REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 7 of 21
arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Not All Refusals Are Equal: How Safety Alignment Fails Cybersecurity at Scale arXiv:2607.02714v1 Announce Type: new Abstract: There is no doubt that safety alignment is an essential step in LLM training. However, conceptually it does not distinguish between various domains and the level of potential harm of a query, which creates significant complications in the fields like cyber security, where a model should not be constrained by its safety circuits to accomplish the goals…
Read original ↗https://arxiv.org/abs/2607.02714arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
RES-DARE: Failure-Aware Expert Adaptation and Rollback-Safe Self-Repair for Intrusion Detection arXiv:2607.02687v1 Announce Type: new Abstract: Intrusion detection systems are often trained under static benchmark conditions, although deployed network environments are affected by traffic drift, sensor noise, changing workloads, and evolving attack behaviour. Under such distribution shifts, static detectors may produce confident but incorrect predictions, leading to silent and…
arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Execution Divergence Graphs:Effective Discovery of Control-Flows from Execution Traces as Fuzzing Feedback arXiv:2607.03396v1 Announce Type: new Abstract: Fuzz testing is a popular approach to the security testing of proprietary software. Efficient testing strategies rely on execution feedback to guide the input generation process, particularly when the basic blocks in the binary can be directly observed and instrumented. Unfortunately, collecting such feedback is impossible…
Read original ↗https://arxiv.org/abs/2607.03396arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
ShannonProver: Towards Automating Formal Cryptographic Proofs arXiv:2607.02847v1 Announce Type: new Abstract: Cryptographic proofs are produced at a scale that increasingly exceeds the community's ability to verify them manually. Machine-checked proofs offer a path toward scalable proof verification, but writing proof scripts for expressive proof assistants such as EasyCrypt remains a major bottleneck: even when the high-level proof plan is known, converting it into proof ta…
Read original ↗https://arxiv.org/abs/2607.02847arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
LeanDY: Type-Based and Trace-Based Symbolic Protocol Verification in Lean arXiv:2607.03406v1 Announce Type: new Abstract: Computer-aided formal verification is a widely used approach for the symbolic analysis of cryptographic protocols. However, many modern protocols rely on features that remain challenging for existing techniques. In particular, reasoning about state, time-dependent behavior, inductively defined data structures, unbounded executions, and conditional secrecy…
Read original ↗https://arxiv.org/abs/2607.03406arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents arXiv:2607.02857v1 Announce Type: new Abstract: LLM coding agents increasingly complete development tasks by issuing ordinary CLI commands. Following the Unix design, these commands cooperate through shared operating-system state: one command may write state that a later command reads. While this composition is benign and intended, it creates an overlooked exploit surface. Existing attacks and defen…
Read original ↗https://arxiv.org/abs/2607.02857arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Security Analysis for SCONE Logic Locking arXiv:2607.03288v1 Announce Type: new Abstract: SCONE [DAC'25] expands a logic locking interface with additional encoded inputs derived from the original primary inputs, and admits two realizations: a \textit{with-ES} variant, where the critical encoding stage is implemented in hardware, and a \textit{without-ES} variant, where the locked design directly exposes an encoded interface of width $n+m$. We show that both realizations are …
Read original ↗https://arxiv.org/abs/2607.03288arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
LLM-Enhanced Hierarchical Heterogeneous Graph Representation Learning for Malicious Python Package Detection arXiv:2607.03350v1 Announce Type: new Abstract: Malicious Python packages have become a major threat to software supply chain ecosystems due to the widespread adoption of open-source repositories such as PyPI. Existing learning-based detection methods struggle to capture the hierarchical organization and heterogeneous interactions among different program entities. Alt…
Read original ↗https://arxiv.org/abs/2607.03350arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
Scalable Differentially Private Data Compression via Diffusion and Stochastic Codes arXiv:2607.03392v1 Announce Type: new Abstract: The ever-increasing collection of personal data has created mounting pressure to develop technologies that protect sensitive aspects of individual identity. Differential privacy (DP) provides a principled framework with strong formal guarantees and has already achieved practical success. However, releasing high-dimensional data, such as images, …
Read original ↗https://arxiv.org/abs/2607.03392arxiv_cs_cr · tlp:amber · 7/7/2026, 4:00:00 AM
The agent creates, we validate: A Lightweight Framework for Agentic Artifact Generation arXiv:2607.02615v1 Announce Type: new Abstract: Generating structured artifacts with Large Language Models - e.g. database queries, threat framework mappings, entity schemas - is relatively straightforward; however, making them reliable enough for production deployments presents challenges. We present a lightweight framework based on a core principle: LLMs generate, we validate. This refr…
Read original ↗https://arxiv.org/abs/2607.02615arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Sign in the Air to Unlock: An Interface for authentication in Virtual and Augmented Reality Powered by Point-Voxel Cross-Attention Network arXiv:2607.01435v1 Announce Type: cross Abstract: Significant advancement of immersive technologies such as Virtual and Augmented Reality (VR/AR) and their integration into diverse aspects of modern life need authentication interfaces that are secure, intuitive, and compatible with embodied interaction. Traditional methods such as passwor…
Read original ↗https://arxiv.org/abs/2607.01435arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Unveiling the Non-Monotonic Effect of Privacy on Generalization under Byzantine Robustness arXiv:2607.01492v1 Announce Type: cross Abstract: Recent work has established a fundamental trilemma between Byzantine robustness, local differential privacy (LDP), and optimization error in distributed learning. We show that this trilemma does not universally extend to generalization error, but instead depends critically on the privacy regime. Specifically, in the high-noise regime (s…
Read original ↗https://arxiv.org/abs/2607.01492arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Black-Box Inference of LLM Architectural Properties with Restrictive API Access arXiv:2607.01313v1 Announce Type: cross Abstract: In practice, most commercial LLM providers do not publicly release details of underlying LLM architectures. However, prior work has shown that given limited API access to an LLM (namely, top-$k$ logits and/or a logit bias function), one can recover certain architectural details of an LLM, such as the hidden dimension of the feed-forward network. P…
Read original ↗https://arxiv.org/abs/2607.01313arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
SoK: A Taxonomy for Cybersecurity Incident Response Influence Factors arXiv:2607.02451v1 Announce Type: new Abstract: Cybersecurity incident response has emerged as a critical area of interest for both researchers and practitioners. The corpus of literature on cybersecurity incident response is expanding, yet a unified framework for systematically organizing the accumulated knowledge remains absent. The aspects of incident response span multiple domains, including technology…
Read original ↗https://arxiv.org/abs/2607.02451arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Janus: a Playground for User-Involved Agentic Permission Management arXiv:2607.01510v1 Announce Type: cross Abstract: AI agents that autonomously execute tool calls on a user's behalf raise pressing questions about permission management: what role could users play, and what role should they play? Despite many proposed approaches, the user's role in agentic permission management remains under explored. We introduce Janus, a playground system for implementing and evaluating us…
Read original ↗https://arxiv.org/abs/2607.01510arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Behind the Refusal: Determining Guardrail Activation via Behavioral Monitoring arXiv:2607.02121v1 Announce Type: new Abstract: As Large Language Models (LLMs) and agentic systems become integrated into real-world applications, ensuring their safety and security is critical. Guardrail systems that detect and block malicious instructions sent to and from an LLM are an essential component of AI security. However, researchers conducting black-box adversarial emulation against pr…
Read original ↗https://arxiv.org/abs/2607.02121arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Has This Checkpoint Been Abliterated? A Two-Signal Audit and Its Failure Map arXiv:2607.01854v1 Announce Type: new Abstract: Can a platform tell, before deployment, whether an open-weight checkpoint has had its refusal mechanism stripped? Runtime guards cannot: they score generations, not the artifact. We combine two cheap internal signals, a reference-anchored activation refusal-gap and a weight-recovery energy of the base-to-candidate weight difference, into a threshold-fr…
Read original ↗https://arxiv.org/abs/2607.01854arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware arXiv:2607.02357v1 Announce Type: new Abstract: LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-…
Read original ↗https://arxiv.org/abs/2607.02357arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
AgentFlow: Building Agent Dependency Graphs for Static Analysis of Agent Programs arXiv:2607.01640v1 Announce Type: cross Abstract: LLM agents are increasingly developed as source-code applications built on agent frameworks. These agent programs combine conventional host-language code with framework-defined semantics for models, prompts, tools, memory, and multi-agent orchestration logic. As a result, their behavior depends not only on traditional control and data flows, but…
Read original ↗https://arxiv.org/abs/2607.01640arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Knowledge Over Parameters: Evolving Smart Contract Vulnerability Detection arXiv:2607.01742v1 Announce Type: new Abstract: Smart contract vulnerabilities are predominantly logic bugs whose detection requires structured, step-by-step procedural knowledge of attack patterns and contract semantics. Existing LLM-based methods struggle to generate this knowledge automatically: prompt-based methods rely on manually crafted detection rules, while fine-tuning requires massive labele…
Read original ↗https://arxiv.org/abs/2607.01742arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Embedding Inference Attack arXiv:2607.01276v1 Announce Type: new Abstract: Embedding models are essential components of modern Information Retrieval (IR) systems, yet they are typically hidden behind APIs. Recent works have shown that dense IR system can lead to security vulnerabilities such as embedding inversion attacks. However, such attacks usually require that the attacker knows the embedding model for the attack to be applicable. In this paper, we study IR systems unde…
Read original ↗https://arxiv.org/abs/2607.01276arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
ElephantAgent: Contextual State Continuity in Agentic Systems arXiv:2607.01919v1 Announce Type: cross Abstract: Agentic systems enhance their capabilities by invoking external tools and maintaining persistent memory. However, these external dependencies introduce novel attack surfaces. Recent tool and memory poisoning attacks show that maliciously crafted tool descriptors and poisoned memory can covertly bias agent behavior. These threats reflect a deeper issue: the lack of …
Read original ↗https://arxiv.org/abs/2607.01919arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Pmeta-TLA: Backdoor Attacks for Speech Classification Models via Meta-Learning with Timbre Leakage Attack arXiv:2607.01702v1 Announce Type: new Abstract: Recently, speech classification methods have gained widespread adoption in intelligent gadgets. Current study indicates that backdoor attacks provide a substantial security concern to these models, underscoring the pressing necessity to investigate additional potential attack techniques to expose and prevent such risks. Thi…
Read original ↗https://arxiv.org/abs/2607.01702arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design arXiv:2607.01711v1 Announce Type: new Abstract: Modern systems use format-, protocol-, and signature-based mechanisms before accepting artifacts across trust boundaries. These mechanisms are necessary: they show that an artifact is well formed, protocol-compliant, or properly authenticated. They do not, however, show that the artifact satisfies the semantic security properties re…
Read original ↗https://arxiv.org/abs/2607.01711arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Overthink-Triggered Slowdown Attacks on LVLM-Based Robotic Systems arXiv:2607.01518v1 Announce Type: new Abstract: Large Vision-Language Models (LVLMs) have been increasingly integrated into robotic systems. However, these models may exhibit overthinking behaviors, where they generate excessively long reasoning traces, incurring an excessive inference time. This overthinking behavior poses a serious risk to robotic systems, as the adversary can deliberately trigger overthink…
Read original ↗https://arxiv.org/abs/2607.01518arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
LIB-TRAP: Standard Cell Library Hardware Trojan Risk Assessment and Prevention arXiv:2607.01526v1 Announce Type: new Abstract: Vulnerabilities inherent to the fabless semiconductor manufacturing model have significantly increased the risk of malicious Hardware Trojan (HT) insertion, posing severe threats to hardware security. Several HT mitigation and detection strategies have been developed, and existing works explore the insertion of HTs in the space between standard cells…
Read original ↗https://arxiv.org/abs/2607.01526arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification arXiv:2607.01668v1 Announce Type: new Abstract: Hardware security verification is a multi-stage process in which engineers must navigate complex design analyses, threat considerations, and verification strategies. They often need security-focused guidance, yet current verification environments provide little structured support for such assistance. Although conversational AI could offer such o…
Read original ↗https://arxiv.org/abs/2607.01668arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Hamm-Grams: An Algorithm for Mining Regular Expressions of Bytes arXiv:2607.01445v1 Announce Type: new Abstract: Malware poses a critical and ever-evolving threat, and robust and effective systems for detecting and classifying malware are of essential importance. $n$-grams features are among the common static features used in effective machine learning systems for malware, but these features are inherently brittle. We propose an algorithm for constructing more robust feature…
Read original ↗https://arxiv.org/abs/2607.01445arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Resilient Liquid Democracy: Mitigating Voting Power Imbalances via Secure Delegation Networks arXiv:2607.01730v1 Announce Type: new Abstract: Liquid democracy promises to improve collective decision-making by allowing voters to vote directly, delegate their voting power to trusted participants, or combine both approaches through fallback mechanisms. However, existing deployments typically rely on transparent delegation, which exposes voters to popularity-driven herding, make…
Read original ↗https://arxiv.org/abs/2607.01730arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
An alternative approach towards attacks against fully-split PLWE instances arXiv:2607.01340v1 Announce Type: new Abstract: In the present work we address some key questions regarding the generalization of root-based attacks presented in a recent work by the authors. In particular, we analyze potential root-based attacks extensions via the construction of explicit isomorphisms from vulnerable instances, and provide a formal proof that this approach will not yield any new vuln…
Read original ↗https://arxiv.org/abs/2607.01340arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Cognitive Firewall: A Proactive, Zero-Trust, Multi-Gate Framework for LLM Safety arXiv:2607.01277v1 Announce Type: new Abstract: Large language models (LLMs) can be induced to produce harmful content through multi turn strategies in which no single user message appears clearly unsafe. Existing runtime safeguards commonly evaluate prompts or responses as isolated messages, which limits their ability to recover ac-cumulated intent, verify asserted authority, or detect harmful …
Read original ↗https://arxiv.org/abs/2607.01277arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Beyond Gradient-Based Attacks: Adversarial Robustness and Explainability Stability in Cybersecurity Classifiers arXiv:2607.01679v1 Announce Type: new Abstract: Adversarial attacks on cybersecurity classifiers pose a dual threat: degrading predictions and destabilising the SHAP-based explanations that security analysts rely on to understand and triage alerts. We extend our prior MLP conference study to Random Forest and XGBoost across four tabular security datasets (phishing …
Read original ↗https://arxiv.org/abs/2607.01679arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Generative AI and Federated Learning for Intrusion Detection Systems: A Survey arXiv:2607.01305v1 Announce Type: new Abstract: Intrusion Detection Systems (IDSs) are essential for monitoring network traffic and identifying malicious activities in modern cyber-physical, Internet of Things (IoT), enterprise, and distributed network environments. However, developing reliable IDS models remains challenging because attack behaviors evolve over time, realistic datasets are difficu…
Read original ↗https://arxiv.org/abs/2607.01305arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
Chameleon: Recovering Cyber-Physical Systems from Memory Corruption Attacks via ML Surrogates arXiv:2607.01356v1 Announce Type: new Abstract: Cyber-physical systems (CPSs) are increasingly deployed in every aspect of our lives and can be compromised through memory corruption vulnerabilities, allowing attackers to hijack the control flow and take over the system. Existing techniques mostly focus on detecting such attacks but respond by terminating or halting execution upon at…
Read original ↗https://arxiv.org/abs/2607.01356arxiv_cs_cr · tlp:amber · 7/3/2026, 4:00:00 AM
From Forgeries to Foundation Models: A Systematic Survey of Identity Document Attack and Detection arXiv:2607.01442v1 Announce Type: new Abstract: Identity document forgery has undergone a fundamental capability shift: generative AI tools now enable high-fidelity document synthesis and field-level manipulation with minimal technical expertise, while detection methods remain constrained by benchmarks that do not reflect this threat. The resulting attack surface spans physical…
Read original ↗https://arxiv.org/abs/2607.01442arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Safe Alone, Unsafe Together: Safeguarding Against Implicit Toxicity When Benign Images Combine arXiv:2607.00576v1 Announce Type: cross Abstract: Multi-image content has become an increasingly prevalent form of visual communication in social media, giving rise to a new safety issue, multi-image implicit toxicity (MIIT), where each image appears benign in isolation, but harmful semantics emerge when the images are interpreted jointly. MIIT is particularly challenging for exist…
Read original ↗https://arxiv.org/abs/2607.00576arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
High-Performance NTT Accelerators for PQC leveraging Unified Redundant Arithmetic and Fine-Tuned Microarchitecture arXiv:2607.00621v1 Announce Type: cross Abstract: Post-quantum cryptography and privacy-preserving technologies are expected to play a central role in future secure communication systems. Lattice-based PQC schemes such as ML-KEM (CRYSTALS-Kyber) and ML-DSA (CRYSTALS-Dilithium) rely heavily on large-degree polynomial arithmetic, making the Number Theoretic Transf…
Read original ↗https://arxiv.org/abs/2607.00621arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
A Non-Line-of-Sight, Multi-Modality-based Side-Channel IP Theft Attack on Additive Manufacturing Using Dual Smartphones arXiv:2607.00186v1 Announce Type: new Abstract: Additive Manufacturing (AM) has revolutionized major sectors, including aerospace, automotive, and healthcare, by enabling adjustable production. As the usage of AM increases, so does the risk of Intellectual Property (IP) leakage during the printing process due to unintended side-channel emissions. Current st…
Read original ↗https://arxiv.org/abs/2607.00186arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
The Rise and Fall of Google's Privacy Sandbox arXiv:2607.00693v1 Announce Type: new Abstract: On October 17th, 2025, Google announced the retirement of most Privacy Sandbox APIs, concluding nearly five years of experimentation with its alternative to privacy-invasive data collection on the Web. Designed to balance privacy with advertising functionality and cross-site tracking, the initiative faced repeated redesigns and limited ecosystem support. In this work, we present the…
Read original ↗https://arxiv.org/abs/2607.00693arxiv_cs_cr · tlp:amber · 7/2/2026, 4:00:00 AM
Cross-Domain Generalization Failure in Lightweight Intrusion Detection Models for IIoT Networks arXiv:2607.00553v1 Announce Type: new Abstract: Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment. Most reported results evaluate these models only within their training network, leaving behavior on unseen networks unverified. This …
Read original ↗https://arxiv.org/abs/2607.00553