arXiv:2609.27155v1 Announce Type: new Abstract: With recent advancements in large language models (LLMs) and LLM-based agents, these agents are becoming increasingly autonomous and gaining broader…
arXiv:2609.27367v1 Announce Type: new Abstract: Verifying outsourced language-model inference requires a precisely identified computation and an audit whose cost a service can afford.
arXiv:2609.27424v1 Announce Type: new Abstract: Maximal Extractable Value (MEV) has evolved into a major economic force in blockchain ecosystems, yet its capture is dominated by experienced teams…
Autonomous penetration testing in the Praetorian Guard Platform has changed shape. Hannibal started as a hunt agent for external and cloud attack surfaces. Today, it’s something your security team…
Threat Intelligence, Threat Walkthroughs CARBONATO: a botnet built around an AI agent ThreatDown researchers uncovered CARBONATO, a Docker botnet built around an AI agent that compromises exposed…
arXiv:2609.25173v1 Announce Type: new Abstract: Attack success rate (ASR) is the headline metric in nearly every published evaluation of attacks on, and defenses for, LLM agents. We argue that ASR as…
arXiv:2609.25637v1 Announce Type: new Abstract: Formal hardware information-flow verification (IFV) provides strong guarantees against secret-dependent timing and control behavior, but often scales…
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including…
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server…
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over…
In comparison to Claude Opus 5, Claude Opus 5.5 produced fewer blocker-level bugs, vulnerabilities, and code smells, and did so by writing significantly fewer lines of code and consuming fewer output…
A cairn is a marker left behind on a trail, a deliberately placed stack of stones that helps hikers find their way when the path is unclear. Attackers building AI-integrated malware unintentionally…
arXiv:2609.22510v1 Announce Type: new Abstract: As LLM applications integrate with external tools, they are increasingly exposed to indirect prompt injection (IPI), where adversarial instructions are…
arXiv:2609.22573v1 Announce Type: new Abstract: LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain…
arXiv:2609.22724v1 Announce Type: new Abstract: Mobile agents powered by foundation models now automate complex, multi-step workflows on real devices, but their trajectories can violate app-specific…
arXiv:2609.22792v1 Announce Type: new Abstract: LLM agents are increasingly used for security tasks: vulnerability discovery, exploit reproduction, and patch generation. Improving them at the model…
arXiv:2609.22818v1 Announce Type: new Abstract: Memory-poisoning defenses for LLM agents are typically evaluated by their ability to prevent attacks. However, the traffic they process is rarely…
arXiv:2609.22949v1 Announce Type: new Abstract: Existing prompt injection research focuses on single-model chatbot scenarios, where an attacker manipulates one LLM through crafted input.