REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2281 reports · page 47 of 58
microsoft_mstic · tlp:amber · 5/14/2026, 3:00:00 PM
Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target environments. The post Kazuar: Anatomy of a nat…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnetlwn_kernel · tlp:amber · 5/14/2026, 2:54:26 PM
[$] Buffered atomic writes, writethrough, and more In back-to-back sessions at the start of the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit (which spilled over into a third slot), the atomic-buffered-writes feature was discussed. In the first session, Pankaj Raghav and Andres Freund set the stage with an introduction to the problem, along with a use case for its solution: the PostgreSQL database system. In the second, Ojaswin Mujoo described a potential…
lwn_kernel · tlp:amber · 5/14/2026, 2:44:32 PM
Three stable kernels for Thursday Greg Kroah-Hartman has announced the release of the 7.0.7 , 6.18.30 , and 6.12.88 stable kernels. These kernels do not include a patch for the Fragnesia local-privilege-escalation exploit that came to light on May 13, but do include many other important fixes throughout the tree. Users are, as always, advised to upgrade. Three stable kernels for Thursday [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Ker…
Read original ↗https://lwn.net/Articles/1072849microsoft_mstic · tlp:amber · 5/14/2026, 2:20:55 PM
When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps Exposed UIs, weak authentication, and risky defaults could turn cloud-native AI apps on Kubernetes into potential targets by threat actors. Learn how exploitable misconfigurations lead to RCE and data leaks. The post When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps appeared first on Microsoft Security Blog . In this article Background What is an exploitab…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/14/configuration-becomes-vulnerability-exploitable-misconfigurations-ai-appslwn_kernel · tlp:amber · 5/14/2026, 1:14:30 PM
[$] Keeping COWs in context (a.k.a. anonymous reverse mapping) The kernel's reverse-mapping machinery is charged with locating the page-table entries that refer to a given page in memory. The reverse mapping of anonymous pages is handled differently than for file-backed pages. The kernel's implementation of reverse mapping for anonymous pages is, according to Lorenzo Stoakes in his proposal for a memory-management-track session at the 2026 Linux Storage, Filesystem, Memory M…
Read original ↗https://lwn.net/Articles/1072378lwn_kernel · tlp:amber · 5/14/2026, 1:09:38 PM
Security updates for Thursday Security updates have been issued by AlmaLinux (gimp, jq, and yggdrasil), Debian (nghttp2 and thunderbird), Fedora (chromium, firefox, freerdp, GitPython, kernel, kernel-headers, krb5, nano, nix, nodejs20, php, python-click, python-django5, SDL2_image, and xen), Mageia (dnsmasq, flatpak, kernel, kmod-virtualbox, kernel-linus, perl-Net-CIDR-Lite, perl-XML-LibXML, and redis), SUSE (dnsmasq, firefox, jupyter-jupyterlab, kernel, krb5, libvinylapi3, …
Read original ↗https://lwn.net/Articles/1072838sentinelone · tlp:amber · 5/14/2026, 1:00:44 PM
LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout Mick Baccio and Scott Roberts examine whether public breach signals and market timing models can turn cyber incidents into actionable trading opportunities. When a company suffers a cyber breach, its stock price often takes a hit, but the timing, depth, and duration of that reaction are far less predictable. In this LABScon25 presentation, Mick Baccio and Scott Roberts explore whether public indicators of breach acti…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-breach-alpha-trading-on-cyber-falloutcisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Siemens ROS# View CSAF Summary ROS# contains a ROS service file_server, that before version 2.2.2 contains a path traversal vulnerability which could allow an attacker to access, i.e. read and write, arbitrary files, which are accessible with the user rights of the user that runs the service, on the system that hosts service. Siemens has released a new version for ROS# and recommends to update to the latest version. The following versions of Siemens Siemens ROS# are …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-08cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIMATIC S7 PLC Web Server View CSAF Summary SIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMAT…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-15cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox contains an input validation vulnerability in the feature key installation process that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/&…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-11cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIMATIC View CSAF Summary SIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version. The following versions of Siemens SIMATIC are affected: SIMATIC CN 4100 vers:intdot/<5.0 CVSS Vendor Equipment Vulnerabilities v3 9.6 Siemens Siemens SIMATIC NULL Pointer Dereference, Reacha…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SENTRON 7KT PAC1261 Data Manager View CSAF Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain administrative control over the device. Siemens has released a new version for SENTRON 7KT PAC1261 Data Manager and recommends to update to the latest version. The following versions of Si…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-14cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Industrial Devices View CSAF Summary Multiple industrial devices contain a vulnerability that could allow an attacker to cause a denial of service condition. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Industrial Devices are affec…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-06cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox contains an input validation vulnerability in the Scheduler functionality that could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-12cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIMATIC View CSAF Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link. This vulnerability allows an attacker to access the web browser through the Control Panel if it is not protected by the corresponding security mechanisms. This opens the possibility for the attacker to find backdoors, which might lead to unwanted misconfigurations. Siemens has re…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-07cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Universal Robots Polyscope 5 View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code. The following versions of Universal Robots Polyscope 5 are affected: Polyscope 5 <5.25.1 CVSS Vendor Equipment Vulnerabilities v3 9.8 Universal Robots Universal Robots Polyscope 5 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure S…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-17cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Simcenter Femap View CSAF Summary Simcenter Femap is affected by heap based buffer overflow vulnerability in Datakit library that could be triggered when the application reads files in IPT format. If a user is tricked to open a malicious file with the affected application, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released a new version for Simcenter Femap and recommends to update …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-05cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox before v2.17.1 contain multiple third-party vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1 (CVE-2019-13103, CVE-2019-13104, CVE-2019-13106, CVE-2019-14192, CVE-2019-14193, CVE-2019-14194, CVE-2019-14195, CVE-2019-14196, CVE-2019-14197, CVE-…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Teamcenter View CSAF Summary Siemens Teamcenter is affected by multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Teamcenter are affected: Teamcenter V2312 vers:intdot/<2312.0014, vers:intdot/<2312.0009 (CVE-2026-33862, CVE-2026-33893, CVE-2024-4367) Team…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-04cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Ruggedcom Rox View CSAF Summary Ruggedcom Rox contains an improper access control vulnerability that could allow an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/<2.17.1 RUGGEDCOM ROX …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-02cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Opcenter RDnL View CSAF Summary Opcenter RDnL is affected by missing authentication in critical function in ‘ActiveMQ Artemis’. An unauthenticated attacker within the adjacent network could use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in availability impacts or message injection into any queue via the rogue broker. Breaking the integrity of a me…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-09cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens SIPROTEC 5 View CSAF Summary The SIPROTEC 5 devices do not use sufficiently random numbers to generate session identifiers. This could facilitate a brute-force attack against a valid session identifier which could allow an unauthenticated remote attacker to hijack a valid user session. The affected session identifiers are only used in a subset of the endpoints that are provided by the affected products. Siemens is preparing fix versions and recommends countermeasures…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-13cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens Solid Edge View CSAF Summary Solid Edge SE2026 before Update 5 is affected by two file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released a new version for Solid Edge SE2026 and recommends to update to the latest version. The following versions of Siemens Solid Edge are affected: Solid Edge vers:intdot/&l…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-03cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
Siemens gWAP View CSAF Summary Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code. Siemens has released a new version for gWAP and recommends to update to the la…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-01cisa_alerts · tlp:amber · 5/14/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Note: Please ad…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/14/cisa-adds-one-known-exploited-vulnerability-catalogeset · tlp:amber · 5/14/2026, 8:50:00 AM
FrostyNeighbor: Fresh mischief and digital shenanigans ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations FrostyNeighbor: Fresh mischief and digital shenanigans Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts Whi…
Read original ↗https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigansarxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Security Incentivization: An Empirical Study of how Micropayments Impact Code Security arXiv:2605.13100v1 Announce Type: new Abstract: Security often receives insufficient developer attention because it does not directly generate visible value, leading to underinvestment in practice. We evaluate a countermeasure by team-level incentives tied to measurable security improvements over time. Our semi-automated mechanism aggregates static analysis findings from Bearer, Detekt, an…
Read original ↗https://arxiv.org/abs/2605.13100arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Context-Aware Web Attack Detection in Open-Source SIEM Systems via MITRE ATT&CK-Enriched Behavioral Profiling arXiv:2605.13337v1 Announce Type: new Abstract: Security Information and Event Management (SIEM) systems aggregate log data from heterogeneous sources to detect coordinated attacks. Traditional rule-based correlation engines struggle to classify multi-step web application attacks because they examine each event without reference to the behavioural history of the orig…
Read original ↗https://arxiv.org/abs/2605.13337arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
From Compression to Accountability: Harmless Copyright Protection for Dataset Distillation arXiv:2605.12942v1 Announce Type: new Abstract: Large-scale datasets have been a key driving force behind the rapid progress of deep learning, but their storage, computational, and energy costs have become increasingly prohibitive. Dataset distillation (DD) mitigates this problem by synthesizing compact yet informative datasets, thereby enabling efficient model training and storage. Ho…
Read original ↗https://arxiv.org/abs/2605.12942arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Automatic Detection of Reference Counting Bugs in Linux Kernel Drivers arXiv:2605.13246v1 Announce Type: new Abstract: Reference counting bugs in Linux kernel drivers can lead to severe resource mismanagement and security vulnerabilities. We introduce DrvHorn, a novel automated tool to detect these bugs by reducing reference counting verification to an assertion checking problem leveraging the Linux driver interface. Through efficient modeling of the Linux kernel and aggress…
Read original ↗https://arxiv.org/abs/2605.13246arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Insecure Despite Proven Updated: Extracting the Root VCEK Seed on EPYC Milan via a Software-Only Attack arXiv:2605.12990v1 Announce Type: new Abstract: In the official whitepaper of Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP), AMD explicitly emphasizes the capability to prevent Trusted Computing Base (TCB) rollback attacks. Cryptographically, this is realized by signing attestation reports with the Versioned Chip Endorsement Key (VCEK), which is deriv…
Read original ↗https://arxiv.org/abs/2605.12990arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Backdoor Channels Hidden in Latent Space: Cryptographic Undetectability in Modern Neural Networks arXiv:2605.13214v1 Announce Type: new Abstract: Recent cryptographic results establish that neural networks can be backdoored such that no efficient algorithm can distinguish them from a clean model. These guarantees, however, have been confined to stylised architectures of limited practical relevance, leaving open whether comparable undetectability extends to modern, end-to-end…
Read original ↗https://arxiv.org/abs/2605.13214arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
CLOUDBURST: Cloud-Layer Observations Using Beacons for Unified Real-time Surveillance and Threat Attribution arXiv:2605.12976v1 Announce Type: new Abstract: Modern cloud-native environments present a fundamentally different exfiltration threat surface than traditional file-based scenarios. Attackers targeting AWS, GCP, Azure, and OCI steal S3 presigned URLs, container images, Kubernetes secrets, Terraform state modules, and IAM role tokens -- artefacts that existing honeytok…
Read original ↗https://arxiv.org/abs/2605.12976arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
LoREnc: Low-Rank Encryption for Securing Foundation Models and LoRA Adapters arXiv:2605.13163v1 Announce Type: new Abstract: Foundation models and low-rank adapters enable efficient on-device generative AI but raise risks such as intellectual property leakage and model recovery attacks. Existing defenses are often impractical because they require retraining or access to the original dataset. We propose LoREnc, a training-free framework that secures both FMs and adapters via …
Read original ↗https://arxiv.org/abs/2605.13163arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Empowering IoT Security: On-Device Intrusion Detection in Resource Constrained Devices arXiv:2605.13159v1 Announce Type: new Abstract: IoT devices particularly microcontrollers are challenged by their inherent limitations in processing capabilities, memory capacity, and energy conservation. Securing communication within IoT networks is further complicated by the heterogeneity of devices and the myriad of potential security threats. Our study introduces a lightweight model th…
Read original ↗https://arxiv.org/abs/2605.13159arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Watermarking Should Be Treated as a Monitoring Primitive arXiv:2605.13095v1 Announce Type: new Abstract: Watermarking is widely proposed for provenance, attribution, and safety monitoring in generative models, yet is typically evaluated only under adversaries who attempt to evade detection or induce false positives at the level of individual samples. We argue that watermarking should be treated as a monitoring primitive, and that internal monitoring is unavoidable given per-…
Read original ↗https://arxiv.org/abs/2605.13095arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
BackFlush: Knowledge-Free Backdoor Detection and Elimination with Watermark Preservation in Large Language Models arXiv:2605.12529v1 Announce Type: new Abstract: In recent trends, one can observe Large Language Models (LLMs) are exposed to backdoor attacks where vicious triggers added during training or model editing to elicit harmful outputs on specific input patterns while maintaining clean performance on normal inputs. Legitimate watermarks used as ownership signatures sh…
Read original ↗https://arxiv.org/abs/2605.12529arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Ghost in the Context: Measuring Policy-Carriage Failures in Decision-Time Assembly arXiv:2605.12535v1 Announce Type: new Abstract: LM agents do not act on raw interaction history; they act on a bounded decision state assembled by truncation, summarization, reordering, and rewriting. If directive-bearing state is dropped, weakened, or rebound during that step, an agent can cross a policy boundary without prompt override, model changes, or persistent-memory compromise. We stud…
Read original ↗https://arxiv.org/abs/2605.12535arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
OverrideFuzz: Semantic-Aware Grammar Fuzzing for Script-Runtime Vulnerabilities arXiv:2605.12563v1 Announce Type: new Abstract: Script-language runtimes such as Python, Lua, and JavaScript are widely deployed in security sensitive contexts, yet they remain difficult to test because valid inputs must satisfy syntax, dynamic type constraints, and object-level semantics. Existing grammar and reflection-based fuzzers improve syntactic validity and interface reachability, but the…
Read original ↗https://arxiv.org/abs/2605.12563arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Persona-Conditioned Adversarial Prompting (PCAP): Multi-Identity Red-Teaming for Enhanced Adversarial Prompt Discovery arXiv:2605.12565v1 Announce Type: new Abstract: Existing automated red-teaming pipelines often miss attacks that depend on attacker identity, framing, or multi-turn tactics. This under-coverage underestimates real-world risk. We introduce Persona-Conditioned Adversarial Prompting (PCAP), which conditions adversarial search on attacker personas and strategy c…
Read original ↗https://arxiv.org/abs/2605.12565