REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
850 reports · page 17 of 22
arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
NeuroLog: Reasoning You Can Audit -- Neuro-Symbolic Vulnerability Discovery via LLM Facts, Datalog, and SMT arXiv:2606.00669v1 Announce Type: new Abstract: Vulnerability discovery on C/C++ source asks the analyst to choose between heavyweight static analysers, which need a working build before a single query runs, and free-form LLMs, which read source readily but invent details and lose track of cross-function dataflow on real codebases. We present NeuroLog, an end-to-end bu…
Read original ↗https://arxiv.org/abs/2606.00669arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents arXiv:2606.00497v1 Announce Type: new Abstract: Deceptive web content, widely instantiated across the internet and commonly known as \textit{social-engineering attacks}, manipulates autonomous web agents into submitting users' personally identifiable information (PII) to attacker-controlled endpoints. In this paper, we show that social-engineering atta…
arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Authenticity Debt and the Synthetic Content Threat Landscape: A Layered Framework for Trust, Provenance, and IP Governance in the Generative AI Era arXiv:2606.00621v1 Announce Type: new Abstract: Generative artificial intelligence has fundamentally changed how content is now produced. It has enabled how high-fidelity text, images, audio, and videos are created, modified, and redistributed at near-zero marginal cost. This shift exposes enterprises and ecosystems to a number o…
Read original ↗https://arxiv.org/abs/2606.00621arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
NICE: A Framework for Declarative and Machine-Checkable Vulnerability Reproduction arXiv:2606.00625v1 Announce Type: new Abstract: Reproducing software vulnerabilities is fundamental to security researchers, open-source maintainers, and educators. Yet, vulnerabilities remain hard to reproduce today, and even when they can be reproduced, recreating a software environment where the vulnerability can be exploited becomes harder and harder over time. We present NICE, the NIx CvE…
Read original ↗https://arxiv.org/abs/2606.00625arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
PrivacyPeek: Auditing What LLM-Based Agents Acquire, Not Just What They Say arXiv:2606.00152v1 Announce Type: new Abstract: LLM-based agents are rapidly advancing, autonomously invoking external tools to complete multi-step tasks for users. However, agents often acquire more sensitive information than the task requires. Existing privacy benchmarks audit what the agent's response or outgoing actions disclose, but overlook the acquisition stage where data first enters the agen…
Read original ↗https://arxiv.org/abs/2606.00152arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
The Invitation Trap: Proactive Availability Backdoor in LLMs via Conversational Induction arXiv:2606.00654v1 Announce Type: new Abstract: Current backdoor attacks against LLMs are typically manipulated by the attacker and remain passive. In this paper, we introduce the \textbf{Proactive Availability Backdoor (PAB)}, a novel paradigm that shifts the attack vector from passive waiting to active social engineering. By weaponizing the inherent helpfulness of aligned LLMs, PAB pr…
Read original ↗https://arxiv.org/abs/2606.00654arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
How to Compare the Security of Code Written by Humans to LLM-generated Code arXiv:2606.00186v1 Announce Type: new Abstract: Large language models (LLMs) are rapidly transforming how software is created and maintained. Comparing LLM-generated code against human-written standards is essential to determine whether these new tools uphold or erode the security baselines established by professional developers. Yet, we lack a standardized method for empirically comparing the securi…
Read original ↗https://arxiv.org/abs/2606.00186arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
A Moderatorless Protocol for WEREWOLF arXiv:2606.00190v1 Announce Type: new Abstract: Social deduction games, or hidden-role games, are multiplayer games in which players are assigned private roles and act under asymmetric information about other players' roles and actions. In the canonical example Werewolf, werewolves conceal their roles and mislead the other players, while the seer can obtain role information about a chosen player. Thus, a central functionality of such gam…
Read original ↗https://arxiv.org/abs/2606.00190arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Persona Attack: Incremental Memory Injection Jailbreak Attack against Large Language Models arXiv:2606.00150v1 Announce Type: new Abstract: As Large Language Models evolve for user convenience, vulnerability to jailbreak attacks continues to be reported despite ongoing efforts in safety training. Traditional jailbreak techniques typically focus on a single prompt injection, neglecting the models' ability to remember the flow of conversation and the user's instructions. In th…
Read original ↗https://arxiv.org/abs/2606.00150arxiv_cs_cr · tlp:amber · 6/2/2026, 4:00:00 AM
Framework for Discovering GPS Spoofing Attacks in Drone Swarms arXiv:2606.00904v1 Announce Type: new Abstract: Swarm robotics, particularly drone swarms, are used in various safety-critical tasks. While a lot of attention has been given to improving swarm control algorithms for improved intelligence, the security implications of various design choices in swarm control algorithms have not been studied. We highlight how an attacker can exploit the vulnerabilities in swarm cont…
Read original ↗https://arxiv.org/abs/2606.00904arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking arXiv:2605.30883v1 Announce Type: new Abstract: The rise of LLM agents introduces a new threat by enabling planning, coding, and even end-to-end execution of expert-level attack workflows. However, this threat remains underexplored and underestimated since (i) safety alignment prevents LLMs from directly generating harmful instructions, and (ii) most existing jailbreak methods cannot consistently induce agents to …
Read original ↗https://arxiv.org/abs/2605.30883arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
The Surface You Test Is Not the Surface That Breaks arXiv:2605.30454v1 Announce Type: new Abstract: Tool-augmented LLM agents are vulnerable to prompt injection: a third party who controls part of the agent's context can plant instructions that the agent then executes as if they came from the user. Current evaluations report a single attack success rate per model on one channel, the tool output and treat that number as the model's vulnerability. But tool descriptions, which …
Read original ↗https://arxiv.org/abs/2605.30454arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Strengthening Polymorphic Prompt Assembling: Dynamic Separator Generation Against Emerging Prompt Injection Attacks arXiv:2605.30534v1 Announce Type: new Abstract: Polymorphic Prompt Assembling (PPA) defends LLM agents against prompt injections by randomly selecting separator pairs from a fixed pool to isolate user input from system instructions. Although effective, static pool reuse exposes a blast-radius vulnerability: once a separator leaks, it can be exploited in future …
Read original ↗https://arxiv.org/abs/2605.30534arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
AdvScene: Rethinking Adversarial Patch Evaluation Through Scene Robustness arXiv:2605.30578v1 Announce Type: new Abstract: Adversarial patches are physical patterns attached to real objects to mislead AI vision systems. Their real-world risk is not determined by a single successful prediction, but by whether they remain effective after deployment under changing viewpoints, distances, and scene conditions. We refer to this property as scene robustness, the effectiveness of a …
Read original ↗https://arxiv.org/abs/2605.30578arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
An Organization-Scoped LLM Agent Runtime Architecture for Regulated Cybersecurity Operations arXiv:2605.30604v1 Announce Type: new Abstract: Regulated cybersecurity workflows lack a runtime substrate that enforces organization-level scope across retrieval, tool calls, memory, findings, reports, and audit while remaining model-agnostic and locally deployable. Recent large language model (LLM) agent systems report strong results on isolated cybersecurity tasks, yet they do not…
Read original ↗https://arxiv.org/abs/2605.30604arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
CacheProbe: Auditing Prompt Cache Isolation in Gateway APIs arXiv:2605.30613v1 Announce Type: new Abstract: Over the past year, prompt caching in Large Language Models (LLMs) has become increasingly more popular across inference APIs. Prompt caching helps save precious compute resources and speeds up response times by reusing parts of the KV cache of a specific prompt for another request. However, many implementations of prompt caching are not secure against timing attacks o…
Read original ↗https://arxiv.org/abs/2605.30613arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors arXiv:2605.30614v1 Announce Type: new Abstract: With the rise of AI-generated audio, watermarking has become widely used for detecting misuse and protecting intellectual property. However, adversaries may try to remove these watermarks, making it critical to evaluate how well watermarking schemes withstand removal attacks. Existing attacks are often impractical: they either noticeably degrade perceptual qu…
Read original ↗https://arxiv.org/abs/2605.30614arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech arXiv:2605.30650v1 Announce Type: new Abstract: Artificial intelligence is now embedded as a primary decision engine in continuously operated financial AI pipelines spanning training and updating, deployment and inference, and operation with monitoring and feedback. The automation and scale that make these pipelines effective also create novel attack surfaces, where small algorithmic perturbations can amplify i…
Read original ↗https://arxiv.org/abs/2605.30650arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Automatically Attacking Software Reverse Engineering AI Agents arXiv:2605.30667v1 Announce Type: new Abstract: Software tools for reverse engineering executable binary files, such as Ghidra, enable malware analysts to safely conduct robust static analysis without having access to original source code. Coupled with the analytic power of large language models (LLM), agentic systems enabled with tools, such as GhidraMCP, can allow analysts to automate a previously human driven …
Read original ↗https://arxiv.org/abs/2605.30667arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Investigating Detection and Obfuscation of Prompt Injection Attacks Against Software Reverse Engineering AI Agents arXiv:2605.30677v1 Announce Type: new Abstract: Agentic software reverse engineering systems are vulnerable to prompt injection attacks placed into the source code of executable binary files. This research demonstrates defensive tactics for detecting the presences of prompt injection strings in the decompiler output of adversarial example programs. Methods for o…
Read original ↗https://arxiv.org/abs/2605.30677arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity arXiv:2605.30686v1 Announce Type: new Abstract: ReAct agents that interleave chain-of-thought reasoning with tool calls are increasingly deployed for real tasks such as scheduling, file retrieval, and data access. Their tool observation loop creates a direct attack surface: an adversary who controls any tool's return value can embed instructio…
Read original ↗https://arxiv.org/abs/2605.30686arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Triaging Threats to Specialized Guardrails arXiv:2605.30693v1 Announce Type: new Abstract: Building robust safety guardrails is essential for deploying Large Language Models across diverse real-world applications. However, this goal remains challenging because safety risks span heterogeneous threat domains, while existing datasets cover only fragmented risk subsets and rely on inconsistent taxonomies. Consequently, it remains unclear whether current guardrails can generalize…
Read original ↗https://arxiv.org/abs/2605.30693arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
FASR: Automated Identification of Unsafe Control Actions in STPA arXiv:2605.30697v1 Announce Type: new Abstract: The System-Theoretic Process Analysis (STPA) is a well-established hazard analysis technique that has been applied to a wide range of safety-critical systems. Despite its popularity, there is relatively little automation support for STPA, and most of its steps are carried out manually by a human analyst, which can be time consuming and error prone. This paper inve…
Read original ↗https://arxiv.org/abs/2605.30697arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Differentially Private Preference Data Synthesis for Large Language Model Alignment arXiv:2605.30808v1 Announce Type: new Abstract: Preference alignment is a crucial post-training step for large language models (LLMs) to ensure their outputs align with human values. However, post-training on real human preference data raises privacy concerns, as these datasets often contain sensitive user prompts and human judgments. To address this, we propose DPPrefSyn, a novel algorithm f…
Read original ↗https://arxiv.org/abs/2605.30808arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Send a SCOUT First: Pre-hoc Reasoning for Adaptive Detector Allocation in Prompt-Injection Defense arXiv:2605.30837v1 Announce Type: new Abstract: Prompt-injection detectors are heterogeneous: each is strong on a different slice of attacks, and none is always reliable. Yet existing systems still treat detection as a fixed single-detector pipeline, committing every request to one detector's blind spots. We reframe defense as detector allocation: given a heterogeneous pool, de…
Read original ↗https://arxiv.org/abs/2605.30837arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
LLM Anonymization Against Agentic Re-Identificatio arXiv:2605.30848v1 Announce Type: new Abstract: Agentic LLMs with web search change the threat model for text anonymization: weak contextual cues can become cross-referenceable evidence for re-identification, yet those same details also carry downstream analytic value of the text. Existing defenses either remove explicit identifiers, perturb text for formal privacy, or test rewritten text against non-web inference models, le…
Read original ↗https://arxiv.org/abs/2605.30848arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
A Core-Structure-Based Automated Analysis Tool for Commercial Virtualization Obfuscation Deobfuscation arXiv:2605.30902v1 Announce Type: new Abstract: Virtualization obfuscation is a more powerful obfuscation technique compared to other obfuscation methods, and as it is increasingly being applied to malware, it demands significant effort and time from analysts. This study analyzes virtualization obfuscation and proposes a tool called VMPredator that automatically extracts se…
Read original ↗https://arxiv.org/abs/2605.30902arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Free-Riding in the AI Economy: Demystifying Logic Flaws in x402-Enabled Payment Systems arXiv:2605.30998v1 Announce Type: new Abstract: The agentic economy demands programmatic financial rails, positioning the x402 protocol as the de facto standard for machine-to-machine payments. However, bridging synchronous HTTP requests with asynchronous blockchain finality introduces profound state synchronization challenges. In this work, we perform the first comprehensive security ana…
Read original ↗https://arxiv.org/abs/2605.30998arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Thou Shall Not Pass: Gatekeeping Outbound TLS Connections arXiv:2605.31020v1 Announce Type: new Abstract: Despite the widespread use of Transport Layer Security (TLS), its security guarantees are frequently compromised by outdated versions and misconfigurations. To analyze this problem, we collected more than 50 million TLS handshakes over a two-week period at our research institution, Fondazione Bruno Kessler, and analyzed three server-selected parameters against the recomm…
Read original ↗https://arxiv.org/abs/2605.31020arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors arXiv:2605.31042v1 Announce Type: new Abstract: LLM agents are evolving from conversational chatbots to operational tools in real-world workspaces. In local agentic harnesses, an LLM can read and write files, call tools, and reuse workspace state across sessions. While such capabilities enhance utility, they also expose a new attack surface for attackers. Attackers can embed a pro…
Read original ↗https://arxiv.org/abs/2605.31042arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge arXiv:2605.31135v1 Announce Type: new Abstract: The misuse of Java security APIs is a serious security problem in software development. Research in 2024 has shown that this problem is widespread in LLM-generated code. However, it remains unclear whether this phenomenon persists in current models and how external security knowledge affects it. This pa…
Read original ↗https://arxiv.org/abs/2605.31135arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
EvoDefense: Co-Evolving Black-Box Defense with Large Language Models arXiv:2605.31140v1 Announce Type: new Abstract: Large Language Models (LLMs) remain highly vulnerable to diverse attacks, particularly in black-box settings where the internals of target models are inaccessible. Existing black-box defenses typically rely on pre-defined filtering heuristics, which often fail to generalize to unseen attack types and target model architectures. We introduce EvoDefense, an expe…
Read original ↗https://arxiv.org/abs/2605.31140arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
MAECO-Lite: Modular Ontology for Dynamic Malware Analysis arXiv:2605.31199v1 Announce Type: new Abstract: Capturing dynamic malware behavior in a practical but still semantically precise manner remains a significant challenge in cyber threat intelligence. While standards such as MAEC and STIX provide widely adopted vocabularies for describing malware artifacts and observations, they represent data with considerable complexity in structures that often obscure important ontolo…
Read original ↗https://arxiv.org/abs/2605.31199arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt Learning arXiv:2605.31246v1 Announce Type: new Abstract: Prompt learning is a new machine learning paradigm that has attracted ample attention due to its simplicity and proven efficacy. Despite its growing adoption, the security vulnerabilities associated with this paradigm remain underexplored. In this work, we take the first step to propose BadBone, a stealthy and adaptive backdoor attack against prompt lea…
Read original ↗https://arxiv.org/abs/2605.31246arxiv_cs_cr · tlp:amber · 6/1/2026, 4:00:00 AM
Escaping the Linearity Trap: Manifold Detours for Black-Box Adversarial Attacks on Singing Audio Deepfake Detection arXiv:2605.30366v1 Announce Type: new Abstract: Recent Singing Voice Synthesis (SVS) advances enable highly realistic but potentially malicious AI covers, making singing voice deepfake detection (SVDD) crucial. Self-Supervised Learning (SSL)-based detectors achieve state-of-the-art performance by fine-tuning speech SSL backbones to capture singing-specific spoo…
Read original ↗https://arxiv.org/abs/2605.30366arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Latent Geometry as a Structural Monitor: Eigenspace Alignment for Anomaly Detection in Anonymity Networks arXiv:2605.20391v1 Announce Type: new Abstract: Traditional anomaly detection marks events when measured signals cross predefined thresholds. This captures the moment of transition but not the structural pressure that precedes it. We propose treating large behavioral populations as geometric energy landscapes whose deformation can be measured before and during major tran…
Read original ↗https://arxiv.org/abs/2605.20391arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Detecting Data Exfiltration through I2P Anonymity Networks: A Two-Phase Machine Learning Approach arXiv:2605.20546v1 Announce Type: new Abstract: The Invisible Internet Project (I2P) provides strong anonymity through garlic routing and distributed network architecture, making it attractive for legitimate privacy needs. Nevertheless, the same properties can be exploited by malicious actors to steal sensitive information from corporate networks without detection. Current netwo…
Read original ↗https://arxiv.org/abs/2605.20546arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Verifiable Provenance and Watermarking for Generative AI: An Evidentiary Framework for International Operational Law and Domestic Courts arXiv:2605.21002v1 Announce Type: new Abstract: Generative artificial intelligence now synthesizes photorealistic imagery, audio, and video at a cost that defeats traditional forensic intuition. The legal consequences span three regimes studied so far in isolation: international operational law, domestic procedure, and product regulation. T…
Read original ↗https://arxiv.org/abs/2605.21002arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Security Document Classification with a Fine-Tuned Local Large Language Model: Benchmark Data and an Open-Source System arXiv:2605.20368v1 Announce Type: new Abstract: Organizations that scan documents for sensitive information face a practical problem. Cloud services require data to be sent to external infrastructure, while rule-based tools often miss threats that depend on context. This study presents TorchSight, an open-source local system for security document classifica…
Read original ↗https://arxiv.org/abs/2605.20368arxiv_cs_cr · tlp:amber · 5/21/2026, 4:00:00 AM
Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs arXiv:2605.20641v1 Announce Type: new Abstract: Inference optimization is a vital technique for deploying LLMs at scale. Compilation is the most widely adopted optimization technique for LLMs. While it assumes semantic equivalence between the original and compiled graphs, we first uncover its numerical side effects can be maliciously exploited to implant stealthy backdoors in LLMs. We…
Read original ↗https://arxiv.org/abs/2605.20641