• GitLab has rolled out a crucial security update to fix multiple vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms. Organizations utilizing self-managed GitLab instances are strongly advised by GitLab security experts to apply these updates immediately to prevent potential exploitation. Customers utilizing GitLab Dedicated or the cloud-hosted GitLab.com services are already protected […]

    The post GitLab Addresses Multiple Vulnerabilities Linked to DoS and Code Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers are weaponizing legitimate Meta Business Manager notifications to sneak phishing emails past security filters and into users’ inboxes. By abusing trusted Meta infrastructure, attackers make their messages appear authentic while quietly funneling victims to credential‑stealing pages. Because Meta systems generate these invites, the emails come from real Meta domains such as facebookmail.com and pass […]

    The post Meta Business Alerts Abused for Phishing Campaigns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft recently addressed a disruptive server-side flaw that completely disabled Start Menu search functionality for some Windows 11 23H2 users. The tech giant quickly acknowledged the incident and deployed an automatic fix behind the scenes. Because the repair happens directly on Microsoft’s servers, users do not need to search for or install any additional software […]

    The post Microsoft Confirms Windows 11 Update Breaks Start Menu Search appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anthropic’s decision to keep close hold on a powerful frontier AI model, paired with a new initiative to study its effects on global networks, is prompting intelligence-community discussions about the ways such tools might help friendly and adversary forces alike.

    On Tuesday, Anthropic unveiled Project Glasswing, a bid to raise AI-powered defenses before AI-enabled attackers can overwhelm critical software. 

    “The fallout — for economies, public safety, and national security — could be severe. Project Glasswing is an urgent attempt to put these capabilities to work for defensive purposes,” the AI company said in a blog post.

    Program partners—among them, Amazon Web Services, Apple, Cisco, Google, Microsoft—get access to Claude Mythos Preview, an unreleased model that, officials wrote, “has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.”

    The intelligence community is reacting to the news, according to a person familiar with the thinking of multiple IC agencies. 

    “They want secure code and to use AI to find network vulnerabilities as well,” said the person, who, like some others in this story, spoke on the condition of anonymity to describe sensitive internal deliberations.

    Anthropic has briefed senior officials across the U.S. government, including at the Cybersecurity and Infrastructure Security Agency and NIST’s Center for AI Standards and Innovation, on Mythos Preview’s offensive and defensive cyber applications, a company official said.  

    “Bringing government into the loop early — on what the model can do, where the risks are, and how we’re managing them — was a priority from the start,” the company official said.

    Analysts at the National Security Agency have also been casually chatting about the release of the Mythos model, another person familiar with the matter told Nextgov/FCW.

    Multiple intelligence agencies and Defense Department components play roles in offensive cyber operations and defending U.S. networks. Because offensive missions often depend on understanding a target’s defenses, tools like the Mythos model in the wrong hands could help adversaries identify and exploit weaknesses in critical systems. Agencies are already known to stockpile hacking exploits for future use.

    The development is also drawing major attention and concern, in some cases, from cyber-focused firms that engage with the intelligence community. 

    “How is anyone supposed to defend against all of this at once?” said one executive at a cyber investment firm, alarmed by the scale at which the Anthropic model was able to identify vulnerabilities.

    The Glasswing news is “scary and ominous” because it isn’t clear how Mythos Preview could be used offensively, especially if it falls into the hands of a foreign adversary, said Hayden Smith, a co-founder at Hunted Labs, a company focused on software supply chain risks.

    It’s very possible the model could land in the possession of governments considered hostile to the U.S., he said, explaining that “even with deep vetting, the odds of Mythos flowing into the wrong hands is barely a hypothetical given the landscape of current attacks on the open source ecosystem and software supply chain.”

    Because much of the internet runs on widely used open-source software maintained by developers around the world, tools like Mythos could uncover weaknesses in code that underpin large parts of the digital ecosystem. 

    That dynamic has come into sharper focus following recent software supply chain incidents that had widespread repercussions — including a compromise of the Axios JavaScript library disclosed last week — and amid concerns that some developers behind critical open-source projects are affiliated with companies the U.S. government considers tied to foreign adversaries.

    Capitol Hill is also paying attention to the Anthropic development.

    “We are already seeing cyber threat actors using AI tools to improve their capabilities, putting government, businesses and consumers’ security and personal information at risk,” said Sen. Mark Warner, D-Va., the vice chairman of the Senate Intelligence Committee. “As AI dramatically accelerates the discovery of new vulnerabilities, I hope industry will correspondingly accelerate and reprioritize patching.”

    Observers have been awaiting the release of a model like Mythos Preview that could identify and exploit cyber vulnerabilities at scale for some time, said Morgan Adamski, the former executive director at U.S. Cyber Command and lead for PwC’s Cyber, Data & Technology Risk services.

    “For those in the offensive cyber community, for the U.S. government, there’s obviously a huge potential there from an adversarial perspective,” she said in an interview.

    But offense and defense are, in many ways, one and the same. If cyberintelligence analysts find a novel vulnerability in an enemy computer network, it’s possible a U.S. system might have the same vulnerability, too.

    “There’s going to be a real equity conversation that occurs,” Adamski said. “If we exploit something in an adversarial network, we’re going to have to be able to defend against it in our own critical infrastructure.”

    She also said to expect more of these innovations in the AI space, as “typically, when these types of models come out, other models aren’t far behind.”

    In an interview, Gary DePreta, the senior vice president of Cisco’s U.S. Public Sector Organization, told Nextgov/FCW that the company’s participation in Project Glasswing is part of its larger aim to address cybersecurity threats while bringing the benefits of AI to its customer base. 

    “We’re going from an age of detect-and-respond — and as we automate with AI — to predict-and-prevent threats,” DePreta said on Wednesday. “We keep saying this phrase at Cisco: ‘there is a paradox of progress as it relates to AI and the enterprise.’ And what it simply means is the capabilities of AI are far exceeding the enterprise’s ability to implement it in a safe and secure way.”

    Anthropic has become a major voice in the line AI companies are willing to draw in ethical uses of their technology, though that stance has drawn friction with the U.S. military. Earlier this year, the company declined to ease restrictions against its tools being used for domestic surveillance or fully autonomous weapons for Pentagon use, triggering a “supply chain risk” designation from the Defense Department and a White House order that all federal agencies phase out their uses of Anthropic tools. The company has legally challenged the move. 

    It’s possible that the Mythos announcement may reshape how the Defense Department interacts with the company.

    The government “needs to make amends with Anthropic and help them and Glasswing members maintain the American lead on AI by preventing Chinese model theft,” said Leah Siskind, an AI research fellow at the Foundation for Defense of Democracies think tank. 

    “Anthropic is making the responsible call — but adversaries won’t,” she said. “China is already exploiting U.S. AI models to accelerate its own capabilities, and when they reach Mythos-level performance, they will weaponize it.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat’scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet’s targeting infrastructure. “Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices,” Darktrace said in a new report.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Pentagon wants to buy almost $1 billion—$994.1 million to be precise—worth of counterdrone tech in 2027, according to budget documents. 

    The request, under other Army procurement for counter-small unmanned aerial systems, is close to double the $596 million enacted for 2026, which includes atypical funding from budget reconciliation. 

    That funding spike extends to research and development too. The Army is asking for $26.5 million for counter-small unmanned aerial systems in applied research, which is more than double what is set aside for 2026. Plus, funding for c-UAS development could jump from $140 million in 2026 to $359.2 million proposed in 2027 if finalized by Congress, the documents show. 

    While some of the increases may reflect budget line consolidation, the proposal comes as U.S. military counterdrone tech spending is expected to grow. That could mean more contracts domestically and abroad as drone threats proliferate and militaries continue to look to the Russia-Ukraine war for best practices and tech

    The Pentagon’s counterdrone task force says it wants to buy $600 million in c-UAS tech to support the U.S.-Israel war on Iran, FIFA World Cup protection, and to protect critical infrastructure. 

    Drone threats and systems used to defeat them could be at an “inflection point,” Brett Velicovich, who co-founded the startup, Powerus, which helps deliver Ukrainian drone tech to the U.S. military, told Defense One. “The question is no longer detection, but kinetic, interception solutions at scale” and the proposed budget could be “a chance to prioritize affordable, deployable interceptor solutions…that can actually stop threats in real time.”

    It’s a numbers game.

    “The Ukrainians, as an order of magnitude, consider that they need to lose four drones for every one that they take down,” said Doug Abdiel, a Marine Corps reservist and global vice president at Advanced Navigation, which focuses on GPS alternatives and autonomous systems. 

    But being able to buy drones in large quantities is only part of the challenge. 

    “It's also a mindset shift around agility, and…how you use these assets,” he told Defense One, including “the notion that you would buy a drone to then do a kinetic kill on another drone. Or that you are going to have so much in your radar pattern that you're going to be unable to process all that information.” 

    Welcome

    You’ve reached the Defense Business Brief, where we focus on what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and streaming recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!

    A new defense tech unicorn is born. Hypersonic aircraft maker Hermeus hit $1 billion valuation after a $350 million Series C funding round—and it plans to use that money to speed up production and make more prototypes. 

    • The In-Q-Tel backed firm is also moving its headquarters from Atlanta to El Segundo, Calif., where it plans to expand prototyping and research and development efforts. While some employees are already in the new space, full relocation is expected in early 2027. 
    • In the coming months, Hermeus’ Atlanta site will pivot to become the company’s manufacturing epicenter, producing its Quarterhorse aircraft.
    • “The team is now scaling to a fleet of three F-16 scale aircraft, accelerating our path to Mach 3 and starting customer payload integration,” a company spokesperson told Defense One.

    HII dives into physical AI through a new agreement with Gray Matter Robotics to explore how it can be integrated into shipbuilding for manned and unmanned vessels. 

    • The move is part of a larger strategy to increase productivity in shipbuilding, which involves complex, precise, and yet variable tasks like “grinding, blasting and finishing of metal structure,” Eric Chewning, HII’s head of strategy and maritime systems, told reporters. “There is a broader set of industrial use cases where we need a single robot to do 100,000 tasks just once. And that’s where physical AI is a game changer.”
    • Background: Navy Secretary John Phelan has pushed for more use of AI, automation, and robotics in shipbuilding—from back-office work to manufacturing and maintenance—to speed up deliveries and close workforce gaps. 
    • But while robots aren’t necessarily new to shipyards, it may take a while before the HII-Gray Matter Robotics partnership has hard data on how much the technology can improve throughput
    • “We've got to get the technology certified before we can put them in a production environment,” Chewning said, noting the paperwork process to get Gray Matter’s technology certified with the Navy is underway.
    • The emphasis now is on demonstrating how well the tech works. 
    • “Once we can begin to demonstrate these technologies are qualified, and that our hypothesis around their integration [and] the value stream works, then we can begin to get them deployed into the shipyard,” Chewning said, adding that HII plans to install a Gray Matter Robotics cell at Ingalls. “So as quickly as we're able to, we're going to get these things instituted to help drive throughput.” 
    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have lifted the curtain on a stealthy botnet that’s designed for distributed denial-of-service (DDoS) attacks. Called Masjesu, the botnet has been advertised via Telegram as a DDoS-for-hire service since it first surfaced in 2023. It’s capable of targeting a wide range of IoT devices, such as routers and gateways, spanning multiple architectures. “Built for

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Operation Masquerade: The FBI and DoJ disrupted a Russian GRU campaign that hijacked routers via DNS attacks to spy on users and steal credentials.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft researchers have uncovered a fast-moving group, Storm-1175, launching high-speed Medusa ransomware attacks against healthcare and education sectors in the UK, US, and Australia by exploiting security flaws in as little as 24 hours.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Defense Secretary Pete Hegseth declared the U.S.’s war against Iran a “decisive military victory” during a press briefing on Wednesday—day one of a two-week ceasefire that could lead to more strikes if the U.S. and Iran can’t reach a long-term deal.

    Hegseth said that “Iran begged for this ceasefire” and that “they’ve had enough,” though the 10-point plan Iran has proposed to end the war includes some propositions that have been non-starters for the U.S. in the past, including withdrawing U.S. troops from the Middle East and lifting all sanctions on Iran.

    “Yeah, we'll be hanging around. We're not going anywhere. We're going to make sure Iran complies with this ceasefire and then ultimately comes to the table and makes a deal,” Hegseth said. “Our troops are prepared to defend, prepared to go on offense, prepared to restart at a moment's notice with whatever target package would be needed in order to ensure that Iran complies.”

    The secretary boasted of 800 targets struck Tuesday night before the ceasefire began, “completely destroying” their defense industrial base. That followed his March 13 declaration that it had been “functionally defeated.”

    “What little they have left buried in bunkers is all they will have,” Hegseth said Wednesday. “They can still shoot. We know that their command and control is so decimated they can't really talk and coordinate.”

    Hegseth added that “Iran no longer has any sort of comprehensive air defense” capability.

    Still, Iran retains the ability to fire on ships in the Strait of Hormuz, which suggests that the country still has enough military power to be a threat beyond its borders. Eliminating Iran’s ability to do so is among the key military objectives repeatedly touted by the administration since strikes began in late February.

    Hegseth’s claims about the operation’s success may be overwrought, officials and analysts told the Washington Post, in light of the downing of an F-15 fighter jet on Friday and the subsequent downing of an A-10 aiding in the rescue of the fighter’s aircrew

    At the briefing, Air Force Gen. Dan Caine, chairman of the Joint Chiefs, estimated that the U.S. had taken out 80 percent of Iran’s air defense systems and sunk more than 90 percent of its navy over the course of striking more than 13,000 targets.

    “Over the course of 38 days of major combat operation, the Joint Force achieved the military objectives as defined by the president,” Caine said in prepared remarks. “We welcome the ongoing cease fire, and as the Secretary said, we hope that Iran chooses a lasting peace.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶