• A GitHub repository posing as a vulnerability scanner for CVE-2025-55182, also referred to as “React2Shell,” was exposed as…

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • After pushing hundreds of thousands of government employees to leave their posts and dismantling many government technology units, the Trump administration is launching an effort to recruit new technology talent.

    The United States Tech Force, announced Monday, is meant to hire the artificial-intelligence talent the government needs to win the global AI race and modernize the government, the administration says. The goal is to recruit an initial cohort of around 1,000 technologists who will be placed in agencies for two-year stints as soon as March. 

    “We need you,” said Scott Kupor, the director of the Office of Personnel Management. “The U.S. Tech Force offers the chance to build and lead projects of national importance, while creating powerful career opportunities in both public service and the private sector.”

    The new program aims primarily to recruit early-career software engineers, data scientists, and other technologists. It also seeks some engineering managers on leaves of absence from private-sector companies.

    About 20 technology companies have signed on to participate so far, including Palantir, Meta, and Oracle. Elon Musk’s xAI is also participating, and the NobleReach Foundation — a nonprofit that seeks to inspire science and technology workers toward civil service — will be helping administer the program, OPM says. These companies will allow their employees to take temporary terms of service in the government; they will also provide training and mentorship opportunities to the Tech Force participants. 

    Led by OPM, a team from the Office of Management and Budget, General Services Administration and White House Office of Science and Technology Policy will direct the placing of Tech Force workers at federal agencies, including the Defense Department, Labor Department, IRS, and others. The recruits will be employed by the agency they work for and paid between $150,000 and $200,000 annually. 

    The creation of the Tech Force follows the administration’s hasty closure of several of the government's existing technology teams and the exodus of thousands of other employees under the administration’s various other efforts to reduce the size of the workforce.

    In March, the General Services Administration dismantled 18F, an internal government tech consultancy group, after Elon Musk posted on X that the group had been “deleted.” 

    Other agencies also saw losses. The Social Security Administration closed its tech-focused Office of Transformation in February, the Defense Digital Service closed after suffering mass resignations and the IRS had lost over 2,000 tech workers as of June, for example.

    “There’s a lot of value in bringing in tech talent,” Donald Moynihan, a professor of public policy at the University of Michigan, told Nextgov/FCW. “That said, part of the reason why there’s a need for tech talent in government right now is because [Department of Government Efficiency] drove out some very talented individuals who were already in government.”

    “Another concern is that this could simply recreate some of the worst aspects of the early days of DOGE, which is to bring in people who don't really understand or respect some of the legal constraints that come with working in the public sector,” he said. 

    Trump created DOGE with a nominal focus on technology on his first day in office, although the group became a controversial flashpoint for its work implementing administration goals to cull the ranks of federal workers, shutter entire agencies and access sensitive government data and systems. 

    The website of the new Tech Force emphasizes that the program does not have a “political mission.”

    The ideas behind the new Tech Force aren’t necessarily new. Other government programs have also sought to bring in specialized workers for time-limited stints meant to infuse the government with new ideas and expertise.

    Most notably, the U.S. Digital Service was created during the Obama administration to bring experts into the government for time-limited terms of service. 

    Trump transformed the group to house DOGE on his first day in office, and many former employees were dismissed or quit during the first months of the Trump administration, although around 50 staffers are still at the organization working in various government modernization and tech projects.

    Kupor told reporters that the new program will be much bigger than USDS and bring in technologists to be stationed in agencies.

    The government also already has an early career tech fellowship called the U.S. Digital Corps, which launched in 2022.

    One unique aspect of the newest program is the involvement of private sector companies in allowing employees to participate and then come back to their prior jobs.

    “My first question with any programs like this are, ‘What are the rules that are in place to guard against conflicts of interest?’” said Rob Shriver, former acting OPM director and current managing director of Civil Service Strong at Democracy Forward.

    This is especially worthy of attention, he said, given DOGE’s approach to data — “coming in and taking over agency systems and accessing data without going through the regular procedures” — which has been at the center of several lawsuits.

    The setup may vary by company, but the managing engineers from private companies participating in the program will “effectively take a leave of absence” to become full time government employees during the program, Kupor told reporters Monday. They won’t be required to divest from their stocks.

    “We feel like we’ve run down all the various conflict issues and don’t believe that that’s actually going to be an impediment to getting people here,” said Kupor. “The huge benefit to the government will be getting people who are very skilled in the private sector at managing engineering teams.”

    The idea is that the participants can return to their old jobs with new skills and expertise after working for the government, he said. 

    “Come work on literally the world’s most complex and difficult problems,” Kupor said in his pitch to potential recruits. “There is no bigger and more complex set of problems than we face in the federal government.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Multiple security vulnerabilities have been disclosed in the open-source private branch exchange (PBX) platform FreePBX, including a critical flaw that could result in an authentication bypass under certain configurations. The shortcomings, discovered by Horizon3.ai and reported to the project maintainers on September 15, 2025, are listed below – CVE-2025-61675 (CVSS score: 8.6) – Numerous

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Dec. 15, 2025

    Watch the YouTube video

    Thanks to artificial intelligence (AI), cybercrime and, as a result, cybersecurity are evolving rapidly, leaving businesses and individuals across the world scrambling to catch up.

    Cybercrime Magazine caught up with Mastercard’s Deputy CSO Alissa (Dr Jay) Abdullah to discuss the field’s explosive growth.

    Dr Jay looks at the past, present, and future of AI and cybersecurity in a new three-minute video, a must-watch for consumers, small-to-midsize businesses, and large enterprises.

    You can learn more from Dr Jay on “Mastering Cyber“, a weekly one-minute series on the Cybercrime Magazine Podcast to help you maneuver cybersecurity industry tips, terms, and topics.

    Whether you’re a C-suite executive, CIO, CISO, IT security professional, engineer, or developer, or a small business owner, student, parent, or educator, Dr Jay’s podcast series speaks to you.

    Watch the Video



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Mastercard’s Deputy Chief Security Officer Alissa (Dr Jay) Abdullah, PhD on AI & Cybersecurity appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft’s December 2025 security update has introduced a significant compatibility issue affecting Message Queuing (MSMQ) functionality across Windows Server and client environments. The problematic update, identified as KB5071546 (OS Build 19045.6691), was released on December 9, 2025, and has already impacted organizations relying on MSMQ for inter-application communication, particularly in Internet Information Services (IIS) deployments. […]

    The post Microsoft December 2025 Security Updates Disrupt MSMQ Functionality on IIS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Since December 2025, security operations centers have identified a rising threat targeting Japanese enterprises through the exploitation of React2Shell (CVE-2025-55182), a critical remote code execution vulnerability affecting React and Next.js applications. While initial attacks primarily deployed cryptocurrency miners, researchers discovered a more dangerous payload a previously unknown malware family designated ZnDoor. Evidence suggests this threat […]

    The post ZnDoor Malware Actively Exploits React2Shell to Breach Network Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers discovered an unsecured 16TB database exposing 4.3 billion professional records, including names, emails, and LinkedIn data. Learn what happened, why this massive data leak enables new scams, and how to protect your PII.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated attack campaign attributed to a group identifying as “PCP” has compromised 59,128 servers in less than 48 hours by exploiting critical Next.js vulnerabilities. Security researchers discovered the large-scale operation while monitoring a Docker honeypot, uncovering an industrialized attack infrastructure with command-and-control capabilities targeting React-based applications globally. The campaign leverages CVE-2025-29927 and CVE-2025-66478, two […]

    The post PCPcat Malware Leverages React2Shell Vulnerability to Breach 59,000+ Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New report by Unit 42 reveals the Hamas-linked Ashen Lepus (WIRTE) group is using the AshTag malware suite to target Middle Eastern diplomatic and government entities with advanced, hidden tactics.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • xHunt, a sophisticated cyber-espionage group with a laser focus on organizations in Kuwait, has continued to demonstrate advanced capabilities in infiltrating critical infrastructure. The group’s persistent, multi-year campaigns targeting the shipping, transportation, and government sectors underscore the evolving threat landscape facing Middle Eastern enterprises. Since its first documented operations in July 2018, xHunt has refined […]

    The post xHunt APT Exploits Microsoft Exchange and IIS to Deploy Custom Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶