REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2333 reports · page 56 of 59
trail_of_bits · tlp:amber · 4/9/2026, 11:00:00 AM
Master C and C++ with our new Testing Handbook chapter We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code . We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases and organized them into sections covering Linux, Windows, and seccomp. Whereas other handbook chapters focus on static and dynamic analysis, this chapter offers a strong basis for manual code review. LLM ent…
Read original ↗https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chaptertrend_micro · tlp:amber · 4/9/2026, 12:00:00 AM
U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 The first quarter of 2026 has reinforced a hard truth: U.S. government agencies and educational institutions are operating in the most hostile cyber threat environment ever recorded. U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate an…
huggingface_blog · tlp:amber · 4/9/2026, 12:00:00 AM
Multimodal Embedding & Reranker Models with Sentence Transformers Multimodal Embedding & Reranker Models with Sentence Transformers Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Multimodal Embedding & Reranker Models with Sentence Transformers Published April 9, 2026 Update on GitHub Upvote 58 +52 Tom Aarsen tomaarsen Follow Table of Contents What are Multimodal Models? Installation Multimodal Embedding Models…
Read original ↗https://huggingface.co/blog/multimodal-sentence-transformershuggingface_blog · tlp:amber · 4/9/2026, 12:00:00 AM
Waypoint-1.5: Higher-Fidelity Interactive Worlds for Everyday GPUs Waypoint-1.5: Higher-Fidelity Interactive Worlds for Everyday GPUs Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Waypoint-1.5: Higher-Fidelity Interactive Worlds for Everyday GPUs Published April 9, 2026 Update on GitHub Upvote 29 +23 Andrew Lapp lapp0 Follow Overworld Louis Castricato LouisCastricato Follow Overworld Scott Fox ScottieFox Follow Overwo…
Read original ↗https://huggingface.co/blog/waypoint-1-5unit42 · tlp:amber · 4/8/2026, 10:00:51 PM
Cracks in the Bedrock: Agent God Mode Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks. The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42 . Cracks in the Bedrock: Agent God Mode Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Cracks in the Bedrock: Agent God Mode 8 min read Related Products Cort…
Read original ↗https://unit42.paloaltonetworks.com/exploit-of-aws-agentcore-iam-god-modears_security · tlp:amber · 4/8/2026, 8:49:11 PM
Iran-linked hackers disrupt operations at US critical infrastructure sites As the US and Israel's war has ramped up, so too have hacks on US industrial sites. Hackers working on behalf of the Iranian government are disrupting operations at multiple US critical infrastructure sites, likely in response to the country's ongoing war with the US, a half-dozen government agencies are warning. In an advisory published Tuesday, the FBI, Cybersecurity and Infrastructure Security Age…
Read original ↗https://arstechnica.com/security/2026/04/iran-linked-hackers-disrupt-operations-at-us-critical-infrastructure-sitesars_security · tlp:amber · 4/8/2026, 11:00:08 AM
Thousands of consumer routers hacked by Russia's military End-of-life routers in homes and small offices hacked in 120 countries. The Russian military is once again hacking home and small office routers in widespread operations that send unwitting users to sites that harvest passwords and credential tokens for use in espionage campaigns, researchers said Tuesday. An estimated 18,000 to 40,000 consumer routers, mostly those made by MikroTik and TP-Link, located in 120 countr…
Read original ↗https://arstechnica.com/security/2026/04/russias-military-hacks-thousands-of-consumer-routers-to-steal-credentialshuggingface_blog · tlp:amber · 4/8/2026, 12:00:00 AM
Safetensors is Joining the PyTorch Foundation Safetensors is Joining the PyTorch Foundation Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Safetensors is Joining the PyTorch Foundation Published April 8, 2026 Update on GitHub Upvote 38 +32 Luc Georges mcpotato Follow Lysandre lysandre Follow How we got here Why the PyTorch Foundation What this means for users and contributors What comes next Get involved Today, we're a…
Read original ↗https://huggingface.co/blog/safetensors-joins-pytorch-foundationunit42 · tlp:amber · 4/7/2026, 10:00:11 PM
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Unit 42 uncovers critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, demonstrating DNS tunneling and credential exposure. The post Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox appeared first on Unit 42 . Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malware Cracks in the Bedr…
Read original ↗https://unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-modetrail_of_bits · tlp:amber · 4/7/2026, 11:00:00 AM
What we learned about TEE security from auditing WhatsApp's Private Inference WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such as message summarization. To make this possible, Meta built a system that processes encrypted user messages inside trusted execution environments (TEEs), secure hardware enclaves designed so that not even Meta can access the plaintext. Our now-…
Read original ↗https://blog.trailofbits.com/2026/04/07/what-we-learned-about-tee-security-from-auditing-whatsapps-private-inferenceeset · tlp:amber · 4/7/2026, 9:00:00 AM
As breakout time accelerates, prevention-first cybersecurity takes center stage Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy. As breakout time accelerates, prevention-first cybersecurity takes center stage Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About E…
Read original ↗https://www.welivesecurity.com/en/business-security/breakout-time-accelerates-prevention-first-cybersecurity-center-stagetrend_micro · tlp:amber · 4/7/2026, 12:00:00 AM
Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do Threat actors leveraged Anthropic’s Claude Code npm release packaging error to distribute Vidar, GhostSocks, and PureLog Stealer. This blog details immediate steps organizations can take and best practices to prevent further risk. Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do | Trend Micro (US) search close About Mission and Culture Mission…
Read original ↗https://www.trendmicro.com/en_us/research/26/d/claude-code-remains-a-lure-what-defenders-should-do.htmlunit42 · tlp:amber · 4/6/2026, 10:00:08 PM
Understanding Current Threats to Kubernetes Environments Unit 42 uncovers escalating Kubernetes attacks, detailing how threat actors exploit identities and critical vulnerabilities to compromise cloud environments. The post Understanding Current Threats to Kubernetes Environments appeared first on Unit 42 . Understanding Current Threats to Kubernetes Environments Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Malware Malwa…
Read original ↗https://unit42.paloaltonetworks.com/modern-kubernetes-threatscheckpoint_research · tlp:amber · 4/6/2026, 11:21:31 AM
6th April – Threat Intelligence Report For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The European Commission, the European Union’s executive body, has confirmed a data breach after its Europa.eu platform was compromised through a third-party exchange linked to the Trivy supply chain attack. The incident […] The post 6th April – Threat Intelligence Report appeared…
Read original ↗https://research.checkpoint.com/2026/6th-march-threat-intelligence-report-2trail_of_bits · tlp:amber · 4/3/2026, 11:00:00 AM
Simplifying MBA obfuscation with CoBRA Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and software protectors rely on it because no standard simplification technique covers both domains simultaneously; algebraic simplifiers don’t understand bitwise logic, and Boolean minimizers can’t handle arithmetic. We’re releasing CoBRA , an open-source tool that simplifies the fu…
Read original ↗https://blog.trailofbits.com/2026/04/03/simplifying-mba-obfuscation-with-cobramandiant · tlp:amber · 4/2/2026, 2:00:00 PM
vSphere and BRICKSTORM Malware: A Defender's Guide Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. These operations directly target the VMware vSphere ecosystem, specifically the vCenter Server Appliance (VCSA) and ESXi hypervisors. To help organizations stay ahead of these risks, we will focus on the essential hardening strate…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/vsphere-brickstorm-defender-guidehuggingface_blog · tlp:amber · 4/2/2026, 12:00:00 AM
Welcome Gemma 4: Frontier multimodal intelligence on device Welcome Gemma 4: Frontier multimodal intelligence on device Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Welcome Gemma 4: Frontier multimodal intelligence on device Published April 2, 2026 Update on GitHub Upvote 890 +884 merve merve Follow Pedro Cuenca pcuenq Follow Sergio Paniego sergiopaniego Follow ben burtenshaw burtenshaw Follow Steven Zheng Steveeeeee…
Read original ↗https://huggingface.co/blog/gemma4trail_of_bits · tlp:amber · 4/1/2026, 11:00:00 AM
Mutation testing for the agentic era Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures execution, not verification. Test suites with high coverage can obfuscate the fact that critical functionality is untested as software develops over time. We saw this when mutation testing uncovered a high-severity Arkis protocol vulnerability , overlooked by coverage metrics, tha…
Read original ↗https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-eraeset · tlp:amber · 4/1/2026, 9:00:00 AM
Digital assets after death: Managing risks to your loved one’s digital estate Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay. Digital assets after death: Managing risks to your loved one’s digital estate Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podca…
Read original ↗https://www.welivesecurity.com/en/cybersecurity/digital-assets-death-managing-risks-your-loved-ones-digital-estatehuggingface_blog · tlp:amber · 4/1/2026, 7:13:20 AM
Falcon Perception Falcon Perception Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Falcon Perception Community Article Published April 1, 2026 Upvote 67 +61 FalconPerception FalconPerception Follow tiiuae The problem: why do perception systems end up as pipelines? The architecture: early fusion, hybrid attention, and an efficient dense interface One Backbone, Two Behaviors Chain-of-Perception: coarse-to-fine supervisio…
Read original ↗https://huggingface.co/blog/tiiuae/falcon-perceptionhuggingface_blog · tlp:amber · 4/1/2026, 12:00:00 AM
Any Custom Frontend with Gradio's Backend Any Custom Frontend with Gradio's Backend Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles gradio.Server: Any Custom Frontend with Gradio's Backend Published April 1, 2026 Update on GitHub Upvote 25 +19 yuvraj sharma ysharma Follow Abubakar Abid abidlabs Follow What We Wanted to Build gradio.Server</code>"> Enter gradio.Server @app.api()</code> Instead of a Plain FastAP…
Read original ↗https://huggingface.co/blog/introducing-gradio-serverhuggingface_blog · tlp:amber · 3/31/2026, 3:10:41 PM
Granite 4.0 3B Vision: Compact Multimodal Intelligence for Enterprise Documents Granite 4.0 3B Vision: Compact Multimodal Intelligence for Enterprise Documents Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Granite 4.0 3B Vision: Compact Multimodal Intelligence for Enterprise Documents Enterprise Article Published March 31, 2026 Upvote 34 +28 Madison Lee kristunlee Follow ibm-granite Rogerio Feris rferis Follow ibm-gra…
Read original ↗https://huggingface.co/blog/ibm-granite/granite-4-visionmandiant · tlp:amber · 3/31/2026, 2:00:00 PM
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack Written by: Austin Larsen, Dima Lenz, Adrian Hernandez, Tyler McLellan, Christopher Gardner, Ashley Zaya, Michael Rudden, Mon Liclican, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) is tracking an active software supply chain attack targeting the popular Node Package Manager (NPM) package " axios ." Between March 31, 2026, 00:21 and 03:20 UTC, an attacker int…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-packagecheckpoint_research · tlp:amber · 3/31/2026, 1:16:50 PM
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8…
Read original ↗https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targetstrail_of_bits · tlp:amber · 3/31/2026, 11:00:00 AM
How we made Trail of Bits AI-native (so far) This post is adapted from a talk I gave at [un]prompted , the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or download the slides . Most companies hand out ChatGPT licenses and wait for the productivity numbers to move. We built a system instead. A year ago, about 5% of Trail of Bits was on board with our AI initiative. The other 95% ranged from p…
Read original ↗https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-fareset · tlp:amber · 3/31/2026, 8:27:18 AM
This month in security with Tony Anscombe – March 2026 edition The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan This month in security with Tony Anscombe – March 2026 edition Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Pod…
Read original ↗https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-march-2026huggingface_blog · tlp:amber · 3/31/2026, 8:23:44 AM
Training mRNA Language Models Across 25 Species for $165 Training mRNA Language Models Across 25 Species for $165 Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Training mRNA Language Models Across 25 Species for $165 Team Article Published March 31, 2026 Upvote 27 +21 Maziyar Panahi MaziyarPanahi Follow OpenMed Part II: Building the Pipeline, From Structure Prediction to Codon Optimization 1. What We Built 2. The Arch…
Read original ↗https://huggingface.co/blog/OpenMed/training-mrna-models-25-speciescheckpoint_research · tlp:amber · 3/30/2026, 1:09:01 PM
ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime Key Takeaways What Happened AI assistants now handle some of the most sensitive data people own. Users discuss symptoms and medical history. They ask questions about taxes, debts, and personal finances, upload PDFs, contracts, lab results, and identity-rich documents that contain names, addresses, account details, and private records. That trust depends on a simple expectation: […] The pos…
Read original ↗https://research.checkpoint.com/2026/chatgpt-data-leakage-via-a-hidden-outbound-channel-in-the-code-execution-runtimecheckpoint_research · tlp:amber · 3/30/2026, 12:53:08 PM
30th March – Threat Intelligence Report For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Iranian state-affiliated threat group Handala Hack has breached FBI director’s Patel’s personal Gmail account and leaked many personal photos and documents. This follows the FBI’s seizure of domains related to Handala Hack’s […] The post 30th March – Threat Intelligence Report appeare…
Read original ↗https://research.checkpoint.com/2026/30th-march-threat-intelligence-reportcheckpoint_research · tlp:amber · 3/29/2026, 10:08:45 AM
AI Threat Landscape Digest January-February 2026 KEY FINDINGS AI-assisted malware development has reached operational maturity.VoidLink framework, which is modular, professionally engineered, and fully functional, was built by a single developer using a commercial AI-powered IDE within a compressed timeframe. AI-assisted development is no longer experimental but produces deployment ready output. AI-assisted development is not always obvious from the final product.VoidLink wa…
Read original ↗https://research.checkpoint.com/2026/ai-threat-landscape-digest-january-february-2026eset · tlp:amber · 3/27/2026, 10:38:21 AM
RSAC 2026 wrap-up – Week in security with Tony Anscombe This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven't caught up with RSAC 2026 wrap-up – Week in security with Tony Anscombe Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threa…
Read original ↗https://www.welivesecurity.com/en/videos/rsac-2026-wrap-up-week-security-tony-anscombeeset · tlp:amber · 3/27/2026, 7:00:00 AM
A cunning predator: How Silver Fox preys on Japanese firms this tax season Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them A cunning predator: How Silver Fox preys on Japanese firms this tax season Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts …
Read original ↗https://www.welivesecurity.com/en/business-security/cunning-predator-how-silver-fox-preys-japanese-firms-tax-seasontrail_of_bits · tlp:amber · 3/25/2026, 11:00:00 AM
Try our new dimensional analysis Claude plugin We’re releasing a new Claude plugin for developing and auditing code that implements dimensional analysis, a technique we explored in our most recent blog post . Most LLM-based security skills ask the model to find bugs. Our new dimensional-analysis plugin for Claude Code takes a different approach: it uses the LLM to annotate your codebase with dimensional types, then flags mismatches mechanically. In testing against real audit…
Read original ↗https://blog.trailofbits.com/2026/03/25/try-our-new-dimensional-analysis-claude-plugineset · tlp:amber · 3/25/2026, 10:00:00 AM
Virtual machines, virtually everywhere – and with real security gaps Cloud VMs offer unmatched speed, scale and flexibility – all of which could eventually count for little if they’re left to fend for themselves Virtual machines, virtually everywhere – but not all protected Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts…
Read original ↗https://www.welivesecurity.com/en/business-security/virtual-machines-virtually-everywhere-real-security-gapstrail_of_bits · tlp:amber · 3/24/2026, 11:00:00 AM
Spotting issues in DeFi with dimensional analysis Using dimensional analysis, you can categorically rule out a whole category of logic and arithmetic bugs that plague DeFi formulas. No code changes required, just better reasoning! One of the first lessons in physics is learning to think in terms of dimensions . Physicists can often spot a flawed formula in seconds just by checking whether the dimensions make sense. I once had a teacher who even kept a stamp that said “non-ho…
Read original ↗https://blog.trailofbits.com/2026/03/24/spotting-issues-in-defi-with-dimensional-analysiseset · tlp:amber · 3/24/2026, 10:00:00 AM
Cloud workload security: Mind the gaps As IT infrastructure expands, visibility and control often lag behind – until an incident forces a reckoning Cloud workload security: Mind the gaps Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security re…
Read original ↗https://www.welivesecurity.com/en/business-security/cloud-workload-security-mind-gapsmandiant · tlp:amber · 3/23/2026, 2:00:00 PM
M-Trends 2026: Data, Insights, and Strategies From the Frontlines Every year, the cyber threat landscape forces defenders to adapt to evolving adversary tactics, techniques, and procedures (TTPs). In 2025, Mandiant observed a clear divergence in adversary pacing that closely aligns with the trends we have been documenting for defenders over the past year. On one end of the spectrum, cyber criminal groups optimized for immediate impact and deliberate recovery denial. On the o…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026checkpoint_research · tlp:amber · 3/23/2026, 1:38:09 PM
23rd March – Threat Intelligence Report For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and […] The post 23rd March – Threat Intellig…
Read original ↗https://research.checkpoint.com/2026/23rd-march-threat-intelligence-reporteset · tlp:amber · 3/20/2026, 10:00:00 AM
Move fast and save things: A quick guide to recovering a hacked account What you do – and how fast – after an account is compromised often matters more than it may seem Move fast and save things: A quick guide to recovering a hacked account Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiv…
Read original ↗https://www.welivesecurity.com/en/cybersecurity/move-fast-save-things-quick-guide-recovering-hacked-accountsentinelone · tlp:amber · 3/19/2026, 10:00:07 AM
Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis Single-tool LLM analysis produces reports that look authoritative but aren't. A serial consensus pipeline catches artifacts and hallucinations at source. Executive Summary Large Language Models can perform static malware analysis, but individual tool runs produce unreliable results contaminated by decompiler artifacts, dead code, and hallucinated capabilities. We built a multi-agent a…
Read original ↗https://www.sentinelone.com/labs/building-an-adversarial-consensus-engine-multi-agent-llms-for-automated-malware-analysis