• AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems during controlled cybersecurity testing. This issue, which has since been resolved, stemmed from a single evaluation scenario in which internet access was permitted and a fictional target name overlapped with a real domain. Irregular stated that […]

    The post AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python […]

    The post CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still […]

    The post JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Trump administration says the nation’s science and technology research ecosystem needs to embrace “novel security solutions” to ensure the U.S. maintains its global edge, according to a new document publicly released on Monday. 

    The National Security Science and Technology Strategy published by the White House Office of Science and Technology Policy outlines how the U.S. innovation sector should be leveraged and guarded to defend the country. The new document builds off last year’s National Security Strategy, which called, in part, for “protecting the competitiveness of the U.S. economy and bolstering the resilience of the American technology sector.”

    To help safeguard the nation’s innovation sector from threats “that could impair U.S. economic and military strength and competitiveness,” the strategy calls for “approaches that protect without inhibiting the productivity and agility of the national security S&T enterprise.”

    President Donald Trump previously moved to curtail illicit foreign interference in the nation’s research institutions, most notably through a January 2021 memo that sought to keep adversarial governments from exploiting U.S. science and technology research.

    Lawmakers from both parties have also pushed legislation to limit Chinese involvement in federally-funded research projects, and the Pentagon similarly announced on Monday that it called for 30 U.S. academic institutions to review their ties with foreign entities.

    But the strategy says research institutions need to take further steps to enhance their threat awareness, including conducting “automated research security vetting” of agency-funded research proposals and performing continuous monitoring of federally-supported projects. 

    It also calls for “bolstering counter-intelligence support to governmental and non-governmental research centers” — which would give researchers more immediate and timely insights into potential threats—and creating “risk-based review criteria and a repository of sharable information to enhance the efficiency of information collection and sharing among agencies.”

    It noted, for instance, that the FBI-led Quantum Information Science and Technology Counterintelligence Protection Team “brings an interagency team of quantum experts and security professionals to fine-tune technology protection and security outreach activities for the quickly evolving quantum R&D community.”

    Another section calls for “establishing cybersecurity guidelines for researchers and research institutions,” although it is sparse on the details of what this would look like. The National Science Foundation, for its part, has a research security policy framework that includes some cyber-specific guidance as part of its broader blueprint. 

    “Given the evolving nature of research security threats, security experts should embrace comprehensive, new, and novel security solutions, particularly where they can be crafted to address unique or nuanced requirements of specific technology fields,” the document said. 

    The strategy’s implementation section highlights the need to enhance K-12 and higher education training opportunities and bring more skilled talent into the federal workforce—an effort the Trump administration has been undertaking, in part, by prioritizing skills-based hiring over degree requirements. 

    Notably, however, the strategy references the need to attract more nonimmigrant tech workers to the U.S., which differs from the Trump administration’s prior stance that called for a more restrictive approach.

    “The United States will further strengthen its workforce by attracting and retaining top-tier global talent in critical national security S&T fields,” the strategy says. “Agencies will collaborate on using existing authorities to recruit the exquisite talent necessary to ensure the national security S&T Enterprise leads the world in developing and applying these technologies.”

    OSTP did not immediately respond to a request for comment about the strategy’s inclusion of the need to attract and retain global talent. 

    Last year’s National Security Strategy said, in part, that the U.S. “cannot allow meritocracy to be used as a justification to open America’s labor market to the world in the name of finding ‘global talent’ that undercuts American workers.”

    Trump issued a proclamation in September 2025 that moved to restrict the number of H-1B visas, saying that the program has harmed American workers. The visas allow U.S. firms to temporarily hire foreign workers, with the tech industry notably using the program to attract nonimmigrant talent. The proclamation attempted to institute a $100,000 H-1B visa fee, although a district court has overturned that mandate.

    In addition to calling for the nation’s innovation sector to embrace new security solutions, the strategy said the U.S. needs to speed up its pace of innovation, build up its domestic “technological resilience” and focus its science and technology ecosystem on “maintaining battlefield advantage, countering strategic threats to the homeland, and shaping the competition toward areas of U.S. strength.”

    Nextgov/FCW Cyber Reporter David DiMolfetta contributed to this story.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Legislation aimed at improving the amount of paid leave federal employees are eligible each year took another step forward as Democratic senators introduced companion legislation shortly before Congress left for its August recess.

    In June, a bipartisan group of House lawmakers introduced the Comprehensive Paid Leave for Federal Employees Act (H.R. 9261), a measure that would provide feds with up to 12 weeks each year of paid family leave, to be used to attend to a serious health condition or care for a spouse, child or parent. It also would cover absences needed in connection with a family member’s deployment into active-duty military service, or to help a family member who has been the survivor of domestic violence, sexual assault or stalking.

    And last month, Sens. Brian Schatz, D-Hawaii, and seven other Democrats introduced their own version of the bill (S. 5168). That measure also extends 12 weeks per year of paid family leave to federal workers to deal with a health condition or a family member’s health condition and to attend to a family member’s military deployment, but it excises the provision relating to victims of domestic violence, sexual assault and stalking.

    “Right now, our laws are forcing federal workers to make the impossible choice between caring for their families and keeping their jobs,” Schatz said in a statement. “Our bill will provide federal workers with 12 weeks of paid leave, giving them the time they need to take care of their own health and their loved ones.”

    Paid family leave and other provisions relating to federal workers has recently been a tougher sell for the Senate side of the U.S. Capitol. In 2019, as lawmakers considered providing 12 weeks of paid parental leave to federal workers each year via the 2020 National Defense Authorization Act, the House’s version of the legislation also included family leave, only for the Senate to balk during negotiations between the chambers.

    Likewise, the House has included a provision blocking President Trump’s anti-union executive orders’ implementation at the Pentagon in both last year’s NDAA and the one currently under consideration. The Senate stripped the provision from their version of the bill last year.

    Despite the more pared-back approach, the Senate’s family leave bill has still attracted the support of several unions and other federal employee associations.

    “Expanding paid family and medical leave ensures federal employees never have to choose between caring for themselves or a loved one and serving the American people,” said Everett Kelley, national president of the American Federation of Government Employees. “This legislation will strengthen the federal workforce, improve employee retention, and help the government remain a competitive employer for the dedicated public servants our nation depends on.”

    “Federal employees should never have to choose between caring for their loved ones and paying their bills on time,” said National Treasury Employees Union National President Doreen Greenwald. “The Comprehensive Paid Family Leave Act would provide federal workers with the flexibility and support they need during some of life’s most significant moments. As the federal government works to attract and retain talented public servants, providing comprehensive paid family leave is both the right thing to do and a smart investment in the workforce.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • I built the Cybersecurity Maturity Model Certification because self-attestation was failing our war industrial base. Contractors could simply promise they were following basic cybersecurity practices, with no verification behind that promise. Our adversaries noticed that gap long before Washington did—and they have not eased up since. If anything, the opposite is true. 

    Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago. This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did.

    But defending a program doesn't mean pretending it's perfectly aimed. Now that CMMC is a final rule moving into real contracts, it's the right time to ask: are we targeting it precisely enough? I don't think we are yet—and artificial intelligence, used correctly, can help fix that without touching the cybersecurity bar itself.

    The problem is targeting, not the standard

    CMMC's requirements hinge on controlled unclassified information. But CUI determinations across the war industrial base are inconsistent: Two subcontractors doing nearly identical work can end up with completely different assessments because the call still depends on manual judgment with incomplete visibility into how data actually flows down. Some small businesses get pushed into heavy assessment burdens for data that isn't really CUI. Others handling real, sensitive data slip through with a lighter requirement. Neither outcome helps national security; the first wastes compliance dollars, the second leaves real exposure unaddressed.

    AI can do the first-pass sorting here—flagging likely CUI from contract language and statements of work and catching mismatches between what a prime contract designates and what actually flows down to subcontractors — far more consistently than today's patchwork of manual reviews. In this scenario, a human with contracting authority still makes the final call. But that human should be working from a much better starting point than we give them now.

    Small business is the economy, not just the supply chain

    Small businesses are 99.9% of American companies and employ nearly half the private workforce. And right now, they face threats most aren't equipped to handle: ransomware that can shut down operations overnight; AI-enabled fraud that's harder to spot every year, and a coming reckoning when quantum computing breaks today's standard encryption. The quantum threat is already real, since data harvested now can simply be decrypted later.

    I'm glad the Small Business Administration is leaning into this. Its Cybersecurity for Small Business Pilot Program has done real work funding training through state partners. But training grants aren't capital, and no amount of counseling gets a small manufacturer through a ransomware recovery or a quantum-resistant encryption upgrade. Small businesses can't get favorable financing for cybersecurity the way they can for equipment because most lenders don't know how to underwrite it.

    We need a dedicated SBA loan program for cybersecurity investment—open to every small business, not just those working with the Department of War—to fund things like multi-factor authentication rollouts, endpoint detection, incident response, and early migration toward quantum-resistant encryption, before it's an emergency instead of a plan.

    Same mission, two fronts

    Inside the war industrial base, use AI to make sure CUI calls and flow-down match reality. Outside it, give the broader small business economy the capital to defend itself against adversaries who are only getting more aggressive. I still believe unverified promises are not a security strategy. But precision and support aren't the enemies of security—they're what make it sustainable.

    Sharpen how we target CMMC, and open the door for every small business to invest in its own war footing. That's not lowering the bar. That's making sure the bar is doing its job.

    Katie Arrington is a former South Carolina state legislator and cybersecurity executive who served as DOD CISO for Acquisition and Sustainment starting in 2019, and later returned as DOD CISO/PTDO DOD CIO under the second Trump administration. She spearheaded the Pentagon’s initial efforts to create the CMMC program for defense contractors beginning in 2019, driven by a conviction that contractors needed to actually prove — not just self-attest to — their cybersecurity compliance in order to protect sensitive defense data from adversaries. Her commitment to the program has been described as stemming from a deeply personal mission to secure the Defense Industrial Base from cyber threats that jeopardize national security.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Army officials plan to resume Apache training flights in days, after the fleet was grounded following a crash that left two soldiers dead in Texas, according to an internal memo reviewed by Defense One.

    The two soldiers, Chief Warrant Officer 2 Deontre T. Huey and Warrant Officer Seth L. Olmstead, died during a maintenance test flight out of Fort Hood on Aug. 12. On Friday, Army officials announced a stand down of AH64 Apache training flight operations and said in a news release it “will remain in effect until we have a better understanding of the root cause of the accident.” 

    However, a widely circulated internal Aug. 14 memo reviewed by Defense One said the grounding “concludes on midnight Tuesday,” with plans for “flight operations resuming on Wednesday 19 August.” The document acknowledges that from fiscal year 2023 through this year, the Army had nine fatalities from nineteen Class A mishaps, the term used for the service's deadliest and costliest incidents. 

    “During the Army aviation AH-64 fleet safety stand down, commands will focus on aviation academics and safety related topics,” the memo states. “Senior commanders will be involved during the aviation safety stand down. Opening remarks shall be provided by general officers, who will articulate the importance of this event. Commanders will review, brief, and discuss an overview of current safety statistics and trends.” 

    Safety stand downs are common after military crashes, but the current Apache grounding marks the latest in a recent string of safety mishaps for the storied attack helicopter. Three months ago, Defense One exclusively revealed a transmission problem that could “result in loss of tail rotor thrust, electrical power, and hydraulics. Some of the AH-64 Echo models had to be grounded as a result. Prior to that investigation, there had been at least three Apache incidents—including one crash during a maintenance flight out of Fort Hood, according to photos and information from a pilot.

    While investigations into the crash are ongoing, a U.S. official told Defense One the service  was “able to eliminate the transmission as a causal factor.” The official confirmed the Apache fleet would resume training flights this week.

    A Boeing executive told Defense One on the sidelines of the Farnborough International Air Show in the United Kingdom last month that they couldn’t share the progress on fixing those transmission problems.

    “Boeing does have crews that are there working with the U.S. Army on some of those components,” said Mark Ballew, Boeing Defense, Space, and Security’s senior director of business development and strategy for vertical lift. “So our team's been there, they’ve been working there for the last month-plus on that.” 

    A Boeing spokesman told Defense One on Sunday the company is still working with the Army on the transmission problem.

    Apaches are being relied on heavily during the ongoing war in Iran, are part of major foreign military sales this year, and have been used for high-level transportation of Defense Department leaders and celebrities. 

    Officials wrote in Friday’s memo that “CENTCOM deployed formations are exempt from the safety stand down requirements.” 

    In June, an Apache went down near the coast of Oman while “patrolling international waters,” according to U.S. Central Command. After the helicopter was reportedly struck by an Iranian drone, the U.S. military deployed a Navy drone boat to rescue the downed crew

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶