Fetching from the wire…
Security2026-09-05 · source-backed
arXiv 2609.03789 examines eight attack vectors across the FIDO2/WebAuthn stack: malicious browser extensions, platform-handler malware, passive sniffing, virtual device drivers, CTAP2-specific malware, USB and hardware implants, malicious hubs and docks, and NFC relay. It shows AAGUID and timing information enable user profiling and targeted attacks, and that compromise of browser, OS or hardware undermines FIDO2 even with the primitives intact. Phishing-resistant hardware auth gets sold as security by design, and this is a careful argument that the design assumes an uncompromised environment nobody has (arXiv).
Each link below shares sources, entities, or timing with this story.
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
Context Privilege Escalation names two classes, M-CPE where attacker-controlled low-privilege content gets folded into a higher-privileged message role, and X-CPE where it persists past the context that introduced it. The authors ran it against 12 production harnesses includin...
13 public sources consolidated into 9,740 skills (7,505 malicious, 2,235 benign) across 11 harmonized attack categories. Learned text detectors score 0.882-0.932 Macro-F1 under random splits but collapse to 0.653-0.665 source-disjoint. arXiv Three off-the-shelf skill scanners...
Reflex-Guard combines jailbreak-aware preprocessing, compact sentence-transformer embeddings and seven binary classifiers trained on 30,568 samples, reporting 95.9% recall end-to-end against 255ms for Llama Guard 2 and 723ms for SafeDecoding, with 100% detection of GCG suffix...
WebMASLab holds task, tools, and browser fixed and varies only architecture. The Telephone Loop attack exploits cross-agent delegation to create cyclical task loops, averaging 80% success with 0% detection against multi-agent versions of Claude Sonnet 4.5, GPT-5.2, and GPT-5.4...
arXiv 2607.27080 traces malicious semantics through persistence, downstream consequence, and selective repair across 310 test cases in 48 contexts, under a 24-configuration matrix of 2 harnesses × 4 memory backends × 3 LLM backends. Malicious memory persists in 84.2% of cases,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.