Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,092 source documents · 4,061 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
0
Publisher text withheld
16
Evaluating ML-based Intrusion Detection Systems: The Illusion of Model Efficacy
arXiv:2609.02469v1 Announce Type: new Abstract: Intrusion Detection has been revolutionized due to the integration of Machine Learning. Improved detection rates, reduced false alarms, and optimized algorithms contribute to the perception of improved systems with optimal accuracy and near-perfect performance, the illusion of model efficacy. However, the value of this effectiveness diminishes when confronted with unseen attacks. In this paper, we go beyond solely algorithmic en…
Can Risk-Based Alerting Mitigate Cybersecurity Alert Fatigue?
arXiv:2609.02465v1 Announce Type: new Abstract: Security operations centers (SOCs) face large numbers of false alerts, making detection of cyberattacks difficult under typical resource constraints. Risk-based alerting (RBA) has been proposed as a means to reduce false alerts and has reportedly succeeded in doing so in various enterprise deployments. However, RBA has not been comprehensively evaluated until now, leaving implementation mostly guesswork based on anecdotal eviden…
CAPTCHAs in the Agentic Era: Solvers That Learn from Every Encounter
arXiv:2609.02393v1 Announce Type: new Abstract: Vision-language models (VLMs) can solve visual CAPTCHAs without task-specific training, but the agents built on them approach every challenge from scratch. For such an agent, the hundredth instance of a familiar puzzle costs as much time and compute as the first. Specialized detectors invert the trade-off, answering in milliseconds but only for categories they were trained on. Neither improves with exposure. We study what change…
Retrosynthesis of Synthetic Media for Explainable AI Provenance Forensics
arXiv:2609.02268v1 Announce Type: new Abstract: With the rapid proliferation of generative models on Machine Learning as a Service (MLaaS) platforms, reliably tracing the provenance of synthetic media without modifying generator architectures or parameters remains a major challenge. In this work, we propose a self-referential retrosynthesis framework for explainable AI provenance forensics under a fixed-generator setting. The framework leverages a jointly optimized encoder-de…
Agentic Settlement Protocol: An Application Profile for Refundable, Delayed-Fulfilment Agent Commerce on Stablecoin Rails
arXiv:2609.02208v1 Announce Type: new Abstract: Autonomous agents can already pay per request: HTTP-native protocols such as x402 let an agent sign a stablecoin authorization and receive a resource in the same round trip. That model is atomic and final, which suits metered access and fails commerce: a purchase made on a person's behalf -- a service appointment, a physical order, a flight -- is large, frequently cancelled, and should not become the seller's money until deliver…
WeaveMark: Robust and Scalable Multi-bit LLM Watermarking via Coded Payload Spreading
arXiv:2609.02177v1 Announce Type: new Abstract: Multi-bit watermarking for large language models (LLMs) enables content source tracing by embedding user-identifiable messages into generated text. Existing methods face a fundamental trade-off among extraction accuracy, text quality, and payload capacity. We propose WeaveMark, a robust and scalable multi-bit LLM watermarking scheme based on coded payload spreading. WeaveMark shifts this trade-off frontier by improving payload c…
Stored Is Not Supported: Typed Provenance and Assertion Guardrails for Persistent AI Agents
arXiv:2609.02127v1 Announce Type: new Abstract: Persistent AI agents construct autobiographical state through reflection, retrieval, and consolidation. Persistence changes availability, not epistemic standing: stored or retrieved material is not thereby supported. Untrusted inputs, prompt injections, and model inferences can therefore enter persistent state and later be presented as agent history or user commitments. We specify typed provenance and assertion guardrails for au…
Type-Directed, Secure-by-Construction Enclave Partitioning for LLVM
arXiv:2609.02048v1 Announce Type: new Abstract: Trusted Execution Environments (TEEs) provide hardware-supported isolation through enclaves that protect code and data independently of software abstractions. However, TEEs alone cannot enforce information-flow security. This problem is further aggravated in LLVM-like low-level languages that allow unrestricted pointer manipulation and unstructured control flow. Moreover, using TEEs effectively typically requires manually partit…
Implicit Manipulation for Skill Selection in LLM Agents with Semantic Matching
arXiv:2609.02035v1 Announce Type: new Abstract: Skill selection is a key stage in LLM-agent workflows, determining which installed skill should handle a user request. Existing attacks on this stage primarily rely on explicit prompt injection or instruction-level steering, which can expose recognizable manipulation signals. In this work, we identify a new implicit attack surface for skill selection: even when the user prompt and skill description appear benign in isolation, th…
C$^2$T-OpenMax: A Novel Open-Set WiFi RF Fingerprinting Method via Center Constrained Learning and Confidence-Guided Tail Modeling
arXiv:2609.02007v1 Announce Type: new Abstract: Radio frequency fingerprinting (RFF) enables device authentication from transmitter-specific hardware imperfections, but practical deployment requires cross-environment open-set recognition. Data augmentation improves environmental generalization, yet may yield dispersed, low-confidence known-class representations that distort the class statistics used by OpenMax. To address this problem, we propose C$^2$T-OpenMax, an enhanced O…
Pushing Forward Multi-Secret-Key Homomorphic Encryption for Private Average Aggregation
arXiv:2609.01945v1 Announce Type: new Abstract: Federated Learning enables multiple clients to train a shared model while keeping their local datasets isolated. However, the exchanged model updates may still leak sensitive information, making private aggregation a central building block in practical deployments, especially in the cross-silo setting. Homomorphic Encryption naturally fits the client--aggregator communication pattern of Federated Learning, but conventional singl…
Privacy Amplification Without Independence: How Far Negative Dependence Carries the Guarantees of Poisson Subsampling
arXiv:2609.01944v1 Announce Type: new Abstract: Poisson subsampling is the default sampler in differentially private optimization because its independence makes privacy amplification tractable. Practical systems, however, are moving toward structured participation: random allocation (balls-in-bins), per-epoch allocation, random check-ins, schemes widely believed to be at least as private as Poisson subsampling at the matched rate. We isolate the probabilistic mechanism behind…
Bonded Recourse for Smart-Contract Settlement of Compensable Agent Side Effects
arXiv:2609.01939v1 Announce Type: new Abstract: Autonomous agent runtimes execute tool actions that mutate databases, repositories, and cloud services across organizational boundaries. Authorization and local compensation cover pre-action admission and in-runtime rollback, but neither settles the residual harm left after a permitted action fails. We design Recourse, a smart-contract settlement protocol for compensable agent side effects that binds each admitted action to scop…
Agent Flight Recorder: Tamper-Evident Audit Trails with On-Chain Anchoring for Long-Horizon Tool-Using Agents
arXiv:2609.01931v1 Announce Type: new Abstract: Long-horizon agents execute thousands of actions, resulting in sequential failures rather than isolated errors. When a coding agent deletes a production database or a prompt injection spreads across agents, the incident raises questions of causality, authority, and non-repudiable third-party verification. The Agent Flight Recorder captures each agent action as a structured, canonically serialized event binding eight semantic fie…
Adversarial Vulnerabilities of Neural Biomarker Identification Systems
arXiv:2609.01856v1 Announce Type: new Abstract: There is growing interest in the proposed use of EEG signals as biometric credentials, but thus far there has been little research on the reliability and security of such biometrics. Prior adversarial tests have focused on deep-learning classifiers and assumed attackers have full access to the classifier model. This has left unexamined other, more popular categories of neural signature methods as well as the more realistic case…
Agent Memory Is a Surface for Endogenous Authorization Laundering
arXiv:2609.01836v1 Announce Type: new Abstract: Long-running LLM agents rely on persistent memory to carry state across interactions, including permissions, restrictions, and revocations. When memory misrepresents this evolving authorization state, the agent's own records can grant authority that the underlying history never permitted, resulting in misaligned behavior without any external attacks. We term this failure endogenous authorization laundering, where spurious permis…
Towards Behavior Tree-Guided Vulnerability Detection with Lightweight LLMs
arXiv:2609.01758v1 Announce Type: new Abstract: Large Language Models (LLMs) are increasingly used for software vulnerability detection, but their performance depends on how source code is represented in the input. Most prompting approaches use source code in its original form, while some works propose the use of structured representations. Abstract Syntax Trees (ASTs) are one of the most popular approaches, but AST verbosity increases input size relative to source code, maki…
HEAT: Faster Fully Homomorphic Inference via Approximations-Weights Co-Adaptation
arXiv:2609.01730v1 Announce Type: new Abstract: Fully homomorphic encryption (FHE) allows a server to run a language model directly on encrypted user prompts, but current approaches remain prohibitively slow. Ciphertexts natively support only addition, multiplication, and rotation, and multiplications may be composed only to a bounded depth before a costly bootstrapping operation is needed to continue. Every nonlinearity must therefore be approximated by an iterative method,…
Hearing the Whispers: Black-Box Membership Inference Attacks on Finetuned TTS Models
arXiv:2609.01723v1 Announce Type: new Abstract: Text-to-Speech (TTS) foundation models are increasingly fine-tuned on private datasets to synthesize highly personalized voices, introducing severe privacy risks by exposing both biometric identities and sensitive speech content. Existing black-box membership inference attacks (MIAs) follow a two-stage pipeline of query generation and representation engineering, both of which face unique challenges when adapted to TTS. For query…
Public-Sharing Labels and Verbatim Field Egress in an MCP-to-A2A Agent Configuration: A Controlled Multi-Model Study
arXiv:2609.01693v1 Announce Type: new Abstract: Safety properties assessed separately for Model Context Protocol (MCP) tool use and Agent2Agent (A2A) delegation need not describe behavior when one agent uses both. We measure one such behavior in a single controlled MCP-to-A2A configuration: a testbed drives a real-model host across a local MCP and a local A2A leg into an ordered event trace scored by exact deterministic rules (no LLM judge), one restricted decision per trial.…
Skill-as-API: Confidential Multi-Agent Coordination for Agentic Software Engineering
arXiv:2609.01677v1 Announce Type: new Abstract: AI coding agents are evolving from solitary tools into collaborative teammates that discover and invoke one another's specialized skills. But the coordination channel itself can leak a skill's intellectual property. Protocols such as MCP and A2A run implementations server-side, yet they still publish each skill's description and typed schemas to every peer, offer no way to hide a skill's existence, and cannot guarantee that a wr…
Ranked by the Matcher: A Reproducibility Audit of Knowledge Graph Extraction from Threat Reports
arXiv:2609.01671v1 Announce Type: new Abstract: Security teams and researchers choose knowledge-graph extraction tooling for threat reports on the strength of published triple-F1 scores, yet those scores depend on how predicted triples are matched to gold annotations. We could reimplement the stated matching rule for only five of twelve inspected systems. Re-scoring ten system outputs on shared documents under eight protocols reverses eleven of forty-five pairwise orderings;…
Private Computation Space: Experience with Trusted Multi-Cluster Federated Learning for Agriculture
arXiv:2609.01667v1 Announce Type: new Abstract: Artificial Intelligence has shown to help improve agricultural practices, yet adoption remains limited: 69% of U.S. farmers have privacy concerns with sharing their data, and these concerns must be addressed before adoption is widespread. While Federated Learning has been demonstrated to protect privacy at scale for other sectors, deploying a system for agriculture comes with its own set of challenges; the problem necessitates a…
Context Inference Attacks Without Jailbreaks
arXiv:2609.01663v1 Announce Type: new Abstract: Agentic AI systems are increasingly deployed to process sensitive data at inference time, such as healthcare records or financial documents assembled into a hidden \emph{context} before the system answers. Prior work has studied privacy risks primarily through \emph{jailbreaking} attacks that induce models to directly disclose sensitive content, but has largely overlooked the agentic setting where the context is assembled by the…
[$] LWN.net Weekly Edition for September 3, 2026
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Training a coding model to paint watercolours with TRL and OpenEnv
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
My driver's license is one of 153 million for sale on a new dark website
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
OpenLeash Adds a Human Check to Risky AI Agent Actions
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Russian national facing 20 years for malware campaign that infected 80,000 freelancers
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Health data of more than 9.5 million people leaked from Aesto record system
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
[$] Securely suspending LUKS-encrypted disks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
New pro-Ukraine hacker group targets Russian companies with custom ransomware
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
[$] Governing GNOMEs: how the project's technical decision-making is evolving
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Incus 7.4 released
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Real-Time Intelligence with IBM Time Series Models on Confluent
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.