REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
825 reports · page 9 of 21
arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH Deception arXiv:2606.27990v1 Announce Type: new Abstract: LLM-based SSH honeypots can generate believable interactions, but evaluations indicate they remain somewhat identifiable to determined attackers, indicating the need for a better scaffolding. We present a new LLM-based honeypot design that uses a multi-agent, multi-LLM architecture to address the limitations of the previous shelLM LLM honeypot. Our honeypot, …
Read original ↗https://arxiv.org/abs/2606.27990arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Halt Fast! Early Stopping for Certified Robustness arXiv:2606.27694v1 Announce Type: cross Abstract: Randomized Smoothing (RS) provides rigorous robustness guarantees for neural networks without architectural constraints, yet its adoption is limited by extreme computational costs. Standard RS requires tens of thousands of model evaluations per input and forces practitioners to commit to fixed sample sizes a priori. In this work, we present a novel meta-learning framework for…
arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots arXiv:2606.28006v1 Announce Type: new Abstract: Cyber deception research has focused on improving honeypot deception capabilities to increase attacker engagement and extend their interactions to collect more and better intelligence. For SSH honeypots, this relies on the assumption that attackers log in, open a shell, and type. We tested whether this still held by deploying eleven SSH honeypots that serve…
Read original ↗https://arxiv.org/abs/2606.28006arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Agentic AI-Powered Re-Identification: An Emerging, Scalable Threat to Mobility Microdata Privacy arXiv:2606.27936v1 Announce Type: new Abstract: The widespread collection of fine-grained location data by commercial data brokers creates a re-identification risk that is not widely recognised by the public. While prior research has established that mobility traces are highly unique and that individuals can, in principle, be identified from a handful of spatio-temporal points, s…
Read original ↗https://arxiv.org/abs/2606.27936arxiv_cs_cr · tlp:amber · 6/29/2026, 4:00:00 AM
Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK arXiv:2606.27966v1 Announce Type: new Abstract: Cyber deception research often assumes that a decoy can be placed wherever there is attacker behavior. This work tests that assumption across MITRE ATT&CK v18.1. We introduce a four-criterion rubric for infrastructure deception and apply it to all 250 ATT&CK techniques. The rubric evaluates whether a defender-controlled decoy can be placed, wheth…
Read original ↗https://arxiv.org/abs/2606.27966arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Chai: Agentic Discovery of Cryptographic Misuse Vulnerabilities arXiv:2606.26933v1 Announce Type: new Abstract: AI-assisted vulnerability discovery has proven effective for bug classes like memory safety, where instrumentation confirms memory violations and efficiently filters false positives. Many dangerous vulnerability classes, such as cryptographic misuse, however, lack any comparable instrumentation. In this work, we present Chai, an AI-based system that discovers and v…
Read original ↗https://arxiv.org/abs/2606.26933arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Adversarial Diffusion Across Modalities: A Fusion Survey of Attacks, Defenses, and Evaluation for Text, Vision, and Vision-Language Models arXiv:2606.26566v1 Announce Type: new Abstract: Adversarial evaluation of AI systems has matured along four largely disconnected tracks: diffusion-based attacks on text and large language models (LLMs), diffusion-based attacks on image classifiers, jailbreak pipelines against vision-language models, and diffusion-based input purification …
Read original ↗https://arxiv.org/abs/2606.26566arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
TESLA-for-5G: Broadcast Authentication for 5G Networks Using TESLA arXiv:2606.26528v1 Announce Type: new Abstract: 5G base stations broadcast unauthenticated system information (SI) that every user equipment (UE) reads during cell selection. This enables attackers to broadcast forged SI from a fake base station (FBS), deceiving UEs into camping on it. Prior approaches require UEs to authenticate System Information Block 1 (SIB1) using digital signatures. This necessitates co…
Read original ↗https://arxiv.org/abs/2606.26528arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
SpikeTimer: Exploring Active Copyright Protection in Spiking Neural Networks via Temporal Backdoor Regularization arXiv:2606.26841v1 Announce Type: new Abstract: Spiking Neural Networks (SNN) have emerged as a revolutionary paradigm compared to traditional Deep Neural Networks (DNN) in energy-efficient computing, showcasing exceptional capabilities in processing event-driven sensory data for real-time applications like robotics and edge AI systems. However, unlike extensive …
Read original ↗https://arxiv.org/abs/2606.26841arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Fortress and Gatekeeper: Theorizing Transitive Trust in Third-Party Cybersecurity Risk Governance arXiv:2606.26866v1 Announce Type: new Abstract: Third-party vendors, such as analytics platforms, cloud services, identity providers, and software suppliers, are increasingly embedded in digital service delivery. While these arrangements enable scale and specialization, they also move customer data and security-relevant practices into environments that customers rarely see, sele…
Read original ↗https://arxiv.org/abs/2606.26866arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
The Fungible Reserve Standard: A Deterministic Framework for Encoding Carrying Costs in Asset-Backed Tokens arXiv:2606.26704v1 Announce Type: new Abstract: The tokenization of real-world assets (RWAs) has emerged as a transformative application of blockchain technology, with market projections estimating trillions of dollars in tokenized assets within the coming decade. However, a fundamental challenge remains unaddressed: physical assets such as precious metals, stored comm…
Read original ↗https://arxiv.org/abs/2606.26704arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
DroidBreaker: Practical and Functional Problem-Space Attacks on Machine-Learning Android Malware Detectors arXiv:2606.26707v1 Announce Type: new Abstract: Adversarial APKs are Android applications modified in the problem space to evade machine-learning malware detectors. In this work, we first show that, despite claims, existing problem-space attacks remain largely impractical. Most techniques leverage software transplantation to inject entire benign modules, introducing man…
Read original ↗https://arxiv.org/abs/2606.26707arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
DKVE: Decentralized Key Validation for End-to-End Encrypted Messaging arXiv:2606.26486v1 Announce Type: new Abstract: End-to-end encrypted messaging systems depend on authentic public key distribution to prevent man-in-the-middle (MitM) attacks. Current solutions present a stark trade-off: out-of-band (OOB) verification provides strong security but lacks scalability for large contact lists, while key transparency (KT) systems enable automated verification at high storage cos…
Read original ↗https://arxiv.org/abs/2606.26486arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents arXiv:2606.26479v1 Announce Type: new Abstract: Recent work (2024 to 2026) has converged on a strategy for defending tool-using LLM agents against indirect prompt injection: rather than training the model to refuse malicious instructions, enforce security outside the model with a deterministic policy that mediates the agent's actions. Systems such as CaMeL, FIDES, Progent, RTBAS, and FORGE rea…
Read original ↗https://arxiv.org/abs/2606.26479arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
VIGIL: Runtime Enforcement of Behavioral Specifications in AI Agent Skills arXiv:2606.26524v1 Announce Type: new Abstract: Agentic systems increasingly act through third-party skills, allowing model-generated decisions to affect files, communication channels, and cyber-physical devices. These skills often include natural-language specifications that define access permissions, disclosure limits, execution privileges, and required preconditions. Although such specifications de…
Read original ↗https://arxiv.org/abs/2606.26524arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
What Browsers Do in the Shaders: A Measurement Study of WebGPU Privacy arXiv:2606.26412v1 Announce Type: new Abstract: WebGPU lets ordinary web pages run GPU workloads through a validated programming model. Validation protects memory safety, but shared browser, driver, OS, and GPU state can still expose privacy-relevant signals. We present WGPULens, a framework for measuring those signals across controlled scenarios, browser-native co-residency, a participant field study, pu…
Read original ↗https://arxiv.org/abs/2606.26412arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Lessons from the Adoption and Deprecation of the Privacy Sandbox Web APIs arXiv:2606.26390v1 Announce Type: new Abstract: While several web actors have been trying to reduce web tracking for years, it remains unclear how to achieve both desirable levels of utility and privacy. In 2019, Google launched the Privacy Sandbox initiative to balance that trade-off and find privacy alternatives to common use cases such as advertising. Yet, in late 2025, Google canceled the project a…
Read original ↗https://arxiv.org/abs/2606.26390arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Verifying Intent and Harm: A Unified Defense Against LLM-Generated Threats arXiv:2606.26377v1 Announce Type: new Abstract: Large language models (LLMs) are increasingly deployed in interactive applications, yet they remain vulnerable to adversarial interactions that induce harmful, deceptive, or policy-violating outputs. Existing defenses typically analyze either user prompts or generated outputs, but not both. However, many real-world attacks exploit a separation between ad…
Read original ↗https://arxiv.org/abs/2606.26377arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Hybrid privacy-aware semantic search: SVD-truncated document geometry and CKKS-encrypted query reranking under a restricted threat model arXiv:2606.26373v1 Announce Type: new Abstract: Dense embeddings power semantic search and retrieval-augmented generation, but embedding-inversion attacks can reconstruct source text from a vector: when a vector database leaks, the documents behind it leak too. The textbook defences are extremes - encrypting the whole search homomorphically…
Read original ↗https://arxiv.org/abs/2606.26373arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
TGHE: Template-based Graph Homomorphic Encryption for Privacy-Preserving GNN Inference in Edge-Cloud Systems arXiv:2606.26664v1 Announce Type: new Abstract: Existing homomorphic encryption (HE)-based GNN systems adopt a graph-centric paradigm that couples per-query cost to global graph size, limiting evaluations to at most ~20k nodes and making them incompatible with dynamic, large-scale financial graphs. We propose TGHE (Template-based Graph Homomorphic Encryption), an ego-…
Read original ↗https://arxiv.org/abs/2606.26664arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild arXiv:2606.26291v1 Announce Type: new Abstract: We measure an automation-based supply chain campaign in the Go ecosystem. The attackers repackage legitimate Go modules under attacker-controlled owners, and embed them with obfuscated code for an import-triggered downloader. Our results come from two complementary analyses: a) a manual search on GitHub across 2,113 repositories and b) a large-scale scan of …
Read original ↗https://arxiv.org/abs/2606.26291arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
MergeLLL: A Hierarchical Divide-and-Conquer Framework for LLL-Based Lattice Reduction arXiv:2606.26784v1 Announce Type: new Abstract: Lattice basis reduction algorithms have various applications in computational number theory and lattice-based cryptography, but their complexity increases rapidly with the dimension. Motivated by the divide-and-conquer strategy of merge sort and incorporating PotLLL-style deep insertions during recombination, MergeLLL is proposed. In this fram…
Read original ↗https://arxiv.org/abs/2606.26784arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
TEMPO-Diffusion: Temporally Exposed Malicious Poisoning of Diffusion Models arXiv:2606.26285v1 Announce Type: new Abstract: Noise-based backdoor attacks on diffusion models typically rely on input-time trigger injection, untargeted activation, and out-of-distribution target generation. Such assumptions reduce both the stealthiness and the practical relevance of these attacks. In this work, we present TEMPO-Diffusion, a targeted backdoor framework that localizes the malicious…
Read original ↗https://arxiv.org/abs/2606.26285arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Expecting (Targeted Ads)? Network Analysis of User Health Data Leakage in Fertility Tracking Apps arXiv:2606.26276v1 Announce Type: new Abstract: While human factors in the privacy of fertility tracking apps -- health trackers that record user's menstrual or pregnancy data -- has been the subject of extensive study, little attention has been paid to the technical aspects of apps' data handling practices. We conduct a network-based measurement study of a corpus of 20 Android …
Read original ↗https://arxiv.org/abs/2606.26276arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
CyberChainBench: Can AI Agents Secure Smart Contracts Against Real-World On-Chain Vulnerabilities? arXiv:2606.26216v1 Announce Type: new Abstract: We present CyberChainBench, a benchmark for evaluating LLM-based agents on smart contract security across three complementary tasks: vulnerability detection, exploit generation, and patch synthesis. Built from 541 real-world exploit incidents from DeFiHackLabs spanning 9 EVM chains, the benchmark provides end-to-end on-chain evalu…
Read original ↗https://arxiv.org/abs/2606.26216arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Data Facts: A Metadata Schema for Structured Data Exchange in the NANDini Multi-Agent Ecosystem arXiv:2606.26211v1 Announce Type: new Abstract: NANDini (Networked Agents Natural Distillation of Interconnected Nodal Intelligence) envisions an automated ecosystem where intelligent agents independently create, process, and exchange data to drive decisions at scale. Realizing this vision requires infrastructure beyond agent discovery and communication: agents must be able to adv…
Read original ↗https://arxiv.org/abs/2606.26211arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
MIRAGE: Protecting against Malicious Image Editing via False Moderation arXiv:2606.26199v1 Announce Type: new Abstract: The proliferation of AI-powered image editing systems raises serious concerns because it allows personal images to be arbitrarily manipulated at scale, with minimal effort, and a lower barrier to entry. Prior work on image immunization adds imperceptible perturbations to an image to protect against unauthorized manipulations. However, these methods usually …
Read original ↗https://arxiv.org/abs/2606.26199arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents arXiv:2606.26627v1 Announce Type: new Abstract: Large language model agents increasingly query databases, search document collections, call external APIs, remember past interactions, and act on a user's behalf. As they move from answering questions to operating over sensitive data, privacy becomes harder to enforce. An agent touches many data sources, runs multi-step workflows, keeps state across sessi…
Read original ↗https://arxiv.org/abs/2606.26627arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
Jailbreaking for the Average Jane: Choosing Optimal Jailbreaks via Bandit Algorithms for Automatically Enhanced Queries arXiv:2606.26936v1 Announce Type: new Abstract: With a profusion of jailbreaks for LLMs now widely known, a growing concern is that non-expert malicious actors ("the average Jane") could elicit actionable responses to malicious requests. In this work, we examine whether this concern is justified. A non-expert malicious actor requires two ingredients for a s…
Read original ↗https://arxiv.org/abs/2606.26936arxiv_cs_cr · tlp:amber · 6/26/2026, 4:00:00 AM
MIRROR: Novelty-Constrained Memory-Guided MCTS Red-Teaming for Agentic RAG arXiv:2606.26793v1 Announce Type: new Abstract: Multimodal agentic retrieval-augmented generation (RAG) systems expand the attack surface beyond prompt injection to include text poisoning, image injection, direct-query attacks, and orchestrator-level tool manipulation. Existing red-teaming approaches are typically surface-specific and often recycle known attack templates; on text-poisoning benchmarks …
Read original ↗https://arxiv.org/abs/2606.26793arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Unprivileged Topology Certificates for Cloud GPU Attestation arXiv:2606.24934v1 Announce Type: new Abstract: Cloud GPU tenants receive a model name and a region, but cannot directly inspect the physical accelerator that runs their job. We present a software-only attestation primitive for this setting. A CUDA probe measures an SM-by-memory-region latency matrix using physical SM labels and dependent global loads. A streaming reducer commits sufficient statistics, configuratio…
Read original ↗https://arxiv.org/abs/2606.24934arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Quantum-Resilient Decentralized AI Economies: Proof-of-Useful-Work and Post-Quantum Security arXiv:2606.24942v1 Announce Type: new Abstract: Proof-of-Work blockchains secure consensus through hash puzzles, producing no external value. In this research, we propose a decentralized AI economy where nodes are rewarded for useful machine-learning work, i.e., inference and training, instead of ineffective hashing method. Our proposed three-layer architecture separates compute, val…
Read original ↗https://arxiv.org/abs/2606.24942arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
What Does It Mean to Break a Distillation Defense? arXiv:2606.25059v1 Announce Type: new Abstract: Black-box LLMs (accessible only via API) are vulnerable to distillation attacks, in which an attacker queries the model and trains a student on its outputs. A recent line of work proposes output perturbation defenses that modify the teacher's output to reduce student performance while preserving utility for legitimate users. As a relatively new family of approaches, output pert…
Read original ↗https://arxiv.org/abs/2606.25059arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem arXiv:2606.26028v1 Announce Type: new Abstract: As autonomous AI agents increasingly transact across organizational boundaries, a fundamental trust challenge emerges: how can an agent assess whether an unknown counterpart is trustworthy? The ERC-8004 protocol addresses this challenge with the first permissionless trust layer for AI agent economies, built around three on-chain…
Read original ↗https://arxiv.org/abs/2606.26028arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Privacy Vulnerabilities of Attention Layers in Tabular Foundation Models and Protection of High-Risk Queries arXiv:2606.26021v1 Announce Type: new Abstract: Tabular foundation models are commonly assumed to present limited privacy concerns as they are often pre-trained on large collections of synthetic data. However, these models leverage in-context learning, where sensitive records may be provided directly at inference time as labelled context examples. In this paper, we de…
Read original ↗https://arxiv.org/abs/2606.26021arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
BlowLive: Blow-Based Multi-Factor Biometrics with Liveness Detection and Revocability arXiv:2606.25998v1 Announce Type: new Abstract: Biometric authentication systems are increasingly deployed in security-critical applications, yet existing physiological and behavioral biometrics suffer from fundamental limitations: 1) they are vulnerable to spoofing attacks due to unreliable liveness detection, 2) biometric templates may leak privacy-sensitive information 3) intra-user vari…
Read original ↗https://arxiv.org/abs/2606.25998arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Certification of Machine Learning Models via Directional Sharpness arXiv:2606.25004v1 Announce Type: cross Abstract: In machine learning, model certification has been identified as an important method for gaining assurance about a model's trustworthiness and quality. A model's quality is largely determined by its ability to generalize, i.e., to perform well on data beyond what it was trained on. It is not possible to certify generalization directly, however, as it depends on…
Read original ↗https://arxiv.org/abs/2606.25004arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Speculative Decoding at Temperature Zero: A Scoped Safety-Invariance Screen with a 48,072-Sample Expansion arXiv:2606.25097v1 Announce Type: cross Abstract: Speculative decoding accelerates inference by letting a draft model propose tokens for a target model to verify, raising a concrete safety question: at temperature zero, can draft-side behavior leak into safety-scored outputs? We answer with Typical-Acceptance Invariance Screen (TAIS), a behavioral-equivalence screen tha…
Read original ↗https://arxiv.org/abs/2606.25097arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Tracing Target Answers in Poisoned Retrieval Corpora via Token Influence Attribution arXiv:2606.25721v1 Announce Type: new Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to corpus poisoning attacks that manipulate model outputs through malicious retrieved documents. Existing detection methods typically rely on auxiliary classifiers or additional LLM-based verification, introducing substantial computational overhead. We present TRACE, a lightweight dete…
Read original ↗https://arxiv.org/abs/2606.25721arxiv_cs_cr · tlp:amber · 6/25/2026, 4:00:00 AM
Probabilistic Agents in Deterministic Audits: Evaluating Multi-Agent Systems for Automated Audits Based on the German IT-Grundschutz arXiv:2606.25622v1 Announce Type: new Abstract: The NIS-2 Directive mandates robust Risk Management from thousands of small and medium enterprises. To ensure compliance, companies rely on established standards such as the German IT-Grundschutz (IT-GS) of the Federal Office for Information Security. However, IT-GS certification is resource-inten…
Read original ↗https://arxiv.org/abs/2606.25622