• As the Army works to gather and organize data to support battlefield decisions, it has created a task force to help with small, short-term problems—and in the longer term, to shape the service’s overall approach to data management.

    The Army Data Operations Center went live on April 3, service officials told reporters on Tuesday, and so far its small team of civilian and soldier data and software engineers have received seven requests from different organizations to help deconflict.

    “It used to be about firepower, but it isn't really about that anymore,” said Lt. Gen. Jeth Rey, the Army’s chief of staff for command, control, communications, cyber operations, and network architecture. “It's really about who can get the data to make decisions faster, to dominate.”

    The task force might help, say, to get a partner force’s data flowing into the Army’s next-generation command-and-control platform so that a U.S. commander can compare what the two militaries are seeing on one screen. 

    The ADOC is organized into a “warfighter engagement cell” that that triages requests, then feeds them to data engineers at the “finish cell” to come up with a solution, who then runs that by the “data management cell” to figure out what kinds of policies need to be created or modified to fix the issue in the long-term. 

    “Those things are actually a lot more difficult than what you think, to be able to do—because it might be different cloud environments, it might be different [areas of operations], data owners— and you need to go through all the access requests,” said Brig. Gen. Michael kaloostian, who heads the Command and Control Future Capability Directorate at Army Transformation

    and Training Command.

    ADOC has so far been fielding requests from units in training environments, he said, but it’s technically open to responding to troops in combat, and will prioritize those tickets.

    “We haven't received anything yet to support those operations, but if there were to be a request, we would surge on that and prioritize that appropriately,” he said.

    For the first 180 days, ADOC will respond to requests and track trends to give the Army feedback on which fixes can be incorporated into training or standard operation and whether the help-desk model is necessarily in the longer term. 

    “The Army will make informed decisions about what the structure should be and whether a centralized capability in the future is even needed, right?” Kaloostian said. “We just aren't mature enough as an Army right now to really, truly become data-centric. We need something that can aid the continuous transition and transformation of the Army to a data-centric force.”

    It’s possible that the future looks like a centralized operations center that deals with the “higher-level heavy lifting” of organizing different data formats from their respective systems, so that soldiers on the ground aren’t having to sort through it themselves, said Lt. Gen. Chris Eubank, who heads U.S. Army Cyber Command.

    “So I think the cyberspace domain is evolving at such a rapid pace that the organizations involved in that domain must evolve as well, but I think it's a necessary thing right now,” he added. “And the hope is we're creating soldiers that are data-smart more and more, and the heavier lifting is done inside of a central organization, if need be.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Army has picked at least two finalists to take over the service’s entry-level helicopter training program, despite Congressional pushback on the plan last year. Service officials have said they plan to choose a winner by September.

    Bell and M1 Support Services both confirmed in press releases this week that they were selected to move to the fourth and final stage of the competition.

    Another competitor, Lockheed Martin, was not chosen to move on, a company spokesperson confirmed to Defense One.The Army did not immediately respond to a request for comment asking whether any other companies were selected. 

    Last month, it was reported that AAR Corp was also in the running for the competition. The Illinois-based company did not immediately respond to requests for comment.

    Finalists will be asked to demonstrate how they could execute the service’s Initial Entry Rotary Wing training program more affordably and efficiently. 

    Funding for the effort to shift the in-house school to a contractor-owned and -operated model, dubbed Flight School Next, was paused by lawmakers in the most recent National Defense Authorization Act. The provision asked for a detailed report on the one-year pilot program and for Army Secretary Dan Driscoll to brief Congress on the cost-effectiveness and rationale before Congress would release funds for the contract.

    An Army spokesperson did not immediately return a request for comment on Tuesday asking whether the service provided Congress with the results and briefing. 

    Despite the pushback and funding uncertainty, the competition is still marching on. 

    Bell is working with DigiFlight, Delaware Resource Group (DRG), V2X, Alpha 1 Aerospace, Semper Fly and TRU Simulation, the company said in a news release. The team’s bid is centered around Bell’s 505 helicopter as the trainer.

    “Bell is proud to be selected for the fourth phase of the Flight School Next competition alongside our teammates,” John Novalis II, the company’s Flight School Next strategic director said in a press release. “Making it to this stage proves that Bell’s solution is strong and we look forward to demonstrating our ability to execute.”

    M1’s team consists of General Dynamics Information Technology, Robinson Helicopter Company, Quantum Helicopters, and the University of North Dakota Aerospace Foundation. Its offering includes Robinson Helicopters’ R66 trainer. 

    A Robinson spokesperson confirmed to Defense One the company is working with multiple prime contractors for a Flight School Next offering.

    “We are honored to advance to Phase IV,” George Krivo, M1’s CEO and chairman, said in a news release. “In this next phase, Team M1 will demonstrate our comprehensive, innovation-rich solution to produce more proficient Army Aviators on time and on budget.”

    The Bell 505 and R66, both single-engine aircraft, are both departures from the Army’s current training helicopter, Airbus’ twin-engine UH-72 Lakota, which has been criticized by service leaders as being too expensive and restrictive for teaching aviation basics. An Airbus spokesperson referred questions to the Army when asked if the company was moving ahead in the competition.

    A call-for-solutions document issued late last year says that the winner of the Flight School Next contract would produce 800 to 1,500 Army aviators annually for 26 years, with an award expected by September.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Iran-aligned hackers have exploited and disrupted operational technology control systems embedded in U.S. critical infrastructure, according to a federal advisory issued Tuesday.

    “The authoring agencies assess a group of Iranian-affiliated advanced persistent threat (APT) actors is conducting this activity to cause disruptive effects within the United States.” the advisory reads. “The group has targeted devices spanning multiple U.S. critical infrastructure sectors, including Government Services and Facilities (to include local municipalities), Water and Wastewater Systems (WWS), and Energy Sectors.”

    The assessment was signed by the Cybersecurity and Infrastructure Security Agency, FBI, NSA, EPA, the Department of Energy, and U.S. Cyber Command’s Cyber National Mission Force.

    It says hackers are especially targeting Rockwell Automation's Allen-Bradley line of programmable logic controllers, or PLCs, which monitor and automate the equipment used in industrial processes such as water treatment, power generation, and manufacturing.

    It says that the hackers have manipulated data on human-machine interfaces and on supervisory control and data acquisition, or SCADA, displays, and had harmful interactions with project files.

    The advisory is the latest signal that Iran-aligned hacker groups have impeded U.S. systems since the United States and Israel went to war against Iran on Feb. 28. 

    It comes after an apparent Tehran-backed hacker group carried out a cyberattack against medical technology giant Stryker last month, which wiped employees’ phones and prevented workers from accessing their computers.

    A request for comment sent to Rockwell Automation’s media relations email bounced back.

    Pro-Iran hackers have made a habit of targeting any computer systems tied to nations deemed foreign adversaries by Tehran, especially the U.S. and Israel. In late 2023, amid the Israel-Hamas war, one hacker group defaced the interfaces of water treatment systems in Pennsylvania, which had Israel-made Unitronics equipment built inside.

    In 2020, Rockwell Automation acquired Israel-based Avnet Data Security, aiming to bolster the cyber posture of its industrial control systems and operational technology.

    The assessment urged organizations to keep PLCs off the open internet, review logs for suspicious activity and lock down affected Rockwell devices to prevent unauthorized access. Unsecured internet-connected operational technology can expose industrial systems to remote access, giving attackers a pathway to disrupt or manipulate functions.

    The Iran war has been widely expected to test the strength of U.S. cyberdefenses, and experts have warned that exposed devices would be a potential target for pro-Iran hackers.

    President Donald Trump escalated his threats against Tehran on Tuesday, saying a “whole civilization will die tonight” if Iran doesn’t open the Strait of Hormuz by an 8 p.m. ET deadline. 

    Trump has promised to attack “every bridge” and power station in the country if a deal isn’t reached. Iran has promised a “devastating” response if such an attack occurs. Any sharp escalation could heighten the risk of retaliatory cyberattacks.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ever since President Donald Trump signed an executive order in September authorizing the Defense Department to go by the “secondary title” of War Department, the Pentagon has been working to change its signage, signature blocks, and as many instances of "Defense" as possible. But that stops with the Defense Criminal Investigative Service and its official filings, because “War Department” still isn’t a legal name.

    Though DoD personnel and defense contractors have been compelled to use “War Department,” only Congress has the authority to officially change the department’s name. Lawmakers have made no moves to do so; most recently, they passed up the opportunity in the latest defense authorization bill. So where legal proceedings are concerned, DoD remains DoD, according to a memo for the department’s inspector general office signed April 1 by the assistant inspector general for legislative and communications.

    The IG’s main concern appears to be that using the unofficial name in legal documents could undermine a criminal case.

    “While the ‘Department of War’ label may serve a rhetorical or symbolic purpose, its introduction into official contexts has generated internal confusion and compelled legal safeguards,” a DCIS contractor, who asked not to be identified to prevent retaliation from his employer, told Defense One.

    While the memo clears the IG to rebrand itself as the "Department of War Office of the Inspector General," the use of that nickname will be limited.

    “For DCIS in particular, the stakes are high: even minor deviations from statutory identity in criminal proceedings could undermine the integrity of cases aimed at holding individuals accountable for fraud, waste, and abuse within the government,” the contractor said. 

    The memo also states that the DoD Hotline, the anonymous tip line for fraud, waste and abuse allegations, will keep its name. Nor will DoW be used in any memoranda of understanding or agreement with outside organizations, to prevent misunderstandings.

    “The rebranding effort introduces unnecessary friction into interagency coordination, congressional oversight, and international engagements, all of which rely on the legally established identity of the Department of Defense,” the contractor said. “The internal guidance’s repeated emphasis on disclaimers, footnotes, and restricted usage underscores the extent to which legal and policy officials are attempting to contain that risk.”

    And though Defense Secretary Pete Hegseth personally replaced the bronze Department of Defense sign at the Pentagon’s river entrance in November, the memo explicitly says that no existing OIG office signage should be removed and budgeted funds can’t be used to buy DoW signs. 

    The Pentagon did not respond to a request for comment about legally safeguarding investigations, or whether there is a push to convince lawmakers to make the War Department legal. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • REF1695 hackers spread Monero mining malware via fake non-profit installers, using stealth tactics to evade detection and hijack systems for profit.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers linked to Russia’s military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks without deploying any malicious software or code.

    Microsoft said in a blog post today it identified more than 200 organizations and 5,000 consumer devices that were caught up in a stealthy but remarkably simple spying network built by a Russia-backed threat actor known as “Forest Blizzard.”

    How targeted DNS requests were redirected at the router. Image: Black Lotus Labs.

    Also known as APT28 and Fancy Bear, Forest Blizzard is attributed to the military intelligence units within Russia’s General Staff Main Intelligence Directorate (GRU). APT 28 famously compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.

    Researchers at Black Lotus Labs, a security division of the Internet backbone provider Lumen, found that at the peak of its activity in December 2025, Forest Blizzard’s surveillance dragnet ensnared more than 18,000 Internet routers that were mostly unsupported, end-of-life routers, or else far behind on security updates. A new report from Lumen says the hackers primarily targeted government agencies—including ministries of foreign affairs, law enforcement, and third-party email providers.

    Black Lotus Security Engineer Ryan English said the GRU hackers did not need to install malware on the targeted routers, which were mainly older Mikrotik and TP-Link devices marketed to the Small Office/Home Office (SOHO) market. Instead, they used known vulnerabilities to modify the Domain Name System (DNS) settings of the routers to include DNS servers controlled by the hackers.

    As the U.K.’s National Cyber Security Centre (NCSC) notes in a new advisory detailing how Russian cyber actors have been compromising routers, DNS is what allows individuals to reach websites by typing familiar addresses, instead of associated IP addresses. In a DNS hijacking attack, bad actors interfere with this process to covertly send users to malicious websites designed to steal login details or other sensitive information.

    English said the routers attacked by Forest Blizzard were reconfigured to use DNS servers that pointed to a handful of virtual private servers controlled by the attackers. Importantly, the attackers could then propagate their malicious DNS settings to all users on the local network, and from that point forward intercept any OAuth authentication tokens transmitted by those users.

    DNS hijacking through router compromise. Image: Microsoft.

    Because those tokens are typically transmitted only after the user has successfully logged in and gone through multi-factor authentication, the attackers could gain direct access to victim accounts without ever having to phish each user’s credentials and/or one-time codes.

    “Everyone is looking for some sophisticated malware to drop something on your mobile devices or something,” English said. “These guys didn’t use malware. They did this in an old-school, graybeard way that isn’t really sexy but it gets the job done.”

    Microsoft refers to the Forest Blizzard activity as using DNS hijacking “to support post-compromise adversary-in-the-middle (AiTM) attacks on Transport Layer Security (TLS) connections against Microsoft Outlook on the web domains.” The software giant said while targeting SOHO devices isn’t a new tactic, this is the first time Microsoft has seen Forest Blizzard using “DNS hijacking at scale to support AiTM of TLS connections after exploiting edge devices.”

    Black Lotus Labs engineer Danny Adamitis said it will be interesting to see how Forest Blizzard reacts to today’s flurry of attention to their espionage operation, noting that the group immediately switched up its tactics in response to a similar NCSC report (PDF) in August 2025. At the time, Forest Blizzard was using malware to control a far more targeted and smaller group of compromised routers. But Adamitis said the day after the NCSC report, the group quickly ditched the malware approach in favor of mass-altering the DNS settings on thousands of vulnerable routers.

    “Before the last NCSC report came out they used this capability in very limited instances,” Adamitis told KrebsOnSecurity. “After the report was released they implemented the capability in a more systemic fashion and used it to target everything that was vulnerable.”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025. The large-scale exploitation campaign has been codenamed 

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GrafanaGhost is a critical vulnerability in Grafana’s AI components that uses indirect prompt injection and protocol-relative URL bypasses to exfiltrate data.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to light in July 2024. “

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A team of AI-driven vulnerability hunting agents directed by security researcher Asim Viladi Oglu Manizada has discovered two critical security flaws in CUPS, the standard printing system for Linux and Unix-like operating systems. When chained together, these vulnerabilities allow an unauthenticated remote attacker to gain unprivileged remote code execution and eventually escalate their access to […]

    The post CUPS Vulnerabilities Could Allow Remote Attackers to Achieve Root-Level Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶