{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_eb6d4428f26e3cfc5515662fe0ca4f43172dc3b9e78c6c284a04eaece523784e","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_eb6d4428f26e3cfc5515662fe0ca4f43172dc3b9e78c6c284a04eaece523784e","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"442398c5b463008d625601a614d80a1a743159fb85cbff7dc10161f35b6feb73","published":"Mon, 13 Jul 2026 00:00:00 -0400","receipt_hash":"442398c5b463008d625601a614d80a1a743159fb85cbff7dc10161f35b6feb73","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"442398c5b463008d625601a614d80a1a743159fb85cbff7dc10161f35b6feb73","observed_at":"2026-07-13T04:43:08.394955Z","parent_run_hash":"900c1c934245e788564e199a9619f2dc36ec91d9804ddd9c6a40fb42c8a1e1c0","published":"Mon, 13 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2607.09653v1 Announce Type: cross \nAbstract: Internet of Things (IoT) systems are inherently vulnerable due to constrained hardware, outdated firmware, and insecure default configurations, creating a need for scalable and adaptive security testing approaches. While recent adoptions of Large Language Model (LLM) agents have demonstrated promise in penetration testing and Capture-the-Flag (CTF) environments, their application to IoT specific vulnerabilities remains unexplored. This paper presents an autonomous multi-agent framework, referred to as Vulnerability EXploitation using AI Agents (VEXAIoT), for vulnerability discovery and exploitation in IoT environments using LLM-based reasoning and offensive security tools. The framework combines a vulnerability detection agent and an attack execution agent to perform reconnaissance, plan attack sequences, and execute exploits against vulnerable IoT services. The system is evaluated in IoTGoat and Metasploitable environments across ten ","title":"VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents","url":"https://arxiv.org/abs/2607.09653","vendor":"arxiv_cs_ai"},"summary":"arXiv:2607.09653v1 Announce Type: cross \nAbstract: Internet of Things (IoT) systems are inherently vulnerable due to constrained hardware, outdated firmware, and insecure default configurations, creating a need for scalable and adaptive security testing approaches. While recent adoptions of Large Language Model (LLM) agents have demonstrated promise in penetration testing and Capture-the-Flag (CTF) environments, their application to IoT specific vulnerabilities remains unexplored. This paper presents an autonomous multi-agent framework, referred to as Vulnerability EXploitation using AI Agents (VEXAIoT), for vulnerability discovery and exploitation in IoT environments using LLM-based reasoning and offensive security tools. The framework combines a vulnerability detection agent and an attack execution agent to perform reconnaissance, plan attack sequences, and execute exploits against vulnerable IoT services. The system is evaluated in IoTGoat and Metasploitable environments across ten ","title":"VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-13T04:43:08Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2607.09653"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:84359ac27965a973ea9040e58c9651a1cdffb8f6d1b5f3333a44313c3c76c4a915b7233f7ddd85a40c9d20381dca161664d52141de6632ce6c643ce93ce28109","signer":"crovia.substrate","subject":{"observed_at":"2026-07-13T04:43:08Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2607.09653"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"9d5be74c198554768e79ed93e20cde07c7eb33b2072f9e62f600bd89f72e6d3e","leaf_index":309682,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"b499f7d4d6ce796353d6c00b15e029610c55dcb516f4583d40047f5351801459","side":"right"},{"sibling":"4fd74383f8d71da86c6e8c0e64124f2c1a71900479fcf04d1d0fe6a3ea4bfb0f","side":"left"},{"sibling":"9333665c69960d21260e83d17635ab50fc3685fd601a2d71853f01d7d994b40a","side":"right"},{"sibling":"a7b5844935dc2be73146774b0c8af653711dddb56f9c7b31de6bac3bb727c4c2","side":"right"},{"sibling":"ab1c0c6d9d8af83eb8492b80da0fc0eed82a2476d6ceb76af9aa30552af8e309","side":"left"},{"sibling":"817e14c6ab3a66a77efac57ff4cc63efe5efe647afce47f5aefa03dc77fc1f24","side":"left"},{"sibling":"a06f2db4ff89b8806c463205a6d957aa0950263fff991c2aa1386688c611457f","side":"right"},{"sibling":"49f7764de5dea797b32547b8437f6d371cde9fb33ac6cf784651dcfa196b149a","side":"left"},{"sibling":"6cbb0c4695e74fa8ec17dfde89fa56c1958a1d4dffbbcbe3556da4a69c699ebc","side":"left"},{"sibling":"c4bde3283be97905033d39c1097ac73b82f180de8830384fe6f9f1933f7fa4b9","side":"right"},{"sibling":"3b5f968ebea87e7be458ef7e63c6637988d27ba6d170e1f3794d385cd76ca23f","side":"right"},{"sibling":"5ed534e945b31085c140b50460415e7960b76a4b6266da67d272b853dc94b352","side":"left"},{"sibling":"91010b271bc8eb5253b3549292ef3146e1d85bc9bac7ca36e0862f1204f84e8d","side":"left"},{"sibling":"772fbc112e94d8e574379343387c65503d3cf8fb16ff89090174eccced871a41","side":"left"},{"sibling":"5d50450cae1a230f682b390c8e28ae822ec6c0c04a9bc79b0d27af97306ccccd","side":"right"},{"sibling":"d8b9143917b539c543cf4448cec00131f8b807bd8004979c54ebe09798748c66","side":"left"},{"sibling":"e9ac4b1e71d3f572751b7984e9ca00893d71628137b4634e82df02cf3db9ab68","side":"right"},{"sibling":"99ff86058e045249bf936a629308be31e4cc71328f0282c4a924f4e6718be5f0","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":309862,"merkle_root":"f18a76abb66e7cb448986b6541091416ed4ebdde8124f5208a7c7c94bb4165d1","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260713T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-13T05:38:23Z","sig_algorithm":"ed25519","signature":"0488e3527b1d559ba55116220f91e2f6c22bb5358a135e8a9b94a65450b50511702044fa993555662ebca09f005b277f5f6ad0d044ec96a5568e9993c09ef007","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_eb6d4428f26e3cfc5515662fe0ca4f43172dc3b9e78c6c284a04eaece523784e"}}