• This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Dec. 9, 2025

    Read the full story from Wiz

    Due to their cascading effect, supply chain attacks are costlier than most, with vendors and customers both bearing the brunt. Global costs of software supply chain attacks alone are estimated at $60 billion in 2025, and they’re expected to reach a whopping $138 billion by 2031, according to Cybersecurity Ventures.

    Wiz breaks down three types of supply chain attacks:

    Software supply chain attacks infiltrate software vendor systems to deliver compromised software to thousands of customers;

    Hardware supply chain attacks involve adversaries introducing counterfeit devices into the global supply chain;

    Third-party service attacks target customers of cloud service providers (CSPs), managed service providers (MSPs), SaaS platforms, and AI vendors by compromising software updates, API keys, or service integrations.

    Comprehensive supply chain security requires visibility across the entire code-to-cloud lifecycle, and Wiz breaks that down for CISOs and security leaders in a blog post that includes a handy cheat sheet with best practices.

    Read the Full Story



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Global Costs of Software Supply Chain Attacks On The Rise appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zero Trust helps organizations shrink their attack surface and respond to threats faster, but many still struggle to implement it because their security tools don’t share signals reliably. 88% of organizations admit they’ve suffered significant challenges in trying to implement such approaches, according to Accenture. When products can’t communicate, real-time access decisions break down. The

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google on Monday announced a set of new security features in Chrome, following the company’s addition of agentic artificial intelligence (AI) capabilities to the web browser. To that end, the tech giant said it has implemented layered defenses to make it harder for bad actors to exploit indirect prompt injections that arise as a result of exposure to untrusted web content and inflict harm. Chief

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Canadian organizations have emerged as the focus of a targeted cyber campaign orchestrated by a threat activity cluster known as STAC6565. Cybersecurity company Sophos said it investigated almost 40 intrusions linked to the threat actor between February 2024 and August 2025. The campaign is assessed with high confidence to share overlaps with a hacking group known as Gold Blade, which is also

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered two new extensions on Microsoft Visual Studio Code (VS Code) Marketplace that are designed to infect developer machines with stealer malware. The VS Code extensions masquerade as a premium dark theme and an artificial intelligence (AI)-powered coding assistant, but, in actuality, harbor covert functionality to download additional payloads, take

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Updated Dec. 9, 10 a.m. ET:

    The Pentagon will widely deploy new AI tools for logistics, intelligence analysis, and combat planning in days or weeks, its research-and-engineering chief said Monday, adding that wide deployment of artificial intelligence now tops his list of “critical technologies.”

    The department has chosen Gemini for Government as the platform that will support DOD’s first department-wide rollout of AI tools, Google and defense officials announced Tuesday morning.

    The moves come after the Defense Innovation Unit, the Chief Digital and Artificial Intelligence Office, or CDAO, and others were combined under Emil Michael, defense undersecretary for research and engineering, in a bid to accelerate deployment of AI and other technologies. He said that he will likely reduce the number of technology areas that DIU is working on as well. 

    The advent of large-language-model tools such as ChatGPT, Claude, and Gemini have made it possible—and necessary—to develop AI tools faster, Michael told reporters at the Defense Writers Group on Monday.

    “The explosion of capabilities has been enormous, and we're just catching up to that,” he said. “Now we can take CDAO and actually try to use it to push the capability into the Department for actual use cases.”

    He said that expands the usefulness of CDAO, which was largely managing in-house analytic tools like Advana and exploring data assets within the military.

    The explosion of ChatGPT and other consumer tools makes that necessary, Michael said Saturday during the Reagan Defense Forum in California.

    “For a department of 3 million people, we're vastly under-utilizing AI relative to the general population,” he said.

    On Monday, Michael said Russia’s war on Ukraine and Ukraine’s response serves as a key lens on future conflict.

     “You have a robot on robot frontline now, which we've never seen before,” he said.

    And China’s military buildup of the past 10 to 15 years—“the most significant” in world history, he said— also “requires a kind of a different mindset.” 

    Michael said China is working to reverse-engineer advanced chips and to develop its own.

    “China is absolutely trying to indigenize their own TSMC. If you look at the supply chain of the ASML, TSMC, and Nvidia, [China is] trying to replicate that capability with their own domestic sources,” he said.

    Michael said he is seeking help from foreign countries such as Australia and South Korea, searching for more sources for chips, access to test ranges for hypersonic weapons, and more.

    Last month, he pared the list of critical technology areas that his office would pursue from 14 to six. (“14 priorities, in truth, means no priorities at all,” he said in a Nov. 17 video.) On Monday, he said that wide AI deployment would be his top priority. 

    “I'm going to put the capability in front of you so you can start learning, using it. We'll have training. We'll have support for deployed engineers, all that. And then you'll see innovations come from there.” 

    He said his office would soon announce acquisition changes along the lines of the Pentagon’s broader November announcement.

    Michael made his remarks days after the White House released a National Security Strategy that declared an intention to refocus the U.S. security and strategy toward the Western Hemisphere. He deferred policy questions to people “abiove his pay-grade’ but said that he was still “focused much more on other parts of the world”—particularly China, the potential adversary whose capabilities are closest to the Pentagon’s.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Two divisions of General Dynamics are looking to coworking spaces and brainstorming events to bring companies together to build, showcase, and ultimately deliver new technology faster.

    This week, General Dynamics Information Technology opened a new 5,200 square-foot digital lab called the Mission Emerge Center outside of Fort Belvoir, Va. The goal for the facility is to develop military technology alongside other companies, including cloud providers—and to show the Pentagon what works.

    It’s not always possible to show defense officials what new tech can actually do in their offices, so having a separate space could help show the Pentagon what’s possible. 

    “I've spent a lot of time in my life in uniform—and not in uniform—in the Pentagon, and there isn't the opportunity in the Pentagon to showcase this…to demonstrably show how it works,” Amy Gilliland, GDIT’s president, told reporters Dec. 2. “We can create solutions that we showcase here that are attached to a sandbox environment that we’re building where the customer can actually see things.”

    The project took more than a year, and the company’s strategy of  building a space for government customers to engage with developing technology and provide input, dovetails with the Pentagon’s call for defense contractors to take on more risk

    “If we are going to prevent and avoid war, which is what we all want, we must prepare now. Our adversaries are not sitting idly by. They're moving fast. They're developing and delivering new capabilities at a rate that should be sobering to every American,” Defense Secretary Pete Hegseth said during a Nov. 7 speech. “And frankly, at times, we've been too damn slow to respond.”

    “What the customer is telling us now is, you understand the mission, and you understand technology, and you need to anticipate what is coming next. So help us. Help us help ourselves. So that anticipatory piece is part of the investment, because if you don't invest ahead of time, by definition, you'll be late,” Gilliland said. 

    GDIT has pivoted in recent years from primarily a “very good executor of enterprise IT” to building products. That shift also marked a change from “one-off partnerships with commercial companies”  to those with “strategic collaboration agreements,” Gilliland said. 

    Earlier this year, GDIT gave new leaders in its emerging tech business a clear directive: understand what the Defense Department needs and find new companies with “promising” tech to work with that could potentially fulfill those needs. 

    “Those partnerships can ultimately end up being a teaming arrangement. They could be an acquisition in the future. They could be any number of things,” Gilliland said. “Part of the value proposition of an IT services company to a corporation like General Dynamics is very low invested capital. What I am leveraging is the R&D budgets of commercial companies, together with the mission understanding and expertise of this workforce and my technologists to bring forward the best that commercial tech has.” 

    And while each arrangement is different, the new facility was designed to encourage co-development. 

    “Companies are typically voluntarily contributing their R&D efforts alongside GDIT. We build these relationships to maximize impact, and facility access is part of that,”  Dale Hogan, GDIT’s information systems senior director, said via email. GDIT said it doesn’t charge companies for access to the lab. 

    Putting defense companies in close proximity isn’t new, but the idea could become more popular as the Pentagon courts business from smaller, non-traditional companies, which are often backed by private investors. 

    Instead of creating a new facility, General Dynamics Land Systems, which builds combat vehicles, plans to join a co-working space that caters to startups and investors in downtown Detroit

    “We actually just recently signed to become a full member of Newlab,” and start placing employees in the coworking space in the New Year, said Scott Taylor, who leads business development for General Dynamics Land Systems. “Because what we're realizing is—as much as we don't want it to be—the security protocols of the defense company compound that we're in [in Sterling Heights, Mich.] can be daunting at times…It can slow that ability to share emerging capabilities from the commercial sector back into the defense sector.”

    General Dynamics Land Systems tested Newlab's potential last week when it hosted an event for military leaders, investors, and drone companies to talk through challenges for ground troops, like battery life and resupply, and how to solve them.

    “Senior leaders in the Army—from the secretary to the chief—have been encouraging industry to start self organizing and bring a team of teams together to solve the Army and the Marine Corps’, land forces’, biggest problems, or present solutions” so the military can know what’s doable, Taylor said.

    The inaugural event, called the Maneuver Warfighter Industry Symposium, hosted  defense tech companies, such as Anduril, Palantir, Autonodyne, Primordial Labs, investors, and other representatives from General Dynamics entities. The plan is to do more next year, Taylor said.  

    “We all have a very similar common goal: We want to support the U.S. military, and our allies' needs,” Taylor said. “How we achieve that collaboration requires a little bit more thought and mature effort.” 

    Plus, the sheer competition and potential for billions of contract dollars can mean that working together may be riskier than it sounds—even if there’s a common goal. 

    “You fill a room with 24 companies, and some of [them] are competitors with each other. They're not always forthright in being very open…we recognize that that's a part of the risk. But what we thought was valuable is the opportunity to just figure out who had the most promising [proposals] to pursue some of these,” Taylor said. “Frankly, I think there's an opportunity for us to pull in several of our ‘competimates’.” 

    But while there seems to be demand, it will take time to find the right mix of companies to create something the Pentagon wants to buy. 

    “Do we have the right team put together? Not yet,” he said. “It's still in development right now. How we formalize that consortium remains to be seen.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • House leaders have stripped a bipartisan provision aimed at protecting civilian Defense Department workers’ collective bargaining rights after Senate Republicans balked at the prospect of clashing with President Trump over his efforts to excise unions from most federal agencies.

    Last July, the House Armed Services Committee voted to bar the Pentagon’s use of fiscal 2026 funds to implement Trump’s March executive order stripping two-thirds of the federal workforce of their collective bargaining rights, including the measure as part of the 2026 National Defense Authorization Act. The House voted 231-196 to pass the bill in September, leaving the provision intact.

    But when the House Rules Committee unveiled compromise language for the annual must-pass bill on Sunday, the measure, originally proposed by Rep. Donald Norcross, D-N.J., had disappeared. A source familiar with congressional negotiations told Government Executive that despite 16 House Republicans urging their Senate colleagues to support the measure, only Sen. Lisa Murkowski, R-Alaska, ultimately pushed for its inclusion.

    Matt Biggs, national president of the International Federation of Professional and Technical Engineers said the provision’s exclusion from the likely final version of the NDAA was a “disappointment.” Although there are other avenues for lawmakers to nullify the anti-union executive orders, like the Protect America’s Workforce act, which is slated for a vote on the House floor in the coming weeks, including the measure on an annual must-pass bill was seen as the most realistic.

    “We put a lot of effort into [the NDAA provision] and our members made a lot of calls,” he said. “If it was part of the NDAA, the White House wouldn’t have vetoed it. If it passed on its own, they could have, but the NDAA’s too important.”

    The American Federation of Government Employees on Monday called on lawmakers to vote against the bill. The House Rules Committee is set to consider the compromise bill on Tuesday.

    “Congress should not be in the business of weakening national security by weakening the workforce that makes national security possible,” said AFGE National President Everett Kelley. “DOD civilians are patriots. They serve this country with skill, honor and sacrifice. Denying them collective bargaining rights is wrong, it is harmful to the mission, and it has no place in a defense bill. If lawmakers are serious about supporting our military, they must send this bill back to conference, fix it, restore these protections and then pass an NDAA worthy of the men and women who defend this nation every day.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Nearly a year after Defense Secretary Pete Hegseth purged the top judge advocates general of the Army, Navy, and Air Force, lawmakers are poised to require an explanation if it happens again.

    A provision in the compromise version of the 2026 National Defense Authorization Act would require the defense secretary to provide Congress with notice and a reason for the removal soon after a top JAG’s dismissal.

    “If the Judge Advocate General is removed from office before the end of the term … the Secretary of Defense shall, not later than five days after the removal takes effect, submit to the Committees on Armed Services of the Senate and the House of Representatives notice that the Judge Advocate General is being removed and a statement of the reason for the removal,” the provision reads. 

    The provision was originally inserted in the Senate version of the NDAA, which passed in October. It appears in the 3,000-plus-page version agreed by House and Senate negotiators, which was released late Sunday evening and could see a House vote within days.

    Three days after Hegseth fired the services’ JAGs in February, he said that the lawyers were “roadblocks to orders that are given by a commander in chief.”

    The top JAGs—sometimes called TJAGs—are the principal legal advisers to leaders of their service branch.

    Fears are growing within the national-security legal community that military legal guidance is being ignored, especially as seemingly unjustified airstrikes on alleged drug boats continue. 

    Sen. Elizabeth Warren, D-Mass., a member of the Senate Armed Services Committee, inserted the language into the Senate’s version of the NDAA this summer. 

    “Secretary Hegseth’s attack on independent legal advisors doesn’t make anyone safer. I’m fighting to rein in this abuse of power and ensure transparency from this administration,” Warren said in a July news release.

    A Warren spokesperson had no further comment on Sunday evening.

    One former JAG said the language was a notable development, but was skeptical about how transparent the Pentagon would be about such removals. Military branches have often offered no more than some variation of the phrase “loss of trust and confidence” in explaining the dismissal of officers from top leadership roles. 

    “I hope that this helps. My fear is that the Department of Defense will cite generic rationale for removing the individual,” the former JAG said. “My other hope is that we never see a future TJAG removed in a way that this current administration has done it.”  

    The Air Force’s top legal role has remained vacant since Hegseth fired Lt. Gen. Charles Plummer on Feb. 21. Maj. Gen. Rebecca Vernon, who had served as the service’s deputy JAG, became acting TJAG earlier this year but stepped away from the job in October and is set to retire by Jan. 1, Defense One first reported. An Air Force spokesperson said there’s an acting TJAG but the deputy JAG position remains vacant.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers are calling attention to a new campaign dubbed JS#SMUGGLER that has been observed leveraging compromised websites as a distribution vector for a remote access trojan named NetSupport RAT. The attack chain, analyzed by Securonix, involves three main moving parts: An obfuscated JavaScript loader injected into a website, an HTML Application (HTA) that runs encrypted

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶