• Hybrid engines are in the news as consumers seek relief from gas prices boosted by the war on Iran, but military customers are also looking beyond internal combustion.

    “There's a lot of interest in battery-operated, electric-driven drones…but there's also a lot of interest in heavy, fuel-based drones” that use JP-8, says Greg Thompson, president of Survice Engineering. “Batteries are great, they're very clean, they're very efficient. But transporting them, maintaining them, storing them, charging them—all that can be a little bit of a growth phase…and so there's still this hunger for a fuel-based drone, and so we're trying to marry that together. Think of it like a hybrid car, like a Prius.” 

    For the past year, Survice Engineering has been developing a hybrid-powered drone that it hopes to show defense customers later this year. The plan is to have a suite of electric only, fuel-based hybrid, and fuel-only drones in the Group 3 and above category. 

    “We are looking at maybe late summer, early fall timeframe to be able to demonstrate to our customers at least a concept of what we can bring to market,” Thompson said of the hybrid option. “That hybrid gen set is part of what's next for us…and also continuing to develop the next higher-level platform that gives them the next class up in terms of lift, something that does hundreds of pounds and gives them more, more mission capability in terms of things like [casualty evacuation] and bigger payloads.”

    Hybrid-powered drones are quieter and can have a longer flying range compared to gas-only ones.. And their military use could be beneficial for surveillance operations or ferrying cargo long distances, such as across the Indo-Pacific. They could also serve as an alternative for purely battery-powered drones, which can lose precious energy capacity in different temperatures

    And drone companies are increasingly spending capital to build hybrid offerings, said Michael Robbins, president and CEO of the drone trade group AUVSI. 

    “You are seeing a lot of companies investing in research and innovation in hybrid propulsion, particularly as the focus increasingly shifts, at least in theory, to the Indo-Pacon region, where “In the Indo-Pacom theater, range is always a challenge. With the exception of maybe some very niche use cases like pre-positioned assets on Taiwan, virtually every other use case is going to not rely upon battery technology alone. And it's going to be some combination of jet-powered or some sort of hybrid propulsion,” Robbins said. 

    “Drones grew primarily as a commercial technology. And for a long time because of FAA regulations, the drones were limited to a fairly narrow operation area, typically within line of sight of the operator. So range wasn't a top consideration in the same way it is for military missions. And now the Pentagon is getting very serious about drone acquisition and different use cases…I think there is a growing market for companies to enter into that space.”

    Welcome

    You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and song recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!

    More amphibs please. The Marine Corps needs at least 40 amphibious ships—nine more than statutorily required, Navy officials told the Senate Armed Services Committee on Tuesday. And if funded, it’ll take six years to get there. 

    • That figure came out of an internal Amphibious Forces Readiness Board report that Acting Navy Secretary Hung Cao recommended to the defense secretary ahead of Tuesday’s hearing. The vice chief of naval operations and assistant commandant of the Marine Corps lead the board.
    • The report has “two courses of action and the course of action that we would like to pursue would be able to extend the [Optimized Fleet Response Plan] up to 56 months, allowing us to have two work up cycles, two integrated training cycles, as well as two deployments for every ship,” Cao testified. “So, for that, we would require 40 amphibious ships. Right now, we're at 31.”
    • Adm. Daryl Caudle, chief of naval operations, said, “Forty just makes a lot of sense. It's going to take that to give me the friction in there necessary to have a persistent 3.0”—that is, to have three ARGs ready at any time. Caudle echoed Gen. Eric Smith, Marine Corps commandant, who argued the same in Defense One, and Lt. Gen. Jay Bargeron, deputy commandant for plans, policies, and operations, speaking at this year’s Modern Day Marine conference.
    • Background: Just about half of the Navy’s 32 amphibious ships are in deployable shape, the Government Accountability Office found in 2024. 
    • The 2026 procurement budget for amphibs is about $4.6 billion, according to budget documents. The request for 2027 is about $8.3 billion for two amphibious ships and six Medium Landing Ships or LSMs. 
    • Over the next five years, the Navy plans to spend $29.3 billion for five LPDs, two LHAs, and 23 LSMs, according to the Navy’s latest 30-year shipbuilding plan released last week. 

    Making mobile data centers. Armada, which makes mobile data centers in shipping containers, secured $230 million in a series B funding round, which will be used to expand manufacturing in its Arizona facility. The company’s valuation now sits around $2 billion.

    • “This is really how we need to go about winning this AI race,” CEO Dan Wright told reporters. “First and foremost, it's a manufacturing and infrastructure production problem: we have to be able to deploy AI both domestically and with allies faster than our adversaries or potential adversaries.” 
    • The company plans to increase production in its Arizona facility of its largest offering, the Leviathan data center, which is configured with three shipping containers. “We're going to start with two units per month, scaling up to six units per month,” Wright said. 
    • The company is currently “producing dozens of Galleons a year,” which are what Armada calls its ruggedized data center modules. The goal is to multiply that and make hundreds by the end of the year, “then next year to thousands and then to tens of thousands,” Wright said. 

    Lightning round

    • The Space Development Agency has a permanent director, Gurpartap Sandhoo, who has been acting in the role since September. Sandhoo is also the Space Force Portfolio Acquisition Executive for Missile Warning and Tracking.
    • Firefly Aerospace added a new lab and is doubling its Texas manufacturing facility to support its aim of multiple moon landings. 
    • James Mingus, retired general and former Army vice chief of staff, joins the board of directors for cyber defense company REDLattice.
    • Acma, which develops defense and aerospace components, landed a $300 million Series B funding round led by Caffeinated Capital. The round puts the company at unicorn status after just 18 months in the business.
    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain high-level administrative access to sensitive enterprise environments. The flaw, tracked as CVE-2026-20223, carries a maximum CVSS score of 10.0 and is classified under CWE-306 (Missing Authentication for Critical Function). According to Cisco’s advisory (cisco-sa-csw-pnbsa-g8WEnuy), the issue […]

    The post Critical Vulnerability in Cisco Secure Workload Threatens Enterprise API Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A large-scale phishing campaign leveraging fake event invitations is actively targeting U.S. organizations, combining credential theft, OTP interception, and remote access tool abuse into a single attack chain. The campaign stands out due to its repeatable phishing framework, which allows threat actors to rapidly generate event-themed lure pages at scale. These pages often begin with […]

    The post Fake Invitation Phishing Campaign Steals Credentials From U.S. Organizations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A growing trend in India where student data is increasingly being exploited for cybercrime activities, including phishing, impersonation, social engineering, and financial fraud. As educational institutions rapidly adopt digital platforms for admissions, fee payments, examinations, and communication, the volume of sensitive student information stored across systems has expanded significantly, creating new opportunities for threat actors. […]

    The post Indian Student Data Weaponized in Phishing and Financial Fraud Campaigns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Drupal Security Team has issued a warning about a highly critical vulnerability affecting Drupal core, with a security release scheduled for May 20, 2026 (PSA-2026-05-18). The flaw carries a severity rating of 20/25, indicating a significant risk that attackers could compromise affected websites shortly after public disclosure. According to the advisory, the security update […]

    The post Critical Drupal Vulnerability Could Leave Sites Open to Cyberattack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • An Active and sophisticated supply chain attack targeting the widely used @antv npm ecosystem, where a threat actor compromised a maintainer account and pushed malicious package updates designed to steal sensitive CI/CD credentials. The campaign, dubbed “Mini Shai-Hulud,” demonstrates how deeply embedded open-source libraries can be weaponized to infiltrate modern development pipelines at scale. The […]

    The post Mini Shai-Hulud Hits @antv npm Packages, Targets CI/CD Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, poses a serious risk to SSH private keys and other sensitive credentials. The flaw, present in the kernel since 2016, allows a local attacker to escalate from a basic shell account to full root access on many popular Linux distributions. Nine-Year-Old Kernel Flaw The issue lies […]

    The post Nine-Year-Old Kernel Flaw Puts Linux SSH Private Keys at Risk appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A persistent P2Pinfect botnet campaign targeting Google Kubernetes Engine (GKE) clusters through exposed Redis instances, highlighting how a single cloud misconfiguration can enable long-term compromise. In several investigated environments, attackers maintained access for up to six months, with consistent botnet activity detected through FortiCNAPP composite alerts. The intrusion chain began with publicly exposed Redis services, […]

    The post P2PInfect Botnet Targets Kubernetes via Exposed Redis appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Two U.S.-based business executives have pleaded guilty to their roles in enabling large-scale tech-support fraud operations linked to call centers in India, according to the U.S. Department of Justice. Adam Young, 42, former CEO of a telecommunications services company based in Miami, and Harrison Gevirtz, 33, former CSO from Las Vegas, admitted to knowingly supporting […]

    The post Two U.S. Executives Plead Guilty in India-Based Tech Support Fraud Schemes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶