• The Cybersecurity and Infrastructure Security Agency (CISA) has released a Malware Analysis Report (MAR) detailing a new malware family dubbed RESURGE, which is actively exploiting a zero-day vulnerability in Ivanti Connect Secure devices. According to CISA, RESURGE builds upon the functionality of the earlier SPAWNCHIMERA malware strain, introducing new commands designed to enhance persistence and […]

    The post CISA Alerts on RESURGE Malware Exploiting Ivanti Connect Secure Zero-Days appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A popular Iranian prayer timing application, BadeSaba Calendar, was hacked to deliver anti-government push notifications to millions of users. This cyber incident occurred early Saturday morning, coinciding with joint U.S. and Israeli military strikes on Iran. While the kinetic strikes targeted physical locations, this coordinated cyber operation sought to broadcast messages of defection directly to […]

    The post Prayer App Used by Millions Hacked to Broadcast Defection Messages Amid U.S.-Israel Strikes on Iran appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A popular Chrome add-on, “QuickLens – Search Screen with Google Lens,” has quietly morphed from a legitimate productivity tool into a full‑fledged remote code-execution platform that abuses browser trust, security headers, and silent auto‑updates. What began as a simple Google Lens wrapper ended in a covert C2‑driven campaign capable of injecting arbitrary scripts into any […]

    The post Pixel Perfect Browser Extension Exploited for Stealth Script Injection and Security Header Stripping appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenClaw, a highly popular open-source AI personal assistant with over 100,000 GitHub stars, recently faced a critical security flaw. This AI tool, which autonomously manages developer workflows across laptops, messaging apps, and dev tools, was found to be vulnerable to a 0-click exploit. Any website visited by a developer could silently hijack their OpenClaw agent […]

    The post OpenClaw 0-Click Flaw Lets Malicious Websites Hijack Developer AI Agents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • B-2 bombers, stealth fighter jets, recon aircraft, and other weapons were used to strike more than 1,000 targets in the first day of the U.S. war on Iran, according to fact sheets and other statements by U.S. military units.

    On Sunday, U.S. Central Command released a list of U.S. weapons and platforms used in the first 24 hours of Operation Epic Fury, which began at 1:15 a.m. Eastern time on Feb. 28. Initial targets included aerospace forces and joint headquarters facilities of the Islamic Revolutionary Guard, Iranian navy ships and submarines, anti-ship and ballistic missile sites, command and control centers, military communications capabilities, and air defense systems, according  to a fact sheet distributed by CENTCOM. 

    An Iranian Jamaran-class corvette was hit by U.S. forces and “is currently sinking to the bottom of the Gulf of Oman at a Chah Bahar pier,” CENTCOM posted at 9 a.m. on Sunday.

    U.S. combat jets used in the war’s first day included F-16, F/A-18, F-16, F-22, and F-35 fighter jets; and the A-10 Warthog, a close-air-support jet that was used frequently in the Global War on Terror conflicts that followed the 9/11 attacks. 

    Some of the planes took off from the USS Abraham Lincoln. CENTCOM denied Iranian claims on Sunday that the nuclear-powered aircraft carrier was hit by ballistic missiles. 

    Electronic warfare, warning, and reconnaissance aircraft included the EA-18G, P-8 maritime patrol aircraft, unspecified RC-135s, and MQ-9 Reapers. Mobility aircraft included tankers and C-17 and C-130 airlifters.  

    Munitions and defenses used against Iranian attacks included Patriot Interceptors, THAAD anti-ballistic missile systems, and M-142 high mobility artillery rockets. 

    The operation marked the combat debut of the Pentagon’s new LUCAS one-way attack drones. 

    CENTCOM said it also used “special capabilities,” which they declined to include on the list. 

    U.S. Space Command did not respond when asked which Space Force assets were used in the operation. 

    Iranian counterattacks were swift. At a U.N. Security Council meeting on Saturday, the Iranian ambassador said the response was targeted solely at U.S. military assets. 

    On Sunday, CENTCOM denied that. In a post on X, command officials said Iran had attacked international airports in Dubai, UAE; Kuwait; Abu Dhabi; and Iraq. The post also said thatIran had attacked hotels in Dubai and Bahrain and residential areas in Israel and Qatar.

    U.S. casualties

    As of Sunday morning, three U.S. service members had been killed and five seriously wounded during the operation, CENTCOM said.  Addition. Those troops had not been publicly identified as of Sunday afternoon. Several others were hit by shrapnel and were concussed.

    Teetotaling order

    The guardians of the Space Force’s 5th Missile Warning Squadron at Buckley Space Force Base in Aurora, Colorado, were ordered to not consume alcohol in order to “maintain operational readiness” starting Saturday morning, a memo reviewed by Defense One read. 

    The 5th Missile Warning Squadron is part of Delta 4, which uses Overhead Persistent Infrared satellites and ground-based radars to track missile threats across the globe, according to a service fact sheet.

    A Space Force spokesperson confirmed the memo was authentic and said it was issued “in response to Operation Epic Fury and associated conflict in the U.S. Central Command area of responsibility.”

    CENTCOM fact sheet:

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake Xeno and Roblox gaming tools are spreading a Windows RAT (remote access trojan) using PowerShell and LOLBins, Microsoft Threat Intelligence warns.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • After the largest buildup of warships and aircraft in the Middle East in decades, American and Israeli military forces launched a massive assault on Iran on Feb. 28, 2026. President Donald Trump has called the attacks “operations” and has urged regime change in Tehran.

    To better understand what this means for the U.S. and Iran, Alfonso Serrano, a U.S. politics editor at The Conversation, interviewed Donald Heflin, a veteran diplomat who now teaches at Tufts University’s Fletcher School.

    Widespread attacks have been reported across Iran, following weeks of U.S. military buildup in the region. What does the scale of the attacks tell you?

    I think that Trump and his administration are going for regime change with these massive strikes and with all the ships and some troops in the area. I think there will probably be a couple more days’ worth of strikes. They’ll start off with the time-honored strategy of attacking what’s known as command and control, the nerve centers for controlling Iran’s military. From media reporting, we already know that the residence of Supreme Leader Ayatollah Ali Khamenei was attacked.

    What is the U.S. strategic end game here?

    Regime change is going to be difficult. We heard Trump today call for the Iranians to bring the government down. In the first place, that’s difficult. It’s hard for people with no arms in their hands to bring down a very tightly controlled regime that has a lot of arms. 

    The second point is that U.S. history in that area of the world is not good with this. You may recall that during the Gulf War of 1990-1991, the U.S. basically encouraged the Iraqi people to rise up, and then made its own decision not to attack Baghdad, to stop short. And that has not been forgotten in Iraq or surrounding countries. I would be surprised if we saw a popular uprising in Iran that really had a chance of bringing the regime down. 

    Do you see the possibility of U.S. troops on the ground to bring about regime change?

    I will stick my neck out here and say that’s not going to happen. I mean, there may be some small special forces sent in. That’ll be kept quiet for a while. But as far as large numbers of U.S. troops, no, I don’t think it’s going to happen. 

    Two reasons. First off, any president would feel that was extremely risky. Iran’s a big country with a big military. The risks you would be taking are large amounts of casualties, and you may not succeed in what you’re trying to do.

    But Trump, in particular, despite the military strike against Iran and the one against Venezuela, is not a big fan of big military interventions and war. He’s a guy who will send in fighter planes and small special forces units, but not 10,000 or 20,000 troops. 

    And the reason for that is, throughout his career, he does well with a little bit of chaos. He doesn’t mind creating chaos and figuring out a way to make a profit on the other side of that. War is too much chaos. It’s really hard to predict what the outcome is going to be, what all the ramifications are going to be. Throughout his first term and the first year of his second term, he has shown no inclination to send ground troops anywhere. 

    Speaking of President Trump, what are the risks he faces?

    One risk is going on right now, which is that the Iranians may get lucky or smart and manage to attack a really good target and kill a lot of people, like something in Jerusalem or Tel Aviv or a U.S. military base. 

    The second risk is that the attacks don’t work, that the supreme leader and whoever else is considered the political leadership of Iran survives, and the U.S. winds up with egg on its face. 

    The third risk is that it works to a certain extent. You take out the top people, but then who steps into their shoes? I mean, go back and look at Venezuela. Most people would have thought that who was going to wind up winning at the end of that was the head of the opposition. But it wound up being the vice president of the old regime, Delcy Rodríguez.

    I can see a similar scenario in Iran, if Khamenei and a couple of other leaders were taken out. But the only institution in Iran strong enough to succeed them is the army, the Guards in particular. Would that be an improvement for the U.S.? It depends on what their attitude was. The same attitude that the vice president of Venezuela has been taking, which is, “Look, this is a fact of life. We better negotiate with the Americans and figure out some way forward we can both live with.”

    But these guys are pretty hardcore revolutionaries. I mean, Iran has been under revolutionary leadership for 47 years. All these guys are true believers. I don’t know if we’ll be able to work with them.

    Any last thoughts?

    I think the timing is interesting. If you go back to last year, Trump, after being in office a little and watching the situation between Israel and Gaza, was given an opening, when Israeli Prime Minister Netanyahu attacked Qatar.

    A lot of conservative regimes, who didn’t have a huge problem with Israel, essentially said “That’s going too far.” And Trump was able to use that as an excuse. He was able to essentially say, “Okay, you’ve gone too far. You’re really taking risk with world peace. Everybody’s gonna sit at the table.”

    I think the same thing’s happening here. I believe many countries would love to see regime change in Iran. But you can’t go into the country and say, “We don’t like the political leadership being elected. We’re going to get rid of them for you.” What often happens in that situation is people begin to rally around the flag. They begin to rally around the government when the bombs start falling.

    But in the last few months, we’ve seen a huge crackdown in Iran. We may never know the number of people the Iranian regime killed in the last few months, but 10,000 to 15,000 protesters seems a minimum. 

    That’s the excuse Trump can use. You can sell it to the Iranian people and say, “Look, they’re killing you in the streets. Forget about your problems with Israel and the U.S. and everything. They’re real, but you’re getting killed in the streets, and that’s why we’re intervening.” It’s a bit of a fig leaf. 

    Now, as I said earlier, the problem with this is if your next line is, “You know, we’re going to really soften this regime up with bombs; now it’s your time to go out in the streets and bring the regime down.” I may eat these words, but I don’t think that’s going to happen. The regime is just too strong for it to be brought down by bare hands.

    This article is republished from The Conversation under a Creative Commons license. Read the original article.

    The Conversation

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hours after Iranian drones damaged U.S. Navy facilities in Manama, Bahrain, U.S. Navy Central Command told all servicemembers and contractors who live and work in and around the base that the area is no longer safe and they will receive money to stay in a hotel elsewhere. 

    An email obtained by Defense One titled “evacuation of Juffair”—the neighborhood in southern Manama that is home to Naval Support Activity Bahrain—says NAVCENT “has concluded that the Juffair boundaries are no longer assessed as safe for US personnel.” 

    The closure came Saturday night local time, after Iranian drones hit the base and multiple high-rise residential buildings in Bahrain in response to U.S. strikes on Iran. Videos posted on social media purport to show a drone nearing the Navy’s 5th Fleet headquarters building, striking a radar inside a large white bubble, and plumes of dark gray smoke billowing from the explosion. Other videos show apparent drone damage to residential high-rise buildings in several areas of Manama, as well as debris from intercepted drones and missiles.

    In a statement, the Bahrain Defense Force said it had shot down 45 incoming missiles and nine drones. 

    Air-raid sirens, followed by all-clear signals, sounded throughout the day, as the U.S. embassy there issued a shelter-in-place order and warned that “even if the incoming missile or drone is intercepted, falling debris represents a significant risk.”  

    No U.S. casualties have been reported; Fox News reported Thursday that the 5th Fleet headquarters had been operating under reduced staffing. Several hundred families of military and civilian employees live in Bahrain, which has no base family housing and limited barracks facilities. An evacuation of dependents was authorized after the first U.S. strikes on Tehran, Stars & Stripes reported, but the evacuation was not mandatory. Though one flight did depart, further flights are on hold. 

    Bahrain International Airport was hit by a drone early Sunday local time. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Overnight, robot-vs.-robot warfare spread from Europe to the Red Sea. 

    The U.S.-made LUCAS, a low-cost attack drone modeled on the Iranian Shahed-136, made its combat debut in Saturday’s strikes on Iran, and drew a wave of Shahed attacks in return.

    “CENTCOM's Task Force Scorpion Strike—for the first time in history—is using one-way attack drones in combat during Operation Epic Fury. These low-cost drones, modeled after Iran's Shahed drones, are now delivering American-made retribution,” U.S. Central Command said in a statement.

    In response to the strikes, Iran used Shaheds to strike U.S. Fifth Fleet headquarters in Bahrain, a CENTCOM official confirmed to Defense One

    “A few did get through” but caused no casualties and inflicted only “minimal damage” to the base, which remains operational, they said. 

    Last July, Arizona-based drone maker Spectreworks showed off the LUCAS at an event in the Pentagon courtyard, just a month before the Air Force began seeking an “exact replica” of the Iranian Shahed-136. In December, CENTCOM announced that they had deployed a “squadron” of the LUCAS drones to the region for testing and experimentation. 

    On Saturday, the official said that the term “squadron” did not really denote the actual number of aircraft. 

    “Don’t think of it as a traditional squadron; it could be 100 or 2,000,” they said.

    While the LUCAS was originally developed to mimic the Shahed for training, its modular, open architecture enables it to carry a variety of payloads. In December, officials acknowledged that they were testing it for a wide variety of missions, including reconnaissance and intelligence collection, in addition to one-way attacks. On Dec. 16, a LUCAS was test-launched from the littoral combat ship Santa Barbara in the Persian Gulf. 

    The official would not say how many LUCAS drones were used in Operation Epic Fury, but said the strikes also included Tomahawk cruise missiles, which can also be fired from Navy warships. (Asked about reports that said 21 Tomahawks had been fired in the operation, the official said it was “way more” than that.)

    Iranian stocks

    The number of Shaheds that Iran can bring to bear depends on a number of factors. Its ability to manufacture the drone is limited. U.S.-led sanctions have forced the regime to turn to smuggling to obtain critical accelerometers and gyroscopes for navigation, satellite-navigation receivers, and other components.

    In January, Iran’s Tasnim News Agency reported that its government had received a new batch of 1,000 drones, but those numbers are impossible to verify by Western sources. 

    Tehran’s stockpile also depends on how many Shaheds it has exported to Russia, its strategic ally, which has for several years used the drone heavily to strike targets in Ukraine.

    A CNA report from January 2025 said Iran was “struggling to meet Russia’s demand.”

    So Russia has been building up its ability to produce Shaheds under license. Last July, U.S. satellite photos showed that Russia greatly expanded its Alabuga SEZ facility and was aiming to produce 25,000 Shahed-136 drones a year, the Institute for Science and International Security noted, adding that the actual figure is likely closer to 18,540 per year. 

    In 2024, RUSI estimated that Russia was making the drones for $80,000 apiece. 

    Moscow’s willingness to build up Iranian stockpiles is unclear, but the two countries have been collaborating to improve their drones and related tactics.

    “The Iranians and their Russian allies had four years of target practice on Ukrainian cities to improve their Shahed drones. And most of the world smiled politely and thought it is just the Ukrainians’ unfortunate problem,” noted Wall Street Journal chief financial correspondent Yaroslav Trofimov on X., adding, “New Shaheds are much more difficult to intercept and are very accurate.”

    U.S. production

    But the U.S. ability to produce the Shahed clones is also limited. While the Pentagon has expanded efforts to quickly produce large numbers of cheap one-way attack drones, they are still relatively new.

    The U.S. still has conventional missiles for both targeted strikes and potential defense against drones. But these are often orders of magnitude more costly than Shaheds. Here, too, the U.S. faces constraints an a growing number of potential deployments.

    “US destroyers launched Tomahawks at Iranian targets, but here’s the problem: America doesn’t have unlimited [Tomahawk Land Attack Missile, or TLAMs]. The Trump administration burned through big numbers in earlier strikes on Iran, Houthis, and Nigeria without replenishing stockpiles. TLAMs would be vital in a China fight,” Bloomberg defense analyst Becca Wasser posted on X on Saturday.

    The United States might try to turn to its European allies for help, and those relationships provide a possible picture of the robot war’s next scene. The most effective defense against Shahed-136 drones is a $2,500 interceptor made by Ukraine.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Coordinated U.S. and Israeli strikes on Iranian targets are putting renewed focus on how the United States integrates offensive cyber capabilities into the battlespace — and how prepared federal agencies are for retaliation at home.

    Iran has shown a tendency to respond to overseas threats with cyber means, from defacing websites to spying on U.S. and allied targets. Tracking such actions and alerting the U.S. government and public is a job of the Cybersecurity and Infrastructure Security Agency, which has been operating with sharply reduced staffing due to a funding lapse for its parent agency, the Department of Homeland Security.

    “This is a bad time for Washington’s cyber agency to be operating with limited staff,” said Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, a national security think tank.

    That funding lapse comes after Trump-administration moves shrank CISA’s workforce by about one-third last year and degraded public-private collaboration mechanisms. This “limits the ability of the federal government to provide timely cyber threat information to the private sector,” Fixler said.

    In the wake of the U.S. and Israeli airstrikes, American companies could see a “barrage” of low-level attacks like website defacements and distributed denial-of-service attacks, said Fixler. “Iran might also see some limited success against targets that do not have proper cyber hygiene — exposed edge devices with default passwords, for example.”

    Other cyber experts said the U.S. should prepare for a mix of distributed denial-of-service campaigns, ransomware and hack-and-leak operations meant to send a message.

    “While it’s not operating at the same technical level as China or Russia, Iranian-linked groups have carried out disruptive attacks against U.S. financial institutions, infrastructure providers and private sector companies,” said Tom Pace, a former Marine intelligence specialist and CEO of NetRise, a cybersecurity supply chain firm.

    The conflict will likely see a surge in state-sponsored hacking activity, “specifically targeting operational technology and critical infrastructure through the exploitation of internet-facing industrial control systems and vulnerable [programmable logic controller] hardware,” said Brian Harrell, a former CISA official. 

    “Threat hunters should be working overtime right now. By combining disruptive attacks with psychological operations, Iran will seek to erode public trust in government institutions and project domestic strength during periods of heightened conflict,” he said.

    Elisity CEO James Winebrenner echoed that advice. “We should be vigilant in protecting exposed [industrial controls systems] and expect heightened retaliatory activity in the coming days and weeks,” he said. In late 2023, Iran-linked hackers digitally defaced U.S. water treatment equipment.

    Tehran may play up the effectiveness and scope of their cyberattacks, said Cynthia Kaiser, a former FBI cybersecurity deputy director who leads the Ransomware Research Center at Halcyon. Industry research has documented these theatrics.

    “They’ll turn [an intrusion] into an information operation, and say, ‘Look, we compromised this entire facility,’ even though they compromised just a machine,” Kaiser said. 

    Asked about the diminished DHS and CISA workforce, Kaiser said other national security elements across the government like the FBI and NSA are still able to track and respond to cyber threats in full. “People marshal themselves together to focus on a big threat” even if there are resource shortages, she said. 

    Matt Hayden, a former DHS infrastructure security official, said CISA would continue its standard threat-hunting procedures as if the government was fully operating. “While there are operators that are working without pay, they are still working,” he said. Hayden is now vice president of cyber and emerging threats at GDIT.

    Defense One has asked CISA and DHS for comment.

    The U.S. has likely deployed a powerful toolset of cyber and electronic operations against Iranian targets, said Charles Moore, a retired three-star general and former U.S. Cyber Command official who is now a distinguished visiting professor at Vanderbilt University’s Institute of National Security.

    “I would suspect that anything that Iran is using to communicate, anything they’re using to keep situational awareness or visibility on the battle space, and any systems they’re using to try to defend themselves, all those types of things — would be targets that would be of interest from a cyber perspective,” Moore said.

    The U.S. and Israel are also likely intercepting communications to aid in its operations. “In general, signals intelligence of any type, is something the United States is very interested in and is very adept at gathering. And so I have no doubt that those types of efforts will continue,” he said.

    Internet connectivity in Iran has also been heavily reduced. The exact cause of this decline is uncertain. While the U.S. or Israel may have played a role, Iran frequently restricts internet access during periods of unrest, such as anti-regime protests.

    In coming days, there may be public indications that Cyber Command played a role in U.S. components of the operation, said FDD’s Fixler.

    Influence operations have played a role in the efforts. Israel notably hacked a major Iranian prayer app, aiming to fuel uprising against the regime. But its effectiveness may be limited, said Maggie Feldman-Piltch, CEO of Iceberg Holdings, a firm that helps private-sector entities prevent IP theft. 

    The infiltration of a prayer app with those messages is “a wonderful example of not knowing your audience or understanding what happens when you don’t,” said Feldman-Piltch, who formerly led the digital and electronic portfolio at the Wilson Center. 

    A simple message finally calling for uprising ignores years of already documented protests against Iran that have resulted in civilian killings, she said.

    The U.S. and its allies will have to stay vigilant. The operation “has destroyed Iran’s conventional military options, making cyber operations the regime’s sole remaining instrument of asymmetric retaliation,” says a threat intelligence report sent to Defense One produced by cybersecurity firm Anomali. Iran-linked cyber units were “activated and retooling before the kinetic trigger,” it adds.

    “Geography provides no protection against a cyber-enabled adversary,” said Tatyana Bolton, principal and head of Monument Advocacy’s cybersecurity practice. “Iran possesses some of the most creative and dangerous cyber operators in the world, and with the current escalation, their incentive for restraint is significantly reduced.”

    “They don’t need to win a naval battle in the Gulf to hurt the U.S. — they can simply hold our power grids, water systems, and hospitals hostage from halfway around the world to force our hand at the negotiating table,” Bolton said. “We must recognize that in 2026, the front line isn’t just in the Middle East — it’s in our own backyard.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶