REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
850 reports · page 16 of 22
arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
HAVE: Host Active Verification Engine for Closing the Contextual Reality Gap in Security Digital Twins arXiv:2606.06968v1 Announce Type: new Abstract: Security Digital Twins (SDTs) provide continuously updated virtual replicas of infrastructure for threat simulation, yet they rely on theoretical CVSS scores to assign lateral-movement probabilities -- creating the Contextual Reality Gap: risk is overestimated where unacknowledged mitigations neutralize exploits, and drastical…
Read original ↗https://arxiv.org/abs/2606.06968arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Online Safety Regulation Increases Privacy Risk: Evidence from the UK Online Safety Act arXiv:2606.05273v1 Announce Type: cross Abstract: Governments worldwide are increasingly regulating digital platforms to reduce online harms, particularly those affecting children. However, access restrictions can alter user behaviour and introduce new privacy and security risks. The UK Online Safety Act (OSA), passed in October 2023, illustrates this trend: it extends age-assurance and s…
arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Verifiable and Confidential DNN Inference on Low-End Edge Devices arXiv:2606.07470v1 Announce Type: new Abstract: Deploying deep neural network (DNN) inference on low-end edge devices raises two key challenges: protecting model confidentiality against a potentially compromised edge system and enabling verifiable inference without incurring prohibitive overhead. Existing approaches either house partial models and inference software within trusted execution environments (TEEs)…
Read original ↗https://arxiv.org/abs/2606.07470arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Lost in Migration: Exposing Android Framework Vulnerabilities in Parallel Java-Kotlin Implementations arXiv:2606.07420v1 Announce Type: new Abstract: Android has adopted Kotlin alongside Java across apps and core system components. During this shift, we observe parallel implementations in the Android Open Source Project (AOSP) where the same component is implemented in both Java and Kotlin. In principle, their functional purposes are identical. In practice, subtle semantic d…
Read original ↗https://arxiv.org/abs/2606.07420arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
On the Shoulders of Giants: Empowering Automated Smart Contract Auditing via the GiAnt Corpus arXiv:2606.07363v1 Announce Type: new Abstract: High-quality smart contract auditing datasets are crucial for evaluating security tools and advancing smart contract security research. Two major limitations of existing datasets are the manual-induced scalability bottleneck and the deficiency in data granularity and diversity. To address these limitations, we propose GiANT, an automat…
Read original ↗https://arxiv.org/abs/2606.07363arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Empirical Evaluation of Large Language Models for Migration of Code Fragments to Post-Quantum Cryptography arXiv:2606.07341v1 Announce Type: new Abstract: The transition to post-quantum cryptography (PQC) requires not only replacing vulnerable cryptographic primitives, but also refactoring the surrounding software logic. While existing PQC migration frameworks provide organizational guidance, practical code-level remediation remains largely manual and error-prone. This paper…
Read original ↗https://arxiv.org/abs/2606.07341arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Defending Jailbreak Attacks on Large Language Models via Manifold Trajectory Kinetics arXiv:2606.07335v1 Announce Type: new Abstract: Jailbreak prompts can bypass alignment guardrails in large language models (LLMs) and elicit unsafe outputs, making reliable deployment-time detection critical. Prior detection approaches largely rely on a fixed metric space, e.g., raw inputs, gradients, or hidden features, in which benign and jailbreak prompts are linearly separable. We show …
Read original ↗https://arxiv.org/abs/2606.07335arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Authorized and Verifiable Searchable Encryption Based on Public Key Equality Test for Cloud Storage arXiv:2606.07319v1 Announce Type: new Abstract: Cloud storage revolutionizes data management but raises conflicts between functionality and privacy. Public Key Encryption with Equality Test (PKEET), an advanced cryptographic technique, can enable multi-user searchable encryption (SE) through cross-key ciphertext comparison without shared keys. However, existing PKEET-based SE …
Read original ↗https://arxiv.org/abs/2606.07319arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Rethinking IoT Intrusion Detection: Augmenting Routing Metrics with Radio Features arXiv:2606.07282v1 Announce Type: new Abstract: Machine learning-based intrusion detection systems (IDS) for RPL-based IoT networks often rely solely on routing layer features, which provide only a partial view of network behaviour. In this work, we investigate whether incorporating Transmit (TX) and Receive (RX) radio features alongside the standard RPL feature set can improve detection perfo…
Read original ↗https://arxiv.org/abs/2606.07282arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Synthetic APTs: the Collapse of TTP-Based Attribution arXiv:2606.07158v1 Announce Type: new Abstract: Cyber Threat Intelligence CTI attribution relies on identifying the Tactics, Techniques, and Procedures TTPs that distinguish one threat actor from another. This approach presupposes that each adversary leaves a recognizable operational fingerprint. This work investigates whether AI driven adversary emulation challenges that presupposition. We deploy agents from our Cybersec…
Read original ↗https://arxiv.org/abs/2606.07158arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
From Privacy to Workflow Integrity: Communication-Graph Metadata in Autonomous Agent Interoperability arXiv:2606.07150v1 Announce Type: new Abstract: Agent-interoperability protocols such as A2A and MCP standardize what agents say to one another, but assume address-based transport over HTTP(S). Such transports protect message content, increasingly with end-to-end encryption. What they leave in the clear is the communication graph: which agent contacts which, when, and how of…
Read original ↗https://arxiv.org/abs/2606.07150arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
MalSkillBench: A Runtime-Verified Benchmark of Malicious Agent Skills arXiv:2606.07131v1 Announce Type: new Abstract: AI coding agents such as Claude Code and Gemini CLI increasingly extend themselves with third-party skills: markdown packages bundling natural-language instructions, executable scripts, and tool permissions. Because a skill is at once code and agent-facing instruction, it introduces a supply chain dependency whose risk is neither pure code nor pure prompt. De…
Read original ↗https://arxiv.org/abs/2606.07131arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Fast Bounded-Independence Functions and Their Duals arXiv:2606.07009v1 Announce Type: new Abstract: We continue the study of {\em fast} functions, computable by linear-size circuits, that share useful properties of random functions. Motivated by cryptographic applications, we generalize and improve on previous results in this area, obtaining the following results: - For any constant $t$, we construct a fast $t$-wise independent hash function with algebraic degree $\log_2 t$ …
Read original ↗https://arxiv.org/abs/2606.07009arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
The Sound of Malware: A Memory Forensics Approach for Android Malware Analysis via Audio Signals arXiv:2606.07005v1 Announce Type: new Abstract: Android malware analysis is currently facing increasing challenges in achieving robust classification and detecting stealth attacks. Modern threats employ advanced evasion strategies such as code obfuscation, dynamic loading, packing, and even steganographic manipulation of traditional static and dynamic features. These techniques r…
Read original ↗https://arxiv.org/abs/2606.07005arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
DPAgent-in-the-Middle: Agentic Defense and Repair Against AI-Groomed Deceptive Patterns arXiv:2606.06914v1 Announce Type: new Abstract: Privacy deceptive patterns in web interfaces systematically manipulate users into disclosing personal data, yet existing defenses are fragmented, static, and increasingly vulnerable to manipulation by large language models. Moreover, data voids, areas of information scarcity within the web ecosystem, create fertile ground for adversaries to …
Read original ↗https://arxiv.org/abs/2606.06914arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Blockchain Infrastructure for Intelligent Cyber--Physical--Social Systems:Post-Quantum Security, Interoperability, and Trustworthy Data Economies in the Era of Embodied AI arXiv:2606.06895v1 Announce Type: new Abstract: The deployment of embodied artificial intelligence via world-model-based robotics presents a transformative opportunity for blockchain infrastructure, establishing urgent demand for trustworthy data provenance, cross-organizational governance, and incentive-c…
Read original ↗https://arxiv.org/abs/2606.06895arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
FDM: A Framework for Decision-making to build ML-based Malware detection systems arXiv:2606.06894v1 Announce Type: new Abstract: Selecting appropriate machine learning (ML) configurations for malware detection is a complex, multi-criteria problem. Model choice, feature engineering, and update mechanisms must jointly satisfy operational constraints that vary across deployment contexts. This paper proposes the Framework for Decision-making (FDM) to build ML-based malware detec…
Read original ↗https://arxiv.org/abs/2606.06894arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
On the Incentive Compatibility of Block Propagation in Bitcoin arXiv:2606.06860v1 Announce Type: new Abstract: Bitcoin is permissionless and does not rely on any central administrator, which gives it strong censorship resistance. At the same time, it is important to incentivize miners to behave in ways that align with the interests of the system as a whole. This paper asks whether miners are individually incentivized to propagate blocks, one of the most fundamental processes…
Read original ↗https://arxiv.org/abs/2606.06860arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
AMD-FCG: An Enhanced Function Call Graph Dataset with Integrated Topological Features for Malware Detection and Classification arXiv:2606.06815v1 Announce Type: new Abstract: As malware illustrates a complex structure and behavior, detection of these has been a significant challenge in the domain of cybersecurity along with related services in daily life. So, it becomes crucial to have a reliable and adaptive solution to address the issue. Among the several detection methods…
Read original ↗https://arxiv.org/abs/2606.06815arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
What Your Posts Reveal: A Benchmark and Agentic Framework for User-Level Privacy Leakage on Social Media arXiv:2606.06784v1 Announce Type: new Abstract: Public social media posts can reveal private information through weak cues scattered across text, images, or metadata. Such leakage is often cumulative and cross-post: cues that appear harmless in isolation may jointly expose a user's home, workplace, or routine. However, current research lacks a unified benchmark for user-l…
Read original ↗https://arxiv.org/abs/2606.06784arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
The Custody Envelope Threshold: Authority-Scaled Admission of External Artifacts in Institutional Infrastructure arXiv:2606.06767v1 Announce Type: new Abstract: Modern infrastructure depends on externally maintained artifacts such as package-registry dependencies, CI/CD actions, container images, Terraform providers and modules, developer extensions, model artifacts, and AI tool servers. These artifacts are easy to fetch but difficult for institutions to admit, govern, and r…
Read original ↗https://arxiv.org/abs/2606.06767arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
AgileOS: A GPU Operating System Layer for Protected CUDA Services arXiv:2606.06697v1 Announce Type: new Abstract: Modern GPU applications increasingly interact with storage systems, network devices, vendor libraries, and GPU-resident services rather than executing only isolated compute kernels. This shift creates a need for operating-system-like protection around GPU services, where service metadata, device queues, memory-mapped I/O regions, and library-internal state should…
Read original ↗https://arxiv.org/abs/2606.06697arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
MalTree: Tracing Malware Evolution from Embeddings at Scale arXiv:2606.06570v1 Announce Type: new Abstract: Malware detection remains largely reactive: machine learning models trained on known samples degrade as threats evolve. Understanding evolutionary relationships among malware families can inform proactive defense, but traditional reverse engineering can take months to years to uncover such lineage relationships. We propose MalTree, a framework that applies bioinformati…
Read original ↗https://arxiv.org/abs/2606.06570arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Subtle Injection for Ground-truth Inference of LLM Training Data arXiv:2606.06502v1 Announce Type: new Abstract: As large language models (LLMs) are increasingly trained on scraped web corpora without authorisation, content owners require forensic methods to prove that their documents were included in a model's training set. We propose \textbf{SIGIL} (\textbf{S}ubtle \textbf{I}njection for \textbf{G}round-truth \textbf{I}nference of \textbf{L}LM training data), a framework t…
Read original ↗https://arxiv.org/abs/2606.06502arxiv_cs_cr · tlp:amber · 6/8/2026, 4:00:00 AM
Enhancing Malware Detection with Generative AI: Using Variational Autoencoders to Boost Machine Learning Classifiers' Performance arXiv:2606.06501v1 Announce Type: new Abstract: The advancement of malware poses obstacles for cybersecurity, necessitating the development of advanced detection techniques. This paper proposes an approach to enhance malware detection through the use of a generative artificial intelligence model. Specifically, variational autoencoders (VAEs) are u…
Read original ↗https://arxiv.org/abs/2606.06501arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Bit-Exact AI Inference Verification Without Performance Tradeoffs arXiv:2606.00279v1 Announce Type: new Abstract: Verifying claims about AI workloads is a pre- requisite for credible AI governance of covert adversaries (who comply with monitoring only when detection likelihood is high), yet the ap- parent non-determinism of GPU floating-point arithmetic forces auditors to accept approximate output matches. Covert adversaries can exploit un- verifiable degrees of freedom in m…
Read original ↗https://arxiv.org/abs/2606.00279arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
From Frontier to Shadow AI: A Simmering Threat to Assurance and Security in Critical Infrastructure arXiv:2606.00088v1 Announce Type: new Abstract: Frontier AI systems, including large language models and emerging agentic AI tools, offer significant operational benefits but present unique challenges to critical infrastructure (CI) environments due to their non-deterministic and emergent properties. While formal adoption is inherently cautious and tightly controlled due to st…
Read original ↗https://arxiv.org/abs/2606.00088arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
A Lightweight Hybrid MLP-Based Framework for Real-Time Phishing URL Detection Using Structural URL Features arXiv:2606.00889v1 Announce Type: new Abstract: Phishing attacks remain a major cybersecurity threat, exploiting deceptive URLs to steal sensitive user information. Traditional blacklist and rule-based detection approaches are reactive and often fail to identify newly emerging phishing URLs. This paper proposes a lightweight hybrid framework for real-time phishing URL …
Read original ↗https://arxiv.org/abs/2606.00889arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
GCVE: A Decentralized Model for Vulnerability Identification, Publication, and Operational Enrichment arXiv:2606.00856v1 Announce Type: new Abstract: The Global CVE initiative (GCVE) proposes a decentralized, open, and extensible model for vulnerability identification, publication, and enrichment. It addresses a gap in today's vulnerability ecosystem: centralized systems provide rigorous control and widely recognized identifiers, while many producers publish advisories indep…
Read original ↗https://arxiv.org/abs/2606.00856arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
A Survey on Security with Quantum Computing arXiv:2606.00058v1 Announce Type: new Abstract: Quantum computing has emerged as a transformative computing paradigm capable of solving problems that remain computationally infeasible for classical systems; however, its rapid advancement also introduces significant security, privacy, and reliability concerns. In this context, this survey presents a comprehensive review of security challenges and mitigation strategies associated wit…
Read original ↗https://arxiv.org/abs/2606.00058arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Improving IoT Intrusion Detection Through SMOTE-Based Oversampling and Extended Multi-Model Evaluation on Side-Channel Power Data arXiv:2606.00161v1 Announce Type: new Abstract: The detection of intrusions in IoT-based networks poses challenges that cannot be overcome using traditional machine learning methods. Perhaps the biggest of them is related to the presence of a class imbalance in the side-channel dataset, where the number of samples in the normal class compared to t…
Read original ↗https://arxiv.org/abs/2606.00161arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Beyond Edge Coverage: Per-Task Data-Flow Extraction at Kernel Function Boundaries via LLVM arXiv:2606.00455v1 Announce Type: new Abstract: Coverage-guided kernel fuzzers such as syzkaller rely on edge coverage (trace-pc) as their sole feedback signal. This context-blind approach cannot distinguish execution paths that differ only in argument values. for example, two invocations of copy_from_user() with different size parameters hit identical basic blocks yet have vastly diff…
Read original ↗https://arxiv.org/abs/2606.00455arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
DataShield: Safety-degrading Data Filtering for LLM Benign Instruction Fine-Tuning arXiv:2606.00160v1 Announce Type: new Abstract: Large language models (LLMs) suffer from degraded safety capabilities even when fine-tuned with benign datasets. However, existing methods for identifying safety-degrading samples in benign datasets suffer from high computational costs and significant noise issues. In this paper, we propose DataShield to efficiently and effectively identify poten…
Read original ↗https://arxiv.org/abs/2606.00160arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Cross-Generational Transfer of Adversarial Attacks Reveals Non-Monotonic Safety Alignment in LLMs arXiv:2606.00813v1 Announce Type: new Abstract: Safety alignment in LLMs does not improve monotonically across model generations. Studying four generations of Google's Gemma family (7B-31B) with quality-diversity evolution (MAP-Elites) as an automated red-teaming probe, we find that Gemma 3 (12B) exhibits 68.7% +/- 5.7% attack success rate (ASR; mean +/- std, 3 seeds), significa…
Read original ↗https://arxiv.org/abs/2606.00813arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Stochastic Analysis of Cybersecurity Defense Strategies Under Single Attack Scenario arXiv:2606.00481v1 Announce Type: new Abstract: This research presents a novel stochastic framework for proactive cybersecurity defense timing under a single attack scenario. The approach models the defense process as a continuous observation mechanism in which the defense instant and the subsequent observation slot follow independent exponential distributions. Laplace-Carson transforms comb…
Read original ↗https://arxiv.org/abs/2606.00481arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
XAI-SOH-FL: Enhancing SOH-FL with Adaptive Aggregation and Explainable AI for Intrusion Detection in Heterogeneous IoT arXiv:2606.00134v1 Announce Type: new Abstract: Intrusion Detection Systems (IDS) in Internet of Things (IoT) environments face significant challenges due to data heterogeneity, lack of labeled data, and limited model interpretability. Federated Learning (FL) offers a privacy-preserving solution; however, existing approaches such as SOH-FL suffer from two ke…
Read original ↗https://arxiv.org/abs/2606.00134arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Quality-Diversity Evolution for Discovering Diverse Vulnerabilities in LLM Safety arXiv:2606.00801v1 Announce Type: new Abstract: Current approaches to LLM adversarial testing suffer from coverage gaps: manual red-teaming does not scale, LLM-as-attacker methods exhibit mode collapse, and gradient-based approaches produce uninterpretable gibberish. We introduce a quality-diversity evolutionary framework that operates at the semantic level, evolving interpretable attack strate…
Read original ↗https://arxiv.org/abs/2606.00801arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
A Protocol-Language Model for Network Intrusion (Without Deep Packet Inspection) arXiv:2606.00155v1 Announce Type: new Abstract: Modern network intrusion detection systems (NIDS) are caught in a structural contradiction: the protocols carrying the highest threat intelligence are precisely those encrypted under TLS 1.3 and QUIC, where payload inspection yields nothing. We ask a simpler question -- what if the attack signature is not in the bytes, but in the rhythm? -- and ans…
Read original ↗https://arxiv.org/abs/2606.00155arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs arXiv:2606.00485v1 Announce Type: new Abstract: ChatGPT Apps, launched by OpenAI on Oct. 6, 2025, introduce an app-in-app paradigm in which third-party applications share a single chat context with the user and with every other connected app. The ecosystem grew from 122 apps in Dec. 2025 to 888 by May 2026, yet its security has remained uninvestigated. We identify cross-app context poisoning, a variant of ind…
Read original ↗https://arxiv.org/abs/2606.00485arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Inferring Routing-Layer Defense Mechanisms from Observable Behavior in OLSR-Based MANETs arXiv:2606.00184v1 Announce Type: new Abstract: Mobile ad hoc networks (MANETs) based on proactive routing protocols such as OLSR remain vulnerable to routing-layer attacks. While prior work has focused primarily on attack detection, the problem of identifying deployed defenses has received comparatively little attention. This work examines whether the presence of a routing-layer defense…
Read original ↗https://arxiv.org/abs/2606.00184