REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 1 of 54
securityweek · tlp:amber · 7/21/2026, 11:30:00 AM
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek . CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurit…
Read original ↗https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-agsecurityweek · tlp:amber · 7/21/2026, 11:12:33 AM
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek . Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats C…
securityweek · tlp:amber · 7/21/2026, 10:19:21 AM
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek . Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cyber…
Read original ↗https://www.securityweek.com/meta-pays-78000-bounty-for-vulnerability-exposing-customer-support-datasecurityweek · tlp:amber · 7/21/2026, 9:36:51 AM
Clover Health Investments Discloses Data Breach Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek . Clover Health Investments Discloses Data Breach - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference…
Read original ↗https://www.securityweek.com/clover-health-investments-discloses-data-breach
the_hacker_news · tlp:amber · 7/21/2026, 8:59:30 AM
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well WordPress w…
Read original ↗https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.htmlsecurityweek · tlp:amber · 7/21/2026, 8:41:53 AM
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek . Exploitation of ServiceNow Vulnerability Seen Days After Disclosure - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecurity News…
Read original ↗https://www.securityweek.com/exploitation-of-servicenow-vulnerability-seen-days-after-disclosuresecurityweek · tlp:amber · 7/21/2026, 8:20:08 AM
Zimbra Update Patches Critical Vulnerabilities The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek . Zimbra Update Patches Critical Vulnerabilities - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware …
Read original ↗https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities
the_hacker_news · tlp:amber · 7/21/2026, 7:34:32 AM
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem. The entry New ENCFORGE Ran…
Read original ↗https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
the_hacker_news · tlp:amber · 7/21/2026, 6:29:26 AM
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were
Read original ↗https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.htmlarxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Auditable Session Admission for Cross-Silo Federated Learning arXiv:2607.16559v1 Announce Type: new Abstract: Cross-silo federated learning keeps raw data local, but deployments frequently stall on a practical bottleneck when deciding who may invoke which session-scoped operations across organizational boundaries, under constraints that remain auditable after execution. In practice, admission is implemented via centralized policy services, platform configuration, or ad hoc c…
Read original ↗https://arxiv.org/abs/2607.16559arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
How Jailbreak Attacks Inform Safety Alignment: A Defender-Centric, Shapley-Based Evaluation of Jailbreak Contributions arXiv:2607.17152v1 Announce Type: new Abstract: Jailbreak attacks on large language models are usually evaluated by attacker-centric metrics such as attack success rate (ASR), yet an attack that breaks a model is not necessarily useful for improving its safety. We propose a defender-centric view of jailbreak evaluation, where attacks are evaluated by the dow…
Read original ↗https://arxiv.org/abs/2607.17152arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Boundary-Seeking GAN-Augmented TabTransformer for Adversarially Robust Intrusion Detection arXiv:2607.16348v1 Announce Type: new Abstract: Machine learning-based intrusion detection systems (IDSs) often suffer from class imbalance and vulnerability to adversarial attacks, leading to degraded detection performance and reduced robustness. This study proposes a TabTransformer framework augmented by the Boundary-Seeking Generative Adversarial Network (BGAN) for flow-based intrus…
Read original ↗https://arxiv.org/abs/2607.16348arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Reliable Remediation Impact Prediction for Black-Box Security Ratings arXiv:2607.16357v1 Announce Type: new Abstract: Security rating platforms summarize externally observable cyber exposure and are expected to help organizations prioritize remediation. A platform may want to tell an organization how a candidate remediation action would affect its score, but repeatedly exposing exact score responses can reveal information about the hidden scoring engine. We propose a surroga…
Read original ↗https://arxiv.org/abs/2607.16357arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SATLOCK: Handover-Coupled Scheduling for Weather-Resilient Quantum Key Distribution over LEO Constellations arXiv:2607.17076v1 Announce Type: new Abstract: Routing quantum keys over low-earth-orbit (LEO) satellite constellations is harder than classical routing: satellite handovers couple consecutive scheduling decisions, stochastic cloud cover can silently zero a ground link, and finite-key effects eliminate short, low-elevation passes entirely. We present SATLOCK, a handov…
Read original ↗https://arxiv.org/abs/2607.17076arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
VIGIL: Verifying Identity via Gated Intermittent Likelihoods for Continuous Biometric Authentication arXiv:2607.16651v1 Announce Type: new Abstract: Continuous multi-modal authentication has emerged as a necessity for securing modern environments against persistent threats. Existing temporal fusion techniques fail to identify a persistent attacker from a genuine user with poor signal strength. In this study, we propose VIGIL (Verifying Identity via Gated Intermittent Likelih…
Read original ↗https://arxiv.org/abs/2607.16651arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Synchronization-Free Algebraic Fingerprints for Large Language Models: From Autoregressive to Diffusion Models arXiv:2607.16648v1 Announce Type: new Abstract: Large Language Models (LLMs) have created an urgent need for reliable watermarking methods that enable attribution of generated text while remaining robust to editing and paraphrasing. We propose a novel synchronization-free watermarking scheme in which every watermark consists of a single binary congruence generated f…
Read original ↗https://arxiv.org/abs/2607.16648arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Federated Lightweight Intrusion Detection in Drone Swarms with Knowledge Distillation arXiv:2607.17025v1 Announce Type: new Abstract: Drone swarms are increasingly deployed in critical applications such as surveillance, disaster response, and infrastructure monitoring. However, their reliance on open communication channels and their limited computational resources make them vulnerable to a wide range of cyber-threats. There is a growing interest in intrusion detection system…
Read original ↗https://arxiv.org/abs/2607.17025arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Towards Secure and Trustworthy DAOs for Cross-Chain Governance arXiv:2607.16548v1 Announce Type: new Abstract: Cross-chain DAOs face unique security challenges that go beyond traditional single-chain vulnerabilities. This paper identifies and categorizes four critical attack vectors in cross-chain DAO governance: bribery attacks, token control exploits, human-computer interaction deceptions, and protocol vulnerabilities. We propose a comprehensive security framework with a m…
Read original ↗https://arxiv.org/abs/2607.16548arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Signal-based Model Access Risk Analysis for AI System Operations Security arXiv:2607.16414v1 Announce Type: new Abstract: Artificial intelligence (AI) systems are now ubiquitous across domains such as security, finance, healthcare, consumer technology, and large-scale cloud services, where they process massive volumes of data and make consequential decisions daily. This widespread adoption has created a broad attack surface through which adversaries can manipulate, evade, ex…
Read original ↗https://arxiv.org/abs/2607.16414arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Fuzz'EMup: Leveraging EM Side-Channel Emanation to Guide Black-Box Embedded Firmware Fuzzing arXiv:2607.16487v1 Announce Type: new Abstract: As IoT and embedded devices proliferate across various domains, securing their firmware has become critical. Fuzzing offers a systematic approach to uncovering vulnerabilities in firmware, and coverage feedback can improve its effectiveness by guiding exploration. However, many devices make coverage information impossible to obtain by p…
Read original ↗https://arxiv.org/abs/2607.16487arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Identity-Bound Academic Credentials on Blockchain: On-Chain Issuer Accreditation with ERC-3643 and OnchainID arXiv:2607.16383v1 Announce Type: new Abstract: Verifying academic credentials remains difficult: records are held by individual institutions in proprietary systems, verification is slow and manual, and counterfeit qualifications are widespread. Blockchain-based registries have been proposed as a remedy, but existing systems tend to anchor certificate hashes without b…
Read original ↗https://arxiv.org/abs/2607.16383arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Enhanced Multi-Class DDoS Attack Identification using a Meta-Learning Ensemble arXiv:2607.16521v1 Announce Type: new Abstract: Distributed Denial of Service (DDoS) attacks continue to pose significant threats to network availability and security. While many detection systems focus on binary classification (attack vs. benign), effective mitigation often requires identifying the specific type of DDoS attack. This paper introduces a robust intrusion detection framework centered…
Read original ↗https://arxiv.org/abs/2607.16521arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SlotGuard: Stop Oversharing Private Local Context in LLM Agent Transcri arXiv:2607.17147v1 Announce Type: new Abstract: LLM agents can leak privacy (e.g., paths, emails) and credentials (e.g., API keys) as agent observations (e.g., tool outputs, shell logs, and file reads) are appended to provider-bound transcripts. Existing placeholder redaction is brittle: it can miss embedded or cross-turn references, over-redact benign lookalikes, and destroy the structure useful for rea…
Read original ↗https://arxiv.org/abs/2607.17147arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Fast and Private Max-Sum Diversification arXiv:2607.17196v1 Announce Type: new Abstract: Result diversification is crucial for generating informative, non-redundant data summaries and query outputs. Although its various formulations have been extensively studied across an array of data-driven disciplines, existing methods fail to address the privacy concerns that arise when the underlying data is sensitive. In this work, we initiate the study of result diversification under …
Read original ↗https://arxiv.org/abs/2607.17196arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
TaintRadar: Semantic-Aware Taint-Style Vulnerability Detection via Augmented Code Property Graphs arXiv:2607.16456v1 Announce Type: new Abstract: Despite significant advances, static vulnerability analysis suffers from three critical limitations: coarse sanitization modeling, which treats validation as a binary barrier; database blindness, which breaks taint tracking across persistence layers; and shallow object-oriented analysis, which misses field-level and interprocedural…
Read original ↗https://arxiv.org/abs/2607.16456arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
DSA Nonce Vulnerabilities: An Interactive Analysis arXiv:2607.17107v1 Announce Type: new Abstract: Digital signatures are fundamental to identity authentication and data integrity in cybersecurity, and the NIST-standardized Digital Signature Algorithm (DSA) frequently appears in the cryptography track of CTF competitions. However, DSA relies on number theory, modular arithmetic, and large-integer computation, making both the algorithm and its associated attacks difficult for…
Read original ↗https://arxiv.org/abs/2607.17107arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SpexPay: A Privacy-Preserving Pay-As-You-Go System for Dynamic Spectrum Sharing arXiv:2607.17218v1 Announce Type: new Abstract: Dynamic Spectrum Sharing (DSS) is a cornerstone of next-generation wireless systems, yet existing solutions such as Spectrum Access Systems (SAS) rely on centralized administrators that expose sensitive operational metadata and lack cryptographic transaction accountability. Though SAS administrators, such as Google, have introduced pay-as-you-go pri…
Read original ↗https://arxiv.org/abs/2607.17218arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Rollback-Free Cross-Chain Atomicity Through Forward-Only Correction arXiv:2607.16959v1 Announce Type: new Abstract: Blockchain platforms have grown into an ecosystem of independent networks, and a growing class of applications now requires smart contracts on separate chains to act as one. Such operations must be atomic, yet immutability makes this fundamentally harder: a confirmed transaction cannot be reversed, so the rollback on which classical atomic commitment protocols …
Read original ↗https://arxiv.org/abs/2607.16959arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
A Multi-Model Hybrid Defense Approach Against White-box Adversarial Attacks in Computer Network Traffic arXiv:2607.17105v1 Announce Type: new Abstract: It is crucial to safeguard computer networks from evolving network security threats and unknown cyberattacks. An essential tool for protecting computer networks against unknown cyber threats is Network Intrusion Detection System (NIDS). However, NIDS faces a major security concern due to its susceptibility to adversarial atta…
Read original ↗https://arxiv.org/abs/2607.17105arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
A Control-Driven Framework for Secure SaaS Onboarding in Regulated Enterprises arXiv:2607.16543v1 Announce Type: new Abstract: As enterprises increasingly adopt Software-as-a-Service (SaaS) platforms for mission-critical functions, onboarding these services has emerged as a complex challenge extending well beyond procurement and basic security review. In regulated environments, SaaS onboarding must address multiple interdependent control domains, including Third-Party Risk M…
Read original ↗https://arxiv.org/abs/2607.16543arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Federated Learning and LLM-Driven Threat Intelligence for Zero Trust IoT Architecture arXiv:2607.17035v1 Announce Type: new Abstract: While the Internet of Things (IoT) has become essential, they introduced serious security and privacy challenges, especially for mission-critical environments. Legacy devices are vulnerable to viruses, data breaches, and unauthorized access, and updating these devices would be infeasibly costly. As a solution, this paper presents a Federated L…
Read original ↗https://arxiv.org/abs/2607.17035arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
A Systematic Evaluation of Traditional Privacy Policy Analysis Tools Against LLMs arXiv:2607.17075v1 Announce Type: new Abstract: The advent of LLMs has significantly changed the research on privacy policy and data compliance analysis by enabling tasks that previously required specialized, domain-specific tools. However, it remains unclear to what extent LLMs can truly replicate the diverse functionalities, and the wide range of methodologies and analysis offered by prior wo…
Read original ↗https://arxiv.org/abs/2607.17075arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
SABLE: Minimalist Instruction-Level Authenticated Encryption for Constrained Confidential Computing arXiv:2607.16771v1 Announce Type: new Abstract: Conventional processor designs expose code and data as plaintext throughout execution, rendering them inherently vulnerable to attacks that recover intellectual property or modify security/safety checks. Instruction-level encryption (ILE) enables CPU-level decryption, execution, and optionally authentication of individual encrypt…
Read original ↗https://arxiv.org/abs/2607.16771arxiv_cs_cr · tlp:amber · 7/21/2026, 4:00:00 AM
Adaptive Incident Prioritization for Security Operations at Scale arXiv:2607.16963v1 Announce Type: new Abstract: Large security operations centers (SOCs) often face hundreds of active incidents per day, creating substantial cognitive and operational demands for analysts. Analysts must quickly decide which incidents deserve attention within long, constantly changing queues, yet incidents are commonly ordered by arrival time, coarse severity, or product-specific heuristics th…
Read original ↗https://arxiv.org/abs/2607.16963huggingface_blog · tlp:amber · 7/21/2026, 12:00:00 AM
Grabette: an open system to record robot-manipulation data Grabette: an open system to record robot-manipulation data Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a…
Read original ↗https://huggingface.co/blog/grabette
the_record · tlp:amber · 7/20/2026, 7:55:00 PM
Flock Safety kills acoustic system designed to detect 'human distress' "Community consultation" is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system. Flock Safety kills acoustic system designed to detect 'human distress' | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast…
Read original ↗https://therecord.media/flock-safety-kills-audio-detection-system-human-distresslwn_kernel · tlp:amber · 7/20/2026, 6:26:55 PM
[$] Fedora grapples with change The Fedora Project is known for, among other things, having a well-defined set of processes for just about everything. It has extensive packaging guidelines that deal with the complexities of creating RPMs to install software, as well as processes for managing the legal questions that arise around shipping software. Fedora also has a well-defined change process for dealing with self-contained technical changes as well as major changes to the d…
Read original ↗https://lwn.net/Articles/1081557
the_hacker_news · tlp:amber · 7/20/2026, 6:23:03 PM
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP FakeG…
Read original ↗https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
the_record · tlp:amber · 7/20/2026, 6:20:00 PM
India says allegedly leaked nuclear plant files pose no safety risk Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said. India says allegedly leaked nuclear plant files pose no safety risk | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to …
Read original ↗https://therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents
the_hacker_news · tlp:amber · 7/20/2026, 5:29:50 PM
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a Exp…
Read original ↗https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html