01▲A Seed for Privacy -- semi-automatic privacy-revealing data reminder in databases and data streams arxiv.org ArXiv paper on pArborist, semi-automatic query growth for privacy-revealing events in DBs and streams, because privacy loves paperwork.arxivdata-streamsdatabasesprivacyquery-generationsecuritystream-processing4 pts/willg/1 day ago/8 comments
02▲Rust-proof your code with our new Testing Handbook chapter blog.trailofbits.com Trail of Bits adds a Rust security testing chapter, covering Miri, property tests, Kani, Clippy, and supply-chain vetting.dynamic-analysismirimodel-checkingproperty-testingrustsecuritystatic-analysissupply-chaintestingtwitter3 pts/verak/1 day ago/1 comment
03▲Devil in the Lens: Analyzing and Defending Physical Prompt Injection Against Vision-Language Models on Wearable Devices arxiv.org Physical prompt injection on AI glasses works across VLMs; the paper also benchmarks a mask filter and semantic detector.arxivprivacyprompt-injectionsecurityvision-language-modelswearables1 pt/ben/7 hours ago/2 comments
04▲Attested TLS Was Supposed to Be the Last Trust Boundary. It Isn't. Formal Methods Show How. hackernoon.com ProVerif finds CVE-2026-33697, a relay attack that breaks attested TLS binding, so the last trust boundary wasn't.confidential-computingformal-verificationlinkedinman-in-the-middleprivacyprotocol-analysisproverifrelay-attackremote-attestationsecuritytlszk1 pt/nadiaf/1 day ago/3 comments
05▲Why Small Businesses Should Start Preparing for Post-Quantum Cryptography Today homebusinessmag.com Why should a small business care about PQC now? An intro to harvest-now-decrypt-later, crypto-agility, and vendor checklists.compliancecrypto-agilitycryptographyhybrid-encryptionlinkedinpqcquantum-computingsecurity1 pt/willkeller/2 days ago/1 comment
06▲FINMA Drops The Quantum Hammer: 72% Of Banks Unprepared As Post-Quantum Crypto Deadline Looms + Video undercodetesting.com FINMA's PQC warning: 72% of banks aren't ready, and the article walks through crypto-agility, hybrid TLS, and OpenSSL/liboqs tests.crypto-agilityhybrid-cryptographylatticeopenssloqspost-quantumpqcprivacyquantum-computingsecuritysignaturestlstwitter2 pts/gabewebb/3 days ago/1 comment
07▲The triage is the product: running AI agents against Ethereum's protocol code blog.ethereum.org Ethereum Foundation on using AI agents to triage protocol bugs, because apparently the hard part is proving the bugs exist.ai-agentsblockchainblogsprotocol-securitysecuritytriage10 pts/calebt/4 days ago/1 comment
08▲TRACE: A Two-Channel Robust Attribution Watermark via Complementary Embeddings for LLM-Agent Trajectories arxiv.org TRACE watermarks LLM-agent trajectories with two keyed channels, trying to survive log deletion and rewriting, which is the annoying part.agentsarxivcryptographyllmprivacysecuritywatermarking10 pts/deadlock7/4 days ago/discuss
09▲Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis arxiv.org Paper on MINIAUTH, a dynamic crawler for mini-program OAuth bugs, with tens of thousands of apps and one delightful Baidu key-bruteforce...arxivauthenticationcryptanalysiscryptographymobileoauthprivacysecurity2 pts/deadlock/4 days ago/2 comments
10▲KS-CFA: Control-Flow Attestation via Symbolic Replay Against Control-Flow Bending Attacks arxiv.org Can control-flow attestation catch bending attacks by replaying the path symbolically instead of enumerating it?arxivattestationcontrol-flowcryptographysecuritysymbolic-executiontee9 pts/nonce/4 days ago/4 comments
11▲Beware What You Autocomplete: Forensic Attribution of Backdoored Code Completions arxiv.org Can you trace a poisoned code completion back to the fine-tuning sample that taught it? CodeTracer says yes, mostly.arxivbackdoorcode-completioncryptanalysisforensicsllmsecurity21 pts/nullptr7/4 days ago/discuss
12▲Quantum Readiness is Quietly Becoming a SLED Cyber Priority dlt.com Is SLED ready for PQC, or is this just a polite way of saying nobody knows where the crypto lives?compliancecryptographygovernmentpqcquantumsecuritytwitter2 pts/nullptr/4 days ago/discuss
13▲Mechanistic Interpretability of LLM Jailbreaks via Internal Attribution Graphs arxiv.org Mechanistic jailbreak analysis with paired clean/attacked attribution graphs, finally doing more than waving at prompt gradients.arxivattribution-graphscausal-interventionjailbreaksllmmechanistic-interpretabilityprivacysecurity8 pts/proverbill/4 days ago/discuss
14▲Finding and Understanding Miscompilation Bugs in the Solidity Compiler arxiv.org Paper on SolSmith, a semantics-aware fuzzing tool that found 25 Solidity miscompiles, because compilers still enjoy surprises.arxivblockchaincompiler-testingethereumfuzzingsecuritysmart-contracts8 pts/bsato/5 days ago/2 comments
15▲ONUG Launches Quantum-Ready Enterprise Advisory Board to Help Enterprises Navigate the Convergence of AI Infrastructure einpresswire.com Quantum-ready advisory board, because the usual enterprise committee apparently wasn't confusing enough.cryptographyinfrastructurepqcprivacyquantumsecuritytwitter2 pts/theolowe/5 days ago/10 comments
16▲Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies arxiv.org How bad is the dual-use mess? This survey maps LLM cyber use from phishing and malware to explainability and defenses.aiarxivexplainabilityllmmalwareprivacysecurity3 pts/dford/5 days ago/1 comment
17▲cr.yp.to cr.yp.to D. J. Bernstein’s cryptography site, with papers, code, talks, and projects like NaCl and SafeCurves, because one homepage was enough.cryptographyhashlatticelinkedinpqcprivacysecuritysignaturessoftware3 pts/rvance/5 days ago/1 comment
18▲2026.07.06: NSA and IETF, part 8 blog.cr.yp.to DJB critiques the IETF's repeated TLS last call on solo ML-KEM, arguing the process and security story are both wobbly, as usual.latticelinkedinpolicypqcsecuritystandardstls13 pts/sanatran/5 days ago/discuss
19▲Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations arxiv.org Can MCP tool approvals hide Unicode TAG payloads from humans while still feeding them to the model? Apparently yes.arxivmcpmetadataprompt-injectionprotocolsanitizationsecurityunicode3 pts/ovoss/6 days ago/9 comments
20▲OpenSSH 10.4 Security Fixes + Experimental Post-Quantum Signatures (July 6, 2026) windowsforum.com OpenSSH 10.4 ships experimental ML-DSA 44 + Ed25519 signatures, plus the usual SSH bugfix pile.authenticationclient-serverhardeningpqcscpsecuritysftpsignaturessshtwitter3 pts/pavelk/6 days ago/discuss
21▲Reluctant enforcers: certificate authorities as malware police blog.randomoracle.io An essay on CAs revoking Windows code-signing certs for malware, and why PKI was never meant to be a software cop.authenticationauthenticodeauthorizationblogscode-signingmalwarepkipkixrevocationsecuritywindowsx50912 pts/dan/6 days ago/discuss
22▲oss-security - Announce: OpenSSH 10.4 released openwall.com OpenSSH 10.4 release notes: stricter KEX, SFTP/SCP fixes, and an experimental ML-DSA 44 + Ed25519 composite signature.cryptographypqcprotocolssecuritysignaturessshtwitter12 pts/ben_stderr/6 days ago/2 comments
23▲Robinhood Chain - L2BEAT l2beat.com What trust assumptions does Robinhood Chain’s Orbit L2 actually make, and how much of it still hinges on Robinhood?arbitrumblockchaindata-availabilityfraud-proofsrollupsecuritytwitter11 pts/ben/6 days ago/discuss
24▲aiAuthZ: Off-Host, Identity-Bound Authorization for AI Agents arxiv.org Off-host auth for AI agents: per-message HMACs, nonce/timestamp binding, and a policy engine the model can't tamper with.agent-securityarxivaudit-logauthenticationauthorizationcryptographyhashhmacprivacysecurity9 pts/ivan9/6 days ago/2 comments
25▲A Failure-Mode Benchmark for Polymorphic Sybil Poisoning in RAG arxiv.org Arxiv benchmark for polymorphic Sybil poisoning in RAG, with forced exposure and a 4-way failure taxonomy instead of yet another toy attack.arxivbenchmarkllmpoisoningprivacyragretrievalsecurity13 pts/deadlock99/7 days ago/3 comments
26▲Governed Individuation: Cryptographically Decoupling an Agent's Learning from Its Authority arxiv.org Paper on cryptographically freezing an agent's identity so learning can't widen authority, because apparently tools needed a leash.ai-safetyarxivcryptographyprivacysecurity5 pts/deadlock23/7 days ago/discuss
27▲Conductance-Repair Evidence Graphs for Prospective Security Retrieval arxiv.org Defines conductance-repair evidence graphs for delayed or poisoned security retrieval, plus repair certificates and complexity results.arxivbenchmarkingcomplexityinformation-retrievalprivacysecuritytemporal-graphs6 pts/deadlock42/7 days ago/2 comments
28▲Observer-Quotient Security: Composable Leakage Bounds for Hidden State Continuations arxiv.org A composable leakage framework for adaptive observers, finally unifying transcripts, timing, cache, power, and EM without ad hoc glue.arxivcryptographyencryptionhashleakageprivacysecurityside-channeltiming4 pts/nonce99/7 days ago/1 comment
29▲OpenSSH 10.4 released lwn.net OpenSSH 10.4 adds an experimental ML-DSA 44 + Ed25519 composite signature, plus stricter Linux sandbox checks.cryptographypqcsecuritysignaturestwitter2 pts/nullptr42/7 days ago/7 comments
30▲Look-Ahead-Freedom as Temporal Non-Interference: A Verifiable Correctness Property for Backtesting and Agentic Trading Pipelines arxiv.org Paper formalizes look-ahead bias as temporal non-interference for backtests and trading, with a decidable fragment, naturally.arxivformal-methodsnon-interferenceprivacysecuritytype-systemsverification10 pts/honestmaj/7 days ago/2 comments