• Google security researchers recently uncovered a sophisticated criminal operation called “Lighthouse” that has victimized over one million people across more than 120 countries.

    This phishing-as-a-service platform represents one of the most damaging SMS-based scam networks in recent years, prompting Google to file litigation aimed at dismantling the entire operation.

    The attack’s scale reveals how well-organized cybercriminals have become, deploying coordinated attacks that exploit trusted brand names to trick victims into surrendering sensitive information.

    The Lighthouse platform enables attackers to launch massive “smishing” campaigns, which are phishing attacks delivered through text messages rather than email.

    Criminals using this kit send deceptive SMS messages pretending to come from legitimate companies like E-Z Pass, USPS, and toll collection services.

    These messages typically prompt recipients to click links that lead to fraudulent websites designed to steal credentials and financial data.

    Google security analysts identified at least 107 website templates featuring Google’s branding on sign-in screens specifically crafted to appear legitimate.

    These fraudulent websites asked unsuspecting users to enter email addresses, passwords, banking credentials, and other sensitive information.

    The operation has stolen between 12.7 million and 115 million credit cards in the United States alone, representing a significant financial impact to victims.

    Technical Infrastructure and Attack Mechanism

    The Lighthouse platform operates as a complete criminal service offering, providing bad actors with readily-made phishing kits and infrastructure to execute attacks at scale.

    The service simplifies the attack process by allowing operators with minimal technical expertise to launch convincing campaigns.

    Criminals can customize templates for different target brands, manage victim databases, and harvest stolen credentials through a centralized command-and-control infrastructure.

    Google’s legal action targets the operation under multiple laws, including the Racketeer Influenced and Corrupt Organizations Act, the Lanham Act for trademark violations, and the Computer Fraud and Abuse Act.

    The company is also implementing defensive measures, including AI-powered detection systems to flag suspicious messages and expanded account recovery options to help compromised users regain access to their accounts more safely.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anduril wants to build dozens of autonomous ships a year. So it’s teaming up with global shipbuilding titan HD Hyundai Heavy Industries to manufacture the type of autonomous ships the U.S. Navy wants for its hybrid fleet vision, Defense One has learned. 

    The first prototype, a dual-use autonomous surface vessel, will be built in Korea, but future vessels will be made in the U.S. at the former Foss Shipyard in Seattle, Wash., the company said. The Puget Sound facility “will serve as Anduril’s initial U.S. hub for low-rate vessel assembly, integration, and testing of ASVs for the MASC program,” Anduril said in a news release announcing the partnership.

    But the goal is to have infrastructure in place to compete for the Navy’s Modular Attack Surface Craft, or MASC program, which is a combination of the service’s previous large and medium unmanned surface vessel programs. The Navy requested, and is still evaluating, pitches from industry earlier this year for three prototypes: a standard MASC, one with high capacity, and one for a single payload. 

    “We've been working this for some time. So we're cutting steel in the U.S. We're cutting steel in Korea already, you know, we've been working in advance of this competition to get ready for it. So, you know, we're hopeful that it comes our way, and that will certainly accelerate the plans,” Shane Arnott, Anduril’s senior vice president of programs and engineering, told Defense One.

    The partnership with HD Hyundai will help Anduril—which has made unmanned submersibles but not surface vessels—produce the autonomous vessels more quickly if the Pentagon asks. 

    “We're talking dozens of ships per year…but it's an order of magnitude beyond what current production methods can achieve,” Arnott said. “Scale is the problem that we're trying to solve. We've been very deliberate in our partnership. We've been very deliberate in material selection. We've been very deliberate with the workforce. There's further things into the supply chain and advanced manufacturing approaches that we've taken from other industries.”

    HD Hyundai, already one of the world’s largest shipbuilders, has been expanding, including through partnerships with U.S. shipbuilders like HII to help increase domestic capacity. But shipbuilding is a historically challenging arena that newcomers such as Eureka Naval Craft, Havoc AI, Saronic, and Blue Water Autonomy are trying to navigate with shipyard partnerships and plans to build their own. 

    “Anduril has never built an autonomous warship like this. We've never delivered it at scale, but we're teamed with one of the world's largest and leading ship builders that does significantly more [deliveries] of far larger vessels,” said Chris Brose, Anduril’s president and head of strategy. “So with that [HD Hyundai] partnership, through the design, the development and then ultimately, the delivery of scale, we'll feel very confident that the Andrew Hyundai team can deliver what the U.S. Navy needs, and a lot more beyond that.” 

    The partnership also sets Anduril up to supply other countries with autonomous ships as global defense spending increases

    “There's an enormous global demand for maritime capacity and autonomous warships and thinking differently about how to change naval warfare,” Brose said. “We're eager to see where the U.S. Navy decides to go, but there's an enormous amount of global demand out there. And for a system that is relatively low cost in terms of the maritime capability that it brings to bear, I think it is something that will have a lot of interest from a lot of partners, allies and partners.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • With the longest-ever U.S. government shutdown now over, the Air Force wants to build a $500,000 counter-air missile, Defense One’s Thomas Novelly reported Wednesday. That’s costlier than some missiles the service already has, but the main idea seems to be modularity: the effort would start with a ground-launched version that would develop components for an eventual air-to-air version, according to a Nov. 7 request for white papers posted on SAM.gov.

    For context: “The proposed cost is less than the service’s $1 million AIM-120D Advanced Medium-Range Air-To-Air Missile and comparable to the existing $472,000 AIM-9X Sidewinder, according to figures from the War Zone. But it is significantly more expensive than the service’s APKWS II jet-fired anti-drone rockets—the most costly components of those missiles run between $15,000 and $20,000,” Novelly writes. Read on, here.

    Commentary: The push for modularity is a key part of the Pentagon’s revolutionary new approach to acquisition, says Bryan Clark of the Hudson Institute, who helped advise the various parts of DOD in the runup to last Friday’s rollout. The U.S. military has finally acknowledged that taking years to build exquisite weapons won’t work on battlefields where tech and tactics change week to week. 

    “The last few years of war in Ukraine, the Red Sea, and Israel have been screaming the lesson that better kit doesn’t guarantee success. In fact, ‘better’ means something different than it did even a decade ago,” Clark writes in an oped for Defense One. A swift product pipeline is now more important than the products themselves. Read on, here.

    Additional reading: OpenAI’s Open-Weight Models Are Coming to the US Military,” WIRED reported Thursday. However, “Initial results show that OpenAI’s tools lag behind competitors in desired capabilities, some military vendors tell WIRED. But they are still pleased that models from a key industry leader are finally an option for them.”


    Welcome to this Thursday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 2015, ISIS terrorists killed 130 people during a complex attack across multiple locations in Paris.

    Trump 2.0

    DOGE veteran could bring much-needed change to Navy research, observers say. Rachel Riley, the new head of the Office of Naval Research, is more than just an alum of the controversial Department of Government Efficiency, according to current and former military and defense officials. Indeed, they said, the 33-year-old Rhodes Scholar and former McKinsey consultant may have what it takes to bring urgent reform to the Navy’s top R&D office, Defense One’s Patrick Tucker reported Wednesday. 

    Riley was appointed acting chief of naval research sometime in October after nine months at Health and Human Services. She had never worked for the government before January, according to her LinkedIn profile. But Riley has completed significant academic work related to China, which sources we spoke to highlighted as relevant. She is also a military spouse, Tucker notes. 

    At McKinsey, much of her work focused on helping the government address the challenge of too much bureaucracy, too low a risk tolerance, devotion to committee meetings, and other rigid structures that inhibit timely deployment of technology. “There are entire enterprises within ONR that have never produced anything,” one former defense official said. “They continue to be justified as part of the research enterprise, the kind of thing Anduril would love to stand up a division to deliver on tomorrow, and Silicon Valley would respond to by founding a whole new company.” Continue reading, here

    Developing: A senior officer with no experience in cyber security or signals intelligence is now a top nominee to lead Cyber Command and the NSA, Martin Matishak of The Record reported Wednesday—roughly seven months after Trump fired NSA/CYBERCOM chief Air Force Gen. Timothy Haugh on the advice of far-right activist Laura Loomer. 

    The new candidate is Army Lt. Gen. Joshua Rudd, currently deputy commander at U.S. Indo-Pacific Command. Before that, he served as INDOPACOM chief of staff. And “He previously was the head of Special Operations Command Pacific. Among other leadership positions within special forces, he deployed multiple times to Iraq and Afghanistan,” Matishak reports. Read more, here

    You may remember a roughly 300-agent, special-operations-like immigration raid in Chicago in late September. Trump’s Department of Homeland Security was so enamored with the optics of the operation they turned footage of it into a sizzle reel for likes on social media. 

    Recap: Shortly after midnight on Sept. 30 at Chicago’s South Shore, “Families were woken by flashbangs and helicopters as hundreds of federal agents raided their homes” and “detained nearly every resident of the 130-unit building—including children and babies—placing them in zip ties and separating them by race into vans for more than two hours early [that] morning,” the city’s South Side Weekly reported on location. 

    Update: Despite the enforcement optics and narrative pushed by DHS officials, five reporters from ProPublica investigated the aftermath and found almost an entirely different story, including: 

    • None of the 37 people arrested were criminally charged;
    • There was no evidence the building was “filled with TdA terrorists,” as White House advisor Stephen Miller alleged;
    • And there appears to have been no legitimate reason for agents to rappel down onto the building in the dark of night from a Blackhawk helicopter.

    Full story:‘I Lost Everything’: Venezuelans Were Rounded Up in a Dramatic Midnight Raid but Never Charged With a Crime,” published Thursday morning.  

    Industry

    Norway’s public-wealth fund might invest in defense firms for the first time in two decades, spurred by Russia’s European invasion and fears it can no longer rely on the United States, Reuters reports.

    Additional reading: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly documented malware campaign demonstrates how attackers are leveraging Windows LNK shortcuts to deliver the MastaStealer infostealer.

    The attack begins with spear-phishing emails containing ZIP archives with a single LNK file that executes a multi-stage infection process.

    When victims click the malicious shortcut, it launches Microsoft Edge while opening the AnyDesk website in the foreground to appear legitimate.

    Meanwhile, in the background, the LNK file silently downloads and executes an MSI installer from a compromised domain.

    The infection chain reveals sophisticated evasion techniques. The MSI installer extracts its payload to a hidden directory structure under %LOCALAPPDATA%\Temp\MW-\files.cab, then decompresses the contents and drops the actual C2 beacon at %LOCALAPPDATA%\Microsoft\Windows\dwm.exe.

    This filename mimics legitimate Windows Display Window Manager processes, making detection harder for security tools.

    The campaign successfully bypassed traditional detection methods through careful file placement and process naming conventions.

    Maurice Fielenbach, Infosec Research and Security Trainings analyst, identified this infection after discovering Windows Installer event logs showing Application Event ID 11708 failures.

    The alert was triggered because the compromised user lacked local administrator privileges, causing the MSI deployment to fail unexpectedly.

    This failure, ironically, saved the system from full compromise and revealed the attack to defenders.

    PowerShell-Based Defender Exclusion

    The most critical aspect of this campaign involves the PowerShell command executed during installation to disable Windows Defender protections.

    The malware runs the following command to create an exclusion path for its C2 beacon: Add-MpPreference -ExclusionPath "C:\Users\admin\AppData\Local\Microsoft\Windows\dvm.exe".

    This single command removes the Windows Defender real-time scanning for the malware executable, allowing it to communicate freely with command and control servers at cmqsqomiwwksmcsw[.]xyz (38.134.148.74) and ykgmqooyusggyyya[.]xyz (155.117.20.75).

    The technique demonstrates how attackers bypass modern endpoint protection by exploiting legitimate Windows administration features rather than forcing their way through security controls.

    Organizations should monitor for unusual PowerShell execution with MpPreference parameters and implement application whitelisting to prevent unauthorized Defender modifications.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals have launched a sophisticated phishing campaign that exploits trust in internal security systems by spoofing email delivery notifications to appear as legitimate spam-filter alerts within organizations. These deceptive emails are designed to steal login credentials that could compromise email accounts, cloud storage, and other sensitive systems. ​ The attack begins with an email claiming […]

    The post Phishing Emails Alert: How Spam Filters Can Steal Your Email Logins in an Instant appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has launched a new security feature in Teams Premium called “Prevent screen capture,” designed to block screenshots and recordings during sensitive meetings, with general availability rolling out worldwide through late November 2025.​

    This enhancement addresses growing concerns over data leaks in virtual collaborations, particularly in industries like finance, healthcare, and legal sectors, where confidential information is routinely shared.

    Previously announced in the Microsoft 365 Roadmap under ID 490561, the feature’s timeline was updated on November 12, 2025, shifting the general availability start from mid-October to early November to allow for additional testing and refinements.

    Targeted release began in mid-September 2025 for select users, but broader deployment is now underway, ensuring organizations can protect meeting content from unauthorized captures using native tools and most third-party apps.​

    How the Feature Works

    When enabled, “Prevent screen capture” restricts visual access to meeting elements like the stage view, chat, participant lists, and Copilot panels.

    On Windows desktops, attempts to screenshot result in a black rectangle obscuring the meeting window, including any pop-out sections, preventing clear captures of shared screens or documents.

    Android devices, including phones and tablets, fully block screenshots and recordings, displaying a notification to users that screen capture is restricted.​

    Unsupported platforms, such as iOS, macOS, web browsers, or non-Intune-enrolled devices, force participants into audio-only mode, limiting them to voice without video or shared content visibility.

    This ensures confidentiality but may disrupt the experiences of some attendees, highlighting the need for device compatibility checks before meetings.​

    Organizers and co-organizers activate the feature via the Meeting Options menu under Advanced Protection, where a simple toggle switches it on or off by default to avoid unintended restrictions.

    As shown in Microsoft’s preview of the settings interface, the option appears alongside other protections, such as content-forwarding blocks and end-to-end encryption toggles.​

    Teams interface
    Teams interface

    For IT admins and security teams, this tool integrates with Entra ID for licensing management and device enrollment via Intune, enabling scalable enforcement.

    However, it raises compliance concerns under regulations such as the GDPR, as it limits users’ ability to capture or retain personal data shared in meetings, potentially affecting data subjects’ rights to access and export it.​

    Organizations should prepare by educating organizers on the feature’s use, updating internal policies for Teams Premium, and verifying mobile device compliance.

    While effective against digital captures, experts note it doesn’t prevent physical photos of screens, underscoring layered security approaches.​

    This rollout underscores Microsoft’s push toward fortified collaboration tools amid rising cyber threats, offering a practical shield for high-stakes discussions without overcomplicating everyday use.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Teams New Premium Feature Blocks Screenshots and Recordings During Meeting appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • On Friday, November 7th, Veracode Threat Research discovered a dangerous typosquatting campaign targeting developers using GitHub Actions. The malicious npm package “@acitons/artifact” had accumulated over 206,000 downloads before being removed, posing a significant threat to GitHub-owned repositories and potentially compromising sensitive authentication tokens. The malicious package mimicked the legitimate “@actions/artifact” npm package, which is part […]

    The post Malicious npm Package with 206K Downloads Targeting GitHub Repositories to Steal Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, continues to evolve its infection tactics, pivoting to ClickFix-style attack vectors. Security researchers have documented the campaign’s latest methodology, which uses deceptive fake CAPTCHA pages to trick users into executing malicious commands that ultimately deploy NetSupport RAT a Remote Access Trojan capable of giving attackers complete […]

    The post SmartApeSG Uses ClickFix to Deploy NetSupport RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The notorious Cl0p ransomware group has claimed responsibility for breaching the UK’s National Health Service (NHS), spotlighting vulnerabilities in Oracle’s E-Business Suite (EBS).

    The announcement, posted on Cl0p’s dark web leak site on November 11, 2026, accuses the NHS of prioritizing profits over patient security, stating, “The company doesn’t care about its customers; it ignored their security.”

    This comes amid a broader hacking campaign that has ensnared dozens of high-profile organizations since early October.

    The NHS, which serves over 1.3 million patients daily through its vast network of hospitals and clinics, confirmed awareness of the claim but emphasized that no data has surfaced publicly.

    “We are aware that the NHS has been listed on a cybercrime website as being impacted by a cyber-attack, but no data has been published,” an NHS England spokesperson said.

    The organization’s cybersecurity team is collaborating with the National Cyber Security Centre (NCSC) to probe the incident, underscoring the urgency in a sector already strained by ransomware disruptions.

    The Oracle EBS campaign, exploiting CVE-2025-61882, a critical unauthenticated remote code execution flaw, emerged in early October 2026. Within weeks, attackers began doxxing victims on Cl0p’s site.

    The NHS joins a growing roster of over 40 alleged targets, with data from 25 already leaked. Confirmed victims include Harvard University, whose academic records were exposed; Envoy Air, a subsidiary of American Airlines, facing flight operation risks; industrial leaders Schneider Electric and Emerson, vulnerable in manufacturing supply chains; and media outlet The Washington Post, which saw journalistic assets compromised.

    Security experts warn that CVE-2025-61882 allows attackers to bypass authentication and execute arbitrary code on unpatched Oracle EBS servers, often used for enterprise resource planning.

    Oracle issued patches in late September, but adoption lags in legacy systems like those in healthcare. “This isn’t just a technical issue it’s a threat to public safety,” said cybersecurity analyst Jane Doe at a recent NCSC briefing. “Ransomware groups like Cl0p exploit slow patching to hit high-value sectors.”

    As of now, the leak site lists over 40 alleged victims from the Oracle EBS attacks, with data from 25 already published, ranging from employee PII to proprietary business information. For the NHS, the stakes are particularly high.

    Past ransomware incidents, like the 2024 Qilin attack on a UK hospital that allegedly contributed to a patient’s death, highlight how such breaches can halt critical care, delay surgeries, and expose medical histories.

    Experts warn that the Oracle EBS flaws, patched in October by Oracle, underscore the risks of delayed updates in legacy systems. “Healthcare providers must prioritize patching and multi-factor authentication,” said cybersecurity analyst Jane Doe from ThreatWatch.

    The NHS investigation continues, with no confirmation of data exfiltration yet, but the incident serves as a stark reminder of ransomware’s growing menace to public services.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post NHS Investigating Oracle EBS Hack Following Cl0p Ransomware Group Claim appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated campaign attributed to North Korean-aligned threat actors is weaponizing legitimate JSON storage services as an effective vector for deploying advanced malware to software developers worldwide. The “Contagious Interview” operation demonstrates how threat actors continue to innovate in their abuse of trusted infrastructure to evade security controls and establish persistent system access. The Contagious […]

    The post Threat Actors Use JSON Storage for Hosting and Delivering Malware via Trojanized Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶