/abs/2605.19253snyk_blog · tlp:amber · 5/20/2026, 12:00:00 AM
A Day in the Life of a Strategy Co-Op in Snyk’s Boston Office Go behind the scenes with Lulu, a Strategy Co-Op at Snyk, and discover a day balancing high-impact AI security projects with a vibrant Boston office culture. A Day in the Life of a Strategy Co-Op at Snyk | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applicat…
Read original ↗https://snyk.io/blog/strategy-co-op-snyk-boston-officesnyk_blog · tlp:amber · 5/19/2026, 11:00:00 PM
The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised A day after the AntV npm supply chain attack, the same campaign appears to have struck `durabletask`, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here's what we know. The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised | Snyk You need to enable JavaScript to run thi…
Read original ↗https://snyk.io/blog/durabletask-pypi-supply-chain-attackhuggingface_blog · tlp:amber · 5/19/2026, 6:38:09 PM
OlmoEarth v1.1: A more efficient family of models OlmoEarth v1.1: A more efficient family of models Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles OlmoEarth v1.1: A more effic…
Read original ↗https://huggingface.co/blog/allenai/olmoearth-v1-1ars_security · tlp:amber · 5/19/2026, 6:27:08 PM
In stunning display of stupid, secret CISA credentials found in public GitHub repo SSH keys, plaintext passwords, other sensitive data had been up since November 2025. Security researcher Brian Krebs brings us the news that America's Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and "other sensitive CISA assets" exposed in a public GitHub repo since at least November 2025. The now-offline public repo…
Read original ↗https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repolwn_kernel · tlp:amber · 5/19/2026, 4:10:38 PM
Firefox 151.0 released Version 151.0 of the Firefox browser has been released. Significant changes include the ability to clear and restart a private-browsing session, better fingerprinting protection, control over the apparent location when using the Firefox VPN, and more. Firefox 151.0 released [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Sub…
Read original ↗https://lwn.net/Articles/1073579talos · tlp:amber · 5/19/2026, 3:39:37 PM
TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability Cisco Talos’ Vulnerability Discovery & Research team recently dis…
Read original ↗https://blog.talosintelligence.com/tp-link-photoshop-openvpn-norton-vpn-vulnerabilitieslwn_kernel · tlp:amber · 5/19/2026, 3:27:08 PM
[$] openSUSE "terms of site" raise complaints about age restrictions Many people in the Linux community began using the operating system—and contributing to open source—at a tender age, often well before their 16th birthday. Thus, a recent change in openSUSE's terms of site (ToS) that required users of the project's web site to be " at least 16 years of age or the age of majority " in their jurisdiction has raised objections. The terms have since been modified, t…
Read original ↗https://lwn.net/Articles/1072689microsoft_mstic · tlp:amber · 5/19/2026, 3:07:01 PM
Exposing Fox Tempest: A malware-signing service operation Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware. The post Exposing Fox Tempest: A malware-signing service operation appeared first on Microsoft Security Blog . In this article Fox Tempest’s role and impact Fox Tempest’s malwa…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operationlwn_kernel · tlp:amber · 5/19/2026, 2:30:40 PM
[$] In search of faster this_cpu operations The kernel's this_cpu operations are meant to speed access to per-CPU variables. They are more optimal on some CPUs than others, though. During a memory-management-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , Yang Shi proposed a fundamental, and somewhat controversial, change to how these operations work in order to provide better performance on a wider range of architectures.
Read original ↗https://lwn.net/Articles/1073395lwn_kernel · tlp:amber · 5/19/2026, 2:15:48 PM
[$] What's brewing in CXL Compute Express Link (CXL) is a technology intended to enable the provision of "memory nodes" in data centers that provide (possibly shared) memory to nearby CPUs. It has, Dan Williams said at the beginning of his memory-management-track session on the topic at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , " been making memory-management problems worse since 2021 ". He used the session to provide an overview of the ways in …
Read original ↗https://lwn.net/Articles/1072858lwn_kernel · tlp:amber · 5/19/2026, 1:27:28 PM
[$] Improving the per-CPU memory allocator There are many places in the kernel where performance can be improved by using per-CPU data. But, as it turns out, the kernel's allocator for per-CPU data has some performance problems of its own. Harry Yoo led a session in the memory-management track of the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit to explore ways to address those problems and accelerate the allocation and initialization of per-CPU data.
Read original ↗https://lwn.net/Articles/1072840lwn_kernel · tlp:amber · 5/19/2026, 1:24:00 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (libpng and nginx), Debian (erlang, netatalk, and nginx), Fedora (mod_md and SDL2_image), Mageia (perl-libwww-perl, perl-HTTP-Message, perl-WWW-Mechanize-Cached, perl-File-XDG, perl-Path-Tiny, perl-YAML-Syck, postgresql15, and rclone), SUSE (agama, alloy, cacti, cloud-init, dnsmasq, emacs, firefox, glibc, go1.25, go1.26, google-cloud-sap-agent, google-guest-agent, ibus-rime, librime, imagemagick, ker…
Read original ↗https://lwn.net/Articles/1073542lwn_kernel · tlp:amber · 5/19/2026, 12:05:42 PM
pgBackRest will continue In April, David Steele, maintainer of the popular pgBackRest backup and restore project for PostgreSQL, announced that he had archived the project and it would no longer be maintained due to lack of sponsorship. On May 18, he announced that a number of sponsors have stepped forward to ensure its continued development: Over the last few weeks, a coalition of sponsors has come together to fund ongoing development. Their support means the project i…
Read original ↗https://lwn.net/Articles/1073470cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
ScadaBR View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to perform unauthenticated remote code execution. The following versions of ScadaBR are affected: ScadaBR 1.2.0 (CVE-2026-8602, CVE-2026-8603, CVE-2026-8604, CVE-2026-8605) CVSS Vendor Equipment Vulnerabilities v3 9.1 ScadaBR ScadaBR Missing Authentication for Critical Function, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Cross-Si…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
Siemens RUGGEDCOM APE1808 Devices View CSAF Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customer…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-02cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
ZKTeco CCTV Cameras View CSAF Summary Successful exploitation of this vulnerability could result in information disclosure, including capture of camera account credentials. The following versions of ZKTeco CCTV Cameras are affected: SSC335-GC2063-Face-0b77 Solution CVSS Vendor Equipment Vulnerabilities v3 9.1 ZKTeco ZKTeco CCTV Cameras Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas De…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
Kieback & Peter DDC Building Controllers View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of the victim's browser. The following versions of Kieback & Peter DDC Building Controllers are affected: DDC4002 <=1.12.14 (CVE-2026-4293) DDC4100 <=1.12.14 (CVE-2026-4293) DDC4200 <=1.12.14 (CVE-2026-4293) DDC4200-L <=1.12.14 (CVE-2026-4293) DDC4400 <=1.12.14 (CVE-2026-4293) DDC4002e <=1.23.4 (CVE-2026-4293) …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05cisa_alerts · tlp:amber · 5/19/2026, 12:00:00 PM
ABB CoreSense HM and CoreSense M10 View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information. The following versions of ABB CoreSense HM and CoreSense M10 are affected: CoreSens…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-01talos · tlp:amber · 5/19/2026, 10:00:20 AM
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetization. Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb&…
Read original ↗https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystemeset · tlp:amber · 5/19/2026, 8:50:00 AM
The quest for greater tech independence A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies The quest for greater tech independence Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts Whit…
Read original ↗https://www.welivesecurity.com/en/cybersecurity/quest-greater-tech-independencearxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Universal Graph Backdoor Defense: A Feature-based Homophily Perspective arXiv:2605.16815v1 Announce Type: new Abstract: Graph neural networks (GNNs) have achieved remarkable success in relational learning. However, their vulnerability to graph backdoor attacks (GBAs) poses a significant barrier to broader adoption in high-stakes applications. Despite recent advances in graph backdoor defense (GBD), existing methods primarily focus on subgraph-based GBAs, relying on the assum…
Read original ↗https://arxiv.org/abs/2605.16815arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
A Lightweight QR-assisted Zero-knowledge Identification Protocol For Secure Authentication arXiv:2605.16912v1 Announce Type: new Abstract: This study proposes a lightweight Zero-Knowledge authentication model supported by QR codes. The approach is based on the Schnorr authentication protocol and provides an additional security layer against replay attacks through nonce and timestamp mechanisms. The proof data generated by the prover is embedded within a QR code and transmitt…
Read original ↗https://arxiv.org/abs/2605.16912arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-demand Input Delivery arXiv:2605.16798v1 Announce Type: new Abstract: Firmware fuzzing has gained attention for identifying firmware bugs. However, current approaches often directly integrate fuzzing tools for general software. General software receives input as it encounters I/O functions, but firmware input can be received asynchronously and independently of the firmware's execution, with uncertain …
Read original ↗https://arxiv.org/abs/2605.16798arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Watermarks Attack Watermarks: Re-Watermarking as a Generic Removal Strategy arXiv:2605.16796v1 Announce Type: new Abstract: Watermarking combines an imperceptible change to an input image that will trigger a detector, to assert provenance and protect intellectual property. The literature has shown great interest in attacks on watermarking schemes: attackers are clearly motivated to steal copyrighted material or circumvent legislated deepfake protections. In this work, we mak…
Read original ↗https://arxiv.org/abs/2605.16796arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Securing LLM Agents Need Intent-to-Execution Integrity arXiv:2605.16976v1 Announce Type: new Abstract: This position paper argues that securing LLM agents requires first defining an end-to-end correctness property that specifies when an agent's execution faithfully reflects the user's intent. Modern LLM agents operate over an \emph{intent-to-execution pipeline}, where natural-language instructions are translated into concrete system operations such as tool calls, API request…
Read original ↗https://arxiv.org/abs/2605.16976