Tag: #security

Articles related to security

technology

Detokenization Cache Attack Can Reconstruct Local LLM Outputs, Researchers Warn

Researchers show locally run LLM outputs can be reconstructed from CPU cache activity during detokenization, raising privacy concerns for on-device AI.

#security, #llm, #sidechannel, #privacy

technology

Cronos halted block production after Tectonic exploit; preliminary losses estimated $66–75M

Cronos halted its blockchain on Aug. 30 after an exploit at Tectonic froze activity; on-chain researchers estimate $66–75 million in preliminary losses.

#crypto, #defi, #blockchain, #security

world

South Korea, U.S. and Japan hold trilateral call after North Korea fires short-range missiles

South Korea, the U.S. and Japan held a trilateral phone consultation after North Korea fired about 10 short-range ballistic missiles, coordinating information and response.

#northkorea, #missiles, #diplomacy, #security

technology

Coinkite says 2021 COLDCARD firmware bug linked to theft of ~1,083–1,367 BTC; users must replace affected seeds

Coinkite warns a 2021 RNG bug in COLDCARD wallets weakened seed phrases, tied to 1,083–1,367 BTC stolen; affected users must create new seeds and migrate funds.

#bitcoin, #hardwarewallet, #security, #coinkite

technology

Coinkite Coldcard Firmware Bug Weakened Seed Randomness, Allowing Tens of Millions in Bitcoin to Be Stolen

A firmware bug in Coldcard wallets weakened seed randomness, enabling attackers to drain roughly 600–1,082 BTC. Affected users must generate new seeds and move funds.

#bitcoin, #hardwarewallet, #cryptocurrency, #security

technology

Harmony Says Exploit Minted About 4 Billion ONE Tokens, Token Drops 26%

Harmony confirmed an apparent exploit that minted roughly 4 billion ONE tokens, prompting a ~26% price drop and consideration of a chain rollback.

#cryptocurrency, #blockchain, #harmony, #one, #security

technology

Study finds structured-output decoding can enable 'control-plane' jailbreaks in LLMs

Researchers find constrained-output grammars can be exploited to jailbreak LLMs; DictAttack hit up to ~99% success on flagship models, paper says.

#ai, #security, #llm, #jailbreak

technology

Preprint finds flaw that let researchers decode encrypted chain-of-thought blobs from major LLM APIs

An arXiv preprint says a cross-model replay flaw let researchers decode encrypted chain-of-thought blobs from major LLM APIs, exposing PII and credentials.

#ai, #security, #privacy, #openai

technology

BTCPay Server issues urgent v2.4.2 patch for critical vulnerability under active exploitation

BTCPay Server released v2.4.2 to fix a critical vulnerability being actively exploited and urges self-hosted operators to update immediately.

#bitcoin, #btcpay, #security, #nbxplorer

technology

Researchers Find Position-Independent KV Cache Reuse Can Let One User Hijack Another’s LLM Output

Researchers show position-independent KV-cache reuse in LLM inference can let attackers' context influence other users' outputs, posing risks for shared serving.

#ai, #security, #infrastructure, #ml, #llm

technology

Coinkite Warns Weak Randomness in Coldcard Firmware May Have Exposed Some Bitcoin

Coinkite says a 2021 firmware bug weakened seed randomness on older Coldcard devices, possibly exposing wallets; affected users must generate new seeds.

#bitcoin, #coldcard, #hardwarewallet, #security, #randomness

technology

Chained Harmless Tools Let LLM Agents Perform Harmful Real-World Actions, Study Finds

An arXiv preprint shows attackers can chain innocuous tool calls to make LLM agents carry out harmful operations, with about 91% success.

#ai, #security, #machinelearning, #agents

technology

Academic Paper Details “Action Rebinding” Flaw That Can Trick Android GUI Agents

Academic paper describes “Action Rebinding,” a TOCTOU-style exploit that can trick Android GUI agents into acting in other apps during seconds-long reasoning delays.

#android, #security, #ai, #vulnerabilities, #research

technology

Researchers Warn of 'Agent Data Injection' That Can Trick AI Agents via Trusted Fields

An arXiv preprint shows attackers can hide malicious payloads in metadata to make AI agents click, run code or alter supply chains, researchers say.

#ai, #security, #agents, #cybersecurity

technology

Taiko Halts Block Production and Urges Withdrawals After Bridge Verification Flaw Drains Over $1 Million

Taiko halted block production and urged users to withdraw after a bridge verification flaw allowed attackers to drain more than $1 million from its ERC20 vault.

#crypto, #ethereum, #blockchain, #security