• The United States has “a tight time window to adapt” to the “civilizational" challenge of adapting to AI, the former head of the Defense Department’s Office of Net Assessment, often referred to as the “Pentagon’s Think Tank,” told Defense One. He’s joining AI company Anthropic as a “strategist-in-residence” to lead analysis of how AI is affecting U.S. institutions and competition with China, the company announced Friday.

    James Baker led ONA from 2015 to 2025, when it was temporarily closed by the Trump administration. As the director he advised defense secretaries and national security advisors on the long-term effects of emerging technology on national security, and prior to that role served on the Joint Staff and in other advisory roles.

    For decades, ONA played an instrumental role in helping the U.S. military evolve to match broader social, economic, environmental and technological trends. 

    Andrew Marshall, a policy strategist in the Nixon Administration, established the Office of Net Assessment in 1973 to take a data-driven, “system-of-systems” approach to understanding future trends, which looked across areas of human activity to better forecast how they might interrelate, such as technology development on military affairs or labor. The office forecast how information technology would greatly increase the speed of warfare and the availability and precision of new weapons, including cyber and electromagnetic effects. These ideas prompted large-scale rethinking of force structure and underscored the need to accelerate acquisition reform across the military.

    In its last decade, ONA devoted an increasing amount of time to the implications of accelerating artificial intelligence, especially in the context of Cold War institutions that Congress has been slow to adapt. A 2016 summary study, which formed the basis for an unclassified 2017 Belfer Center examination, saw a “Cambrian explosion” in robotics and artificial intelligence that would make warfare cheaper and faster, and reduce the advantage of expensive investments in so-called "exquisite platforms” like $90 million dollar jets.

    That trend is playing out today in Ukraine, where the smaller force is using drones to decimate expensive Russian naval and air defense assets.

    But Baker said the national security effects of AI stretch far beyond the military. Only by appreciating the vulnerability of all institutions, including the Defense Department, will society be able to adapt to the changes that are coming.

    “We aren't spending enough time thinking about the implications of recursive self-improvement,” he said, meaning intelligent systems that improve themselves far faster than their creators anticipate. “The greatest risk is the long-term viability of present institutions in war and in peace. That’s one of the questions I came to Anthropic to work on. It’s a multi-decade structural—even civilizational—problem.”

    The Defense Department shuttered the ONA office last March, claiming to refocus its personnel on what a spokesperson then called another step in a series of cuts to Defense Department basic research beyond applications for specific weapons and technologies. A Pentagon spokesperson said at the time that the reorganization aimed to allow the Defense Department to better address “pressing national security challenges,” but offered no further explanation. In October, the department reinstated a downgraded version of ONA.

    This March, the White House designated Anthropic a supply-chain risk, due to a disagreement between current Defense Department leadership and the company over safe deployment of Anthropic models.

    In April, Anthropic announced that it would limit the release of a new AI tool dubbed Mythos to a handful of federal agencies and corporate partners, in order to help the company discover vulnerabilities they might otherwise have overlooked. The number of new vulnerabilities logged in the National Vulnerability Database nearly doubled this month.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – May. 1, 2026

    Listen to the podcast

    A quarter-century old article in The Wall Street Journal reported in 1998 that Serge Humpich, a 37-year-old (at the time) programmer approached the French association of bank-card issuers with the news that he had cracked the mathematical algorithm that had served as the main line of defense against fraud for the better part of a decade.

    Humpich thought that the group’s 175 financial institutions, which in 2000 had almost 38 million cards in circulation, would be grateful to him for pointing out the vulnerability of their system. Through an intermediary, he proposed a contract that valued those services at 200 million French francs (30.5 million euros).

    But things didn’t work out so simply. The bank-card group called the police, who began intercepting Mr. Humpich’s communications. They detained him in Sep. 1998, after a special team descended on the enormous farmhouse in Tournan where Mr. Humpich lived alone.



    In Feb. 1999, Humpich got a 10-month suspended sentence for piracy and “fraudulent system access.” Along the way, he lost his job writing software for financial traders; he said that his employer got cold feet about having a headline-making hacker on his payroll.

    And that wasn’t the end of it. In Mar. 2000, the secret bank-card algorithm appeared anonymously posted on a French cryptology Internet bulletin board. The storm ignited again, with the security of the nation’s electronic-payment system called into question. And so the understated Mr. Humpich was thrown back into the spotlight.

    In a new Cybercrime Magazine Podcast episode, Humpich joins host Heather Engel to discuss his experience, the ethical hacking landscape over 25 years later, and more.

    Listen to the Podcast Episode


    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Ethical Hacking Gone Wrong In 1999: French Software Engineer Looks Back appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly uncovered cyber campaign dubbed “EtherRAT” is raising concerns across enterprise environments, as attackers combine SEO poisoning, GitHub abuse, and blockchain-based infrastructure to target high-privilege IT professionals. Instead of broadly targeting users, the attackers deliberately impersonate trusted administrative tools, increasing the likelihood that victims already have elevated system access. The attack chain begins with […]

    The post EtherRAT Uses SEO Poisoning and Fake GitHub Pages to Target Enterprise Admins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical cPanel vulnerability lets attackers bypass login and gain root access, with active exploitation reported before patches were released.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The managed security services market is projected to grow from $38.31 billion in 2025 to $69.16 billion by 2030[1], with cybersecurity being the fastest-growing sector[2]. Despite this opportunity, many MSPs leave revenue on the table because their go-to-market strategy fails to connect technical expertise with business needs. This execution gap is where most deals stall. MSPs often focus on

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered Android spyware platform is raising concerns among cybersecurity researchers by introducing a business model that allows buyers to rebrand and resell surveillance malware as their own product. Buyers can subscribe to the service, customize branding, and launch their own spyware operation with minimal effort. KidsProtect presents itself as a parental monitoring app, […]

    The post New Android Spyware Platform Enables Rebranding and Resale appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Department of Justice (DoJ) on Thursday announced the sentencing of two cybersecurity professionals to four years each in prison for their role in facilitating BlackCat ransomware attacks in 2023. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were accused of deploying the ransomware against multiple victims located throughout the U.S. between April and December 2023.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence. The activity has been attributed to the GitHub account “BufferZoneCorp,” which has published a set of repositories that are associated with malicious Ruby gems and Go modules. As of

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Attackers are increasingly combining QR codes, fake CAPTCHA gates, and ClickFix-style tricks to steal credentials at scale, even as major phishing-as-a-service (PhaaS) platforms face disruption. These tactics shift risk from traditional malware attachments to highly convincing, hosted phishing flows that are harder for both users and email filters to spot. Across this volume, 78% of […]

    The post CAPTCHA and ClickFix Abuse Fuels Credential Theft Surge appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The developers of the Exim mail server have officially rolled out version 4.99.2 to address four newly discovered security vulnerabilities. This critical update patches multiple software flaws that could allow attackers to crash server connections, corrupt memory heaps, or potentially leak sensitive system data. Mail server administrators are strongly advised to apply these fixes immediately […]

    The post Multiple Exim Mail Server Vulnerabilities Could Trigger Crashes via Malicious DNS Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶