Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,096 source documents · 4,064 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
2
Publisher text withheld
31
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Chinese and Russian spies stepping up cyberattacks, German companies report
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
[$] Using steal time to moderate CPU demands
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Claude, Codex, and Hermes installed unowned code inside corporate networks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Eight stable kernels for Thursday
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Security updates for Thursday
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Australia charges two men for TeamPCP supply-chain hacking spree
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Australia Arrests 2 Alleged TeamPCP Hackers
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
DOJ firearms agency says hackers breached system containing investigation targets
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Learn How to Build Security Operations Ready for AI-Powered Attacks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
What the Data Says About AI in Security Operations in 2026
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Cyberattack Causes Global Disruption at Boston Scientific
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
JavaScript obfuscation: From party trick to phishing kit
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
The Future of AI-Driven Security Depends on Complete Data
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Recent Citrix NetScaler Vulnerability Exploited in the Wild
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
A Hybrid Security Framework for Mini-Programs: Visual UI Compliance and Network Risk Assessment
arXiv:2608.25877v1 Announce Type: new Abstract: With the continuous development of the WeChat ecosystem, WeChat Mini Programs, due to their advantages of not requiring installation, using little memory, and being ready to use instantly, have seen a surge in user numbers and have now become an indispensable service carrier in mobile internet. However, as Mini Programs rapidly became popular, issues regarding the compliance of their interface interaction design and the safety o…
SkillShield: Prompt-Space Security Skills for LLM Coding Agents
arXiv:2608.25817v1 Announce Type: new Abstract: A coding agent edits files and executes shell commands with its developer's privileges, allowing malicious requests to translate directly into harmful actions or functional malware. Existing defenses have complementary limitations: weight-level alignment is unavailable to API-only deployers, whereas input filters and execution-boundary monitors require auxiliary classification or checking components along the agent's trajectory.…
Closing the Gap: Automated Discovery of Secure Dockerfile Reference Standards via Semantic Clustering in Enterprise Inner Source
arXiv:2608.25793v1 Announce Type: new Abstract: Containerization dominates enterprise software delivery, yet Dockerfiles that assemble container images frequently harbor security misconfigurations and structural technical debt. This problem is poorly understood in corporate inner-source environments, where proprietary context and isolated governance prevent direct application of open-source findings. We present an automated, six-stage pipeline that: (1) crawls an enterprise G…
EVOMAL: Self-Poisoning in Self-Evolving Coding Agents
arXiv:2608.25776v1 Announce Type: new Abstract: Self-evolving LLM coding agents write their own tools by imitating retrieved skills from shared skill libraries. We identify a vulnerability in this loop: during authoring, a retrieved malicious skill can become the template for a new skill that preserves the payload. We call this self-poisoning: the agent authors, stores, and runs the resulting malicious skill. We exploit it through EvoMal, an attack that amplifies self-poisoni…
Toward Interpretable Privacy Guarantees in Face-Swapping Anonymization
arXiv:2608.25750v1 Announce Type: new Abstract: Face-swapping has emerged as a promising approach to facial privacy protection, replacing a target individual's appearance with that of a donor while preserving non-facial context. The resulting images visually resemble the donor, and face recognition systems tend to suppress the target's match scores -- ostensibly satisfying privacy requirements. Empirical evaluation across a range of face-swapping models, however, reveals that…
MeMark: Membrane-Space Watermarking for Spiking Neural Networks
arXiv:2608.25738v1 Announce Type: new Abstract: Spiking Neural Networks (SNNs) are increasingly distributed as pretrained checkpoints and reused as backbones for new tasks. However, current SNN watermarks are mainly verified against the model output. Thus, a user who replaces the output head can keep most of the original network while removing the evidence used for verification. We present MeMark, a watermark designed for the checkpoint-reuse setting. Instead of storing the w…
Pointing the Way, Hiding the Destination: Practical Private Dense Retrieval at Scale
arXiv:2608.25735v1 Announce Type: new Abstract: Hosted retrieval-augmented generation (RAG) and semantic search allow users to query valuable provider-held corpora, raising two competing demands: to hide each query and chosen result, yet reveal only the documents that the user is authorized to receive. Existing cryptographic approaches either make this costly by processing the entire corpus for every query, or sacrifice quality for efficiency by scanning a few clusters. We re…
From Verdict to Diagnosis: Attributable Security Review of Pull Requests
arXiv:2608.25730v1 Announce Type: new Abstract: Automated code reviewers are increasingly used as gates on pull requests (PRs), yet evaluations measure whether they block a malicious change. A block may be triggered by an unrelated issue rather than the vulnerability that makes the PR unsafe; fixing the reported issue can leave the target defect exploitable. We call this discrepancy the Verdict-Diagnosis (VD) gap. We present MalPR-Bench, a mechanism-grounded benchmark of 89 m…
Reassembling Distributed Risk: Trajectory-Conditioned Action Generation for Multi-Turn Agent Safety
arXiv:2608.25711v1 Announce Type: new Abstract: Tool-using LLM agents extend security risks beyond generated text to actions that affect external systems. Under multi-turn decomposition attacks, a harmful objective can be distributed across individually plausible requests and tool calls, becoming apparent only from the accumulated trajectory. Existing defenses either rely on auxiliary online reasoning to recover long-horizon security evidence or assess actions after generatio…
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.