REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2281 reports · page 46 of 58
lwn_kernel · tlp:amber · 5/15/2026, 2:54:56 PM
[$] Controlling memory-management with BPF Roman Gushchin began his session in the memory-management track of the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit by saying that the community has seen a lot of proposals adding BPF-based interfaces for memory management. None of them have made their way into the mainline, though. He wanted to explore the ways in which BPF might be helpful and the obstacles that have kept BPF-based solutions out so far. This s…
Read original ↗https://lwn.net/Articles/1072538mandiant · tlp:amber · 5/15/2026, 2:00:00 PM
Welcome to BlackFile: Inside a Vishing Extortion Operation Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass tra…
lwn_kernel · tlp:amber · 5/15/2026, 1:34:24 PM
Seven new stable kernels with patches for CVE-2026-46333 Greg Kroah-Hartman has announced the 7.0.8 , 6.18.31 , 6.12.89 , 6.6.139 , 6.1.173 , 5.15.207 , and 5.10.256 stable kernels. These kernels contain a patch for CVE-2026-46333 a vulnerability reported by the Qualys Security Advisory team , though Jann Horn proposed a patch in 2020. The vulnerability has a proof-of-concept exploit published already. Some of the kernels have additional patches for other bugs; as always, us…
Read original ↗https://lwn.net/Articles/1073060lwn_kernel · tlp:amber · 5/15/2026, 1:27:42 PM
[$] HugeTLB preservation over live update Recent times have seen a lot of effort put into the implementation of the kexec handover and live update orchestrator features in the Linux kernel. But that work is not yet complete. At the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , Pratyush Yadav led a memory-management-track session on adding the ability to preserve hugetlbfs -provided memory during the live-update process.
Read original ↗https://lwn.net/Articles/1072531lwn_kernel · tlp:amber · 5/15/2026, 1:16:03 PM
Security updates for Friday Security updates have been issued by Debian (ffmpeg, gsasl, nodejs, postgresql-15, postgresql-17, python3.9, and thunderbird), Fedora (expat, firefox, freerdp, GitPython, kernel, php, rust-podman-sequoia, rust-rpm-sequoia, rust-sequoia-chameleon-gnupg, rust-sequoia-git, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-openpgp, rust-sequoia-sop, rust-sequoia-sq, and rust-sequoia-sqv), Mageia (awstats, libreoffice, perl-HTTP-T…
Read original ↗https://lwn.net/Articles/1073059cisa_alerts · tlp:amber · 5/15/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of K…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/15/cisa-adds-one-known-exploited-vulnerability-catalogunit42 · tlp:amber · 5/15/2026, 10:00:52 AM
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42 . Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files Menu Tools ATOMs Security Consulting About Us Under…
Read original ↗https://unit42.paloaltonetworks.com/gremlin-stealer-evolutioneset · tlp:amber · 5/15/2026, 8:50:00 AM
Why geopolitical turmoil is a gift for scammers, and how to stay safe Conflict is a boon for opportunistic fraudsters. Look out for their ploys. Why geopolitical turmoil is a gift for scammers, and how to stay safe Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine …
Read original ↗https://www.welivesecurity.com/en/scams/geopolitical-turmoil-gift-scammers-how-stay-safearxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
XAI and Statistical Analysis for Reliable Intrusion Detection in the UAVIDS-2025 Dataset: From Tree to Hybrid and Tabular DNN Ensembles arXiv:2605.13922v1 Announce Type: new Abstract: During the last few years, the term Mechanistic Interpretability, a specific area, under the umbrella of explainable artificial intelligence (XAI), has been introduced, to explain the decisions made by complex machine learning (ML) models in critical systems like UAV intrusion detection systems…
Read original ↗https://arxiv.org/abs/2605.13922arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Analyzing Codes of Conduct for Online Safety in Video Games at Scale arXiv:2605.15047v1 Announce Type: new Abstract: Online video games have become major online social spaces where users interact, compete, and create together. These spaces, however, expose users to a wide spectrum of online harms, including harassment, discrimination, inappropriate content, privacy breach, cheating, and more. The shape and severity of such harms vary across game design, mechanics, and commun…
Read original ↗https://arxiv.org/abs/2605.15047arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
ExploitBench: A Capability Ladder Benchmark for LLM Cybersecurity Agents arXiv:2605.14153v1 Announce Type: new Abstract: Exploitation is not a binary event. It is a ladder of acquiring progressive capabilities, from executing a single buggy line of code to taking full control of the target. However, existing LLM security benchmarks treat a crash as exploitation success. That single binary outcome collapses the hard parts of exploitation: the transition from triggering a bug …
Read original ↗https://arxiv.org/abs/2605.14153arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Defenses at Odds: Measuring and Explaining Defense Conflicts in Large Language Models arXiv:2605.14514v1 Announce Type: new Abstract: Large Language Models (LLMs) deployed in high-stakes applications must simultaneously manage multiple risks, yet existing defenses are almost exclusively evaluated in isolation under a one-shot deployment assumption. In practice, providers patch models incrementally throughout their lifecycle-responding to newly exposed vulnerabilities or targ…
Read original ↗https://arxiv.org/abs/2605.14514arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections arXiv:2605.15030v1 Announce Type: new Abstract: Web agents can autonomously complete online tasks by interacting with websites, but their exposure to open web environments makes them vulnerable to prompt injection attacks embedded in HTML content or visual interfaces. Existing guard models still suffer from limited generalization to unseen domains and attack patterns, high false positive rates on beni…
Read original ↗https://arxiv.org/abs/2605.15030arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Do Coding Agents Understand Least-Privilege Authorization? arXiv:2605.14859v1 Announce Type: new Abstract: As coding agents gain access to shells, repositories, and user files, least-privilege authorization becomes a prerequisite for safe deployment: an agent should receive enough authority to complete the task, without unnecessary authority that exposes sensitive surfaces.To study whether current models can infer this boundary themselves, we first introduce permission-bound…
Read original ↗https://arxiv.org/abs/2605.14859arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
On the (non-)resilience of encrypted controllers to covert attacks arXiv:2605.14230v1 Announce Type: new Abstract: The security of networked control systems (NCS) is receiving increasing attention from both cyber-security and system-theoretic perspectives. The former focuses on classical IT security goals such as confidentiality, integrity, and availability of process data, while the latter investigates tailored attacks (and detection schemes), including covert and zero-dyna…
Read original ↗https://arxiv.org/abs/2605.14230arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Exploiting LLM Agent Supply Chains via Payload-less Skills arXiv:2605.14460v1 Announce Type: new Abstract: Autonomous agents powered by Large Language Models (LLMs) acquire external functionalities through third-party skills available in open marketplaces. Adopting these integrations broadens the potential attack surface, prompting a need for systematic security evaluation. Current auditing mechanisms are effective at identifying explicit code payloads and predefined threat …
Read original ↗https://arxiv.org/abs/2605.14460arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Toward Securing AI Agents Like Operating Systems arXiv:2605.14932v1 Announce Type: new Abstract: Autonomous agents based on large language models (LLMs) are rapidly emerging as a general-purpose technology, with recent systems such as OpenClaw extending their capabilities through broad tool use, third-party skills, and deeper integration into user environments. At the same time, these agentic systems introduce substantial security risks by combining unconstrained capabilitie…
Read original ↗https://arxiv.org/abs/2605.14932arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Characterizing AI-Assisted Bot Traffic in Darknet Data: Implications for ICS and IIoT Security arXiv:2605.14209v1 Announce Type: new Abstract: The rise of automated scanning tools and AI assisted reconnaissance agents has significantly altered internet background traffic patterns, threatening the baseline assumptions underlying intrusion detection systems (IDS) deployed in critical infrastructure networks. This paper characterizes the evolution of automated bot traffic by an…
Read original ↗https://arxiv.org/abs/2605.14209arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Web Agents Should Adopt the Plan-Then-Execute Paradigm arXiv:2605.14290v1 Announce Type: new Abstract: ReAct has become the default architecture across LLM agents, and many existing web agents follow this paradigm. We argue that it is the wrong default for web agents. Instead, web agents should default to plan-then-execute: commit to a task-specific program before observing runtime web content, then execute it. The reason is that web content mixes inputs from many parties. A…
Read original ↗https://arxiv.org/abs/2605.14290arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
To See is Not to Learn: Protecting Multimodal Data from Unauthorized Fine-Tuning of Large Vision-Language Model arXiv:2605.14291v1 Announce Type: new Abstract: The rapid advancement of Large Vision-Language Models (LVLMs) is increasingly accompanied by unauthorized scraping and training on multimodal web data, posing severe copyright and privacy risks to data owners. Existing countermeasures, such as machine unlearning and watermarks, are inherent post-hoc approaches that ac…
Read original ↗https://arxiv.org/abs/2605.14291arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Memory Forensics Techniques for Automated Detection and Analysis of Go Malware arXiv:2605.14020v1 Announce Type: new Abstract: The Go programming language has become increasingly popular among malware developers due to its ability to produce statically linked, cross-platform executables that challenge traditional analysis techniques. These binaries embed a substantial runtime and compiler-generated metadata and are compiled with aggressive optimizations that discard type inf…
Read original ↗https://arxiv.org/abs/2605.14020arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces arXiv:2605.14786v1 Announce Type: new Abstract: As LLM-based agents increasingly browse the web on users' behalf, a natural question arises: can websites passively identify which underlying model powers an agent? Doing so would represent a significant security risk, enabling targeted attacks tailored to known model vulnerabilities. Across 14 frontier LLMs and four web environments spanning information re…
Read original ↗https://arxiv.org/abs/2605.14786arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Model Forensics in AI-Native Wireless Networks: Taxonomy, Applications, and Case Study arXiv:2605.14387v1 Announce Type: new Abstract: As artificial intelligence (AI) is increasingly embedded in wireless networks, models are becoming core components that influence signal processing, resource scheduling and network control. However, model anomalies, tampering and malicious functions also introduce new security risks. In this article, we focus on model forensics in AI-native w…
Read original ↗https://arxiv.org/abs/2605.14387arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Adapting AlphaEvolve to Optimize Fully Homomorphic Encryption on TPUs arXiv:2605.14718v1 Announce Type: new Abstract: The deployment of Fully Homomorphic Encryption (FHE) at scale is hindered due to its heavy computational overhead. While specialized hardware accelerators like Google Tensor Processing Units (TPUs) can help, mapping complex cryptographic kernels onto such architectures remains a challenge. Efficient execution requires co-optimization between the systolic arra…
Read original ↗https://arxiv.org/abs/2605.14718arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
DSTAN-Med: Dual-Channel Spatiotemporal Attention with Physiological Plausibility Filtering for False Data Injection Attack Detection in IoT-Based Medical Devices arXiv:2605.14165v1 Announce Type: new Abstract: False data injection (FDI) attacks on Internet of Medical Things (IoMT) sensor streams falsify vital signs in transit, threatening patient safety and defeating clinical monitoring systems that lack cyber-physical anomaly detection capability. Existing deep learning det…
Read original ↗https://arxiv.org/abs/2605.14165arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills arXiv:2605.13940v1 Announce Type: new Abstract: Third-party skills are becoming the package ecosystem for LLM agents. They package natural-language instructions, helper scripts, templates, documents, and service configuration into reusable workflows. This makes skills useful, but it also introduces a new security problem: a malicious skill does not need to ask the model to perform an obviously harmful ac…
Read original ↗https://arxiv.org/abs/2605.13940arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
The Great Pretender: A Stochasticity Problem in LLM Jailbreak arXiv:2605.14418v1 Announce Type: new Abstract: "Oh-Oh, yes, I'm the great pretender. Pretending that I'm doing well. My need is such, I pretend too much..." summarizes the state in the area of jailbreak creation and evaluation. You find this method to generate adversarial attacks proposed by a reputable institution (e.g., BoN from Anthropic or Crescendo from Microsoft Research). However, this method does not deli…
Read original ↗https://arxiv.org/abs/2605.14418arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Capacitive Touchscreens at Risk: A Practical Side-Channel Attack on Smartphones via Electromagnetic Emanations arXiv:2605.14633v1 Announce Type: new Abstract: Capacitive touchscreens in modern smartphones introduce severe side-channel vulnerabilities. However, existing attacks often require restrictive conditions or invasive measurements. This paper presents TESLA, a novel, contactless electromagnetic (EM) side-channel attack that exploits inherent EM emanations during touch…
Read original ↗https://arxiv.org/abs/2605.14633arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
One Step to the Side: Why Defenses Against Malicious Finetuning Fail Under Adaptive Adversaries arXiv:2605.14605v1 Announce Type: new Abstract: Model providers increasingly release open weights or allow users to fine-tune foundation models through APIs. Although these models are safety-aligned before release, their safeguards can often be removed by fine-tuning on harmful data. Recent defenses aim to make models robust to such malicious fine-tuning, but they are largely eval…
Read original ↗https://arxiv.org/abs/2605.14605arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
Privacy Auditing with Zero (0) Training Run arXiv:2605.14591v1 Announce Type: new Abstract: Privacy auditing provides empirical lower bounds on the differential privacy parameters of learning algorithms. Existing methods, however, require interventional access to the training pipeline, either to retrain multiple times or to randomize data inclusion. This is often infeasible for large deployed systems such as foundation models. We introduce Zero-Run privacy auditing, a post-h…
Read original ↗https://arxiv.org/abs/2605.14591arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
PickleFuzzer: A Case Study in Fuzzing for Discrepancies Between Python Pickle Implementations arXiv:2605.15084v1 Announce Type: new Abstract: Python's native serialization protocol, pickle, is a powerful but insecure format for transferring untrusted data. It is frequently used, especially for saving machine learning models, despite known security challenges. While developers sometimes mitigate this risk by restricting imports during unpickling or using static and dynamic an…
Read original ↗https://arxiv.org/abs/2605.15084arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
EVA: Editing for Versatile Alignment against Jailbreaks arXiv:2605.14750v1 Announce Type: new Abstract: Large Language Models (LLMs) and Vision Language Models (VLMs) have demonstrated impressive capabilities but remain vulnerable to jailbreaking attacks, where adversaries exploit textual or visual triggers to bypass safety guardrails. Recent defenses typically rely on safety fine-tuning or external filters to reduce the model's likelihood of producing harmful content. While…
Read original ↗https://arxiv.org/abs/2605.14750arxiv_cs_cr · tlp:amber · 5/15/2026, 4:00:00 AM
MemLineage: Lineage-Guided Enforcement for LLM Agent Memory arXiv:2605.14421v1 Announce Type: new Abstract: We introduce MemLineage, a defense for LLM agent memory that attaches both cryptographic provenance and LLM-mediated derivation lineage to every entry. Recent and concurrent work shows that untrusted content can be written into persistent agent state and re-enter later sessions as an instruction; the remaining systems question is how to preserve useful memory recall wh…
Read original ↗https://arxiv.org/abs/2605.14421snyk_blog · tlp:amber · 5/15/2026, 12:00:00 AM
Malicious node-ipc versions published to npm in suspected maintainer account compromise On May 14, 2026, multiple malicious versions of the popular npm package node-ipc were published to the npm registry. Current public reporting identifies node... Malicious node-ipc Versions Published to npm | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven …
Read original ↗https://snyk.io/blog/malicious-node-ipc-versions-published-npmlwn_kernel · tlp:amber · 5/14/2026, 7:02:35 PM
[$] Policy groups for memory management The kernel's control-group subsystem works well for resource management, Chris Li said at the beginning of his memory-management-track session at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit . Control groups work less well for other use cases, though. He was there to present his proposed enhancement, called "policy groups", that would address some of the shortcomings that he has encountered. A consensus on how …
Read original ↗https://lwn.net/Articles/1072517huggingface_blog · tlp:amber · 5/14/2026, 6:55:01 PM
Granite Embedding Multilingual R2: Open Apache 2.0 Multilingual Embeddings with 32K Context — Best Sub-100M Retrieval Quality Granite Embedding Multilingual R2: Open Apache 2.0 Multilingual Embeddings with 32K Context — Best Sub-100M Retrieval Quality Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise …
Read original ↗https://huggingface.co/blog/ibm-granite/granite-embedding-multilingual-r2ars_security · tlp:amber · 5/14/2026, 6:32:01 PM
Zero-day exploit completely defeats default Windows 11 BitLocker protections It's not entirely clear how the exploit works. Microsoft says it's investigating. A zero-day exploit circulating online allows people with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted drive within seconds. The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. I…
Read original ↗https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protectionstalos · tlp:amber · 5/14/2026, 6:00:24 PM
The time of much patching is coming In this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases. Welcome to this week’s edition of the Threat Source newsletter.  Many solutions have been proposed to reduce software bugs: zero-defect mandates, pair programming, formal methods, and mathematical software proofs. The reality is that software engineering …
Read original ↗https://blog.talosintelligence.com/the-time-of-much-patching-is-comingtalos · tlp:amber · 5/14/2026, 4:02:36 PM
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage. Cisco Talos is tracking the active exploitation of CVE-2026-20182 , an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD…
Read original ↗https://blog.talosintelligence.com/sd-wan-ongoing-exploitationmicrosoft_mstic · tlp:amber · 5/14/2026, 4:00:00 PM
Defense in depth for autonomous AI agents As AI agents gain autonomy, defense in depth must evolve, with application-layer design, identity, and human oversight at the center. The post Defense in depth for autonomous AI agents appeared first on Microsoft Security Blog . Designing Secure Autonomous AI Agents with Defense in Depth AI agents are moving beyond assistance and into action. Instead of generating content, they invoke tools, modify data, trigger workflows, and opera…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/14/defense-in-depth-autonomous-ai-agents