-
This week’s cyber stories show how fast the online world can turn risky. Hackers are sneaking malware into movie downloads, browser add-ons, and even software updates people trust. Tech giants and governments are racing to plug new holes while arguing over privacy and control. And researchers keep uncovering just how much of our digital life is still wide open. The new Threatsday Bulletin
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have disclosed details of a new fully-featured Windows backdoor called NANOREMOTE that uses the Google Drive API for command-and-control (C2) purposes. According to a report from Elastic Security Labs, the malware shares code similarities with another implant codenamed FINALDRAFT (aka Squidoor) that employs Microsoft Graph API for C2. FINALDRAFT is attributed to a
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
As enterprises refine their strategies for handling Non-Human Identities (NHIs), Robotic Process Automation (RPA) has become a powerful tool for streamlining operations and enhancing security. However, since RPA bots have varying levels of access to sensitive information, enterprises must be prepared to mitigate a variety of challenges. In large organizations, bots are starting to outnumber
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An advanced persistent threat (APT) known as WIRTE has been attributed to attacks targeting government and diplomatic entities across the Middle East with a previously undocumented malware suite dubbed AshTag since 2020. Palo Alto Networks Unit 42 is tracking the activity cluster under the name Ashen Lepus. Artifacts uploaded to the VirusTotal platform show that the threat actor has trained its
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A high-severity unpatched security vulnerability in Gogs has come under active exploitation, with more than 700 compromised instances accessible over the internet, according to new findings from Wiz. The flaw, tracked as CVE-2025-8110 (CVSS score: 8.7), is a case of file overwrite in the file update API of the Go-based self-hosted Git service. A fix for the issue is said to be currently in the
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google on Wednesday shipped security updates for its Chrome browser to address three security flaws, including one it said has come under active exploitation in the wild. The vulnerability, rated high in severity, is being tracked under the Chromium issue tracker ID “466192044.” Unlike other disclosures, Google has opted to keep information about the CVE identifier, the affected component, and
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Huntress is warning of a new actively exploited vulnerability in Gladinet’s CentreStack and Triofox products stemming from the use of hard-coded cryptographic keys that have affected nine organizations so far. “Threat actors can potentially abuse this as a way to access the web.config file, opening the door for deserialization and remote code execution,” security researcher Bryan Masters said.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
·
Countries looking to join NATO are still welcome to apply, a top alliance official said Wednesday in tacit repudiation of the Trump administration’s recent declaration that the group must not be a “perpetually expanding alliance.”NATO has an open-door policy, the alliance’s parliamentary secretary general, Benedetta Berti, told reporters Wednesday at an event hosted by the Project for Media and National Security. That was reaffirmed as recently as June’s summit, but the new U.S. national security strategy calls for “ending the perception, and preventing the reality, of NATO as a perpetually expanding alliance.”
However, Berti added, “there is no consensus for moving forward with the accession of new members,” to include Ukraine.
Berti was in Washington, D.C., this week for NATO’s Parliamentary Assembly Transatlantic Forum, where officials discussed both the new NSS and the Trump administration’s recent attempt at a ceasefire between Russia and Ukraine, which alliance officials roundly denounced.
“What we would underline, and I've heard this from the secretary general, is that, of course, from the NATO perspective, the job for today is for the alliance to continue to support Ukraine so it can defend itself today, to continue to work with Ukraine for the long-term transformation of its armed forces, and really to, through military support, to contribute to ensure that it can negotiate from a position of strength,” Berti said.
As for the rest of the NSS—which, among other things, warns that immigrants threaten to bring about Europe’s “civilizational erasure”—Berti said NATO is keeping its focus on its commitment to increase its defense capabilities, a demand from the Trump administration that the organization is working to meet.
“It's in line, very much in line, with what all 32 NATO allies agreed on the at the summit … and that is essentially a recognition that the post-Cold War peace dividend level of defense spending that we saw from Europe was simply not adequate to the current threat assessment that we have, including because of Russia against Ukraine, but not exclusively,” Berti said.
So NATO is not necessarily recalibrating its relationship with the U.S., she said, but focusing on how the administration’s positions in the NSS will affect NATO. From discussions at the parliamentary summit, she added, it’s clear that different member countries have different reactions to the administration’s particular interest in Europe’s cultural health.
“From our organization, we really just focus on, how do we actually forward in implementing what, to me, is really the most important question from a security perspective, and that is a more credible European core,” she said.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of previously undocumented malware families, according to new findings from Huntress. This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel named CowTunnel, and a Go-based
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
·
SIMI VALLEY, California—This year’s Reagan National Defense Forum had a slightly different mix: fewer uniforms, more Silicon Valley and finance types.The former likely reflected the Pentagon’s new restrictions on public engagements; the latter, a new willingness by financiers to invest in the defense industry. That trend was seemingly epitomized by JPMorgan Chase’s October announcement that it would invest up to $10 billion, as part of a much larger pledge, in “industries critical to national economic security and resiliency.”
“I'm happy this is taking place. I'm happy a lot of this venture capital money is going into things we really need, not things like social media, for example,” Dimon said on stage Saturday. “It's been obvious for a while. When Ukraine got invaded by the Russian armies four years ago, it should have shattered any illusion that people have that we're safe.”
“Somehow, we missed a lot” of vulnerabilities, from the Pentagon’s dependence on foreign supplies of crucial materials to America’s broader reliance on imported pharmaceuticals, he said.
JPMorgan’s investment is meant to galvanize others’, and ultimately boost and reshore small and medium suppliers for major primes, like RTX, whose CEO, Chris Calio, shared the stage with Dimon. Such investments might finance “vendor supply chains that someone like Chris might have, where if he wants to double, triple production of his missiles, he's got to get some of them to double triple their production. They may not have the money, or they may need a little bit of advice or help, or build a new plant.”
Dimon said the money might also boost research, help tackle complicated problems like shipbuilding, and even affect policy.
“What can we do to [be] faster, better, quicker? As you all know, you've heard it many times: There's not that much time, and so, we better get our act together,” he said.
Welcome
You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and rooftop recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!
AI for shipyards. The Navy wants its shipbuilders to use AI to improve production, so it’s spending $448 million to link their data to a new tool—Palantir’s ShipOS—to simplify scheduling, increase capacity, and reduce costs, Navy Secretary John Phelan announced Tuesday in Washington, D.C.
The move is part of Phelan’s promise to cut costs and put more hulls in the water faster using emerging technologies.
This “isn't a concept, it's not a pilot program. It's not a study. It's real. This is funded. This is happening,” Phelan said during the service’s first industry day for its new Rapid Capabilities Office. “Every shipbuilder who partners with us will have AI-powered tools that optimize their work in real time. Every supplier in the network will be connected through intelligent logistics. Every program manager will have unprecedented visibility into schedule, cost and risk. We're not just building ships faster. We're rebuilding American maritime industrial capacity for the AI age.”
What’s interesting about this deal is that the onus is on Palantir to prove its usefulness to suppliers once the tech is implemented. Oh, and part of that $448 million is being funded by budget reconciliation.
The goal is to “automate manual processes” such as paper drawings, and have a handful of public and private shipyards and 100 suppliers “delivering sooner and not being delayed in getting their items to the shipyards,” Jason Potter, the Navy’s current acquisitions head told a select group of reporters. “That's what success looks like.”
During pilot deployments, a Navy press release said, General Dynamics Electric Boat did 160 manual hours’ worth of submarine schedule planning in less than 10 minutes, while Portsmouth Naval Shipyard “cut material review times from weeks to under one hour.”
New frigate. Just days earlier, Phelan had announced plans to design and build a new frigate just days after canceling the Constellation-class program. The “big, beautiful ship,” as he called it, will be an American design and part of the White House’s proposed “Golden Fleet.” But it won’t displace other shipbuilding efforts.
The service is also retooling the Landing Ship Medium, Phelan announced over the weekend. The “14-knot, lightly armed, and unprotected” LSM, which had drawn criticism from former Marine Corps commandants, had seen an earlier acquisition effort aborted.
ICYMI
The Pentagon wants AI everywhere too. The Defense Department rolled out AI tools Tuesday—Google Gemini for Government.
Golden Dome gets a $151 billion contract vehicle. The Pentagon picked 1,000 companies to vie for pieces of the White House’s domestic missile defense system via SHIELD, perhaps the department’s biggest-ever contract vehicle.
“I don't know if it's the largest ever, but it's certainly near the top in terms of overall contract ceiling,” Todd Harrison, a defense budget expert with the American Enterprise Institute, told Defense One’s Thomas Novelly. “The number of awards suggests that they're just trying to get nearly everyone on contract so they have easy options to award actual funding later on.”
New CCA, who dis? Defense One got a sneak peak of Northrop Grumman’s Project Talon—an autonomous aircraft borne out of the defense company’s original, losing bid for the Air Force program. The sleek multi-mission roboplane, which was unveiled under soft lighting at the company’s facilities in Mojave, California, will use the Prism autonomy package that also flies Northrop’s optionally manned Beacon aircraft.
A little more: Northrop Grumman said it increased the range of its Ground/Air Task-Oriented Radar. The company wouldn’t give numbers, but said software upgrades boosted “high-fidelity surveillance,” such as threat detection, tracking, and targeting.
Keyword: collaboration. The Pentagon has called on defense companies to come up with new tech the military can use before it asks for it in a program of record. To address that, two segments of General Dynamics are trying something different: creating spaces, including a new lab, where companies can work shoulder-to-shoulder with competitors. Get the story here.
On my radar
- Army taps C3.AI for brigade command and control to improve logistics and supply distribution.
- More maritime drones. Venture-backed Vatn Systems secured $60 million in a series A funding round for its underwater autonomous vessel.
- Workforce + implementing acquisition reform. The latest version of the 2026 National Defense Authorization Act removes a House-passed provision that would have protected collective bargaining rights for the Defense Department’s civilian workers.
- White House-directed workforce cuts have hit DOD across organizations, but especially with respect to contracting officers. That could affect the Pentagon’s move to systemically change how it buys weapons and other technology as part of broad acquisition reform—and how contracts are executed amid top-down directive to move fast. For example, the U.S. The Space Force is already feeling the impact of those cuts to contracting workers.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


