๐ต๏ธ RESEARCH & DEEP DIVES
-
Anthropic Warns Attackers Using Infostealers to Hijack Claude Login Sessions
Anthropic is warning Claude users that infostealer malware is being used to hijack their login sessions.- Applies to Claude users, whose accounts Anthropic warns are being targeted via compromised login sessions
- Attackers use infostealer malware to hijack sessions and steal account usage to run their own activities
- The tactic reflects a broader shift by bad actors from stealing credentials to hijacking session tokens and authentication cookies
๐ Coverage: securityboulevard.com ยท ๐ via securityboulevard.com (discovered)
-
Risky Bulletin: BGP hijack delivers malicious Virtualizor updates โ Risky Business News
-
Divi through 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via... โ CVE ThreatInt
-
Baserow 2.3.3 - SQL injection in formula index() JSONB array extractionBasero... โ CVE ThreatInt
-
MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt... โ CVE ThreatInt
-
WP File Download through 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deleti... โ CVE ThreatInt
-
FIPS mode assertion failure via malicious CERT payloadIn FIPS mode, Libreswan... โ CVE ThreatInt
-
Piwigo Image Derivative i.php path traversalA security vulnerability has been... โ CVE ThreatInt
-
OpenCart Autocomplete Workflow edit.php cross site scriptingA vulnerability w... โ CVE ThreatInt
-
Keycloak-services: keycloak-services: cross-session email verification proof ... โ CVE ThreatInt
-
OpenCart Autocomplete Workflow address.php cross site scriptingA vulnerabilit... โ CVE ThreatInt
-
FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Upda... โ CVE ThreatInt
-
APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organiz... โ CVE ThreatInt
-
ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnvION-DTN versions before... โ CVE ThreatInt
-
AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRe... โ CVE ThreatInt
-
AgentProv: Auditing Agentic LLM API Providers via Tool-use Policy Probes โ arXiv cs.CR
-
A Formal Analysis of Agent Payment Protocols โ arXiv cs.CR
-
Explainable Artificial Intelligence for Industrial Cybersecurity: A Review of Methods, Operational Integration, and Research Challenges โ arXiv cs.CR
-
DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner โ arXiv cs.CR
-
Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems โ arXiv cs.CR
-
Workload Identification with Physical Side Channels for AI Governance โ arXiv cs.CR
-
OreProof: Verifiable Provenance with Limited Disclosure for Critical-Minerals Supply Chains Using Zero-Knowledge Proofs โ arXiv cs.CR
-
NeuroPriv: Adversarial Representation Learning for Privacy in Wearable EEG Systems โ arXiv cs.CR
-
Federated Trust for Embodied Robot Capability Marketplaces โ arXiv cs.CR
-
Don't Trust the Code, Check Its Effects: Runtime Refinement for Regenerated Systems Code Under an Adversarial Generator โ arXiv cs.CR
-
Capability-Gated Language Models: Security Composes, Utility Does Not โ arXiv cs.CR
-
Does Reasoning Mitigate Backdoor Attacks? A Neuro-Symbolic Perspective โ arXiv cs.CR
-
GlitchLab: A Hardware-in-the-Loop Optimizer for Physical Fault Injection โ arXiv cs.CR
-
The Safeguard Worked. Is the LLM System Safer? โ arXiv cs.CR
-
Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents โ arXiv cs.CR
-
SoK: When Safe Agents Fail Together: The Security of Multi Agent LLM Systems โ arXiv cs.CR
-
NeuroGraph: An AI Graph-Driven Neuro-Symbolic Framework for Explainable Threat Reasoning in Advanced Manufacturing โ arXiv cs.CR
-
A Version Space Approach for Digital Circuit Analysis โ arXiv cs.CR
-
Automating Static Code Analysis Through CI/CD Pipeline Integration โ arXiv cs.CR
-
PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation โ arXiv cs.CR
-
Anthropic Launches Claude Fable and Mythos 5.1 for Advanced Coding and Research โ cryptika.com (discovered)
-
OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at Scale โ cryptika.com (discovered)