• Frankfurt am Main, Germany, December 16th, 2025, CyberNewsWire Link11, a European provider of web infrastructure security solutions, has released new insights outlining five key cybersecurity developments expected to influence how organizations across Europe prepare for and respond to threats in 2026. The findings are based on analysis of current threat activity, industry research, and insights […]

    The post Link11 Identifies Five Cybersecurity Trends Set to Shape European Defense Strategies in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining. The activity, first detected by Amazon’s GuardDuty managed threat detection service and its automated security monitoring systems on November 2, 2025, employs never-before-seen persistence techniques to hamper

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. military attacked three more alleged drug-trafficking boats off the Latin American coast, this time all three “were transiting along known narco-trafficking routes in the Eastern Pacific and were engaged in narco-trafficking,” officials at Southern Command said in a statement and compilation video posted to social media Monday evening. 

    “A total of eight male narco-terrorists were killed during these actions—three in the first vessel, two in the second and three in the third,” SOUTHCOM said. As before, no evidence was provided to back up their claims. 

    The attacks raise the death toll to 95 people spread across at least 25 strikes, which have left two survivors, the New York Times reports in its updated tracker, which includes U.S. military attacks going back to Sept. 2.

    New: The White House says it has now designated fentanyl as a “weapon of mass destruction,” according to an executive order posted online Monday. President Trump and Pentagon chief Pete Hegseth have claimed their attacks on alleged drug-trafficking boats stems from their war on drug cartels and the flow of fentanyl into the U.S., which experts say travels into the country via Mexico and not the Caribbean, as the New York Times explained last month.

    A note on alleged strategy: Trump’s chief of staff Susie Wiles told Vanity Fair in an interview published today that the president “wants to keep on blowing boats up until [Venezuelan dictator Nicholas] Maduro cries uncle. And people way smarter than me on that say that he will.” VF’s Chris Whipple noted immediately afterward, “Wiles’s statement appears to contradict the administration’s official stance that blowing up boats is about drug interdiction, not regime change.” Former State Department counsel Brian Finacune called this strategy “​​as boneheaded as it is illegal.” 

    Extra reading: Wiles also told the Times in a separate interview published Tuesday (gift link) that the president “has an alcoholic’s personality,” and that the vice president has “been a conspiracy theorist for a decade.” What’s more, she called Elon Musk “an avowed ketamine” user and described White House budget director Russell Vought as “a right-wing absolute zealot.”

    U.S. International Command? Pentagon ponders major consolidation of combatant commands. CJCS Gen. Dan Caine is preparing to brief SecDef Hegseth on a plan to consolidate U.S. Central Command, U.S. European Command and U.S. Africa Command under the control of a new U.S. International Command, the Washington Post reports, citing five people familiar with the matter. 

    “If adopted, the plan would usher in some of the most significant changes at the military’s highest ranks in decades, in part following through on Hegseth’s promise to break the status quo and slash the number of four-star generals,” four Post reporters write. “Such moves would complement other efforts by the administration to shift resources from the Middle East and Europe and focus foremost on expanding military operations in the Western Hemisphere, these people said.”

    U.S. NORTHCOM and SOUTHCOM would also be consolidated, an idea reported earlier this year by NBC News. The consolidation is “meant to speed decision-making and adaptation among military commanders,” one senior defense official told the Post.

    But one former defense secretary said it would likely reduce regional expertise. “The world isn’t getting any less complicated,” Chuck Hagel said in an interview. “You want commands that have the capability of heading off problems before they become big problems, and I think you lose some of that when you unify or consolidate too many.” Read on, here (gift link).

    Commentary: The White House’s new National Security Strategy is “the longest suicide note in U.S. history,” writes Anne Applebaum in The Atlantic. Noting that the 2025 NSS differs most starkly from its predecessors in neglecting to name any country that threatens the United States, Applebaum writes: “I am not sure whether there has ever been a moment like this one, when the American government’s most prominent foreign-policy theorists have transferred their domestic obsessions to the outside world, projecting their own fears onto others. As a result, they are likely to misunderstand who could challenge, threaten, or even damage the United States in the near future. Their fantasy world endangers us all.” Read that, here (gift link).

    Update: Syrian DOD casualties named. The pair of U.S. soldiers killed on Saturday were Iowa National Guardsmen: Sgt. Edgar Brian Torres Tovar, 25, of Des Moines, and Sgt. William Nathaniel Howard, 29, of Marshalltown, the chief of the National Guard Bureau said in a Monday post

    Consideration: Is carrier Wi-Fi distracting sailors? Investigations released last week into the loss of three F/A-18 Super Hornets and a collision with a merchant vessel by the carrier Harry S. Truman found training gaps and a lack of focus and professionalism, due perhaps to overwork or even distraction by the relatively recent arrival of shipboard wifi, Navy Times reported last week.

    Coverage continues below…


    Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1944, the Battle of the Bulge began.

    It’s been a record year for U.S. airstrikes on militants in Somalia, with at least 114 to date, according to a detailed running tally compiled by researchers at the Washington-based New America think tank. The second-busiest year—in a campaign that stretches back to 2003—was 2019 with 66 recorded strikes. 

    The most recent declared strike occurred Sunday, though it’s unclear if it resulted in any casualties, according to the press release from U.S. officials at Africa Command. “Specific details about units and assets will not be released to ensure continued operations security,” AFRICOM noted in a change of transparency that’s become a staple of U.S. military activity in Africa since about April. 

    About 500 U.S. troops were stationed in Somalia earlier this year, and their attention has focused almost exclusively on airstrikes targeting either al-Shabaab insurgents fighting the government based in Mogadishu—in more than 40 U.S. strikes this year—or Islamic State militants lingering a bit further to the northeast, often around the Golis mountains in the semi-autonomous Puntland region. More than 60 U.S. strikes have targeted IS-Somalia, according to New America’s data. U.S. troops also conducted a ground raid targeting IS-Somalia in late July, the only publicly-known raid of its kind in 2025. 

    Not every U.S. strike results in a death, as AFRICOM officials told New America’s David Sterman. Still, according to his digging, somewhere ​​between 115 and 292 people have been killed in those U.S. operations. How many were militants and how many were civilians? It’s unclear, and AFRICOM hasn’t clarified. (Hat tip to Spencer Ackerman and Wesley Morgan for bringing attention to these developments.)

    Also notable: UAE troops have conducted at least 19 airstrikes against Islamic State militants in Somalia this year as well, Caleb Weiss of FDD’s Long War Journal reported in late July. However, it’s likely that “this number could be higher, as the UAE does not publicly announce such operations,” and “UAE strikes are only confirmed through Puntland officials officially commenting on them,” Weiss wrote. 

    A key question for the White House remains: Escalate or exit? Both options seem to carry risks. Recall that back in April, the New York Times reported the Trump administration’s National Security Council was “divided” over how to handle Somalia, with some—citing years of similar action—concerned an increase in U.S. strikes might have little effect, while others feared withdrawal could “inadvertently incite a rapid collapse.” 

    Five alleged “high-threat” migrants were sent to U.S. detention facilities at Guantánamo Bay, Cuba, on Sunday, Carol Rosenberg of the New York Times reported Sunday. They came as part of a wider group of 22 migrants, which were the first arrivals of their kind in two months, a defense official told Rosenberg. 

    “The latest transfers, from Louisiana, raised to about 730 the number of men who have been held at the base since early February, when the Trump administration began using it as a way station for ICE detainees designated for deportation,” she added. 

    For comparison, during America’s Global War on Terror, the U.S. held as many as 780 men and boys in detention at Guantánamo, only seven of whom were convicted, according to a 2023 report (PDF) by the UN Special Rapporteur on the Promotion and Protection of Human Rights and Fundamental Freedoms while Countering Terrorism. 

    Before the Sunday transfers, just 15 men were held at the American military prison at Guantánamo, Rosenberg reported last month. “Of those, 9 have been charged with war crimes in the military commissions system—seven have yet to be put on trial and two have been convicted,” she wrote. Read more, here

    At least eight U.S. veterans have been deported, and the Trump administration plans to deport dozens more, Rhode Island Democratic Rep. Seth Magaziner announced Saturday using data from the Department of Homeland Security obtained in September by House Armed Services Committee member and Marine veteran Rep. Seth Moulton, D-Mass. 

    Why bring it up: DHS Secretary Kristi Noem told lawmakers in a hearing last week, “We have not deported U.S. citizens or military veterans.” But Magaziner then showed her U.S. Army veteran Sae Joon Park, who was deported this summer as part of Trump’s anti-immigration crackdowns. Noem later promised to look into the circumstances behind Park’s deportation, as two different Democratic lawmakers requested in August. 

    ICYMI: “The Trump administration is sharing all air travelers’ names with ICE officials to find people with deportation orders,” the New York Times reported Friday in an update to a program that began “quietly in March.” 

    Officials at the Transportation Security Administration are now sharing the data “multiple times a week,” after which “ICE can then match the list against its own database of people subject to deportation and send agents to the airport to detain those people.” 

    Related reading: 

    Etc.

    Building post-quantum gear is hard. A new partnership aims to make it easier, Defense One’s science and tech editor Patrick Tucker reported Monday. SEALSQ, which specializes in “quantum-safe” chips, and Airmod, a French company that specializes in secure electronics for aerospace and drones, say they can help companies produce the larger, more energy-intensive software that meets standards for quantum-safe hardware and software environments, as defined by the National Institute of Standards and Technology, or NIST. 

    Under a deal announced Monday, the partners will use Airmod’s middleware software to help clients turn “months of complex cryptographic integration into days” by allowing clients to bridge more easily apply software from previous applications into new ones. 

    Why it matters: The standards reflect growing concern and certainty among a broad range of computer and security professionals that engineers—most likely in either China or the United States—will announce the development of a quantum computer capable of breaking Shor’s algorithm before 2035. This is the encryption standard that runs at the heart of most of the world’s financial transactions, web surfing, and device-to-device communication (such as drone operation). 

    Whoever wins the race would essentially have a backdoor into private transactions and communications all over the world. Continue reading, here

    The White House recently suspended a $40 billion “technology prosperity deal” with the UK that Trump agreed to during a visit there in September, the Financial Times reported in a Monday follow-up to New York Times reporting Saturday. The agreement spanned cooperation in artificial intelligence, quantum computing and nuclear energy. 

    Why bring it up: “It shows how the administration is continuing to leverage trade policy to push foreign governments to make more concessions on trade and other policies,” the Times noted. “People familiar with those talks said US officials were becoming increasingly frustrated with the UK’s lack of willingness to address so-called non-tariff barriers, including rules and regulations governing food and industrial goods,” FT reports. Reuters has a bit more.

    Also from the UK:New MI6 Chief Warns Putin is ‘Dragging Out’ Ukraine Talks,” Bloomberg reported Monday.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer. The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Direct navigation — the act of visiting a website by manually typing a domain name in a web browser — has never been riskier: A new study finds the vast majority of “parked” domains — mostly expired or dormant domain names, or common misspellings of popular websites — are now configured to redirect visitors to sites that foist scams and malware.

    A lookalike domain to the FBI Internet Crime Complaint Center website, returned a non-threatening parking page (left) whereas a mobile user was instantly directed to deceptive content in October 2025 (right). Image: Infoblox.

    When Internet users try to visit expired domain names or accidentally navigate to a lookalike “typosquatting” domain, they are typically brought to a placeholder page at a domain parking company that tries to monetize the wayward traffic by displaying links to a number of third-party websites that have paid to have their links shown.

    A decade ago, ending up at one of these parked domains came with a relatively small chance of being redirected to a malicious destination: In 2014, researchers found (PDF) that parked domains redirected users to malicious sites less than five percent of the time — regardless of whether the visitor clicked on any links at the parked page.

    But in a series of experiments over the past few months, researchers at the security firm Infoblox say they discovered the situation is now reversed, and that malicious content is by far the norm now for parked websites.

    “In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the ‘click’ was sold from the parking company to advertisers, who often resold that traffic to yet another party,” Infoblox researchers wrote in a paper published today.

    Infoblox found parked websites are benign if the visitor arrives at the site using a virtual private network (VPN), or else via a non-residential Internet address. For example, Scotiabank.com customers who accidentally mistype the domain as scotaibank[.]com will see a normal parking page if they’re using a VPN, but will be redirected to a site that tries to foist scams, malware or other unwanted content if coming from a residential IP address. Again, this redirect happens just by visiting the misspelled domain with a mobile device or desktop computer that is using a residential IP address.

    According to Infoblox, the person or entity that owns scotaibank[.]com has a portfolio of nearly 3,000 lookalike domains, including gmai[.]com, which demonstrably has been configured with its own mail server for accepting incoming email messages. Meaning, if you send an email to a Gmail user and accidentally omit the “l” from “gmail.com,” that missive doesn’t just disappear into the ether or produce a bounce reply: It goes straight to these scammers. The report notices this domain also has been leveraged in multiple recent business email compromise campaigns, using a lure indicating a failed payment with trojan malware attached.

    Infoblox found this particular domain holder (betrayed by a common DNS server — torresdns[.]com) has set up typosquatting domains targeting dozens of top Internet destinations, including Craigslist, YouTube, Google, Wikipedia, Netflix, TripAdvisor, Yahoo, eBay, and Microsoft. A defanged list of these typosquatting domains is available here (the dots in the listed domains have been replaced with commas).

    David Brunsdon, a threat researcher at Infoblox, said the parked pages send visitors through a chain of redirects, all while profiling the visitor’s system using IP geolocation, device fingerprinting, and cookies to determine where to redirect domain visitors.

    “It was often a chain of redirects — one or two domains outside the parking company — before threat arrives,” Brunsdon said. “Each time in the handoff the device is profiled again and again, before being passed off to a malicious domain or else a decoy page like Amazon.com or Alibaba.com if they decide it’s not worth targeting.”

    Brunsdon said domain parking services claim the search results they return on parked pages are designed to be relevant to their parked domains, but that almost none of this displayed content was related to the lookalike domain names they tested.

    Samples of redirection paths when visiting scotaibank dot com. Each branch includes a series of domains observed, including the color-coded landing page. Image: Infoblox.

    Infoblox said a different threat actor who owns domaincntrol[.]com — a domain that differs from GoDaddy’s name servers by a single character — has long taken advantage of typos in DNS configurations to drive users to malicious websites. In recent months, however, Infoblox discovered the malicious redirect only happens when the query for the misconfigured domain comes from a visitor who is using Cloudflare’s DNS resolvers (1.1.1.1), and that all other visitors will get a page that refuses to load.

    The researchers found that even variations on well-known government domains are being targeted by malicious ad networks.

    “When one of our researchers tried to report a crime to the FBI’s Internet Crime Complaint Center (IC3), they accidentally visited ic3[.]org instead of ic3[.]gov,” the report notes. “Their phone was quickly redirected to a false ‘Drive Subscription Expired’ page. They were lucky to receive a scam; based on what we’ve learnt, they could just as easily receive an information stealer or trojan malware.”

    The Infoblox report emphasizes that the malicious activity they tracked is not attributed to any known party, noting that the domain parking or advertising platforms named in the study were not implicated in the malvertising they documented.

    However, the report concludes that while the parking companies claim to only work with top advertisers, the traffic to these domains was frequently sold to affiliate networks, who often resold the traffic to the point where the final advertiser had no business relationship with the parking companies.

    Infoblox also pointed out that recent policy changes by Google may have inadvertently increased the risk to users from direct search abuse. Brunsdon said Google Adsense previously defaulted to allowing their ads to be placed on parked pages, but that in early 2025 Google implemented a default setting that had their customers opt-out by default on presenting ads on parked domains — requiring the person running the ad to voluntarily go into their settings and turn on parking as a location.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability (CVE-2025-34352) found by XM Cyber in the JumpCloud Remote Assist for Windows agent allows local users to gain full SYSTEM privileges. Businesses must update to version 0.317.0 or later immediately to patch the high-severity flaw.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Dec. 16, 2025

    Read the full story from BreachLock

    Integrating LLMs (large language models) with enterprise applications enables organizations to directly embed LLMs into operations for a wide range of use cases. These integrations can create greater operational efficiencies and enhance employee productivity, unlock better data insights, improve decision-making, and gain a competitive edge. But these integrations also create certain security risks, according to BreachLock.

    The key risks are data loss, prompt injection attacks, unauthorized actions, and supply chain vulnerabilities. Security teams cannot ignore the new exposure paths that LLM-app integrations introduce. Securing these integrations requires continuous validation, real-world adversarial testing, and a clear understanding of how LLM-driven workflows behave, especially under pressure in unique scenarios.

    In a new blog post, the experts at BreachLock explain how organizations can adopt LLM-app integrations with more confidence and safely turn AI innovation into a competitive advantage.

    Read the Full Story



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post The Risks of Integrating LLMs into Enterprise Apps appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability affecting multiple Apple products to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in the wild.  CVE-2025-43529 represents a severe use-after-free vulnerability in WebKit, Apple’s rendering engine, that poses a significant risk to millions of users across iOS, iPadOS, macOS, and other […]

    The post CISA Alerts on Apple WebKit Zero-Day Actively Used in Cyberattacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Frankfurt am Main, Germany, 16th December 2025, CyberNewsWire

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russian state-sponsored hackers are intensifying attacks on misconfigured network edge devices across Western critical infrastructure, marking a significant tactical shift as 2025 comes to a close. According to new insights from Amazon Threat Intelligence, this campaign linked with high confidence to Russia’s Main Intelligence Directorate (GRU) and the Sandworm/APT44/Seashell Blizzard cluster has deprioritized overt vulnerability […]

    The post Russian Hackers Launch Attacks on Network Edge Devices in Western Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶