Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,092 source documents · 4,061 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
0
Publisher text withheld
29
A Bayesian Correlated Equilibrium for Early Insider-Threat Detection
arXiv:2609.03096v1 Announce Type: new Abstract: We model insider threat detection as a dynamic Bayesian game in which a platform coordinates a committee of strategic certifiers to sustain equilibrium among honest users and detect malicious deviations before exfiltration. Certifiers and users operate under a Bayesian Temporal Correlated Equilibrium (BTCE), where a sealed-envelope correlating device issues private recommendations over time and obedience is verified at every on-…
Differentially private federated learning with Byzantine-robust aggregation: A cross-domain framework for secure model training in banking and healthcare systems
arXiv:2609.03064v1 Announce Type: new Abstract: Federated learning allows banks, hospitals, and other regulated organizations to train a shared model without moving raw records off their own servers, which is attractive wherever data protection law or competitive sensitivity rules out pooling data centrally. Two problems limit how far this promise can be trusted in practice. First, the parameter updates that clients exchange still leak information about local records through…
Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New Chains
arXiv:2609.03036v1 Announce Type: new Abstract: Compliance screening of blockchain addresses is, in practice, a lookup against sanctions registries plus clustering heuristics; it fails on unlabelled addresses and on chains with no label coverage at all. We describe a deployed system that scores an address by its position in a multi-chain transaction graph rather than by its presence in a list. The substrate is a single graph of 835,330,427 addresses and 15,826,261,934 edges a…
Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation
arXiv:2609.02983v1 Announce Type: new Abstract: Pattern-based secret scanners are commonly validated with example-based fixtures that fix one variable: the text surrounding a credential. We introduce boundary-mutation testing to vary that context, generating credentials from each rule's own regular expression, embedding them in realistic source contexts, and classifying outcomes at the rule level rather than the tool level, yielding three detection metrics. Applied to three s…
Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks
arXiv:2609.02971v1 Announce Type: new Abstract: As vehicular networks move toward 5G/6G edge intelligence, federated learning (FL) is widely promoted as a privacy-preserving way for vehicles and infrastructure to train shared models without exposing raw sensor data. Yet the updates clients transmit still leak enough information to identify who sent them, which threatens the anonymity that safety-critical V2X applications assume and adds to existing concerns over adversarial M…
Privacy-Preserving Topology-Guided Safety for LLM-Based Multi-Agent Systems via Federated Graph Learning
arXiv:2609.02967v1 Announce Type: new Abstract: Topology-guided safeguards for LLM-based multi-agent systems (MAS) train a GNN over the inter-agent communication graph to localize risky agents and intervene on the topology---but they assume one operator can pool all labeled traces. Across organizations that assumption breaks: episodes contain private prompts, tool outputs, and proprietary workflows, and no silo alone sees the full attack distribution. We cast privacy-preservi…
When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization
arXiv:2609.02964v1 Announce Type: new Abstract: This paper focuses on defending generative search engines against malicious Generative Engine Optimization (GEO), which rewrites web documents to match engines' citation preferences and thereby manipulates generated answers. Recent GEO methods have advanced from hand-crafted rewriting to automated and agentic optimization, substantially increasing the visibility of target documents in generated answers. However, defending agains…
PrivateHub: Contrastive Diffusion Model for Private Sensor-Intensive Environment Data Generation
arXiv:2609.02958v1 Announce Type: new Abstract: Sensor-intensive environments enable many intelligent services by inferring user applications from heterogeneous data streams. However, not all applications should be exposed: users want some activities to stay private. This creates a tension between inferring applications for useful services and preventing unwanted inference. Existing approaches such as differential privacy and rule-based filtering protect individual streams bu…
Privacy-Preserving Heterogeneous Multi-LLM Federated Inference for Cognitive Diagnosis
arXiv:2609.02947v1 Announce Type: new Abstract: Significant challenges remain in AI-driven educational systems in balancing privacy preservation with accurate cognitive diagnosis. To overcome this, we propose a federated inference framework in which several commercial LLM APIs collaborate without requiring access to raw student data or proprietary model internals. Using multiple federated entities, such as LLaMA-3.3-70B, GPT-4o-mini, and Claude-3-Haiku, our framework builds u…
A Public-Key-Dependent Adversarial-Deletion Ceiling for Fixed-Alphabet Multi-Bit Pseudorandom Codes
arXiv:2609.02943v1 Announce Type: new Abstract: A pseudorandom code (PRC) is a keyed error-correcting code whose codewords are computationally indistinguishable from uniform strings. We study public-key PRCs over fixed alphabets against adversarial deletions, where the deletion channel may both depend on the public encoding key and the transmitted codeword. Let $\gamma_q^{\mathrm{LCS}}$ denote the asymptotic normalised longest-common-subsequence length of two independent unif…
US senator calls on the NSA to give guidance for use of VPNs
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Large group of Serbian opposition, activist figures targeted with spyware
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
The story behind the intelligence
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Chainalysis Supports HyperEVM with Automatic Token Support
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
ASCII smuggling crosses over from AI prompt injection to phishing evasion
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
[$] Recent work in memory tiering
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Audacity 4.0 released
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
*NeoMME*: an efficient Multimodal-native and Multilingual Encoder
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Security updates for Thursday
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
FBI Seizes $560K in Crypto From Hamas Fundraising Network
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
HiddenLayer Raises $100 Million for AI Runtime Security
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
US and Canadian court data exposed in Thomson Reuters breach
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
153 Million Driver License Images Offered on Dark Web
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
SpiderSapien: Client-Centric Web Crawler and Security Scanner
arXiv:2609.02532v1 Announce Type: new Abstract: Black-box web application crawling and scanning play an important role for security testing of web applications. Yet state-of-the-art scanners fall short of addressing key characteristics of a modern web application: its extreme dynamism and interactivity on the client side. This paper identifies immersive interaction as a key ingredient for scanners to deeply explore modern web applications. We propose SpiderSapien, a client-ce…
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.