• A critical vulnerability nicknamed “BitPixie” in Windows Boot Manager allows attackers to bypass BitLocker drive encryption and escalate privileges, security researchers have revealed. The flaw exploits a weakness in the PXE soft reboot feature that fails to properly clear encryption keys from system memory, affecting systems from 2005 to 2022. How the BitPixie Attack Works […]

    The post BitPixie Windows Boot Manager Flaw Lets Hackers Escalate Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability in the Linux kernel’s KSMBD implementation has been discovered that allows remote attackers to completely exhaust server connection resources through a simple denial-of-service attack. The flaw, tracked as CVE-2025-38501 and dubbed “KSMBDrain,” enables malicious actors to render SMB services unavailable by consuming all available connections. How the Attack Works The vulnerability exploits […]

    The post Linux Kernel KSMBD Flaw Lets Remote Attackers Drain Server Resources appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft’s Digital Crimes Unit said it teamed up with Cloudflare to coordinate the seizure of 338 domains used by RaccoonO365, a financially motivated threat group that was behind a phishing-as-a-service (Phaas) toolkit used to steal more than 5,000 Microsoft 365 credentials from 94 countries since July 2024. “Using a court order granted by the Southern District of New York, the DCU seized 338

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Decades-old defense contractors are leaning into the Pentagon’s new focus on startups, entwining themselves with emerging companies that have the technologies or even the contracts they seek.

    “We're making bets in advance on specific capabilities and then going back to the market to say, ‘Who are the founders, and who are taking novel approaches to building something that is unique and different and can be applied within a military context?’” said Brian McCarthy, Booz Allen Hamilton’s managing partner of ventures.

    The trend reflects the Pentagon’s new urgency—after years of pleading by commanders, lawmakers, and even defense officials—to expand the military’s industrial base and bring in more tech companies. A series of recent directives from Defense Secretary Pete Hegseth and other administration officials have prodded the Pentagon to more aggressively pursue commercial technologies, enable lower-level commanders to make their own purchases, and to use simpler contracting methods that are friendlier to would-be contractors.

    That has caused a shift in strategy for firms like Booz Allen Hamilton, which was founded in 1914 and began work for the U.S. Air Force in 1947. In July, the company announced it was tripling its plans to invest in newer firms to $300 million.

    Company executives said they are not trying to mimic Silicon Valley venture firms, but to invest in new defense-relevant technologies as well as new companies.

    One of those companies is Firestorm Labs, which aims to enable the additive manufacturing of drones in “the hardest conditions in the world: Taiwan, etc.,” McCarthy said. “They're putting all of their building and printing all of their drones on location in a skiff-like box, which is what the military is ordering. So you have no supply-chain issues.’”

    Booz is also looking at space-based services such as autonomous navigation for satellites via a company called Starfish. McCarthy said his company is looking toward the space market of tomorrow, diversified far beyond today’s handful of players like SpaceX and Blue Origin.

    “There's going to be hundreds, if not thousands, of these launched over the next couple of years,” he said.

    Northrop Grumman, meanwhile, is also seeking to broaden its appeal to newer companies. It has a startup investor fund, and in June it launched an ecosystem for testing and developing autonomous technologies. 

    The Beacon ecosystem is intended to give “third-party partners an opportunity to test new autonomous solutions with exposure to industry leaders who can scale them,” according to a release.

    What does that mean? In a practical sense, it means access to the company’s 437 Vanguard plane, which can toggle between manned and unmanned operation. The goal is to enable companies working on AI pilots to test how their software performs within different mission focus areas, said Tom Jones, corporate vice president and president of Northrop Grumman’s Aeronautics Systems sector.

    “We take care of the flight operations, we take care of the safety and airworthiness to allow this capability, and we turn them loose on our computers to write software at a pace” that can be safely tested, Jones said, adding that the company aims to announce new flight demonstrations with partners later this year.

    Even established Silicon Valley firms are getting into the game. In 2023, Andreessen Horowitz—an early investor in Airbnb, Lyft, and Twitter—stood up an “American Dynamism” fund aimed at government contracts. 

    On a Monday call with reporters, officials outlined a lobbying effort to enshrine a Pentagon preference for commercial technology into law. Bolstered by Hegseth’s March memo to that effect, the company has managed to get the preference into the Senate version of the 2026 defense authorization act. The company also wants to change the “past performer” preference that gives companies that have executed federal contracts an advantage over rookies.

    Matt Cronin, a senior advisor at Andreessen Horowitz, said the past-performer preference keeps innovative companies from competing for awards they could otherwise win. One such company, he said, “chose not to bid on those contracts even though they offer a superior product. We'd argue things also objectively can be shown to be the case simply because the unbelievable level of bureaucracy and compliance burden is so high it's not worth their time.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Pentagon aims to get AI tools to its entire workforce next year, the department's chief technical officer said one month after being given control of its main AI office.

    “We want to have an AI capability on every desktop — 3 million desktops — in six or nine months,” Emil Michael, defense undersecretary for research and engineering, said at a Politico event on Tuesday. “We want to have it focus on applications for corporate use cases like efficiency, like you would use in your own company…for intelligence and for warfighting.”

    Four weeks ago, the Chief Digital and Artificial Intelligence Office was demoted from reporting to Deputy Defense Secretary Stephen Feinberg to Michael, a subordinate.

    Michael said CDAO will become a research body like the Defense Advanced Research Projects Agency and Missile Defense Agency. He said the change is meant to boost research and engineering into AI for the military, but not reduce its efforts to deploy AI and make innovations.

    “To add AI to that portfolio means it gets a lot of muscle to it,” he said. “So I'm spending at least a third of my time—maybe half—rethinking how the AI-deployment strategy is going to be at DOD.”

    He said applications would emerge from the CDAO and related agencies that will be tailored to corporate workloads.

    The Pentagon created the CDAO in 2022 to advance the agency’s AI efforts and look into defense applications for emerging technologies. The office's restructuring earlier this year garnered attention. Job cuts within the office added another layer of concern, with reports estimating a 60% reduction in the CDAO workforce.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Newark, New Jersey, United States, September 16th, 2025, CyberNewsWire The OpenSSL Conference 2025 will take place on October 7 – 9 in Prague. The program will bring together lawyers, regulators, developers, and entrepreneurs to discuss security and privacy in a global context. Conference starts in 3 weeks. [REGISTRATION AVAILABLE HERE]  Conference Contact Details The OpenSSL Conference team […]

    The post OpenSSL Conference 2025: Just 21 Days Until It Begins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Newark, New Jersey, United States, September 16th, 2025, CyberNewsWire

    The OpenSSL Conference 2025 will take place on October 7 – 9 in Prague. The program will bring together lawyers, regulators, developers, and entrepreneurs to discuss security and privacy in a global context.

    • Opportunities to meet the people behind the OpenSSL LibraryBouncy Castle, and cryptlib projects.
    • Sessions with compliance leaders, policymakers, and certification experts.
    • Networking forums to connect with partners, mentors, contributors, or co-founders.
    • Discussions with project maintainers: challenge decisions, ask questions, and shape the future.
    • Exchanges where technical, commercial, and ethical perspectives collide.
    • Presentations on regulatory obligations to post-quantum cryptography.
    • Talks addressing past, present, and future security challenges.
    • Networking activities with fellow participants.

    Conference starts in 3 weeks.

    [REGISTRATION AVAILABLE HERE] 

    Conference Contact Details

    The OpenSSL Conference team can be reached at info@openssl-conference.org

    About The OpenSSL Corporation

    The OpenSSL Corporation is a global leader in cryptographic solutions, specializing in developing and maintaining the OpenSSL Library – an essential tool for secure digital communications. The OpenSSL Corporation provides a range of services tailored to assist businesses of all sizes to ensure the secure and efficient implementation of OpenSSL solutions. The OpenSSL Corporation also supports projects aligned with its Mission and Values by providing infrastructure, resources, expert advice, and engagement through advisory committees, particularly in the commercial sector. Collaboration among these projects fosters innovation, enhances security standards, and effectively addresses common challenges, benefiting all our communities.

    Contact

    MarCom Manager
    Hana Andersen
    OpenSSL Software Services
    hana@openssl.org

    The post 3 Weeks Left Until the Start of the OpenSSL Conference 2025 appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The rise of large language models (LLMs) has revolutionized how we interact with technology, but their true potential has always been limited by their inability to interact with the real world. LLMs are trained on vast, static datasets, meaning they have no direct access to real-time information or the ability to perform actions in external […]

    The post Top 10 Best MCP (Model Context Protocol) Servers in 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Luxury fashion company Kering has confirmed a data exfiltration incident in which threat actor Shiny Hunters accessed private customer records for Gucci, Balenciaga, and Alexander McQueen.

    The breach, detected in June but occurring in April, exposed personally identifiable information (PII) for an estimated 7.4 million unique email addresses.

    Key Takeaways
    1. PII and spend data of ~7.4 M luxury-brand customers stolen.
    2. High-value shoppers face elevated phishing and SIM-swap risks.
    3. Kering notified regulators/customers, refused ransom.

    Massive Data Exfiltration 

    According to Kering’s statement, the attacker gained temporary unauthorized access via compromised internal credentials—likely harvested through a phishing campaign targeting Salesforce SSO portals. 

    The stolen dataset contains:

    • Email
    • Full name
    • Phone number
    • Shipping address
    • Total sales

    No PCI-DSS-regulated data, such as credit card numbers or bank account details, was exfiltrated. Instead, the files include names, email addresses, phone numbers, shipping addresses, and a “Total Sales” field indicating each customer’s cumulative spending. 

    Analysis of a proof-of-concept sample revealed spend tiers ranging from $10,000 to $86,000 per individual, heightening concerns over targeted whaling and spear-phishing.

    Kering has notified relevant data protection authorities under GDPR Article 33 and communicated directly with affected customers via email. 

    Under EU regulations, firms need only publicly disclose breaches if the incident poses a high risk to data subjects—Kering maintains its direct notification obligations have been met.

    Shiny Hunters’ Ransom Demands 

    BBC reports that the attacker, self-identified as Shiny Hunters, claimed to have negotiated a ransom in Bitcoin (BTC) with Kering beginning in June via Telegram. 

    Kering denies any paid negotiations and confirms adherence to law-enforcement guidance to refuse ransom payments.

    In parallel, Google’s Threat Analysis Group attributes a similar campaign tracked as UNC6040 to Shiny Hunters, noting exploitation of stolen API tokens and misuse of OAuth scopes to harvest credentials from other major firms. 

    This pattern underscores evolving TTPs (Tactics, Techniques, and Procedures), including:

    • Credential theft via social engineering
    • Abuse of third-party CRM integrations
    • Exfiltration through encrypted channels 

    Security experts warn that leaked PII combined with customer spend profiles could facilitate secondary intrusions—such as account takeover or SIM swapping, especially against high-value targets.

    Victims should assume scammers may impersonate legitimate organizations using stolen PII. Recommended mitigations include:

    • Enable multi-factor authentication (MFA) on all accounts.
    • Use unique, randomly generated passwords (e.g., passphrases of three random words).
    • Monitor credit reports and set up alerts for suspicious activity.

    The NCSC advises resetting passwords and reviewing account recovery settings for all email and e-commerce profiles. Remaining vigilant against unsolicited calls or emails demanding urgent action can help thwart follow-on fraud.

    Free live webinar on new malware tactics from our analysts! Learn advanced detection techniques -> Register for Free

    The post Hackers Stolen Millions of Users Personal Data from Gucci, Balenciaga and Alexander McQueen Stores appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A second Russian drone incursion led NATO to scramble aircraft on Friday, the same day the alliance announced a new quick-response effort, officials said Monday. 

    A Rafale jet and a Polish helicopter responded to a drone over Romania on Sept. 12, marking the first action of the new Eastern Sentry effort, a press release said. 

    The effort was unveiled by U.S. Air Force Gen. Alexus Grynkewich, NATO’s Supreme Allied Commander Europe.

    “Although the immediacy of our focus is on Poland, this situation transcends the borders of one nation. What affects one ally affects us all. This is an issue that impacts the entire Alliance, and we will treat it as such,” Grynkewich said at a Friday press conference..

    Grynkewich said Britain, Denmark, France, and Germany had already deployed forces as part of the effort.  He described the initiative as a “comprehensive and integrated approach” that goes beyond the case-by-case “individual air policing actions” of NATO’s previous air-defense posture.

    The move follows Poland’s Sept. 9 report of 19 Russian drones crossing its territory. Poland and other NATO members responded by dispatching a variety of aircraft, including F-35 and F-16 jets and Mi-24, Mi-17, and Black Hawk helicopters. The alliance aircraft shot down several of the drones. 

    “Clearly, with the number they came across the border, it’s time to take a fresh look at this,” Grynkewich said.

    The new activity reflects an understanding of Russia’s broader drone-warfare tactics, a NATO official told Defense One on background.

    “If we look at how Russia is using some of those things in Ukraine, what do you normally see follow that large concentration of drones? What are some other things we’ve seen globally with respect to drone use? We’ve seen drones launched from ships as well as land,” the official said. 

    They said Eastern Sentry is meant not just to respond to drones and other air threats, but to a range of potential Russia escalations.

    Grynkewich met Monday with all of his domain commanders, they said. 

    “It doesn’t just impact Allied Air Command, and it doesn’t just impact Allied Joint Force Command Brunssum, which leads integrated land command. We’re looking at this holistically along the eastern front,” they said.

    In the coming weeks, NATO will also deploy of new counter-drone technologies. The official said more details would follow but pointed to Project Flytrap, a series of U.S. Army Europe and Africa experiments—with the United Kingdom—that employ counter-drone systems developed from Ukraine’s battlefield experience, including acoustic sensing.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶