• Flipper Devices has officially unveiled Flipper One, a modular, Linux-based cyberdeck designed to push the boundaries of open hardware and portable network analysis platforms. Unlike the popular Flipper Zero, the new device targets high-performance networking, software-defined radio (SDR), and embedded Linux development, positioning itself as a powerful toolkit for cybersecurity professionals, researchers, and hardware developers. Flipper […]

    The post Flipper Introduces Flipper One as a Modular Linux-Based Cyberdeck appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Authorities in Europe have dismantled a major criminal VPN service known as “First VPN,” which was widely used by ransomware operators and cybercriminal groups to conceal their activities. The coordinated operation, led by French and Dutch authorities with support from Eurojust and Europol, marks a significant disruption to cybercrime infrastructure across multiple countries. Criminal VPN […]

    The post Authorities Take Down “First VPN” Service Used in Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Nearly seven weeks after an autopilot problem crashed a General Atomics collaborative combat aircraft, the company announced Thursday that its drone wingmen are back in the skies.

    On April 6, a  YFQ-42A “Dark Merlin" crashed at the company airport in California, prompting a joint investigation by the company and the Air Force. General Atomics spokesperson C. Mark Brinkley said flight testing resumed on Wednesday. The company continued ground testing and other evaluations while flight testing was paused. A software problem identified during the investigation has been fixed.

    “A thorough safety review isolated the cause to an autopilot miscalculation for the weight and center of gravity of the aircraft, prompting a software remediation,” General Atomics said in a news release. “Following a stringent evaluation, technical authorities endorsed the software changes and YFQ-42A has returned to the air.”

    No one was injured in the April 6 crash, but the company said the aircraft was a “total loss”. 

    It was one of several production-representative CCAs being made for the Air Force’s drone wingman competition. General Atomics is going head-to-head against Anduril and Northrop Grumman for the service’s business. An Increment 1 production decision is expected before the end of September, and the Air Force is requesting nearly $1 billion to buy its first CCAs, 2027 budget documents released last month show.

    “It’s been said that you learn more from your setbacks than your successes,” General Atomics President David R. Alexander said in the news release. “We are applying what we’ve learned to our growing fleet of CCAs, as we continue building the most dependable and cost-efficient unmanned fighters in the world.”

    Air Force Col. Timothy Helfrich, portfolio acquisition executive for fighters and advanced aircraft, said the incident showed the service’s new willingness to accept risks.

    “The USAF and General Atomics response to the YFQ-42 mishap validates our approach to accept acquisition/test risk instead of operational risk allowing us to accelerate the program towards fielding,” he said in an emailed statement. “We pushed the envelope, identified a risk, learned from the data, and have cleared the YFQ-42A to return to flight.”

    Helfrich stressed that the crash didn’t pause progress on the CCA program. He said the service’s Experimental Operations Unit at Edwards Air Force Base in California flew several sorties with Anduril’s YFQ-44A Fury aircraft the same week General Atomics paused test flights.

    “Despite the pause on one platform, we executed this critical exercise that same week using the YFQ-44A to validate core operational and deployment concepts,” Helfrich said in the statement. “Because of this momentum and our resilient, multi-vendor approach, overall CCA progress never missed a beat as we drive toward delivering advanced capability to the fleet."

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.

    A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a. “Dort,” of Ottawa, Canada with operating the Kimwolf DDoS botnet. A statement from the Department of Justice says the complaint against Butler was unsealed following the defendant’s arrest in Canada by the Ontario Provincial Police pursuant to a U.S. extradition warrant. Butler is currently in Canadian custody awaiting an initial court hearing scheduled for early next week.

    The government said Kimwolf targeted infected devices which were traditionally “firewalled” from the rest of the internet, such as digital photo frames and web cameras. The infected systems were then rented to other cybercriminals, or forced to participate in record-smashing DDoS attacks, as well as assaults that affected Internet address ranges for the Department of Defense. Consequently, the DoD’s Defense Criminal Investigative Service is investigating the case, with assistance from the FBI field office in Anchorage.

    “KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads. “These attacks resulted in financial losses which, for some victims, exceeded one million dollars. The KimWolf botnet is alleged to have issued over 25,000 attack commands.”

    On March 19, U.S. authorities joined international law enforcement partners in seizing the technical infrastructure for Kimwolf and three other large DDoS botnets — named Aisuru, JackSkid and Mossad — that were all competing for the same pool of vulnerable devices.

    On February 28, KrebsOnSecurity identified Butler as the Kimwolf botmaster after digging through his various email addresses, registrations on the cybercrime forums, and posts to public Telegram and Discord servers. However, Dort continued to threaten and harass researchers who helped track down his real-life identity and dramatically slow the spread of his botnet.

    Dort claimed responsibility for at least two swatting attacks targeting the founder of Synthient, a security startup that helped to secure a widespread critical security weakness that Kimwolf was using to spread faster and more effectively than any other IoT botnet out there. Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder Ben Brundage told KrebsOnSecurity he’s relieved Butler is in custody.

    “Hopefully this will end the harassment,” Brundage said.

    An excerpt from the criminal complaint against Butler, detailing how he ordered a swatting attack against Ben Brundage, the founder of the security firm Synthient.

    The government says investigators connected Butler to the administration of the KimWolf botnet through IP address, online account information, transaction records, and online messaging application records obtained through the issuance of legal process. The criminal complaint against Butler (PDF) shows he did little to separate his real-life and cybercriminal identities (something we demonstrated in our February unmasking of Dort).

    In April, the Justice Department joined authorities across Europe in seizing domain names tied to nearly four-dozen DDoS-for-hire services, although because of a bureaucratic mix-up the list of seized domains has remain sealed until today. The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.

    A statement from the Ontario Provincial Police said a search warrant was executed on March 19 at Butler’s address in Ottawa, where they seized multiple devices. As a result of that investigation, Butler was arrested and charged this week with unauthorized user of computer; possession of device to obtain unauthorized use of computer system or to commit mischief; and mischief in relation to computer data. He is scheduled to remain in custody until a hearing on May 26.

    In the United States, Butler is facing one count of aiding and abetting computer intrusion. If extradited, tried and convicted in a U.S. court, Butler could face up to 10 years in prison, although that maximum sentence would likely be heavily tempered by considerations in the U.S. Sentencing Guidelines, which make allowances for mitigating factors such as youth, lack of criminal history and level of cooperation with investigators.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The White House decision to seek about one-quarter of its gargantuan $1.5 trillion defense-spending request as reconciliation funding leaves some of the military’s top priorities—munitions, industrial-base upgrades—up to lawmakers’ appetite for another precedent-breaking budget maneuver.

    The Army, for example, is asking for $24.5 billion to fund purchases through DOD’s Munitions Acceleration Council, according to budget documents. The service is also asking for $206 million to expand and upgrade its own weapons factories—ten times the amount requested in last year’s reconciliation bill.

    “We have all of these incredible things that we're trying to do and move forward, but acceleration is only as good as our counterparts on the Hill are able to push it forward as well, right?” Maj. Gen. Rebecca McElwain, the Army’s budget director, said Thursday during an Association of the United States Army event. “So, if we get our funding halfway through a fiscal year, that could complicate things.”

    Last year’s reconciliation bill is a case in point. After months of back and forth, the bill finally passed in July, with just weeks left in the fiscal year. Then it took the Pentagon another seven months to produce its plan to spend the money, including $2.6 billion for Army procurement.

    And there is no guarantee that Congress—which broke precedents to pass last year’s reconciliation bill—will approve the administration’s request for a new one worth twice as much to the Pentagon.

    “When we're looking at reconciliation, you can see very clearly what will not be accelerated, and a lot of that is in our munitions and our industrial base,” McElwain said. “I would say that would slow it down, especially some of the multi-year programs that we have that are vested in there with the munitions.”

    The Army doesn’t decide which parts of its funding request will go into which bill, and the administration hasn’t been open about its strategy to fund so much of the government through reconciliation.

    The difference in funding types means that an appropriations bill has line-by-line mandates for how each dollar is spent, while a reconciliation bill is a big check that the department can ultimately divvy up as it sees fit, though Congress makes recommendations and agencies report back their spending plans. 

    “Mr. Secretary, the administration is taking an enormous risk by asking for $350 billion in priorities through reconciliation,” Rep. Betty McCollum, D-Minn., the ranking member of the House Appropriations Subcommittee on Defense, told Defense Secretary Pete Hegseth earlier this month.  “As we told you in our last meeting, reconciliation is not the best way to fund the department. Last year, reconciliation created broken glass—funding holds for vital programs that the appropriators had to fix. And that's why we need the information in a timely fashion.”

    Her concern is a bipartisan one. Sen. Mitch McConnell, R-Ky., who chairs the Senate Appropriations defense subcommittee, railed against the reconciliation bill last year and recently lamented the administration’s request for a new one.

    “The distinction between base and reconciliation really matters,” McConnell said during a hearing earlier this month. “Base funding is what creates budget stability for the services and sends consistent demand signals to industry, and base funding is what gets extended by short-term continuing resolutions when work on full-year appropriations is unfinished.”

    McConnell cautioned against a Republican administration relying on a Republican majority to get its budget requests funded, especially for money that goes toward longer-term investments.

    “As I said last year, reconciliation should be a supplement to, not a substitute for,” he said. “Political realities will not always allow for party line, budget reconciliation, and if the department's top priorities aren't built into annual appropriations. We're actually taking a big risk.”

    There are also concerns about the timing of how separate pots of money are distributed, Sen. Chris Coons, D-Del., SAC-D’s ranking member, said at the same hearing.

    “Last year, $150 billion was provided to the department, but the mismatch between base year and one-year, between long-term and short-term, caused tens of billions of dollars in errors,” he said. “Errors in how shipbuilding was handled, errors in how new munitions are being acquired. And working together on a bipartisan basis, we fixed many of those problems.” 

    Coons warned that this year’s near-tripling of that amount could result in even more of those errors.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Deleted Google API Keys remain active for up to 23 minutes after deletion, exposing GCP, Gemini, BigQuery, and Maps data to attackers.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. “Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files, and functioning as a SOCKS5 proxy,” Lumen

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Europol has seized First VPN, a service used by ransomware gangs, arrested its administrator and gained access to data linked to thousands of users.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical authentication bypass vulnerability in Apache OFBiz allows attackers to hijack forced password-change flows and achieve remote code execution (RCE) via a single HTTP request, affecting all versions before 24.09.06. Apache OFBiz RCE Flaw Apache OFBiz is an open-source Enterprise Resource Planning (ERP) platform used for managing business processes. When an administrator flags a […]

    The post Apache OFBiz RCE Flaw Abuses Password-Change Restrictions for Authentication Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust. That is what makes it worrying. The danger is in normal things now – updates, apps, cloud buttons, support chats, trusted accounts. AI

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶