REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 6 of 54
arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
BARS: Benign-Anchored Ranking and Selection for False Alarm Reduction in Network Intrusion Detection arXiv:2607.13203v1 Announce Type: new Abstract: False alarms remain a major barrier to deploying network intrusion detection systems (NIDS). In high-volume environments, even a sub-1% false positive rate can generate tens of thousands of daily alerts. Filter-based feature selection is attractive because it operates upstream of the classifier and adds no inference-time cost. H…
Read original ↗https://arxiv.org/abs/2607.13203arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Composable Trust for Language Models: A proven boundary and a measured defense arXiv:2607.13149v1 Announce Type: new Abstract: In a language model, instructions and data share one token stream, so nothing inside the model's generation can keep untrusted text from steering it. We develop a trust model that places the authority to act outside the model, in code: a source's standing, not its content, decides which operation runs and whether it acts. A lower-trust source may inf…
arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
The Entanglement Wall: Activation-Space Probes as Risk Detectors, Not Context Adjudicators arXiv:2607.13075v1 Announce Type: new Abstract: Context can change whether a request is harmful without changing its topic or surface form. We ask whether residual-stream probes distinguish harmful requests from surface-matched benign controls at a useful operating point. Across three 7-8B model families, an activation sensor blocks 95.5-97.7 percent of judge-classified compliant attac…
Read original ↗https://arxiv.org/abs/2607.13075arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
SingGuard-NSFA: Extensible Guardrails for Agentic AI via Generative Reasoning and Real-Time Classification arXiv:2607.13081v1 Announce Type: new Abstract: We present nsfaguard, a guardrail framework for securing agentic AI systems against operational threats, such as prompt injection, sensitive information extraction, malicious code requests, dangerous tool misuse, and resource exhaustion. We first introduce the NSFA taxonomy, which organizes 185 risk variants into a CIA-tri…
Read original ↗https://arxiv.org/abs/2607.13081arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
To Play or Not to Play: Insights and Lessons Learned from 20 Years of CTFs with ENOFLAG arXiv:2607.13480v1 Announce Type: new Abstract: Security contests in the form of CTF (Capture The Flag) exercises are nowadays a common way to learn cyber security. 20 years ago at DIMVA 2006 the on-site CTF CIPHER II was one of the conference highlights and led to the foundation of the team ENOFLAG. In this poster, we reflect on the changes in the CTF gameplay and report on lessons learn…
Read original ↗https://arxiv.org/abs/2607.13480arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
{\epsilon}-Indistinguishability In Moving Target Defense: Framework, Algorithms, And Cloud Case Studies arXiv:2607.13440v1 Announce Type: new Abstract: Moving Target Defense (MTD) assumes its pool of candidate configurations is safe to cycle among, i.e. latency and other observables do not trivially fingerprint the active choice, but this assumption has not been quantified at the pool level. We formalize this pool-safety problem as finding the largest $\varepsilon$-close sub…
Read original ↗https://arxiv.org/abs/2607.13440arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Proof in a Bottle: Long-Lived Verifiable Secret Sharing via Pre-Quantum Commitment and Immutable Ledger Binding arXiv:2607.13235v1 Announce Type: new Abstract: Traditional secret sharing techniques such as Verifiable Secret sharing (VSS) are vulnerable to quantum attacks by a Cryptographically Relevant Quantum Computer (CRQC) running Shor's algorithm. We observe that the binding a VSS needs is required only at the moment of dealing, and this binding can be made before any CR…
Read original ↗https://arxiv.org/abs/2607.13235arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
AI in Cyberpsychology: A systematic literature review of Cybersecurity enhancement by using AI for analyzing psychology of Victims, Attackers, and Defenders arXiv:2607.13123v1 Announce Type: new Abstract: Cybersecurity is the practice of protecting systems, networks, and data from digital attacks. Cyberpsychology (CPSY) is defined as the use of psychology to enhance cybersecurity applications. Since the early 2010s, the evolution of Artificial Intelligence (AI) has increasin…
Read original ↗https://arxiv.org/abs/2607.13123arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
GDM AI Control Roadmap arXiv:2607.13087v1 Announce Type: new Abstract: AI agents are rapidly accelerating work at frontier AI companies, helping with AI R&D, cyber-defence, and advancing scientific discoveries. As these agents become more tightly integrated into our systems, unlocking their full potential requires rethinking how we do security. We should not assume that AI agents are always perfectly aligned, but should instead build in multiple layers of defence. We pre…
Read original ↗https://arxiv.org/abs/2607.13087arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Operational Evidence Gaps for LLMs in Fraud Detection and Trust-and-Safety Workflows arXiv:2607.13078v1 Announce Type: new Abstract: LLMs are now proposed for fraud detection, scam investigation, content moderation, and other trust-and-safety workflows. Much of the public literature still evaluates them as models, with less attention to their behavior as components in operational pipelines. This creates a practical evidence question: what would justify placing an LLM inside …
Read original ↗https://arxiv.org/abs/2607.13078arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
xChk: Bring Your Own Identity -- Heterogeneous Assurance with Verifier-Determined Sufficiency arXiv:2607.13369v1 Announce Type: new Abstract: We present xChk, a reference identity provider for Bring Your Own Identity (BYOI): users enroll via heterogeneous proofs (government KYC, corporate SSO, WebAuthn/FIDO2, professional networks, live verification, longitudinal activity, behavioral signals) and disclose them as portfolio claims in standard OAuth 2.0 / OpenID Connect (OIDC)…
Read original ↗https://arxiv.org/abs/2607.13369arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
The Refusal Residue: When Probes Catch Alignment Faking and When They Don't arXiv:2607.13346v1 Announce Type: new Abstract: Alignment faking is dangerous because a model can appear compliant under monitoring while preserving behavior it would reveal when unmonitored. When no scratchpad is visible, behavior alone cannot distinguish strategic from genuine compliance. We ask whether hidden states reveal what outputs hide. We run a 13-model sweep for naturally-emerging faking, t…
Read original ↗https://arxiv.org/abs/2607.13346arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
ReBound: Reuse-Aware Privacy For Interactive Decision Support arXiv:2607.13441v1 Announce Type: new Abstract: Differentially private decision support frameworks answer complex aggregate threshold queries with formal bounds on false negative and false positive rates, but treat each query independently with no memory of past results. In practice, analysts work interactively, issuing sequences of related queries that refine bounds, adjust thresholds, or derive new functions fro…
Read original ↗https://arxiv.org/abs/2607.13441arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
WaterMoE: Expert-Routing-based Watermarking for High Fidelity and Efficiency arXiv:2607.13099v1 Announce Type: new Abstract: Large language models (LLMs) have achieved remarkable success but raise growing concerns about content provenance and misuse, motivating the need for reliable watermarking techniques. However, these techniques have rarely been adopted in practice mainly for two reasons: i) severely degraded model performance, and ii) additional inference overhead. To c…
Read original ↗https://arxiv.org/abs/2607.13099arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Adversarial Prompting Framework for AI Safety Assessment arXiv:2607.13453v1 Announce Type: new Abstract: Artificial Intelligence (AI), especially Generative AI (GenAI), adoption has increased in industries significantly in recent years. However, the use of these models may also expose systems to new forms of cyberattacks by different malicious actors -- adversarial prompt attack (APA) being one of the most prominent examples of such threats. This paper presents the implement…
Read original ↗https://arxiv.org/abs/2607.13453arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Privacy Preserving Recommender Systems Balancing Personalization with Privacy arXiv:2607.13328v1 Announce Type: new Abstract: Personalized recommendation systems are central to modern e-commerce and retail platforms, but they typically rely on centralized storage of detailed user interaction data, creating significant privacy and regulatory challenges. With increasing requirements from regulations such as GDPR, CCPA, and CPRA, organizations must develop recommendation system…
Read original ↗https://arxiv.org/abs/2607.13328arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design Approach arXiv:2607.13122v1 Announce Type: new Abstract: IoMT-based remote elderly care systems generate continuous streams of sensitive health data, yet existing security architectures have not simultaneously addressed three interdependent challenges: GDPR-compliant edge-layer pseudonymisation, elderly-specific zero-interaction usability as a binding architectural constrain…
Read original ↗https://arxiv.org/abs/2607.13122arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Securing LLMs in the Wild: Privacy and Security Challenges at the Edge arXiv:2607.13088v1 Announce Type: new Abstract: Large Language Models (LLMs) are rapidly moving from research settings into the wild, deployed on enterprise infrastructure, personal devices, and edge platforms. While cloud deployments offer scalable compute, concerns over data sovereignty, compliance, latency, and third-party dependence are driving organizations toward edge and on-premise LLMs. This shift…
Read original ↗https://arxiv.org/abs/2607.13088arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Evaluating Frontier AI Agents as Autonomous Clinical Security Auditors arXiv:2607.13411v1 Announce Type: new Abstract: Clinical AI models can expose patients to harm when adversarial vulnerabilities go undetected, yet formal security auditing requires statistical expertise, specialized tools, and significant time. We present an open evaluation task, built on METR Task Standard v0.3.0, that tests whether frontier AI agents can autonomously implement a structured clinical AI s…
Read original ↗https://arxiv.org/abs/2607.13411arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Baselines Before Architecture: Evaluating Coding Agents for Autonomous Penetration Testing arXiv:2607.13085v1 Announce Type: new Abstract: Recent autonomous penetration testing papers report high benchmark scores while adding multi-component security harnesses around frontier LLMs. Because these systems often change both architecture and backbone model, it is difficult to tell how much performance comes from the harness rather than from the underlying model. This paper prese…
Read original ↗https://arxiv.org/abs/2607.13085arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Phantom Guardrails: When Self-Improving Agent Harnesses Fix Failures That Never Happened arXiv:2607.13083v1 Announce Type: new Abstract: Self-improving AI agents are designed to learn from their mistakes. We show they can also hallucinate mistakes that never happened. We study this failure mode in automated harness optimization, where an LLM-based proposer edits an agent's scaffold, including prompts, parsers, filters, validators and guardrails, to eliminate observed failure…
Read original ↗https://arxiv.org/abs/2607.13083arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software arXiv:2607.13206v1 Announce Type: new Abstract: Security patches for open-source software constitute a foundational resource for vulnerability remediation research and practice. However, analyzing and applying multiple patches remains challenging, especially when trying to determine at what point in a patch sequence a vulnerability is fully remediated. This…
Read original ↗https://arxiv.org/abs/2607.13206arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Efficient and Privacy Aware Edge Cloud Collaborative Inference for Large Language Models arXiv:2607.13093v1 Announce Type: new Abstract: On-device LLM inference faces a trilemma of response latency, limited hardware resources and user privacy. Full cloud inference delivers strong computing power but exposes user prompts and dialogue data, while standalone on-device inference is unfeasible for most consumer and embedded edge devices. This paper presents a privacy-centric edge…
Read original ↗https://arxiv.org/abs/2607.13093arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
DREA: Decoupled Reasoning and Exploration Agents for Repository-Level Vulnerability Detection arXiv:2607.13439v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly applied to vulnerability detection due to their strong code comprehension capabilities, but most existing approaches rely on isolated functions or context extracted by fixed program-analysis rules. These methods cannot adaptively explore repository-level dependencies to gather sufficient co…
Read original ↗https://arxiv.org/abs/2607.13439arxiv_cs_cr · tlp:amber · 7/16/2026, 4:00:00 AM
Beyond AI-Generated Labels: Watermarking, Co-Creation, and Conflation of AI-Generation with Disinformation arXiv:2607.13082v1 Announce Type: new Abstract: Watermarking is often presented as a straightforward solution for distinguishing AI-generated from human-generated content, enabling platforms and regulators to trace synthetic content and detect AI-generated outputs at scale. This paper examines whether such mechanisms meaningfully address the epistemic and ethical challe…
Read original ↗https://arxiv.org/abs/2607.13082microsoft_mstic · tlp:amber · 7/16/2026, 1:36:21 AM
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog . In this article Attack chain overview How the attac…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-deliverylwn_kernel · tlp:amber · 7/16/2026, 1:24:55 AM
[$] LWN.net Weekly Edition for July 16, 2026 Inside this week's LWN.net Weekly Edition: Front : Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE. Briefs : Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ... Announcements : Newsletters, conferences, security updates, patches, and more.
Read original ↗https://lwn.net/Articles/1081915huggingface_blog · tlp:amber · 7/16/2026, 12:00:00 AM
Security incident disclosure — July 2026 Security incident disclosure — July 2026 Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> Security incident disclos…
Read original ↗https://huggingface.co/blog/security-incident-july-2026
the_record · tlp:amber · 7/15/2026, 11:00:00 PM
Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies Kentucky Fried Chicken restaurants have been left short on ingredients and major restaurant chains struggling to keep up with deliveries following a cyberattack on Nichirei Logistics Group. Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber…
Read original ↗https://therecord.media/cyberattack-japan-nichirei-logistics-impacts-kfcchainalysis · tlp:amber · 7/15/2026, 10:37:36 PM
OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday updated its Central Bank of Iran designation to… The post OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins appeared first on Chainalysis . OFAC Sanctions Iran Central Bank Crypto Wallets, Freezing $131M in Stablecoins - Chainalysis Chainalysis Products Crypto Investigations Invest…
Read original ↗https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins
the_record · tlp:amber · 7/15/2026, 8:00:00 PM
Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said. Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Tec…
Read original ↗https://therecord.media/gold-eagle-cybersecurity-vulnerabilities-clearinghouse
ars_security · tlp:amber · 7/15/2026, 7:59:48 PM
Windows 0-day drops the same day Microsoft releases record number of patches HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions. Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts. The exploit, which multiple researchers say works , is sending Microsoft scrambling, yet again,…
Read original ↗https://arstechnica.com/security/2026/07/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches
the_hacker_news · tlp:amber · 7/15/2026, 6:43:08 PM
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed TuxBot v3 E…
Read original ↗https://thehackernews.com/2026/07/tuxbot-v3-evolution-shows-signs-of-llm.html
the_record · tlp:amber · 7/15/2026, 5:50:00 PM
Trump’s DNI pick grilled about election security, voter fraud Senators pressed director of national intelligence nominee Jay Clayton about his stance on the 2020 election and previous statements about voter fraud. Other issues took a back seat. Trump’s DNI pick grilled about election security, voter fraud | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Fre…
Read original ↗https://therecord.media/jay-clayton-odni-nominee-senate-confirmation-hearing
the_record · tlp:amber · 7/15/2026, 5:45:00 PM
23andMe reaches $18 million settlement with states for massive breach A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach. 23andMe reaches $18 million settlement with states for massive breach | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter Headquarter…
Read original ↗https://therecord.media/genetic-testing-settlement-data-breachhuggingface_blog · tlp:amber · 7/15/2026, 5:29:41 PM
What building Shippy taught us about building agents What building Shippy taught us about building agents Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> W…
Read original ↗https://huggingface.co/blog/allenai/shippy-tech-bloghuggingface_blog · tlp:amber · 7/15/2026, 5:27:01 PM
Model Routing Is Simple. Until It Isn’t. Model Routing Is Simple. Until It Isn’t. Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> Model Routing Is Simple. …
Read original ↗https://huggingface.co/blog/ibm-research/model-routing-is-simple-until-it-isntlwn_kernel · tlp:amber · 7/15/2026, 4:19:26 PM
[$] Topics in filesystem testing It should come as no surprise that a gathering of filesystem developers would discuss filesystem testing; it has been a mainstay of the Linux Storage, Filesystem, Memory Management, and BPF Summit over the years and the 2026 summit was no exception. Ted Ts'o led the discussion this time; he had a few different topics to raise, including his perception of increasing regressions for ext4 in the stable kernels and what can be done to help reduce…
Read original ↗https://lwn.net/Articles/1082342microsoft_mstic · tlp:amber · 7/15/2026, 4:00:35 PM
Turning threat intelligence into decisive action with Defender Experts Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog . In this article Upstream: See the campaign before it reaches you Microsoft Defender Threat …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/15/turning-threat-intelligence-into-decisive-action-with-defender-expertslwn_kernel · tlp:amber · 7/15/2026, 3:52:13 PM
Local DoS attack vectors in seunshare 3.10 (SUSE Security Team Blog) The SUSE Security Team Blog has a post with an analysis of seunshare , which is used by SELinux to confine untrusted programs. During a review of version 3.10 of the program, the team identified two local Denial-of-Service (DoS) vectors. Since seunshare is supposed to run on SELinux-enabled systems, it is important to understand what kind of privilege escalation can be achieved when vulnerabilities are expl…
Read original ↗https://lwn.net/Articles/1083076