<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>privilege escalation Topic Archive</title>
<link>privilege-escalation.html</link>
<description>关键词 privilege escalation 的长期追踪 RSS，汇总历史命中文献。</description>
<language>zh-CN</language>
<lastBuildDate>Sun, 28 Jun 2026 05:24:06 +0000</lastBuildDate>
<item>
<title>Seeing Is Not Screening: Multimodal Hidden Instruction Attacks on Agent Skill Scanners</title>
<link>../papers/arxiv-fca0d26d69a9.html</link>
<guid>https://arxiv.org/abs/2606.18198v1#2026-06-17#privilege-escalation</guid>
<pubDate>Wed, 17 Jun 2026 14:22:19 +0800</pubDate>
<description>Agent skills are emerging as an important attack surface in LLM-based systems. Through an empirical study of existing skill scanners, we find that current defenses primarily rely on textual descriptions, manifests, and source code as the main signals for security analysis, which can leave visually conveyed malicious intent insufficiently examined. This creates a practical blind spot: harmful operational instructions hidden in images may bypass scanning while still being recoverable by multimoda…</description>
</item>
<item>
<title>Agentic Vulnerability Reasoning on Windows COM Binaries</title>
<link>../papers/arxiv-fc8295aa4188.html</link>
<guid>https://arxiv.org/abs/2605.05000v1#2026-05-07#privilege-escalation</guid>
<pubDate>Thu, 07 May 2026 12:38:06 +0800</pubDate>
<description>Windows Component Object Model (COM) services run with elevated privileges and are widely accessible to authenticated users, making race conditions in these binaries a critical surface for local privilege escalation. We present SLYP, an end-to-end agentic pipeline that discovers race condition vulnerabilities in COM binaries and generates debugger-verified proof-of-concept (PoC) code. SLYP exposes binary exploration, COM inspection, and dynamic debugging as reusable tool interfaces, giving agen…</description>
</item>
</channel>
</rss>
