Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,100 source documents · 4,068 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
1
Publisher text withheld
16
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
When Safety Becomes a Vulnerability: Exploiting LLM Alignment Homogeneity for Transferable Blocking in RAG
When Safety Becomes a Vulnerability: Exploiting LLM Alignment Homogeneity for Transferable Blocking in RAG arXiv:2603.03919v2 Announce Type: replace Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to blocking attacks, in which poisoned documents cause large language models (LLMs) to refuse benign queries. Existing attacks rely on adversarial suffixes or explicit instructions, which are increasingly ineffective against modern LLMs, susceptible to prompt …
AgenticRepair: Multi-Faceted Program Context Engineering for Agentic Vulnerability Repair
AgenticRepair: Multi-Faceted Program Context Engineering for Agentic Vulnerability Repair arXiv:2607.29422v1 Announce Type: cross Abstract: Automated vulnerability repair aims to reduce the time and effort required to patch security flaws from a vulnerability triage report. Recent agentic AI approaches have shown promising results in automated program repair. However, vulnerability repair demands richer program context than general bug repair - context that security engineer…
StraightDP: Geometry-Aware Differential Privacy for Rectified-Flow Transformers
StraightDP: Geometry-Aware Differential Privacy for Rectified-Flow Transformers arXiv:2607.29100v1 Announce Type: cross Abstract: Differentially private (DP) training of text-conditioned generative models suffers a utility cliff at strong privacy. We revisit this problem through the geometry of rectified flows: along the straight interpolation between noise and data, the Bayes-optimal velocity is governed to leading order at the noise end by a few class-conditional moments, …
Mind the Gap: Policy vs Reality in Post-Quantum TLS Deployment
Mind the Gap: Policy vs Reality in Post-Quantum TLS Deployment arXiv:2607.29005v1 Announce Type: cross Abstract: Post-quantum cryptography (PQC) has evolved from a long-term planning concern into an operational priority. Following NIST's standardization of PQC, governments and standard bodies published transition roadmaps outlining migration timelines, priority sectors, and deployment strategies. However, our survey of these policies reveals substantial divergence in technic…
TextCloak: Thwarting Unauthorized LLM Exploitation via RL-Driven Unlearnable Text
TextCloak: Thwarting Unauthorized LLM Exploitation via RL-Driven Unlearnable Text arXiv:2607.28862v1 Announce Type: cross Abstract: The rapid development of Large Language Models (LLMs) has led to significant advances across a wide range of language tasks, while simultaneously raising growing concerns about unauthorized data exploitation and privacy leakage. Unlearnable examples (UEs) offer a promising defense by introducing carefully designed perturbations into data such th…
CWEEP: A Lexical Static Analysis Framework for CWE Early Prevention
CWEEP: A Lexical Static Analysis Framework for CWE Early Prevention arXiv:2607.29604v1 Announce Type: new Abstract: As the hardware layer becomes a focus point for attackers, the need for improved hardware security verification techniques is more important than ever. State-of-the-art security verification techniques require significant manual effort from individuals with security expertise. Furthermore, there is no standard method to locate where the fault lies within the re…
Beyond Resilience: Antifragility in Critical Infrastructure Cybersecurity
Beyond Resilience: Antifragility in Critical Infrastructure Cybersecurity arXiv:2607.29550v1 Announce Type: new Abstract: Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient Sys…
Bending the Curve: Operational Cyber Epidemiology for Ransomware
Bending the Curve: Operational Cyber Epidemiology for Ransomware arXiv:2607.29444v1 Announce Type: new Abstract: Ransomware is often treated as a detection problem, but the most disruptive incidents behave more like outbreaks. A single foothold can spread through identities, administrative tools, and shared services while responders make time-critical decisions with incomplete visibility. This paper presents an operational cyber epidemiology framework that adapts the Suscept…
Enforcing Cryptographic Distributed-VCS Access Control with No Trust on Servers
Enforcing Cryptographic Distributed-VCS Access Control with No Trust on Servers arXiv:2607.29417v1 Announce Type: new Abstract: Version control systems (VCS), including central VCS (CVCS) and distributed VCS (DVCS), are widely adopted to manage changes to software code and various types of documents. Unlike CVCS, where entities obtain data from a central server, each entity in DVCS stores the entire repository and shares it independently. In VCS, existing access control sche…
On fair and realistic performance evaluations for graph-based lateral movement detectors
On fair and realistic performance evaluations for graph-based lateral movement detectors arXiv:2607.29390v1 Announce Type: new Abstract: Research on lateral movement detection has made significant progress in recent years, spurred by the widespread availability of benchmark datasets that make evaluating detectors practical. However, the exact way in which these benchmark datasets are used varies across the literature: both the preprocessing applied before feeding the data to…
On the Resilience of 5G NR Against Jamming
On the Resilience of 5G NR Against Jamming arXiv:2607.29384v1 Announce Type: new Abstract: With the increasing use of 5G networks in availability-critical systems, including industrial networks and critical infrastructure, a comprehensive understanding of their resilience to cellular jamming has become imperative. However, research so far has focused on isolated evaluations under fixed 5G physical-layer configurations, making it difficult to perform sound comparisons, for ex…
JUNO: Aggregated Vector Consensus for Optimal Asynchronous Common Subset
JUNO: Aggregated Vector Consensus for Optimal Asynchronous Common Subset arXiv:2607.29244v1 Announce Type: new Abstract: In this paper, we propose \textit{aggregated vector consensus}, a new vector consensus primitive designed for asynchronous networks. The primitive achieves agreement by outputting a vector of values aggregated from independent process inputs. We then introduce \textsc{Juno}, an asynchronous common subset (ACS) protocol that fully implements our aggregated …
MOSAIC: Masked Outsourcing of Secure AI Computations
MOSAIC: Masked Outsourcing of Secure AI Computations arXiv:2607.29221v1 Announce Type: new Abstract: We address the challenge of securely and efficiently outsourcing AI computations from a trusted but computationally weak client to an untrusted but powerful server, in the setting where the client holds both the input and the model, and the server must learn neither. We present MOSAIC, whose core is a novel matrix-multiplication masking protocol that scales to far larger matr…
Alignment Is Local: A Paired Diagnostic for GUI Agents under User-Side Persuasion
Alignment Is Local: A Paired Diagnostic for GUI Agents under User-Side Persuasion arXiv:2607.29199v1 Announce Type: new Abstract: Trustworthy deployment of GUI agents in ubiquitous computing settings requires alignment that survives dynamic interaction and precise threat conditions, not just single-turn refusal of explicit harmful requests. We argue that prompt-level alignment, the dominant lightweight defense in current mobile agents, is a local phenomenon: it works reliabl…
Memory Provenance Laundering in LLM Agents: A Non-Amplification Firewall for Persistent Memory
Memory Provenance Laundering in LLM Agents: A Non-Amplification Firewall for Persistent Memory arXiv:2607.29167v1 Announce Type: new Abstract: Long-term memory lets large language model(LLM) agents reuse prior preferences and work flows, but it also turns untrusted observations into persistent action context. We identify memory provenance laundering: during LLM-based memory consolidation, an external observation may be rewritten as apparent user history or workflow support, …
GoldenRetriever: Non-Interactive Homomorphic Encrypted Retrieval for Privacy-Preserving RAG
GoldenRetriever: Non-Interactive Homomorphic Encrypted Retrieval for Privacy-Preserving RAG arXiv:2607.29019v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) enhances large language models by incorporating external knowledge, but existing pipelines typically operate on plaintext data, raising significant privacy concerns. Prior work on privacy-preserving retrieval leverages cryptographic techniques such as homomorphic encryption (HE) and private informatio…
MESS: Fast and Private Semantic Search on Multi-Graph HNSW
MESS: Fast and Private Semantic Search on Multi-Graph HNSW arXiv:2607.28999v1 Announce Type: new Abstract: Semantic search systems map data to a high-dimensional vector space and support retrieval of similar data via approximate nearest neighbor search. When the system is hosted by a trusted cloud provider, there is no privacy for the data or the query. Our goal is to design a system with three properties: privacy, accuracy, and efficiency. Existing works adopt either homomo…
A Biometric Sensor Network to Enable Real-Time Measurement of Individual Student Engagement in STEM Lecture Environments
A Biometric Sensor Network to Enable Real-Time Measurement of Individual Student Engagement in STEM Lecture Environments arXiv:2607.28944v1 Announce Type: new Abstract: Student engagement (SE) is a critical predictor of academic performance and retention in STEM education, yet existing measurement approaches are often intrusive, manually intensive, or unsuitable for real-time classroom use. This thesis proposes a novel $\textit{Biometric Sensor Network}$ (BSN) designed to en…
Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference
Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference arXiv:2607.28884v1 Announce Type: new Abstract: As large language models (LLMs) grow in scale and are predominantly served from remote platforms, verifying faithful inference execution becomes critical (i.e., ensuring that a provider actually executes the advertised model and computational workload rather than a tampered or downsized variant). Zero-knowledge (ZK) LLM inference …
YazSes: An Offline, Privacy-First, Cross-Platform Hold-to-Talk Voice-Dictation System
YazSes: An Offline, Privacy-First, Cross-Platform Hold-to-Talk Voice-Dictation System arXiv:2607.28878v1 Announce Type: new Abstract: Cloud voice-dictation services deliver strong accuracy but require streaming a user's speech to a remote provider, an unacceptable trade-off in privacy-sensitive professions and offline or air-gapped settings; the leading on-device alternatives are either platform-locked or aimed at expert scripting rather than plug-and-play dictation. We pres…
Partial Derandomization for Leakage-Resilient Shamir's Secret Sharing over Composite Order Fields
Partial Derandomization for Leakage-Resilient Shamir's Secret Sharing over Composite Order Fields arXiv:2607.28757v1 Announce Type: new Abstract: We make progress on the question of constructing explicit evaluation places for leakage-resilient Shamir's secret sharing, over composite order fields. Previously, Maji et al. (EUROCRYPT 2024) showed that random evaluation places yield Shamir's secret sharing over the composite order field $\mathbb{F}_{p^d}$ that is statistically s…
Blockchain Transaction Simulation Phishing
Blockchain Transaction Simulation Phishing arXiv:2607.28747v1 Announce Type: new Abstract: Cryptocurrency users have increasingly become targets of phishing and scam attacks. To mitigate these threats, leading crypto wallets (e.g., MetaMask) have introduced transaction simulation, which previews a transaction's balance changes before on-chain execution. While effective against traditional fund-draining attacks, we show that this defense can itself be exploited by a new phish…
Costs of Arbitrary Real Matrix Factorizations for Pure-DP Continual Counting
Costs of Arbitrary Real Matrix Factorizations for Pure-DP Continual Counting arXiv:2607.28703v1 Announce Type: new Abstract: Let \(T_n\) be the lower-triangular prefix-sum matrix and let \(\cfrob(T_n)\) and \(\ctwo(T_n)\) be the factorization costs that govern mean and maximum per-coordinate squared error of the Laplace matrix mechanism under pure \(\eps\)-differential privacy, for \(\eps>0\). We prove \(\cfrob(T_n),\ctwo(T_n)=\Theta\bigl((\log(n+1))^{3/2}\bigr)\) with no si…
Bridging the Gap Between PHE and FHE: A Performance and Trade-off Analysis of The Somewhat Homomorphic BGN Cryptosystem
Bridging the Gap Between PHE and FHE: A Performance and Trade-off Analysis of The Somewhat Homomorphic BGN Cryptosystem arXiv:2607.28700v1 Announce Type: new Abstract: Homomorphic encryption (HE) enables privacy-preserving data analytics, but practitioners often face a trade-off between lightweight Partially Homomorphic Encryption (PHE) and computationally dominant Fully Homomorphic Encryption (FHE). The Boneh-Goh-Nissim (BGN) cryptosystem bridges this gap as a Somewhat Homo…
Kernel prepatch 7.2-rc6
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Ruby on Rails Patches Critical Vulnerability
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Defcon's new badge is a security key you can see inside
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.