Mitre ATT&CK
PulseAugur coverage of Mitre ATT&CK — every cluster mentioning Mitre ATT&CK across labs, papers, and developer communities, ranked by signal.
- used by cyber threat intelligence 80%
- affiliated with Common Vulnerabilities and Exposures ID 70%
- used by Common Vulnerabilities and Exposures ID 70%
- used by ScienceCast 70%
- used by Gotit.pub 70%
- used by DagsHub 70%
- used by CatalyzeX 70%
- used by National Vulnerability Database 70%
- used by alphaXiv 70%
- used by Royal Galician Academy 70%
- affiliated with MITRE ATLAS 70%
- affiliated with cyber threat intelligence 60%
2 day(s) with sentiment data
-
New system AHLERT automates threat hunting lead generation from CTI reports
Researchers have developed AHLERT, a novel system designed to automatically generate actionable threat hunting leads from Cyber Threat Intelligence (CTI) reports. Unlike previous methods that focus solely on entities or…
-
New LLM framework BEACON constructs cyber threat intelligence knowledge graphs
Researchers have developed BEACON, a new framework that uses LLMs to construct knowledge graphs from cyber threat intelligence (CTI) reports. This approach anchors extracted information to standardized attack behaviors …
-
Trust Gateway pipeline refines security with 12-stage verification
The Trust Gateway, previously mislabeled as a firewall, is now a 12-stage verification pipeline designed to deny requests at any stage. It incorporates prompt injection detection rules and argument inspection, though th…
-
New AUTOSIGMA system automates cyber threat intelligence to Sigma rule generation
Researchers have developed AUTOSIGMA, an automated system designed to convert unstructured cyber threat intelligence (CTI) into actionable Sigma rules for threat detection. This system enhances rule generation by integr…
-
New CTIFoundry corpus scaffold boosts LLM agent cyber threat intelligence
Researchers have introduced CTIFoundry, a new corpus scaffold designed to enhance the capabilities of LLM agents in cyber threat intelligence (CTI). This system structures CTI data by creating an ontology graph from aut…
-
AI code generation pipeline tackles security vulnerabilities
A new research paper introduces an automated pipeline designed to detect and fix security vulnerabilities in code generated by AI development tools. The pipeline processes code from LLM-generated prompts, uses tools lik…
-
New theory certifies risk for automated security decisions
A new paper introduces a decision-contract theory to address the challenge of certifying risk for automated security decisions, particularly in the context of LLM-based intrusion detection systems. The theory aims to pr…
-
New framework TTP-R1 enhances cyber threat intelligence analysis
Researchers have developed TTP-R1, a novel two-stage framework designed to improve the extraction of attack techniques from cyber threat intelligence (CTI) text. This framework combines retrieval-augmented supervised fi…
-
AI Recommendation Poisoning: "Summarize with AI" buttons can corrupt LLM memory
Microsoft has identified a new threat called AI Recommendation Poisoning, where seemingly innocuous "Summarize with AI" buttons can permanently alter an LLM assistant's memory. By clicking a specially crafted link, user…
-
L1.9 prompt injection screening system rebrands, plans public corpus release
The L1.9 system, previously referred to as a firewall, is being renamed to prompt injection screening. This change reflects its function as a static pre-admission filter rather than a runtime enforcement layer. The deve…
-
Generative AI tool AegisShield democratizes cyber threat modeling
Researchers have developed AegisShield, a generative AI tool designed to automate and simplify cyber threat modeling, particularly for organizations with limited resources. The tool integrates the STRIDE framework and M…
-
MITRE ATLAS adds agentic attack techniques to AI threat catalog
MITRE has updated its Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS) knowledge base to include specific techniques targeting autonomous AI agents. These new techniques, such as AI Supply Chain …
-
New AI system ThreatForest automates attack tree generation from code
Researchers have developed ThreatForest, a novel multi-agent system designed to automate threat modeling for cloud-native software development. This system analyzes code repositories to generate structured attack trees,…
-
New paper maps CVEs to MITRE ATT&CK using expert-labeled data
A new research paper details a method for mapping Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK techniques using a classifier trained on 1,207 expert-labeled CVEs. The study found that using LLM-generated …
-
TRACE-CTI framework enhances audibility of cyber threat intelligence claims
A new framework called TRACE-CTI has been developed to improve the audibility and governance of cyber threat intelligence (CTI) claims extracted by automated systems. This framework preserves evidence, provenance, and v…
-
New Classifier Maps CVEs to MITRE ATT&CK Techniques, LLM Labeling Shows No Benefit
Researchers have developed a reproducible pipeline to map Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK Enterprise techniques using free-text descriptions. Their custom-trained classifier, built on expert-…
-
Sakana AI launches Fugu-Cyber for cybersecurity tasks · 2 sources tracked
Sakana AI has launched Fugu-Cyber, an orchestration model specifically tuned for cybersecurity tasks. This model achieved 86.9% on the CyberGym benchmark and 72.1% on the CTI-REALM benchmark, positioning it as a competi…
-
Open-weight LLMs evaluated for autonomous vehicle threat intelligence generation
Researchers have developed a new dataset, CAV-STIXGen, to evaluate open-weight Large Language Models (LLMs) in generating structured threat information for autonomous vehicle vulnerabilities. The study assessed 11 LLMs,…
-
Developer builds 8-layer defense after trojan hits MCP marketplace
A developer recently discovered a Windows trojan, Trojan:Win64/Lazy.PGPK!MTB, within a skill package on their Model Context Protocol (MCP) marketplace. The malware was disguised as a legitimate GitHub repository through…
-
Coding agents trigger security alerts by mimicking attacker behavior · 1 source tracked
A recent report from Sophos highlights how coding agents like Claude Code, Cursor, and OpenAI Codex can inadvertently trigger security alerts on endpoints. These agents, while performing legitimate tasks such as automat…