REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 5 of 21
arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
TRACE: A Two-Channel Robust Attribution Watermark via Complementary Embeddings for LLM-Agent Trajectories arXiv:2607.08400v1 Announce Type: new Abstract: LLM agents reach users through resellers, who may rebrand a developer's agent or substitute a cheaper model. When provenance is disputed, attribution rests on the trajectory log (the record of tool calls, observations, and executed actions, not the model's reasoning), which the reseller stores and processes to meter usage. …
Read original ↗https://arxiv.org/abs/2607.08400arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
TRM-Raft: A Byzantine-Resistant Raft Consensus via Integrated Trust and Reputation Model arXiv:2607.08666v1 Announce Type: new Abstract: Internetware envisions autonomous software entities collaborating over the open Internet. Raft consensus is widely adopted for its simplicity and performance in distributed coordination, e.g., service registries and blockchains. However, Raft assumes crash faults only, making it vulnerable to Byzantine behaviors like election forgery and lo…
arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Forensic Schema for Psychological Manipulation in Cyber Fraud: LLM-Driven Victim Reports Analysis arXiv:2607.07751v1 Announce Type: new Abstract: Existing cybercrime classification schemas capture contact metadata and financial transactions but omit the psychological manipulation techniques perpetrators employ. We present a forensic schema (four categories, 35 questions) adding 11 manipulation indicators and cryptocurrency evidence fields to established forensic foundations.…
Read original ↗https://arxiv.org/abs/2607.07751arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents arXiv:2607.08395v1 Announce Type: new Abstract: Persistent AI agents extend large language models (LLMs) beyond single-turn interaction into long-lived software systems. Unlike traditional chat assistants, unsafe content in these agents can propagate through persistent state, reusable skills, and tool-mediated interactions, creating a substantially larger semantic attack surface. We observe that most sec…
Read original ↗https://arxiv.org/abs/2607.08395arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Controllability-Aware Adversarial Examples Against LLM-Based Network Traffic Classifiers arXiv:2607.07739v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly explored as network intrusion detection classifiers, but their adversarial robustness under realistic attacker constraints remains unclear. We present a controllability-aware black-box transfer framework for LLM-based network traffic classifiers. The framework partitions flow features into direc…
Read original ↗https://arxiv.org/abs/2607.07739arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
ScopeJudge: Cost-Aware Pre-Execution Gating for Offensive Security Agents arXiv:2607.07774v1 Announce Type: new Abstract: As LLM agents take on offensive security work, a single out-of-scope tool call can breach a client's engagement boundary, disrupt production, or void a bug-bounty finding. Unlike a fixed safety policy, the boundary that matters is declared in the user's request and must be inferred from intent. That challenge is sharpened by the adversarial nature of offe…
Read original ↗https://arxiv.org/abs/2607.07774arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Multi-Agent Firewall Architecture for Privacy Protection of Sensitive Data in Interactions with Language Models arXiv:2607.08282v1 Announce Type: new Abstract: While Large Language Models (LLMs) have become essential productivity tools, their integration into workflows without adequate safeguards creates significant risks. This paper proposes an open-source, privacy-focused, user-facing firewall designed to secure both web-based and programmatic LLM interactions. The archite…
Read original ↗https://arxiv.org/abs/2607.08282arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis arXiv:2607.08232v1 Announce Type: new Abstract: Mini-programs have become a dominant paradigm for lightweight application deployment within super apps such as WeChat. To support seamless integration, super apps provide OAuth mechanisms for user login. However, improper integration of OAuth-based Authentication (OBA) flows by third-party developers can lead to crit…
Read original ↗https://arxiv.org/abs/2607.08232arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Simulating the Resident: Generating Executable Smart Home Schedules via LLM Personas arXiv:2607.08231v1 Announce Type: new Abstract: Smart homes have emerged as an important domain for HCI research, including work on usable security and privacy. Ideally, studies in these areas draw on datasets collected in real homes with real residents, capturing authentic device interactions, network traffic, and daily routines. However, creating such datasets is slow, expensive, and raise…
Read original ↗https://arxiv.org/abs/2607.08231arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure arXiv:2607.08288v1 Announce Type: new Abstract: In critical infrastructure, operational technology environments often cannot be actively scanned, and yet active system feedback is needed for risk assessment and compliance. This paper presents a non-invasive, MCP-grounded multi-agent pipeline that converts natural-language system descriptions in…
Read original ↗https://arxiv.org/abs/2607.08288arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Threshold Authorization Without Threshold Signatures: Signature-Agnostic MPC Custody arXiv:2607.08226v1 Announce Type: new Abstract: Digital-asset custody has been built on threshold multi-party approval: no operation proceeds unless $t$ of $n$ parties approve, and fewer than t compromised parties can neither authorize nor learn the authorization secret. Threshold signature schemes (TSS) have been the standard mechanism, but the post-quantum transition disrupts this model: s…
Read original ↗https://arxiv.org/abs/2607.08226arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
MLQENABLER: Enabling Secure Machine Learning Queries over Encrypted Database in Cloud Computing arXiv:2607.08197v1 Announce Type: new Abstract: In cloud computing, the public cloud service providers (CSPs) can provide cloud storage as the primary service while providing additional machine learning (ML)-based services by using the clients' data in storage. This business model extends the border of cloud computing services and brings in new business growth possibilities. Altho…
Read original ↗https://arxiv.org/abs/2607.08197arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts arXiv:2607.08292v1 Announce Type: new Abstract: The NIS-2 Directive increases the need for continuous, auditable compliance evidence and motivates a shift from document-based compliance toward machine-readable compliance artifacts. The Open Security Controls Assessment Language (OSCAL) is a standard for this purpose, which the German Federal Office for Information Sec…
Read original ↗https://arxiv.org/abs/2607.08292arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Mechanistic Interpretability of LLM Jailbreaks via Internal Attribution Graphs arXiv:2607.07903v1 Announce Type: new Abstract: Large language models (LLMs) exhibit remarkable capabilities but remain highly vulnerable to adversarial prompts and jailbreak attacks. Existing approaches primarily analyze these failures through input-output behaviors or attribution methods, offering limited insight into how adversarial perturbations alter the model's internal reasoning. Consequent…
Read original ↗https://arxiv.org/abs/2607.07903arxiv_cs_cr · tlp:amber · 7/10/2026, 4:00:00 AM
Secure QR Codes: Authenticity Verification via EdDSA Signatures and CBOR Certificates arXiv:2607.08383v1 Announce Type: new Abstract: QR codes are a ubiquitous part of daily life, widely trusted by millions. However, their lack of inherent security features has given rise to critical attack vectors, such as spoofing (quishing) on public infrastructure like self-service parking machines. To address this, we present a comprehensive evolution of secure QR code architectures. Fi…
Read original ↗https://arxiv.org/abs/2607.08383arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages arXiv:2607.06596v1 Announce Type: new Abstract: Trusted monitoring is a central defense in AI control: a cheaper trusted model scores an untrusted model's actions for sabotage, and the most suspicious are audited or deferred. Such monitors are evaluated against one or two untrusted models, and the accuracy is reported as a property of the monitor. We ask whether it is partly a property o…
Read original ↗https://arxiv.org/abs/2607.06596arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies arXiv:2607.06963v1 Announce Type: new Abstract: Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated…
Read original ↗https://arxiv.org/abs/2607.06963arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Thinking More, Harnessing Better: State Machine Guided Harness Automatic Generation with Project Digestion and Workflow Decomposition arXiv:2607.07007v1 Announce Type: new Abstract: High-quality fuzz harnesses are essential for effective gray-box fuzzing. While Large Language Models (LLMs) offer promise for automating this task, existing one-turn generation methods suffer from hallucinations and inadequate coverage due to coarse-grained function targeting and misaligned gene…
Read original ↗https://arxiv.org/abs/2607.07007arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
An Automated Framework for Generating Stealthy Cell-Embedded Hardware Trojans arXiv:2607.07049v1 Announce Type: new Abstract: Hardware Trojans (HTs) pose significant threats across the Integrated Circuit (IC) design lifecycle because they can be inserted by untrusted entities at different stages under the zero-trust model. When triggered under rare conditions, HTs can compromise the functionality, reliability, or security of the fabricated chip. HT assessment is typically pe…
Read original ↗https://arxiv.org/abs/2607.07049arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Security and Privacy in Agentic AI: Grand Challenges and Future Directions arXiv:2607.06608v1 Announce Type: new Abstract: We present key challenges and future research directions in the security and privacy of agentic AI, based on a horizon-scanning exercise that brought together thirty leading international experts from academia, industry, and government to engage in focused discussions and collaborative exercises on the emerging risks associated with the growing agency of…
Read original ↗https://arxiv.org/abs/2607.06608arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Auditable Machine Unlearning for Privacy-Compliant Ransomware Detection Using Multi-Shard SISA and Deep Reinforcement Learning arXiv:2607.06860v1 Announce Type: new Abstract: Ransomware poses an escalating cybersecurity threat as attackers continuously modify behavioral patterns to evade static defenses. Although existing machine learning-based detectors often achieve strong predictive performance, they generally assume fixed training data and do not support the selective re…
Read original ↗https://arxiv.org/abs/2607.06860arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
SA-DRL: Security-Aware Deep Reinforcement Learning for Ransomware Detection with Asymmetric Reward Design arXiv:2607.06880v1 Announce Type: new Abstract: Ransomware detection is a security-critical task in which false negatives and false positives have unequal operational consequences. Conventional machine learning detectors often use symmetric objectives that penalize missed ransomware detections and benign false alarms equally, although a false negative can cause irreversi…
Read original ↗https://arxiv.org/abs/2607.06880arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents arXiv:2607.06595v1 Announce Type: new Abstract: Personal AI agents powered by large language models can reason and act using available tools to access emails, manage calendars, and push code to remote repositories, all with minimal oversight. When augmented with long-term memory, an agent can recall specific details relevant to the current task, reducing the need for large context windows.…
Read original ↗https://arxiv.org/abs/2607.06595arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
When Agents Go Rogue: Activation-Based Detection of Malicious Behaviors in Multi-Agent Systems arXiv:2607.06807v1 Announce Type: new Abstract: While enabling effective collaboration on complex tasks, LLM-based Multi-Agent Systems (MAS) face critical security challenges due to vulnerabilities at the agent and interaction levels. Most existing MAS security defenses are built upon two core assumptions: semantically-explicit malicious attacks and explicit graph-based modeling of…
Read original ↗https://arxiv.org/abs/2607.06807arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
ECO/CPO-DAG: A Contradiction-Based Accountability Layer for Adversarial Supply Chains arXiv:2607.06804v1 Announce Type: new Abstract: We present ECO/CPO-DAG, a domain-specific accountability protocol for adversarial supply chains that formalizes contradiction detection as a supplemental validation layer rather than a consensus or truth-establishing mechanism. Participants publish signed Event Claim Objects (ECOs) into a causally ordered, append-only directed acyclic graph (D…
Read original ↗https://arxiv.org/abs/2607.06804arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Blockchain Attacks and Defenses: A Layered and Cross-Domain Survey arXiv:2607.06593v1 Announce Type: new Abstract: Blockchains have evolved from simple distributed ledgers into programmable platforms that process complex application logic and carry significant financial value. All modern Web3 systems share a common goal: providing secure, decentralized, and trustworthy execution in an increasingly interconnected environment. However, this evolution has shifted the attack sur…
Read original ↗https://arxiv.org/abs/2607.06593arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
MoLIFE: Methodology, Technologies, and Challenges for Mobile Live Intelligent Forensics Examination arXiv:2607.07269v1 Announce Type: new Abstract: Nowadays, mobile forensics is less explored in Digital Forensics case analysis due to the increase in data protection mechanisms implemented by tech companies (i.e., Google for Android and Apple for iOS). For example, the physical acquisition or analysis of specific directories under super-user protection would corrupt the eviden…
Read original ↗https://arxiv.org/abs/2607.07269arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Safe2Hail: A Forensic-Driven Post-Trip Tracking Framework for Ride-Hailing Safety in Africa arXiv:2607.07271v1 Announce Type: new Abstract: Ride-hailing mobile apps have become an essential feature in the mobility ecosystem in Africa, offering much safer and much more affordable rides. Although user bases have increased and the number of daily trips has proliferated, reports of imminent safety threats, particularly after the cancellation of the ride or the ride is prematurel…
Read original ↗https://arxiv.org/abs/2607.07271arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
POPS: Recovering Unlearned Multi-Modality Knowledge in MLLMs with Prompt-Optimized Parameter Shaking arXiv:2607.06649v1 Announce Type: new Abstract: Multimodal Large Language Models (MLLMs) have demonstrated impressive performance on cross-modal tasks by jointly training on large-scale textual and visual data, where privacy-sensitive examples could be unintentionally encoded, raising concerns about privacy or copyright violation. To this end, Multi-modality Machine Unlearnin…
Read original ↗https://arxiv.org/abs/2607.06649arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Behavioral Privacy Leakage in Agentic Negotiation: Formalizing and Mitigating Inference Attacks via Randomized Policies arXiv:2607.06815v1 Announce Type: new Abstract: Autonomous negotiation agents are increasingly deployed in high-stakes settings such as insurance and procurement. While cryptographic techniques protect explicitly disclosed constraint values, they fail to address a subtler threat: behavioral privacy leakage, where an adversary infers private constraints from…
Read original ↗https://arxiv.org/abs/2607.06815arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Evaluating Endpoint Detection Robustness Against Genetic Algorithm Driven Code Transformations arXiv:2607.07191v1 Announce Type: new Abstract: Post-compromise test variants are widely used in controlled security evaluation and endpoint robustness benchmarking. However, modern Antivirus (AV) and Endpoint Detection and Response (EDR) systems increasingly combine signature- and behavior-based detection, challenging the reliability of conventional detection pipelines under adapt…
Read original ↗https://arxiv.org/abs/2607.07191arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Is Randomness Necessary for Adaptive Data Analysis? arXiv:2607.07085v1 Announce Type: new Abstract: The Adaptive Data Analysis (ADA) problem formalizes the challenge of preventing false discovery and overfitting when a dataset is repeatedly reused. Formally, our input is a dataset containing $n$ i.i.d. samples from an unknown distribution $\mathcal{P}$ over a domain $\mathcal{X}$, and our goal is to answer a sequence of $k$ adaptively chosen statistical queries with respect …
Read original ↗https://arxiv.org/abs/2607.07085arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Certifying Ghosts: How Cybersecurity AI Agents Break the EU Cyber Resilience Act arXiv:2607.07109v1 Announce Type: new Abstract: The EU Cyber Resilience Act (CRA) makes a smart bet. It does not demand that products be free of vulnerabilities, but only that manufacturers run a process: assess risk, handle flaws, ship updates. The bet pays off if four things about the world stay true: (P1) finding vulnerabilities is slow, skilled, human work; (P2) a product's exploitable flaws…
Read original ↗https://arxiv.org/abs/2607.07109arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe arXiv:2607.07209v1 Announce Type: new Abstract: Modern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor contin…
Read original ↗https://arxiv.org/abs/2607.07209arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Cyber Dynamics I: Finite Macrostates for Behavioral Anomaly Detection in Network Telemetry arXiv:2607.07075v1 Announce Type: new Abstract: Entropy-based methods have long been used for network anomaly detection, but most existing approaches treat entropy as a scalar statistic on narrow observables rather than as part of a broader behavioral state-space for cyber systems. We propose a finite-dimensional macrostate framework for network telemetry, instantiated over the Canonic…
Read original ↗https://arxiv.org/abs/2607.07075arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
The Power of Backdoor Absorption in Community Training arXiv:2607.06643v1 Announce Type: new Abstract: Backdoor attacks severely threaten large-scale AI models. When model owners delegate training to external compute providers within a decentralized training paradigm, adversaries can craft stealthy, low-frequency triggers to inject malicious behavior while evading standard audits. Traditionally, detecting these attacks requires a full re-computation of the training steps--a …
Read original ↗https://arxiv.org/abs/2607.06643arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
PRoVeFL: Private Robust and Verifiable Aggregation in Federated Learning arXiv:2607.06612v1 Announce Type: new Abstract: Federated Learning (FL) enables multiple clients to collaboratively train machine learning models while retaining data locality, thereby enhancing user privacy. However, traditional FL frameworks rely on a centralized aggregation server and assume honest-but-curious clients, making them susceptible to both server-side inference and client-side poisoning at…
Read original ↗https://arxiv.org/abs/2607.06612arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Monitoring Vulnerabilities in Next-Generation Automotive Operating Systems arXiv:2607.07226v1 Announce Type: new Abstract: Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short i…
Read original ↗https://arxiv.org/abs/2607.07226arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
Deanonymizing Monero Transactions in Tor Network arXiv:2607.07062v1 Announce Type: new Abstract: Monero is a privacy-focused cryptocurrency that deploys the Dandelion++ protocol and incorporates anonymity networks (such as Tor and I2P) to prevent malicious attackers from linking transactions with their source IPs. In this paper, we demonstrate that Monero's integration of the Tor network introduces a fundamental vulnerability: a Monero Tor node's originated transactions are …
Read original ↗https://arxiv.org/abs/2607.07062arxiv_cs_cr · tlp:amber · 7/9/2026, 4:00:00 AM
ORAN-DEFEND: Subspace Detection and Sanitization of Backdoor DRL xApps in Open RAN arXiv:2607.06647v1 Announce Type: new Abstract: Open Radio Access Networks (O-RAN) increasingly delegate near-real-time control to deep reinforcement learning (DRL) xApps obtained from third-party vendors, creating a new supply-chain attack surface. A backdoor policy behaves optimally until an adversary injects a covert trigger into the observed key performance indicator (KPI) telemetry, at wh…
Read original ↗https://arxiv.org/abs/2607.06647