• A newly disclosed attack technique dubbed “GhostTree” is raising concerns among defenders after researchers demonstrated how it can disrupt endpoint detection and response (EDR) tools and bypass file scanning mechanisms on Windows systems. The technique, discovered by Varonis Threat Labs, abuses NTFS junctions to create recursive directory structures that can cause security tools to hang indefinitely. New […]

    The post New GhostTree Attack Causes EDR Tools to Hang, Leaving Files Unscanned appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed security flaw in Anthropic’s Claude Code platform has exposed a critical weakness in its network sandbox, potentially allowing attackers to bypass restrictions and exfiltrate sensitive data. The issue, identified by security researcher Aonan Guan, marks the second complete sandbox bypass discovered in under six months, raising concerns about the reliability of built-in […]

    The post Claude Code Sandbox Flaw May Compromise User Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension.  The development comes as the Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers’ systems was hacked in the

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org. Drupal said the vulnerability resides in a database abstraction API that is

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • F-15 Eagles and F-35 Lightning II fighters may take on future combat search and rescue missions, as the Air Force aims to retire the last A-10 Thunderbolt IIs by 2030, service officials told lawmakers Wednesday. 

    The A-10 “Warthog” has been the cornerstone close air support aircraft of the military’s combat search and rescue formations, or “sandy package,” for decades. Gen. Kenneth Wilsbach, the Air Force’s top uniformed leader, faced questions from several lawmakers during a House Armed Services Committee hearing about how the service will maintain that capability.

    “The reason why the A-10 is really good at that is because it's a core mission of that platform, and as we transition with putting the A-10 in the retirement phase, there will be other platforms that it will become their core mission,” Wilsbach said. “So F-35s, F-15s, other platforms have the capability."

    Warthogs have been used heavily in the Iran war, from strafing boats in the Strait of Hormuz to the daring rescue operation of a downed F-15 airman. Last month, the Air Force announced it will keep three squadrons flying: one through 2029 and the other two through 2030. But as the service eyes replacement platforms, other pilots will have to be trained on how to do the combat search and rescue mission. 

    "The A-10 pilots are specifically trained for combat search and rescue,” said Rep. Austin Scott, R-Ga.. “Are we going to specifically train F-35 and other pilots for combat search and rescue?”

    “We’ll have to,” Wilsbach said. “It’s our mission.” 

    In response to similar questions from Rep. Sarah Elfreth, D-Md., Wilsbach said the fiscal year 2027 budget asks for $10 billion in flying hours, which would cover additional combat search and rescue training for the service’s pilots.

    “The mission of the A-10 is close air support, but part of that subset of close air support is combat search and rescue,” Wilsbach said. “And we can do close air support, and we can do combat search and rescue support from other platforms, and it's unacceptable to have a gap if you have somebody down behind enemy lines, like you saw with Dude 44 Bravo, you have to go get them.”

    The White House, Congress, and Defense Secretary’s work to extend the A-10’s retirement to 2030 “allows us to make sure that we don't have a break in that capability,” said Air Force Secretary Troy Meink.

    Dan Grazier, a Stimson Center senior fellow and the director of the nonprofit's national-security reform program, is skeptical.

    "Firstly, it is highly doubtful that neither the F-35 or the F-15 will ever be able to match the A-10's capabilities,” Grazier said. “Secondly, Gen. Wilsbach said the quiet part out loud. He admitted that the F-35, even though it was sold as a replacement for the A-10, still isn't a viable replacement."

    The F-35 was first pitched as a substitute for the A-10’s close air support mission. Internal tests involving the two aircraft raised concerns about whether it could be an effective replacement, according to a report obtained by the Project on Government Oversight. Additionally, during the F-15’s development, the phrase “not a pound for air-to-ground” was used to describe the program’s pivot away from bombing missions. But both platforms have been significantly upgraded and have been branded as multirole fighters capable of numerous missions, including close-air support, ISR, and air-to-air operations.

    Rep. Derrick Van Orden, R-Wis., pointed out that the F-35’s price tag, loiter time, and flight hour costs are all significantly higher than the A-10.

    “So having been on the ground as a United States Naval SEAL in combat, loiter time matters,” Van Orden said. “We cannot have a gap in close air support, a close air support platform, that will be able to kill the enemy that is in that hallway, vice dropping something from an F-35.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents, covering

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Before indicators, before oscillators, before anything that requires a formula – the market communicates through price structure. Peaks…

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company’s Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world. The tech giant attributed the activity to a threat actor it calls Fox Tempest, which it said offered the MSaaS scheme

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitHub Breach: TeamPCP stole 3,800 internal repositories through a malicious VS Code extension and is now selling the data online for $95,000.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – May. 20, 2026

    Watch the YouTube video

    Cybersecurity Ventures estimates that there are around 35,000 chief information security officers (CISOs) employed worldwide in 2026, up minimally from 32,000 in 2023.

    The 2026 CISO Report from Cybersecurity Ventures in partnership with Sophos examines the evolving role of the CISO and the shortfall of CISO resources available to the world’s businesses, and the role of MSPs and MSSPs in filling the CISO gap for underserved SMBs.

    The report also reveals related facts, figures, predictions, and statistics to assist in the war on cybercrime.

    A special 4-minute video companion to the 2026 CISO Report, released on the award-winning Cybercrime Magazine YouTube Channel, features the following thought leaders:

    – Joe Levy, CEO at Sophos
    – Raja Patel, President, Product & Marketing at Sophos
    – Adam Keown, CISO at Eastman (former FBI)
    – Deneen DeFieore, CISO at United Airlines
    – Tim Brown, Former CISO at Solarwinds
    – Marcus Sachs, SVP & Chief Engineer at CIS
    – Lisa Plaggemier, Executive Director at NCSA

    Watch the Video



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post VIDEO: 2026 CISO Report On How MSSPs Are Filling The CISO Gap For Underserved SMBs appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶