• A critical security flaw has been identified in CentOS 9 that allows a local user to escalate their privileges to root. The vulnerability, which stems from a Use-After-Free (UAF) condition in the Linux kernel’s networking subsystem, was awarded first place in the Linux category at the TyphoonPWN 2025 hacking competition. A Proof-of-Concept (PoC) exploit has […]

    The post CentOS 9 Security Flaw Enables Privilege Escalation – PoC Released appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Two medium-severity vulnerabilities, an unsecured email API endpoint and verbose error messages exposing OAuth tokens, chain together to enable authenticated phishing that bypasses all email security controls, persistent access to Microsoft 365 environments While protocols like SPF, DKIM, and DMARC have made traditional domain spoofing difficult, attackers have evolved. They now seek ways to send […]

    The post Phishing and OAuth Token Vulnerabilities Lead to Full Microsoft 365 Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new spear phishing campaign that weaponizes a forgotten file type to bypass modern defenses. Attackers are luring victims into downloading Windows screensaver (.scr) files, which silently deploy legitimate Remote Monitoring and Management (RMM) software to establish persistent control over targeted systems. The campaign utilizes a simple yet effective delivery mechanism designed to evade reputation-based […]

    The post Hackers Exploit Windows Screensaver to Deploy RMM Tools, Gain Remote Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Artificial intelligence (AI) company Anthropic revealed that its latest large language model (LLM), Claude Opus 4.6, has found more than 500 previously unknown high-severity security flaws in open-source libraries, including Ghostscript, OpenSC, and CGIF. Claude Opus 4.6, which was launched on Thursday, comes with improved coding skills, including code review and debugging capabilities, along

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting SmarterTools SmarterMail to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-24423, this flaw is actively being weaponized in the wild, with security researchers confirming its use in recent ransomware campaigns. This addition mandates that Federal Civilian Executive Branch (FCEB) agencies remediate the […]

    The post CISA Advisory Highlights Exploited SmarterTools Vulnerability in Recent Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • An ongoing spam campaign that leverages social engineering to deploy legitimate Remote Monitoring and Management (RMM) software on victim networks. By disguising malicious payloads as essential Adobe Acrobat updates, threat actors are successfully bypassing traditional security controls and establishing persistent remote access to sensitive systems. The campaign begins with a deceptive email delivering a PDF […]

    The post Spam Campaign Distributes Fake PDFs, Deploys Remote Monitoring Tools for Ongoing Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Automated investment platform Betterment has confirmed a data breach affecting approximately 1.4 million customers. The incident, which occurred in January 2026, was the result of a targeted social engineering attack rather than a direct exploit of the company’s core infrastructure. The breach sequence began on January 9, 2026. According to Betterment’s forensic investigation, unauthorized actors […]

    The post Betterment Data Breach Exposes Sensitive Information of 1.4 Million Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. military’s largest shipbuilder reported increased production in 2025, but said submarine-building schedules could slip if the Navy doesn’t award new contracts by midyear. 

    “One thing I know for sure, the Navy is going to buy submarines. So we need to get it done before the first half of the year, so we can maintain the production schedules and make sure that is not a risk that we have to deal with,” HII CEO Christopher Kastner  said Thursday during the company’s earnings call

    The company has been negotiating with the Navy and General Dynamics Electric Boat on multiyear deals for 10 Virginia-class Block VI attack boats and for the next five Columbia-class submarines, but timing is uncertain. 

    “We need it before the end of the first half of the year in order to maintain our production schedules, but it's just hard to say,” Kastner said. “And I think we will get it done. And as I said previously, the '26 budget getting done and then clarity around what's going to happen in '27 and the [Future Years Defense Program], I think, really helps. And after that falls into place, we can get those contracts behind us.”

    In 2025, HII improved shipyard productivity by 14 percent; this year, it is aiming for a 15-percent increase, Kastner said. 

    It also hopes to hire even more workers than the 6,600 it brought on last year, he said.

    Kastner’s comments come as U.S. shipbuilding demands—and budgets—rise with existing and new programs and the Trump administration pressures builders to move quickly. 

    Electric Boat also reported a productivity increase: 13 percent more submarine tonnage, Danny Deep, General Dynamics president, said during the company’s Jan. 28 earnings call

    “At Bath Iron Works, we are seeing consistent ship-over-ship learning. And at NASSCO, we are seeing a very positive trend in terms of schedule variances against plan for each successive ship we build,” Deep said. “Our priority in the Marine Group is to remain laser-focused on execution and continue to accelerate production, and we are seeing good progress on that front.”

    But there are still supply-chain concerns, General Dynamics CEO Phebe Novakovic said on the call.

    “We are continuing to improve efficiency, retention at Electric Boat. Our throughput, as you know, is up and proficiency is really key, as is retention. The supply chain remains the gating item. And we have seen significant improvement in some areas, but we still have some suppliers and parts of the supply chain that are at risk,” Novakovic said. “The government has been heavily investing in the supply chain, which is why we've seen some improvement, but we need to focus and do more, particularly with respect to sole-source suppliers where there are bottlenecks.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Pentagon could further accelerate its technology purchasing if the services’ emerging-tech budget requests flowed through the office of the defense undersecretary for research, the Government Accountability Office says in a new report

    The report urges lawmakers to give "budget certification authority" for the services’ research and engineering spending to the Office of the Under Secretary of Defense for Research and Engineering. 

    “This would require the secretary of each military department and the head of each defense agency to transmit their department’s or agency’s proposed budget for research, development, test, and evaluation activities,” the report says. The R&E office would then “review each proposed budget and determine whether it is adequate.”

    Unsurprisingly, the proposal was not well received by the services. 

    “The Departments of the Army, Air Force, and Navy disagreed,” arguing that the change would lead to “delays, restricted autonomy, and increased workload,” the report said.

    But GAO says the current setup limits the Pentagon tech chief’s ability to ensure that service purchases fit with broader plans for the joint force—a “key role” the office was intended to play.

    Consolidation, happening

    The Pentagon has already pushed through a variety of measures to speed up and coordinate technology efforts. A March memo prioritizes the purchase of existing “dual-use” technology, particularly software, over custom, service-built solutions. The Department also is pushing acquisition authority down to the tactical level, allowing colonels and Navy captains to buy equipment in small batches using other transaction authorities.

    These moves have met with approval from long-time Pentagon watchers like Paul Scharre, author of Four Battlegrounds and vice president of the Center for a New American Security.

    “This leadership team is very invested in shaking things up, moving faster, and clearing out some of the red tape,” Scharre told Defense One in December. “A big piece of this has to happen on Capitol Hill as well. Congress has to be supportive…that has to do with things like getting less control out of the appropriators and giving the Department of Defense more flexibility to spend money very fast and be flexible in how they move money around.”

    The NDAA fight

    The current draft of the 2026 National Defense Authorization Act, passed by the Senate in October, includes a provision that echoes the GAO’s recommendation but stops short of full certification power.

    Instead, the Senate-passed bill would establish Portfolio Acquisition Executives, or PAEs, to replace traditional Program Executive Officers. These PAEs would have the ability to change requirements on their own and would grant the Pentagon’s research office more direct authority over their activities.

    However, the House version of the bill is more cautious. It stipulates that these acquisition executives “shall continue to report through their respective functional commands.” This discrepancy remains a primary point of contention as the House and Senate move to reconcile their versions of the bill. Despite the friction, there is at least a philosophical agreement that the services must buy equipment that aligns with a broader joint-force strategy.

    The GAO report also included a pointed note for the Pentagon’s tech leaders: the office “has yet to ensure that Critical Technology Area roadmaps consistently provide sufficient information for military departments to invest in technologies for the joint fight.”

    In other words: if the Pentagon is expected to follow a comprehensive tech strategy, the tech chief needs to finish writing it down.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Army has cleared three companies to bid on the service’s plan to outsource initial helicopter pilot training, despite some lawmakers’ reservations about the idea.

    Bell, Lockheed Martin, and M1 Support Services have all publicly confirmed this week that they are moving to the third phase of the competition for Flight School Next: a contract to take over the Army’s Initial Entry Rotary Wing training program at Fort Rucker, Alabama. The three companies must submit a Commercial Solutions Proposal for their offering, according to a Dec. 9 call for solutions outlining the process on SAM.gov.

    “This next phase is a critical point in the competition and Bell along with our teammates are ready to demonstrate what we believe is the most cost-effective and low-risk solution for the Army's next-generation flight training program,” said John Novalis, Bell’s strategic director of flight school next, in a press release. 

    Service officials and contractors believe the new model, which is intended to produce 800 to 1,500 Army aviators annually for 26 years, will lower costs by taking the aircraft, maintenance, and training out of the service’s hands. Congress isn’t convinced. In December, lawmakers said they wouldn’t make funds available for the initiative until they receive a report detailing the results of a trial program and a briefing from Army Secretary Dan Driscoll on the benefits of the new model. 

    Lawmakers want details on the cost-effectiveness and “the rationale for any proposed changes to training systems or platforms,” according to a provision in the National Defense Authorization Act passed into law on Dec. 20. It’s unclear if the Congressional inquiry into the program will delay the contract’s anticipated September award date.

    Representatives for Bell, Lockheed, and M1 all deferred to the Army when asked about the competition’s progress amid those Congressional concerns. 

    As part of Flight School Next, the Army wants a new initial-training helicopter to replace the twin-engine UH-72 Lakota, which has been criticized by Army leaders as being too expensive and restrictive for training. Its manufacturer, Airbus, has pushed back on those claims.

    Lockheed Martin announced Wednesday that its pitch would  include Robinson Helicopter Company’s R66 NxG helicopter.

    “Our selection of Robinson brings a safe, proven and innovative platform to the table. We are fully committed to getting this right for the Army—investing the time, expertise and technology needed to accelerate IERW training and ensure aviators are prepared for their next mission,” said Todd Morar, Lockheed’s vice president of Air and Commercial Solutions, in a press release.

    M1 is also working with Robinson, along with  General Dynamics Information Technology, Quantum Helicopters, and the University of North Dakota Aerospace Foundation.

    “We are ready now to conduct an exceptionally low risk transition while introducing a wide range of impactful innovations to transform Army flight training and deliver more proficient aviators at significantly reduced cost,” James Cassella, M1’s chief growth officer, said in a news release. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶