CuraSec

tag: Research · 26 items

2026-09-01 · GitHub Trending · source ↗ #security-tooling#open-source#research
  • Engineer — Learn: A nascent open-source security harness worth bookmarking once it matures; with only 56 stars and a thin research-preview description, there is nothing to evaluate or adopt today.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-31 · arXiv cs.CR · source ↗ #deepfake#research#watermarking
  • Engineer — Learn: Novel proactive defense that embeds perturbations into facial video regions to surface manipulation artifacts post-edit — no deployable product yet, but relevant to teams building video authentication or media integrity pipelines.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Learn: If you rely on semantic watermarking to detect AI-generated content in your pipeline, this research shows existing schemes are brittle to embedding displacement attacks — worth tracking before committing to a vendor or open-source scheme, but no change to running systems today.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Learn: If you rely on DP guarantees to protect training data in ML pipelines, this research shows that controlling memorization and controlling extraction are formally separate — a model can be memorized yet unextractable, or vice versa. Revisit your threat model assumptions, but no system change is required today.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Learn: Reinforces the design principle that LLM safety filters alone are insufficient; architecture decisions should place external guardrails (input/output validation, prompt firewalls) outside the model layer rather than trusting built-in refusals.
  • SOC/IR — Skip
  • Leader — Learn: Supports the case for defense-in-depth policy around AI deployments: if safety refusals are fragile by design, any AI system handling sensitive data needs external controls beyond the model’s built-in guardrails — useful framing for board or audit conversations about AI risk.
2026-08-24 · arXiv cs.CR · source ↗ #supply-chain#research#trust
  • Engineer — Learn: Qualitative research on how practitioners actually respond to supply-chain trust erosion — automation, trust delegation, and guardian models — offers conceptual framing useful when designing SBOM, dependency-review, or artifact-signing workflows, but requires no immediate action.
  • SOC/IR — Skip
  • Leader — Learn: The finding that trust costs are rising and practitioners are accumulating controls is relevant context for board-level conversations about supply-chain risk investment, though the study offers no regulatory deadlines or vendor-specific exposure to act on now.
  • Engineer — Learn: Novel TTP-free approach to mutual attestation using fixed-point theory, with working PoCs for TPM and AWS Nitro Enclaves. Worth reviewing if you design decentralized attestation pipelines; no current systems require changes.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-24 · arXiv cs.CR · source ↗ #llm-security#ai-safety#research
  • Engineer — Learn: The findings — that safety alignment increases over-refusal (safety tax), privacy is near-orthogonal to other trustworthiness dimensions, and distillation degrades robustness — are useful mental models for engineers selecting or evaluating LLMs in their stack, though no immediate system changes are required.
  • SOC/IR — Skip
  • Leader — Learn: The finding that strong alignment does not protect privacy, and that distilled models suffer robustness collapse, provides empirical grounding for AI governance decisions and risk conversations with leadership about LLM adoption — useful for future board decks but no same-week action needed.
2026-08-21 · The Hacker News · source ↗ #nfc#payment-security#research
  • Engineer — Learn: Interesting NFC/EMV protocol research showing a gap between cryptographic validity and expiration enforcement at POS terminals; no software patch available and no enterprise infrastructure to reconfigure, but worth tracking if you own payment integrations.
  • SOC/IR — Skip
  • Leader — Learn: Academic research with no active exploitation; relevant context for payment-related risk discussions or PCI DSS conversations, but no immediate action required.
2026-08-19 · The Hacker News · source ↗ #ai-agents#prompt-injection#research
  • Engineer — Learn: Novel attack class showing that writable system-prompt state files in multi-agent harnesses can carry self-propagating payloads between agents; no exploitation in the wild yet, but engineers building agentic pipelines should treat those files as untrusted input surfaces and avoid giving agents write access to other agents’ system prompts.
  • SOC/IR — Learn: Pure research with no IOCs, no ATT&CK mapping, and no detected campaigns; no hunt or detection to write today, but worth tracking as agentic AI deployments grow and this technique matures toward real-world use.
  • Leader — Plan: If the organization is deploying or evaluating multi-agent AI systems, this peer-reviewed research identifies a systemic risk class that warrants a policy guardrail — specifically around which components may write to agent state files — before agentic tooling scales further internally.
  • Engineer — Learn: Academic analysis showing that practical graph encryption schemes leak structural metadata enabling query recovery; relevant if evaluating encrypted graph databases for sensitive workloads, but no currently deployed product or patch is implicated.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Skip
  • SOC/IR — Learn: A dataset of 2,438 verified illicit Bitcoin addresses with HackForums provenance and cybercrime category labels could enrich threat intel feeds or wallet-screening tooling; no immediate detection action required, but worth evaluating the released dataset for integration.
  • Leader — Skip
  • Engineer — Learn: Multi-step indirect prompt injection significantly raises attack success rates on computer-use agents (up to 72.9% for GPT-4o-mini at three-step depth), which is directly relevant to teams building or deploying agentic AI systems; no patch exists, but understanding this attack class should inform how you design sandboxing, permission scopes, and input validation for any CUA deployment.
  • SOC/IR — Learn: This research formalizes a new attack class against AI agents that may soon appear in enterprise environments; no active exploitation or IOCs reported, but understanding multi-step injection techniques will help detection engineers think ahead about behavioral anomalies in agentic workflows.
  • Leader — Learn: If your organization is piloting or deploying computer-use AI agents, this benchmark demonstrates meaningful safety gaps in current state-of-the-art systems; worth factoring into your AI governance policy and vendor evaluation criteria before broader rollout.
  • Engineer — Plan: An Apache Traffic Server zero-day surfaced during this research with no patch yet available; confirm whether ATS is in your proxy stack and monitor PortSwigger and Apache advisories for remediation guidance. The novel desync techniques also warrant a review of request-handling assumptions in any HTTP pipeline you operate.
  • SOC/IR — Learn: PortSwigger’s research introduces new HTTP desynchronization primitives that expand the attack surface for reverse proxies and CDNs, but no IOCs, active exploitation, or mappable TTPs are published yet — file for context when building HTTP-layer detections.
  • Leader — Skip
2026-08-03 · arXiv cs.CR · source ↗ #privacy#vector-search#research
  • Engineer — Learn: Academic research on privacy-preserving vector search using differential privacy and LSH — worth tracking if you run RAG or embedding search pipelines over sensitive data, but no actionable change to running systems today.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Learn: Academic benchmarking of the BGN SWHE scheme may inform future architecture decisions for privacy-preserving analytics pipelines, but no current system changes are needed.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-03 · arXiv cs.CR · source ↗ #5g#wireless-security#research
  • Engineer — Learn: Academic simulation study on 5G jamming variables; no vulnerability or patch — useful background if you operate 5G-dependent industrial IoT or private networks and want to inform configuration choices.
  • SOC/IR — Skip
  • Leader — Learn: Relevant for leaders with critical-infrastructure or industrial network exposure; findings on channel bandwidth and frequency range as jamming resilience factors could inform future 5G deployment decisions.
  • Engineer — Learn: The paper’s four-property model (Source Authorization, Task Alignment, Action Alignment, Data Isolation) offers a useful design lens for teams building agentic systems, but no running system requires a change today — absorb when designing agent authorization boundaries.
  • SOC/IR — Learn: Reframing indirect prompt injection as a Source Authorization violation is a useful mental model for thinking about what agent behaviors to monitor, but the paper yields no IOCs, detection rules, or hunt queries.
  • Leader — Skip
  • Engineer — Learn: Academic thesis proposing game-theoretic models for AD attack-path hardening, including dynamic graph defense and honeypot placement. No patch or configuration change needed today, but the prioritization framework could inform future AD remediation planning.
  • SOC/IR — Learn: The decoy/honeypot placement model—designed to maximize worst-case incident response time in dynamic AD environments—is worth reading for analysts building deception layers, though no actionable detection content or IOCs are included.
  • Leader — Skip
2026-07-27 · arXiv cs.CR · source ↗ #llm-agents#research#appsec
  • Engineer — Learn: Novel static-analysis approach to sandboxing LLM-generated shell commands before execution; worth evaluating if you’re building or securing agentic pipelines, but no patch or config action required today.
  • SOC/IR — Skip
  • Leader — Learn: Useful framing for AI-agent risk governance — highlights that shell-executing LLM agents need formal pre-execution controls, relevant when developing policy for agentic AI tooling adoption.
2026-07-21 · The Hacker News · source ↗ #cloud-security#gpu#research
  • Engineer — Learn: Novel academic research showing that ordinary tenant GPU workloads can modulate data center power draw enough to stress the upstream grid — no exploit or patch surface exists, but it reshapes how multi-tenant GPU infrastructure risk should be assessed in cloud architecture reviews.
  • SOC/IR — Learn: No IOCs, no active exploitation, and no practical detection surface for workload-level power manipulation; file as background awareness on an emerging side-channel class with no near-term hunt or rule-writing opportunity.
  • Leader — Learn: Early-stage academic research with no current exploitation; worth tracking as a long-horizon risk narrative around cloud infrastructure resilience and power-grid dependencies, but no board or customer communication is warranted now.
  • Engineer — Learn: Relevant for teams designing or evaluating cryptographic hardware; Vogls enables pre-silicon DPA testing at RTL/gate level, which could inform security requirements for custom silicon or FPGA-based crypto implementations.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-13 · arXiv cs.CR · source ↗ #ai-agents#llm-security#research
  • Engineer — Learn: If you deploy LLM agents with skill files or tool orchestration, this research quantifies a real risk class: agents routinely violate preconditions and constraints, producing privacy leaks and unsafe config changes. No patch action today, but the SLGuard scaffold approach is worth evaluating if you build skill-guided agents.
  • SOC/IR — Skip
  • Leader — Learn: Academic evidence that LLM agents fail safety constraints at high rates is useful background for AI governance discussions, but there is no immediate vendor exposure or regulatory trigger here — file for the next AI risk policy review.
2026-07-13 · arXiv cs.CR · source ↗ #sd-jwt#access-control#research
  • Engineer — Learn: Academic proposal to embed cryptographic authenticity directly into shared files using SD-JWT, bypassing centralized IAM. Worth evaluating if you distribute immutable resources (PDFs, configs) and want to reduce identity-infrastructure dependencies, but no running system changes needed today.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-13 · arXiv cs.CR · source ↗ #privacy#data-streams#research
  • Engineer — Learn: Academic tool for identifying privacy-revealing query patterns in databases and streams; worth evaluating if your team struggles to label sensitive data flows, but no operational action required today.
  • SOC/IR — Skip
  • Leader — Learn: Research on semi-automated privacy labeling in data pipelines may be relevant when assessing data-utility vs. privacy tradeoffs, but no immediate risk register or compliance action follows.
2026-07-10 · HN (vulnerability) · source ↗ #fuzzing#appsec#research
  • Engineer — Learn: Practical walkthrough on building custom vulnerability harnesses — useful for teams doing fuzzing or exploit research, but no running-system change required today.
  • SOC/IR — Skip
  • Leader — Skip