APIMade · Research

Cybersecurity research, made easier to follow

Hand-picked papers, explained through concise findings and practical podcasts for people working in security.

Explore the episodes

What is this?

I don’t have a background in academia, so I’m naturally much less likely to come across new research publications than I am a blog post, conference talk or security write-up.

As more of our industry’s news feeds become awash with thinly veiled marketing, some of the most interesting security work, particularly around AI, is becoming increasingly harder to find through channels I usually follow. I’ve started using the tools available to us today to discover research that someone with my background may otherwise miss.

I also find academic papers harder to consume than most practitioner-focused writing. There’s often a lot of structure, convention and academic machinery around the useful bits I actually care about. At the same time, I’ve become reasonably good at using these tools to learn unfamiliar concepts and turn that material into short podcasts I can listen to.

This page is an attempt to bridge that gap: finding research I’d otherwise miss, stripping away some of the ceremony, and making the actual ideas easier to follow.

The papers are discovered automatically through a number of online sources, but the ones published here are generally hand-picked before being turned into short podcasts using either Qwen3-TTS or ElevenLabs. If it’s here, either I or one of my friends has listened to it before publication. The selection inevitably reflects what we find interesting and useful, so some parts of the industry will get more attention than others due to personal interest (or, in some cases, disinterest—sorry, blockchain).

You can follow new publications through the podcast RSS feed.

The podcasting format is something I’ve been iterating on over the past 12 months. The aim is to explain concepts progressively, so the knowledge needed to understand the paper builds and develops as you listen. It assumes you already have a cybersecurity background, so it won’t spend much time on the basics, but it should use practical examples, anecdotes and metaphors where they make difficult concepts easier to understand.

In spirit, it’s a little like The Phoenix Project: introduce the concepts as they become relevant, rather than front-loading all of the theory.

Feedback?

Message me on LinkedIn. I listen to several of these each week and continuously adjust the selection, structure and format based on what works and what doesn’t.


Latest research

Continuous listening

Keep listening without opening each episode

Loading listening history…

Filter episodes Choose domains, lifecycle stages, publication maturity or topics. Everything is included.

Everything is included until you choose a focus. Pick several options to broaden a category; choices across categories narrow the results.

Choose the areas you care about Practitioner domains, not publisher labels.
Where in the research lifecycle? Understand, observe, build, challenge or validate.
1
Understand

Frame what is known and why it matters.

2
Observe

Measure what happens in practice.

3
Build

Propose a system, method or defence.

4
Challenge

Attack assumptions or prove properties.

5
Validate & reuse

Compare results or leave reusable evidence.

How mature is the publication? Preprint, accepted, published, corrected or unconfirmed.

Status evidence can come from arXiv records, Crossref publisher metadata, and OpenAlex manuscript-version metadata.

Focus on a specific topic Use narrower tags when a domain is too broad.

Topic tags are deliberately narrower than domains. Select one or more that matter to you.

Timeline view Browse papers chronologically, using the paper date by default. 87 papers
87 papers
Governance, Risk, Law & Human Factors Survey or review Published edition

MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity

Giuseppe Desolda, Francesco Greco, Rosa Lanzilotti, Cesare Tucci

ACM Transactions on Computer-Human Interaction · Paper 12 Jul 2026 · Episode 31 Aug 2026

Researchers combined a systematic scoping review with AI-assisted, human-validated screening to organize human factors, their interactions, and measurement instruments in cybersecurity. MORPHEUS can support risk diagnosis and targeted interventions. Separately, cited studies associate missing information, time, tools, and training with incorrect or delayed configuration correction, while absent periodic audits, continuous monitoring, and education may leave cloud misconfigurations unresolved.

AI Systems & Agent Security Attack study Preprint

Out of Sight, Not Out of Mind: Unveiling Latent Attack in Latent-based Multi-Agent Systems

Chenxi Wang, Ruiyang Huang, Jiayan Sun, Lei Wei, Yifan Wu

arXiv · Paper 25 May 2026 · Episode 31 Aug 2026

Researchers constructed attack-associated steering vectors from paired clean and attacked runs, injected them into agents’ hidden states and KV-cache handoffs without adversarial text, and observed substantial task-performance degradation, especially through inter-agent handoffs. Security teams should therefore monitor and restrict latent-state infrastructure rather than rely on visible-message inspection, although the evaluated attacker required privileged access to intermediate states and the experiments did not exhaust the intervention space.

Governance, Risk, Law & Human Factors Policy or conceptual analysis Published edition

Cybersecurity Budgeting: A Cyber Risk Perspective

Lawrence A. Gordon, Martin P. Loeb, Lei Zhou

Transactions on Engineering and Computing Sciences · Paper 27 Aug 2026 · Episode 31 Aug 2026

The paper develops an economic framework for preventive cybersecurity budgeting based on the Gordon–Loeb model, cataloguing budgeting challenges, arguing for an initial spending upper bound, and proposing ways to align spending authority with accountability. Security leaders can use it to structure risk-based investment and governance discussions, but the study did not empirically test its arguments.

Endpoint, Device & Hardware Security Survey or review Published edition

eBPF-based cybersecurity mechanisms: a systematic literature review

Stamatios Kostopoulos, Panagiotis Tsakonas, Evangelos K. Markakis

International Journal of Information Security · Paper 28 Aug 2026 · Episode 31 Aug 2026

The review synthesized peer-reviewed research and found that evaluated eBPF mechanisms often combined low-overhead enforcement with strong detection performance, especially for kernel monitoring, real-time packet processing, and cloud-native workload protection. For deployment, treat those results as promising but context-bound: kernel fragmentation hinders portability, most work leaves eBPF’s own vulnerabilities unaddressed, and shared-kernel container designs cannot provide complete isolation.

Cloud, SaaS & Infrastructure Survey or review Published edition

Research on Edge-Cloud Collaborative Resource Scheduling and Security Management Based on Intelligent Optimization and Privacy Protection

Tianyu Luo

Frontiers in Computing and Intelligent Systems · Paper 27 Aug 2026 · Episode 31 Aug 2026

Tianyu Luo reviewed edge-cloud scheduling and privacy research, then proposed a decision model that weighs performance, cost, node trust, data sensitivity, privacy risk, reliability and auditability. For security architects and edge-platform teams, it offers a design checklist for making trust and privacy part of task placement, but the article does not test the idea experimentally, so operational benefits remain untested.

Threats, Malware & Security Operations System or technique Published edition

AGENTSHIELD: AN AGENTIC ARTIFICIAL INTELLIGENCE FRAMEWORK FOR REAL-TIME CYBERSECURITY ORCHESTRATION IN INDIA’S UPI AND FINTECH ECOSYSTEM

Chandrashekar P, Mohana Kumar S, Naveen Kumar B K

International Journal of Science and Research Archive · Paper 27 Aug 2026 · Episode 31 Aug 2026

The researchers propose Agent Shield, a real-time cybersecurity orchestration framework with coordinated threat-intelligence, transaction-anomaly, behavioral-biometric, and compliance agents. In a comparative evaluation, it achieved 98.7% fraud-detection accuracy and lower detection time and false-positive rates than existing approaches. A stated limitation of ML-only approaches is dependence on labelled training data when novel attacks have no prior labels.

Cloud, SaaS & Infrastructure Policy or conceptual analysis Published edition

Secure Cloud-Native Platforms for Critical Service Continuity: An AI-Driven Framework for National Cyber and Economic Resilience

Jawad Yaqoob Mir, Fawad Mir

American Journal of Innovation in Science and Engineering · Paper 27 Aug 2026 · Episode 31 Aug 2026

Researchers designed AICER as a conceptual decision-support architecture linking cloud-native operations, cyber intelligence, AI-assisted analytics, secure delivery, supply-chain assurance, economic impact assessment, and governance, using an integrative literature and standards review. For security teams, it offers a structure for coordinating continuity controls while keeping AI suggestions under human oversight, but its benefits remain unvalidated because the work provides no numerical simulation or synthetic experimental evidence.

Governance, Risk, Law & Human Factors Empirical measurement Published edition

DIGITAL MATURITY: EVIDENCE FROM A 24-COMPANY ASSESSMENT WITH THE RR-FRAMEWORK

Роман Резніков

Економіка та суспільство · Paper 27 Aug 2026 · Episode 31 Aug 2026

The study combined a broad resilience assessment with confidence adjustments, crisis stress tests and tail-risk modeling. Lower maturity was associated with greater modeled loss, while red-line breaches were reported descriptively. In the evaluated setting, security teams may use the results to prioritize cyber/privacy and IT-continuity weaknesses within wider resilience planning. The evidence derives from a deliberately heterogeneous portfolio of synthetic organizations used as a calibration sample.

Governance, Risk, Law & Human Factors Policy or conceptual analysis Preprint

Reciprocal Disclosure and the Ethics of Vulnerability Reporting: A Cybersecurity Ethics Case Study of Nightmare Eclipse

James Herrick

crossref · Paper 6 Jul 2026 · Episode 31 Aug 2026

Herrick analyzes Nightmare Eclipse, where a researcher moved from cooperative reporting to publishing Windows zero-days after alleging dismissal, undervaluation and legal intimidation; 3 of the first 6 disclosed flaws were exploited in the wild and chained with ransomware. Security teams should keep reporting channels functional and distinguish vulnerability intake from bounty incentives, while recognizing that nondisclosure terms can sometimes bind researchers even when a report is rejected and never fixed.

AI Systems & Agent Security Survey or review Published edition

Security and Privacy Implications of Microsoft 365 Copilot and GenAI Integration in Enterprise Environments

Pullaiah Vutla, Triveni Yenugu

openalex · Paper 25 Jun 2026 · Episode 31 Aug 2026

Using a secondary qualitative review and STRIDE threat modeling, the authors mapped how Copilot’s access to email, files, chats, and calendars can expose enterprises to prompt injection, model interference, unauthorized access, and information leakage. Security teams should pair technical controls with organizational and regulatory governance, but treat the recommendations as threat-model guidance rather than measured risk: the study relies on public documentation and lacks primary empirical data.

Threats, Malware & Security Operations Evaluation or comparison Published edition

AI-Driven Threat Detection and Automated Incident Response for Securing Cloud Workloads

Anton Chagovec, Teodora Bakardjieva, Antonina Ivanova, Fatima Sapundzhi, Veselina Spasova, Andriana Ivanova

Applied Sciences · Paper 28 Jun 2026 · Episode 31 Aug 2026

Researchers compared an AI-augmented cloud security architecture integrating SIEM, XDR, behavioral analytics, AI-assisted correlation and SOAR with manual triage and signature-based controls across phishing-led account takeover, multi-stage ransomware and shadow-IT exfiltration scenarios. For SOCs, the study supports evaluating integrated automation for cloud response, but its 30-day window and selected scenarios limit generalisation; ambiguous social-engineering and encrypted-content cases still require analyst judgment.

Cloud, SaaS & Infrastructure Policy or conceptual analysis Published edition

Enterprise Infrastructure Modernization Framework for Hybrid Cloud Transformation: A Governed Workload-Centered Approach

Ashok Gopalakrishnan

openalex · Paper 19 Jul 2026 · Episode 31 Aug 2026

Gopalakrishnan organizes hybrid-cloud modernization around workload assessment, strategy selection, target architecture, platform engineering, and continuing governance, with readiness checks linking design, build, migration, operations, and optimization. Security and platform teams can use those checks to keep controls and monitoring from becoming post-migration cleanup, but the evidence comes from specific enterprise programs rather than a randomized study and may not transfer uniformly elsewhere.

Cloud, SaaS & Infrastructure Evaluation or comparison Preprint

Enterprise Integration Modernization with SAP BTP

Shunmukha Sagar Puppala

openalex · Paper 21 Jul 2026 · Episode 31 Aug 2026

Using a synthetic enterprise landscape, Puppala compared legacy point-to-point integration with an SAP BTP-centered architecture and measured lower latency, recovery time and failed-message rates. Security and integration teams can use the framework to prioritize fragile, business-critical interfaces and embed access control, audit and runtime visibility, but the synthetic data cannot establish that the gains will carry into every real enterprise.

Governance, Risk, Law & Human Factors Policy or conceptual analysis Published edition

Cryptocurrency as a Payment Method for Ransomware Cybercrime Lockbit Ransomware and the Implementation of Cyberlaw and Cybersecurity

Seri Mughni Sulubara, Rizky Maulana, Nurkhalisah

Legalita · Paper 19 Jul 2026 · Episode 31 Aug 2026

Using a normative legal analysis of Indonesian criminal, electronic-information and personal-data law, the paper argues that cryptocurrency enables LockBit ransom payments, while leaked wallet addresses and blockchain forensics can support tracing and possible wallet freezes. Enforcement remains difficult because attackers use TOR/VPN and international perpetrators present jurisdictional difficulties, while Indonesian regulations are not yet specific to cryptocurrency ransom and do not fully capture double extortion.

Cloud, SaaS & Infrastructure Policy or conceptual analysis Preprint

A Control-Driven Framework for Secure SaaS Onboarding in Regulated Enterprises

Naga Sundeep Krishna Thota, Rithika Dulam

openalex · Paper 16 Jul 2026 · Episode 31 Aug 2026

Thota and Dulam propose a control-driven SaaS onboarding lifecycle integrating vendor risk, cybersecurity, identity, and DR, while distinguishing vendor-level assurance from validation of enterprise-specific tenant configurations. The framework maps control activities to responsible owners and evidence artifacts. Recovery objectives depend on vendor contractual commitments, and vendor attestations cannot substitute for platform-specific tabletop exercises.

Governance, Risk, Law & Human Factors Empirical measurement Published edition

The Influence of Cybersecurity Practices on Project Management in Software Engineering

Shaymaa A. Chyad, Fırdews A. Alsalman, Esra Zuhair Majeed

International Journal Of Electrical Engineering And Intelligent Computing · Paper 27 Aug 2026 · Episode 31 Aug 2026

In a survey of 128 software engineering experts, stronger risk management preparedness was associated with more favorable perceptions of timeline management, budgeting and team collaboration. Respondents also identified training, budget constraints, unclear roles, late cybersecurity integration and limited collaboration as challenges. The findings suggest ongoing training, budget planning, role definition and earlier cybersecurity inclusion, but self-reported, purposively sampled perceptions may be biased and may not generalize.

Threats, Malware & Security Operations Policy or conceptual analysis Published edition

SECURING HEALTHCARE INFORMATION SYSTEMS AGAINST RANSOMWARE: A RISK-BASED FRAMEWORK

Luqman Ali

World Journal of Advanced Engineering Technology and Sciences · Paper 20 Aug 2026 · Episode 31 Aug 2026

Ali proposed a healthcare ransomware framework that assesses threats based on asset criticality, vulnerability severity, likelihood of exploitation and potential operational impact, then includes preventive, detective, response and recovery controls. It can help organisations allocate scarce cybersecurity resources to protect critical services and patient safety, but incomplete incident data and variation among hospitals mean conclusions from selected cases and representative settings may not apply everywhere.

Governance, Risk, Law & Human Factors Survey or review Preprint

Workplace Surveillance and Insider Threat Risk Management: Legal Limits and Privacy Harms

Haywood Gelman, John D. Hastings, Suvineetha Herath, Quentin Covert

arXiv · Paper 19 Aug 2026 · Episode 27 Aug 2026

Through a literature review of workplace surveillance tools, practices, laws and privacy harms, the researchers identified gaps in monitoring transparency, insider-threat education and the use of behavioral indicators in detection systems. Security teams can use its recommendations to focus monitoring on work-related signals and reduce log noise, but the paper warns that excessive logging creates operator alert fatigue and uniform federal rules may overlook regional privacy differences.

AI Systems & Agent Security Benchmark or dataset Accepted manuscript

AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Edoardo Debenedetti, Jie Zhang, Mislav Balunović, Luca Beurer-Kellner, Marc Fischer, Florian Tramèr

38th Conference on Neural Information Processing Systems (NeurIPS 2024), Datasets and Benchmarks Track · Paper 18 Jun 2024 · Episode 25 Aug 2026

AgentDojo turns prompt-injection evaluation into an executable, stateful test: tool-using agents must complete legitimate tasks while deterministic checks detect adversarial effects. Security teams can use it to compare tested defenses, but its dataset is synthetic and static, users assigning multiple tasks over time without context reset are not covered, and comparisons must be pinned to exact versions because an implementation bug was fixed and Travel was updated.

AI Systems & Agent Security Attack study Preprint

Universal and Transferable Adversarial Attacks on Aligned Language Models

Andy Zou, Zifan Wang, Nicholas Carlini, Milad Nasr, J. Zico Kolter, Matt Fredrikson

arXiv preprint · Paper 26 Jul 2023 · Episode 25 Aug 2026

Zou and colleagues automated jailbreak discovery by optimizing reusable adversarial suffixes on source models, then measured transfer to held-out harmful requests and several other models, with success varying sharply by target. Security teams can use this pattern for repeatable evaluations, but the tests covered prohibited text generation at a 2023 snapshot—not consequential agent compromise or durability across model and API updates.

AI Systems & Agent Security Attack study Preprint

Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, Mario Fritz

16th ACM Workshop on Artificial Intelligence and Security (AISec 2023) · Paper 25 Nov 2023 · Episode 25 Aug 2026

Across controlled LLM applications and Bing Chat, Greshake and colleagues showed that adversarial instructions in retrieved content could steer responses, trigger tool-mediated data leakage, spread through synthetic email, and persist through memory. Security teams should treat retrieved data as a possible control input, while recognizing that the study did not estimate attack success rates or test public poisoning.

Software, Application & Supply-Chain Security System or technique Published edition

Sigstore: Software Signing for Everybody

Zachary Newman, John Speed Meyers, Santiago Torres-Arias

Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS ’22) · Paper 6 Nov 2022 · Episode 25 Aug 2026

Newman, Meyers, and Torres-Arias combined identity-based short-lived certificates, transparency logs, trust-root distribution, and usable clients into Sigstore, while measurements found online verification took roughly 1.5 seconds in their setup. Release and identity teams can reduce persistent-key handling, but they still need authorization policy, monitoring, and recovery plans because a valid signature does not prove safe code or stop a compromised account.

Governance, Risk, Law & Human Factors Attack study Published edition

The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections

Michael A. Specter, James Koppel, Daniel Weitzner

29th USENIX Security Symposium · Paper 11 Aug 2020 · Episode 25 Aug 2026

The researchers tested Voatz’s Android client against a researcher-built server and found that device, network-path, identity-service, and API-server adversaries could variously suppress or alter ballots, learn secret votes, or expose identity and IP information. A malicious API server could act before blockchain processing. They urged publication of source, design, threat models, and operational details while noting they did not test production backend, iOS client, blockchain, audit portal, or live configuration.

Vulnerability Research & Exploitation Empirical measurement Preprint

Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus Instability

Philip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li, Xueyuan Zhao, Iddo Bentov, Lorenz Breidenbach, Ari Juels

2020 IEEE Symposium on Security and Privacy · Paper 17 May 2020 · Episode 25 Aug 2026

Daian and colleagues measured decentralized-exchange ordering competition and documented bots repeatedly raising transaction fees to win profitable positions, while framing miners’ inclusion, exclusion and ordering power as extractable value. Detection engineers and protocol architects should treat transaction ordering as a security incentive, but the measured market was only a lower bound and the study demonstrated feasible reordering, not a consensus reorganization caused by miner extractable value.

Privacy, Cryptography & Data Security Attack study Published edition

Extracting Training Data from Large Language Models

Nicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Úlfar Erlingsson, Alina Oprea, Colin Raffel

30th USENIX Security Symposium · Paper 10 Aug 2021 · Episode 25 Aug 2026

The study used black-box generation and ranking against GPT-2, confirming 604 unique memorized training examples among 1,800 inspected candidates and showing that a low average train-test loss gap did not prevent rare examples from having anomalously low loss. It proposed curation, deduplication, downstream filtering and model audits as complementary mitigations, but did not measure private-data extraction rates in deployed proprietary models.

AI Systems & Agent Security Attack study Published edition

Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples

Anish Athalye, Nicholas Carlini, David Wagner

35th International Conference on Machine Learning · Paper 9 Jul 2018 · Episode 25 Aug 2026

Researchers found that seven of nine selected ICLR 2018 defenses claiming white-box robustness relied on obfuscated gradients; adaptive attacks fully bypassed six and partially bypassed one within their stated threat models. After every defense change, attacks must adapt again; however, the evidence covers only selected non-certified defenses, while defenses with provable-security claims and a defense claiming only black-box security were excluded.

AI Systems & Agent Security Attack study Published edition

Towards Evaluating the Robustness of Neural Networks

Nicholas Carlini, David Wagner

38th IEEE Symposium on Security and Privacy · Paper 21 May 2017 · Episode 25 Aug 2026

Carlini and Wagner built targeted optimization attacks across multiple pixel-distance measures and achieved 100% success on distilled and undistilled MNIST and CIFAR-10 networks, tracing much of the apparent protection to scaled outputs and vanishing gradients. Model-security teams should test defenses with attacks adapted to their mechanisms, while recognizing that the evidence comes from white-box image-classification benchmarks whose pixel distances do not fully represent human similarity or operational security.

Privacy, Cryptography & Data Security Attack study Published edition

Membership Inference Attacks Against Machine Learning Models

Reza Shokri, Marco Stronati, Congzheng Song, Vitaly Shmatikov

2017 IEEE Symposium on Security and Privacy · Paper 21 May 2017 · Episode 25 Aug 2026

Shokri and colleagues trained shadow models to learn how confidence outputs differ between training members and non-members, demonstrating membership inference through black-box prediction access across local and cloud models. For security teams, the results motivate leakage audits and consideration of differential privacy, but the balanced laboratory tests do not represent settings where membership is rare, and the study documented no victim harmed in the wild.

AI Systems & Agent Security Attack study Published edition

Stealing Machine Learning Models via Prediction APIs

Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart

25th USENIX Security Symposium (USENIX Security 16) · Paper 9 Aug 2016 · Episode 25 Aug 2026

For multiclass logistic regression, prediction API responses enabled exact parameter extraction, while the paper distinguished this from improper extraction that duplicates useful behavior. Extracted models in the evaluated online Amazon and BigML case studies agreed with every tested input. Preprocessing and response structure exposed feature information. The work did not evaluate ensembles, contemporary deep architectures, distributed attackers, adaptive defenses, or production-grade monitoring.

Privacy, Cryptography & Data Security System or technique Accepted manuscript

Deep Learning with Differential Privacy

Martín Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang

2016 ACM SIGSAC Conference on Computer and Communications Security · Paper 30 Jun 2016 · Episode 25 Aug 2026

Abadi and colleagues made neural-network training differentially private by clipping each example’s gradient, adding calibrated Gaussian noise, and tracking accumulated privacy loss more tightly across training steps. Security and privacy teams can treat this as a design pattern, but the guarantee was mainly example-level and the benchmark experiments were neither production deployments nor audits of the full training pipeline.

Privacy, Cryptography & Data Security System or technique Published edition

Towards Making Systems Forget with Machine Unlearning

Yinzhi Cao, Junfeng Yang

2015 IEEE Symposium on Security and Privacy · Paper 16 May 2015 · Episode 25 Aug 2026

Cao and Yang made selected training records removable by storing reusable sums, then subtracting a record’s contribution; across the evaluated systems, this was sometimes much faster than retraining and reversed constructed poisoning effects. Detection engineers can treat unlearning as an incident-recovery primitive, but the study mostly checked prediction agreement and attack repair, not equivalent model distributions or privacy extraction, and it left record identification to other processes.

Privacy, Cryptography & Data Security Attack study Published edition

Model Inversion Attacks That Exploit Confidence Information and Basic Countermeasures

Matt Fredrikson, Somesh Jha, Thomas Ristenpart

22nd ACM SIGSAC Conference on Computer and Communications Security (CCS 2015) · Paper 11 Oct 2015 · Episode 25 Aug 2026

Fredrikson, Jha, and Ristenpart tested model inversion against confidence-bearing decision trees and face classifiers, inferring sensitive survey responses and producing identity-linked face representatives. Security teams should treat confidence precision as a privacy-relevant design choice and test whether coarser outputs help, but the face images were not recovered training photos and the evaluated countermeasures were explicitly basic.

Network & Communications Security Policy or conceptual analysis Accepted manuscript

Outside the Closed World: On Using Machine Learning for Network Intrusion Detection

Robin Sommer, Vern Paxson

2010 IEEE Symposium on Security and Privacy · Paper 17 May 2010 · Episode 25 Aug 2026

Sommer and Paxson explain why machine-learning network intrusion detectors often work better at finding activity resembling known examples than at identifying genuinely novel attacks from normal-traffic models. Detection teams should define a narrow threat model, validate with real traffic and independent ground truth, and compare against simpler rules; because the work is conceptual and largely intuitive, it does not prove that all machine-learning detectors fail.

AI Systems & Agent Security Policy or conceptual analysis Published edition

Can Machine Learning Be Secure?

Marco Barreno, Blaine Nelson, Russell Sears, Anthony D. Joseph, J. D. Tygar

2006 ACM Symposium on Information, Computer and Communications Security (ASIACCS 2006) · Paper 20 Mar 2006 · Episode 25 Aug 2026

Barreno and colleagues organized attacks on machine-learning systems by whether adversaries alter training or probe the learner, how broadly they target inputs, and whether they cause integrity or availability failures; they also analyzed how malicious training points can shift a simple online detector. Security teams should treat training and query interfaces as attack surfaces, but the proposed defenses were speculative and were not validated on realistic learners.

Privacy, Cryptography & Data Security System or technique Corrected edition

Bulletproofs: Short Proofs for Confidential Transactions and More

Benedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra, Pieter Wuille, Greg Maxwell

39th IEEE Symposium on Security and Privacy · Paper 20 May 2018 · Episode 25 Aug 2026

Bulletproofs compresses range proofs without a trusted setup: proof bytes grow logarithmically, including when same-width proofs are aggregated, while proving and verification work remain linear. For confidential-transaction teams, that can reduce permanent ledger data, but deployments must price verification and denial-of-service cost, bind every public input into Fiat-Shamir transcripts, and plan around the scheme’s discrete-logarithm and long-term quantum risks.

Privacy, Cryptography & Data Security System or technique Published edition

Zerocash: Decentralized Anonymous Payments from Bitcoin

Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, Madars Virza

2014 IEEE Symposium on Security and Privacy · Paper 17 May 2014 · Episode 25 Aug 2026

Zerocash lets a public ledger enforce ownership, balance, and non-double-spending while hiding payment origin, destination, and amount, and was evaluated through a research prototype and modeled network. It supports ledger-level private validation, not end-to-end anonymity or production readiness; its guarantees depend on cryptographic primitives, correct circuitry, trusted setup, and security proofs, and exclude network traffic, wallet endpoints, exchanges, and human payment behavior.

Privacy, Cryptography & Data Security Empirical measurement Accepted manuscript

The Web Never Forgets: Persistent Tracking Mechanisms in the Wild

Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juarez, Arvind Narayanan, Claudia Diaz

21st ACM Conference on Computer and Communications Security (CCS 2014) · Paper 2 Nov 2014 · Episode 25 Aug 2026

Acar and colleagues measured canvas fingerprinting, evercookie respawning and cookie synchronization in large web crawls, finding that separate identifiers could restore or connect tracking state, while third-party-cookie blocking reduced but did not eliminate synchronization. Browser and privacy teams should coordinate state clearing and layer defenses, but the desktop Firefox, homepage-heavy dataset and unobserved back-end mergers limit claims about broader environments.

Privacy, Cryptography & Data Security System or technique Accepted manuscript

RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal Response

Úlfar Erlingsson, Vasyl Pihur, Aleksandra Korolova

2014 ACM SIGSAC Conference on Computer and Communications Security · Paper 2 Nov 2014 · Episode 25 Aug 2026

RAPPOR lets a collector estimate population statistics from values randomized on each client, reducing access to unmodified data, but useful accuracy can demand enormous samples. For security telemetry teams, it offers a way to reduce reliance on a trusted central collector; rare or changing values, correlated collection, candidate-list construction, and implementation choices can still undermine utility or longitudinal privacy.

Privacy, Cryptography & Data Security System or technique Corrected edition

Pinocchio: Nearly Practical Verifiable Computation

Bryan Parno, Craig Gentry, Jon Howell, Mariana Raykova

2013 IEEE Symposium on Security and Privacy · Paper 18 May 2013 · Episode 25 Aug 2026

Pinocchio compiled a restricted subset of C into pairing-based proofs that remained 288 bytes regardless of computation size, and typically let anyone verify seven evaluated applications in about 10 milliseconds. For security engineering, public verification can reduce trust in outsourced workers, but the prototype was not a drop-in cloud verifier: it required function-specific setup, used large evaluation keys, supported constrained programs, and three applications did not beat native execution.

Privacy, Cryptography & Data Security System or technique Accepted manuscript

Path ORAM: An Extremely Simple Oblivious RAM Protocol

Emil Stefanov, Marten van Dijk, Elaine Shi, Christopher Fletcher, Ling Ren, Xiangyao Yu, Srinivas Devadas

20th ACM Conference on Computer and Communications Security (CCS 2013) · Paper 3 Nov 2013 · Episode 25 Aug 2026

Stefanov and colleagues present a tree protocol in which the server stores encrypted real and dummy blocks, while the client stores a position map and stash. Each logical access remaps the target, reads its old full path, updates the block, and writes back a padded, re-encrypted path. The evaluation does not cover independent cloud-service deployment, multi-tenant concurrency, or end-to-end application privacy, and timing leakage is explicitly excluded.

Privacy, Cryptography & Data Security Attack study Published edition

Robust De-anonymization of Large Sparse Datasets

Arvind Narayanan, Vitaly Shmatikov

2008 IEEE Symposium on Security and Privacy · Paper 17 May 2008 · Episode 25 Aug 2026

Narayanan and Shmatikov matched sparse Netflix rating histories against outside clues; in one noisy 8-rating experiment, 99 percent of released records were uniquely identified, and linked profiles exposed attributes absent from those clues. Security teams should treat row-level behavioral releases as linkable and use risk-tested controls, but that rate is dataset-specific and the small IMDb test lacked verified identities.

Privacy, Cryptography & Data Security System or technique Corrected edition

Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data

Vipul Goyal, Omkant Pandey, Amit Sahai, Brent Waters

13th ACM Conference on Computer and Communications Security (CCS 2006) · Paper 29 Oct 2006 · Episode 25 Aug 2026

Vipul Goyal and colleagues introduced a key-policy form of attribute-based encryption in which ciphertext attributes are tested against access policies embedded in decryption keys, with resistance to combining individually unauthorized keys. The design may suit encrypted audit logs or targeted distribution, but deployment requires separate solutions for revocation, exposed attributes, compromised issuers, and other lifecycle gaps the work did not solve.

Privacy, Cryptography & Data Security System or technique Accepted manuscript

Calibrating Noise to Sensitivity in Private Data Analysis

Cynthia Dwork, Frank McSherry, Kobbi Nissim, Adam Smith

Third Theory of Cryptography Conference (TCC 2006) · Paper 3 Mar 2006 · Episode 25 Aug 2026

Privacy is defined through transcript probabilities against arbitrary adversaries and auxiliary knowledge, with one-row adjacency but no specified person, household, device, document, or user-level contribution model. Independent Laplace noise scaled to vector-query sensitivity divided by epsilon provides the guarantee. Epsilon is a policy parameter; the theory reports no software implementation, production deployment, performance evaluation, or empirical privacy audit and does not analyze floating-point, random-number, timing, or metadata channels.

Threats, Malware & Security Operations Empirical measurement Published edition

Understanding the Mirai Botnet

Manos Antonakakis, Tim April, Michael Bailey, Matthew Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J. Alex Halderman, Luca Invernizzi, Michalis Kallitsis, Deepak Kumar, Chaz Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas, Yi Zhou

26th USENIX Security Symposium · Paper 15 Aug 2017 · Episode 25 Aug 2026

Antonakakis and colleagues combined Internet-scale sensing, honeypots, malware, DNS, command observations and victim traces to reconstruct how Mirai found exposed Telnet services, tried hard-coded credentials and received distributed-denial-of-service orders. For defenders, the evidence supports closing management services by default and maintaining secure update and end-of-life processes, but it covers only visible activity and selected traces—not every device, operator or harm.

Endpoint, Device & Hardware Security System or technique Published edition

Security Enhanced (SE) Android: Bringing Flexible MAC to Android

Stephen Smalley, Robert Craig

20th Annual Network and Distributed System Security Symposium (NDSS 2013) · Paper 24 Feb 2013 · Episode 25 Aug 2026

Smalley and Craig integrated SELinux policy across Android, including Binder, and showed in tested exploit cases that obtaining the root user identity could still leave a process confined without broader SELinux authority. Android platform and vendor security teams can use that model to narrow allowed operations, but policy cannot block actions it permits or generally repair kernel flaws, so the results do not establish an ecosystem-wide compromise-prevention rate.

Cloud, SaaS & Infrastructure Attack study Accepted manuscript

Cross-VM Side Channels and Their Use to Extract Private Keys

Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart

19th ACM Conference on Computer and Communications Security (CCS 2012) · Paper 15 Oct 2012 · Episode 25 Aug 2026

Zhang and colleagues used Prime-and-Probe measurements of L1 instruction-cache activity between co-resident virtual machines, then classified noisy traces and searched a reduced candidate set to recover an ElGamal private key in a controlled Xen experiment. The result did not require exploiting the hypervisor or directly reading victim memory, but depended on favorable laboratory conditions, repeated decryptions, known victim code, and a secret-dependent implementation; public-cloud placement was not demonstrated.

Endpoint, Device & Hardware Security Attack study Published edition

Comprehensive Experimental Analyses of Automotive Attack Surfaces

Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno

20th USENIX Security Symposium · Paper 9 Aug 2011 · Episode 25 Aug 2026

Checkoway and colleagues built working paths into automotive networks through crafted media, a dealership service device, Bluetooth, and cellular telematics, then demonstrated remote control and surveillance capabilities after compromise. Vehicle and fleet defenders should restrict interfaces, strengthen authentication, monitor behavior, and protect updates, while recognizing that the experiments covered a single unnamed model and a pair of equivalent vehicles, not prevalence or portability across manufacturers.

Endpoint, Device & Hardware Security Empirical measurement Published edition

Android Permissions Demystified

Adrienne Porter Felt, Erika Chin, Steve Hanna, Dawn Song, David Wagner

Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS '11) · Paper 16 Oct 2011 · Episode 25 Aug 2026

By instrumenting Android 2.2 and comparing compiled app calls with manifest requests, the researchers estimated that 30.4 percent of 795 fully handled Android Market apps requested unnecessary permissions. For mobile security teams, that supports better permission mapping and documentation, but the corpus was a 2011 snapshot, complex reflection was unresolved, and the analysis never quantified how many overprivileged apps it missed.

Privacy, Cryptography & Data Security System or technique Published edition

TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones

William Enck, Peter Gilbert, Byung-Gon Chun, Landon P. Cox, Jaeyeon Jung, Patrick McDaniel, Anmol N. Sheth

9th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2010) · Paper 5 Oct 2010 · Episode 25 Aug 2026

Enck and colleagues modified Android to attach labels to sensitive data and follow explicit flows across variables, files, messages and selected libraries, flagging 68 potentially misused flows across 20 of 30 tested apps. For detection and mobile-security teams, it demonstrates why observing data use can add context beyond permissions, but the Android 2.1-era, manually exercised sample and incomplete native and control-flow tracking limit generalisation.

Endpoint, Device & Hardware Security Attack study Accepted manuscript

Experimental Security Analysis of a Modern Automobile

Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage

2010 IEEE Symposium on Security and Privacy · Paper 15 May 2010 · Episode 25 Aug 2026

Using custom CAN capture, replay and fuzzing tools on two same-model 2009 cars, researchers showed that unauthenticated internal messages could falsify displays, manipulate body functions, disrupt engines, and engage or release brakes, while compromised components could bridge network separation and persist. Cybersecurity teams should therefore test post-compromise containment, detection, fail-safe behavior, and recovery, but the study assumed internal-network access and did not establish remote exploitability or prevalence across vehicle platforms.

Cloud, SaaS & Infrastructure Attack study Published edition

Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds

Thomas Ristenpart, Eran Tromer, Hovav Shacham, Stefan Savage

Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS '09) · Paper 8 Nov 2009 · Episode 25 Aug 2026

Ristenpart and colleagues showed that an ordinary cloud customer could map EC2 placement, launch probe virtual machines, sometimes reach physical-host co-residence with a chosen target, and demonstrate controlled cross-VM leakage rather than theft from an unrelated customer. Cloud security teams should treat shared hardware as an observable attack surface, but the measured placement economics were deployment-specific and no real customer secret was extracted.

Software, Application & Supply-Chain Security System or technique Published edition

in-toto: Providing farm-to-table guarantees for bits and bytes

Santiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola, Justin Cappos

28th USENIX Security Symposium · Paper 15 Aug 2019 · Episode 25 Aug 2026

in-toto has project owners sign a supply-chain policy, authorized actors sign evidence for each step, and clients check a delivered artifact against both. Security teams can use thresholds and role separation to limit a compromised authorized actor, but the model trusts owner and functionary keys, and the evaluation did not test long-term organizational operation.

Privacy, Cryptography & Data Security Empirical measurement Accepted manuscript

Online Tracking: A 1-Million-Site Measurement and Analysis

Steven Englehardt, Arvind Narayanan

Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS '16) · Paper 23 Oct 2016 · Episode 25 Aug 2026

Englehardt and Narayanan used a full Firefox-based crawl of the Alexa top 1 million sites to measure cookies, third parties, cookie syncing and browser fingerprinting at web scale. Security and privacy teams can reuse that measurement mindset, but the results are a lower bound: the crawl visited only homepages, performed no interaction or login, used one US East vantage, and omitted known techniques.

Identity & Access Formal analysis or verification Accepted manuscript

A Comprehensive Formal Security Analysis of OAuth 2.0

Daniel Fett, Ralf Küsters, Guido Schmitz

Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security · Paper 23 Oct 2016 · Episode 25 Aug 2026

Fett, Küsters, and Schmitz modeled the OAuth grant types together, identified several attack patterns, and checked variants in real software and a website. Identity teams can apply the proposed issuer, redirect, state, and user-intent checks during design review, but the proof depends on stated assumptions and does not cover implementation code, token expiry, logout, or revocation.

Privacy, Cryptography & Data Security Attack study Published edition

Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice

David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta, Benjamin VanderSloot, Eric Wustrow, Santiago Zanella-Béguelin, Paul Zimmermann

22nd ACM Conference on Computer and Communications Security (CCS '15) · Paper 12 Oct 2015 · Episode 25 Aug 2026

Adrian and colleagues demonstrated Logjam: an active TLS downgrade that forced export-grade ephemeral Diffie-Hellman, then used reusable prime-specific computation to compromise sessions; their precomputation enabled attacks on more than 7 percent of Alexa Top Million HTTPS sites. Defenders should remove export suites and weak finite-field groups, but the broader 1024-bit nation-state scenario remained an uncertain extrapolation rather than a demonstrated computation or attribution.

Network & Communications Security System or technique Published edition

ZMap: Fast Internet-Wide Scanning and its Security Applications

Zakir Durumeric, Eric Wustrow, J. Alex Halderman

22nd USENIX Security Symposium (USENIX Security 13) · Paper 13 Aug 2013 · Episode 25 Aug 2026

Durumeric, Wustrow and Halderman built a stateless scanner that made comprehensive, single-port public-IPv4 surveys practical on a commodity machine; on their gigabit system, a scan took about 44 minutes. For exposure teams, that enables repeatable discovery, but an address response does not establish the application or owner, and a single probe can miss responsive web hosts.

Identity & Access Attack study Published edition

On Breaking SAML: Be Whoever You Want to Be

Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann, Meiko Jensen

21st USENIX Security Symposium · Paper 9 Aug 2012 · Episode 25 Aug 2026

Using systematically generated structural SAML message variants, the researchers examined how signature verification and claim processing may select different XML nodes. SAML integrations should preserve signed-element provenance and pass only content established as signed to application logic. Because the evaluation covered particular systems and generated variants, its findings do not establish exposure beyond the evaluated setting.

Privacy, Cryptography & Data Security Empirical measurement Published edition

Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices

Nadia Heninger, Zakir Durumeric, Eric Wustrow, J. Alex Halderman

21st USENIX Security Symposium (USENIX Security 12) · Paper 7 Aug 2012 · Episode 25 Aug 2026

Using Internet-wide TLS and SSH measurements, Heninger and colleagues found shared RSA factors and repeated signing values that exposed private keys, while widespread reuse also reflected manufacturer defaults. Security teams should block key generation until randomness is ready and regenerate weak keys, but the scan covered only publicly reachable IPv4 endpoints on selected ports and device attribution was strongest for recognizable clusters.

Network & Communications Security Empirical measurement Published edition

The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software

Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh, Vitaly Shmatikov

19th ACM Conference on Computer and Communications Security · Paper 15 Oct 2012 · Episode 25 Aug 2026

Georgiev and colleagues tested non-browser clients and libraries with adversarial certificate cases and found missing certificate-chain validation and hostname matching, with low-level interfaces, middleware, legacy dependencies and attempted fixes contributing to failures. Security engineers should test both checks throughout the software stack, but the sampled applications and study scope limit how broadly these findings can be applied.

Software, Application & Supply-Chain Security Attack study Published edition

A Look in the Mirror: Attacks on Package Managers

Justin Cappos, Justin Samuel, Scott Baker, John H. Hartman

15th ACM Conference on Computer and Communications Security (CCS 2008) · Paper 26 Oct 2008 · Episode 25 Aug 2026

An examination of ten package managers in their 2008 configurations found each exposed to at least one malicious-mirror or network-intermediary attack, including replay of correctly signed old state, dependency metadata manipulation, or resource exhaustion from unbounded responses. Practitioners should authenticate repository metadata, compare repository versions, use signed expiration to detect indefinite freezes, and bound downloads, but these historical configurations do not establish how today’s package ecosystems behave.

Endpoint, Device & Hardware Security Attack study Preprint

Spectre Attacks: Exploiting Speculative Execution

Paul Kocher, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, Yuval Yarom

arXiv · Paper 2 Jan 2018 · Episode 25 Aug 2026

Researchers showed that conditional-branch mistraining and indirect-branch target poisoning could encode secrets in cache state and expose memory in native programs and a Chrome browser process, where language and same-process sandbox checks were transiently bypassed. Conditional-branch behavior was observed on tested Intel and AMD processors, with initial ARM confirmation. Exploitability depends on CPU, software, compiler choices, and attacker interaction, while long-term solutions require processor changes.

Endpoint, Device & Hardware Security Attack study Published edition

Meltdown: Reading Kernel Memory from User Space

Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, Mike Hamburg

27th USENIX Security Symposium (USENIX Security 18) · Paper 14 Aug 2018 · Episode 25 Aug 2026

Lipp and colleagues showed that affected processors could transiently use supervisor-only bytes before rejecting a user-mode load, then recover those bytes through cache traces; page-table isolation blocked ordinary kernel and physical mappings in their tests. Defenders should preserve that isolation and scrutinize minimal mapped transition pages, while recognizing that the controlled cloud work did not establish cross-customer exploitation.

Endpoint, Device & Hardware Security System or technique Published edition

CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization

Robert N. M. Watson, Jonathan Woodruff, Peter G. Neumann, Simon W. Moore, Jonathan Anderson, David Chisnall, Nirav Dave, Brooks Davis, Khilan Gudka, Ben Laurie, Steven J. Murdoch, Robert Norton, Michael Roe, Stacey Son, Munraj Vadera

2015 IEEE Symposium on Security and Privacy · Paper 17 May 2015 · Episode 25 Aug 2026

Analysis of tcpdump covered 29 historical vulnerabilities, and the combined compartments addressed all but two. The cited evidence also reports cycle counts for function, libcheri, and process transitions, without establishing a comparative performance conclusion. Base CHERI does not natively provide temporal safety, while threat-model, trusted-code, and side-channel limitations also apply.

Endpoint, Device & Hardware Security Attack study Published edition

Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors

Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, Onur Mutlu

41st Annual International Symposium on Computer Architecture · Paper 13 Jun 2014 · Episode 25 Aug 2026

Kim and colleagues showed that repeatedly activating and closing DDR3 memory rows could flip bits in other rows that software never touched, with errors appearing in over 80 percent of tested modules and chips. For security teams, this exposed a possible path to cross-process corruption, crashes or control hijacking, but the study did not build such an attack, and its PARA mitigation was simulated rather than implemented.

Software, Application & Supply-Chain Security System or technique Published edition

Modeling and Discovering Vulnerabilities with Code Property Graphs

Fabian Yamaguchi, Nico Golde, Daniel Arp, Konrad Rieck

35th IEEE Symposium on Security and Privacy · Paper 17 May 2014 · Episode 25 Aug 2026

Yamaguchi and colleagues combined source syntax, control flow, and program dependencies in a queryable code property graph, then used traversals to identify 18 previously unknown kernel vulnerabilities that developers addressed. Analysts can refine these traversals to balance false alarms against missed findings, but static analysis cannot cover runtime-dependent behavior, and this implementation analyzed within individual functions rather than across calls.

Endpoint, Device & Hardware Security Formal analysis or verification Published edition

seL4: Formal Verification of an OS Kernel

Gerwin Klein, Kevin Elphinstone, Gernot Heiser, June Andronick, David Cock, Philip Derrin, Dhammika Elkaduwe, Kai Engelhardt, Rafal Kolanski, Michael Norrish, Thomas Sewell, Harvey Tuch, Simon Winwood

22nd ACM Symposium on Operating Systems Principles (SOSP '09) · Paper 10 Oct 2009 · Episode 25 Aug 2026

Klein and colleagues used Isabelle/HOL to prove that seL4’s C kernel implementation stayed within behavior allowed by an abstract specification and, within modeled assumptions, excluded crashes, null or misaligned pointer dereferences, assertion failures, and non-terminating kernel calls. Security architects can use that assurance to strengthen isolation, but the result did not verify compiler, assembly, hardware, boot and memory-management assumptions, multiprocessor concurrency, or timing-channel resistance.

Vulnerability Research & Exploitation Attack study Published edition

The Geometry of Innocent Flesh on the Bone: Return-into-libc without Function Calls (on the x86)

Hovav Shacham

Proceedings of the 14th ACM Conference on Computer and Communications Security · Paper 27 Oct 2007 · Episode 25 Aug 2026

Shacham showed that short, return-terminated instruction sequences already present in an x86 process could be chained into a manually built 12-word program that invoked execve on a shell path while write-xor-execute stayed active. Defenders should treat non-executable writable memory as incomplete protection against code reuse, while recognizing that the evaluation covered one older 32-bit Linux/glibc build and did not compare modern mitigations or exploit reliability.

Vulnerability Research & Exploitation System or technique Published edition

Automated Whitebox Fuzz Testing

Patrice Godefroid, Michael Y. Levin, David Molnar

Network and Distributed System Security Symposium 2008 · Paper 7 Feb 2008 · Episode 25 Aug 2026

SAGE executes concrete inputs, records x86 binary traces, symbolically collects input-dependent path constraints, negates selected predicates and solves them to generate new inputs. The authors report more than 30 previously unknown bugs in shipped Windows applications; exploitability remained their assessment. Coverage was not a universal predictor of crashes, and SAGE’s incomplete heuristic exploration cannot prove that unexplored paths or bugs are absent.

Identity & Access Empirical measurement Published edition

Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms

Patrick Gage Kelley, Saranga Komanduri, Michelle L. Mazurek, Richard Shay, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Julio López

2012 IEEE Symposium on Security and Privacy · Paper 19 May 2012 · Episode 25 Aug 2026

Kelley and colleagues ranked 12,000 study passwords under 31 combinations of cracking algorithms and training data, finding that policy comparisons changed with the attack budget and that matched training data improved cracking against stronger-policy groups. Defenders can use attacker-aware rankings to compare policy choices, but the estimates are model-specific, one lookup stopped at 50 trillion guesses, and the study did not cover every attack type.

Identity & Access Policy or conceptual analysis Published edition

The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes

Joseph Bonneau, Cormac Herley, Paul C. van Oorschot, Frank Stajano

2012 IEEE Symposium on Security and Privacy · Paper 22 May 2012 · Episode 25 Aug 2026

Bonneau and colleagues compared 35 web authentication schemes across usability, deployability and security, finding that none preserved every password benefit while improving on it. For identity teams, the framework supports lifecycle-level evaluation rather than choosing by login strength alone; its expert ratings were not controlled measurements. Coverage of mobile use, migration and business incentives was omitted or compressed, and complete recovery lifecycles were not evaluated.

Governance, Risk, Law & Human Factors Policy or conceptual analysis Published edition

So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users

Cormac Herley

New Security Paradigms Workshop (NSPW 2009) · Paper 7 Sep 2009 · Episode 25 Aug 2026

Herley compares the user cost of password, URL-inspection and certificate-warning advice with the losses those behaviours might prevent, arguing that rejection can be rational when compliance costs exceed expected avoided harm. Security teams should measure harms, target at-risk users, prioritise and retire advice—but the URL estimate depends on victimisation, cleanup-time and wage assumptions, and the work does not encourage users to ignore policies or advice.

Identity & Access Empirical measurement Accepted manuscript

Why Phishing Works

Rachna Dhamija, J. D. Tygar, Marti Hearst

Proceedings of the SIGCHI Conference on Human Factors in Computing Systems (CHI 2006) · Paper 21 Apr 2006 · Episode 25 Aug 2026

In a 22-person study, the strongest replica fooled 20 participants, average error was about 40 percent, and passive browser security indicators plus a tested certificate warning often failed. Security teams should make untrusted states conspicuous rather than depend only on positive indicators, while recognizing that the small sample could not establish demographic or experience effects.

Privacy, Cryptography & Data Security Attack study Published edition

Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing

Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, Thomas Ristenpart

23rd USENIX Security Symposium · Paper 19 Aug 2014 · Episode 25 Aug 2026

Using black-box access to a warfarin dose model, patient-specific facts, and population priors, the researchers inferred VKORC1 genotype up to 22 percentage points above a 36 percent majority baseline. Health-model security teams should test leakage against realistic prior-based baselines and clinical harm, but not generalize this result: success depended on the model, auxiliary data, population assumptions, and a simulated rather than deployed clinical setting.

Endpoint, Device & Hardware Security Formal analysis or verification Preprint

Granite: A Modular Methodology for Foundational Verification of Hardware-Software Leakage Contracts

Stella Lau, Andres Erbsen, Adam Chlipala

arXiv (Cornell University) · Paper 28 Jul 2026 · Episode 23 Aug 2026

Granite uses machine-checked proofs to connect an instruction-set leakage specification to cycle-by-cycle behavior in a synthesizable pipelined processor, then demonstrates integration with a proved static analysis for constant-time programming. The processor implementation is eliminated from the trusted computing base, but the evaluation uses a minimal single-hardware-thread RISC design and excludes power, within-cycle timing, and physical-access channels.

Threats, Malware & Security Operations Survey or review Published edition

Anomaly Detection using Knowledge Graphs: A Survey for Network Management and Cybersecurity Application

Lionel Tailhardat, Raphaël Troncy, Yoan Chabot

ACM Computing Surveys · Paper 2 Jul 2026 · Episode 23 Aug 2026

The survey compares NMS and SIEM capabilities, semantic network models, and anomaly-detection techniques, finding that heterogeneous data hampers full contextualization of network and service failures. Security teams may use knowledge graphs to connect and reason over disparate telemetry, but should not expect complete automated incident context: current contextualization can omit network topology and operational information.

Privacy, Cryptography & Data Security Empirical measurement Published edition

The Bisq decentralised exchange: on the privacy cost of participation

Liam Hickey, Martin Harrigan

Blockchain Research and Applications · Paper 5 Oct 2021 · Episode 23 Aug 2026

Hickey and Harrigan built Bisq-specific address-clustering heuristics from Bitcoin transaction structure and Bisq peer-to-peer data, linking trading and governance activity across addresses and uncovering aliases that sometimes included real-world names. Bisq privacy engineers could offer optional dummy-transfer tooling and guidance, but it adds transaction cost, and possible false-positive alias links and deliberately induced false negatives limit confidence.

AI Systems & Agent Security Attack study Preprint

Evaluation and Hardening of LLM System Instructions Against Extraction via Encoding Attacks

Anubhab Sahu, Diptisha Samanta, Reza Soosahabi

arXiv (Cornell University) · Paper 31 Mar 2026 · Episode 23 Aug 2026

Sahu, Samanta and Soosahabi tested whether models that refused direct system-instruction requests would leak protected content when asked to encode or serialize it; structured formats produced the highest leakage rates, while small instruction rewrites reduced leakage. Security teams can add these transformations to pre-deployment tests and harden instruction wording, but the evaluation covered a limited model set and omitted possible multistage attacks.

Software, Application & Supply-Chain Security System or technique Preprint

AgenticRepair: Multi-Faceted Program Context Engineering for Agentic Vulnerability Repair

Michael Fu, Qiyue Mei, Patanamon Thongtanunam, Kla Tantithamthavorn

arXiv (Cornell University) · Paper 30 Jul 2026 · Episode 23 Aug 2026

AgenticRepair combined code-structure, runtime-execution, and commit-history analysis with a dedicated repair agent, fixing 73% of 300 SEC-Bench cases and outperforming its strongest comparable baseline by 29%. The results support richer context and patch-integrity checks in repair workflows, but not autonomous deployment: the evaluation is limited to SEC-Bench, and generated patches still require functional review beyond sanitizer success.

Governance, Risk, Law & Human Factors Policy or conceptual analysis Published edition

Cybersecurity laws, digital crimes, and ethical considerations: a multidimensional perspective on Cyber Risk Regulation (MPoCRR)

Jafar Ababneh, Abdulmajeed Alzara, Hani Attar, Ala’a Al-Shaikh, Amer Abu-Jassar, Mohamed Hafez

Journal of Cloud Computing Advances Systems and Applications · Paper 28 Jun 2026 · Episode 23 Aug 2026

Using secondary sources and structured qualitative matrices, researchers compared GDPR, HIPAA and NIS on legislative scope, enforcement and ethical sensitivity, concluding that existing regulation is fragmented and reactive to global, AI-enhanced threats. The proposed unified framework integrates data protection, AI ethics and legal compliance, but enforcement of extraterritorial rules such as GDPR is politically contested, and transplanted rules can fail without appropriate national implementation mechanisms.

Threats, Malware & Security Operations Policy or conceptual analysis Published edition

Exploiting Cybersecurity Vulnerabilities for Financial Crime: An Integrated Framework for Understanding Fraudster Tactics, Digital Attack Pathways, and Financial Loss Prevention

Unknown author

International Research Journal of Modernization in Engineering Technology and Science · Paper 11 Aug 2026 · Episode 23 Aug 2026

The study builds an integrated framework linking technical vulnerabilities and fraudster tactics to attack paths, victim exposure, and financial-loss prevention, combining several cyber and financial analysis methods. Security and fraud teams can use that chain to coordinate intervention points, but publicly available datasets may miss emerging or institution-specific fraud patterns, limiting how well model findings carry across financial sectors.

Network & Communications Security System or technique Preprint

TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies

Xiaokang Qu, Jianliang Ma, Zao Fan, Tianshu Chu, Tianlong Fan, Linyuan Lü

arXiv (Cornell University) · Paper 12 Aug 2026 · Episode 23 Aug 2026

TopoIntent converts natural-language business requirements into schema-constrained network topologies, checks topology-visible CIS safeguards, exports Mininet tests, and uses diagnostic feedback to improve policy enforcement; one feedback round raised the post-ACL pass rate from 0.78 to 0.88. This could help practitioners prototype zones, paths, and ACLs with executable checks, but it does not establish organizational CIS certification, and unresolved test endpoints require manual review.

Threats, Malware & Security Operations Evaluation or comparison Preprint

Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis

Adel ElZemity, Shujun Li, Budi Arief

arXiv (Cornell University) · Paper 21 Jul 2026 · Episode 23 Aug 2026

Researchers compared solo language models with four orchestration designs for structured questions about malware detonation reports. In the evaluated benchmark, a hybrid combining evidence retrieval with adversarial peer critique exceeded the strongest cyber-specialized and ungrounded frontier baselines, while grounded Gemini remained stronger. This could support locally deployed analyst assistance, but outputs require human verification; the study assessed multiple-choice report comprehension, not malware detection, low-level binary analysis, or open-ended operational triage.

Threats, Malware & Security Operations Benchmark or dataset Preprint

Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion

Cédric Bonhomme, Alexandre Dulaunoy

arXiv (Cornell University) · Paper 27 Jul 2026 · Episode 23 Aug 2026

The researchers trained a multilabel classifier on expert-curated mappings that outperformed a semantic-similarity baseline across the evaluated ranking metrics. LLM-generated labels provided no reliable improvement and hurt rare-technique coverage at the largest tested expansion. Ranked outputs may help connect vulnerability feeds to detection, prioritisation and risk-assessment workflows, although the curated set is small and expert mappings may omit plausible techniques.

Vulnerability Research & Exploitation Benchmark or dataset Preprint

The Next Challenge for Agentic Cybersecurity: A Realistic, Contamination-Free Reverse Engineering Benchmark

Jeremy Spence (21351782), Nicholas Assaderaghi, Jinhao Zhu, Nikil Ravi, Raluca Ada Popa, Guannan Wei, Yangruibo Ding, Zhuo Zhang

arXiv (Cornell University) · Paper 10 Aug 2026 · Episode 23 Aug 2026

Researchers built SRE-Bench from private, real-world-scale programs with in-house anti-analysis primitives, then tested five frontier models in a standardized agent harness; even the strongest model fully recovered only a minority of binary instances. For practitioners, strong source-code performance is therefore poor evidence of readiness for malware, firmware, or proprietary-binary work, although the benchmark’s breadth is limited to 19 programs.

Endpoint, Device & Hardware Security Attack study Preprint

Transforming Keystroke Noise to Text: Self-Supervised Acoustic Eavesdropping Attacks on Keyboards

Atsunori Okada, Akira Ito, Rei Ueno, Yuichi Hayashi, Naofumi Homma

arXiv (Cornell University) · Paper 23 Jul 2026 · Episode 23 Aug 2026

Okada and colleagues clustered unlabeled keystroke recordings, used Transformer-based language-model inference to resolve uncertain acoustic-to-character mappings, and achieved more than 99% reconstruction accuracy from 100–150 close-range keystrokes in their evaluated setup. Microphones may be leakage paths, but the online-meeting tests disabled noise suppression, which can attenuate keystroke sounds, and exact password recovery remained harder than natural-language reconstruction.

AI Systems & Agent Security Benchmark or dataset Preprint

MaliciousSkillBench: A Comprehensive Benchmark for Malicious Agent Skill Detection

Yue Wang, Yi Liu, Gelei Deng, Ying Zhang, Yuekang Li, Zhenyu Chen, Leo Zhang

arXiv · Paper 17 Aug 2026 · Episode 22 Aug 2026

Researchers consolidated heterogeneous malicious-Skill sources, canonicalized and deduplicated records, separated structural reuse from attack semantics, and found that learned detectors degraded on held-out sources while scanners traded fewer benign false positives for lower malicious recall. For pre-installation screening, test cross-source performance and measure malicious detection alongside benign over-flagging; contributing datasets were built under different assumptions and should not be treated as interchangeable rows.

Network & Communications Security System or technique Preprint

QUASAR: A Quantum-Classical Neural Network for SAR Satellite Physical-Layer Authentication

Vincenzo Sammartino, Nathanael Denis, Roberto Di Pietro

arXiv · Paper 17 Aug 2026 · Episode 22 Aug 2026

Sammartino, Denis and Di Pietro built a hybrid convolutional and variational-quantum classifier for X-band satellite fingerprints, evaluating 37 ICEYE satellites and attacks based on replay, crafted signals and space-borne spoofing. Ground-station defenders may gain a second authentication signal with less training data, but the 28-day, single-constellation evaluation and non-interchangeable learned fingerprints leave cross-system and long-term performance uncertain.