• A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across four widely used PHP localization repositories. The attack, detected on May 22, 2026, and reported by both Aikido Security and the Socket Research Team, introduces a fully functional remote code execution (RCE) backdoor that executes automatically via Composer’s […]

    The post Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anthropic has published an update on Project Glasswing, its collaborative AI-powered vulnerability discovery initiative launched last month, revealing that Claude Mythos, the company’s most capable and tightly restricted model, has already surfaced more than 10,000 high- or critical-severity zero-day vulnerabilities across the world’s most systemically important software. The findings represent one of the most significant […]

    The post Claude Mythos Preview Discovers 10,000+ 0-Days in Glasswing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • FBI warns of Kali365, a PaaS scam kit that lets cybercriminals bypass MFA and hijack Microsoft 365 accounts without passwords.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Pentagon announced the Replicator Initiative with fanfare in 2023, aiming to field vast numbers of affordable, expendable drones as a strategic counter to China. However, by 2025, the program was limping along due to congressional criticism over stalled progress and the absence of a permanent institutional home or consistent funding.

    The Pentagon officially dissolved Replicator in late 2025, absorbing it into the newly minted Defense Autonomous Warfare Group, or DAWG. Originally allocated a modest $225.9 million in the fiscal year 2026 budget, DAWG was widely expected to be just another iterative defense working group. 

    But the Trump administration’s FY27 budget request has shattered those expectations. The White House is requesting a staggering $54.6 billion for DAWG—a near 24,000 percent increase in a single fiscal year. Reflecting on the scale of the surge, retired general and former CIA Director David Petraeus noted that DAWG represents the “largest single commitment to autonomous warfare in history.” 

    This is no longer a pilot program. The Pentagon has stopped treating autonomous warfare like a startup project and is now funding it like a permanent branch of the American military apparatus. 

    Why did Replicator fail?

    The unprecedented scale of DAWG’s budget is a direct response to the limitations that stalled its predecessor. 

    The Replicator Initiative rushed to procure specific, ready-built drone platforms. However, Replicator’s chosen drones suffered from persistent technical issues, struggled to integrate with existing military command-and-control systems, and were far too expensive and slow to manufacture in the quantity needed. 

    Furthermore, the Pentagon was paralyzed by its own procurement process. It struggled with up-front vetting, finding that many systems were entirely unfinished or purely conceptual. Perhaps most critically, Replicator failed to procure software able to orchestrate and command massive swarms of different drones. 

    Compounding these technological hurdles was an institutional homelessness. Because Replicator never possessed its own dedicated line-item budget, defense officials were forced to constantly reprogram. Frustrated by the lack of transparency regarding long-term lifecycle costs, Congress increasingly pushed back. 

    Managing the $54 billion operational whiplash 

    DAWG is designed to rectify the past mistakes of the Replicator Initiative, but its sudden financial windfall has only introduced more questions. How does an office that managed $225 million last year suddenly oversee $54.6 billion?

    Pushing this massive sum through traditional Pentagon procurement pipelines risks a bottleneck. DAWG simply does not possess the infrastructure (contracting officers, lawyers, program managers etc.) to obligate that volume of capital in a twelve-month cycle. To prevent this, the Pentagon divided DAWG’s funds. 

    Of the $54.6 billion request, only $1 billion sits in the standard, highly restricted base budget. The remaining $53 billion has been tucked away into a flexible future reconciliation pot. This gives DAWG up to five years to obligate the funds. Instead of being forced to frantically dump billions into obsolete hardware before the fiscal clock runs out, DAWG can instead dole out cash incrementally as autonomous technology matures. To ensure long-term viability, DAWG will emphasize procurement, operations, maintenance, training, and sustainment over the first few years before scaling back to ensure active manufacturing lines while avoiding the risk of overproduction

    Will DAWG be different? 

    There are some early signs that the institutional shift to DAWG will be different from the Replicator experience. Unlike Replicator, which sat precariously under the Defense Innovation Unit as a pilot program, DAWG is getting more permanent institutional teeth. Defense Secretary Pete Hegseth recently announced the impending creation of a dedicated Sub-Unified Command for Autonomous Warfare. Simultaneously, U.S. Southern Command has established its own autonomous warfare command, which will work closely with DAWG to identify available expertise and capabilities required for operations. 

    Architecturally, the focus has shifted from hardware to software. Acting Pentagon Comptroller Jules Hurst describes DAWG as a “pathfinder,” embedded with private tech firms, live-testing “orchestration tools for autonomy” and providing real-time combat feedback. This software-focused mentality is demonstrated by the recent announcement that Shield AI has been tapped to integrate its Hivemind AI pilot software into the military’s new Low-Cost Uncrewed Combat Attack System, or LUCAS. Unlike Replicator, DAWG has introduced a new divergent priority to develop sophisticated software that can be flashed onto any cheap drone frame. 

    Yet, lawmakers are starting to raise major red flags. There is a growing anxiety in Congress that the Pentagon’s foundational policy on AI weapons, DoD Directive 3000.09, is completely unequipped for this scale of deployment. The directive mandates “appropriate levels of human judgement,” but when orchestrating thousands of autonomous systems simultaneously, human-in-the-loop oversight becomes a mathematical impossibility. An uncomfortable reality is beginning to emerge: the Pentagon is throwing a military-branch-sized budget at autonomous swarms before deciding on the rules of engagement. 

    Ultimately, the creation of DAWG represents a structural shift rather than a guaranteed technological revolution. By shifting the ad-hoc, hardware-first approach of the Replicator Initiative to a permanent, software-focused funding line, the Pentagon is attempting to fix a broken acquisition pipeline that has historically been unable to move at the speed of commercial technology. 

    However, funding and execution are different. DAWG’s ambitious plans still heavily rely on a congressional reconciliation process that faces a complicated and uncertain political path. Even if the $54.6 billion request is approved, the Pentagon must still solve the immense logistical challenge of integrating thousands of autonomous systems into a joint force that lacks established doctrine for swarm warfare. 

    The Pentagon has clearly signaled where it believes the future of warfare lies. But as DAWG moves from a budget proposal to an operational reality, its success will not be measured by the size of its funding pot, but by whether the military can safely and effectively integrate these algorithmic tools into the reality of modern combat.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Director of National Intelligence Tulsi Gabbard will resign from her role in the coming weeks, her office confirmed to Nextgov/FCW on Friday.

    Gabbard’s husband, Abraham Williams, was “diagnosed with a rare form of bone cancer, and she is stepping away from public service to be by his side and fully support him through this battle,” Olivia Coleman, a spokesperson for the Office of the Director of National Intelligence, said in an email.

    In a Truth Social post that included Gabbard’s resignation note, President Donald Trump said she would be leaving June 30. It marks the fourth major cabinet departure of his second term.

    During Gabbard’s roughly 16-month tenure overseeing the nation’s 18 intelligence agencies, the former Democratic congresswoman and 2020 presidential candidate sought to reshape ODNI around Trump’s priorities while facing persistent scrutiny over her past comments on Russia, Syria, Edward Snowden and surveillance authorities. She was narrowly confirmed to the position in February 2025.

    In office, Gabbard launched a sweeping restructuring effort aimed at shrinking ODNI, including plans to cut staffing and consolidate or eliminate several offices tied to cyber, foreign influence and intelligence integration functions. Supporters framed the moves as long-overdue reforms, while critics warned they could weaken coordination across the intelligence community.

    Gabbard also became a central figure in Trump’s efforts to target former intelligence officials viewed as political adversaries. Last year, she revoked security clearances for dozens of current and former national security officials, accusing some of politicizing intelligence and leaking classified information, which drew sharp criticism from Democrats and former intelligence leaders.

    Her tenure was additionally marked by renewed disputes over U.S. intelligence assessments, including intelligence findings involving Venezuela.

    Gabbard’s political rise was built in part around opposition to U.S. interventionism and what she called “regime change wars,” a posture that at times appeared increasingly at odds with White House actions involving military operations in Iran and Venezuela.

    In March, a Senate hearing highlighted growing tensions between intelligence community assessments of the war in Iran and the administration’s framing of the conflict. It also came a day after the departure of then-aide and National Counterterrorism Center Director Joe Kent, who said he could not agree with the Trump administration’s premise for the war, which was launched alongside Israel in February.

    In the hearing, Gabbard told senators that it’s “not the intelligence community’s responsibility to determine what is and is not an imminent threat” and that the president has authority to make such conclusions.

    In a Friday statement, Sen. Mark Warner, D-Va. the vice chairman of the Senate Intelligence Committee, said his thoughts were with Gabbard and her family. 

    “Anyone who has watched a loved one go through a serious illness understands the toll it takes, and I wish him strength and hope for a full recovery in the difficult days ahead. I also appreciate her willingness to serve her country in a variety of different roles,” he said.

    “The Director of National Intelligence is entrusted with one of the most serious responsibilities in government: providing objective, fact-based intelligence to policymakers and the American people, regardless of politics or pressure from the White House,” added Warner, who often sparred with Gabbard over issues involving her office. 

    “At a time when the boundaries between verified intelligence and politically convenient claims have too often been blurred, it is critical that the office remain grounded in facts, independence, and the rule of law,” he said.

    “I thank Tulsi Gabbard for her service in this administration and in uniform, and I wish her the very best as she supports her husband Abe in his battle with cancer. Please join me in sending them prayers for a full and fast recovery,” said Sen. Tom Cotton, R-Ark., the intelligence committee chairman.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. The disruption of First VPN Service was led by France and the Netherlands, with several other nations supporting the investigation since December

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

    On May 18, KrebsOnSecurity reported that a CISA contractor with administrative access to the agency’s code development platform had created a public GitHub profile called “Private-CISA” that included plaintext credentials to dozens of internal CISA systems. Experts who reviewed the exposed secrets said the commit logs for the code repository showed the CISA contractor disabled GitHub’s built-in protection against publishing sensitive credentials in public repos.

    CISA acknowledged the leak but has not responded to questions about the duration of the data exposure. However, experts who reviewed the now-defunct Private-CISA archive said it was originally created in November 2025, and that it exhibits a pattern consistent with an individual operator using the repository as a working scratchpad or synchronization mechanism rather than a curated project repository.

    In a written statement, CISA said “there is no indication that any sensitive data was compromised as a result of the incident.” But in a May 19 a letter (PDF) to CISA’s Acting Director Nick Andersen, Sen. Maggie Hassan (D-NH) said the credential leak raises serious questions about how such a security lapse could occur at the very agency charged with helping to prevent cyber breaches.

    “This reporting raises serious concerns regarding CISA’s internal policies and procedures at a time of significant cybersecurity threats against U.S. critical infrastructure,” Sen. Hassan wrote.

    A May 19 letter from Sen. Margaret Hassan (D-NH) to the acting director of CISA demanded answers to a dozen questions about the breach.

    Sen. Hassan noted that the incident occurred against the backdrop of major disruptions internally at CISA, which lost more than a third of it workforce and almost all of its senior leaders after the Trump administration forced a series of early retirements, buyouts, and resignations across the agency’s various divisions.

    Rep. Bennie Thompson (D-MS), the ranking member on the House Homeland Security Committee, echoed the senator’s concerns.

    “We are concerned that this incident reflects a diminished security culture and/or an inability for CISA to adequately manage its contract support,” Thompson wrote in a May 19 letter to the acting CISA chief that was co-signed by Rep. Delia Ramirez (D-Ill), the ranking member of the panel’s Subcommittee on Cybersecurity and Infrastructure Protection. “It’s no secret that our adversaries — like China, Russia, and Iran — seek to gain access to and persistence on federal networks. The files contained in the ‘Private-CISA’ repository provided the information, access, and roadmap to do just that.”

    KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets.

    On May 20, KrebsOnSecurity heard from Dylan Ayrey, the creator of TruffleHog, an open-source tool for discovering private keys and other secrets buried in code hosted at GitHub and other public platforms. Ayrey said CISA still hadn’t invalidated an RSA private key exposed in the Private-CISA repo that granted access to a GitHub app which is owned by the CISA enterprise account and installed on the CISA-IT GitHub organization with full access to all code repositories.

    “An attacker with this key can read source code from every repository in the CISA-IT organization, including private repos, register rogue self-hosted runners to hijack CI/CD pipelines and access repository secrets, and modify repository admin settings including branch protection rules, webhooks, and deploy keys,” Ayrey told KrebsOnSecurity. CI/CD stands for Continuous Integration and Continuous Delivery, and it refers to a set of practices used to automate the building, testing and deployment of software.

    KrebsOnSecurity notified CISA about Ayrey’s findings on May 20. CISA acknowledged receipt of that report, but has not responded to follow-up inquiries. Ayrey said CISA appears to have invalidated the exposed RSA private key sometime after that notification. But he noted that CISA still hasn’t rotated leaked credentials tied to other critical security technologies that are deployed across the agency’s technology portfolio (KrebsOnSecurity is not naming those technologies publicly for the time being).

    Ayrey said his company Truffle Security monitors GitHub and a number of other code platforms for exposed keys, and attempts to alert affected accounts to the sensitive data exposure(s). They can do easily on GitHub because the platform publishes a live feed which includes a record of all commits and changes to public code repositories. But he said cybercriminal actors also monitor these public feeds, and are often quick to pounce on API or SSH keys that get inadvertently published in code commits.

    The Private CISA GitHub repo exposed dozens of plaintext credentials to important CISA GovCloud resources. The filenames include AWS-Workspace-Bookmarks-April-6-2026.html, AWS-Workspace-Firefox-Passwords.csv, Important AWS Tokens.txt, kube-config.txt, etc.

    The Private-CISA GitHub repo exposed dozens of plaintext credentials to important CISA GovCloud resources.

    In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, the most egregious of which appears to have happened in late April 2025, Ayrey said.

    “We monitor that firehose of data for keys, and we have tools to try to figure out whose they are,” he said. “We have evidence attackers monitor that firehose as well. Anyone monitoring GitHub events could be sitting on this information.”

    James Wilson, the enterprise technology editor for the Risky Business security podcast, said organizations using GitHub to manage code projects can set top-down policies that prevent employees from disabling GitHub’s protections against publishing secret keys and credentials. But Wilson’s co-host Adam Boileau said it’s not clear that any technology could stop employees from opening their own personal GitHub account and using it to store sensitive and proprietary information.

    “Ultimately, this is a thing you can’t solve with a technical control,” Boileau said on this week’s podcast. “This is a human problem where you’ve hired a contractor to do this work and they have decided of their own volition to use GitHub to synchronize content from a work machine to a home machine. I don’t know what technical controls you could put in place given that this is being done presumably outside of anything CISA managed or even had visibility on.”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine’s National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine (CERT-UA), involves sending phishing emails to government

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SafeDep uncovered the Megalodon attack targeting 5,561 GitHub repositories with malicious CI workflows and cloud credential theft.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers are increasingly abusing Middle East telecommunications networks and hosting providers to operate large-scale command-and-control (C2) infrastructure. The findings highlight a strategic shift away from disposable indicators toward infrastructure-level tracking, allowing defenders to identify persistent patterns behind cyber operations rather than reacting to constantly changing indicators of compromise. The dataset reveals that C2 infrastructure dominates […]

    The post Hackers Exploit Middle East Telecoms for Massive C2 Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶