• SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. The vulnerabilities, all rated 9.1 on the CVSS scoring system, are listed below – CVE-2025-40538 – A broken access control vulnerability that allows an attacker to create a system admin user and execute arbitrary

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors recently abused a critical Apache ActiveMQ vulnerability to gain deep access to a Windows environment, eventually deploying LockBit ransomware over RDP. The attack shows how failing to patch CVE-2023-46604 can give adversaries repeat access and time to turn an initial foothold into full-domain impact. The exploit loaded a malicious Java Spring bean configuration XML file, […]

    The post Threat Actors Exploit Apache ActiveMQ Vulnerability to Gain RDP Access, Deploy LockBit Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OAuth consent attacks in Microsoft Entra ID are giving threat actors a stealthy path to cloud email, and even trusted apps like ChatGPT can become a vehicle if permissions are abused. In this hypothetical case, a user in an Entra ID tenant adds the legitimate ChatGPT service principal and grants it Microsoft Graph OAuth permissions, […]

    The post OAuth Vulnerabilities in Entra ID Could Exploit ChatGPT to Breach User Email Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Donald Trump’s break with the liberal democracies of Europe couldn’t have come at a worse time for U.S. defense and tech giants, whose market dominance will be challenged by European competitors riding several favorable trends.

    One is geographic: EU policies now coming into force mean U.S. firms will have to alter their strategies and practices—or lose access to a critical market. On the military side, the role of Ukraine in military technology innovation benefits European partners that are closer to the front line. Another is technological: At a time when faster tech cycles and open-source software make it easier for startups to challenge the giants, venture capital is flowing to European defense firms and a few U.S. startups. Yet another is, perhaps, philosophical: Europe is souring on the 21st-century bargain in which U.S. tech services are purchased, in part, with access to European data.

    All this suggests that while Europe will find it difficult to uncouple quickly or entirely from the U.S. defense and tech industries, a new order is coming.

    No divorce yet

    Even as European policymakers elevate concepts like digital sovereignty and strategic autonomy from interesting discussions to formal goals, decades of dependence on the U.S. military and industry are not so easily undone.

    U.S. defense firms account for nearly half of global sales, while European companies account for just under one-quarter, according to a Feb. 12 report from the McKinsey consulting firm. Europe buys about half of its defense goods from U.S. firms, a proportion that has grown in the past five years, the report says. And European governments are completely dependent on U.S. suppliers for some key capabilities such as large satellite constellations for internet connectivity or earth imaging. 

    As NATO Secretary General Mark Rutte, who has referred to Trump as "Daddy," told alliance members earlier this month, “Europe can defend itself without the US? Keep on dreaming. You can't.”

    The biggest hole in Europe’s plans for technological independence may be the cloud. Distributed large-scale data storage and retrieval are all but essential for modern weapons, defense manufacturing, societal resilience, and military operations; they are vital for autonomous systems and tools that use generative AI and large language models. 

    Some 80 percent of European spending on cloud services goes to U.S. companies, according to a December report by the European Commission. Even European officials concede that they have no near-term alternatives to U.S. enterprise cloud and data integration companies. But European governments who worry about their dependence on U.S. tech are openly rethinking their relationships with companies like Microsoft, Palantir and others. 

    "There is no quick fix," an analyst with a leading U.S. consulting firm told Defense One. “Given the annual capital and operating spend of hundreds of billions over multiple years from the hyperscalers”—the U.S. giants of computing—“we are not yet seeing a comparable European alternative.”

    While that’s the picture today, it’s not a permanent one. 

    Regulation

    U.S. executives love to point to EU regulations that hurt European competitiveness—for example, the General Data Protection Regulation. But a pair of new laws aim to help European digital-services companies grow—and will require U.S. firms to adapt. 

    The Digital Networks Act will replace multiple regulatory schemes with a single one, enabling companies to expand more quickly throughout the EU. The 2024 Data Act, now coming into force, gives users ownership over device-generated data and makes it easier for Europeans to switch cloud providers. 

    U.S. cloud providers that want to stay in the European market must create EU-based, or at least EU-compliant, versions of their products. These “sovereign clouds” must run on and store data in centers on the European continent. Microsoft, AWS, and Google, for example, have worked with France’s Capgemini to do so, but it eats into U.S. companies’ bottom lines.

    Cloud providers must also obey laws that prohibit unapproved sharing of EU-based data with, say, the U.S. government. The laws have teeth; in December, the EC hit X with a €120 million fine for DSA violations. But U.S. tech firms have also been threatened by the Trump administration if they comply. 

    And at least one analyst believes the DSA will force U.S. companies to open up their ecosystems and share intellectual property with European competitors. In October, AEI fellow Shane Tews argued that this will lead to “race to the bottom where copying existing features becomes more appealing than innovation.”

    Ukraine the pioneer

    Military tech is also becoming more European—specifically, Ukrainian. U.S. military commanders are closely watching as Ukrainian forces develop tactics and gear that have held Russian invaders at bay—and even defeated a simulated NATO mechanized attack. Last year,  Gen. Alexus Grynkewich, the U.S. Air Force officer who is the alliance’s Supreme Allied Commander, urged U.S. companies to workshop their arms and gear on Ukrainian battlefields.

    Eric Brock is a co-founder of the venture capital firm Ondas, which backs startups that work closely with Ukrainian troops. He said European governments increasingly want to buy made-in-Europe products. U.S. companies could approach this by seeking joint ventures with European firms—but he said that will require a humbler, more collaborative approach than U.S. companies have been used to.

    “We…want to bring European capital as well to match ours. So it can't be the bigger, American company coming in and dictating,” he said. “I think it's going to be hard for the established defense manufacturers who are so embedded with the Department of War to localize in Europe. Some of the emerging players on the fast cycle, like the companies we are working with, will have an easier time.” 

    Europe’s defense firms have typically moved more slowly than their American counterparts. One way to measure this is backlog-to-revenue, the time between taking an order and delivering a product. It’s an average of 3.7 years in Europe and 2.4 in the United States.

    But Ukraine is showing the rest of Europe how to move more quickly. It has, for example, developed and mass-produced interceptor drones while the United States has struggled to deploy far fewer at far greater cost

    That ambition is proving contagious. On Feb. 2, Germany unveiled a new highly maneuverable hypersonic missile in a fraction of the time and cost it took U.S. firms to debut theirs. 

    New-tech spending

    Europe is also putting a large portion of its new defense spending into new technology, rather than updating older tech. From 2022 to 2025, European defense-tech spending rose thirteenfold while U.S. spending on new tech only doubled, according to Jonathan Dimson, a senior partner at McKinsey, who added that investment in European defense-tech startups from 2021-2024 was more than five times greater than in the previous three-year period.

    Europe has also noted how Ukraine’s use of open-source software has sped innovation, and the EU has explicit efforts to encourage its use. Google last week criticized the plan as anti-innovation, but investors who bet on open-source AI companies say they can out-iterate closed models. They point to China’s DeepSeek and Arcee AI, a U.S. company that in January released Trinity, a 400-billion-parameter open-source model. Arcee built the model for $20 million, a fraction of the amount that, say, Meta spent on Llama, co-founder Mark McQuade said at an January event in San Francisco.

    “You're gonna have so many people building on top of that,” said William Sherman, whose AIN Ventures backs Arcee, “that those you already see those models getting are, like Mark said, getting close to as good as the closed-source models.”

    The U.S. military is also pushing for open architectures and freer data sharing, often over the objections of large incumbent defense contractors.

    “I'm very much encouraging any company interested in building that kind of open-source U.S.-based model to do so, and there's companies that are starting to do it,” Emil Michael, the defense undersecretary for research and engineering, told a small group of reporters last week at the AWS Defense Leadership Tech Summit in West Palm Beach.

    Public distrust

    Europeans’ growing distrust of the United States is dragging down their willingness to use U.S.-made tech. Public sentiment began to drop a year ago, after Vice President JD Vance’s speech at the 2025 Munich conference, said one U.S. financier who works with European and U.S. defense firms. 

    “The Europeans were aghast…They couldn't believe it. They were very upset. Very quickly. They realized that, okay, you know, ‘We have to be resilient,’” the financier said. “I don't think it's widely appreciated how big of a deal it is.

    More recently, a poll by the Munich organizers showed that most European respondents strongly felt that Trump’s policies were bad for their countries. In September, a Pew poll found that 63 percent prefer European-made security technologies, even at a higher cost, because they see Trump’s influence as a security risk. Just weeks ago, a poll conducted by Swiss technology company Proton found that nearly three-quarters of Europeans believe that their countries are too dependent on U.S. technology.

    Those changes in perception are especially relevant when it comes to AI, which U.S. hyperscalers are investing most heavily. European and U.S. citizens are increasingly aligned in wanting control over their own data and how AI is used in their lives, the Pew poll found.

    Military officials also talk about the control they want from AI and defense contractors in general: control over the data that goes into model reasoning, control of or at least transparency into model processes, control over compute resources. That puts the Pentagon on a collision course with big tech, which wants to retain, or even increase its control over user data, compute infrastructure, and intellectual property.

    All of this points to a great shift. Allies and consumers are skeptical of tech companies’ relationship with the White House. A new class of startups is emerging to compete against big tech providers. The Ukrainian model is shaping how every military thinks about the future of building and buying weapons. 

    Bottom line: While large U.S. tech firms will retain their leadership position for years, they are already becoming more European. And they’ll have to re-invent themselves in other ways if they are going to make the pitch that they can still grow and not just manage a slow decline.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has warned that threat actors are weaponizing malicious Next.js repositories to compromise developers through what appear to be legitimate projects and recruiting‑style technical assessments. The campaign abuses normal workflows in Visual Studio Code and Node.js to reach a staged command‑and‑control (C2) backdoor without relying on traditional malware installers. Attackers publish repositories that appear to […]

    The post Microsoft Alerts Developers of Malicious Next.js Repositories Used in Ongoing Hacker Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed vulnerability in FileZen to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that could allow an authenticated user to execute

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • “And our nation's capital itself, where we have almost no crime anymore, Washington, D.C. How did that happen?” President Donald Trump said Tuesday evening as he kicked off the national-security portion of his State of the Union speech with a nod to various domestic National Guard deployments he launched in 2025.

    It was one of several dubious claims the president made during the longest annual address in history, clocking in at nearly an hour and 48 minutes. Among those claims were ones he and other administration officials have often repeated, including that last June’s Operation Midnight Hammer “obliterated” Iran’s nuclear program and that the president’s intervention “ended eight wars” in 2025.

    “It isn’t funny,” Trump responded to snickers from the audience as he began to list the countries whose conflicts he claimed to have brought to a close.

    Among them are Thailand and Cambodia, which agreed to a ceasefire but are still contesting their shared border as of this month. 

    “The prime minister of Pakistan would have died if it weren’t for my involvement,” Trump went on to say, though India has denied that the U.S. president’s influence had anything to do with the end of its military operation against Pakistan last May.

    Trump’s claims about crime in D.C.—the purported result of his deployment of the National Guard in August and later Immigration and Customs Enforcement raids—are demonstrably untrue. He claimed crime in the district is at its lowest-ever recorded level; homicides were lower in 2014, according to D.C. police statistics. He also said crime was down 100 percent in January 2026 compared to January 2025—which would have meant the city had experienced zero crime the entire month.

    D.C. did see a 30-percent drop in crime in 2025, continuing a trend after a similar drop in 2024.

    And while Metropolitan Police have credited the increased presence of federal law enforcement with some of that progress, they have also pointed to crime-reduction programs and an unusually cold winter.

    On claims that June’s strikes hobbled Iran’s nuclear program, Trump’s special envoy to the Middle East said as recently as Monday during a Fox News appearance that the country is “a week away” from obtaining “industry-grade bomb-making material.” 

    “We wiped it out and they want to start all over again,” Trump said Tuesday. 

    He added that it was U.S. policy to ensure that Iran never builds a nuclear bomb, and claimed that the Iranian government’s violence against protestors had been halted “with the threat of serious violence.”

    Trump did not otherwise address his administration’s military buildup in the Middle East, including a second deployment extension for the aircraft carrier Gerald R. Ford.

    The president went on to take credit for “approving” a $1 trillion defense budget, a sum that was proposed by the White House last year but that Congress has not voted on. The Defense Department, which would receive the vast majority of that funding, is operating on a second continuing resolution for this fiscal year, while the Homeland Security Department is in its second week of a second partial shutdown.

    Most glaringly, the president outright lied that the $1,776 “warrior dividends” distributed to service members late last year were funded by tariff revenue. In reality, the checks were a one-time basic allowance for housing supplement paid for by the reconciliation bill, which a senior administration official first confirmed to Defense One in December. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The United States Department of the Treasury has taken decisive action against a network of exploit brokers responsible for trafficking stolen government cyber tools. On February 24, 2026, the Office of Foreign Assets Control designated Russian national Sergey Zelenyuk and his company, Operation Zero, alongside several affiliates. This marks a significant enforcement action aimed at […]

    The post US Sanctions Exploit Brokers Behind Theft of Government Cyber Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Lazarus Group is now using Medusa ransomware in attacks on healthcare and social services, signaling a move toward profit-focused cybercrime.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AURORA, Colorado—Air Force test pilots used artificial intelligence aboard an experimental fighter jet to successfully evade a simulated incoming missile, showcasing how the service’s aviators may rely on AI in a future fight. 

    Lockheed’s secretive Skunk Works research arm acknowledged the experiment Monday during the Air and Space Forces Association’s conference here. Late last year, test pilots at Edwards Air Force Base, California, received a simulated warning for an incoming surface-to-air missile while flying Lockheed’s experimental X-62A Vista jet. The onboard AI detected the missile and, without the pilot’s control, conducted an evasive maneuver. 

    “In this case, the missile signal or warning came in, the pilot didn't have to do anything, and the aircraft responded in a tactically appropriate way to keep the pilot alive and preserve the aircraft,” OJ Sanchez, Skunk Works’vice president and general manager, told reporters. 

    The test was called “Have Remy,” named for the rodent who helps a French chef cook by controlling his movements in the Disney film “Ratatouille.” The project also illustrates how AI tools might be used by the service’s fighter pilots. Distrust in AI among the general public still remains high, which experts have said may have broader national security implications. 

    Skunk Works’ project helped Air Force pilots train its AI models while simultaneously offering an opportunity for pilots to help develop and see how the technology may benefit them in future fights. Sanchez said the project showed how a fully autonomous unmanned aircraft could perform evasive maneuvers or be used as a feature in a suite of tools for aviators.

    “Exercises like Have Remy are part of changing the way that we think about using AI agents in some of the most stressing human conditions, and I can't think of one more stressing than inside a fighter cockpit under attack.”

    The X-62A Vista is a modified version of the F-16D Fighting Falcon, used to test automation and artificial intelligence. In 2024, Air Force Secretary Frank Kendall flew in an X-62A piloted by Shield AI’s software in a simulated dogfight with a manned F-16 fighter. 

    A September survey from the Pew Research Center detailed American skepticism and lack of trust in AI. Fifty percent of respondents said they’re more concerned than excited about the increased use of AI in daily life, and a majority of those surveyed also believe the technology will only make problem solving worse. Sanchez said experiments like “Have Remy” hope to break down those hesitations.

    “We are going to have to get all of us as humans comfortable with working alongside artificial intelligence, and that takes trust, just like a human-to-human relationship,” Sanchez said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶