• A suspected nation-state threat actor has been linked to the distribution of a new malware called Airstalk as part of a likely supply chain attack. Palo Alto Networks Unit 42 said it’s tracking the cluster under the moniker CL-STA-1009, where “CL” stands for cluster and “STA” refers to state-backed motivation. “Airstalk misuses the AirWatch API for mobile device management (MDM), which is now

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Trump administration has chosen military installations inside Venezuela to attack, “and the strikes could come at any moment,” the Miami Herald reported Friday—hours after the Wall Street Journal first reported the available targeting. 

    The attacks “will seek to destroy military installations used by the drug-trafficking organization the U.S. says is headed by Venezuelan strongman Nicolás Maduro and run by top members of his regime,” with the goal of “decapitat[ing] the cartel’s hierarchy,” the Herald reports. 

    “If President Trump decides to move forward with airstrikes…the targets would send a clear message to Venezuelan leader Nicolás Maduro that it is time to step down,” U.S. officials told the Journal.

    Update: U.S. military officials “do not know precisely who they have killed in multiple military strikes against alleged drug smuggling boats in the Caribbean” since the attacks began on Sept. 1, Politico reported Thursday following a classified briefing for lawmakers in the House Armed Services Committee. 

    Notable: “The briefing came just one day after Democratic lawmakers were shut out of a similar closed-door Senate meeting on the boat strikes,” the New York Times reports

    Sen. Mark Warner of Virginia, the senior Democrat on the Senate Intelligence Committee: “When an administration decides it can pick and choose which elected representatives get the understanding of their legal argument of why this is needed for military force and only chooses a particular party, it ignores all the checks and balances.” Read on, here.

    Additional reading:UN human rights chief says US strikes on alleged drug boats are ‘unacceptable,’” the Associated Press reported Friday. 

    STRATCOM nominee takes heat hours after Trump’s nuclear-test bombshell. The morning after President Donald Trump vowed to “start testing our Nuclear Weapons,” his pick to lead U.S. Strategic Command fielded questions from senators who wondered what the president meant and what the nominee planned to do about it. Vice Adm. Richard Correll, a submariner and STRATCOM’s deputy commander, vows to give his best military advice. Defense One’s Lauren C. Williams reports.

    ICBM test planned? It appears the U.S. military is about to test an unarmed intercontinental ballistic missile over the Pacific next week, as it does periodically, Dutch researcher Marko Langbroek flagged on social media Friday. 

    New: SpaceX tipped to win $2B for Golden Dome satellites. Wall Street Journal: “The funding was included in the tax-and-spending bill that Trump signed in July, but wasn’t publicly linked to a contractor. The planned ‘air moving target indicator’ system could eventually field as many as 600 satellites,” according to “people familiar with the matter.” More, here.

    Air Force: We need more money to buy the fighter jets we need. Clarifying a report sent to Congress last week, a service official said the Air Force plans to have nearly 1,400 manned tactical aircraft by 2030, about one-quarter more than the 1,160 it has today. But it would need 1,558 to achieve its missions with high confidence and low risk—a goal that would require more funding from Congress. Defense One’s Thomas Novelly reports from the Thursday briefing, here.

    Related: The Senate confirmed fighter pilot Gen. Kenneth Wilsbach to be the Air Force’s next chief of staff. Wilsback will replace Gen. David Allvin, who  unexpectedly announced his retirement in August, halfway through his customary four-year term. Task & Purpose reports, here.

    Moving into generals’ houses. Political appointees Stephen Miller, Kristi Noem, Defense Secretary Pete Hegseth, and Secretary of State Marco Rubio have moved onto military bases, “where they are shielded not just from potential violence but also from protest,” the Atlantic reported on Thursday. The New York Times has more, here.

    Coverage continues below…


    Welcome to this Friday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson with Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1956, the United Kingdom and France began bombing Egypt to force the reopening of the Suez Canal.

    Developing: The National Guard is scrambling to staff and train entirely new “quick reaction forces” by the end of the year, Aaron Glantz of the Guardian reported Wednesday. The effort began in earnest on October 8, when National Guard Army Maj. Gen. Ronald Burkett quietly launched the initiative, which extends from an executive order Trump signed on August 25.

    This means every state is now “required to train 500 national guard members, for a total of 23,500 troops nationwide,” Glantz writes. That’s a sizable uptick from administration plans two months ago reportedly featuring just two groups of 300 troops stationed in Alabama and Arizona as a “Domestic Civil Disturbance Quick Reaction Force.”

    Each state is expected to “be able to deploy a fourth of all their troops within eight hours and all of those assigned to the units within a day,” AP reported Thursday, citing the new memo. “To help with that goal, units will be provided 100 sets of crowd control equipment as well as two full-time trainers by the National Guard Bureau.” 

    Since Guard troops are not trained in handling civil disturbances, they will need to attend special courses in “crowd management techniques,” “domestic civil disturbance training,” and “proper use of baton and body shields,” the memo says. 

    Worth noting: It’s not yet clear exactly how these forces will be dispatched since the U.S. military is forbidden by law from conducting law enforcement activities domestically. The Trump administration has already run afoul of that 150-year-old law with its June deployments of Marines and Guard troops to help immigration enforcement operations in the Los Angeles area—an assignment later found by District Judge Charles Breyer to be in violation of U.S. law. The White House appealed that decision, which moved the case to the 9th Circuit Court.  

    Historian reax: “The establishment of a domestic quick reaction force to quell civil disturbances at a time when there are no civil disturbances that can’t be handled easily by existing law enforcement suggests the administration is expecting those conditions to change,” warned Heather Cox Richardson of Boston College, writing Thursday. 

    Update: Despite the government shutdown, U.S. troops will receive their  next paycheck. Newsweek reported this week “The money comes from multiple sources, including $2.5 billion redirected from the administration’s summer tax cut legislation, $1.4 billion from a military procurement account and another $1.4 billion from research and development.”

    See also:Who is Timothy Mellon, the billionaire who reportedly donated $130M to help pay troops?” via The Hill, reporting Monday. 

    Additional reading: 

    Lastly this week, Ukraine isn’t just hurling attack drones; they’re waging real robot warfare, Defense One’s Patrick Tucker reported Thursday after the release of a recent report from the London-based Royal United Services Institute. 

    What’s going on: “Political developments in Washington interrupted the provision of military-technical assistance, disrupting Ukraine’s ability to coherently plan the equipping of its forces with its international partners. As a result, Ukraine doubled down on a method which delivered results and was under its control: drones,” RUSI’s Jack Watling writes. “Two dedicated UAV regiments, and two non-standard brigades of the Armed Forces of Ukraine…are pioneering the use of novel equipment,” as in air and ground drones.

    Parallel to this, the U.S. and other European militaries are developing new battle-robot concepts around Ukraine’s experiences, Tucker reports. NATO and Ukraine recently tested new ways to counter UAVs. This effort, led by the NATO-Joint Analysis, Training And Education Centre, “aims to keep the alliance on the cutting edge and to support Ukraine,” a NATO official said. But the war in Ukraine has revealed the obsolescence of the way the large militaries of NATO members do many things, from force design to acquisitions to battlefield maneuver. Continue reading, here

    Frontline dispatch: Ukrainian soldiers have turned their drone war with Russia into an incentivized game, the New York Times reported Friday. “Wound a Russian soldier? Eight points. Kill one? That is good for 12. A Russian drone pilot is worth more: 15 points for wounding one, and 25 points for a kill. Capturing a Russian soldier alive with the help of a drone is the jackpot: 120 points.”

    How it works: “Teams compete for points to acquire Ukrainian-made gear, including basic surveillance drones and larger drones carrying powerful explosives, through an internal Amazon-style weapons store called Brave1 Market…The more points a unit gets, the better stuff it can buy, ensuring that resources are directed to the teams that best use them.” Story (gift link), here

    For your ears only, Patrick Tucker unpacked what he learned during a recent trip to Latvia and Estonia regarding the European Union’s emerging plans for a “drone wall” to defend against an increasing number of Russian aerial incursions. Find that podcast episode on our site, at Spotify, or wherever you listen to podcasts. 

    And here are two leftover links we didn’t get to this week, but you might still like to read over the weekend: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google is strengthening its defense against mobile scams with advanced AI-powered protections built directly into Android devices.

    As cybercriminals become more sophisticated, using AI themselves to create convincing fraud schemes, Google’s new safeguards work around the clock to protect your personal information and money from theft.

    Mobile scams cost people worldwide over $400 billion annually, as fraudsters send increasingly convincing messages and calls to trick unsuspecting users.

    Android now blocks over 10 billion suspected malicious calls and messages every month, preventing scams before they even reach your phone.

    Android Gets Smarter at Blocking Scammers

    Recent surveys comparing Android and iPhone users reveal significant differences in protection effectiveness. Android users reported receiving 58% fewer scam texts than iPhone users in the previous week.

    When comparing Google Pixel phones specifically to iPhones, the advantage grew even larger. Pixel users were 96% more likely to report zero scam messages.

    users’ experience with scams on Android and iOS
    users’ experience with scams on Android and iOS

    The difference extends to user confidence. Android users were 20% more likely to describe their device’s scam protections as “very effective,” while iPhone users were 150% more likely to say their protections were ineffective.

    Google’s defense strategy uses multiple layers of protection. Google Messages automatically filters spam by analyzing sender reputation and message patterns.

    For suspicious calls, Phone by Google blocks known spam automatically and screens unfamiliar numbers. Advanced on-device AI analyzes conversations in real-time, warning you about fraudulent patterns without saving any call data on your phone.

    comparison of Android and iOS AI-powered protections
    Comparison of Android and iOS AI-powered protections

    These protections work silently in the background, combined with Google Play Protect scanning apps for threats and Safe Browsing protection in Chrome.

    Android continuously updates its defenses, blocking over 100 million suspicious numbers from RCS services monthly to prevent scams before they start.

    comparison of scam protections across various devices
    Comparison of scam protections across various devices

    In today’s threat landscape, intelligent security built into your phone is essential. Google’s commitment to AI-powered protection ensures Android users can communicate confidently, knowing their device is actively defending against modern scams and fraud attempts.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Unveils new AI-Protection for Android to Keep You Safe From Mobile Scams appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A China-affiliated threat actor known as UNC6384 has been linked to a fresh set of attacks exploiting an unpatched Windows shortcut vulnerability to target European diplomatic and government entities between September and October 2025. The activity targeted diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands, as well as government agencies in Serbia, Arctic Wolf said in a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Sophos researchers have identified real-world exploitation of a newly disclosed vulnerability in Windows Server Update Services (WSUS), where threat actors are harvesting sensitive data from organizations worldwide. The critical remote code execution flaw, tracked as CVE-2025-59287, has become a prime target for attackers seeking to breach enterprise networks and extract valuable information without authentication requirements. […]

    The post Attackers Exploit Windows Server Update Services Flaw to Steal Sensitive Organizational Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The exploitation of a recently disclosed critical security flaw in Motex Lanscope Endpoint Manager has been attributed to a cyber espionage group known as Tick. The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges on on-premise versions of the program. JPCERT/CC, in an alert issued this month, said that it

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has announced enhanced artificial intelligence protections designed to combat the rising tide of mobile scams affecting billions of users worldwide. The company revealed that fraudsters stole over $400 billion globally in the past year using advanced AI-powered schemes, making mobile security more critical than ever. Android’s Advanced Defense Against Mobile Fraud Google’s Android platform […]

    The post Google Launches New AI Security Features on Android to Block Mobile Scams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Progress Software has released critical security patches addressing a high-severity vulnerability affecting MOVEit Transfer, a widely used enterprise file transfer solution.

    The vulnerability, tracked as CVE-2025-10932, carries a CVSS score of 8.2 and impacts the AS2 module across multiple product versions.

    The uncontrolled resource consumption vulnerability in MOVEit Transfer’s AS2 module could allow attackers to disrupt service availability by exhausting system resources.

    The flaw exists in versions 2025.0.0 through 2025.0.2, 2024.1.0 through 2024.1.6, and 2023.1.0 through 2023.1.15. With a network-accessible attack vector requiring no authentication or user interaction, organizations using affected versions face significant exposure to potential service disruptions and exploitation.

    MOVEit Transfer Vulnerability

    The vulnerability stems from inadequate controls over resource consumption, classified under CWE-400. This category of flaws enables attackers to overwhelm systems by forcing excessive resource allocation, leading to denial-of-service conditions that impact legitimate business operations.

    Progress has distributed hotfixes that mandate IP address whitelisting for the AS2 module, creating a protective barrier against unauthorized access. Organizations must take immediate action based on their specific deployment model.

    For enterprises not utilizing the AS2 module with MOVEit products, a temporary workaround involves removing the vulnerable endpoints.

    Administrators should delete the AS2Rec2.ashx and AS2Receiver.aspx files from the C:\MOVEitTransfer\wwwroot directory. This straightforward approach requires no server restart and maintains continuity until permanent patches are applied.

    For organizations actively using AS2 functionality, applying the hotfix becomes essential. After updating to the patched versions MOVEit Transfer 2025.0.3, 2024.1.7, or 2023.1.16, administrators must configure IP whitelist rules for authorized trading partners.

    AttributeValue
    CVE IDCVE-2025-10932
    ProductProgress MOVEit Transfer
    Vulnerability TypeUncontrolled Resource Consumption
    Affected ModuleAS2 Module
    CVSS Score8.2 (HIGH)

    This involves logging into MOVEit Transfer as an administrator, navigating to Settings, accessing Security Policies, and configuring Remote Access Rules to restrict AS2 module access to trusted partner IP addresses.

    Progress has made fixed versions available through its Download Center for customers maintaining current maintenance agreements. The patch availability spans three major version lines, ensuring organizations can update within their supported product branch.

    Customers without active maintenance agreements should contact Progress renewal services or their designated partner account representative.

    Notably, Progress MOVEit Cloud users require no immediate action, as the cloud infrastructure has already been upgraded to patched versions. However, on-premises deployments demand rapid attention to mitigate exposure.

    Organizations running MOVEit Transfer versions outside these active branches should prioritize upgrading to currently supported releases or implementing the temporary AS2 endpoint removal workaround.

    The high CVSS score reflects the severity of this vulnerability and the potential business impact of service disruptions. Quick deployment of patches represents a critical priority for security teams managing file transfer infrastructure across their enterprise environments.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Progress Patches MOVEit Transfer Uncontrolled Resource Consumption Vulnerability appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—No single technology can win every battle and fix every problem, the leader of Special Operations Command Pacific said this week. Instead, the “ability to integrate multiple systems, disparate systems, with more open architecture—that is eventually going to win. If you have that sort of single, standalone technology…it’s likely to be cracked, hacked, and eventually overcome.”

    Remember the Karate Kid movies, Maj. Gen. Jeffrey VanAntwerp urged his audience at the AFCEA TechNet Indo-Pacific conference here. When Daniel learned a crane kick, Mr. Miyagi told him, “If done right, no can defense,” VanAntwerp said. “And that worked in Karate Kid one, but then in Karate Kid two, he goes to Okinawa, to people who are more familiar with the operational environment, and…the crane kick did not work.…He eventually had to go to the spinning drum.” 

    For SOCPAC, VanAntwerp said the combination of robotics, autonomy, and resilient networks is “absolutely critical,” because information is useless unless it comes with an ability to make a coherent picture. And whatever combination of systems that might emerge, having “the ability to disrupt our adversaries’ ability to target us, that is the oxygen that we require in this theater.”

    VanAntwerp recounted a Ukrainian SOF commander’s remarks at a recent forum, noting that Ukraine has been able to deny Russia access to large portions of the Black Sea without a navy, deny air superiority with no air force, and hold the line with a significantly smaller army. 

    “They’ve been able to do that through a combination of the ability to see and sense and understand… with some help from partners,” and a network of various unmanned systems, he said. “It’s pretty amazing, and provides a really great example for us.” 

    So why is it taking the United States so much longer to adapt? VanAntwerp believes the key reason is “the lack of a tactical imperative”—namely, no American troops are dying on battlefields. 

    “I do believe this machine, which includes all of you and us, can move incredibly fast when there is that imperative,” he told the audience of industry representatives and troops. “But without it, we tend to, knowingly or unknowingly, we tend to pace ourselves.” 

    And as officials consider solutions, VanAntwerp said they must also be careful to consider the “cost curve,” he said. 

    With unmanned systems and the networks that enable them, the goal is to either have expendable low cost systems, or expensive highly survivable systems. “If we get caught in the middle, which is where we often find ourselves… that’s just bankruptcy. We can’t afford it.” 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Throughout the first half of 2025, the FortiGuard Incident Response team investigated dozens of security breaches across multiple industries driven by financially motivated threat actors. What emerged from these investigations was a striking pattern: attackers are abandoning complex, malware-heavy approaches in favor of a deceptively simple method—simply logging in using stolen credentials and leveraging legitimate […]

    The post Stolen Credentials Drive the Rise of Financially Motivated Cyberattacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶