• Iran-linked Handala hackers claim cyberattacks on Stryker and Verifone. Stryker confirms network disruption while Verifone says no breach evidence found.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • BeatBanker Android Trojan spreads via fake Google Play Store pages, using a silent audio loop to stay active while stealing crypto, banking data, and login credentials.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Pentagon plans to buy 30,000 one-way attack drones this month, but the military’s ability to repair or even build drones on the battlefield could make or break operations in modern conflicts. 

    So when Dan Magy, the CEO of Firestorm, first told me in December about a mobile industrial-grade 3D printing shop inside a shipping container, I needed to see it for myself. And I did, a couple months later on a rare rainy day in San Diego. 

    The entire setup felt like walking into a field lab—white floors, ceilings, and walls draped in vinyl sheets—and smelled like brand new toys just ripped out of the package. There’s a giant computer that shows renderings of what’s to be printed. A table displayed a smorgasbord of what was made—neck braces, satellite antenna, splints, drone arms, and what could only be described as a giant wrench. 

    “You hit print and then you come back in six to 12 hours and you're done,” Magy said. “When you want to move it, this processing station will roll and then these two sides roll up, and then you can just ship it. And then it takes about two hours to redeploy. So you just pull it up, and away you go. Put it on a boat, a plane.” 

    The HP printers are massive, like two coffins stacked on top of one another, and set up in a climate-controlled container, called XCell, which can be broken down and assembled in a few hours. This particular mini factory is two 20-foot units connected, measuring just shy of 1,200 square feet, and includes a chamber to clean and remove particle dust from the 3D prints. 

    “It's an advanced manufacturing line,” Magy said. “We were using [the HP printers] already to make our drones. Then we were asked by the end user to figure out how to put this in a box so we could build stuff where we need it, as opposed to waiting 18 months for resupply on drones.” 

    Firestorm is building a library of the most in-demand items for battlefield and humanitarian use, while also working with the government to create an easily searchable database for computer aided designs the military might need.  

    “A lot of these are parts that the end users have either designed or asked us to build because the supply chain can't sustain them. Remember, there's no Pep Boys or AutoZone in defense. You can't go to the store. So we're building things like engine coolant pans,” Magy said. “Now, you don't need to ship all these components. We'll just have libraries full of things we can print” at a much cheaper rate.

    It’s a growing field gearing up to match the military’s need to deploy drones by the thousands. 

    “The military has looked at expanding the use of 3D-printed parts in everything from Humvees to rocket motors and hypersonics. There's also a big upside for organic maintenance depots…if the military can print its own 3D parts in the field, that cuts down on maintenance costs, reduces equipment downtime, and increases overall capacity at the depot,” said Shaun McDougall, a lead defense analyst for Forecast International. 

    Magy said the next year is about expansion, including printing with other materials beyond the current nylon composite and designing their own medical products, such as knee braces. 

    “What you're going to see over the next year is a dramatic expansion in advanced manufacturing capabilities we're going to be containerizing. We think this covers a part of the pie. We want to expand,” he said. 

    Welcome

    You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and song recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!

    Drones in the USA. The Pentagon wants to buy more than $1 billion in small drones in less than two years—while simultaneously making sure those drones are free from China-made parts and subcomponents. And the first big test starts this summer. 

    • Travis Metz, the Pentagon’s Drone Dominance program manager, told the Senate Armed Services Committee last week that while all drones it delivers to troops are compliant with current legal bans on certain foreign-made small UAS, the plan is to be “more prescriptive than the NDAAs in terms of not allowing various components to be included in the systems that we procure, with the long term goal of building a drone supply chain that is American.”
    • “We'll be placing orders in August for Phase Two. We will not be allowing any Chinese batteries and motors in Phase Two, in addition to other restrictions that we'll be imposing that are above and beyond the current statutory restrictions,” Metz said. 
    • The Pentagon wants to order 30,000 drones in the coming days, after a recent tech competition at Fort Benning, and at least another 50,000 in August after the next competition phase, Metz said. The goal is to deliver 300,000 by 2027 and keep that pace for a few years. 

    AI “copilots” on submarines. Despite the age of the Navy’s fleet of attack submarines, the service is focused on inserting the latest tech when it can, said Vice Adm. Richard Seif, commander, Naval Submarine Forces.  

    • “So, today we have 48 attack submarines,” which are a mix of newer Virginia-class submarines, and older Seawolf and Los Angeles-class submarines, some of which are “over 30 years old,” Seif told the U.S.-China Economic and Security Review Commission. 
    • “Today, we have over a dozen submarines that have, really, state-of-the-art algorithms. We call it a copilot for AI/ML. Anywhere you have a lot of data and not a lot of analysts to look at the data just it screams for AI/ML,  as an example,” Seif said. 
    • That ability to update submarines with new technology “underpins” deterrence, he said: “And so going forward, whether it's quantum, whether it's artificial intelligence, machine learning, or the new capability, or even unmanned systems, as we integrate those payloads, we’ll be fully ready to do that.”

    One last thing: Check out this very cool image of the Civil War-era USS Monitor on the seafloor.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user could be trained and tricked into falling prey to phishing and scam traps. The attack, at its core, takes advantage of AI browsers’ tendency to reason their actions and use it against the model itself to lower their security guardrails, Guardio

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Key refueling-related tests for the B-21 Raider are now underway, an Air Force spokesperson confirmed to Defense One, the latest milestone towards delivering the next-generation bomber by 2027.

    On Tuesday, several open-source intelligence accounts and plane spotters posted images of a B-21 approaching a KC-135 tanker over California. One account cited flight radar data indicating that the tanker was from Edward Air Force Base’s 370th Flight Test Squadron. Other photographs and videos showed the bomber being followed by an F-16 fighter jet.

    “We can confirm that a B-21 Raider flight test aircraft completed a test event involving a close-proximity flight with a KC-135 Stratotanker,” the spokesperson said in an emailed statement. “This flight is part of the ongoing, rigorous test campaign to validate the B-21's capabilities and operational readiness.”

    The B-21’s latest appearance comes as President Trump’s war in Iran stretches into its second week and the U.S. Air Force’s current long-range bomber fleet continues to hit Iranian missile sites and other military infrastructure. The first Raider is scheduled to be delivered next year, but some defense experts said the program’s recent progress might mean key milestones will be hit sooner than anticipated.

    “It's a great sign that, once again, what we've been hearing now for a few years is the program is on track and on time, maybe even ahead of schedule,” said Mark Gunzinger, the Mitchell Institute’s director of future concepts and capability assessments.

    Gunzinger, a former B-52 bomber pilot, said the close approach of a B-21 to a tanker is a key preliminary step. 

    “When you have a new aircraft, you do proximity testing, you approach the refueling envelope, and you do that multiple times.” Gunzinger said. “You practice emergency breakaways from a tanker, which is a standard training event for all aircrew before you actually come in contact. So, that will likely progress until it's actually hooking up and unhooking, hooking up and so forth. And then they actually will pass fuel.”

    Last month, the service reached a deal with Northrop Grumman to accelerate B-21 bomber production by 25 percent, using $4.5 billion approved for the effort in the 2025 reconciliation spending bill. 

    While the original plan was to spend that funding over five years, the Defense Department plans to allocate it all by October “if that can be done without sacrificing effectiveness,” a Pentagon planning document obtained by Defense One last month said. 

    Air Force officials said the service remains “on track” to deliver the first B-21 Raider in 2027 to Ellsworth Air Force Base, South Dakota, which will serve as the bomber’s first main operating base and formal training unit.

    New tanker? 

    While the service prepares for a new bomber, a timeline for a new refueling tanker is less clear. The KC-135, seen refueling the B-21 by plane spotters, has been in service since the late 1950s. Last year, the Air Force weighed keeping the tanker in service past its originally planned 2050 retirement date. 

    Lt. Gen. Reba Sonkiss, the interim head of Air Mobility Command, told reporters last month that the service needs to seriously discuss what the future replacement for its aging tankers will be, given that they’ll be supporting next-generation airframes like the B-21.

    “I cannot have a 90-year-old tanker refueling a B-21, and if you do the math, as we reach the end of programs for things, that’s the reality,” Sonkiss said during a Feb. 24 roundtable at the Air and Space Force Association’s Warfare Symposium. 

    Gunzinger said the KC-135 is capable of refueling a B-21, but agreed with Sonkiss’ point. The 1950s-era tanker was built with other conflicts in mind, and it needs key upgrades to stay relevant in a fight against a future adversary. 

    “I think that's a valid point. The Air Force's Global Strike Forces were designed to operate together back in the 50s and in the 60s,” Gunzinger said. “My point is KC-135 [was] never designed to be part of a secure communications network of the kind that you would want to operate in a conflict with China.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A hacktivist group with links to Iran’s intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker’s largest hub outside of the United States, said the company sent home more than 5,000 workers there today. Meanwhile, a voicemail message at Stryker’s main U.S. headquarters says the company is currently experiencing a building emergency.

    In a lengthy statement posted to Telegram, an Iranian hacktivist group known as Handala (a.k.a. Handala Hack Team) claimed that Stryker’s offices in 79 countries have been forced to shut down after the group erased data from more than 200,000 systems, servers and mobile devices.

    A manifesto posted by the Iran-backed hacktivist group Handala, claiming a mass data-wiping attack against medical technology maker Stryker.

    A manifesto posted by the Iran-backed hacktivist group Handala, claiming a mass data-wiping attack against medical technology maker Stryker.

    “All the acquired data is now in the hands of the free people of the world, ready to be used for the true advancement of humanity and the exposure of injustice and corruption,” a portion of the Handala statement reads.

    The group said the wiper attack was in retaliation for a Feb. 28 missile strike that hit an Iranian school and killed at least 175 people, most of them children. The New York Times reports today that an ongoing military investigation has determined the United States is responsible for the deadly Tomahawk missile strike.

    Handala was one of several Iran-linked hacker groups recently profiled by Palo Alto Networks, which links it to Iran’s Ministry of Intelligence and Security (MOIS). Palo Alto says Handala surfaced in late 2023 and is assessed as one of several online personas maintained by Void Manticore, a MOIS-affiliated actor.

    Stryker’s website says the company has 56,000 employees in 61 countries. A phone call placed Wednesday morning to the media line at Stryker’s Michigan headquarters sent this author to a voicemail message that stated, “We are currently experiencing a building emergency. Please try your call again later.”

    A report Wednesday morning from the Irish Examiner said Stryker staff are now communicating via WhatsApp for any updates on when they can return to work. The story quoted an unnamed employee saying anything connected to the network is down, and that “anyone with Microsoft Outlook on their personal phones had their devices wiped.”

    “Multiple sources have said that systems in the Cork headquarters have been ‘shut down’ and that Stryker devices held by employees have been wiped out,” the Examiner reported. “The login pages coming up on these devices have been defaced with the Handala logo.”

    Wiper attacks usually involve malicious software designed to overwrite any existing data on infected devices. But a trusted source with knowledge of the attack who spoke on condition of anonymity told KrebsOnSecurity the perpetrators in this case appear to have used a Microsoft service called Microsoft Intune to issue a ‘remote wipe’ command against all connected devices.

    Intune is a cloud-based solution built for IT teams to enforce security and data compliance policies, and it provides a single, web-based administrative console to monitor and control devices regardless of location. The Intune connection is supported by this Reddit discussion on the Stryker outage, where several users who claimed to be Stryker employees said they were told to uninstall Intune urgently.

    Palo Alto says Handala’s hack-and-leak activity is primarily focused on Israel, with occasional targeting outside that scope when it serves a specific agenda. The security firm said Handala also has taken credit for recent attacks against fuel systems in Jordan and an Israeli energy exploration company.

    “Recent observed activities are opportunistic and ‘quick and dirty,’ with a noticeable focus on supply-chain footholds (e.g., IT/service providers) to reach downstream victims, followed by ‘proof’ posts to amplify credibility and intimidate targets,” Palo Alto researchers wrote.

    The Handala manifesto posted to Telegram referred to Stryker as a “Zionist-rooted corporation,” which may be a reference to the company’s 2019 acquisition of the Israeli company OrthoSpace.

    This is a developing story. Updates will be noted with a timestamp.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶