Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,099 source documents · 4,067 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
0
Publisher text withheld
15
Security updates for Friday
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Critical Isolated-vm Vulnerability Leads to RCE on Host
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Wazuh and AI For Enhanced SOC Workflows
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Rust Supply Chain Attack Linked to North Korean Hackers
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Microsoft Rolls Out 22 Fresh Security Patches
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Inadvertent Context Leakage in Language Models
arXiv:2608.19857v1 Announce Type: cross Abstract: For AI agents to be useful beyond simple chat, they must hold sensitive user context such as calendars, credentials, health records, and financial data. We study whether the mere presence of such secrets in a model's context window introduces hidden correlations into the model's benign outputs, allowing reconstruction even when the model correctly refuses direct extraction. We further study whether an adversary can actively en…
HARP: Hierarchical Adaptive Ranking with Preference-Adaptive Fusion for Query-Based CVE Prioritization
arXiv:2608.19430v1 Announce Type: cross Abstract: Vulnerability prioritization is inherently preference dependent, since the same CVE can receive different remediation priority under different operational preference scenarios. Existing scoring systems and ranking methods typically assume a fixed criterion. In practice, organizations already operate under a preference scenario, but this preference is often implicit and difficult to express as a written prompt instruction, whil…
Linguistic Holonomy and Statistical Watermarks: Inner Geometry of Meaning-Preserving Transformations
arXiv:2608.19369v1 Announce Type: cross Abstract: Statistical watermarks for language models live in the freedom of the signifier: they choose among tokens that are nearly equivalent in meaning, and they are therefore eroded by exactly those transformations which move the form of a text while leaving its content in place. The literature measures such transformations by their endpoint, through the semantic similarity between the original and the rewritten text. We show that th…
Reproducibility is Not Enough: Artifact Verifiability in Decentralized-Build Package Ecosystems
arXiv:2608.18180v1 Announce Type: cross Abstract: Reproducible and verifiable builds increase trust in distributed software artifacts by enabling independent parties to detect artifacts produced by compromised build or release pipelines. However, artifact verification requires more than deterministic builds: a verifier must also recover the source state, build environment, dependencies, and build instructions that produced the artifact. Decentralized-build ecosystems make thi…
Chameleon: Robust Defense Against Tor Website Fingerprinting via Many-to-Many Traffic Morphing
arXiv:2608.20160v1 Announce Type: new Abstract: Website fingerprinting (WF) attacks can infer users' browsing activities from encrypted Tor traffic by exploiting side-channel features. Although many WF defenses have been proposed, we find that most existing defenses create learnable web trace mapping features. We further show that robustness against adversarial training does not necessarily imply robustness against defense-aware autoencoder (DAAE)-based attacks. To address th…
Trustworthy mobile edge caching: a blockchain approach to mitigate malicious nodes and incentivize cache sharing
arXiv:2608.20145v1 Announce Type: new Abstract: As mobile network traffic continues to grow, content caching on edge servers is critical for reducing latency. However, challenges such as malicious edge servers that may delete or manipulate cached content, along with the limited capacity of these servers, need to be addressed. To overcome the capacity limitations, helper mobile nodes can contribute their cache resources. However, due to their selfish behavior, an incentive mec…
Privacy-Preserving Detection of Rare Disease-Associated Cell Subsets via Secure Multi-Party Computation
arXiv:2608.20118v1 Announce Type: new Abstract: The detection of rare disease-associated cell subsets from high-dimensional single-cell measurements is critical for understanding diseases such as leukaemia and viral infections. CellCnn, a convolutional neural network (CNN) designed for this task, has demonstrated the ability to identify phenotype-associated cell populations at frequencies as low as 0.01\%. Training such models reliably requires patient cohorts that are larger…
A Meta-Study on Replication Papers in Usable Security & Privacy
arXiv:2608.20108v1 Announce Type: new Abstract: The field of usable security and privacy research is a young and expanding field, which is still developing standards for its research, e.g. regarding replications. We used a mixed-method approach, in order to get a better understanding of the current state of replications in the field of usable security and privacy: (1) we examine the Call for Papers of 13 venues spanning security, privacy, and human-computer interaction; (2) w…
TrustRAG: Blockchain-Enhanced RAG via Committee-Based Credibility Scoring
arXiv:2608.20097v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) lets Large Language Models (LLMs) pull in up-to-date, domain-specific information instead of relying only on what they were trained on. Yet most RAG systems still draw from centralized databases with limited oversight, making it difficult to verify where a document came from, whether it has been tampered with, or whether it should be trusted at all. This is a serious problem in domains where…
EchoCoT: Extracting Hidden Chain-of-Thought from Large Reasoning Models
arXiv:2608.20055v1 Announce Type: new Abstract: Hidden chain-of-thought (CoT) traces, especially those from frontier proprietary large reasoning models (LRMs), are valuable model assets. Yet whether these hidden CoTs can be directly extracted from black-box models remains largely unexplored. In this work, we systematically study whether hidden CoTs can be extracted near-verbatim from black-box LRMs through API interactions. We identify a previously overlooked reasoning replay…
COPA: Continual Preference Optimization for Adaptive Prompt Injection Defense
arXiv:2608.19982v1 Announce Type: new Abstract: LLMs remain vulnerable to prompt injection attacks, where adversarial instructions embedded in user inputs or external content manipulate model behavior and bypass safeguards. Existing defenses are predominantly static, relying on fixed alignment objectives or attack-specific filtering mechanisms that require redesign as new attack strategies emerge. While recent lifelong alignment methods address shifting user preferences, they…
Tracking the Trend in How Speech Synthesizers Deceive People
arXiv:2608.19959v1 Announce Type: new Abstract: Advances in speech synthesis have made deepfake audio highly realistic. Earlier studies reported 70-80% human detection accuracy, but relied primarily on older synthesizers. We compare human detection for three selected voice synthesis tools released in 2019, 2022, and 2024 with 82 IT professionals, and benchmark humans against six pretrained detectors on the same material. For fully synthetic speech (full spoofs), the F1 score…
From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs
arXiv:2608.19938v1 Announce Type: new Abstract: Existing approaches to anomalous behaviour log detection, such as Wazuh rely primarily on predefined detection rules, while statistical anomaly detection approaches such as OpenSearch identify deviations from previously observed behavioural patterns. Recent research has investigated LLMs for log anomaly detection because of their ability to interpret semantic and contextual information. However, LLM-based approaches can be affec…
ShadowPath: Lookup-Private Credential Status Verification over Authenticated State
arXiv:2608.19937v1 Announce Type: new Abstract: Verifiable credentials let holders present digitally signed claims without requiring the issuer to participate in every presentation. Revocation complicates this privacy model because a verifier must determine whether a credential remains valid. Existing status checks may expose recurring identifiers, registry positions, or request metadata. Such information can serve as stable handles to link separate presentations. ShadowPath…
Securing Filesystems for Confidential Computing
arXiv:2608.19924v1 Announce Type: new Abstract: Confidential computing protects applications inside Trusted Execution Environments (TEEs), but it leaves storage vulnerable. Even with disk encryption, a malicious cloud provider can roll back, replay, fork, or tamper with disk state, breaking the integrity and freshness guarantees required by stateful applications. Existing solutions either assume trusted storage, incur high overheads, or push integrity logic into applications.…
MaliciousSkillBench: A Comprehensive Benchmark for Malicious Agent Skill Detection
arXiv:2608.19901v1 Announce Type: new Abstract: Agent Skills extend LLM agents with reusable instruction packages that may also include scripts, resources, and service configuration. This creates a direct distribution channel for malicious behavior, yet existing malicious-Skill datasets are fragmented across sources, artifact formats, evidence regimes, and benign coverage; duplicated and structurally related content further complicates direct aggregation and evaluation. We pr…
Survival of~the~Stealthiest: Evolving Low-Entropy Ransomware via~Genetic Algorithms
arXiv:2608.19821v1 Announce Type: new Abstract: Traditional ransomware deployment often relies on massive encryption procedure, triggering immediate detection by modern defense systems. This work introduces a paradigm shift in cryptographic attacks by framing ransomware execution as a Search-Based Software Engineering (SBSE) optimization problem. This approach addresses the persistence gap observed in modern threats, where attacks aim to remain undercover for hours rather tha…
TGL-APT: Temporal Graph Learning with Graph Distillation for Efficient APT Investigation
arXiv:2608.19750v1 Announce Type: new Abstract: Advanced Persistent Threat (APT) attacks pose a critical challenge to modern systems, as their stealthy, multi-stage nature renders conventional detection methods ineffective. While provenance graphs provide rich behavioral context for attack investigation, attack-relevant evidence is often sparse and embedded in large volumes of routine system activity, making full-graph learning both computationally expensive and difficult to…
Enhancing Privacy in Federated Learning via Dual Obfuscation of Gradients and Training Images
arXiv:2608.19650v1 Announce Type: new Abstract: Federated learning enables collaborative model training while keeping data locally at each client; however, recent studies have shown that training data can be reconstructed from shared model updates. To address this issue, this paper proposes a dual obfuscation method that enhances robustness against image restoration attacks by jointly obfuscating updated information and training images. The proposed method combines a robustne…
AEGIS: Attention-Embedding Gradient Isolation Shield - Triple-Channel Gradient Masking for Privacy-Preserving Federated LLM Fine-Tuning
arXiv:2608.19534v1 Announce Type: new Abstract: Gradient inversion attacks recover private training text from gradients shared in federated learning, posing a serious threat to collaborative model training. Through our analysis of transformer gradient structure, we identify three channels through which private token information leaks: the attention output projection gradient exposes a low-rank subspace that encodes input embeddings (Channel 1), the embedding gradient's row-no…
A Federated Learning Framework for Privacy-Preserving Oral Cancer Screening on Smartphones
arXiv:2608.19462v1 Announce Type: new Abstract: Data are the cornerstone of robust AI models. However, in the medical domain, access to reliable data is constrained by regulatory requirements and patient privacy, and clinical oral images are particularly difficult to obtain. Federated learning (FL) mitigates these constraints by enabling collaborative model development across decentralized datasets without centralizing or sharing patient data. This work presents a practical F…
Redactable blockchains and polynomial equations
arXiv:2608.19401v1 Announce Type: new Abstract: We develop new tools for constructing redactable authenticated data structures with post-quantum security. In our construction, inverting the proposed one-way function means solving a polynomial equation (or a system of polynomial equations) in more than one variable. This is presently considered quantum-safe, i.e., there is no known quantum algorithm that could solve this problem efficiently if parameters are chosen wisely.
Aray: Deterministic-First Synthesis of Benign Artifacts for YARA Validation
arXiv:2608.19387v1 Announce Type: new Abstract: A YARA rule is easy to distribute, but the malware sample used to demonstrate a positive match is not. This complicates storage, continuous integration, disaster-recovery exercises, and reproducible scanner validation. Constructing a replacement fixture requires more than embedding literals: YARA conditions can combine alternatives, counts, offsets, integer reads, and executable-container constraints, while the resulting file sh…
ABEAT: Efficient and Anonymous Encryption for ABE-based Dynamic Group Communication
arXiv:2608.19302v1 Announce Type: new Abstract: Confidential communication among a dynamic group of participants that ensures flexible and efficient many-to- many communication is highly desired capability. We leverage attribute-based encryption (ABE) for confidential group communication and enhance it by a graph-based namespace to create an efficient framework that allows groups to be formed and changed dynamically. In this paper, we focus on the important additional need to…
Incident-Data Robustness Analysis of the OWASP Top 10 for LLM Applications (2026): How a Community-Expert Ranking Holds Up Against a Large-Scale LLM Incident Corpus
arXiv:2608.19266v1 Announce Type: new Abstract: The OWASP Top 10 for LLM Applications ranks the risks that a community of security practitioners judges most important. We ask a narrower question: checked against the record of real incidents, does that expert ranking agree with the data? We assembled a large-scale corpus of LLM-security incidents (7,714 snapshotted and 6,639 labeled against the 20-entry taxonomy) drawn from CVE, GHSA, OSV, and AIAAIC, and derived an incident-b…
Measuring benchmark optimization in speech recognition
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
[$] A look at the Quickshell desktop-component toolkit
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.