Tag: #security

Articles related to security

technology

Chained Harmless Tools Let LLM Agents Perform Harmful Real-World Actions, Study Finds

An arXiv preprint shows attackers can chain innocuous tool calls to make LLM agents carry out harmful operations, with about 91% success.

#ai, #security, #machinelearning, #agents

technology

Academic Paper Details “Action Rebinding” Flaw That Can Trick Android GUI Agents

Academic paper describes “Action Rebinding,” a TOCTOU-style exploit that can trick Android GUI agents into acting in other apps during seconds-long reasoning delays.

#android, #security, #ai, #vulnerabilities, #research

technology

Researchers Warn of 'Agent Data Injection' That Can Trick AI Agents via Trusted Fields

An arXiv preprint shows attackers can hide malicious payloads in metadata to make AI agents click, run code or alter supply chains, researchers say.

#ai, #security, #agents, #cybersecurity

technology

Taiko Halts Block Production and Urges Withdrawals After Bridge Verification Flaw Drains Over $1 Million

Taiko halted block production and urged users to withdraw after a bridge verification flaw allowed attackers to drain more than $1 million from its ERC20 vault.

#crypto, #ethereum, #blockchain, #security

technology

Zcash patches critical Orchard privacy flaw after private disclosure; Foundation says no evidence of stolen funds

Zcash patched a soundness flaw in its Orchard shielded pool after a May 29 disclosure. Orchard was briefly disabled; Foundation says no unauthorized ZEC was created.

#zcash, #cryptocurrency, #security, #blockchain

technology

Gravity Bridge Halted After $5.4M Drain; Signing-Layer Compromise Suspected

Gravity Bridge suspended operations after an apparent $5.4M drain that appears tied to a signing/authorization compromise; investigations are ongoing.

#crypto, #ethereum, #cosmos, #security

technology

May 27 vsdCRV Mint on Arbitrum: Trillions Created, But Only ~$91,000 Extracted

An unauthorized mint of vsdCRV on Arbitrum created trillions of tokens, but attackers appear to have cashed out only about $91,000 as DeFi protocols scrambled to contain risk.

#crypto, #arbitrum, #stakedao, #defi, #security

technology

Apparent Infinite‑Mint Exploit Creates 5.4 Trillion vsdCRV on Arbitrum; Attacker Swapped ~43.8 ETH

Security feeds report an apparent infinite‑mint exploit on Arbitrum's vsdCRV, creating ~5.4T tokens; attacker swapped about 43.78 ETH (~$90k).

#crypto, #arbitrum, #stakedao, #defi, #security

technology

New arXiv Preprint Says Adaptive 'Metis' Jailbreak Achieved High Success Against Multiple LLMs, but Results Aren't Yet Reproducible

An arXiv preprint describes Metis, an adaptive jailbreak that reportedly reached ~89% success across 10 LLMs, but its results are author-reported and not yet reproducible.

#ai, #security, #jailbreaking, #arxiv

technology

THORChain Confirms Exploit, Opens Claims Portal; Announces ~$10M Treasury Refund

THORChain confirmed a cross-chain exploit affecting 12,847 wallets, opened a claims portal and announced a roughly $10M treasury-backed refund as probes continue.

#thorchain, #crypto, #security, #exploit

us

GAO: VA hasn’t fully implemented federal facility-security standards; covert tests missed prohibited weapon

A GAO report says the VA hasn’t fully adopted federal facility-security standards; in covert tests a prohibited weapon and alcohol often went undetected.

#veterans, #va, #security, #gaoreport

technology

Preprint Claims PRNG 'SeedHijack' Could Steer LLM Outputs; Authors Propose QRNG Defense

ArXiv preprint claims attackers can steer LLM outputs by hijacking sampling PRNG seeds; authors propose QRNG-based defense, but results are unreviewed.

#ai, #security, #prng, #qrng

technology

KelpDAO to Move rsETH Bridging From LayerZero to Chainlink CCIP After April Exploit

KelpDAO will shift rsETH bridging from LayerZero to Chainlink CCIP after an April exploit that released 116,500 rsETH and prompted DeFi freezes.

#crypto, #defi, #bridges, #security

technology

Preprint Says Browser Tools Exposed 1,000 Patient Chats on Anonymized Medical AI

An arXiv preprint claims ordinary browser inspection allowed retrieval of backend settings and the 1,000 most recent patient-chatbot conversations.

#ai, #privacy, #healthcare, #security

us

Possible Gunfire Near White House Correspondents’ Dinner in Washington Forces Evacuation; Suspect in Custody

President Trump and the first lady were evacuated from the White House Correspondents’ Dinner at the Washington Hilton after possible gunfire near screening; suspect detained.

#whitehouse, #security, #washingtondc, #trump