• Open VSX, the extension marketplace used by VS Code forks such as Cursor and Windsurf, recently fixed a critical vulnerability in its newly introduced pre-publish scanning pipeline that could allow malicious extensions to bypass security checks and go live undetected. The issue, dubbed “Open Sesame,” stemmed from a fail-open condition in the scanning workflow. While […]

    The post Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The European Commission has confirmed a cybersecurity incident affecting its cloud-based infrastructure after attackers gained access to an Amazon Web Services (AWS) account hosting parts of the Europa.eu platform. According to an official statement, the compromised infrastructure supported the Commission’s public-facing web services. Despite the intrusion, authorities reported no disruption to the availability of Europa.eu […]

    The post European Commission Confirms Cyberattack After AWS Account Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Iran-linked Handala hackers breached FBI Chief Kash Patel’s Gmail, leaking photos and documents. Officials say no classified data was exposed.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Space Command aims to relocate around 200 people from Colorado to its new headquarters location in Alabama by the end of the year. 

    “I'm happy at the progress that we're making, and that progress will continue over the next couple of years as we work to get a significant portion of our staff there, even while the permanent headquarters is being built,” Gen. Stephen Whiting, who leads U.S. Space Command, told senators during a Senate Armed Services Committee hearing Thursday. 

    The command’s relocation has been a matter of hot political debate—President Donald Trump has pushed for what will be a 60-acre site in Huntsville, Ala., during both of his terms. The Biden administration in 2023 reversed the original decision to move the headquarters to Alabama, but Trump reversed it again in 2025.

    Right now, Space Command has a small, 20-person office in Redstone Arsenal, with plans to increase that number tenfold by year's end. 

    “By the end of this year, we are targeting that number to be closer to 200 people that will be working from Redstone, from our headquarters, of course. That will be paced with the delivery of interim facilities that are appropriate to the security classification level we need, and that we have all of the appropriate IT networks,” Whiting testified. 

    The command is updating existing facilities, with plans to open a top-secret facility that can accommodate up to 80 people in April, Whiting said. Then the plan is to start moving people who work at that classification level. 

    To hit that 200-person relocation target, the command is offering workers incentives.

    “We are offering relocation incentives for our workforce in Colorado to consider moving to Alabama,” Whiting said. “We also are offering retention incentives, because I need my workforce to stay with me in Colorado until their function is ready to move.” 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ShinyHunters leaves BreachForums, leaks data of 300,000 users, warns all active domains are fake, and threatens more leaks from forum backups.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The United States may need more Columbia-class submarines to break even with existing submarine nuclear capabilities in the aging Ohio-class fleet, Adm. Richard Correll, the head of U.S. Strategic Command, said Thursday. 

    “The existing capability we have includes 14 Ohio-class boats with 20 tubes. So that's 280 launch tubes. The program of record is a minimum of 12 Columbia with 16 tubes each, and that's 192. So that's 280 versus 192,” Correll told the Senate Armed Services Committee. 

    “Additional capacity and capability is very beneficial from my perspective. There's ongoing work within the department in terms of force sufficiency, and that work will inform any future budget decisions associated with Columbia. But if you just do the math for what we have and the program of record, I will continue to advocate for additional capability at sea in terms of the Columbia class.”

    The first Columbia-class submarine is about a year behind schedule, with expected delivery in 2028. The Navy has a maintenance plan to extend the life of Ohio class submarines so they can last until the Columbia submarines are built. 

    But at least one senator seems open to adding to the Columbia program.

    Correll’s response came after Sen. Tommy Tuberville, R-Ala., asked what STRATCOM would do if Congress could fund more Columbia-class submarines—16 instead of the 12 in the program of record. 

    “Submarines are the tip of the spear for our nuclear capabilities. The problem is we can’t seem to build them fast enough,” Tuberville said. “What flexibility and capability does STRATCOM gain if we were able to field 16 Columbia class submarines versus 12?”

    Senate Armed Services Committee Chairman Roger Wicker said the thrust of the question gets at how much better U.S. defenses would be “if we're able to reach the goal that he mentioned. And the answer is that we very much need to do that. Is that correct?”

    If Congress were to fund four more Columbia-class submarines, “that maximizes flexibility and options to present to the president should the need arise,” Correll said. 

    “The importance to our deterring capability, I can't overstate that—all three legs are vitally important. They complement each other, and the sum of the parts are much greater than the whole. For the SSBN, that assured second strike capability that's always at sea, always ready to respond, deters effectively. And I see that in the intel reporting record.” 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • President Donald Trump on Thursday signed an executive order targeting diversity, equity and inclusion programs at companies that are federal contractors.

    While contractors are already subject to anti-DEI directives that the president enacted at the start of his second term, Trump wrote that this new order is necessary because “some entities continue to engage in DEI activities and often attempt to conceal their efforts to do so.”

    Under the directive, agencies must ensure that contracts and subcontracts, within 30 days, include a clause that states the contractor:

    • Will not engage in DEI activities.
    • Agrees to provide information and reports to assess compliance. 
    • Acknowledges that noncompliance with the order could lead to the termination or suspension of the contract and the company being barred from future government contracts. 

    The order defines “racially discriminatory DEI activities” as “disparate treatment based on race or ethnicity in the recruitment, employment (e.g., hiring, promotions), contracting (e.g., vendor agreements), program participation or allocation or deployment of an entity’s resources.”

    While noting that racial discrimination in employment has been illegal for decades, Julia Judish, a special counsel at Pillsbury law firm, said that the inclusion of “recruitment” in the definition is an “about face” for federal contractors. 

    Government contractors had been required to implement affirmative action programs, but on the second day of his second term, Trump repealed an executive order from the 1960s that mandated such a requirement. That led to cuts at the Office of Federal Contract Compliance, a Labor Department agency that enforced the directive.

    “It’s the flip of what had been required of government contractors over decades,” Judish said. 

    She also predicted that the new order will create uncertainty for contractors. 

    “Does this mean that, if a government contractor participates in a career fair at a historically Black college or university, is that viewed as a racially discriminatory allocation or deployment of their resources in support of recruitment that is more likely to reach potential applicants based on race or ethnicity?” she said. “So there’s a lot of questions.” 

    The new directive also requires the Office of Management and Budget, in coordination with the Justice Department, assistant to the president for Domestic Policy and Equal Employment Opportunity Commission, to “identify economic sectors that pose a particular risk of entities engaging in racially discriminatory DEI activities based on current or past conduct and issue additional guidance to contracting agencies regarding best practices to ensure compliance with this order within such sectors.”

    Additionally, the order authorizes the Justice Department to sue contractors and subcontractors that violate these requirements and mandates changes to the Federal Acquisition Regulation in order to ensure the rules correspond with the new directive. 

    The second Trump administration has prioritized cutting employees and programs that officials determine perform work related to DEI. 

    For instance, the Interior Department this month reminded employees that they should report any suspected DEI activities and that doing so is considered to be a protected whistleblower activity.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A federal judge has issued a temporary injunction barring the federal government from enforcing its declaration that Anthropic is a supply-chain security risk.

    Judge Rita Lin in the U.S. District Court of Northern California is also blocking the government's enforcement of a presidential directive that all government agencies stop using the company’s artificial intelligence products.

    Lin cited several grounds in her Thursday ruling, which says the Defense Department’s declaration was retaliation for Anthropic exercising its First Amendment rights.

    DOD also violated Anthropic’s due-process rights by not giving the company advance notice or an opportunity to respond before the ban went into effect. The Pentagon also did not follow the procedures laid out in the federal law they cited to ban the company from federal work, Lin said.

    The judge also called DOD’s action “arbitrary and capricious” and contrary to the law.

    Anthropic has been working with the Defense Department since late 2024 through a partnership with Palantir Technologies. Since March 2025, Anthropic has also gone to market with a standalone product Claude Gov.

    The dispute emerged in the fall of 2025 when DOD pushed for unrestricted access to Claude for “all lawful uses.” Anthropic refused to remove two long standing restrictions – no mass surveillance of U.S. citizens and no lethal autonomous warfare.

    DOD wanted those restrictions lifted, but Anthropic refused. Negotiations were cordial and Anthropic offered to help DOD transition to another vendor, according to the judge’s ruling.

    But things went south in January, when Anthropic and DOD went public with the dispute. CEO Dario Amodei posted an essay that month talking about AI safety, and the company issued a statement on Feb. 26 on its position about how DOD should use AI.

    Within 24 hours, President Trump issued his government-wide ban on Truth Social and Defense Secretary Pete Hegseth designated Anthropic a supply chain risk.

    “Neither the President nor Secretary Hegseth cited any statutory authority for the Directives,” Lin wrote in her ruling.

    Anthropic worked for DOD for years and had gone through a lengthy national-security vetting process. The company received nothing but praise, the judge wrote.

    "The day after the designation was finalized—and before it was communicated to Anthropic—Under Secretary (Emil) Michael and Amodei cordially exchanged drafts of Anthropic's usage terms, with Under Secretary Michael writing to Amodei: 'After reviewing with our attorneys and seeing your last draft (thanks for being fast), I think we are very close here,'" the judge wrote.

    On the First Amendment question, Lin found that Anthropic's public statements about AI safety — including Amodei's essay and the company's public statement on its dispute with DOD — were protected speech on matters of public concern.

    Courts have long held that matters of public concern are at the core of First Amendment protections.

    The judge said the government's own words undermined its national-security argument. Trump called Anthropic a "radical left, woke company" and Hegseth attacked its "sanctimonious rhetoric" and "Silicon Valley ideology."

    Most tellingly, an internal DOD memo stated that Anthropic's risk level escalated because it was engaging in an "increasingly hostile manner through the press."

    "Punishing Anthropic for bringing public scrutiny to the government's contracting position is classic illegal First Amendment retaliation," Lin wrote.

    The injunction takes effect in seven days. That timeline gives the government until around April 2 to seek an emergency stay from the Ninth Circuit Court of Appeals, which it has indicated it will do.

    Meanwhile, a separate but related case challenging the supply chain designation under a different federal statute is already pending in the D.C. Circuit Court of Appeals. That means the legal battle over Anthropic's status as a government contractor is likely to play out on multiple fronts simultaneously.

    Anthropic’s battle with DOD and the Trump administration has drawn a variety of supporters, who have filed amicus briefs with the court.

    Among them are employees of its competitors Google and OpenAI. Microsoft also filed a brief as did several industry associations.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google fast-tracks post-quantum cryptography with a 2029 deadline as researchers warn quantum computers could break current encryption sooner than expected.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A pro-Iran hacker group claimed to have accessed FBI Director Kash Patel’s personal email and posted purported contents from the inbox online.

    Handala, which claimed responsibility in recent weeks for hacks against Stryker and Lockheed Martin in response to the Iran war, circulated images and documents online that they claimed to be from Patel’s email account. Many images include pictures of Patel in a personal capacity before becoming FBI director.

    The leaks appear to be authentic, according to a person familiar with the matter who requested anonymity because they weren’t authorized to publicly discuss details of the breach.

    The incident was first reported by Reuters. 

    “The FBI is aware of malicious actors targeting Director Patel’s personal email information, and we have taken all necessary steps to mitigate potential risks associated with this activity. The information in question is historical in nature and involves no government information,” the bureau said in a statement after this story published. 

    Handala said it carried out the intrusion after the FBI last week said it seized domains used by the group.

    “Today, once again, the world witnessed the collapse of America’s so-called security legends,” the group wrote on its website. “While the FBI proudly seized our domains and immediately announced a $10 million reward for the heads of Handala Hack members, we decided to respond to this ridiculous show in a way that will be remembered forever.”

    The breach is likely legitimate, according to a former U.S. official who said that administration officials’ personal email accounts are a frequent target of Iranian hackers.

    It would not be the first time that Iran-aligned hackers executed a “hack and leak” operation against U.S. targets. In 2024, the Trump campaign was accessed in an Iranian hack that exposed vetting documents for Vice President JD Vance.

    Editor’s note: This story has been updated to include remarks from a former U.S. official and the FBI.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶