Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,100 source documents · 4,068 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
0
Publisher text withheld
15
Water Sector Cyberattacks Reportedly Hit at Least 12 States
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Continuous Offensive Security & AI Pentesting: 20 FAQs
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Tiny Enough to Break In: Agentic Remote Access Trojans Powered by Small Language Models
Tiny Enough to Break In: Agentic Remote Access Trojans Powered by Small Language Models arXiv:2608.03009v1 Announce Type: new Abstract: Agentic artificial intelligence raises a new security concern: cyber threats that reason, act, and adapt locally without continuous human direction. We examine this threat through an Agentic Remote Access Trojan (agentic RAT): a Remote Access Trojan augmented with a locally deployed Small Language Model (SLM). The SLM interprets host and net…
SparSEEty: Extracting Tokens from Sparsity-Exploiting LLM Serving Systems via Deterministic Side Channels
SparSEEty: Extracting Tokens from Sparsity-Exploiting LLM Serving Systems via Deterministic Side Channels arXiv:2608.02995v1 Announce Type: new Abstract: Modern large language models (LLMs) exhibit activation sparsity, wherein only a subset of their neurons is activated for given input tokens. Researchers have leveraged this property to optimize LLM serving systems by omitting weight accesses and computations pertaining to inactive neurons. Unfortunately, however, such optim…
Internalising the Identity Primitive: Cryptographic Individuality for an Autonomous Agent on a Public Blockchain
Internalising the Identity Primitive: Cryptographic Individuality for an Autonomous Agent on a Public Blockchain arXiv:2608.02986v1 Announce Type: new Abstract: A software agent on a public blockchain accumulates authority and economic stakes, raising the engineering question of what makes it count as an individual. The paper's central contribution is a shift of trust root for the key-to-weights binding of agent identity: from hardware, operator, or wrapper trust to cryptogr…
MutMem: Cryptographically Authorized Mutation in Persistent Agent Memory
MutMem: Cryptographically Authorized Mutation in Persistent Agent Memory arXiv:2608.02843v1 Announce Type: new Abstract: Persistent agent memory must adapt as later outcomes change earlier evidence, yet mutable retrieval weights create an attribution problem: reviewers must distinguish authorized adaptation from database tampering. We present MutMem, an authorized-mutation protocol in HOM-AIMOS, a persistent agent-memory engine. MutMem retains memory content, records signed …
Decidability of Parameterised Dolev-Yao Secrecy
Decidability of Parameterised Dolev-Yao Secrecy arXiv:2608.02838v1 Announce Type: new Abstract: We study the verification of parameterised secrecy for cryptographic protocols in the Dolev-Yao model, where the number of protocol sessions is unbounded and treated as a parameter. This differs fundamentally from classical Dolev-Yao secrecy, which asks whether a protocol leaks a secret irrespective of the number of executions; our question is whether secrecy holds uniformly acros…
What the Detector Can See: Evaluating CPS Anomaly Detectors Independently of the Decision Rule
What the Detector Can See: Evaluating CPS Anomaly Detectors Independently of the Decision Rule arXiv:2608.02821v1 Announce Type: new Abstract: Anomaly detectors are often the last line of defense for cyber-physical systems (CPS). But detectors built in very different ways, from deep neural networks to invariant templates, are usually compared using precision, recall, or F1 at a single operating point. These scores mix two separate things: how well the detector represents the…
Evading Chain-of-Thought Monitoring Through Model Poisoning
Evading Chain-of-Thought Monitoring Through Model Poisoning arXiv:2608.02820v1 Announce Type: new Abstract: Chain-of-thought (CoT) monitoring is an increasingly important component of AI safety stacks but relies on the assumption that a model's reasoning trace is informative about its actions. This work studies the limits of CoT monitoring through the lens of model poisoning. We demonstrate that backdoors can be implanted into reasoning models to elicit an attacker-chosen be…
Fast Object Removal Attacks on Safety-Critical Video-based Perception Systems
Fast Object Removal Attacks on Safety-Critical Video-based Perception Systems arXiv:2608.02806v1 Announce Type: new Abstract: By leveraging data from video-based perception systems, intelligent transportation systems (ITS) support safety-critical applications that improve road safety. However, adversaries may manipulate video frames to compromise downstream perception modules, causing failures in safety-critical functions and increasing risks to vulnerable road users. This p…
Privacy-Preserving AI Verification via Minimal Information Disclosure
Privacy-Preserving AI Verification via Minimal Information Disclosure arXiv:2608.02774v1 Announce Type: new Abstract: AI verification crosses a trust boundary: a verifier must learn enough to establish an authorized claim, yet the same evidence can reveal sensitive details about the model, workload, or hardware. We introduce minimal information disclosure (MID), which designs and quantifies the information content of verifier-facing evidence itself. MID measures collateral l…
Steganalysis of Adaptive Covert Collusion in Tool-Using Agent Populations: A Black-Box, Cross-Principal Approach
Steganalysis of Adaptive Covert Collusion in Tool-Using Agent Populations: A Black-Box, Cross-Principal Approach arXiv:2608.02698v1 Announce Type: new Abstract: Tool-using agents built on large language models (LLMs) are increasingly deployed not by a single operator but by many, side by side on shared infrastructure. This creates a population-level risk that single-agent safeguards miss: a handful of agents can quietly coordinate, rigging a market, boosting one another in a…
Stylometric Defenses Against Author Impersonation in Software Repositories
Stylometric Defenses Against Author Impersonation in Software Repositories arXiv:2608.02695v1 Announce Type: new Abstract: Software supply-chain attacks increasingly exploit an identity gap where compromised maintainer accounts authorize malicious changes. This work evaluates patch-level authorship verification as a behavioral defense layer, showing that stylometric analysis can operate not only on full source files but also on patch-level commits. We fine-tune a cross-modal…
PolicyGuard: Prompt-Configurable Semantic DLP for LLM Coding Agents
PolicyGuard: Prompt-Configurable Semantic DLP for LLM Coding Agents arXiv:2608.02687v1 Announce Type: new Abstract: AI coding agents accept free-form natural language prompts that may inadvertently contain credentials, personally identifiable information (PII), or proprietary business data. Existing data loss prevention (DLP) solutions rely on rigid regex patterns, model fine-tuning, or vendor-managed classifiers with limited customizability. We present PolicyGuard, a pre-mo…
$S^3$: Improving Agent Safety through Multi-Stage Defense
$S^3$: Improving Agent Safety through Multi-Stage Defense arXiv:2608.02683v1 Announce Type: new Abstract: Large Language Model (LLM) agents rely on multi-stage agentic workflows, with stages such as memory, planning, and tool execution, to accomplish complex tasks. However, risks may emerge at different stages, propagate across steps, and become difficult to detect and mitigate. Existing safety methods protect only isolated stages and are difficult to integrate, leaving agen…
Safety in Batches? Understanding and Mitigating Safety Failures in Batch Prompting
Safety in Batches? Understanding and Mitigating Safety Failures in Batch Prompting arXiv:2608.02681v1 Announce Type: new Abstract: Batch prompting is a practical inference strategy for large language models, but its safety implications remain underexplored. We show that the success of batch prompting for utility does not extend to safety: a harmful question that is reliably refused in isolation can elicit a harmful response when embedded in a batch of benign questions. We id…
DenialRAG: Single-Document RAG Poisoning via Embedded Parametric Denial
DenialRAG: Single-Document RAG Poisoning via Embedded Parametric Denial arXiv:2608.02678v1 Announce Type: new Abstract: Retrieval-augmented generation (RAG) systems are vulnerable to corpus poisoning: an attacker who inserts a crafted document into the retrieval corpus can steer the underlying large language model (LLM) toward an attacker-chosen wrong answer. Prior single-document attacks typically avoid explicitly naming and refuting the correct answer inside the poisoned p…
Moving the Safety Barrier: Dynamic Routing Adaptive Alignment Against White-Box Attacks
Moving the Safety Barrier: Dynamic Routing Adaptive Alignment Against White-Box Attacks arXiv:2608.02674v1 Announce Type: new Abstract: With the widespread deployment of large foundation models (LFMs) in open environments, safety threats are shifting from black-box jailbreaks toward white-box attacks that directly identify and disrupt internal safety neurons or routes. However, existing safety defenses often rely on static safety units or fixed refusal pathways, leaving mode…
Security-First Evaluation of Text-to-Terraform: Benchmarking LLMs and SLMs for Secure IaC Generation
Security-First Evaluation of Text-to-Terraform: Benchmarking LLMs and SLMs for Secure IaC Generation arXiv:2608.02672v1 Announce Type: new Abstract: Cloud misconfiguration remains a leading cause of security incidents, yet whether LLMs and SLMs can generate security-compliant Infrastructure-as-Code is an open question. We benchmark seven models, three closed LLMs (Claude Opus 4, GPT-5.4, Gemini 2.5 Pro) and four open SLMs (Qwen2.5-Coder-14B, WizardCoder-33B, CodeLlama-13B, M…
On the Performance of Malware Detection Classifiers Using Hardware Performance Counters
On the Performance of Malware Detection Classifiers Using Hardware Performance Counters arXiv:2608.02671v1 Announce Type: new Abstract: Malware detection using Hardware Performance Counters (HPC) has emerged as a promising solution to improve the security of computing systems as a complement to antivirus software. Hardware-based malware detectors (HMD) use Machine Learning (ML) classifiers to detect malicious application patterns. The inputs to ML classifiers are low-level p…
Permission Denied: Policy-Graded Evaluation of Coding Agents in Hardened Environments
Permission Denied: Policy-Graded Evaluation of Coding Agents in Hardened Environments arXiv:2608.02670v1 Announce Type: new Abstract: Coding agents increasingly run inside organizations whose security controls (scoped credentials, restricted egress, read-only filesystems, non-root execution) constrain them like any other software. Existing benchmarks, however, evaluate agents almost exclusively in permissive sandboxes, so it is unknown how performance changes when policy is …
Vulnerabilities, Secrets and Misconfiguration in the Highest-Exposure Docker Hub Images
Vulnerabilities, Secrets and Misconfiguration in the Highest-Exposure Docker Hub Images arXiv:2608.02669v1 Announce Type: new Abstract: Docker Hub is the registry underneath most container deployments, and a flaw in a widely reused base image is inherited by every image built on it. Prior ecosystem-scale measurements each rely on a single detector, leaving the tool-dependence of their counts unquantified, while the studies that do compare scanners use samples of tens to hund…
Single Canonical Prompts Underestimate LLM Safety's Surface-Form Sensitivity
Single Canonical Prompts Underestimate LLM Safety's Surface-Form Sensitivity arXiv:2608.02665v1 Announce Type: new Abstract: A benchmark score is a measurement instrument, yet most benchmarks read each item at a single canonical surface form. We ask whether that reading is faithful: when an item's intent is held fixed and only its meaning-preserving surface form varies, does the canonical-form score estimate model behavior well, and how much of any variation is decoding/judg…
ZK-SR117: A Chunked Zero-Knowledge Attestation Design for Aggregated Fair-Lending Metrics, with a Control Mapping toward Full SR 11-7 Coverage
ZK-SR117: A Chunked Zero-Knowledge Attestation Design for Aggregated Fair-Lending Metrics, with a Control Mapping toward Full SR 11-7 Coverage arXiv:2608.02664v1 Announce Type: new Abstract: Deploying ML models in regulated decision-making (credit underwriting, fraud detection, loan approval) requires demonstrating fairness and robustness to auditors without exposing model weights or customer data. We address this attestation problem for U.S. bank supervision under SR 11-7 a…
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure
Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure arXiv:2608.02657v1 Announce Type: new Abstract: Agentic LLMs are vulnerable to indirect prompt injection (IPI) attacks, e.g., malicious side-tasks hidden in external tool results. While many efforts have sought to address the threats, little is known about the internals of agentic LLMs when they are exposed to IPI attacks, a condition which we call IPI exposure. In this paper, we study thi…
Secure AI Watermarking Framework for IP Protection in Multi-Tenant Cloud Platforms
Secure AI Watermarking Framework for IP Protection in Multi-Tenant Cloud Platforms arXiv:2608.02656v1 Announce Type: new Abstract: The Secured data safe guard transaction with multi-tenant environments run on private-protected authenticate platforms runs by secured handed environments that emerges with the expansion of cloud-based AI services. To enhanced this secured leakage address challenges solution to protect a secure AI Watermarking system incorporating key distributed…
Micro-Segmentation Anomaly Detection in Zero-Trust Software-Defined Network Fabrics
Micro-Segmentation Anomaly Detection in Zero-Trust Software-Defined Network Fabrics arXiv:2608.02627v1 Announce Type: new Abstract: Zero Trust Architecture (ZTA) principles need rigorous network segmentation and ongoing verification to reduce implicit trust and lateral threat propagation. This paper investigates anomaly detection in software-defined networking (SDN) systems by micro-segmentation, using deep learning models to detect harmful actions that evade traditional coa…
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
An LLM agent attempts to compromise a project on GitHub
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
[$] Fedora considers conflict-of-interest policy
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Polish convenience store chain Żabka hacked through third-party account
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Oligo Raises $60 Million for Runtime Security
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.