Loading the current evidence view. Navigation and account controls remain available.
Intelligence reports
Loading the current evidence view. Navigation and account controls remain available.
Ordering reports and their extracted indicators.
Applying the current filters and ordering.
Forensia intelligence desk · 4,096 source documents · 4,064 stories
Live reporting, advisories and research arranged by editorial readiness. Thin sources stay visible, but they are clearly marked instead of being presented as complete analysis.
On this page
40 documents
Briefs ready now
40
Multi-source clusters
0
Publisher text withheld
15
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
PaperCut Releases Emergency Patch for Exploited Zero-Day
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
SecureDrive-FL: Joint Differential Privacy and Gradient-Aware Selective Homomorphic Encryption for Federated Driver Monitoring
arXiv:2608.27108v1 Announce Type: new Abstract: Federated Learning (FL) enables privacy-aware distributed training, yet gradient updates remain exploitable: Man-in-the-Middle (MitM) interception exposes updates in transit, while model poisoning corrupts global convergence. We first introduce GASHE (Gradient-Aware Selective Homomorphic Encryption), a novel selective encryption strategy that dynamically identifies and encrypts only the gradient components exceeding a DP-calibra…
The Framing Gap: Indirect Prompt-Injection Exfiltration Defeats Surface-Level Defenses in Tool-Using Agents
arXiv:2608.27092v1 Announce Type: new Abstract: A tool-using LLM agent that reads attacker-controlled web content while holding a secret faces indirect prompt injection: the content may make it exfiltrate the secret. In a safe synthetic lab (canary secret, mock tools, matched clean-vs-poisoned metric) we report the framing gap: across six models, ten overt injection classes are refused (gpt-4o 0%), but reframing the identical leak as a mandatory integrity signature, config fi…
Cyber-Electromagnetic Anomaly Detection Through Time-Series Analysis
arXiv:2608.27043v1 Announce Type: new Abstract: Military operations benefit from the coordination between kinetic and non-kinetic domains. In particular, the coordination of cyber operations and electromagnetic warfare has become increasingly relevant for gaining operational advantage. This coordination is also relevant for Cyber Situational Awareness (CSA), where the Observe-Orient-Decide-Act (OODA) loop requires monitoring and interpreting evidence from heterogeneous source…
Neighborhood Watch: Privacy Risks in Seeded Local Combination Synthetic Data
arXiv:2608.27037v1 Announce Type: new Abstract: Synthetic data is seen as a promising solution for sharing data in sensitive contexts. However, recent work on privacy attacks have shown that there are still significant residual risks, especially for synthetic data generations methods that are not based on formal approaches such as differential privacy. In this paper, we investigate the privacy risks associated with local combination approaches for generating synthetic data in…
The Guard That Cried Wolf: How Scary Words Make Agent Guardrails Refuse Legitimate Actions
arXiv:2608.27009v1 Announce Type: new Abstract: Agent guardrails are checks that approve or refuse each action before an LLM executes it. Sometimes they refuse requests that are genuinely safe. This over-safety blocks deployment when a guardrail refuses an authorized task. Evaluating over-safety is hard: at the boundary an authorized action resembles an unauthorized one, and the safe-versus-unsafe label is a choice of authorization policy, not fixed by the action alone. We ar…
Metamorphism: A mathematical challenge for antivirus technology
arXiv:2608.27007v1 Announce Type: new Abstract: Metamorphic viruses, currently the most advanced computer viruses in the wild, have the unique ability of mutating their own code virtually into infinitely many highly dissimilar copies of themselves that nevertheless have the same functionality. This ability -- metamorphism -- together with other advanced ob- fuscation techniques makes these computer viruses virtually undetectable by the antivirus software available in the mark…
A Catalog of User Authentication Patterns
arXiv:2608.26955v1 Announce Type: new Abstract: Security patterns are intended to support the design and development of secure software systems. However, although established catalogs of security patterns exist, their practical application remains limited. In particular, despite these catalogs, concrete patterns for common security controls such as user authentication (authentication for short) are lacking. This paper aims to make an initial contribution toward closing this g…
PLCBench: Can Autonomous LLM Agents Turn PLC Access into Sustained Physical Impact?
arXiv:2608.26882v1 Announce Type: new Abstract: Industrial control systems (ICSs) rely on programmable logic controllers (PLCs) to connect networked computation with physical control. Tool-using large language model (LLM) agents represent an emerging attack threat: can an autonomous agent convert a network-reachable PLC into sustained adverse physical impact? However, existing evaluations focus on digital tasks or individual stages of PLC testing. In ICSs, evaluations that st…
SysComb: Fine-Grained Transparent System Call Filtering for Attack Surface Reduction
arXiv:2608.26871v1 Announce Type: new Abstract: Restricting the system calls available to applications shrinks the kernel's attack surface and greatly mitigates the impact of compromised programs. Recent approaches showcase techniques to generate system call filters, however, all existing solutions require either kernel or application modifications to activate them at runtime. This is intrusive, error-prone, and often impractical, especially when the code is maintained by ext…
Information Flow Control in Off-Chain Components
arXiv:2608.26858v1 Announce Type: new Abstract: This paper develops a model of a smart-contract language for a blockchain architecture with off-chain components. Off-chain components are pieces of smart contracts that execute at designated locations outside of the network of blockchain nodes, but remain synchronised with the on-chain contract state. They react to changes to the on-chain state, but may also notify the on-chain component about events in the world, e.g. stock pr…
Are We Shooting Flies with Cannons? Trade-off Analysis for AI-based 5G Intrusion Detection
arXiv:2608.26844v1 Announce Type: new Abstract: The increasing adoption of Artificial Intelligence (AI) in network intrusion detection raises the question of whether complex and computationally expensive models are justified for this task. In this work, we investigate the trade-off between detection performance and computational cost for intrusion detection in 5G network telemetry. We compare traditional machine learning (ML) models, including XGBoost as a representative of t…
When Relationships Break: Interpreting Network Traffic Anomalies via Dependency Violations
arXiv:2608.26831v1 Announce Type: new Abstract: Current research on security monitoring is increasingly focusing on machine-learning-based approaches, but caveats remain. In addition to huge computational overhead, one concern is the lack of insights into "why" alerts are raised. Existing interpretability approaches rely on feature attribution methods that ignore dependencies among features or on causal modeling that requires extensive domain knowledge or computational resour…
Thresholding Post-Quantum Signatures
arXiv:2608.26792v1 Announce Type: new Abstract: Threshold signature schemes distribute the signing process among $T$ parties out of $N$. They enable a variety of applications and their research is also motivated by a recent NIST call. However, applications are dominated by pre-quantum signatures, which are more efficient but not secure in the post-quantum setting. This paper investigates existing post-quantum signatures, based on a variety of paradigms: lattice problems, one-…
A Hybrid Post-Quantum Encryption Architecture with Self-Hosted Key Management for SME Cloud Data Protection
arXiv:2608.26777v1 Announce Type: new Abstract: Harvesting ciphertext from cloud storage needs no quantum computer; decrypting it later does. That gap is the harvest-now-decrypt-later exposure: anything protected by RSA or ECDH today that must stay secret for decades is already compromised. Small and medium-sized enterprises are least able to respond: they neither run the infrastructure on which their data sits on nor employ a cryptographer. Bespoke migration suits firms with…
Daydreaming: Stealing Hidden Agent Skills through Black-Box Task Interaction
arXiv:2608.26733v1 Announce Type: new Abstract: Agent skills bundle instructions, reference data, and executable helpers that let a general agent perform specialized tasks. Hosted providers can keep these files secret while selling access to task results, making the skill itself a valuable target. Existing disclosure defenses can block requests that ask for the skill or reproduce its text, but they cannot block customers from submitting the ordinary tasks the service is built…
KubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule Inference
arXiv:2608.26699v1 Announce Type: new Abstract: As the most widely used container orchestration platform, Kubernetes provides flexible privilege configuration by allowing developers to manage Linux capabilities via manifest files. However, developers rely on default settings or coarse-grained security contexts in practice, violating the principle of least privilege and enlarging the attack surface of containerized workloads. Existing studies either detect vulnerable patterns…
Beyond Vector Hiding: Breaking and Mitigating Shared-Direction Weight Obfuscation in TEE-Offloaded Large Language Models
arXiv:2608.26651v1 Announce Type: new Abstract: Trusted Execution Environment (TEE)-shielded partitioning of Large Language Models (LLMs) accelerates on-device inference by offloading obfuscated linear layers to an untrusted accelerator while retaining only a small correction inside the TEE. However, earlier lightweight obfuscation schemes preserved weight-vector directions and were broken by ArrowMatch. To defend against this attack, ArrowCloak injects scalar multiples of th…
Unsaid, Unsafe? Implicit Security Obligations in LLM-Based RTL Code Generation
arXiv:2608.26588v1 Announce Type: new Abstract: Large Language Models (LLMs) generate register-transfer-level (RTL) code with rapidly improving functional correctness. Security of LLM-generated code, however, has been studied mainly for software, where flaws can still be patched after deployment. Insecure RTL offers no such remedy once taped out into silicon. We construct SECRTL-GEN, a multi-language resource-access security benchmark grounded in real SoC IP: 392 tasks over f…
IoMT-SecAlarmBench: A Counterfactual Benchmark for Integrity Attacks in IoMT
arXiv:2608.26416v1 Announce Type: new Abstract: The Internet of Medical Things (IoMT) combines clinical physiological data with cyber-system information, creating challenges in determining whether an abnormal reading reflects a genuine physiological event, a device fault, or a cyber-attack within the expected physiological range. Answering this requires counterfactual ground truth, which no existing dataset provides. We present IoMT-SecAlarmBench, a semi-synthetic benchmark t…
SILK: Closing the Time-of-Check-to-Time-of-Use Gap in RoT-Protected AI Systems
arXiv:2608.26402v1 Announce Type: new Abstract: Root-of-trust (RoT) authentication verifies a DNN model at load time, but weights may subsequently traverse DRAM, DMA, interconnect, and prefetch paths before reaching the compute engine. Post-verification tampering along this path can therefore alter the weights actually consumed while leaving the authenticated model image unchanged, creating a time-of-check-to-time-of-use (TOCTOU) integrity gap. We present SILK (Streaming Inli…
Improving the Robustness of the XRP Ledger Network via Edge Augmentation Strategies
arXiv:2608.26380v1 Announce Type: new Abstract: The XRP Ledger allows its network participants to select a set of trusted peers within the network (i.e., the Unique Node List (UNL)) and communicate with them to reach consensus on which transactions should be included in the next ledger state. However, its consensus protocol requires significant overlap among participants' UNLs, along with a high agreement threshold among the nodes within each UNL (e.g., 80\%). Consequently, a…
PRISM: Lightweight Enclave Isolation with Prismatic Capabilities
arXiv:2608.26367v1 Announce Type: new Abstract: Trusted execution environments (TEEs) protect sensitive code and data from external interference, but lack inherent memory safety. CHERI can enforce spatial memory safety at the object level. Attempts to establish a TEE using CHERI primitives suffer from (1) expensive capability revocation operations, (2) need to rely on the host operating system (OS) to support provenance tracking and physical memory protection, (3) expensive d…
FRESCO: Complete and Scalable Temporal Safety for CHERI Application Processors
arXiv:2608.26353v1 Announce Type: new Abstract: CHERI provides hardware-enforced spatial memory safety. While prior work extends it with heap temporal safety, stack use-after-return remains unaddressed. Existing defenses fall short: compiler analysis reliably catches only references that escape as function return values, while dynamic sanitizers impose overheads that preclude production deployment. We present FRESCO, built on the principle that a stack capability must not out…
How Do LLM Agents Actually Get the Flag? Trace-Level Provenance for Agentic Offensive Security Evaluation
arXiv:2608.26237v1 Announce Type: new Abstract: Capture-the-Flag (CTF) benchmarks are widely used to assess the offensive security capabilities of autonomous language-model agents. Evaluations rely on shallow binary judgments or aggregate scores, overlooking the agent's trajectory to the flag. Consequently actual exploitation is conflated with direct flag exposure, memorized recall, external lookup, guessing, and unsupported claims, potentially overstating the agent's cyberse…
ADeptS-Bench: Measuring the Trustworthiness of Computer Use Agents Across Devices
arXiv:2608.26204v1 Announce Type: new Abstract: Computer Use Agents (CUAs) are increasingly deployed to navigate mobile and desktop applications on behalf of users, yet no benchmark comprehensively evaluates whether they can safely interact with visual interfaces while handling ambiguous instructions. We introduce ADeptS-Bench, a dual-stream trustworthiness benchmark, grounded in the ADEPTS capability framework and general population user studies. The Safety stream provides p…
Mantra - Rekt
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
The Open ASR Leaderboard Adds Its First Global South Language
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
White House bans foreign-made equipment for power generation over cyber backdoor concerns
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
What’s new in Microsoft Security: August 2026
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Finland appeals court revives case against Eagle S Officers over cable breaks
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
An evidence-built Forensia brief is ready now; publisher prose remains at the original source.
story desk
clustered evidenceWatchGuard Patches Critical Vulnerabilities
developing · new
Microsoft Rolls Out 22 Fresh Security Patches
source only · new
Google Patches 6th Chrome Zero-Day of 2026
developing · new
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
developing · new
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
source only · new
filter by source
sharing classification
TLP describes sharing sensitivity, not copyright permission. Reader text is limited to source-provided descriptive material; original reporting stays with its publisher.