REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2281 reports · page 45 of 58
arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-demand Input Delivery arXiv:2605.16798v1 Announce Type: new Abstract: Firmware fuzzing has gained attention for identifying firmware bugs. However, current approaches often directly integrate fuzzing tools for general software. General software receives input as it encounters I/O functions, but firmware input can be received asynchronously and independently of the firmware's execution, with uncertain …
Read original ↗https://arxiv.org/abs/2605.16798arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Watermarks Attack Watermarks: Re-Watermarking as a Generic Removal Strategy arXiv:2605.16796v1 Announce Type: new Abstract: Watermarking combines an imperceptible change to an input image that will trigger a detector, to assert provenance and protect intellectual property. The literature has shown great interest in attacks on watermarking schemes: attackers are clearly motivated to steal copyrighted material or circumvent legislated deepfake protections. In this work, we mak…
arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Securing LLM Agents Need Intent-to-Execution Integrity arXiv:2605.16976v1 Announce Type: new Abstract: This position paper argues that securing LLM agents requires first defining an end-to-end correctness property that specifies when an agent's execution faithfully reflects the user's intent. Modern LLM agents operate over an \emph{intent-to-execution pipeline}, where natural-language instructions are translated into concrete system operations such as tool calls, API request…
Read original ↗https://arxiv.org/abs/2605.16976arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
On-Device Interpretable Tsetlin Machine-Based Intrusion Detection for Secure IoMT arXiv:2605.16707v1 Announce Type: new Abstract: The rapid evolution of digital health technologies is redefining healthcare services worldwide. The integration of wireless communication and Internet-enabled medical devices within Internet of Medical Things (IoMT) networks enables continuous, real-time patient monitoring. However, this increased connectivity raises cybersecurity and patient safe…
Read original ↗https://arxiv.org/abs/2605.16707arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
SLEIGHT-Bench: A Benchmark of Evasion Attacks Against Agent Monitors arXiv:2605.16626v1 Announce Type: new Abstract: Since autonomous coding agents generate complex behaviors at high-volume, we may want to use other LLMs to monitor actions to reduce the risk from dangerous misaligned behavior. To better understand the limitations of such monitors against the diverse attack strategies that a coding agent could use, we present SLEIGHT-Bench (Subtle Low-itEration Insight-Guided…
Read original ↗https://arxiv.org/abs/2605.16626arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Read This Paper to Get $50 Million:* An Analysis of Mobile Messaging Scams Using Reddit Data arXiv:2605.16656v1 Announce Type: new Abstract: Mobile messaging scams--fraudulent messages delivered over SMS and other mobile applications--have become a persistent and evolving security threat, yet the attributes underlying these campaigns remain unclear. This study seeks to address this gap by examining trends in mobile messaging scams and testing the effectiveness of commercial …
Read original ↗https://arxiv.org/abs/2605.16656arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
quantum-safe: Bridging the Post-Quantum Production Gap with a Hybrid-by-Default Python Cryptography Library arXiv:2605.17061v1 Announce Type: new Abstract: The August 2024 finalisation of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) closed the algorithmic gap in post-quantum cryptography (PQC). The production gap -- hybrid combiners, versioned key formats, protocol helpers, and migration tooling -- remains open. We present quantum-safe, a Python library that …
Read original ↗https://arxiv.org/abs/2605.17061arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort arXiv:2605.17062v1 Announce Type: new Abstract: Spracklen et al. (USENIX Security '25) showed that code-generating large language models hallucinate package names that do not exist on PyPI or npm at rates ranging from 5.2% on commercial models to 21.7% on open-source models, creating an attack surface for slopsquatting -- the registration of malicious packages un…
Read original ↗https://arxiv.org/abs/2605.17062arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
STRIKE: A Structured Taxonomy of Cybercrime for Risk, Impact, Knowledge, and Evolution arXiv:2605.16589v1 Announce Type: new Abstract: Cybercrime has grown exponentially in both scale and sophistication, posing significant threats. As attack methods evolve rapidly, traditional classification schemes often fail to capture the complexity and diversity of modern threats. To address this gap, we introduce STRIKE,a Structured Taxonomy for Risk, Impact, Knowledge, and Emerging Thr…
Read original ↗https://arxiv.org/abs/2605.16589arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI arXiv:2605.16471v1 Announce Type: new Abstract: Generative AI systems are increasingly used not only to produce content but also to retrieve data, invoke tools, and execute actions. This work examines the security and safety implications of that shift across content-level, model-level, and agentic threats. We analyze how attacker access requirements, system autonomy, and the scope of po…
Read original ↗https://arxiv.org/abs/2605.16471arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Asking Back: Interaction-Layer Antidistillation Watermarks arXiv:2605.16462v1 Announce Type: new Abstract: Detecting unauthorized knowledge distillation from a deployed LLM API is hard because the defender controls neither the attacker's training pipeline nor the next-token logits. Existing defenses operate on the teacher's output tokens -- biasing the next-token distribution (green-list watermarks, cryptographic schemes, antidistillation sampling) or rewriting outputs after…
Read original ↗https://arxiv.org/abs/2605.16462arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
MalwarePT: A Binary-Level Foundation Model for Malware Analysis arXiv:2605.16455v1 Announce Type: new Abstract: Automated malware analysis increasingly relies on machine learning, yet most existing methods remain task-specific and depend on handcrafted features or narrowly scoped models. Recent developments in binary-level foundation models suggest a path toward reusable program representations, but their application to malware analysis remains underexplored, and most still …
Read original ↗https://arxiv.org/abs/2605.16455arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment arXiv:2605.17163v1 Announce Type: new Abstract: Traditional cybersecurity methodologies target deterministic systems and fail to address the probabilistic nature of AI, leaving systems vulnerable to attack vectors such as model inversion, data poisoning, and prompt injection. Recent industry reports indicate that a majority of organizations deploying AI lack a dedicated security strategy, with adver…
Read original ↗https://arxiv.org/abs/2605.17163arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Public-Decay Homomorphic State Space Models for Private Sequence Inference arXiv:2605.16647v1 Announce Type: new Abstract: Fully homomorphic encryption (FHE) changes sequence-model design because rotations, encrypted products, ciphertext materialization, multiplicative depth, and bootstrapping pressure can dominate ordinary neural-network costs. This paper presents public-decay homomorphic state space models (HSSMs), recurrent/state-space blocks whose carried state is update…
Read original ↗https://arxiv.org/abs/2605.16647arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
\textsc{PrivScope}: Task-scoped Disclosure Control for Hybrid Agentic Systems arXiv:2605.16630v1 Announce Type: new Abstract: Hybrid local--cloud agents enrich user requests with context from persistent working state before delegating capability-intensive subtasks to a cloud language model (CLM). While this enrichment can improve task success, it also exposes unnecessary information in the cloud-bound payload, including task-irrelevant context, carryover from prior workflows…
Read original ↗https://arxiv.org/abs/2605.16630arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
The End of Trust: How Agentic AI Breaks Security Assumptions arXiv:2605.16436v1 Announce Type: new Abstract: For decades, the security of digital interaction has rested on an unacknowledged economic constraint. Attackers faced a tradeoff between the fidelity of a deception and the scale at which it could be deployed. Convincing impersonation required sustained human effort and was confined to a narrow set of high-value targets, while mass-market attacks sacrificed plausibili…
Read original ↗https://arxiv.org/abs/2605.16436arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Filter-then-Verify: A Multiphase GNN and ModernBERT Framework for Social Engineering Detection in Email Networks arXiv:2605.17201v1 Announce Type: new Abstract: Social engineering attacks exploit human trust rather than software vulnerabilities, making them difficult to detect using conventional filters. We propose a two-stage filter-then-verify framework combining inductive Graph Neural Networks (GNNs) for structural anomaly detection with a co-attention ModernBERT model fo…
Read original ↗https://arxiv.org/abs/2605.17201arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Detecting Verbatim LLM Copy-Paste in Homework arXiv:2605.16336v1 Announce Type: new Abstract: Large language models (LLMs) have made fluent essay writing, code drafting, and quiz answering instantly available to students at every level, from secondary school through graduate study. Many educators do not object to LLM use \emph{per~se}; what they need to detect is the case in which a student pastes the assignment prompt into a chatbot and submits the model's reply verbatim, w…
Read original ↗https://arxiv.org/abs/2605.16336arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
A Red Teaming Framework for Evaluating Robustness of AI-enabled Security Orchestration, Automation, and Response Systems arXiv:2605.17075v1 Announce Type: new Abstract: AI-enabled Security Orchestration, Automation, and Response (SOAR) systems increasingly employ autonomous agents for cyber defense, yet their resilience to adaptive adversaries is underexplored. We introduce an autonomous red teaming framework that integrates large language models (LLMs) with reinforcement le…
Read original ↗https://arxiv.org/abs/2605.17075arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
A Method for Securely Transmitting Large Video Files Using Chaotic Compression and Encryption arXiv:2605.16563v1 Announce Type: new Abstract: Conventional techniques for compression and encryption are frequently laborious and resource-intensive, rendering them inappropriate for real-time applications. A plethora of research has been presented in the current literature to address these difficulties together; yet, it fails to propose any suitable strategy. Therefore, this stud…
Read original ↗https://arxiv.org/abs/2605.16563arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Post-Quantum Discovery as a Governance Capability: Evidence-Based Cryptographic Visibility and Exposure Prioritisation in a Critical Service Provider arXiv:2605.16549v1 Announce Type: new Abstract: Post Quantum Cryptography (PQC) readiness is increasingly constrained not by algorithm availability, but by cryptographic visibility, dependency complexity, and fragmented governance. This paper presents an anonymised case study of a large European critical service provider that i…
Read original ↗https://arxiv.org/abs/2605.16549arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
Simple Power Analysis on Post-Quantum Code Based Cryptosystems arXiv:2605.17116v1 Announce Type: new Abstract: Post-Quantum cryptography is about to substitute current cryptographic schemes as being resilient in attacks from quantum computers. McEleiece and Bit Flip Key Encapsulation (BIKE) are two delight representatives based on coding theory where classical structural attacks against these algorithms can be successfully phased out by selecting the appropriate key size. Us…
Read original ↗https://arxiv.org/abs/2605.17116arxiv_cs_cr · tlp:amber · 5/19/2026, 4:00:00 AM
New Wide-Net-Casting Jailbreak Attacks Risk Large Models arXiv:2605.17128v1 Announce Type: new Abstract: Jailbreak attacks on large models have drawn growing attention due to their close ties to societal safety. This work identifies a practical yet unexplored jailbreak scenario, the wide-net-casting scenario, where an adversary can query a group of large models instead of a single one to elicit harmful outputs. Our analysis reveals substantial yet previously overlooked safet…
Read original ↗https://arxiv.org/abs/2605.17128trend_micro · tlp:amber · 5/19/2026, 12:00:00 AM
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift,…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/banana-rat.htmlhuggingface_blog · tlp:amber · 5/19/2026, 12:00:00 AM
Introducing the Ettin Reranker Family Introducing the Ettin Reranker Family Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Introducing the Ettin Reranker Family Published May …
Read original ↗https://huggingface.co/blog/ettin-rerankersnyk_blog · tlp:amber · 5/18/2026, 11:00:00 PM
Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account A compromised npm maintainer account triggered an automated burst of over 300 malicious package versions across 323 packages in the AntV data visualization ecosystem, part of the ongoing Mini Shai-Hulud supply chain worm campaign. Here's what the malware does, how to detect exposure, and how to respond. Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Comp…
Read original ↗https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attackmicrosoft_mstic · tlp:amber · 5/18/2026, 10:42:50 PM
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected. The post How Storm-2949 turned a compromised identity into a cloud-wide breach appeared first on Microsoft Security Blog . In this article Attack chain overview Cloud compromi…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breachkrebs_on_security · tlp:amber · 5/18/2026, 8:48:21 PM
CISA Admin Leaked AWS GovCloud Keys on Github Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregiou…
Read original ↗https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-githubhuggingface_blog · tlp:amber · 5/18/2026, 4:00:21 PM
Fine-Tuning NVIDIA Cosmos Predict 2.5 with LoRA/DoRA for Robot Video Generation Fine-Tuning NVIDIA Cosmos Predict 2.5 with LoRA/DoRA for Robot Video Generation Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets …
Read original ↗https://huggingface.co/blog/nvidia/cosmos-fine-tuning-for-robot-video-generationmicrosoft_mstic · tlp:amber · 5/18/2026, 4:00:00 PM
How to better protect your growing business in an AI-powered world See how built-in security helps keep your growing business running, protect customer trust, and support growth. The post How to better protect your growing business in an AI-powered world appeared first on Microsoft Security Blog . AI is rapidly reshaping how work gets done in companies and organizations. In celebrating National Small Business Month, we want to acknowledge the unique challenges that growing …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/18/how-to-better-protect-your-growing-business-in-an-ai-powered-worldhuggingface_blog · tlp:amber · 5/18/2026, 3:12:46 PM
PaddleOCR 3.5: Running OCR and Document Parsing Tasks with a Transformers Backend PaddleOCR 3.5: Running OCR and Document Parsing Tasks with a Transformers Backend Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buck…
Read original ↗https://huggingface.co/blog/PaddlePaddle/paddleocr-transformerscheckpoint_research · tlp:amber · 5/18/2026, 2:58:29 PM
18th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that […] The post 18th May – Threat Intelligence Repor…
Read original ↗https://research.checkpoint.com/2026/18th-may-threat-intelligence-reporthuggingface_blog · tlp:amber · 5/18/2026, 2:12:58 PM
The Open Agent Leaderboard The Open Agent Leaderboard Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles The Open Agent Leaderboard Enterprise Article Published May 18, 2026 Upvot…
Read original ↗https://huggingface.co/blog/ibm-research/open-agent-leaderboardars_security · tlp:amber · 5/18/2026, 1:23:34 PM
Bug bounty businesses bombarded with AI slop "Never-ending" AI slop strains corporate hacking reward schemes. Companies that pay hackers to find flaws in their software are being inundated with low-quality reports generated by AI, forcing some to suspend the programs altogether. Businesses that run “bug bounty” schemes have long relied on independent security researchers to spot vulnerabilities. But the rise of AI tools is now overwhelming them with spurious submissions. Bu…
Read original ↗https://arstechnica.com/ai/2026/05/bug-bounty-businesses-bombarded-with-ai-sloplwn_kernel · tlp:amber · 5/18/2026, 1:16:04 PM
[$] Swap tables, flash-friendly swap, swap_ops, and more The kernel's swap subsystem is charged with managing anonymous pages in secondary storage when those pages are (hopefully) not being used and the memory they occupy is needed elsewhere. This long-unloved subsystem has seen a resurgence of developer interest in recent times, so it is not surprising that it was the topic of three separate sessions in the memory-management track at the 2026 Linux Storage, Filesystem, Memo…
Read original ↗https://lwn.net/Articles/1072657lwn_kernel · tlp:amber · 5/18/2026, 12:59:35 PM
Security updates for Monday Security updates have been issued by AlmaLinux (freerdp, gimp:2.8, jq, kernel, and rsync), Debian (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), Fedora (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, open-amp, perl-Net-CIDR-Lite, pg…
Read original ↗https://lwn.net/Articles/1073356trend_micro · tlp:amber · 5/18/2026, 12:00:00 AM
Agentic Governance: Why It Matters Now AI agents now act inside the trust boundary with real credentials, and agentic governance is what keeps them from quietly breaking things at machine speed. Agentic Governance: Why It Matters Now | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and thrive through a focused portfolio of cybersecurity businesses Learn more L…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/agentic-governance-why-it-matters-now.htmllwn_kernel · tlp:amber · 5/17/2026, 9:39:26 PM
Kernel prepatch 7.1-rc4 The 7.1-rc4 kernel prepatch is out for testing. Some of the documentation updates might be worth highlighting: the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools. People spend all their time just forwarding things to the right people or saying "that was already fixed a week/month ago" and pointing to the publi…
Read original ↗https://lwn.net/Articles/1073193lwn_kernel · tlp:amber · 5/17/2026, 7:36:06 PM
RIP Peter G. Neumann We have received word that Peter G. Neumann, who, among many other things, ran the RISKS Digest for decades, has passed away. He will be much missed. Update : the New York Times has published an obituary of Dr. Neumann. RIP Peter G. Neumann [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register RIP Peter G. Neuma…
Read original ↗https://lwn.net/Articles/1073186lwn_kernel · tlp:amber · 5/17/2026, 5:43:12 PM
Some weekend stable kernel updates The 7.0.9 , 6.18.32 , 6.12.90 , and 6.6.140 stable kernels have been released. Each contains yet another set of important fixes. Some weekend stable kernel updates [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us User: Password: | | Log in / Subscribe / Register Some weekend stable kernel updates [Posted May 17, 2026 by corbet] The 7.0.9 , 6.…
Read original ↗https://lwn.net/Articles/1073161