Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,097 source documents · 4,065 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
0
Publisher text withheld
22
Security updates for Tuesday
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Operation Lighthouse: Chainalysis’s CSAM-Disruption Sprint IDs Suspects in 125 Countries
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
OFAC Targets Ministry of Intelligence, Crypto-for-Oil Payments in Latest Iran Sanctions
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
UK government seeks powers to secretly block risky tech suppliers
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Large DDoS attack knocks Norwegian public services offline
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Quantization-Aware Healing: a compressed, 4-bit model that outperforms its full-precision original
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
First Malware Built Specifically for Car Head Units Fuels Botnet
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Frontier AI: Vulnerability Management's Systemic Revolution
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
State divergence enables unauthorized access
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
The safety penalty: Reclaiming operational sovereignty in the age of AI
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Silent Patches Don’t Stop Attackers—They Blind Defenders
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
CISA Warns of Exploited Oracle WebLogic Vulnerability
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
ThreatLens: Evidence-Guided Ranking of High-Priority CVEs
arXiv:2608.22306v1 Announce Type: new Abstract: Security teams must prioritize vulnerabilities before exploitation evidence is complete. Existing signals, such as CVSS, EPSS, advisories, and public exploits, are useful but fragmented and time-sensitive; retrospective rankings can therefore overstate performance by using evidence unavailable at decision time. We present ThreatLens, a simple yet effective and deployment-realistic framework for CVE prioritization. ThreatLens ran…
Beyond Over-Refusal: Defending Indirect Prompt Injection via Latent Instruction Manifolds
arXiv:2608.22248v1 Announce Type: new Abstract: Large Language Models (LLMs) have been integrated into complex ecosystems (e.g., Code Agents), while Indirect Prompt Injection (IPI) attacks have emerged as critical barriers to their safe deployment. Attackers exploit LLMs' indistinguishability between "instructions" and "data" to manipulate LLMs via maliciously injected instructions. Existing defenses, however, face an intractable safety-utility trade-off: most guardrails eith…
PURA: Provably Unbiased and Robust Multi-Bit Text Attribution
arXiv:2608.22218v1 Announce Type: new Abstract: Fine-grained attribution of AI-generated text is becoming increasingly important for accountability and auditing, yet existing multi-bit watermarking methods still struggle to simultaneously preserve the base generation distribution, support high-capacity payloads, and remain recoverable after editing. We present PURA, a provably unbiased and robust multi-bit watermarking method for text attribution. Instead of perturbing token…
AdaptPrint: Response-Adaptive Fingerprinting of Black-Box LLM Services
arXiv:2608.22213v1 Announce Type: new Abstract: Black-box LLM services have emerged as a practical deployment paradigm. Nevertheless, their opacity also hinders the systematic assessment of security risks and complicates copyright auditing for model owners. Black-box LLM fingerprinting, which identifies the underlying LLM identity through query-response interactions, offers a promising way to bridge this gap. Existing approaches typically collect responses from target LLM ser…
Lessons from the Hardware Hacking Competitions: Verification Techniques, Findings, and Insights
arXiv:2608.22202v1 Announce Type: new Abstract: Hardware hacking competitions have emerged as practical platforms for evaluating security weaknesses in complex System-on-Chip (SoC) designs while promoting security-aware verification and tool development. This paper presents a systematic study of SoC security verification through open-box hardware hacking competitions, focusing on practical vulnerability analysis strategies, observed findings, and lessons for security-aware ve…
MARL-Based Sequential RIS Auctions: A Physical-Layer Security Analysis
arXiv:2608.22169v1 Announce Type: new Abstract: Reconfigurable intelligent surfaces (RISs) hold great potential to enhance coverage, spectral efficiency, and communication security by intelligently configuring their reflecting elements. When owned by a neutral RIS operator, these elements can be offered as resources for which legitimate receivers and eavesdroppers compete. This paper investigates such competition and evaluates its impact on the physical-layer security perform…
A Lightweight and Post-Quantum Secure Framework for IEC 61869-9 Sampled Value Communication
arXiv:2608.22123v1 Announce Type: new Abstract: Securing IEC 61869-9 Sampled Values (SV) is challenging because process-bus communication must satisfy stringent real-time constraints while supporting standardized high-rate publication profiles. This paper presents an experimentally validated security framework that combines lightweight per-frame authentication for operational SV traffic with post-quantum-capable key establishment protocol. For message integrity, the proposed…
On Predicting Vulnerability Severity Using In-Context Learning: An Industrial Case Study
arXiv:2608.22089v1 Announce Type: new Abstract: Modern software systems require earlier and more scalable vulnerability severity assessment to reduce exposure to high-impact security flaws. Security analysts typically assign CVSS scores, but this manual triage does not scale with the growth of disclosed vulnerabilities and often depends on cloud LLM services that raise confidentiality concerns. This paper presents an industrial case study on predicting CVSS v3.1 scores direct…
Autonomous Cyber Defense: Real-Time Attack Detection and Mitigation in Software-Defined Networks Using Machine Learning
arXiv:2608.22075v1 Announce Type: new Abstract: Adversaries now move faster than manual response processes can absorb. The average eCrime breakout time, that is, the interval between initial access and the first lateral movement to another host, fell to 29 minutes in 2025, a 65\% increase in speed over the previous year; the fastest observed breakout took 27 seconds, and in one intrusion data exfiltration began within four minutes of initial access. This work presents a machi…
Key Recovery from Residue-Confined Errors in Pradhan CRT-RLWE
arXiv:2608.21989v1 Announce Type: new Abstract: We show that the CRT-FHE scheme of Pradhan et al.\ is insecure for laws within its assumed error distribution range. The secret key follows from the public key by a single ring inversion whenever the public multiplier is a unit. The plaintext is recovered from any ciphertext under such a law without the secret key, for every multiplier, giving chosen-plaintext advantage $1/2$. We further show that the transformation from ordinar…
AI Grinding for Fun and Cryptanalysis
arXiv:2608.21986v1 Announce Type: new Abstract: We present an autonomous cryptanalysis workflow in which agents generate, test, and refine hypotheses before human review. The autonomous stage returns reproducible candidates with exact witnesses, controls, code, and run records. A researcher then decides whether the evidence establishes a break, defect, or coverage gap. Two failure modes recur. First, a public algebraic map or input representation erases or exposes a relation…
How Reliable Are NVD CWE Labels? A Large-Scale Semantic Audit with Seclometry
arXiv:2608.21977v1 Announce Type: new Abstract: CWE labels in the National Vulnerability Database (NVD) are widely treated as ground truth for vulnerability search, scanner evaluation, benchmark construction, learning-based security tools, and vulnerability prioritization. Yet their reliability has not been systematically measured at scale, despite growing concerns about NVD's enrichment backlog and anecdotal reports of inaccurate, ambiguous, or missing labels. This paper pre…
A Loss-Robust Disturbance Certificate for Minimal-Receiver Quantum Key Distribution
arXiv:2608.21974v1 Announce Type: new Abstract: Quantum Key Distribution (QKD) enjoys information-theoretic security, yet the most damaging attacks against deployed systems exploit the receiver, where the key bit is encoded in which one of a pair of never-identical detectors clicks. The minimal receiver, one rotatable polarizer and one threshold detector, removes that attack surface, and single-detector BB84 demonstrations already run sampled error estimation; the structure o…
SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents
arXiv:2608.21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution. We present Skill…
Breaking the Assumptions: Auditing Input-Side Jailbreak Defenses Against Semantic Attacks
arXiv:2608.21895v1 Announce Type: new Abstract: Locally deployed Large Language Models (LLMs) via inference engines such as Ollama run without the moderation and abuse detection present in API-served models. Therefore, the safety of LLMs depends on the defense mechanisms used, and their effectiveness depends on the assumptions on which they were designed. This paper does an audit of defense mechanisms under jailbreak attacks on locally deployed models. Some defenses provide f…
ExplainGuard: A Zero Trust Framework for Post-Hoc Explanation Integrity Guarantees in Blackbox XAI Models
arXiv:2608.21803v1 Announce Type: new Abstract: As machine learning (ML) models are increasingly deployed in high-stakes environments, explainable AI (XAI) methods like SHAP and LIME have become essential for regulatory compliance and trust. However, the current auditing paradigm relies on an implicit "chain of trust" where third-party auditors are assumed to be trusted. Recent research demonstrates that this assumption is flawed and adversarial auditors can manipulate XAI ex…
Privacy Preserving Semantic Communications in Wireless Edge Networks with Vision Language Models
arXiv:2608.21773v1 Announce Type: new Abstract: Semantic communication has emerged as a promising paradigm for next-generation wireless systems by transmitting high-level semantic features rather than raw bits. However, collaborative devices and multimodal transmission increase privacy risks because sensitive information may leak through inter-device semantic fusion and cross-modal representations. To address this issue, we propose a privacy-preserving semantic communication…
Cross-Layer Roots of Trust: Integrating Biometrics, PUFs, and Hardware Obfuscation
arXiv:2608.21643v1 Announce Type: new Abstract: Modern cyber--physical, Internet-of-Things (IoT), wearable, and edge systems increasingly require trust in three distinct entities: the human requesting access, the physical device executing the computation, and the hardware function that is permitted to operate. These requirements are usually studied in separate communities. Biometrics establish human identity but remain vulnerable to presentation attacks, intra-user variabilit…
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.