REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2281 reports · page 48 of 58
arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Still Camouflage, Moving Illusion: View-Induced Trajectory Manipulation in Autonomous Driving arXiv:2605.12743v1 Announce Type: new Abstract: Existing physical adversarial attacks on vision-based autonomous driving induce time-evolving perception errors, including biased object tracking or trajectory prediction, through (i) sophisticated physical patch inducing detection box drift when entering the view distance, or (ii) dynamically changing patches that cause different perc…
Read original ↗https://arxiv.org/abs/2605.12743arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
CoT-Guard: Small Models for Strong Monitoring arXiv:2605.12746v1 Announce Type: new Abstract: Monitoring the chain-of-thought (CoT) of reasoning models is a promising approach for detecting covert misbehavior (i.e., hidden objectives) in code generation tasks. While large models (GPT-5, Gemini-3-Flash) can serve as effective CoT monitors, they are expensive to deploy due to the lengthy reasoning traces and high API cost, emphasizing the need for smaller, cheaper alternatives…
arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
GraphIP-Bench: How Hard Is It to Steal a Graph Neural Network, and Can We Stop It? arXiv:2605.12827v1 Announce Type: new Abstract: Graph neural networks (GNNs) deployed as cloud services can be \emph{stolen} through \emph{model-extraction attacks}, which train a surrogate from query responses to reproduce the target's behaviour, and a growing line of ownership defenses tries to prevent or trace such theft. The title of this paper asks two questions: \emph{how hard is it to s…
Read original ↗https://arxiv.org/abs/2605.12827arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
No Attack Required: Semantic Fuzzing for Specification Violations in Agent Skills arXiv:2605.13044v1 Announce Type: new Abstract: LLM-powered agents can silently delete documents, leak credentials, or transfer funds on a routine user request, not because the agent was attacked, but because the skill it invoked broke its own declared safety rules. We call these specification violations: benign inputs cause a skill to breach the natural-language guardrails in its own specifica…
Read original ↗https://arxiv.org/abs/2605.13044arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
HE-PIM: Demystifying Homomorphic Operations on a Real-world Processing-in-Memory System arXiv:2605.12841v1 Announce Type: new Abstract: Homomorphic encryption (HE) enables computation over encrypted data, offering strong privacy guarantees for untrusted computing environments. Practical adoption remains limited by high computational complexity, large ciphertext sizes, and substantial data movement. Processor-centric architectures (CPUs, GPUs, ASICs) hit fundamental bottlenec…
Read original ↗https://arxiv.org/abs/2605.12841arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
DiffusionHijack: Supply-Chain PRNG Backdoor Attack on Diffusion Models and Quantum Random Number Defense arXiv:2605.13115v1 Announce Type: new Abstract: Diffusion models depend on pseudo-random number generators (PRNGs) for latent noise sampling. We present DiffusionHijack, a supply-chain backdoor attack that hijacks the PRNG to deterministically control generated images. A malicious PRNG, injected via compromised packages, forces pixel-perfect reproduction of attacker-chose…
Read original ↗https://arxiv.org/abs/2605.13115arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Quantifying LLM Safety Degradation Under Repeated Attacks Using Survival Analysis arXiv:2605.12869v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly deployed in a wide range of applications, yet remain vulnerable to adversarial jailbreak attacks that circumvent their safety guardrails. Existing evaluation frameworks typically report binary success/failure metrics, failing to capture the temporal dynamics of how attacks succeed under persistent adve…
Read original ↗https://arxiv.org/abs/2605.12869arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Extending Blockchain Untraceability with Plausible Deniability arXiv:2605.13132v1 Announce Type: new Abstract: Traditional blockchain untraceability schemes, such as mixers and privacy coins, obscure the sender-receiver relationship by placing transfers within an anonymity set. This paper studies a stronger goal: whether the transfer event itself can be made unobservable by blending into common decentralized-finance (DeFi) activity. We introduce Deniable Covert Asset Transfe…
Read original ↗https://arxiv.org/abs/2605.13132arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills arXiv:2605.12875v1 Announce Type: new Abstract: Programmatic skills in LLM ecosystems consist of a natural-language description and executable implementation files. Users and LLMs rely on the description to understand the skill's scope. However, the implementation may perform security-relevant operations, such as credential access, network communication, or command execut…
Read original ↗https://arxiv.org/abs/2605.12875arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
Inducing Overthink: Hierarchical Genetic Algorithm-based DoS Attack on Black-Box Large Language Reasoning Models arXiv:2605.13338v1 Announce Type: new Abstract: Large Reasoning Models (LRMs) are increasingly integrated into systems requiring reliable multi-step inference, yet this growing dependence exposes new vulnerabilities related to computational availability. In particular, LRMs exhibit a tendency to "overthink", producing excessively long and redundant reasoning trace…
Read original ↗https://arxiv.org/abs/2605.13338arxiv_cs_cr · tlp:amber · 5/14/2026, 4:00:00 AM
ThermalTap: Passive Application Fingerprinting in VR Headsets via Thermal Side Channels arXiv:2605.12927v1 Announce Type: new Abstract: Standalone virtual reality (VR) headsets process highly sensitive personal, professional, and health-related data, yet their susceptibility to non-contact physical side channels remains largely unexplored. Existing side-channel attacks typically require malicious software execution or physical access to peripherals, making them conspicuous a…
Read original ↗https://arxiv.org/abs/2605.12927lwn_kernel · tlp:amber · 5/14/2026, 1:04:18 AM
[$] LWN.net Weekly Edition for May 14, 2026 Inside this week's LWN.net Weekly Edition: Front : Fedora AI; Forgejo "carrot" disclosure; memory-management maintainership; huge THPs; mshare; 64KB base pages; DAMON; direct map. Briefs : Dirty Frag; Fragnesia; Mythos and curl; killswitch; Debian reproducible builds; KDE investment; Quotes ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1071535huggingface_blog · tlp:amber · 5/14/2026, 12:00:00 AM
Unlocking asynchronicity in continuous batching Unlocking asynchronicity in continuous batching Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Unlocking asynchronicity in cont…
Read original ↗https://huggingface.co/blog/continuous_asynclwn_kernel · tlp:amber · 5/13/2026, 4:05:26 PM
[$] Friction in Fedora over AI developer desktop initiative A push by Red Hat employees to create a Fedora "AI Developer Desktop" with support for out-of-tree kernel drivers and AI toolkits has been met with objections from some long-time members of the Fedora community. After more than a month of sometimes heated discussion, the Fedora Council had voted to approve the initiative; however, a last-minute change to vote against the proposal by council member Justin Wheeler has…
Read original ↗https://lwn.net/Articles/1071949lwn_kernel · tlp:amber · 5/13/2026, 3:26:20 PM
Yet another Dirty Frag type vulnerability: Fragnesia Sam James has sent an announcement to the OSS Security mailing list about another local-privilege-escalation (LPE) exploit in the same class as Dirty Frag , called "Fragnesia". From the disclosure : This is a separate bug in the ESP/XFRM from dirtyfrag which has received its own patch. However, it is in the same surface and the mitigation is the same as for dirtyfrag. It abuses a logic bug in the Linux XFRM ESP-in-TCP subs…
Read original ↗https://lwn.net/Articles/1072647lwn_kernel · tlp:amber · 5/13/2026, 2:20:00 PM
[$] Managing pages outside of the direct map When Brendan Jackman proposed a session for the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit , his topic was " a pagetable library for the kernel ". During the actual memory-management-track session, though, he stated that the idea had " fizzled " and he was going to cover related topics instead. What resulted was a session on ways to efficiently manage pages that are not present in the kernel's direct map.
Read original ↗https://lwn.net/Articles/1072367lwn_kernel · tlp:amber · 5/13/2026, 1:19:22 PM
[$] Revisiting mshare Linux can share memory between processes, but each process (almost always) has its own set of page tables. In situations where vast numbers of processes are sharing a memory region, the combined size of the page tables can exceed that of the shared memory itself. There has, thus, long been an interest in enabling unrelated processes to share page tables referring to shared memory. Anthony Yznaga is the latest developer to try to push this idea (known as…
Read original ↗https://lwn.net/Articles/1072333lwn_kernel · tlp:amber · 5/13/2026, 1:17:03 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (corosync, freerdp, git-lfs, glib2, jq, kernel-rt, krb5, libpng, libtiff, openexr, and thunderbird), Debian (exim4), Mageia (apache, perl-Gazelle, php, and sed), Slackware (expat), SUSE (assimp-devel, go1.26, libQt6Svg6, python-jupyterlab, raylib, thunderbird, tor, and trivy), and Ubuntu (exim4). Security updates for Wednesday [LWN.net] LWN .net News from the source Content Weekly Edition Archives…
Read original ↗https://lwn.net/Articles/1072596lwn_kernel · tlp:amber · 5/13/2026, 1:09:08 PM
Sovereign Tech Fund invests in KDE The KDE project has announced that it has been awarded over €1 million from the Sovereign Tech Fund to improve its desktop-environment software. " The investment will be used to strengthen the structural reliability and security of KDE's core infrastructure, including Plasma, KDE Linux, and the frameworks underlying its communication services. " Sovereign Tech Fund invests in KDE [LWN.net] LWN .net News from the source Content Weekly …
Read original ↗https://lwn.net/Articles/1072565checkpoint_research · tlp:amber · 5/13/2026, 1:01:01 PM
Thus Spoke…The Gentlemen Key Points Introduction The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. Its operators advertise the service across multiple underground forums, promoting their ransomware platform and inviting penetration testers and other technically skilled actors to join as affiliates. In 2026, based on victims listed on the data leak site (DLS), […] The post Thus Spoke…The Gentlemen appeared fir…
Read original ↗https://research.checkpoint.com/2026/thus-spoke-the-gentlementalos · tlp:amber · 5/13/2026, 10:00:54 AM
Breaking things to keep them safe with Philippe Laulheret Philippe shares his unique journey from French engineering school to the front lines of cybersecurity, explaining how his lifelong love for solving puzzles helps him uncover critical security flaws before they can be exploited. In the latest Humans of Talos, Amy sits down with Senior Vulnerability Researcher Philippe Laulheret to demystify the world of ethical hacking. Philippe shares his unique journey from French e…
Read original ↗https://blog.talosintelligence.com/breaking-things-to-keep-them-safe-with-philippe-laulheretgoogle_project_zero · tlp:amber · 5/13/2026, 7:00:00 AM
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain for the Pixel 9, we wanted to see if it was possible to write a similar exploit chain for Pixel 10. Up…
Read original ↗https://projectzero.google/2026/05/pixel-10-exploit.htmlarxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Few-Shot Truly Benign DPO Attack for Jailbreaking LLMs arXiv:2605.10998v1 Announce Type: new Abstract: Fine-tuning APIs make frontier LLMs easy to customize, but they can also weaken safety alignment during fine-tuning. While prior work shows that benign supervised fine-tuning (SFT) can reduce refusal behavior, deployed fine-tuning pipelines increasingly support preference-based objectives, whose safety risks remain less understood. We show that Direct Preference Optimizatio…
Read original ↗https://arxiv.org/abs/2605.10998arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Digital Identity for Agentic Systems: Toward a Portable Authorization Standard for Autonomous Agents arXiv:2605.11487v1 Announce Type: new Abstract: Enterprise AI is shifting from copilots to autonomous agents capable of executing workflows, negotiating outcomes, and making decisions with limited human oversight. As these systems extend across organizational boundaries, identity alone is insufficient: an agent's authority must also be explicit, constrained, auditable, revoca…
Read original ↗https://arxiv.org/abs/2605.11487arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Can a Single Message Paralyze the AI Infrastructure? The Rise of AbO-DDoS Attacks through Targeted Mobius Injection arXiv:2605.11442v1 Announce Type: new Abstract: Large Language Model (LLM) agents have emerged as key intermediaries, orchestrating complex interactions between human users and a wide range of digital services and LLM infrastructures. While prior research has extensively examined the security of LLMs and agents in isolation, the systemic risk of the agent actin…
Read original ↗https://arxiv.org/abs/2605.11442arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Options, Not Clicks: Lattice Refinement for Consent-Driven MCP Authorization arXiv:2605.11360v1 Announce Type: new Abstract: As Model Context Protocol adoption grows, securing tool invocations via meaningful user consent has become a critical challenge, as existing methods, broad always allow toggles or opaque LLM-based decisions, fail to account for dangerous call arguments and often lead to consent fatigue. In this work, we present Conleash, a client-side middleware that e…
Read original ↗https://arxiv.org/abs/2605.11360arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
A Systematic Security Testing Approach for InterUSS-based environments arXiv:2605.11339v1 Announce Type: new Abstract: Unmanned Traffic Management (UTM) federated ecosystems, such as InterUSS, enable secure coordination among UAS Service Suppliers (USSs). However, they bring up some security challenges at the infrastructure level that haven't been fully explored. This paper presents a security testing approach for InterUSS-based environments from the maintainer's perspective…
Read original ↗https://arxiv.org/abs/2605.11339arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Context-Aware Spear Phishing: Generative AI-Enabled Attacks Against Individuals via Public Social Media Data arXiv:2605.11268v1 Announce Type: new Abstract: We demonstrate how publicly available social-media data and generative AI (GenAI) can be misused to automate and scale highly personalized, context-aware spear-phishing campaigns. With minimal attacker effort, a small amount of public activity per target is sufficient for GenAI models to extract interests and contextual …
Read original ↗https://arxiv.org/abs/2605.11268arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Comment and Control: Hijacking Agentic Workflows via Context-Grounded Evolution arXiv:2605.11229v1 Announce Type: new Abstract: Automation platforms such as GitHub Actions and n8n are increasingly adopting so-called agentic workflows, which integrate Large Language Model (LLM) agents for tasks such as code review and data synchronization. While bringing convenience for developers, this integration exposes a new risk: An adversary may control and craft certain inputs, such as…
Read original ↗https://arxiv.org/abs/2605.11229arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Continuous Discovery of Vulnerabilities in LLM Serving Systems with Fuzzing arXiv:2605.11202v1 Announce Type: new Abstract: LLM inference and serving systems have become security-critical infrastructure; however, many of their most concerning failures arise from the serving layer rather than from model behavior alone. Modern inference engines combine KV cache, batching, prefix sharing, speculative decoding, adapters, and multi-tenant scheduling, creating shared-state behavio…
Read original ↗https://arxiv.org/abs/2605.11202arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Adversarial SQL Injection Generation with LLM-Based Architectures arXiv:2605.11188v1 Announce Type: new Abstract: SQL injection (SQLi) attacks are still one of the serious attacks ranked in the Open Worldwide Application Security Project (OWASP) Top 10 threats. Today, with advances in Artificial Intelligence (AI), especially in Large Language Models (LLMs), an opportunity has been created for automating adversarial attack tests to measure the defense mechanisms. In this pape…
Read original ↗https://arxiv.org/abs/2605.11188arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Benchmarking LLM-Based Static Analysis for Secure Smart Contract Development: Reliability, Limitations, and Potential Hybrid Solutions arXiv:2605.11163v1 Announce Type: new Abstract: The irreversible nature of blockchain transactions makes the identification of smart contract vulnerabilities an essential requirement for secure system development. While Large Language Models (LLMs) are increasingly integrated into developer workflows, their reliability as autonomous security …
Read original ↗https://arxiv.org/abs/2605.11163arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
FedSurrogate: Backdoor Defense in Federated Learning via Layer Criticality and Surrogate Replacement arXiv:2605.11122v1 Announce Type: new Abstract: Federated Learning remains highly susceptible to backdoor attacks--malicious clients inject targeted behaviours into the global model. Existing defenses suffer from substantial false-positive rates under realistic non-independent and identically distributed (non-IID) data, incorrectly flagging benign clients and degrading model …
Read original ↗https://arxiv.org/abs/2605.11122arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? arXiv:2605.11086v1 Announce Type: new Abstract: AI agents are rapidly gaining capabilities that could significantly reshape cybersecurity, making rigorous evaluation urgent. A critical capability is exploitation: turning a vulnerability, which is not yet an attack, into a concrete security impact, such as unauthorized file access or code execution. Exploitation is a particularly challenging task becau…
Read original ↗https://arxiv.org/abs/2605.11086arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
MCPShield: Content-Aware Attack Detection for LLM Agent Tool-Call Traffic arXiv:2605.11053v1 Announce Type: new Abstract: The Model Context Protocol (MCP) has become a widely adopted interface for LLM agents to invoke external tools, yet learned monitoring of MCP tool-call traffic remains underexplored. In this article, MCPShield is presented as an attack detection framework for MCP tool-call traffic that encodes each agent session as a graph (tool calls as nodes, sequential…
Read original ↗https://arxiv.org/abs/2605.11053arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw arXiv:2605.11047v1 Announce Type: new Abstract: Agentic language-model systems increasingly rely on mutable execution contexts, including files, memory, tools, skills, and auxiliary artifacts, creating security risks beyond explicit user prompts. This paper presents DeepTrap, an automated framework for discovering contextual vulnerabilities in OpenClaw. DeepTrap formulates adversarial context ma…
Read original ↗https://arxiv.org/abs/2605.11047arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
A Multi-Interface Firmware Acquisition and Validation Methodology for Low-Cost Consumer Drones: A Case Study on Three Holy Stone Platforms arXiv:2605.11040v1 Announce Type: new Abstract: Consumer unmanned aerial vehicles (UAVs) have evolved into capable computing platforms, yet their embedded firmware remains largely inaccessible to the security community. Entry-level models, in particular those marketed to first-time and younger operators, commonly ship with limited protect…
Read original ↗https://arxiv.org/abs/2605.11040arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck arXiv:2605.11039v1 Announce Type: new Abstract: Tool-using LLM agents must act on untrusted webpages, emails, files, and API outputs while issuing privileged tool calls. Existing defenses often mediate trust at the granularity of an entire tool invocation, forcing a brittle choice in mixed-trust workflows: allow external content to influence a ca…
Read original ↗https://arxiv.org/abs/2605.11039arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
Sequential Behavioral Watermarking for LLM Agents arXiv:2605.11036v1 Announce Type: new Abstract: LLM-based agents act through sequences of executable decisions, but their trajectories provide little evidence of which agent or policy produced them, making provenance, ownership, and unauthorized reuse difficult to establish from observed behavior alone. This motivates watermarking signals embedded directly into agent behavior rather than only into generated text, since text w…
Read original ↗https://arxiv.org/abs/2605.11036arxiv_cs_cr · tlp:amber · 5/13/2026, 4:00:00 AM
MambaNetBurst: Direct Byte-level Network Traffic Classification without Tokenization or Pretraining arXiv:2605.11034v1 Announce Type: new Abstract: We present MambaNetBurst, a compact tokenizer-free byte-level sequence classifier for network burst classification based on a Mamba-2 backbone. In contrast to most recent strong traffic-classification and intrusion-detection approaches, our method operates directly on raw packet bytes, avoids tokenization, patching, and heavy eng…
Read original ↗https://arxiv.org/abs/2605.11034