REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
850 reports · page 13 of 22
arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AutoDojo: Adaptive Attacks Expose Superficial Defenses and User-Underspecification Limits in LLM Agents arXiv:2606.15057v1 Announce Type: new Abstract: Indirect prompt injection (IPI) is a major security threat to LLM-powered agents. Thus, a growing body of work have proposed a variety of defensive approaches against IPI. These can be grouped into three broad categories: 1) prompt-based (using prompting as a way to prevent agents from following malicious instructions), 2) de…
Read original ↗https://arxiv.org/abs/2606.15057arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AnonShield: Scalable On-Premise Pseudonymization for CSIRT Vulnerability Data arXiv:2606.15650v1 Announce Type: new Abstract: We present AnonShield, a high-throughput, on-premise pseudonymization system that combines GPU-accelerated NER, streaming processing, caching, and schema-aware configuration. Evaluated on datasets up to 550 MB (70,951 records), AnonShield reduces processing time from over 92 hours to under 10 minutes (up to 738x speedup) while achieving up to 94.2% F1…
arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
BT-MTD: Bus Traversal-based Moving Target Defense for Smart Grid arXiv:2606.15047v1 Announce Type: new Abstract: Moving Target Defense (MTD) is a proactive security strategy designed to enhance cyber-resilience by dynamically altering system parameters, thereby preventing adversaries from acquiring the critical information needed to execute stealth attacks. In this paper, we consider the case in which the operator modifies the admittance of branches to enable MTD, and focus …
Read original ↗https://arxiv.org/abs/2606.15047arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Semantic Integrity Failures in Document-to-LLM Supply Chains arXiv:2606.15020v1 Announce Type: new Abstract: Document-to-LLM applications typically read uploaded PDFs by first translating them into text through a hidden extraction layer that users cannot observe or audit. We show that this layer enables split-view PDFs: one document can have two semantic views before model reasoning. By mining specification-permitted or implementation-tolerated representation gaps at the PDF…
Read original ↗https://arxiv.org/abs/2606.15020arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Security Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary Violations arXiv:2606.15008v1 Announce Type: new Abstract: Agentic large language model (LLM) systems can now execute actions, not only produce text. When model outputs trigger privileged operations such as shell commands, browser automation, or external tool calls, the security problem shifts from alignment alone to system configuration and structural design. We analyze OpenClaw, a self-…
Read original ↗https://arxiv.org/abs/2606.15008arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Odds Law: The Decomposition Algebra On How Intelligence Organizes Itself to Solve Difficult Problems Reliably arXiv:2606.15712v1 Announce Type: new Abstract: We ask a structural question: given unreliable elementary problem-solvers, what organizations of them solve hard problems reliably, and what are the limits? We develop a $decomposition~algebra$: elementary solvers are morphisms in a stochastic category, and four combinators (sequential composition, parallel ensembling, …
Read original ↗https://arxiv.org/abs/2606.15712arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? arXiv:2606.15762v1 Announce Type: new Abstract: We ran 300 repeated vulnerability-finding scans to measure how repeatable agentic large language model (LLM) security review is on the same JavaScript code, prompt, and benchmark harness. The headline result is that LLM security findings were unevenly repeatable: reference-matched findings were stable, but extra model reports varied heavily from run to run. Across 250 mo…
Read original ↗https://arxiv.org/abs/2606.15762arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Let Them Steal: Trapping Large Language Model Extraction Attacks with Knowledge Honeypot arXiv:2606.15810v1 Announce Type: new Abstract: Large language models deployed as commercial APIs are vulnerable to model extraction attacks, while existing defenses either act too late or degrade utility for legitimate users. We propose \textbf{Knowledge Trap}, a defense that redirects extraction attacks toward low-transferability knowledge through a \emph{Honeypot Knowledge Graph} (HKG…
Read original ↗https://arxiv.org/abs/2606.15810arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
FragFuse: Bypassing Access Control of Large Language Model Agents via Memory-Based Query Fragmentation and Fusion arXiv:2606.15609v1 Announce Type: new Abstract: Large language model (LLM) agents increasingly rely on long-term memory to support complex task execution, user personalization, and domain adaptation. Meanwhile, emerging access-control mechanisms for LLM agents are being explored to block policy-violating requests and prevent misuse. We reveal a novel attack surfa…
Read original ↗https://arxiv.org/abs/2606.15609arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
AttackonCTF: Defending Hardware Security Competition Benchmarks in the Age of LLMs arXiv:2606.15809v1 Announce Type: new Abstract: Hardware security competitions such as HackTheSilicon serve as benchmarking platforms for evaluating vulnerability detection methods and for training humans and AI. However, our study reveals that LLMs threaten their validity. Instead of genuine security reasoning, detectors exploit a diff-style syntactic comparison, achieving an 83% detection ra…
Read original ↗https://arxiv.org/abs/2606.15809arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
GAS-Leak-LLM: Genetic Algorithm-Based Suffix Optimization for Black-Box LLM Jailbreaking arXiv:2606.15788v1 Announce Type: new Abstract: Large Language Models (LLMs) constitute pivotal components within the AI-dominated information technology ecosystem. To mitigate risks associated with harmful or policy-violating outputs, commercial systems employ advanced alignment strategies and multi-layered content moderation mechanisms. Despite these safeguards, recent research has dem…
Read original ↗https://arxiv.org/abs/2606.15788arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
CmdNeedle: Measuring the Incompleteness of Command Denylists for AI Agents arXiv:2606.15549v1 Announce Type: new Abstract: The adoption of AI agents is increasing rapidly. Terminal AI agents, i.e., AI agents that run in terminal environments, are a widely used type of AI agents. Terminal AI agents rely heavily on shell command execution to interact with the host systems. They adopt a three-list command-gating mechanism to mitigate security risks introduced by command executi…
Read original ↗https://arxiv.org/abs/2606.15549arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Continual Backdoor Training in IoT/CPS arXiv:2606.14987v1 Announce Type: new Abstract: Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility. While continual adaptation is essential for long-lived IoT deployments where data patterns evolve, it also introduces new security vulnerabilities. In particular, backdoor attack…
Read original ↗https://arxiv.org/abs/2606.14987arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Multi-tier Differential Private Query Release arXiv:2606.15543v1 Announce Type: new Abstract: Answering statistical queries over sensitive data under differential privacy (DP) is a common task in many settings, including databases, mobile computing, and data markets. In these scenarios, multiple analysts may issue the same query, while receiving answers generated under different privacy budgets due to differences in trust levels or willingness to pay. Existing approaches for…
Read original ↗https://arxiv.org/abs/2606.15543arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
The Audit Gap in Blockchain Security: A Four-Year Empirical Study of Public Audit Findings and Real-World Exploit Incidents arXiv:2606.15465v1 Announce Type: new Abstract: This paper presents an empirical analysis of the Web3 security landscape over the four-year and three-month period from 1 January 2022 to 27 March 2026. The dataset combines 23,818 public audit findings produced by 22 independent security firms with 218 real-world exploit incidents documented by rekt.news,…
Read original ↗https://arxiv.org/abs/2606.15465arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Defending against Adaptive Prompt Injection Attacks via Reasoning-enabled Task Alignment arXiv:2606.15441v1 Announce Type: new Abstract: Indirect prompt injection attacks hijack LLM-based agents by embedding malicious instructions in third-party data that the agent retrieves during task execution. Existing defenses report near-zero attack success rate on static benchmarks, yet recent adaptive evaluations show that these results collapse once the attacker is allowed to optimi…
Read original ↗https://arxiv.org/abs/2606.15441arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Robust and Precise Application Fingerprinting on 5G Physical Uplink Channel arXiv:2606.15221v1 Announce Type: new Abstract: Air fingerprinting infers application activity by sniffing metadata from cellular control channels. 5G encrypts these channels, breaking the attack chain that prior attacks depend on. This paper reveals a physical-layer side channel that bypasses encryption: under the link adaptation mandated by the cellular communication standard, the uplink Modulation…
Read original ↗https://arxiv.org/abs/2606.15221arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Benign in Isolation, Harmful in Composition: Security Risks in Agent Skill Ecosystems arXiv:2606.15242v1 Announce Type: new Abstract: Skills are becoming the capability layer through which LLM agents turn plans into actions, but their use introduces security risks such as data leakage, unauthorized operations, and tool misuse. Existing vetting usually evaluates each skill in isolation, while real agent tasks often invoke multiple skills in a shared execution context. This cr…
Read original ↗https://arxiv.org/abs/2606.15242arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
Censorship-Resistant Sealed-Bid Auctions on Blockchains arXiv:2606.14939v1 Announce Type: new Abstract: Auctions are now central to blockchain markets, settling NFT sales, token launches, DeFi liquidations, and arbitrage opportunities. Each on-chain bid is a public transaction whose inclusion is decided by a single consensus proposer per block. The proposer can observe pending bids, exclude competitors, and submit bids of their own, breaking the fairness guarantees of classi…
Read original ↗https://arxiv.org/abs/2606.14939arxiv_cs_cr · tlp:amber · 6/16/2026, 4:00:00 AM
LLM: LSTM Look-Ahead Moving Target Defense Based on Historical Malicious Scan arXiv:2606.15229v1 Announce Type: new Abstract: Network scanning is a critical preliminary step for most adversaries to gain essential information before launching cyber attacks. Moving Target Defense (MTD) based on IP shuffling has emerged as a proactive defense strategy to counteract these reconnaissance efforts. Unlike static, reactive defense techniques, IP shuffling introduces randomness by dy…
Read original ↗https://arxiv.org/abs/2606.15229arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
AgentCyberRange: Benchmarking Frontier AI Systems in Realistic Cyber Ranges arXiv:2606.14295v1 Announce Type: new Abstract: Frontier AI systems are increasingly capable of cybersecurity tasks, including codebase inspection, vulnerability detection, and exploitation. However, evaluating their offensive capabilities remains constrained by limited access to open, reproducible, multi-host cyber ranges. Existing public benchmarks capture isolated skills such as CTF solving, vulne…
Read original ↗https://arxiv.org/abs/2606.14295arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
FreoStream:Enhancing Stream Guardrails via Future-Aware Reasoning and Safety-Aligned Optimization arXiv:2606.13737v1 Announce Type: new Abstract: Stream guardrails enable token-level safety detection before full responses are generated. However, they often make overly conservative judgements and block those sensitive but safe tokens, which is known as over-refusal. Due to lack of full context, they also fail to detect implicitly harmful content from jailbreaking. To address …
Read original ↗https://arxiv.org/abs/2606.13737arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
SEVRA-BENCH: Social Engineering of Vulnerabilities in Review Agents arXiv:2606.13757v1 Announce Type: new Abstract: Large language model (LLM) reviewers are increasingly used in pull-request (PR) workflows, where their approvals help decide which code is merged into a repository. This raises a question that benchmarks for static vulnerability detection or code generation do not address: can an automated reviewer reject a malicious contribution when the attacker controls both…
Read original ↗https://arxiv.org/abs/2606.13757arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Smart Blockchain-Based Access Control for the Internet of Things arXiv:2606.13798v1 Announce Type: new Abstract: Securing access control in large-scale Internet of Things (IoT) deployments requires mechanisms that adapt to risk while preserving low latency for benign traffic. Permissioned blockchains such as Hyperledger Fabric offer auditability through smart contracts, but static endorsement policies impose the same validation depth on all requests, regardless of security p…
Read original ↗https://arxiv.org/abs/2606.13798arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Information Flow Paths from RTL Traces arXiv:2606.13860v1 Announce Type: new Abstract: Security validation is an important yet challenging part of the hardware design process, yet, by convention, validation engineers are tasked with defining the threat model, specifying the relevant security properties, detecting any violations of those properties, and assessing the consequences to system security, each of which is manually intensive and may introduce errors. The combined te…
Read original ↗https://arxiv.org/abs/2606.13860arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
RTL-Arrow: Hardware-to-Cloud Bridge arXiv:2606.13865v1 Announce Type: new Abstract: Hardware Security at Willamette is a Willamette University affiliated research group studying the hardware-software interface of security critical services. Within our program, we noticed many researchers spent considerable development time learning to understand and manually parse traces-of-execution of hardware designs which are used to identifying whether vulnerabilities or weaknesses aris…
Read original ↗https://arxiv.org/abs/2606.13865arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Crypto x AI, AI x Crypto: A Survey arXiv:2606.13892v1 Announce Type: new Abstract: The intersection of crypto x AI is spawning papers, products, online posts, and companies. All the surrounding buzz, though, obscures what exactly has been done, what the opportunities and challenges are, and what open questions deserve attention. This survey paper asks what AI can do for blockchain-based technologies (broadly construed as "crypto") (crypto x AI), and vice versa (AI x crypto).…
Read original ↗https://arxiv.org/abs/2606.13892arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Side-Channel Attacks Bypass Protection in 3D Printers arXiv:2606.13952v1 Announce Type: new Abstract: Active Motor Noise Cancellation (AMNC) ships in commercial fused deposition modeling (FDM) 3D printers as a hardware countermeasure against acoustic side-channel attacks that target intellectual property (IP). We present the first empirical evaluation of a deployed AMNC countermeasure, using a public dataset of synchronized acoustic and vibration recordings from two AMNC-equ…
Read original ↗https://arxiv.org/abs/2606.13952arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations arXiv:2606.13966v1 Announce Type: new Abstract: Modern software supply chains have evolved into vast, heterogeneous networks where transparency - the granular understanding of all software components - is now a critical security requirement. While Software Bills of Materials (SBOMs) have emerged as the primary mechanism for this transparency, current industry practices rely on a metadata-centric pa…
Read original ↗https://arxiv.org/abs/2606.13966arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Choric Masking in Ambient Release Systems: A Finite Certificate Calculus for Trace Indistinguishability under Bounded Audiences arXiv:2606.13967v1 Announce Type: new Abstract: This paper develops a finite certificate calculus for ambient release systems, staged probabilistic environments in which a protected coordinate is not observed directly but can remain statistically readable through visible roles, timing, repeated movement, bounded attention, linked rooms, and post-rel…
Read original ↗https://arxiv.org/abs/2606.13967arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Hidden in Plain Sight: Benchmarking Agent Safety Against Decomposition Attacks with DECOMPBENCH arXiv:2606.13994v1 Announce Type: new Abstract: LLM-based Agents are becoming increasingly capable and widely deployed, creating growing incentives for adversarial misuse in the real-world. A key emerging threat is Decomposition Attacks \cite{glukhov2024breach, jones2024adversaries} in which a harmful task is broken into simpler, benign subtasks that evade safety mechanisms when e…
Read original ↗https://arxiv.org/abs/2606.13994arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Pseudonym Scheme Based on Hybrid Certificates for Security Credential Management System in Vehicular Communications arXiv:2606.14008v1 Announce Type: new Abstract: In recent years, the Institute of Electrical and Electronics Engineers (IEEE) and the European Telecommunications Standards Institute (ETSI) have developed a series of security communication standards for vehicular communications. These standards include mechanisms such as the Security Credential Management System…
Read original ↗https://arxiv.org/abs/2606.14008arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Same-Origin Policy for Agentic Browsers arXiv:2606.14027v1 Announce Type: new Abstract: Agentic browsers integrate autonomous AI agents into web browsers, enabling users to accomplish web tasks through natural-language instructions. The same-origin policy (SOP) is a fundamental browser security mechanism that prevents unauthorized automated cross-origin data flows induced by scripts. However, whether SOP remains effective in agentic browsers is an open question that has not …
Read original ↗https://arxiv.org/abs/2606.14027arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Defending the Core: A Centrality-Based Protection Strategy for Supply Chain Security in npm Dependency Network arXiv:2606.14036v1 Announce Type: new Abstract: The modern software supply chain, taking Node Package Manager (npm) dependency network for example, relies heavily on shared open-source dependencies. While this promotes rapid development, it introduces systemic vulnerabilities as well. Concerning this potential risk, we analyze the npm dependency network by modeling …
Read original ↗https://arxiv.org/abs/2606.14036arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Hierarchical Identity-Based Signature with Designated Aggregator from Lattices arXiv:2606.14090v1 Announce Type: new Abstract: In hierarchical organizations, authenticating data from multiple users can be complex and resource-intensive. Hierarchical Identity-Based Signature with Designated Aggregator (HIBS-DA) provides an efficient solution by allowing users at different levels to generate signatures that can be combined into a single, compact signature. We first introduce t…
Read original ↗https://arxiv.org/abs/2606.14090arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
SkillMutator: Benchmarking and Defending Language-and-Code Cross-modal Attacks on LLM Agent Skills arXiv:2606.14154v1 Announce Type: new Abstract: Large language model (LLM) agents increasingly extend their capabilities at runtime by loading Agent Skills, which pair natural-language specifications (SKILL.md) with executable scripts and resources. Because a skill's behavior relies on both natural-language instructions and executable code, assessing its safety requires cross-m…
Read original ↗https://arxiv.org/abs/2606.14154arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Security Evaluation of Mobile Banking Applications in Sudan arXiv:2606.14165v1 Announce Type: new Abstract: The rapid digitalization of the Sudanese financial sector has precipitated a surge in Mobile Banking Applications (MBAs); however, this growth has frequently outpaced rigorous security auditing. This study provides a comprehensive technical audit of the four most widely used Sudanese MBAs( Bankak, Fawry, Okash, and Sahil )collectively serving a user base of over 1.6 mi…
Read original ↗https://arxiv.org/abs/2606.14165arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
From Prompts to Responses: Dual-Sided Data Leakage and Defense in Split Large Language Models arXiv:2606.14210v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly deployed in privacy-sensitive domains, where users must balance the risk of data exposure through external APIs against the high computational cost of local deployment. Split learning has therefore emerged as a promising paradigm for LLM fine-tuning and inference under limited local resourc…
Read original ↗https://arxiv.org/abs/2606.14210arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
Security in a Workflow: Exploring Role-Based Agentic Architectures for Vulnerability Handling arXiv:2606.14261v1 Announce Type: new Abstract: Secure software engineering in practice is a multi-stage workflow involving vulnerability analysis, remediation, and fix verification. However, current LLM-based software security approaches often focus on isolated tasks such as detection or patch generation, with limited attention to agentic architectures reflecting industrial workflo…
Read original ↗https://arxiv.org/abs/2606.14261arxiv_cs_cr · tlp:amber · 6/15/2026, 4:00:00 AM
REPOSE: Quantifying the Price of Security in Weakly-Hard Real-Time Cyber-Physical Systems arXiv:2606.14395v1 Announce Type: new Abstract: In contemporary IoT edge devices with real-time requirements, security is primarily enforced through design-time parameters associated with security tasks, leading to mechanisms that operate in an \emph{opportunistic} manner. As a result, security checks are often performed as secondary operations. This approach can result in systems where…
Read original ↗https://arxiv.org/abs/2606.14395