LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveIdentity Visibility in 2026: The Foundation of Identity SecurityCVE-2026-28299 · SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
vulnerability

Intent injection attacks are a new worry for AI-native 6G networks

Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstraction gives attackers new openings, and it tests two machine-learning detectors against one of them. Threat model−Malicious

zeroday.news ·

Researchers from the University of Ottawa and Nokia Bell Labs have identified a new class of threat, termed adversarial intent injection, targeting AI-native 6G networks that utilize intent-based networking (IBN). This attack vector exploits the abstraction inherent in IBN systems, where operators define desired outcomes and software translates these into network policies. The researchers demonstrated that malicious instructions can be hidden among legitimate ones, posing a significant risk to future network architectures.

Intent-based networking relies on machine-readable requests, often in JSON format, which are then converted into network policies. The primary entry point for an adversarial intent injection attack is a compromised API key, allowing an attacker to submit malicious intents disguised as routine updates. Potential consequences include denial of service, privilege escalation, traffic redirection, and the creation of backdoors within the network.

To evaluate this threat, the research team constructed a dataset of 1,100 intents, partially generated with the assistance of a large language model. This dataset included 20 base attack intents, covering scenarios like phishing and data exfiltration, each with nine variants. An example variant involved transforming a rule that drops traffic with logging enabled into one that null-routes traffic with limited logging. To introduce ambiguity, 40 malicious intents were relabeled as benign, and 90 benign intents were relabeled as malicious.

A simple rule-based classifier, built with 88 terms identified as strong discriminators, was used as a baseline. This classifier detected approximately 10% of malicious intents across the full dataset, although 96% of the intents it flagged were indeed malicious. This suggests that simple keyword detection is insufficient for comprehensive protection.

The researchers developed two machine learning detectors designed to identify malicious intent injections by analyzing the sequence and timing of requests. They created four versions of their data, varying the arrival patterns of malicious intents: fixed average pace, random scattering, speeding up over time, and slowing down. The detectors analyze short sequences of up to six consecutive requests, flagging runs that are likely to contain malicious activity for human review.

The first detector, trained on labeled examples of safe and malicious activity, achieved detection rates between 75% and 96% of runs containing malicious requests, depending on the attack pattern. The second detector, which learns only from normal activity and flags deviations, performed best across three of the four attack patterns. However, it struggled with fixed-pace attacks, missing approximately one-third of those runs. Both detectors outperformed an earlier method that evaluated requests individually, which detected roughly 50% to 60% of malicious cases across the four patterns.

Future work planned by the team includes incorporating more diverse JSON policy configurations to better reflect real-world IBN deployments. They also intend to use explainable-AI methods to make the detection decisions of their systems more transparent and interpretable for network operators.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details

vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

nation-state

Gopass: Open-source command-line password manager for teams

Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each secret with GPG and keeps the store in a git repository. Git gives a team a record of every change and a way to sync one store across laptops

ai

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents. The researchers trace the exposure to workflows designed around people. Approvals, handoffs, and manual except

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]