• Security teams are constantly on the move. Alerts never stop coming in, workloads keep piling up, and the pressure to react fast can wear anyone down. Add long investigations and a maze of tools on top of that, and burnout becomes almost inevitable. 

    Still, it doesn’t have to be this way. With the right approach, combining interactive sandboxing and smart automation, SOCs can take the pressure off, resolve incidents faster, and keep analysts focused on what matters most: catching threats before they spread. 

    Here are three ways to make that happen: 

    1. See and Explore Full Attack Chain in Real Time 

    One big reason analysts burn out is the constant waiting. Traditional tools often take hours to confirm whether an alert is real, forcing teams to chase uncertainty while the clock keeps ticking. By the time a threat is verified, it may already be moving through the network, and the workload has doubled. 

    Interactive sandboxes, such as ANY.RUN change that. Instead of relying on static reports, analysts can watch an attack unfold live inside a secure virtual machine. Suspicious files, URLs, or scripts are detonated instantly, revealing every step of the behavior chain, from initial dropper to payload, without risking production systems. 

    That visibility turns slow, fragmented investigations into fast, confident decisions. Analysts know exactly what they’re dealing with and how to stop it, often within seconds. 

    For instance, this analysis session gave final verdict and full attack chain of LockBit 5.0 attack in just 33 seconds: 

    View real-world attack exposed in 33 secs 

    LockBit attack fully exposed inside ANY.RUN sandbox in 33 seconds 

    According to the recent research carried out by ANY.RUN team, companies using interactive sandboxing had the following real-world results: 

    • 88% of attacks become visible within the 60 seconds of analysis. 
    • Teams report up to a 36% higher detection rate on average. 

    See how your SOC can cut investigation time and handle more threats with less stress.  -> Talk to ANY.RUN Experts 

    2. Find Evasive Threats Before They Drain Your Team’s Time 

    Some attacks are built to stay hidden. They wait for the right user action, a click, a CAPTCHA, a file download, before revealing their true behavior. Traditional tools can’t always simulate these steps, which means analysts often spend hours trying to manually trigger and analyze the attack chain. 

    ANY.RUN’s interactive sandbox changes that. Its Automated Interactivity feature mimics real user behavior inside a secure virtual machine, clicking links, solving CAPTCHAs, opening attachments, and following redirects, to expose even the most evasive threats automatically. 

    That means analysts no longer need to repeat the same manual steps for every case. What once took hours, like uncovering a malicious link hidden in a QR code or a payload buried behind multiple redirects, can now be done in seconds. 

    Here’s an example of Automated Interactivity inside the ANY.RUN sandbox: 

    View analysis session with malicious QR code  

    ANY.RUN sandbox solving CAPTCHA automatically 

    As shown in the session, the sandbox performs user actions on its own, uncovering the malicious link hidden in a QR code, solving the CAPTCHA, and collecting all behavioral indicators for immediate review. Analysts get a full report, complete with IOCs and TTPs, without spending too much time and effort. 

    Well-structured report generated by ANY.RUN sandbox 

    Real-world results: 

    • Up to 58% more hidden threats identified compared to traditional tools. 
    • 30% fewer Tier 1 → Tier 2 escalations, as junior analysts can handle more incidents independently. 

    By automating the tedious parts of analysis, SOCs find evasive threats faster, cut down investigation time, and free analysts to focus on higher-value work. 

    3. Connect Your Tools for a Faster, Smoother Workflow 

    Even the most skilled team can lose momentum when tools don’t work together. Jumping between dashboards, copying IOCs, and updating multiple systems manually eats away at valuable investigation time, and adds to analyst frustration. 

    With ANY.RUN’s connectors, your sandbox, threat intelligence, and automation tools all work in sync. The platform connects with popular SOC systems like QRadar, Cortex XSOAR, OpenCTI, and Microsoft Sentinel, letting analysts access threat data, behavioral insights, and enrichment directly from their main workspace. 

    Instead of switching tabs, the context travels with you. Every alert is enriched with fresh IOCs and real behavioral data, helping teams make faster and more confident response decisions. 

    Real-world results: 

    • Up to 3× faster response times thanks to a connected, zero-delay workflow. 
    • Access to 24× more IOCs per case, powered by data from over 15,000 SOCs worldwide. 

    By keeping every system in sync, SOCs save time, eliminate repetitive work, and maintain a clear, unified picture of what’s happening, all without adding extra complexity. 

    Turn Overload into Faster, Confident Response 

    SOC burnout doesn’t happen overnight. It builds up through endless alerts, manual work, and tools that don’t fit together. But when teams gain real-time visibility, automate repetitive tasks, and work within one connected system, the pressure starts to fade, and efficiency takes its place. 

    Analysts can focus on meaningful investigations instead of chasing noise. Collaboration improves, and incidents get solved faster, often in a fraction of the time it used to take. 

    With interactive sandboxing, automation, and integrations that bring everything together, ANY.RUN helps SOCs cut response time by an average of 21 minutes per case, turning daily overload into fast, confident action. 

    Contact the ANY.RUN Enterprise team to see how your SOC can do the same. 

    The post 3 Steps to Beat Burnout in Your SOC and Solve Cyber Incidents Faster  appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated cyberattack campaign, active since August 2025, where a China-nexus threat actor has been weaponizing a legitimate server operations tool called Nezha to execute commands and deploy malware on compromised web servers.

    This campaign, uncovered by Huntress, represents the first publicly reported instance of Nezha being abused in this manner, highlighting a tactical shift towards leveraging open-source tools to evade detection.

    The attackers employed a creative log poisoning technique to gain initial access before deploying the notorious Ghost RAT, primarily targeting entities in Taiwan, Japan, South Korea, and Hong Kong.

    The intrusion began with the exploitation of a vulnerable, public-facing phpMyAdmin panel that lacked proper authentication. After gaining access from an AWS-hosted IP in Hong Kong, the attackers immediately set the interface language to simplified Chinese.

    They then used an inventive technique known as log poisoning to plant a web shell. By manipulating MariaDB’s logging functions, the threat actor set the general log file to a PHP file within the webroot.

    They then executed an SQL query containing a one-liner PHP web shell, effectively writing their backdoor into the executable log file.

    PHP Webshell
    PHP Webshell

    This method allowed them to execute arbitrary code on the server using tools like AntSword, which are designed to manage such backdoors.

    Nezha Monitoring Tool to Deploy Webshell

    After establishing control with the web shell, the adversary’s primary objective was to deploy a more persistent and versatile tool. They used the AntSword connection to download and execute live.exe, an installer for a Nezha agent.

    Nezha is a legitimate, open-source tool for server monitoring and task management. However, in this case, it was repurposed as a malicious implant.

    The agent’s configuration file pointed to the attacker’s command-and-control (C2) server, which was running a Nezha dashboard, Huntress said.

    This dashboard, set to the Russian language, revealed the attackers had compromised over 100 victim machines across 53 regions, with a significant concentration in East Asia, aligning with China’s geopolitical interests.

    Victims
    Victims infected

    With the Nezha agent providing stable and stealthy access, the attackers escalated their privileges. They used Nezha’s command execution capabilities to launch an interactive PowerShell session, where they created an exclusion rule in Windows Defender to avoid detection.

    Immediately after, they deployed x.exe, a variant of the infamous Ghost RAT. Analysis of this malware revealed communication protocols and persistence mechanisms consistent with previous campaigns attributed to Chinese advanced persistent threat (APT) groups.

    The incident underscores the necessity of hardening public-facing applications and monitoring for the abuse of legitimate software, as threat actors continue to adapt their playbooks to stay ahead of defenders.

    CategoryTypeIndicatorDescription
    FilePathC:\xamp\htdocs\123.phpWeb shell
    FileSHA256f3570bb6e0f9c695d48f89f043380b43831dd0f6fe79b16eda2a3ffd9fd7ad16Web shell
    FileURLhttps://rism.pages[.]dev/microsoft.exeNezha Agent
    FilePathC:\Windows\Cursors\live.exeNezha Agent
    FileSHA2569f33095a24471bed55ce11803e4ebbed5118bfb5d3861baf1c8214efcd9e7de6Nezha Agent
    FilePathC:\Windows\Cursors\x.exeGhost RAT Payload
    FileSHA2567b2599ed54b72daec0acfd32744c7a9a77b19e6cf4e1651837175e4606dbc958Ghost RAT Payload
    FilePathC:\Windows\system32\SQLlite.exeRenamed rundll32.exe
    FileSHA25682611e60a2c5de23a1b976bb3b9a32c4427cb60a002e4c27cadfa84031d87999Renamed rundll32.exe
    FilePathC:\Windows\system32\32138546.dllMalicious DLL
    FileSHA25635e0b22139fb27d2c9721aedf5770d893423bf029e1f56be92485ff8fce210f3Malicious DLL
    InfrastructureIP Address54.46.50[.]255Initial Access IP
    InfrastructureIP Address45.207.220[.]12Web shell and Backdoor C2/Operator IP
    InfrastructureDomainc.mid[.]alNezha C2 Domain
    InfrastructureIP Address172.245.52[.]169Nezha C2 IP
    InfrastructureDomaingd.bj2[.]xyzBackdoor C2/Operator Domain
    MiscellaneousService NameSQLlitePersistence Service Name
    MiscellaneousMutexgd.bj2[.]xyz:53762:SQLliteInfection Marker

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post Chinese Hackers Weaponized Nezha Tool to Execute Commands on Web Server appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In 2025, securing global supply chains is one of the top priorities for enterprises seeking business continuity, data integrity, and resilience against threats. As cyber risks, fraud, and disruption increase across physical and digital networks, leaders must adopt robust intelligence and end-to-end security solutions. This definitive ranking evaluates the best supply chain intelligence security companies, […]

    The post Top 10 Best Supply Chain Intelligence Security Companies in 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Generative AI has gone from a novelty to a foundation of organization efficiency in just a few short years. From copilots embedded in office suites to dedicated large language model (LLM) platforms, personnel now rely on these platforms to code, analyze, draft, and decide.

    But for CISOs and security architects, the very speed of adoption has created a dilemma the more powerful the platforms the more porous the organization boundary becomes.

    And here’s the counterintuitive part: the biggest exposure isn’t that personnel are negligent with prompts. It’s that organizations are applying the wrong mental model when assessing offerings trying to retrofit legacy controls for a exposure surface they were never designed to cover. A new report by LayerX Security tries to bridge that gap.

    The Hidden Challenge in Today’s Vendor Landscape

    The AI data security landscape is already crowded. Every vendor, from traditional DLP to next-gen SSE platforms, is rebranding around “AI security.” On paper, this seems to offer transparency In practice, it muddies the waters.

    The truth is that most legacy architectures, designed for file transfers, email, or network gateways, cannot meaningfully analyze or control what happens when a user pastes sensitive code into a chatbot, or uploads a dataset to a personal AI tool.

    Assessing offerings through the lens of yesterday’s risks is what leads many organizations to buy shelfware.

    This is why the buyer’s journey for AI data security needs to be reframed. Instead of asking “Which vendor has the most features?” the real question is: Which vendor understands how AI is actually used at the last mile: inside the browser, across sanctioned and unsanctioned tools?

    The Buyer’s Journey: A Counterintuitive Path

    Most procurement processes start with visibility. But in AI data security, visibility is not the finish line; it’s the starting point. Discovery will show you the proliferation of AI tools across departments, but the real differentiator is how a solution interprets and enforces policies in real time, without throttling productivity.

    The buyer’s journey often follows four stages:

    1. Discovery – Identify which AI tools are in use, sanctioned or shadow. Conventional wisdom says this is enough to scope the problem. In reality, discovery without context leads to overestimation of risk and blunt responses (like outright bans).
    1. Real-Time Monitoring – Understand how these tools are being used, and what data flows through them. The surprising insight? Not all AI usage is risky. Without monitoring, you can’t separate harmless drafting from the inadvertent leak of source code.
    1. Enforcement – This is where many buyers default to binary thinking: allow or block. The counterintuitive truth is that the most effective enforcement lives in the gray area—redaction, just-in-time warnings, conditional approvals. These not only protect data but also educate users in the moment.
    1. Architecture Fit – Perhaps the least glamorous but most critical stage. Buyers often overlook deployment complexity, assuming security teams can bolt new agents or proxies onto existing stacks. In practice, solutions that demand infrastructure change are the ones most likely to stall or get bypassed.

    What Experienced Buyers Should Really Ask

    Security leaders know the standard checklist: compliance coverage, identity integration, reporting dashboards. But in AI data security, some of the most important questions are the least obvious:

    • Does the solution work without relying on endpoint agents or network rerouting?
    • Can it enforce policies in unmanaged or BYOD environments, where much shadow AI lives?
    • Does it offer more than “block” as a control. I.e., can it redact sensitive strings, or warn users contextually?
    • How adaptable is it to new AI tools that haven’t yet been released?

    These questions cut against the grain of traditional vendor evaluation but reflect the operational reality of AI adoption.

    Balancing Security and Productivity: The False Binary

    One of the most persistent myths is that CISOs must choose between enabling AI innovation and protecting sensitive data. Blocking tools like ChatGPT may satisfy a compliance checklist, but it drives employees to personal devices, where no controls exist. In effect, bans create the very shadow AI problem they were meant to solve.

    The more sustainable approach is nuanced enforcement: permitting AI usage in sanctioned contexts while intercepting risky behaviors in real time. In this way, security becomes an enabler of productivity, not its adversary.

    Technical vs. Non-Technical Considerations

    While technical fit is paramount, non-technical factors often decide whether an AI data security solution succeeds or fails:

    • Operational Overhead – Can it be deployed in hours, or does it require weeks of endpoint configuration?
    • User Experience – Are controls transparent and minimally disruptive, or do they generate workarounds?
    • Futureproofing – Does the vendor have a roadmap for adapting to emerging AI tools and compliance regimes, or are you buying a static product in a dynamic field?

    These considerations are less about “checklists” and more about sustainability—ensuring the solution can scale with both organizational adoption and the broader AI landscape.

    The Bottom Line

    CISOs evaluating AI data security solutions face a paradox: the space looks crowded, but true fit-for-purpose options are rare. The buyer’s journey requires more than a feature comparison; it demands rethinking assumptions about visibility, enforcement, and architecture.

    The counterintuitive lesson? The best AI security investments aren’t the ones that promise to block everything. They’re the ones that enable your enterprise to harness AI safely, striking a balance between innovation and control.

    LayerX has published a new Buyer’s Guide to AI Data Security that distills this complex landscape into a clear, step-by-step framework. The guide is designed for both technical and economic buyers, walking them through the full journey: from recognizing the unique risks of generative AI to evaluating solutions across discovery, monitoring, enforcement, and deployment. By breaking down the trade-offs, exposing counterintuitive considerations, and providing a practical evaluation checklist, the guide helps security leaders cut through vendor noise and make informed decisions that balance innovation with control.

    The post Rethinking AI Data Security: A Buyer’s Guide for CISOs appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Tel Aviv, Israel, October 8th, 2025, CyberNewsWire

    Miggo Security, pioneer and innovator in Application Detection & Response (ADR) and AI Runtime Defense, today announced it has been recognized as a Gartner Cool Vendor in AI Security.

    To us, this recognition underscores Miggo’s mission to close the detection-to-mitigation gap that plagues security teams today by providing comprehensive, fast, and precise analysis and response for what applications actually do at runtime. 

    Traditional security approaches are failing to match the dynamic, behavioral reality of modern applications. In fact, Gartner writes, “Through 2029, over 50% of successful cybersecurity attacks against AI agents will exploit access control issues, using direct or indirect prompt injection as an attack vector.”

    However, Miggo’s runtime behavioral security can handle any application from traditional to AI-incorporated features, to AI apps themselves and AI agents.

    We believe Miggo Security’s ADR platform is cool because of how it detects and responds to security flaws in applications in a matter of minutes, combining unique runtime context with AI-augmented reasoning, risk analysis and actionable defense.

    Miggo’s predictive analysis, preemptive protection, and real-time response is built specifically for the risks of AI-driven environments.

    “This recognition by Gartner, in my opinion, validates the vision and innovation that define Miggo Security,” said Daniel Shechter, CEO and Co-Founder of Miggo Security.

    “We believe Application Detection & Response is the future of runtime security in the AI era to give CISOs and security teams the ability to know, prove, and shield AI-native threats in real time.”

    Miggo’s differentiators include:

    • DeepTracing Technology: Detects AI-native threats, zero-days, and emerging attack patterns in real time.
    • AppDNA & Predictive Vulnerability Database: Cuts vulnerabilities backlog by 99% with deep context and automated AI proving engine. 
    • Miggo WAF Copilot: Generate custom WAF rules in minutes, protecting against emerging threats
    • Agentless Integration: Deploys seamlessly with Kubernetes, traces, and application profiles, eliminating friction.
    • Force Multiplier for Teams: Provides centralized AI-driven context, helping security and engineering teams align faster while reducing overhead by 30% or more.

    The GARTNER COOL VENDOR badge is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved.

    Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation.

    Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

    GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Cool Vendors is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.  

    About Miggo Security

    Miggo Security delivers real-time application detection and response (ADR), empowering enterprises to identify and neutralize application threats.

    With its AI-augmented platform, Miggo helps organizations secure both traditional and AI-driven applications at scale, reducing exposure windows by up to 99% and cutting operational overhead by 30% or more.

    For more information, users can visit www.miggo.io.

    Contact

    CEO

    Omri Hurwitz

    Omri Hurwitz Media

    omri@omrihurwitz.com

    The post Miggo Security Named a Gartner® Cool Vendor in AI Security appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Tel Aviv, Israel, October 8th, 2025, CyberNewsWire Miggo Security, pioneer and innovator in Application Detection & Response (ADR) and AI Runtime Defense, today announced it has been recognized as a Gartner Cool Vendor in AI Security. To us, this recognition underscores Miggo’s mission to close the detection-to-mitigation gap that plagues security teams today by providing […]

    The post Miggo Security Named a Gartner® Cool Vendor in AI Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fraud prevention has become one of the most important priorities for enterprises, financial institutions, and digital-first businesses in 2025. With rising cyber threats, account takeovers, synthetic identities, financial crimes, phishing, and social engineering attacks, the need for advanced fraud detection and prevention tools is at an all-time high. The top fraud prevention companies are integrating […]

    The post Top 10 Best Fraud Prevention Companies in 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. “Site visitors get injected content that was drive-by malware like fake Cloudflare verification,” Sucuri researcher Puja Srivastava said in an analysis published last week. The website security company

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Skeptical senators grill White House pick to lead Indo-Pacific policy. Led by Sen. Roger Wicker, R-Miss., a bipartisan slice of the Senate Armed Services Committee took turns on Tuesday expressing concerns about the Trump administration’s inward shift in national-security focus and its alienation of key allies and partners in the Asia-Pacific region.

    Wicker: “The Chinese Communist Party, along with the nuclear-armed Russia and North Korea, pose a significant threat to the United States. The scale and scope of that threat put a premium on our alliances. In light of that, I'm disappointed with some of the decisions the department has made with respect to our allies in Japan, South Korea, Australia, and Taiwan. A few of these choices have left me scratching my head.” 

    Sen. Mark Kelly, D-Ariz.: “There are some rumors, I guess, circulating that the new national defense strategy is going to shift priority away from the PRC and away from the Indo-Pacific, and instead focus on the Western Hemisphere. We'll see what happens when that comes out,” Kelly said. “If that's true…this shift is alarming, because most of what is briefed to this committee focuses on ‘how are we going to deter China’.”

    The senators spoke during the confirmation hearing for John Noh, the Trump administration’s pick to be assistant defense secretary for Indo-Pacific security affairs. Noh, who is currently ASD for East Asia, responded that China is “an enormous concern of mine.” But he waffled when Wicker asked about the Trump administration’s decision to cancel $400 million in military aid to Taiwan, and cited President Donald Trump’s stance that the island’s government should up its defense spending to about 10 percent of its GDP. 

    Wicker worried that “DOD may be using the Ukraine playbook with Taiwan by taking defense items procured with presidential drawdown authority and returning it to the defense stockpile” which misaligns with “congressional intent, and would require Taiwan to purchase these items that have already been authorized as PDA.” Defense One’s Lauren C. Williams has more from the hearing, here.

    The U.S. military in Syria says it killed a militant planner in an unspecified strike Thursday last week. The militant’s name was Muhammad ’Abd-al-Wahhab al-Ahmad, and U.S. Central Command officials claim he was an “attack planner” with Ansar al-Islam, an al-Qaeda affiliated terrorist group. Tiny bit more, here

    Additional reading: Hegseth announces ‘barracks task force’ during speech to new recruits,” The Hill reported Tuesday.


    Welcome to this Wednesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1918, U.S. Army Cpl. Alvin York killed 28 German soldiers and captured 132 others, which eventually won him the Medal of Honor.

    Militarizing America’s streets

    President Trump said Wednesday morning he thinks Chicago’s mayor and the state’s governor should be jailed. Writing on social media, Trump said Wednesday shortly after 8 a.m. ET, “Chicago Mayor should be in jail for failing to protect Ice Officers! Governor Pritzker also!

    Reuters notes: “Neither Chicago Mayor Brandon Johnson nor Illinois Governor JB Pritzker has been accused of criminal wrongdoing,” though “Johnson signed an executive order on Monday creating an ‘ICE Free Zone’ that prohibits federal immigration agents from using city property in their operations.”

    Governor JB Pritzker wrote in reply: “Trump is now calling for the arrest of elected representatives checking his power. What else is left on the path to full-blown authoritarianism?”

    Chicago’s Mayor Johnson responded: “This is not the first time Trump has tried to have a Black man unjustly arrested. I'm not going anywhere.”

    By the way: 58% of Americans “think the president should send armed troops only to face external threats,” according to new polling published Wednesday by Reuters/Ipsos. That includes 51% of Republicans and 72% of Democrats. But when asked if the president should be able to send troops even if a governor objects, there’s a sharp split with 70% of Republicans saying yes but just 13% of Democrats saying they feel similarly.

    “I think it’s a bad precedent,” North Carolina Republican Sen. Thom Tillis said Tuesday of President Trump’s order to deploy out-of-state National Guard troops to Chicago. “I worry about someday a Democrat president sending troops or National Guard from New York, California, Oregon, Washington state to North Carolina.”

    “I don’t see how you can argue that this comports with any sort of conservative view of states’ rights,” he added. 

    Tillis wasn’t the only Republican dissenting this week. “This is not the role of our military,” Sen. Lisa Murkowski, R-Alaska, said Tuesday as well. “It’s one thing if governors ask and they say, ‘Hey, I need help.’ That’s the way we’ve handled it before,” she said. “I am very apprehensive about the use of our military for policing and more the politicization that we’re seeing within the military…We’re seeing these orders, we’re seeing a directive that is unprecedented and it should make us all concerned,” Murkowski said. 

    “I think [Trump is] just poking his finger in [Portland’s] eye,” one anonymous senator told The Hill. “I don’t know it’s the best way to solve the issue, but it looks like in Portland, the place is on fire, but that could be isolated reports,” said the Republican, who requested anonymity. 

    But that’s largely where the Republican dissent ends for sending Texas soldiers to Illinois without the consent of the latter’s governor. Read more at The Hill.

    The six senators from Illinois, Oregon, and California warned Tuesday that Trump is “moving us closer to authoritarianism” with his troop deployments against governors’ wishes. “Whether in Los Angeles, Chicago, or Portland, the Trump Administration continues fabricating claims of chaos and crime on American streets to justify his false assertions that there is a ‘need’ to deploy troops into our cities—all while literally defunding our police by cutting funding that helps local law enforcement,” Democratic Sens. Tammy Duckworth and Dick Durbin of Illinois, Jeff Merkley and Ron Wyden of Oregon, and California’s Alex Padilla and Adam Schiff.

    “None of our states asked for this. None of our states need this. And none of our National Guard Troops—who are our friends and neighbors—signed up to intimidate their fellow Americans in their own communities or to be used as political pawns by a vindictive President,” the senators said, and called for Trump to “immediately reverse course and end these un-American deployments.” 

    Army veteran Tammy Duckworth: “We know deploying the military is not about protecting [Homeland Security] officials, because these same officials are escalating their tactics every day to provoke a manufactured crisis to justify sending in the military,” the retired lieutenant colonel said on the senate floor Tuesday. “We know it’s not about crime, because Trump literally defunded the police by slashing $800 million in public safety programs. This is about Trump’s desire to crush dissent and erode our constitutional rights.”

    “The President wants to use our military as his personal police force that goes into American cities, detains civilians on our bases and intimidates people who disagree with him,” Duckworth said. “Who wins in that scenario? Not the American people. Not our servicemembers. Only Donald Trump, along with our enemies who will exploit our distraction.” 

    Senate Majority Leader John Thune: “If there are federal personnel who are being threatened, then I think the president has a right to protect them,” the Republican from South Dakota said Monday, calling Trump’s decision to send out-of-state troops to Illinois “a justifiable use of executive branch authority.” 

    Commentary: “The greatest crisis of American civil-military relations in modern history is now under way,” argues Tom Nichols, former Naval War College professor, writing in the Atlantic on Tuesday. “Despite the firing of several top officers—and Trump’s threat to fire more—the U.S. armed forces are still led by generals and admirals whose oath is to the Constitution, not the commander in chief. But for how long?” he asked while emphasizing, “I write these words with great trepidation.” 

    Nichols reminds us that Trump has already “declared war on Chicago; called Portland, Oregon, a ‘war zone’; and referred to his political opponents as ‘the enemy from within.’ Trump clearly wants to use military power to exert more control over the American people, and soon, top U.S.-military commanders may have to decide whether they will refuse such orders from the commander in chief.” 

    “The Democrats are too timid, and the Republicans are too compromised. Only by standing together can the senior military officials warn Trump away from leading America into a full-blown civil-military confrontation,” Nichols writes. Read the rest (gift link), here

    Additional reading:Chicago journalists, protesters sue Trump administration, alleging ‘extreme brutality,’Politico reported Tuesday. 

    Shutdown shenanigans

    Republican leaders in Congress are at odds over emergency legislation to pay troops during the government shutdown, Politico reported Tuesday afternoon. The tensions pit Speaker Mike Johnson, who is in favor of the legislation, against Senate Majority Leader John Thune, who told reporters, “Honestly, you don’t need that.”

    Update: Trump is threatening mass layoffs during the ongoing shutdown, but that may be illegal, the New York Times reported Tuesday. What’s more, “Budget experts said that the White House had also incorrectly presented layoffs as a fiscal necessity, something no other president in the modern era has done. Not even during the longest federal stoppage on record—a five-week closure in Mr. Trump’s first term—did the government shed workers so that it could finance the few operations that are allowed to continue.”

    In still more confusing messaging from the White House, on Tuesday, the Trump admin said furloughed feds were not guaranteed back pay. On Wednesday, it sent notices saying they were, Eric Katz of Government Executive reports. 

    Additional reading: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A China-aligned advanced persistent threat (APT) group is actively leveraging OpenAI’s ChatGPT platform to develop malware and craft sophisticated spear-phishing emails for its global campaigns.

    Security firm Volexity tracks the actor as UTA0388 and has analyzed its operations since June 2025, concluding with high confidence that the group uses Large Language Models (LLMs) to automate and enhance its attacks against targets in North America, Asia, and Europe.

    Volexity first detected UTA0388 conducting highly tailored spear-phishing campaigns that impersonated senior researchers from fabricated but legitimate-sounding organizations. The initial goal was to socially engineer targets into clicking links leading to malicious archives.

    Over three months, the threat actor expanded its operations, sending emails in English, Chinese, Japanese, French, and German. UTA0388’s tactics evolved to include “rapport-building phishing,” where they first engage a target in a benign conversation before sending a malicious link.

    GOVERSHELL Malware

    The payload is delivered via a ZIP or RAR archive containing a legitimate executable and a malicious Dynamic Link Library (DLL).

    When the user runs the executable, a technique called DLL search order hijacking is used to load the malicious payload, a backdoor Volexity has named GOVERSHELL.

    Researchers have identified five distinct variants of GOVERSHELL, which provides attackers with remote command execution capabilities and uses scheduled tasks for persistence, indicating active and ongoing development.

    The malware variants show significant rewrites in their communication protocols and capabilities, shifting from C++ to Golang and employing different encryption methods.

    The assessment of LLM usage stems from an aggregation of evidence rather than a single data point, a finding later corroborated by an OpenAI report. A key indicator is the “hallucinations” and nonsensical details present in the phishing campaigns.

    UTA0388’s emails often contained fabricated entities, such as the “Copenhagen Governance Institute,” and used fake phone numbers with suspicious sequential patterns. The group also exhibited a consistent lack of coherence.

    For instance, a single email would sometimes contain three different personas across the sender name, email address, and signature block. Volexity observed emails sent to English-speaking targets with a Mandarin subject line and a German body, suggesting context-unaware automation.

    The targeting itself showed signs of automation without human review, as phishing emails were sent to non-existent addresses like first.last@<domain> scraped from public web pages.

    In some cases, archives contained superfluous “Easter eggs,” including pornographic images and audio recordings of Buddhist chants, which serve no operational purpose and would likely be avoided by a human operator trying to remain undetected.

    Volexity assesses with high confidence that UTA0388 operates in the interest of the Chinese state, based on its targeting profile focused on Asian geopolitical issues and technical artifacts, such as developer paths containing Simplified Chinese characters found within a GOVERSHELL sample.

    The constant and non-iterative rewriting of the malware’s network stack further supports the hypothesis of LLM assistance in code generation.

    While it is difficult to measure the ultimate success of these AI-powered campaigns, the ability to generate a high volume of tailored phishing content, even with its flaws, presents a significant threat.

    The activity demonstrates how threat actors are integrating AI to scale their operations, create more convincing lures, and accelerate malware development.

    The continued evolution of the GOVERSHELL backdoor suggests that UTA0388 remains an active and persistent threat, adapting its tradecraft for future campaigns.

    OpenAI has implemented a ban on ChatGPT accounts that were linked to hackers from China and North Korea who were attempting to use the platform for the development of malware.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶