• Iranian state-sponsored threat actors linked to MuddyWater (Seedworm) have been caught hiding behind the Chaos ransomware brand to conduct sophisticated espionage operations, using Microsoft Teams as a phishing vector to steal credentials and manipulate multi-factor authentication (MFA). Rapid7 researchers uncovered the intrusion in early 2026, revealing a calculated false flag operation designed to mimic financially […]

    The post Cybercriminals Exploit Microsoft Teams to Phish Login Credentials and Bypass MFA appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Multiple high-severity vulnerabilities in the WatchGuard Agent for Windows could allow malicious actors to elevate their privileges to the highest system level or disrupt critical security services. With CVSS scores up to 8.5, these vulnerabilities pose a significant risk to organizations that rely on WatchGuard for endpoint security and threat protection. WatchGuard Agent Flaws Chained […]

    The post WatchGuard Agent Flaws Allow Attackers to Gain Full SYSTEM Privileges on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems. vm2 is an open-source library used to run untrusted JavaScript code inside a secure sandbox by intercepting and proxying JavaScript objects to prevent sandboxed code from accessing the host

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • NATIONAL HARBOR, Md.—Putting yourself first doesn’t mean you can’t have friends, Commerce Secretary Howard Lutnick suggested on Monday at the SelectUSA Investment Summit just outside Washington, D.C.

    His department’s annual event aims to woo foreign investment in the United States, an objective complicated by the Trump administration’s “America First” approach.

    “We’re here to make deals happen,” Lutnick told the crowd on Monday. “To our foreign partners, we want you here. If you build here and commit to build here, the Department of Commerce will have the ability to assist you getting L-1 visas so that you can bring your employees in to launch the project. You'll train American workers over time, but you can bring your people here, and we will set that infrastructure for you. The Department of Commerce has made a deal with the Secretary of State and the State Department that we will assist you in helping you get visas so you can build your factories here.”

    The comments come as the Trump administration has levied heavy tariffs, strained relationships with allies and partners, and launched a war on Iran that has set off a chain reaction of economic effects, including skyrocketing gas and increased fertilizer prices, which could boost food costs and supply down the line

    Lutnick’s speech was largely a pep rally to push the idea that the U.S. is the land of opportunity. America First “doesn't mean America alone,” he said. “It just means that we're open for business, that we're here for our workers, we're here for our communities, and we're here also to make sure that we can take care of ourselves for national security.”

    Delegations from U.S. states seemed undeterred by political headwinds as they pitched projects to foreign attendees. Oklahoma Gov. Kevin Stitt announced a memorandum of understanding with Hitachi, which already has a presence in the state, to explore ways to use AI in developing data centers, energy and transportation infrastructure, biotechnology development, and advanced manufacturing.

    Even amid the U.S.-Israel war on Iran, the state of Iowa is pressing on with goals to work with countries in the Middle East. Juliet Abdel, who leads the Cedar Rapids Metro Economic Alliance, said the organization wants business relationships with Turkey, Bahrain and Saudi Arabia. 

    “We are pushing ahead with conversations…being more forward and having those conversations, because most organizations have not had an international focus before, and so it really has opened up the opportunity for us to have dialogue and really put this as a priority,”  Abdel told Defense One.

    She said Cedar Rapids hopes to convince more defense and aerospace companies to join London-based BAE Systems and RTX’s Collin Aerospace. 

    “There's also over 1,000 acres of available land near our airport. Of that, over 500 acres of certified sites are certified through the state of Iowa as being ready for development. And then over the last several months, the state has invested in a study, commenced to really identify …categories within the aerospace and avionics that we can really target as having the most potential. And we're developing that into a tool” expected to be released this summer.


    Welcome

    You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and song recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!


    Overheard at SelectUSA. Amy Tachco, the State Department senior adviser and industry liaison for the visa office, gave an overview on visa requirements for foreign business travelers at the conference, including a continuous vetting process. 

    • “The administration has really made vetting a priority, and consular officers will take to ensure applicants meet all the eligibility requirements. As Secretary [Marco] Rubio has said, a visa is a privilege, not a right, so every single visa adjudication is treated as a national security matter,” she said Tuesday. 
    • A little background: The Trump administration recently expanded efforts to limit entry of certain foreign nationals, including broadening the State Department’s visa bond program, adding 12 new countries for a total of 50, to deter overstays. 
    • Who attended? The Gaylord convention center was bustling but it wasn’t immediately clear just how many of the attendees were foreign. (Defense One requested attendee stats for this year’s summit but hadn’t heard back by press time.) At a Monday networking reception, I spotted reps from Argentina and Switzerland. Earlier in the day, the U.S. ambassador to India announced that a dozen companies from the subcontinent had plans to invest in the United States. Geraldine Byrne Nason, Ireland’s ambassador to the U.S., said the country had sent its largest delegation ever to SelectUSA this year. Last year’s summit drew more than 5,500 participants from more than 100 countries, “and catalyzed nearly $1 billion in new investment announcements,” according to a Sept. 30 news release

    Making moves + other news

    • Lockheed Martin will get a new aeronautics president. Starting June 1, Orlando Sanchez, Jr., who leads the company’s top-secret development Skunk Works division, will take over from Greg Ulmer, who is retiring after more than 30 years. 
    • Powerus adds another former Pentagon official. Milton “Jamie” Sands III, who will join the drone company’s advisory board, is a retired rear admiral who led U.S. Naval Special Warfare Command. 
    • BAE Systems opened a 150,000-square-foot factory in upstate New York to build high-voltage batteries for hybrid and electric aircraft and ground vehicles. The $65 million facility in Endicott was announced last year.
    • Anduril will head an integration team for companies contracted for Golden Dome’s space-based interceptor program, including Impulse Space, Inversion Space, K2 Space, Sandia National Labs, and Voyager Technologies.
    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Pentagon leaders say workers are using new agentic AI tools to compress weeks of work into hours. But the same tools are opening new frontiers of digital crime and changing the very nature of cybersecurity.

    The rollout of agentic tools on the department’s GenAI.mil platform since December has been a “tremendous success,” Emil Michael, defense undersecretary for research and engineering, told reporters at the Pentagon on Tuesday. 

    Michael said people were using the tools to do “the mundane part of their job” and take a “two-week task and compress it down to three hours.”

    The platform recently added Google’s Gemini and is looking for more such.

    We’re “trying to have options so we're not single-threaded on any one vendor, and each of these models is trained in a somewhat different way on different data. So we're going to learn which ones are more capable on which dimensions,” he said.

    In its quest for AI tools that can help find vulnerabilities, the Pentagon is even evaluating Mythos, a powerful agentic model made by Anthropic—a company that has officially been labeled a national-security risk. Anthropic has sued the government over the designation. 

    Michael said the government is in a “testing and evaluation period” with Mythos, which is already being used by agencies and a select group of large companies to find vulnerabilities. He tried to explain why the Pentagon was still using tools from a company that allegedly threatens national security, saying that Mythos is “a different product in some ways. Different probably than the company itself.”

    What the Pentagon and the rest of the federal government must do now, Michael said, is “look at what this model can do, not only to the government software and hardware infrastructure, but to the private sector…for the rural hospitals, for the wastewater treatment plants, to all the things. So that we have the ability to patch them before adversaries get the same ability.”

    When criminals use agentic AI

    Michael said agent-based AI tools like Mythos, which can find and patch vulnerabilities without human oversight, will become more standard. 

    “All the big tech companies now are using these cyber models to find vulnerabilities. They're trying to make automatic patching using agents and using the same models. So we expect that to grow across the industry, across the government.” 

    But that won’t be enough to protect against future AI-enabled attacks.

    Jackson Reed, founder of AI startup Barding Defense, says that agentic tools will change cybersecurity in ways that many institutions don’t yet appreciate. 

    “We're going to see criminal groups look a lot more like state actors,” Reed said. 

    What does that mean? Today, most cybercriminals ocus on fast-payoff attacks like stealing data or encrypting it for ransom. But soon, he said, they will mimic some state-backed Chinese and Russian groups by trying to stay in a network to spy, move “laterally,” or manipulate data.

    “Changes in attacker skill are going to produce entire new taxonomies of attack (like the industrialized insider trading example, or industry-wide ransomware deployments) that will pose risks to society and raise questions about the feasibility of current constitutional approaches,” Reed said in a followup email.

    That will create business models for cyber criminals and states such as Russia that routinely work with those criminal groups. Reed said using AI to automatically detect and patch software holes won’t protect against that. For instance, Opus 4.6, Anthropic’s latest model for coding and reasoning, can find and fix software vulnerabilities but it misses things like lateral movement, he says.

    Reed is working with Breakpoint Labs, a cybersecurity company that works with the U.S. military, to develop  a new sort of agent platform to help cybersecurity professionals find the new kinds of attacks that agentic AI tools enable but can’t spot.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Explore the best OSINT tools for your digital investigations, threat intelligence, reconnaissance, and tracking online activity in 2026.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Offensive cyber operations may be used against groups deemed threats to U.S. interests, the Trump administration says in its new counterterrorism strategy.

    Counter-terror activities against state actors “include offensive cyber operations against those planning to kill Americans or who support those plotting to do so,” says the strategy, which was released on Wednesday.

    Groups who present threats include narcoterrorists and transnational gangs, Islamic terrorist groups, and “violent left-wing extremists, including anarchists and anti-fascists,” the document says.

    Diplomatic, financial, cyber, and covert actions may be used to deter or otherwise hinder state actors from helping foreign terrorist organizations, the strategy says. Cyber operations would continue against Iran-backed proxy groups, it adds.

    The overt mention of offensive cyberattacks underscores the White House’s broader push to shape foreign hackers’ behavior and follows several public acknowledgments of U.S. cyber warriors’ involvement in the administration’s military activities. 

    The document does not detail the nature of these offensive cyber operations.

    The White House has helped shape a budding market for offensive cyber tools and capabilities, but executives and officials are grappling with legal questions over definitions of cyber offense and defense, as well as who would bear responsibility when private firms are involved in digital operations.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks. Hunt.io, which detailed the malware, said it made the discovery after identifying an exposed directory on a Netherlands-hosted

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google patches a CVSS 10 Gemini CLI vulnerability that allowed hackers to use prompt injection and privilege escalation for a full supply chain compromise.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ShinyHunters breached Instructure and Vimeo, exposing millions of student and user records through direct and supply chain attacks.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶