REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 8 of 54
arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Auditable and Transparent Fully Authenticated Disk Encryption via USB Storage Interposition arXiv:2607.12716v1 Announce Type: new Abstract: Full Disk Encryption (FDE) has become increasingly important in the last decades due to the evident confidentiality concerns. In most systems, encryption is provided by an operating system driver, through which the user can transparently access the encrypted disk after supplying the required keys (or the credentials from which those keys…
Read original ↗https://arxiv.org/abs/2607.12716arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Representation and Reference Selection in Training-Free Synthetic Image Attribution arXiv:2607.12052v1 Announce Type: cross Abstract: Synthetic image attribution aims at identifying the generator responsible for a given AI-generated image. Training-free reference-based attribution methods are easily scalable, since newly emerging generators can be incorporated by adding source-specific references rather than retraining a task-specific classifier. Their performance depends on…
arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
How Agentic Is Agentic Commerce? A Population-Scale Measurement of x402 Adoption and Authenticity arXiv:2607.12575v1 Announce Type: new Abstract: AI agents are said to be forming an economy in which they pay, on their own, for the data, APIs, and compute they consume. x402, which settles a stablecoin payment on-chain for each purchase, is the most widely deployed protocol for this, and its hundreds of millions of settlements are read as proof that the economy has arrived. We…
Read original ↗https://arxiv.org/abs/2607.12575arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Explaining Intrusion Alert Decisions of Deep Learning-based Network Intrusion Detection Systems for Security Analysts arXiv:2607.12203v1 Announce Type: new Abstract: In this paper, we present EXP-SEC, a novel framework which can explain the intrusion detection decisions of DL-based NIDS (which lead to security alerts) in a way that is aligned with the domain knowledge of analysts working in Security Operations Center (SOC). We highlight the following features of our framewor…
Read original ↗https://arxiv.org/abs/2607.12203arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Watermark Forensics for Generative Models: An Information-Theoretic Perspective arXiv:2607.13003v1 Announce Type: new Abstract: A watermark in a generative model's output is usually asked only whether a text is machine-made. The same mark can do more: attribute it to the user who produced it, extract a hidden payload, or localize the part that survives editing. These form a forensic ladder, and we ask what each rung costs in the sample length $n$. One object organizes the an…
Read original ↗https://arxiv.org/abs/2607.13003arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
VanillaBench: The Hidden Accuracy Cost of Adversarial Robustness arXiv:2607.12545v1 Announce Type: new Abstract: Adversarial robustness research has produced hundreds of defended models over the past decade, yet the literature almost universally reports robustness results in isolation: standard (clean) accuracy and adversarial accuracy of the robust model are shown, but the gap to the corresponding vanilla model is rarely quantified. We introduce VanillaBench, a systematic b…
Read original ↗https://arxiv.org/abs/2607.12545arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
MindReader: Using LLMs to Encourage Memorable and Secure Password Replacement arXiv:2607.12148v1 Announce Type: new Abstract: We report on the design and evaluation of MindReader, a tool that helps a user replace her password when she is required to do so. Left to their own devices, users tend to replace their previous passwords with predictable variations of the original ones. MindReader leverages LLMs to suggest password variations that are chosen to be easy for the user t…
Read original ↗https://arxiv.org/abs/2607.12148arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
MTD-Playground: An Attacker-Aware Evaluation Framework for Network Moving Target Defense arXiv:2607.12199v1 Announce Type: new Abstract: Moving Target Defense (MTD) has emerged as a proactive network cyber defense paradigm that increases attacker uncertainty through dynamic network reconfiguration techniques such as Software-Defined Networking (SDN)-enabled path randomization. However, existing evaluations remain fragmented due to inconsistent attacker assumptions, attack sc…
Read original ↗https://arxiv.org/abs/2607.12199arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
AutoTrace: From Patches to Triggers via Agentic Interprocedural Exploration arXiv:2607.12058v1 Announce Type: cross Abstract: Given a vulnerability-fixing commit, trigger localization asks which specific statement turns the vulnerable program state into a concrete unsafe operation. This question is harder than binary vulnerability detection because the answer demands interprocedural, causal reasoning: in a substantial fraction of real-world CVEs the triggering statement lies…
Read original ↗https://arxiv.org/abs/2607.12058arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
PVDetector: Detecting Prompt Injection Attacks on Purpose-Specific LLM Agents through Policy-Violation Concept Analysis arXiv:2607.12624v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly deployed as purpose-specific agents to handle domain-specific tasks such as customer service and code generation. These agents are expected to comply with not only generic safety guardrails but also purpose-specific restrictions tailored to their designated roles. …
Read original ↗https://arxiv.org/abs/2607.12624arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
A Scalable Cloud-Orchestrated and Service-Oriented Multi-Domain QKD Network with PQC Integration arXiv:2607.12765v1 Announce Type: new Abstract: Quantum key distribution (QKD) offers unconditional security but existing QKD networks remain difficult to scale across heterogeneous infrastructures and administrative domains due to vendor-specific interfaces, trusted-node constraints, and limited interoperability. This work presents a flexible multi-domain and multi-site quantum-…
Read original ↗https://arxiv.org/abs/2607.12765arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
On the Security Implications of PQC in TLS: Handshake Exhaustion and IDS Degradation arXiv:2607.12504v1 Announce Type: new Abstract: Post-Quantum Cryptography (PQC) is increasingly being integrated into TLS 1.3 to enhance resilience against quantum-enabled attacks. However, the additional computational and communication overhead introduced by PQC primitives during the handshake phase may also amplify the impact of TLS handshake exhaustion attacks, leading to more severe Dist…
Read original ↗https://arxiv.org/abs/2607.12504arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Silent Alarm: A J-Space Protocol for Comparing Danger Recognition Across Models and Quantization Levels arXiv:2607.12792v1 Announce Type: new Abstract: Jailbreak-robustness research typically evaluates safety through generated responses using an LLM-as-judge approach. Such evaluations, however, are sensitive to the benchmark's grading procedure and capture only observed behavior on a given set of attacks, without directly revealing the hidden fragility of the underlying safe…
Read original ↗https://arxiv.org/abs/2607.12792huggingface_blog · tlp:amber · 7/15/2026, 12:00:00 AM
Introducing Real World VoiceEQ: Measuring the human quality of voice AI Introducing Real World VoiceEQ: Measuring the human quality of voice AI Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In …
Read original ↗https://huggingface.co/blog/real-world-voiceeq
ars_security · tlp:amber · 7/14/2026, 10:20:48 PM
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, tha…
Read original ↗https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence
talos · tlp:amber · 7/14/2026, 8:27:33 PM
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical." Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical." Microsoft notes that t…
Read original ↗https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2026
the_hacker_news · tlp:amber · 7/14/2026, 8:25:47 PM
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are Microsoft…
Read original ↗https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
the_record · tlp:amber · 7/14/2026, 7:26:00 PM
US unseals indictment against alleged operators of Russian bulletproof hosting service The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud. US unseals indictment against alleged operators of Russian bulletproof hosting service | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cy…
Read original ↗https://therecord.media/us-unseals-indictment-russians-bulletproof-hostingkrebs_on_security · tlp:amber · 7/14/2026, 7:22:42 PM
Microsoft Patches a Record 570 Security Flaws Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Microsoft Corp. today released software updates to plug a…
Read original ↗https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flawssecurityweek · tlp:amber · 7/14/2026, 6:50:20 PM
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek . Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts V…
Read original ↗https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-dayssecurityweek · tlp:amber · 7/14/2026, 6:18:45 PM
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek . Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Con…
Read original ↗https://www.securityweek.com/synopsys-finds-no-evidence-of-data-breach-following-bosch-hack-claims
the_hacker_news · tlp:amber · 7/14/2026, 6:17:57 PM
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could SAP Patch…
Read original ↗https://thehackernews.com/2026/07/sap-patches-cvss-99-netweaver-abap-flaw.html
the_record · tlp:amber · 7/14/2026, 5:28:00 PM
Finland issues wanted notice for hacker behind massive psychotherapy data breach The defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland. Finland issues wanted notice for hacker behind massive psychotherapy data breach | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter Daryna…
Read original ↗https://therecord.media/finland-issues-wanted-notice-for-hacker-vastaamo-breach
the_hacker_news · tlp:amber · 7/14/2026, 5:27:23 PM
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt path in May as part of its response to the Re…
Read original ↗https://thehackernews.com/2026/07/claude-for-chrome-flaw-lets-other.htmlsecurityweek · tlp:amber · 7/14/2026, 5:06:35 PM
Adobe Patches Critical ColdFusion Vulnerabilities The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared first on SecurityWeek . Adobe Patches Critical ColdFusion Vulnerabilities - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats Cyberwarfare Cybercrime Data Breaches Fra…
Read original ↗https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities
the_hacker_news · tlp:amber · 7/14/2026, 4:52:37 PM
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. "Once deployed, it can profile the host, LabubaRAT Masquerades …
Read original ↗https://thehackernews.com/2026/07/labubarat-masquerades-as-nvidia.htmllwn_kernel · tlp:amber · 7/14/2026, 4:50:47 PM
The Linux.org story Rob Kennedy has posted the story of the birth of Linux.org — one of the earliest Linux-related web sites — and its more recent rebirth. The site was founded in May 1994 by Michael McLagan, at a time when Linux itself was barely three years old. Linus Torvalds had only just released it to the world, there was no real way for a newcomer to find their footing, no search engines, no Wikipedia, none of the infrastructure people take for granted now for figurin…
Read original ↗https://lwn.net/Articles/1082901chainalysis · tlp:amber · 7/14/2026, 3:24:02 PM
“Stern,” Likely Most Prolific Ransomware Operator Ever, Sanctioned by EU as Action Targets Billions in Ransomware Damage Summary The United States, United Kingdom, and European Union announced sanctions targeting nation-state hackers, cybercriminals, and their enablers in one… The post “Stern,” Likely Most Prolific Ransomware Operator Ever, Sanctioned by EU as Action Targets Billions in Ransomware Damage appeared first on Chainalysis . “Stern” Ransomware Operator Sanc…
Read original ↗https://www.chainalysis.com/blog/cyber-sanctions-trickbot-administrator-july-2026chainalysis · tlp:amber · 7/14/2026, 2:00:14 PM
Chainalysis Supports Stable with Automatic Token Support Chainalysis is excited to announce support for Stable, a Layer 1 blockchain optimized for stablecoin payments and aligned with the… The post Chainalysis Supports Stable with Automatic Token Support appeared first on Chainalysis . Chainalysis Supports Stable with Automatic Token Support - Chainalysis Chainalysis Products Crypto Investigations Investigations Solutions Reactor Investigate and trace funds across blo…
Read original ↗https://www.chainalysis.com/blog/stable-automatic-token-supportsecurityweek · tlp:amber · 7/14/2026, 1:55:41 PM
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek . 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & T…
Read original ↗https://www.securityweek.com/7-severe-vulnerabilities-patched-in-vmware-avi-load-balancer
the_record · tlp:amber · 7/14/2026, 1:55:00 PM
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® C…
Read original ↗https://therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
the_hacker_news · tlp:amber · 7/14/2026, 1:48:07 PM
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth RabbitM…
Read original ↗https://thehackernews.com/2026/07/rabbitmq-flaws-could-leak-oauth-secrets.htmllwn_kernel · tlp:amber · 7/14/2026, 1:41:12 PM
Call for topics for the 2026 Maintainers Summit The Maintainers Summit is an annual, invitation-only gathering of kernel developers and maintainers to discuss development-process issues; see LWN's 2025 Maintainers Summit coverage for an example. The call for topics for the 2026 gathering (Prague, October 8) has gone out. One of the best ways to obtain an invitation to the Summit is with a good topic proposal. For best consideration, topics should be submitted before Jul…
Read original ↗https://lwn.net/Articles/1082838lwn_kernel · tlp:amber · 7/14/2026, 1:16:52 PM
[$] Sending packets directly from BPF Tetragon , the BPF-based security monitoring tool, uses BPF to monitor different aspects of a running kernel and enforce user-specified policies. It sends its data to a user-space process, which forwards the data to a central monitoring service elsewhere in the network, however. This presents a point of vulnerability: if an attacker can kill Tetragon's user-space agent, it won't be able to properly report on the situation. Song Liu, Mahé…
Read original ↗https://lwn.net/Articles/1081696lwn_kernel · tlp:amber · 7/14/2026, 1:16:38 PM
Security updates for Tuesday Security updates have been issued by AlmaLinux (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (imagemagick, p7zip, and redis), Fedora (breezy, calibre, and golang-github-openprinting-ipp-usb), Mageia (ffmpeg, gzip, haproxy, libheif, libtiff, libxml2, packages, perl-List-SomeUtils-XS, and pe…
Read original ↗https://lwn.net/Articles/1082832securityweek · tlp:amber · 7/14/2026, 1:00:00 PM
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek . Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cyb…
Read original ↗https://www.securityweek.com/unpatched-claude-for-chrome-flaw-lets-extensions-read-gmail-calendar
the_hacker_news · tlp:amber · 7/14/2026, 12:46:18 PM
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware," 11 …
Read original ↗https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.htmlcisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
Rockwell Automation 1715-AENTR EtherNet/IP Adapter View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS Vendor Equipment Vulnera…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
CISA Urges SharePoint Hardening After New Exploitations CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , and CVE-2026-56164 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, suc…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitationscisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
ABB T-MAC Plus View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774) CVSS Vendor Equipme…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03