• FORT MCNAIR—Move faster and invest more, Defense Secretary Pete Hegseth told hundreds of defense-industry executives on Friday—or we just might make you. 

    Hegseth, who spoke for more than an hour to a packed auditorium at the National War College, formally unveiled a slew of policy changes intended to replace his department’s Cold War-era acquisition processes with ones that value speed over rigid requirements. The secretary described the gathering as an opportunity to look executives “in the eye.”

    “We commit to doing our part, but industry also needs to be willing to invest their own dollars to meet the long-term demand signals provided to them. Industry must use capital expenditures to upgrade facilities, upskill their workforce, and expand capacity. If they don't, we are prepared to fully employ and leverage the many authorities provided to the president which ensure that the department can secure from industry anything and everything that is required to fight and win our nation's wars,” Hegseth said.

    In the wake of the speech, Hegseth’s office released a trio of memos: one to order the renaming and transformation of the Defense Acquisition System into the Warfighting Acquisition System; another ordering an overhaul of the joint requirements process; and a third focused on streamlining foreign military sales.  

    The Pentagon chief told defense companies to put more of their own money into developing military technology—or take their business elsewhere.

    “You must invest in yourselves rather than saddling taxpayers with every cost. For those who come along with us, this will be a great growth opportunity, and you will benefit. To industry not willing to assume risk in order to work with the military, we may have to wish you well in your future endeavors—which would probably be outside the Pentagon,” he said. “We're going to make defense contracting competitive again.”

    Steve Blank, a professor and co-founder of Stanford University's Gordian Knot Center for National Security Innovation, called the speech a death knell for the Pentagon’s existing acquisition system—”the Department of War just shot the accountants and opted for speed.” And he expects major defense contractors to push back against it.

    “Their first response is going to be hiring a whole ton of K Street people to lobby Congress to point out the problems with this process, which is, we're going to take a lot more risk and a lot more things will fail,” Blank told Defense One after the speech. “So this really forces primes, if they don't want to hire lobbyists, to change their business model. And the problem is their business model is predicated on a system that's no longer sustainable.”

    Blank said Hegseth’s emphasis on speed and commercial technology will see traditional defense prime contractors pushed more than ever to compete with “startups banging on your door. Boy, the direction to me sounded pretty clear: that we're going to people who have stuff that could be delivered cheaply and quickly.” 

    The shift could also mean the Pentagon shifts to more fixed-price contracts, where work has to get done at a certain price, opposed to cost-plus contracts, which allow for increases as a result of delays or unforeseen expenses.

    In his speech, Hegseth called out cost-plus contracts as one of the symptoms that ail the Pentagon’s acquisition system. 

    “These changes will move us from the current prime contractor-dominated system defined by limited competition, vendor lock, cost-plus contracts, stressed budgets, and frustrating protests, to a future powered by a dynamic vendor space that accelerates production by combining investment at a commercial pace with the uniquely American ability to scale quickly,” he said.

    But fixed-price contracts can bring their own woes. Boeing says they are partially to blame for delays to new presidential jets. Northrop Grumman’s CEO has said they don’t make sense in development work. 

    In introductory remarks before Hegseth’s speech, Deputy Defense Secretary Stephen Feinberg said the Pentagon and “our contractors need to change and do better” but “those who don’t and resist it will be done.” 

    Hegseth’s speech seemed well received among defense tech founders, executives, and investors. One attendee told Defense One after the speech that prime contractors should take Pentagon leaders at their word. 

    “It is a vindication of our thesis that America needs an acquisition system focused on meritocracy and transparency,” the expert said. 

    The directive to buy commercial first doesn’t just mean off-the-shelf, it means changing the contracting process to value metrics and speed, which could mean more fixed-price contracts with milestones for production, they said. 

    Arms exports

    Beyond buying and producing weapons systems faster, Hegseth spent a chunk of his speech talking about improving the foreign military sales process.

    “Believe me, I hear about this on every foreign trip. And every conversation I have with every president, prime minister, and minister of defense is, ‘What is wrong with your foreign military sales? We ordered it in 2014; it's 2025 and it's scheduled to deliver in 2032.’ And I sit there going, ‘I don't know, what the hell?’ We didn't break it, but we're going to fix it,” he said. 

    “Not only are foreign military sales and defense commercial sales important to our American industrial base, but they're also critical to our strategic vision on the global landscape…and to accomplish this, our allies and partners must be armed with the best and most interoperable weapons systems in the world. Foreign military sales allow our warfighters to stand shoulder to shoulder with our allies.” 

    One of the Nov. 7 memos orders the organizations that handle foreign military sales—the Defense Security Cooperation Agency and Defense Technology Security Administration—to be moved from the Pentagon’s policy shop to its acquisition shop. 

    The new focus on “burden sharing” and being a better customer to allies and partners is “refreshing,” said Jerry McGinn, who leads the Center for Strategic and International Studies’ industrial base division.

    “The strong endorsement of the importance of allies and partners, it allows more overall industrial capacity. And so I think that's a good thing,” McGinn  said, noting that Denmark had recently canceled its order of U.S. Patriot missiles. 

    “They weren't going to be able to get Patriots for at least five years because of the backlog in production. So, doing better on that will be better overall because you'll have allies buying stuff that's compatible with ours—and it's good for overall capacity, good for the industrial base,” he said.

    Implementing all this will take money and people, he said.

    “I've been calling to have our industrial base on more of a ‘war footing’ for some time. And these are the kind of measures that you would have to take to do that. So follow through is going to be the key,” McGinn said. “And then the question is resourcing. Because some of this is…is going to require a lot of attention and some additional resources.” 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly identified ransomware group, Cephalus, has emerged as a significant threat to organizations worldwide, exploiting stolen Remote Desktop Protocol (RDP) credentials to gain access to networks and deploy powerful encryption attacks.

    The AhnLab researchers observed in mid-June 2025 that the group poses a persistent, financially motivated threat that exploits security gaps in remote access infrastructure.

    Threat Group’s Operation Model

    Cephalus operates with a singular focus on financial gain, employing a systematic approach to compromise organizations.

    The group primarily targets companies running RDP services without multi-factor authentication (MFA) protection, creating an ideal entry point for credential-based attacks.

    Named after the mythological figure who wielded an unerring spear, the group’s nomenclature reflects their confidence in operational success rates.

    Cephalus leak site (DLS)
    Cephalus leak site (DLS)

    Once inside a network, Cephalus executes a standardized attack sequence: breaching systems, exfiltrating sensitive data, and deploying encryption across the victim’s infrastructure.

    The group customizes its ransomware for specific targets, suggesting a high level of operational sophistication.

    Whether operating as a Ransomware-as-a-Service (RaaS) platform or collaborating with other threat groups remains unclear, though their coordinated approach indicates established processes.

    SecureMemory structure and related methods
    SecureMemory structure and related methods

    Technical Capabilities and Evasion Tactics

    The Cephalus ransomware strain, developed in Go, incorporates advanced anti-forensics and evasion mechanisms to maximize encryption success while avoiding detection.

    Upon execution, the malware turns off Windows Defender real-time protection, removes volume shadow copies, and terminates critical services, including Veeam and Microsoft SQL Server.

    The ransomware employs a sophisticated encryption architecture that combines AES-CTR symmetric encryption with RSA public-key cryptography.

    A particularly notable feature involves generating a fake AES key to deceive dynamic analysis tools, obscuring the actual encryption mechanism from AhnLab researchers and endpoint protection systems.

    The process of XORing the original key
    The process of XORing the original key

    Cephalus distinguishes itself through aggressive tactics of victim pressure. The group includes proof of data exfiltration in ransom notes by providing direct links to GoFile repositories containing stolen information.

    This demonstration strategy significantly increases victim compliance with ransom demands, as organizations face the dual threat of encrypted data and potential public exposure.

    Organizations should prioritize implementing multi-factor authentication across all RDP access points, enforce strong credential hygiene, and maintain reliable backup systems isolated from production networks.

    Security teams should also monitor for characteristic indicators of Cephalus activity and implement robust endpoint detection capabilities.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Threat Actors Leveraging RDP Credentials to Deploy Cephalus Ransomware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • German hosting provider aurologic GmbH has emerged as a central facilitator within the global malicious infrastructure ecosystem, providing upstream transit and data center services to numerous high-risk hosting networks.

    Operating from its primary facility at Tornado Datacenter GmbH & Co. KG in Langen, Germany, aurologic markets itself as a high-capacity European carrier offering dedicated server hosting, IP transit services, and distributed denial-of-service protection.

    Despite maintaining a legitimate business focus, the company has become a critical enabler for some of the most abusive networks operating globally.

    Formed in 2023 following the transition of Combahton GmbH’s fastpipe infrastructure, aurologic provides connectivity to several hosting providers assessed as threat activity enablers, including metaspinner net GmbH, Femo IT Solutions Ltd, Global-Data System IT Corporation, Railnet LLC, and the recently sanctioned Aeza Group.

    Femo IT Solutions routing (Source - Recorded Future)
    Femo IT Solutions routing (Source – Recorded Future)

    These downstream customers have consistently ranked among the top sources of validated malicious infrastructure, hosting command-and-control servers for malware families such as Cobalt Strike, Amadey, QuasarRAT, and various information stealers including Rhadamanthys and RedLine Stealer.

    Push Security security analysts identified that aurologic’s infrastructure has repeatedly appeared as a common upstream provider linking multiple suspected threat activity enablers.

    The company serves as a pivotal connection point between sanctioned entities and global internet connectivity, with approximately fifty percent of Aeza International’s announced IP prefixes routed via aurologic despite international sanctions from the United States and United Kingdom.

    The persistence of these relationships raises concerns about the distinction between operational neutralality and systematic enablement of cybercriminal infrastructure.

    The hosting ecosystem surrounding aurologic demonstrates structural vulnerabilities in internet infrastructure accountability.

    Upstream providers occupy strategic positions within the internet hierarchy and possess unique capabilities to disrupt persistent abuse, yet many continue deferring responsibility for downstream activity.

    This reactive approach to abuse handling creates an operational environment where networks associated with cybercrime, disinformation campaigns, and malware distribution maintain resilience and global accessibility.

    Network Infrastructure and Operational Resilience

    aurologic maintains an extensive European interconnection footprint spanning data centers across Germany, Finland, and the Netherlands.

    This infrastructure is anchored in major European internet exchange points in Langen and Amsterdam, where the company maintains direct connections with large colocation facilities.

    Simple Carrier LLC transferring AS34888 and AS42624 to Global-Data System IT Corporation (Source - Recorded Future)
    Simple Carrier LLC transferring AS34888 and AS42624 to Global-Data System IT Corporation (Source – Recorded Future)

    The multi-terabit backbone capacity and presence across multiple facilities ensures fast, redundant data transit throughout Europe, making aurologic attractive to hosting companies operating within ambiguous areas of the hosting ecosystem.

    Whether through technical neutrality, permissive policy enforcement, or limited oversight mechanisms, aurologic’s infrastructure provides operational continuity to providers with documented reputations for hosting malicious activity, positioning the company at the intersection where connectivity creates challenges in distinguishing between infrastructure provision and active facilitation.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—The greatest risk the Army has in the Indo-Pacific region is inaction—“being late” when a crisis or conflict emerges, out of position, not fast enough, “or even worse, doing nothing at all,” said U.S. Army Pacific commander Gen. Ronald Clark.

    The command is the “Army’s innovation testbed,” Clark said, and continuous transformation is imperative. “So as leaders, we have to become comfortable with failing fast, iterating quickly, and developing better solutions,” he told an audience of defense industry representatives and troops at the AFCEA TechNet Indo-Pacific conference.

    The Army is amid a rapid modernization effort called Transformation in Contact, and several of the units created or chosen to test new technology and concepts are part of USARPAC. The command has also “embraced AI to shorten workflows and enhance the speed and efficiency at which we think, learn, and work,” the general said.

    As soldiers walked through the keynote area holding drones, Clark said the command is “at the forefront of testing new systems and processes that are driving the formation of an Army unified network based on zero trust principles, and we’re innovating with unmanned aerial systems.”

    A drone was originally supposed to fly over the audience during the event, Clark explained, but the buzzing sound it makes “scares the crap out of everyone.”

    In an interview with Defense One earlier this year, Clark explained what he sees as the two major challenges for the Army in the region: the “tyranny of distance,” and the “increasingly aggressive, belligerent, and coercive” actions of the Chinese.

    “It’s not just about the Taiwan Strait,” Clark said. “It’s across the region, in multiple areas, where the [People’s Liberation Army] is threatening the sovereignty of our treaty allies and partners, so our ability to be ready to respond to crisis through our activities as we operate in the theater—it’s important that we’re in the right place, at the right time, with the right capabilities to not just match that threat, but to deter.”

    Deterrence, he said at TechNet, “is our highest duty and the cornerstone of our strategy in the Indo-Pacific.…We know that the cost of failure is too damn high, and we owe it to our soldiers and their families and our allies and partners…to be prepared for any challenge.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple Podcasts

    Guest:

    • Jon Wolfsthal, Director of Global Risk at the Federation of American Scientists.
    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ClickFix attacks have experienced a dramatic surge over the past year, establishing themselves as a cornerstone of modern social engineering tactics.

    These sophisticated attacks manipulate victims into executing malicious code directly on their devices through deceptive copy-and-paste mechanisms.

    The threat has evolved beyond traditional email-based phishing, now leveraging multiple delivery channels including poisoned search results and malicious advertising campaigns that bypass conventional security controls.

    The latest iteration of ClickFix represents a significant escalation in sophistication. Attackers have developed highly convincing fake verification pages that mimic legitimate services like Cloudflare, complete with embedded instructional videos, countdown timers, and real-time user counters.

    These elements work together to create an authentic appearance that pressures victims into completing the verification process without suspicion.

    The pages adapt dynamically to the user’s operating system, delivering platform-specific instructions for Windows, Mac, and other systems.

    Push Security researchers identified this advanced campaign as the most sophisticated ClickFix variant observed to date.

    The attack chain demonstrates remarkable technical complexity, automatically copying malicious code to the victim’s clipboard through JavaScript without requiring manual selection.

    According to Microsoft’s 2025 Digital Defense report, ClickFix attacks now account for 47% of all initial access methods, making them the most prevalent entry point for cybercriminals targeting organizations.

    The primary delivery mechanism has shifted dramatically away from email. Research shows that four out of five ClickFix pages are accessed through Google Search, either via poisoned search results or malvertising campaigns.

    ClickFix lures are distributed all over the internet (Source - Push Security)
    ClickFix lures are distributed all over the internet (Source – Push Security)

    Attackers compromise legitimate websites through hosting vulnerabilities or create optimized malicious sites targeting specific search terms.

    This non-email delivery approach effectively bypasses traditional anti-phishing controls implemented at the email gateway layer.

    Detection evasion techniques employed by ClickFix campaigns include domain rotation to avoid blocklists, bot protection services that prevent automated analysis, and heavily obfuscated page content designed to evade signature-based detection systems.

    Because malicious code is copied within the browser sandbox, security tools cannot observe or flag the action before execution, leaving endpoint detection and response systems as the sole remaining defense layer after victims attempt to run the commands.

    Advanced Payload Execution and Evasion Mechanisms

    The technical execution of ClickFix payloads demonstrates increasing sophistication in abusing legitimate system binaries across operating systems.

    Attack flow (Source - Push Security)
    Attack flow (Source – Push Security)

    While mshta and PowerShell remain the predominant attack vectors, threat actors now exploit a diverse array of Living-Off-The-Land Binaries (LOLBINs) targeting different services.

    Recent variants employ cache smuggling techniques that combine ClickFix methodology with JavaScript to cache malicious files disguised as JPG images, enabling local execution without external PowerShell web requests.

    The attack operates through user-initiated paste events requiring interaction such as button presses before loading the malicious payload, making traditional clipboard blocking measures ineffective.

    Security researchers have noted that disabling the Win+R dialog box or restricting File Explorer address bar applications provides limited protection since attackers can leverage alternative legitimate services to execute commands.

    The hybrid attack path bridging browser and endpoint environments positions ClickFix to potentially evolve into entirely browser-based attacks that completely evade EDR solutions, representing a concerning future trajectory for this threat vector.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a “commercial-grade” Android spyware dubbed LANDFALL in targeted attacks in the Middle East. The activity involved the exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in the “libimagecodec.quram.so” component that could allow remote attackers to execute arbitrary

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated banking trojan named Herodotus has emerged as a significant threat to Android users worldwide.

    Operating as Malware-as-a-Service, this malicious application disguises itself as a legitimate tool to trick users into downloading and installing an APK file outside the official Play Store.

    Once installed on a device, the trojan gains access to critical system permissions and can execute banking operations directly on behalf of the compromised user.

    The threat represents a concerning evolution in mobile malware, particularly because it remains largely invisible to traditional antivirus solutions despite its obvious malicious intent.

    The malware spreads primarily through SMS phishing campaigns, with attackers sending deceptive links that direct victims to fraudulent download pages.

    Users unknowingly install the APK, granting Herodotus access to sensitive permissions including accessibility features.

    Pradeo security analysts identified that the trojan then deploys overlay attacks by displaying fake screens on top of legitimate banking applications, enabling credential theft and session hijacking.

    Detection Evasion: The Humanization Technique

    Herodotus employs sophisticated evasion tactics specifically designed to bypass modern anti-fraud detection systems.

    The malware “humanizes” its malicious actions through deliberate random delays, micro-movements, and realistic typing patterns.

    This behavioral approach makes automated detection significantly more challenging.

    The trojan captures both screen content and keystroke data, allowing attackers to monitor user activity in real time and perform transactions while the victim remains logged into their banking session.

    Pradeo security analysts noted that when they searched for Herodotus samples in a leading antivirus provider’s signature database, the application triggered no alerts whatsoever.

    This failure occurred despite the malware being easily identifiable through basic search engine queries. Traditional antivirus solutions typically rely on known signatures and previously observed behavioral patterns.

    Herodotus circumvents these defenses because it operates through SMS phishing (an initial access vector), installs from unknown sources, and only triggers dangerous activities after receiving explicit permission approvals from the user.

    Effective defense requires detecting multiple indicators of compromise working in sequence: suspicious SMS links, installations from untrusted sources, critical permission requests, and behavioral anomalies including screen overlays and simulated interactions.

    Individually, these signals may appear harmless, but their combination reveals an active attack that conventional antivirus protection consistently misses.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Herodotus Android Banking Malware Takes Full Control Of Device Evading Antivirus appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Active Directory sites are designed to optimize network performance across geographically separated organizations by managing replication and authentication across multiple locations.

    The Synacktiv security researchers have demonstrated that these supposedly safe network management tools can be weaponized to launch powerful attacks against enterprise environments.​

    The vulnerability emerges because Active Directory sites can be linked to Group Policy Objects (GPOs), which control system configurations across an organization.

    When attackers gain write permissions to sites or their associated GPOs, they can inject malicious configurations that compromise all computers connected to those sites, including domain controllers.

    This creates a direct pathway to domain-wide compromise without triggering conventional security defenses.​

    How Privilege Escalation Works

    Attackers exploit three primary permission types to accomplish this: GenericAll, GenericWrite, and WriteGPLink permissions on site objects. Even administrators often delegate these permissions without fully understanding the implications.

    Once an attacker controls these permissions, they can either poison existing GPOs or create new malicious ones that execute arbitrary commands on connected systems.

    Attack path for linked GPO exploitation vector.
    Attack path for linked GPO exploitation vector.

    These commands can add attacker-controlled accounts to administrator groups, effectively giving them domain admin privileges within minutes.​ The most dangerous aspect is how Active Directory sites enable lateral movement across entire forests.

    The configuration partition containing site information replicates forest-wide, meaning that a compromised domain controller can modify site configurations that affect other domains.

    Delegation of Group Policy links management via Active Directory GUI.
    Delegation of Group Policy links management via Active Directory GUI. 

    This technique bypasses traditional SID filtering protections that normally prevent such cross-domain attacks.

    The Synacktiv researchers demonstrated that attackers from a child domain can compromise the forest root domain by simply linking malicious GPOs to sites that host the root domain’s controllers.​

    This attack vector represents a significant blind spot in many organizations’ security strategies. It warrants immediate attention from defensive teams managing large Active Directory environments.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Can Attack Active Directory Sites to Escalate Privileges and Compromise the Domain appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The United States military says it destroyed another alleged drug-trafficking boat in the waters off Latin America on Thursday. “The vessel was trafficking narcotics in the Caribbean and was struck in international waters. No U.S. forces were harmed in the strike, and three male narco-terrorists—who were aboard the vessel—were killed,” Pentagon chief Pete Hegseth announced on social media, accompanied by a 20-second video of the violence, which legal experts and critics describe as “extrajudicial killings.” 

    This means the U.S. military has killed more than 60 people in at least 17 strikes, according to information shared by Hegseth and President Trump dating to when these strikes began in early September. (Want more information on each of the prior 16 strikes? Just Security has that covered, here.)

    Due process? As we’ve noted before, Hegseth did not provide evidence to support the claim that those in the boat were trafficking drugs, where they were headed, nor—on a more trivial level—how the secretary’s subordinates determined the gender of those on the vessel before the attack. 

    However, the Associated Press looked into “the identities of four of the men—and pieced together details about at least five others” killed by U.S. troops, reporting Friday from Venezuela. “One was a fisherman struggling to eke out a living on $100 a month. Another was a career criminal. A third was a former military cadet. And a fourth was a down-on-his-luck bus driver.” 

    “Most of the nine men were crewing such craft for the first or second time, making at least $500 per trip…One was a well-known local crime boss who contracted out his smuggling services to traffickers,” AP’s Regina Garcia Cana writes. “We talked with several people in multiple communities who knew the men at different stages of their lives. We used social media posts and publicly available information to corroborate some of the information,” she said in a brief, separate report about her investigative process. 

    New: The U.S. military began operating an AC-130J Ghostrider attack plane out of El Salvador in mid-October, the New York Times reported Thursday. “It is operated by the Air Force Special Operations Command, a unit that carries out sensitive missions for the military.”

    But that’s not all: “The New York Times also identified a Navy [P-8A Poseidon] reconnaissance plane and a rarely seen, unmarked Air Force [C-40 Clipper] jet at the airport,” located in the Cooperative Security Location Comalapa, a small American military outpost at El Salvador’s main airport. More, here

    Update: When it comes to Venezuela, the White House told Congress it “doesn’t have a legal justification that would support attacks against any land targets right now,” and that “the US is not currently planning to launch strikes inside Venezuela” at the moment, CNN reported Thursday. 

    Notable: The White House’s legal framework “includes a list of 24 different cartels and criminal organizations based around Latin America it says the administration is authorized to target, according to one of the sources familiar with the document. But the Trump administration is seeking a separate legal opinion from the Justice Department that would provide a justification for launching strikes against land targets without needing to ask Congress to authorize military force,” according to five CNN reporters.  

    By the way, Senate Republicans on Thursday voted down legislation that would have limited White House attacks inside Venezuela. “The joint resolution, which was introduced by Sen. Tim Kaine (D-Va.) last month, was quelled in a 49-51 Senate vote,” The Hill reports

    Some Republicans wanted to have it both ways: Indiana’s Todd Young voted against the measure, then said afterward that his vote was “not an endorsement of the Administration’s current course in the Caribbean and Eastern Pacific.” North Carolina’s Thom Tillis acted similarly Thursday, voting against the measure, then later telling reporters “he still has doubts about the campaign,” according to AP. Tillis also “pointed out that it was expensive to change the deployment location for an aircraft carrier and questioned whether those funds could be better used at the U.S.-Mexico border to stop fentanyl trafficking.” 

    Democrats dissent: “You cannot bomb your way out of a drug crisis,” Sen. Jack Reed, D-R.I., told reporters, while Virginia’s Tim Kaine, who co-authored the legislation voted down Thursday, said, “We should not be going to war without a vote of Congress.”

    Bigger picture: Why Venezuela? Four writers at The Atlantic took a stab at the question, featuring input from anonymous White House sources and Ryan Berg, an expert on the region who now works at the Center for Strategic and International Studies in Washington. According to Berg, “Trump instinctively understands that if the U.S. is not the top dog in the Western Hemisphere, it can’t be an effective global power.” A senior administration official added, “If the goal is increasingly to have U.S.-aligned leaders, or at a minimum leaders that are not actively aligned with China, Russia, and Iran, then Venezuela sticks out like a sore thumb.” 

    Trump himself said six years ago in Miami, “When Venezuela is free, and Cuba is free, and Nicaragua is free, this will become the first free hemisphere in all of human history.” 

    Also notable: “Trump has a history of deploying deception in his dealings with foreign adversaries,” the four reporters caution, and note that “In June, the White House announced that he would give Tehran two additional weeks to engage in diplomacy about its nuclear program; three days later, Trump sent warplanes far into Iranian airspace to bomb atomic facilities. He may be employing a similar tactic with Venezuela.” Continue reading, here


    Welcome to this Friday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson with Thomas Novelly and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1983, NATO began its large-scale Able Archer 83 exercises, which the Soviets interpreted as possible opening moves in a nuclear war with the alliance.

    Around the Defense Department

    Today, 2 pm ET: Hegseth’s “Arsenal of Freedom” speech at the National Defense University. A Pentagon press release said it would be livestreamed at war.gov, but as of press time, the “Live Events” page had nothing scheduled. Defense One’s Lauren C. Williams is heading to NDU to cover it; look for her story later today. 

    ICYMI: Experts, officials, industry reacted to a six-page draft of a memo expected to be released after the speech. And here’s a draft list of industry CEOs slated to attend. 

    Related: Defense tech companies will weather the shutdown. But what happens next? “From DOGE’s initial descent to the longest government shutdown in U.S. history, defense contractors are weathering policy changes at different rates during the first leg of the second Trump administration. But while larger companies are thriving, smaller companies—the very ones the White House and Pentagon want to court—have a bumpier ride,” Williams reports off recent earning calls and more.

    Commentary: As it seeks to improve acquisition, the Pentagon should do more with MOSA—that is, modular open systems architecture. “The law already requires MOSA to be used in major warfighting programs ‘to the maximum extent practicable’ and Secretary Hegseth’s own Systems Engineering and Architecture office has been pushing the approach since February,” writes Andy Green, who leads the Mission Systems division of HII, the nation’s largest warship builder. “It is direction that, if enforced, could do more to speed acquisitions and cut costs than any process reform under consideration.” Read his argument, here.

    Pentagon policy shop shifts story on pause in Ukraine aid again. “A senior advisor and former deputy to the Pentagon’s undersecretary for policy told senators on Thursday that his office ‘neither ordered nor even recommended a pause to any weapons shipments to Ukraine’ over the summer, contrary to the press reporting from the time, but also in contrast to testimony from his colleague on Tuesday and statements from the Pentagon on July 2,” writes Defense One’s Meghann Myers, here.

    ICMYI: It’s been a rough week for would-be Pentagon policymakers on the Hill. On Tuesday, Sen. Tom Cotton, R-Ark., said the office was producing a “Pigpen-like mess.”

    Developing: A federal judge is set to rule later today on Trump's order to send National Guard troops to Portland, Oregon, which the president has claimed is a “war-ravaged” city due to persistent but largely peaceful protests outside an immigration detention facility at the southern end of the city.

    Why it matters: The judge’s decision “could be the first to permanently block Trump from using troops to quell protests against federal immigration authorities, which he is also attempting to do in Democrat-led Los Angeles, Chicago and Washington D.C.,” Reuters reports, and notes, “The case could ultimately go to the U.S. Supreme Court.”

    For a bit more background on the case, Oregon Public Broadcasting has this from Sunday.

    Update: The cost to dispatch about 200 Texas Guard troops to Chicago (against the wishes of state officials) could rise above $12 million by December, the San Antonio Express-News reported Thursday. Even though the Texas soldiers are already staged in Illinois, “a court order issued nearly a month ago has blocked them from deploying to the streets or guarding a Chicago-area immigration facility,” the Express-News reminds readers. “In the meantime, [Northern Command officials say] the troops are training on deescalation, crowd control and use-of-force rules.”

    Related:Michigan National Guard chief: No troops needed in Detroit.” 

    Newly confirmed Air Force Chief of Staff Gen. Kenneth Wilsbach is getting the band back together. The four-star general has selected Chief Master Sgt. David Wolfe as the service's next top-enlisted leader, Defense One’s Thomas Novelly reports. Previously, Wolfe was Wilsbach's top enlisted advisor when the general led Air Combat Command.

    Wolfe takes over the role from Chief Master Sgt. David Flosi, who announced his retirement last month following the death of his wife Katy. The service's new top enlisted leader began his military career in 1992 with a background in missile security, elite guard duty, protective services, and space warning security. In an August press release, Wolfe also detailed he received non-judicial punishment early in his Air Force career.

    “I didn't exactly start my Air Force career on the right foot,” Wolfe said in the news release. “An Article 15 and a stint in correctional custody made it clear I needed to change course. It was a rough start, but it turned out to be exactly what I needed.”

    Space Force astronauts? “Today, guardians go to space only in popular misconception, but tomorrow? There might be solid tactical reasons to put Space Force personnel in orbit, argues a new report from the Mitchell Institute for Aerospace Studies, writes Defense One’s Thomas Novelly, here.

    Additional reading: 

    Around the world

    At the president’s order, the Pentagon is drawing up plans for war in Nigeria even though military officials told the New York Times this week “U.S. forces are unlikely to be able to end a decades-long insurgency that has claimed lives across sectarian lines in Africa’s most populous country.” 

    Courses of action with the presumed highest likelihood of success include drone strikes “on the few known compounds in northern Nigeria inhabited by militant groups” and joint operations “with Nigerian soldiers to raid…rural hamlets in the country’s north,” Helene Cooper reported Wednesday.  

    A third and more serious option involves “mov[ing] an aircraft carrier group into the Gulf of Guinea” for a campaign of “strikes deep in northern Nigeria” using fighter jets and long-range bombers. Continue reading, here.  

    From the region:Russia could buy leftover uranium from Niger, France warns,” Semafor reported Friday. 

    And lastly this week: China’s third aircraft carrier just entered service during a ceremony at Yulin Naval Base on Wednesday. However, “security analysts and regional diplomats say tough challenges lie ahead before it can be made fully operational,” Reuters reported Friday from Hong Kong. 

    It’s an 80,000-ton, diesel-fueled carrier named CS Fujian, and it “brings catapult-launch capabilities to Chinese naval aviation,” USNI News explains. “The first two PLAN carriers, CS Liaoning (016) and Shandong (017), used Russian-styled short take-off but arrested recovery (STOBAR) designs. [But now] With the vessel’s three electromagnetic catapults, Chinese forces can sortie fighter jets with heavier payloads and larger aircraft—including the new KJ-600 airborne early warning and command aircraft.”

    In recent sea trials, “the Chinese navy launched its new carrier version of the J-35 stealth fighter and an early-warning aircraft, the KJ-600, as well as a variant of its established J-15 fighter,” Reuters reports. 

    Expert reax: “Despite nine sea trials this year, they are working with almost entirely new platforms top to bottom,” which is why “I think it will be at least another year before it reaches full operational capability,” said Ben Lewis, of the open-source data platform PLATracker. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶