• The Office of Personnel Management is set to propose requiring all federal employees to sign a nondisclosure agreement barring them from divulging “confidential” information in most cases, a move that experts warn violate workers’ First Amendment rights and statutes aimed at protecting whistleblowers from retaliation.

    OPM announced its plan in a filing set for publication in the Federal Register Wednesday. In justifying the requirement, officials cited reporting in Government Executive and other news outlets disclosing controversial proposals to overhaul federal layoff and performance management rules—and internal warnings against their implementation—prior to their formal publication.

    “Unauthorized disclosures of confidential government information disrupt agency operations and erode public trust,” OPM wrote. “In recent months, unauthorized disclosures have included internal government materials not intended for public release such as pre-decisional documents and interagency comments exchanged during internal coordination processes . . . Such disclosures risk chilling candid interagency feedback, disrupting orderly decision-making and weakening trust within and among federal agencies.”

    According to a draft copy of the proposed NDA, feds would be required to sign a document barring them from disclosing information related to internal agency operations, personnel and procurement matters and “any sensitive, pre-decisional or deliberative material” and vowing to inform their agency if they learn of others making such a disclosure.

    The draft NDA includes language stating that it does not conflict with the Whistleblower Protection Act, and that whistleblowers may continue to disclose information either to Congress or their agency’s inspector general’s office. But Kevin Owen, a partner at Gilbert Employment Law, a firm that specializes in federal employment issues, described those exceptions as mere “lip service.”

    “Time and time again, we see circumstances where whistleblowers try to go through internal channels—either through an IG or agencies like the Office of Special Counsel—and for one reason or another, either they’re overburdened with work, or with this administration particularly, politically captured and therefore don’t do the necessary work,” Owen said. “So a lot of those channels are ineffective. Only once wrongdoing becomes more widely known is there an appropriate remedy to the waste, fraud and abuse going on. Simply having OPM pick and choose the channels for whistleblowers is not in accordance with the Whistleblower Protection Act.”

    Michael Fallings, managing partner at Tully Rinckey, another federal employment law firm, said it will be hard to gauge the NDA’s true impact until a final draft is released, likely after OPM’s 30-day comment period. As things stand now, much of the document’s language is “over-broad,” he said.

    “When you’re dealing with NDAs, you have to be careful about impacting somebody’s rights to engage in protected activity,” he said. “Even in the private sector, they still have the right to disclose waste, fraud and abuse, and with government entities, you have to be careful of employees’ First Amendment rights as well. That’s the fear of a lot of the employee rights organizations and attorneys right now, especially given what has happened with this administration and the sense that it is trying to prevent employees from speaking out.”

    Owen noted that federal agencies already have longstanding rules governing the unauthorized disclosure of internal government information. OPM’s proposed NDA, which the agency explicitly tied to its effort to assert governmentwide firing power through suitability determinations, could create a new class of federal firings, shielded from Merit Systems Protection Board oversight. An employee deemed unsuitable not only would lose their job but also could be barred from being rehired into government for up to five years.

    “The impact of this is, coupled with other recent changes to its regulations, OPM could become the sole arbiter of whether it is abiding by these rules,” he said. “OPM is now trying to become this super personnel office that centralizes its authority over all federal employees, ostensibly at the direction of the White House. By now controlling how federal employees are even able to communicate about matters of political concern, it’s one further step toward enacting a spoils system and making the civil service a political arm of the White House.”

    Everett Kelley, national president of the American Federation of Government Employees, blasted the proposal as an effort to “silence” federal workers.

    “This proposed NDA is another attempt by the administration to purge the civil service of nonpartisan career employees and replace them with loyalists who won’t speak out against waste, fraud and abuse,” he said. “Federal employees do not surrender their First Amendment rights when they accept federal employment, and the public has a right to know about this administration’s abuses.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware and steal data.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anthropic says its Claude Mythos AI identified more than 10,000 software vulnerabilities in one month, including critical flaws in open-source code.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026. The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • India’s national cyber security agency CERT-In has issued a new blueprint that tells organizations to fix critical vulnerabilities in internet‑facing and “crown‑jewel” systems within 12 hours of discovery, as AI‑driven attackers slash exploitation timelines. The guidance marks one of India’s most aggressive expectations yet on patching speed for exposed infrastructure. CERT-In’s 38‑page document, titled “Blueprint […]

    The post CERT-In Mandates 12-Hour Patch Deadline for Internet-Facing Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Quasar Linux (QLNX) is a new, stealthy Linux Remote Access Trojan that quietly turns developer and DevOps workstations into high‑value beachheads for software supply‑chain attacks, using fileless execution, an eBPF rootkit, PAM backdoors, and a P2P C2 mesh to evade conventional defenses. Despite its name, it is unrelated to the Windows‑focused QuasarRAT family. It is […]

    The post Quasar RAT Hits Developers With Fileless Linux Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The European Union is preparing to issue a landmark penalty against Google under its Digital Markets Act (DMA), marking a significant escalation in regulatory enforcement against major technology platforms. According to multiple reports, EU regulators have formally accused Alphabet’s Google of manipulating search results to prioritize its own services, raising concerns about fair competition, platform […]

    The post EU Regulators Prepare Landmark Fine Against Google Under Digital Markets Act appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop. According to recent updates from The Hacker News, bad actors are using AI to find weak spots in systems and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – May. 26, 2026

    Watch the YouTube video

    According to the Wall Street Journal, criminals increasingly use generative AI to mimic real people’s voices and con their loved ones out of money. There’s a simple solution to the high-tech problem of vishing and deepfake scams: a code word.

    Experts recommend a word that is simple and easy to remember, yet something only family members would know. It should be shared only with trusted family members. If you worry you’ll forget the code word, storing it in a secure password manager is regarded as a best practice.

    With cybercrime on an unprecedented growth track, and predicted to cost the world $12.2 trillion annually by 2031, according to Cybersecurity Ventures, it’s imperative to protect yourself and your family, and a solution this simple is too important to ignore.

    A new 2-minute video on the award-winning Cybercrime Magazine YouTube channel tells the story of a Philadelphia attorney and his son, who’s voice was spoofed by artificial intelligence, a harrowing encounter resulting in a near loss of thousands of dollars.

    Scott Schober, a global cybersecurity expert and author of the popular book Hacked Again, chimes in with advice on selecting a good family code word, and avoiding a bad one.

    Watch the Video



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Deepfakes And Vishing Scams: Why Every Family Needs A Code Word. appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. “Deserialization of untrusted data in Microsoft Office SharePoint allows

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶