• Russian law enforcement agencies have successfully apprehended the suspected administrator of LeakBase, a prominent international cybercrime forum. The arrest, executed by officers from the Russian Ministry of Internal Affairs (MVD) alongside regional security services in Rostov, marks a significant disruption to the global underground trade of stolen data. The suspect, a resident of Taganrog, is […]

    The post LeakBase Forum Admin Arrested by Russian Authorities in Global Cybercrime Operation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. “Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data,” Sansec said in a report published this week. The attack,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Aqua Security’s vulnerability scanner, Trivy, suffered a sophisticated CI/CD supply chain compromise. The threat actor, identified as TeamPCP, leveraged prior incomplete remediation to inject credential-stealing malware into official releases. This incident, tracked as CVE-2026-33634, successfully weaponized a trusted security tool against the organizations relying on it to stay safe. This visualizes the attack propagation timeline […]

    The post Microsoft Unveils New Guidance to Detect and Defend Against Trivy Supply Chain Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A large-scale phishing campaign is actively targeting developers on GitHub by abusing the platform’s Discussions feature to distribute fake Visual Studio Code (VS Code) security alerts. The campaign appears highly coordinated, with thousands of near-identical posts discovered across multiple repositories, indicating automated mass exploitation rather than isolated abuse. Attackers are creating GitHub Discussions with alarming […]

    The post Fake VS Code Security Alerts on GitHub Spread Malware in Massive Phishing Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has released critical security updates to address a maximum-severity vulnerability affecting its Secure Firewall Management Center (FMC) Software. Tracked under the identifier CVE-2026-20131, this flaw carries a perfect CVSS base score of 10.0 and allows unauthenticated, remote attackers to execute arbitrary code. The situation is particularly urgent as the company has confirmed that threat […]

    The post Cisco Secure Firewall Vulnerability Exposes Systems to Remote Code Execution by Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Node.js project issued a critical security update for its Long-Term Support (LTS) branch, marking version 20.20.2 ‘Iron’ as a security release. This urgent patch addresses seven distinct vulnerabilities impacting TLS error handling, HTTP/2 flow control, cryptographic timing, and permission models. Several of these issues can be exploited remotely without authentication, posing an immediate risk […]

    The post Node.js Releases Urgent Patches for Multiple Vulnerabilities Exposing Systems to DoS and Crashes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The debate about lethal autonomy—core to the Trump administration’s fight with Anthropic—obscures a deeper danger of the Pentagon’s rapid adoption of commercial AI tools: they might weaken the U.S. military’s ability to tell fact from fiction.

    New research suggests that relying on AI to do various tasks can erode one's native ability to do them. Military commanders are taking note. 

    “The more you use AI, the more you will use your brain in a different way,” said French Adm. Pierre Vandier, NATO Supreme Allied Commander for Transformation, in a conversation in Defense One’s "State of Defense" series. “And so [we need to] be able to have some oversight, to be able to critique what we see from AI, and to be sure you are not fooled by a sort of false presentation of things. It's something we need to take care of.”

    But there is scant evidence that the Pentagon, in its rush to deploy AI tools, is taking steps to keep its users sharp—or even to monitor the effects of AI.

    “Because of the pace and the urgency associated with deploying these models, maybe that hasn’t been put in place,” said one former senior military official who worked to deploy AI in combat settings.

    In the meantime, the pressure to use AI tools is only growing.

    “Especially as you get deeper into any conflict, there will be more and more pressure to find more targets. That happens in every conflict as well. After two weeks, you're sort of going through your delivery target list. Now you're demanding targets. Well, how fast can you generate targets?” the former senior military official said.

    A cognitive trap

    A growing body of research shows that wide use of large language models can undermine human thought and communication.

    For example, it can homogenize thinking among users, reinforcing “dominant styles while marginalizing alternative voices and reasoning strategies,” according to an Air Force Research Laboratory paper published earlier this month in the journal Cell.

    This presents at least two problems for the military, said Morteza Dehghani, a University of Southern California computer science professor who helped write the paper. In the moment, “it washes away signals about who the author is,” and therefore eliminates important context for evaluating data. And over time, it can stifle critical thinking. 

    “Because these models are optimized for the most likely and ‘idealized’ responses, they often enforce a linear, ‘Chain-of-Thought’ reasoning style,” Dehghani wrote in an email. “This can disincentivize experienced analysts from employing the non-linear, intuitive, or ‘gut feeling’ strategies that are essential for identifying rare exceptions or navigating complex, non-standard intelligence scenarios.”

    Similarly, researchers at Wharton found in January that people using LLMs spend less and less time scrutinizing results for accuracy or employing their own judgment. They found that users rely on the AI’s judgement even when they know it’s wrong, a phenomenon the authors call “cognitive surrender.”

    And a February paper from Princeton found that the way LLMs speak to users—referred to as “sycophantic AI”—instills a false sense of confidence and isolates people within preconceived biases: “Our results show that the default interactions of a popular chatbot resemble the effects of providing people with confirmatory evidence, increasing confidence but bringing them no closer to the truth.”

    Who is driving?

    The military is aware of at least some dimensions of the problem. Speaking on a March 6 podcast, Pentagon research-and-engineering chief Emil Michael said that his core concern about Anthropic—which President Trump has barred from use by the federal government—was that military users might become too dependent on a single untrustworthy tool.

    “Maybe it's a rogue developer who could poison the model to make it not do what you want at the time, or sort of trick you because you have to trick it. I mean, all these things that we know when we worry about models that hallucinate purposefully or do not follow instructions,” Michael said.

    Anthropic had similar concerns: that its tools might be used by people untrained to properly evaluate its output. One company official said their chief worry was that they had not validated that the model could be used reliably for compiling targeting lists. Worse, they had no way of knowing how the military was putting their tools to use. For example, Anthropic officials only learned after the fact that their tools had been used to plan the Jan. 3 raid into Venezuela.

    The Pentagon has since declared Anthropic products a supply-chain risk and is working to replace them, though they are still in use by military planners, including in the Middle East.

    A former senior official described it as “a serious governance question.” Frontier AI companies like OpenAI, Anthropic, Google, and xAI cannot provide the in-depth support required for military units to understand the conditions under which these tools are used.

    “It's almost becoming a journey of discovery for the government,” the former senior military official said. “Are there people on site from these companies helping the day-to-day user? My guess is, if there are, there may be only one or two of them.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HUNTSVILLE, Ala.—The Army is sprinting to field drones and counter-drone systems throughout its units, but there are a handful of capabilities they’re still looking for in order to make these new systems viable in combat.

    That starts with the training environment, Col. Burr Miller, of Security Assistance Group-Ukraine, said Tuesday at the AUSA Global Force Symposium.

    “I saw many U.S. systems in Ukraine that did not survive contact because they were not prepared for the environment,” he said, calling on vendors to help the Army develop training that models the way drone warfare is actually playing out in Ukraine. 

    One of the key factors is navigation, which has primarily been done using GPS. Soldiers need the option to do visual-based navigation, magnetic navigation, even radio or cellular signals, he said, as back-up when GPS isn’t available

    “There are many, many ways of doing it out there, but I encourage you to consider that,” he added.

    Similarly, the command-and-control links for drone systems need to be resilient to interference, able to switch from using satellites to radio frequencies to cellular signals to prevent jamming. 

    “And I saw a lot of systems over there where the C2 links were easily intercepted by the enemy,” Miller said. “The Ukrainians were very good at this. And they would drive off with the enemy's system and bring the party home.”

    Units will have to be dispersed to stay undetected, while still being able to communicate with each other, said Col. Ryan Bell, who commands the 101st Airborne Division’s 3rd Mobile Brigade Combat Team at Fort Campbell, Ky.

    “Wherever we go, we're going to be seen, and so we have to spread out,” he said. “Our communications are going to be contested in the electromagnetic spectrum…If we talk, we can be seen. If we put a signal out, they can be targeting us.”

    One way to prevent that kind of interference would be to use more fiber-optic drones, Miller said, which are tethered to a control station. Though they can’t travel as far, they’re much harder to intercept than drones that rely on signals.

    “I think there's a lot of value to the fact that you can take a drone, put a fiber optic core behind it, and negate the entire electronic protection that you needed to have,” he said, adding that basically the only way to defeat them is to find and physically cut the cord. 

    Miller’s final point was one that Army senior leaders have been pointing out often— especially following the creation this summer of Joint Interagency Task Force-401, which is tasked with creating doctrine for counter-drone operations while putting together an online marketplace accessible to the entire U.S. government.

    “There are incredible counter-UAS systems on the battlefield today that are less than $5,000 that can knock down a Group 2, 3 and 4,” he said, referring to classes of drones. “So I really think that's something important we should look at, and we need to take that experience from Ukraine's, because they are by far the best counter-UAS people on the planet.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mirai malware evolves into hundreds of variants, driving botnet growth, including Aisuru and KimWolf, powering large-scale attacks, and increasing risks to vulnerable IoT devices worldwide.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating and managing a criminal site that allowed stolen

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶