• With the holiday shopping season kicking into high gear, a massive cybersecurity threat has emerged, putting online shoppers at significant risk.

    A coordinated campaign has been discovered, involving the registration of over 2,000 fake holiday-themed online stores.

    These malicious sites are designed to lure unsuspecting consumers with the promise of steep discounts, only to steal their payment information and personal data.

    The scale of this operation is vast, with two distinct clusters of fraudulent storefronts identified, both employing sophisticated tactics to appear legitimate and deceive shoppers.

    The first cluster primarily consists of typosquatted domains mimicking Amazon, while the second spans a wide array of “.shop” domains impersonating well-known brands such as Apple, Samsung, and Ray-Ban.

    These fake stores are not isolated incidents but part of a large-scale, automated campaign. The threat actors behind this operation have timed their attack to coincide with peak shopping periods like Black Friday and Cyber Monday, when consumers are actively hunting for bargains and may be less cautious about unfamiliar websites.

    Fake storefront (Source - CloudSEK)
    Fake storefront (Source – CloudSEK)

    CloudSEK security researchers noted the coordinated nature of these scams, identifying the use of identical phishing kits, recurring website templates, and shared infrastructure across the network of fake stores.

    This level of coordination suggests a well-organized and resourced operation. The impact on consumers is severe, ranging from direct financial losses to the long-term risks of identity theft.

    Furthermore, these scams erode trust in legitimate online retailers and the e-commerce ecosystem as a whole.

    Infection and Deception Tactics

    The modus operandi of these fake stores is both simple and effective. They leverage a combination of social engineering and technical evasion to trick users and avoid detection.

    The sites are designed to look like professional e-commerce platforms, complete with holiday-themed banners, countdown timers creating a false sense of urgency, and fake “trust badges” to build credibility.

    Fabricated “recent purchase” pop-ups are also used to create social proof and pressure visitors into making a purchase.

    Fake Landing Page (Source - CloudSEK)
    Fake Landing Page (Source – CloudSEK)

    When a user attempts to buy a product, they are redirected to a shell checkout page designed to harvest their billing and payment details.

    These shell websites often use unflagged domains to process transactions, allowing the attackers to bypass fraud detection systems.

    Fake & Impersonating Domains:-

    Domain ClusterImpersonated BrandFake Domain Examples
    Cluster A (Amazon-themed)Amazonamaboxhub.com, amawarehousesale.com, amaznshop.com
    Cluster B (.shop domains)Xiaomixiaomidea.shop
    Jo MaloneJomalonesafe.shop
    FujifilmFujifilmsafe.shop
    SamsungSamsungsafe.shop
    A popular brand[brand]safe.shop or [brand]fast.shop

    The investigation also revealed that a shared Content Delivery Network (CDN), cdn.cloud360.top, was used to serve assets to over 750 of the fake stores, further highlighting the centralized nature of the campaign.

    A recurring JavaScript file, identified by its unique SHA-256 hash, was also found across numerous malicious .shop domains, controlling the fraudulent checkout process.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Hackers Registered 2,000+ Fake Holiday-Themed Online Stores to Steal User Payments appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New York, New York, December 1st, 2025, CyberNewswire BreachLock, the global leader in Penetration Testing as a Service (PTaaS), has been named a Leader and Fast Mover in the 2025 GigaOm Radar Report for PTaaS for the third year in a row. The GigaOm Radar Report for PTaaS is published annually to help security leaders and practitioners […]

    The post BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New York, New York, December 1st, 2025, CyberNewswire

    BreachLock, the global leader in Penetration Testing as a Service (PTaaS), has been named a Leader and Fast Mover in the 2025 GigaOm Radar Report for PTaaS for the third year in a row.

    The GigaOm Radar Report for PTaaS is published annually to help security leaders and practitioners evaluate PTaaS solutions for more informed decision-making. This year’s report evaluated 16 of the top PTaaS providers in the market based on key feature capabilities, their ability to meet enterprise business requirements, deployment models, and other important decision-making criteria.  

    2025 marks the third year in a row BreachLock has been positioned as a leader and fast mover in the Maturity and Platform Play Quadrant of the GigaOm PTaaS Radar Report, demonstrating both its consistency and platform innovations geared towards enterprise customers.  

    BreachLock and the 15 other PTaaS providers evaluated in the report were scored based on the following key feature capabilities: 

    1. Built-in vulnerability scanners 
    2. Integration with SDLC technologies 
    3. API access 
    4. Customizable testing methodologies 
    5. Retesting of findings 
    6. Streamlined procurement 
    7. Crowdsourcing pentesters 
    8. Compliance Reporting 

    BreachLock scored highly in all but one category, with the exception of crowdsourcing pentesters, helping earn its position as a leader and fast mover in this year’s report. While crowdsourcing pentesters has its benefits, BreachLock’s 100% in-house team of highly skilled, certified expert pentesters offers enterprises a higher level of consistency, scalability, and reliability to guarantee quality results when penetration testing critical systems and applications. 

    BreachLock also scored highly in GigaOm’s business criteria comparison focused on non-functional requirements buyers commonly consider for purchase decision-making to determine a solution’s impact on an organization. The five factors evaluated as part of the business criteria comparison included: 

    1. Flexibility 
    2. Scalability 
    3. Speed 
    4. Risk Reduction 
    5. Cost 

    While the key capabilities and business criteria scores were the most heavily weighted criteria for radar positioning, GigaOm also scored each provider on emerging features, which scored providers’ integration capabilities with attack surface management (ASM) and private PTaaS platforms. 

    Lastly, GigaOm’s solution overview of BreachLock highlights its unified, cloud-native platform that combines PTaaS, Continuous Threat Exposure Management (CTEM), and Adversarial Exposure Validation (AEV), addressing how it enables organizations to transition from traditional point-in-time security testing to continuous, threat intelligence-driven offensive security. 

    Commenting on BreachLock’s position in the report, Seemant Sehgal, Founder & CEO of BreachLock, expressed, “It’s an honor to be recognized by GigaOm as a PTaaS leader for the third year in a row, which is a clear reflection of BreachLock’s constant innovation and focus on enterprise needs.” He added, “The world is evolving fast with Agentic AI—and so are attackers. BreachLock is one of the very few offensive security companies leading this shift. Our unified, agentic, and automation-first approach is reshaping enterprise-scale offensive security, and we’re proud to be ranked alongside the best—driving innovation, speed, and measurable outcomes for our clients.” 

    Chris Ray, author of the GigaOm Radar Report for PTaaS, highlighted BreachLock’s strengths in the report, writing, “BreachLock excels for enterprises with CI/CD pipelines requiring continuous security validation through its deep SDLC integration, risk-contextualized findings, and pipeline security gates. Its unified PTaaS and ASM solution provides seamless visibility for organizations transitioning from periodic to continuous security testing, eliminating blind spots between scheduled assessments.” 

    About BreachLock 

    BreachLock is a global leader in offensive security, delivering scalable and continuous security testing. Trusted by global enterprises, BreachLock provides human-led and AI-powered Attack Surface Management, Penetration Testing as a Service (PTaaS), Red Teaming, and Adversarial Exposure Validation (AEV) solutions that help security teams stay ahead of adversaries. 

    With a mission to make proactive security the new standard, BreachLock is shaping the future of cybersecurity through automation, data-driven intelligence, and expert-driven execution.

    Contact

    Senior Marketing Executive
    Megan Charrois
    BreachLock
    megan.c@breachlock.com

    The post BreachLock Named a Leader in 2025 GigaOm Radar Report for Penetration Testing as a Service (PTaaS) for Third Consecutive Year appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered Windows malware packer named TangleCrypt has emerged as a serious threat in ransomware attacks, specifically designed to evade endpoint detection and response (EDR) solutions.

    The packer was first observed during a September 2025 ransomware incident involving Qilin ransomware, where threat actors deployed it alongside the ABYSSWORKER driver to disable security tools before encrypting victim systems.

    TangleCrypt works by hiding malicious payloads through multiple layers of encoding, compression, and encryption. The original executable is stored within PE resources using base64 encoding, LZ78 compression, and XOR encryption.

    This multi-layer approach makes it difficult for traditional security tools to detect the actual malware hidden inside the packed executable.

    WithSecure Labs security researchers identified the malware during an incident response investigation, recovering artifacts including two executables packed with TangleCrypt and VMProtect, along with a kernel driver masquerading as a CrowdStrike Falcon Sensor driver.

    The payload embedded in these executables was identified as STONESTOP, an EDR-killer tool that uses the ABYSSWORKER driver to terminate security processes running on the system forcibly.

    The packer employs string encryption and dynamic import resolving to hinder both static and dynamic analysis.

    Although malware authors commonly use these techniques, the TangleCrypt implementation lacks advanced anti-analysis mechanisms, making manual unpacking relatively straightforward for experienced analysts.

    Payload Execution Mechanism

    TangleCrypt supports two distinct methods for launching its payload, determined by a configuration string appended to the embedded executable.

    The first method, identified by the string “exex64_amd64_block_”, decrypts and executes the payload within the same process memory.

    The second method, marked with “exex64_amd64__riin”, creates a suspended child process and writes the decrypted payload into it before resuming execution.

    ProcessMonitor log of ‘b1.exe’ starting child process of itself (Source – Withsecure Labs)

    When executed, the loader first decrypts a small resource entry containing a numeric key, such as “175438”. This key is then used to XOR-decrypt the larger payload stored in the PE resources.

    The decryption process follows a specific sequence where a base64-encoded string is decoded, then LZ78 decompressed, decoded again from base64, and finally XOR-decrypted to reveal the original executable.

    Upon successful unpacking, the STONESTOP payload checks for administrative privileges and registers the ABYSSWORKER driver if elevated rights are present.

    The driver then terminates processes matching a predefined list of security product names, effectively blinding the system’s defenses before ransomware deployment begins.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post TangleCrypt Windows Packer with Ransomware Payloads Evades EDR Using ABYSSWORKER Driver appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has acknowledged a frustrating new issue affecting users of the “new Outlook” for Windows, where Excel attachments fail to open if their filenames contain non-ASCII characters.

    The technical glitch, tracked under the reference ID EX1189359, triggers a vague error message advising users to “Try opening the file again later,” leaving many confused about the cause of the blockage.​

    The problem targets the modern “new Outlook” client explicitly and does not appear to impact the classic version of the software. According to Microsoft’s service health dashboard, the root cause lies in an encoding error within the request used to open the files.

    When an Excel file attached to an email includes non-standard characters such as accented letters, symbols, or non-English scripts, the application fails to process the filename correctly, resulting in an immediate error.​

    This issue has been ongoing since late November 2025, with initial reports surfacing around November 23. While the scope is limited to specific file naming conventions, the impact is significant for international users or organizations that frequently use non-ASCII characters in document titles.​

    Microsoft’s Response and Fix Status

    As of the latest update on December 1, 2025, Microsoft engineers have successfully developed a fix to address the missing encoding in file-handling requests.

    However, the solution is not yet available to all users. The company is currently in the validation phase, testing the deployment to ensure it resolves the error without introducing secondary issues.​

    Microsoft is also investigating why this encoding error occurred in the first place to prevent similar regressions in future updates. A further status update is expected by the evening of December 1, UTC time.​

    Until the patch is fully rolled out, Microsoft has provided two official workarounds for users who need immediate access to their spreadsheets:

    • Use Outlook on the Web (OWA): The web-based version of Outlook correctly processes these attachments, bypassing the client-side encoding failure.​
    • Download the File Locally: Users can save the attachment to their computer first. Once the file is saved to a local drive, it can be opened directly in Excel without triggering the Outlook previewer error.​

    This incident joins a growing list of pains for the new Outlook client, which has faced scrutiny from power users for feature-parity gaps compared to the classic COM-based application. Admin administrators can track the progress of the fix in the Microsoft 365 admin center under EX1189359.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Confirms New Outlook Bug Blocking Excel Attachments appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • India’s telecommunications ministry has reportedly asked major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days. According to a report from Reuters, the app cannot be deleted or disabled from users’ devices. Sanchar Saathi, available on the web and via mobile apps for Android and iOS, allows users to report

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated Advanced Persistent Threat group known as Bloody Wolf has intensified its cyber espionage operations across Central Asia, targeting government and private sectors.

    Since late June 2025, the group has orchestrated spear-phishing campaigns primarily focusing on organizations within Kyrgyzstan and Uzbekistan.

    By meticulously impersonating state entities such as the Ministry of Justice, the attackers successfully deceive victims into compromising their systems.

    The primary vector involves weaponized PDF documents sent via email, mimicking official correspondence. These documents often bear titles suggesting urgent legal matters or case materials, compelling recipients to interact with embedded links.

    Once clicked, these links initiate a multi-stage infection process designed to bypass traditional security defenses and establish long-term access to the victim’s network.

    Group-IB security analysts identified this surge, noting the group shifted from commercial malware like STRRAT to deploying the legitimate, yet weaponized, NetSupport Remote Administration Tool.

    This strategic pivot allows attackers to blend in with normal administrative traffic, making detection significantly more challenging for corporate security teams.

    The campaigns demonstrate a high level of regional adaptation, including the use of local languages and geo-fencing techniques to restrict payload delivery to targets within specific countries.

    The impact is profound, granting attackers full remote control over infected endpoints. This access facilitates data exfiltration, system inventory surveillance, and lateral movement within critical infrastructure networks.

    Infection Chain

    Bloody Wolf’s technical strategy relies on malicious Java Archive files to execute the payload. Victims interacting with the lure are prompted to update Java, a pretext masking the malicious loader’s execution.

    The JAR files, compiled with Java 8, are unobfuscated but highly effective. In the Uzbekistan campaign, the infrastructure employed geo-fencing, where only requests originating from within the country triggered the download of the malicious JAR, while others were redirected to legitimate government portals.

    Persistence functions code (Source - Group-IB)
    Persistence functions code (Source – Group-IB)

    Once executed, the JAR loader ensures persistence through redundant methods. The malware drops a batch file into the Windows Startup folder and modifies registry keys, executing commands like cmd.exe to ensure the RAT launches upon reboot.

    Fake error message pop-ups (Source - Group-IB)
    Fake error message pop-ups (Source – Group-IB)

    Additionally, it creates a scheduled task using schtasks to guarantee execution. This redundancy ensures that the NetSupport RAT remains active on the system, allowing the attackers to maintain a persistent foothold while displaying fake error messages, to distract the user from the background malicious activity.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Bloody Wolf Hackers Mimic as Government Agencies to Deploy NetSupport RAT via Weaponized PDF’s appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • South Korean e-commerce giant Coupang has confirmed a massive security incident affecting approximately 33.7 million customers—nearly the company’s entire user base.

    The breach, which exposed names, phone numbers, email addresses, shipping addresses, and order histories, has been traced back to a former employee who exploited unrevoked internal access credentials.

    While the scale of the leak is unprecedented, Coupang has assured customers that sensitive financial data, including credit card numbers and payment information, as well as account passwords, were not compromised.

    The company has stated that affected users do not need to take specific protective actions regarding their accounts but should remain vigilant against potential phishing attempts disguised as official Coupang communications.

    The unauthorized access reportedly began on June 24, 2025, but went undetected for months. Coupang first identified abnormal activity on November 18, initially estimating that only 4,500 accounts were impacted.

    However, a subsequent internal investigation revealed the true extent of the damage, confirming that tens of millions of records had been accessed via an overseas internet connection.

    The breach highlights a critical failure in Coupang’s identity and access management (IAM) protocols. According to Rep. Choi Min-hee, chair of the National Assembly’s Science, ICT, Broadcasting and Communications Committee, the company failed to revoke cryptographic signing keys associated with a former employee upon their departure.

    The suspect, believed to be a former staff member of Chinese nationality who worked on authentication systems, allegedly used these valid signing keys to generate access tokens.

    These tokens allowed the attacker to bypass standard login procedures and access the system remotely. Coupang admitted that while industry standards for key expiration vary, the specific keys used in this attack remained valid long after the employee left the organization.

    The Seoul Metropolitan Police Agency is currently analyzing server logs and collaborating with international agencies to trace the IP address involved. Investigators are also determining if the suspect is linked to anonymous emails sent to Coupang threatening to reveal the security flaws. Notably, these communications did not include a ransom demand.

    The regulatory fallout for Coupang could be historic. Under the Personal Information Protection Act, companies can be fined up to 3 percent of their average annual revenue for such violations.

    Given Coupang’s recent revenue figures, the fine could reach as high as 1 trillion won ($680 million), potentially shattering the previous record penalty of 134.8 billion won set by a prior telecommunications breach.

    Coupang is currently notifying all affected individuals via email and text message, while fully cooperating with the Personal Information Protection Commission and the Korea Internet & Security Agency.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Coupang Data Breach Exposed Personal Data of 33.7 Million Customers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A threat actor known as ShadyPanda has been linked to a seven-year-long browser extension campaign that has amassed over 4.3 million installations over time. Five of these extensions started off as legitimate programs before malicious changes were introduced in mid-2024, according to a report from Koi Security, attracting 300,000 installs. These extensions have since been taken down. “These

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • “Kill everybody.” Several key bipartisan U.S. lawmakers are warning the U.S. military may have committed war crimes when it launched its first attacks against alleged drug-trafficking boats around Latin America on Sept. 2, according to reporting Friday from Alex Horton and Ellen Nakashima of the Washington Post.  

    Rewind: After the very first U.S. strike, at least two survivors were seen still alive and “clinging to the smoldering wreck” of their destroyed boat, according to the Post’s reporting, which cited seven people with knowledge of the event. Eleven people had been on the boat when the military first hit it with a missile. When a drone feed revealed the two survivors moments later, the Joint Special Operations commander overseeing the strikes at the time—Navy Adm. Frank Bradley—ordered a second strike to kill them, and the “two men were blown apart in the water,” according to the Post

    Defense Secretary Pete Hegseth had delivered a spoken directive to “kill everybody” on the boat, a person with direct knowledge of the operation told the Post. It’s not clear that Hegseth was aware of the survivors; but his subordinates were reportedly keen on following orders since, as the Post reports, Bradley “ordered the second strike to fulfill Hegseth’s directive that everyone must be killed.” (Bradley has since been placed in command of U.S. Special Operations Command, which oversees JSOC.) “If the video of the blast that killed the two survivors on Sept. 2 were made public, people would be horrified, said one person who watched the live feed,” the newspaper reports. 

    If the reporting is true, it would appear the U.S. military violated Section 5.4.7 of the Defense Department’s Law of War Manual (PDF), which states “it is prohibited to order that legitimate offers of surrender will be refused or that detainees, such as unprivileged belligerents, will be summarily executed.” The manual continues, “Moreover, it is also prohibited to conduct hostilities on the basis that there shall be no survivors, or to threaten the adversary with the denial of quarter. This rule is based on both humanitarian and military considerations. This rule also applies during non-international armed conflict.”

    Notable: Hegseth did not dispute the account; but he did call the Post’s reporting “fabricated, inflammatory, and derogatory,” writing Friday on social media, and insisted “Our current operations in the Caribbean are lawful under both U.S. and international law.” 

    New: Both the House and Senate Armed Services Committee leaders announced investigations into the allegations. From the Senate side, “The Committee has directed inquiries to the Department, and we will be conducting vigorous oversight to determine the facts related to these circumstances,” Roger Wicker, R-Miss., and Jack Reed, D-R.I., said in a joint statement, The Hill reported Saturday morning. 

    HASC leaders also vowed “bipartisan action to gather a full accounting of the operation in question,” according to a joint statement from Chairman Mike Rogers, R-Ala., and Adam Smith, D-Wash., Saturday afternoon. “This committee is committed to providing rigorous oversight of the Department of Defense’s military operations in the Caribbean. We take seriously the reports of follow-on strikes on boats alleged to be ferrying narcotics in the SOUTHCOM region,” they said. (And for what it’s worth, “The two committees referred to the Department of Defense by that name, rather than by the ‘Department of War’ rebrand Hegseth and Trump have pushed,” historian Heather Cox Richardson noted Saturday evening.)

    “This rises to the level of a war crime if it's true,” said Sen. Tim Kaine, D-Va., speaking Sunday on “Face the Nation” from CBS News. 

    “Obviously, if that occurred, that would be very serious and I agree that that would be an illegal act,” said Rep. Mike Turner, R-Ohio, speaking Sunday on “Face the Nation” as well. Turner also said the reported events are “completely outside anything that has been discussed with Congress and there is an ongoing investigation.” 

    “We should get to the truth,” said former Air Force Brig. Gen. Don Bacon, R-Neb., speaking Sunday on “This Week” from ABC News. “I don't think he would be foolish enough to make this decision to say, kill everybody, kill the survivors because that's a clear violation of the law of war,” Bacon said. 

    Legal POV: “[T]here can be no conceivable legal justification” for what the Post’s reporting alleges, argues former Pentagon counsel Jack Goldsmith, writing Friday on Substack. 

    President Trump’s reaction: “He said he did not say that. And I believe him 100%,” the president told reporters aboard Air Force One on Sunday. He then added, “I wouldn't have wanted that, not a second strike.” 

    • By the way: The 10th chapter in Hegseth’s book is titled, “More lethality, less lawyers,” Anna Bower of Lawfare noted on social media. “It’s almost as if the signs were there all along,” she added. 

    Latest: Hegseth appeared to be trying to make light of the allegations, posting a meme about the alleged war crime to social media on Sunday evening using an AI-generated image based on the children’s book series, Franklin the turtle. At least two Franklin-based memes were shared by users in response, here and here, emphasizing the legal stakes of Hegseth’s war on drug boats. 

    Additional reading:Trump’s Focus on Drug War Means Big Business for Defense Startups” in the business of selling drones, sensors and AI-based surveillance platforms to the military, the Wall Street Journal reported Saturday. 


    Welcome to this Monday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1969, the U.S. held its first military draft lottery since the Second World War. 

    Ukraine

    Peace-talks update: Ukraine won’t give up land, says the country’s chief negotiator. “As long as Zelensky is president, no one should count on us giving up territory. He will not sign away territory,” Andriy Yermak told The Atlantic’s Simon Shuster by telephone from Kyiv last week. “The constitution prohibits this.”

    Ukraine “is prepared to discuss only where the line should be drawn to demarcate what the warring sides control,” Shuster wrote, quoting Yermak as saying, “All we can realistically talk about right now is really to define the line of contact…And that’s what we need to do.” Read on, here.

    Russia launched Trump’s peace plan with promises of profits. The Wall Street Journal reports. “For the Kremlin, the Miami talks were the culmination of a strategy, hatched before Trump’s inauguration, to bypass the traditional U.S. national security apparatus and convince the administration to view Russia not as a military threat but as a land of bountiful opportunity, according to Western security officials. By dangling multibillion-dollar rare-earth and energy deals, Moscow could reshape the economic map of Europe—while driving a wedge between America and its traditional allies.”

    Putin’s negotiator, Kirill Dmitriev, told Trump envoy Steve Witkoff and son-in-law Jared Kushner that U.S. companies might “tap the roughly $300 billion of Russian central bank assets, frozen in Europe, for U.S.-Russian investment projects and a U.S.-led reconstruction of Ukraine. U.S. and Russian companies could join to exploit the vast mineral wealth in the Arctic.” Read the quintuple(!)-bylined WSJ article, here.

    Rep. Don Bacon: “We saw that Wall Street Journal article yesterday that many people around the president are hoping to make billions of dollars—these are all billionaires in their own right—from…Russia, if they get a favorable agreement with Ukraine. That alarms me tremendously,” the former Air Force one-star told ABC’s “This Week” on Sunday. 

    “Putin’s the invader, he’s the dictator, he’s murdered all his opponents. But I just don’t see that moral clarity coming from the White House,” he continued. “I don’t want to see a foreign policy based on greed. I want to see it based on doing the right thing.”

    Historian reax: “The Trump administration is replacing American democracy with a kleptocracy, a system of corruption in which a network of ruling elites use the institutions of government to steal public assets for their own private gain,” warned Heather Richardson of Boston College, writing Sunday. “It permits virtually unlimited theft while the head of state provides cover for his cronies through pardons and the uneven application of the law. It is the system Russia’s president Vladimir Putin exploits in Russia, and President Donald J. Trump is working to establish it in the United States of America.”

    Additional reading: 

    Around the Defense Department

    Space Force won’t say who got money to start developing orbital interceptors. The amounts are small—under $9.5 million apiece—which exempts them from disclosure requirements, but at least some of them are likely to lead to contracts worth billions of dollars. Several experts said the secrecy that surrounds the wildly ambitious Golden Dome project has several drawbacks. Defense One’s Thomas Novelly reports, here.

    The Navy detected plutonium in the air at a shuttered San Francisco shipyard a year before it told anyone. Pu-239 was detected at an “Action Level” at the former Hunters Point Naval Shipyard in November 2024, but only revealed in October. “On this issue we did not do a good job,” Michael Pound, the Navy’s environmental coordinator overseeing the site’s clean-up, said at a recent community meeting. The Guardian has more, here.

    D.C. Guard shooting

    A National Guardman is “fighting for his life” after the Wednesday shooting that left another dead in Washington, D.C. Air Force Staff Sgt. Andrew Wolfe is hospitalized in critical condition, West Virginia Gov. Patrick Morrisey said Saturday on “Fox & Friends.” 

    Army Spc. Sarah Beckstrom died on Thanksgiving, one day after the attack. Arrested: Rahmanullah Lakanwal, an Afghan national, has been charged with first-degree murder. USA Today has more, here.

    Commentary:A Terrible and Avoidable Tragedy in D.C.,” is how former Homeland Security official Juliette Kayyem described the shooting, writing  the day after in The Atlantic.

    Additional reading: 

    Overseas

    Germany is raising its defenses, following an 1,800-page playbook. WSJ: “The blueprint details how as many as 800,000 German, U.S. and other NATO troops would be ferried eastward toward the front line. It maps the ports, rivers, railways and roads they would travel, and how they would be supplied and protected on the way.”

    The logistics plan is part of an “‘all-of-society’ approach to war,” that marks “a return to a Cold-War mindset, but updated to account for new threats and hurdles—from Germany’s decrepit infrastructure to inadequate legislation and a smaller military—that didn’t exist at the time.” Read on, here

    Additional reading: “Taiwan puts $40 billion toward building a defense dome and buying US weapons,” the Associated Press reported on Wednesday.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶