• Updated on Dec. 10.

    With its calls for “strong, traditional families” and the “reinvigoration of American spiritual and cultural health,” the latest National Security Strategy is a major departure not only from its immediate predecessor, but even the first Trump administration’s.

    A longer version of the NSS that circulated before the White House published the unclassified version late Thursday night shares the main points: competition with China, withdrawal from Europe’s defense, a new focus on the Western Hemisphere. But the unpublished version also proposes new vehicles for leadership on the world stage and a different way to put its thumb on the scales of Europe’s future—through its cultural values.

    Here are some takeaways from the unpublished version, which was reviewed by Defense One

    “Make Europe Great Again”

    While the publicly released NSS calls for the end of a “perpetually expanding NATO,” the full version goes more into the details of how the Trump administration would like to—quote—“Make Europe Great Again,” even as it calls on European NATO members to wean themselves from American military support.

    Working from the premise that Europe is facing “civilizational erasure” because of its immigration policies and “censorship of free speech,” the NSS proposes to focus U.S. relationships with European countries on a few nations with like-minded—right-wing, presumably—current administrations and movements.

    Austria, Hungary, Italy, and Poland are listed as countries the U.S. should “work more with…with the goal of pulling them away from the [European Union].”

    “And we should support parties, movements, and intellectual and cultural figures who seek sovereignty and preservation/restoration of traditional European ways of life…while remaining pro-American,” the document says.

    The C5

    Over the summer, President Trump made headlines when he lamented the expulsion of Russia from the Group of Eight—now the Group of Seven—as  a “very big mistake.” He even suggested that he’d like to see China added  to form a “G9.”

    His national security strategy proposes taking this a step further, creating a new body of major powers, one that isn’t hemmed in by the G7’s requirements that the countries be both wealthy and democratically governed.

    The strategy proposes a “Core 5,” or C5, made up of the U.S., China, Russia, India and Japan—which are several of the countries with more than 100 million people. It would meet regularly, as the G7 does, for summits with specific themes.

    First on the C5’s proposed agenda: Middle East security—specifically, normalizing relations between Israel and Saudi Arabia. 

    “Hegemony wasn’t achievable”

    The full NSS also spends some time discussing the “failure” of American hegemony, a term that isn’t mentioned in the publicly released version.

    “Hegemony is the wrong thing to want and it wasn’t achievable,” according to the document. 

    In this context, hegemony refers to the leadership by one country of the world, using soft power to encourage other countries to consent to being led. 

    “After the end of the Cold War, American foreign policy elites convinced themselves that permanent American domination of the entire world was in the best interests of our country,” the NSS states. “Yet the affairs of other countries are our concern only if their activities directly threaten our interests.”

    The administration appears to be using this reasoning to bow out of the U.S.’s role in defending Europe, while turning its attention to Venezuela-based drug cartels.

    “The Trump administration inherited a world in which the guns of war have shattered the peace and stability of many countries on many continents,” the NSS reads. “We have a natural interest in ameliorating this crisis.”

    The document says it shouldn’t be up to the United States to do it all alone—but also, China and Russia should not be allowed to replace U.S. leadership. The strategy suggests partnering with “regional champions” to help maintain stability.

    “We will reward and encourage the region’s governments, political parties, and movements broadly aligned with our principles and strategy,” according to the document. “But we must not overlook governments with different outlooks with whom we nonetheless share interests and who want to work with us.”

    After this story was published, the White House denied the existence of any version of the National Security Strategy other than the one published online.

    “No alternative, private, or classified version exists,” spokeswoman Anna Kelly told Defense One. “President Trump is transparent and put his signature on one NSS that clearly instructs the U.S. government to execute on his defined principles and priorities.”

    Kelly then added that “any other so-called ‘versions’ are leaked by people distant from the President who, like this ‘reporter,’ have no idea what they are talking about.’ ”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical React2Shell security flaw in React Server Components (RSC) to deliver a previously undocumented remote access trojan dubbed EtherRAT. “EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Five days after President Trump said he was ok with releasing video of the U.S. military’s first attack on alleged drug trafficking boats off the Latin American coast, he backed away from that pledge Monday, telling reporters he’d let his embattled Pentagon chief Pete Hegseth decide. 

    Dec. 3: “I don’t know what they have, but whatever they have, we’d certainly release. No problem,” Trump told reporters (read a transcript via Roll Call, here). 

    Dec. 8: On Monday, a reporter asked the president if he still felt that way. “Mr. President, you said you would have no problem with releasing the full video of that strike on Sept. 2 off the coast of Venezuela. Secretary Hegseth now says—” the reporter said before the president interrupted her. 

    “I didn’t say that. You said that. I didn’t say that,” Trump responded. “This is ABC fake news. I said, whatever Hegseth wants to do is OK with me.”

    SecDef Hegseth’s latest position: “Whatever we were to decide to release, we’d have to be very responsible” about it, he said Saturday on the sidelines of the annual Reagan National Defense Forum in California. 

    Why it matters: The strike in question reportedly killed two survivors aboard the boat on Sept. 2, according to the Washington Post, which noted the operation was carried out on Hegseth’s orders. “I watched it live,” the secretary told Fox the following day. But he changed his account after details of the operation became public. Last week, the Pentagon chief told reporters that he “watched that first strike live” but “didn’t stick around” for subsequent strikes. In the days since, several lawmakers have called for the release of surveillance footage of the attacks, which the Post reports involved four strikes in total: “twice to kill the crew and twice more to sink it.” 

    Killing survivors of a strike at sea could be a violation of the laws of war, multiple legal experts have argued since the Post published its report just after Thanksgiving.

    Lawmakers of both parties want the public to see the videos, and are planning to withhold one-quarter of Hegseth’s travel budget until he releases them, Politico reported Monday after House and Senate negotiators agreed on a compromise version of the 2026 defense policy bill (PDF). House lawmakers are expected to approve the final draft this week, with Senate approval expected shortly afterward. 

    Also included in the pending NDAA: 

    • $400 billion for Ukraine through a provision to pay U.S. companies for the sale of weapons to Kyiv; 
    • $175 million to help boost Latvia, Lithuania and Estonia's defense against Russian aggression; 
    • $200 million for Israeli missile defense as well as $80 million for anti-tunneling operations and $70 million for joint counter-drone programs;
    • $1 billion intended for Taiwan's military to help defend against a possible Chinese attack or invasion; 
    • $1.5 billion in support for the Philippines; 
    • And 4% pay raise for U.S. troops. 

    Notably, the NDAA does not fund Trump’s plan to rename the Defense Department to the “Department of War,” which NBC News reported last month is estimated to cost $2 billion. (Hat tip to Reuters.)

    Additional reading: 

    Coverage continues below…


    Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1938, the first operational shipboard radar was installed aboard the battleship USS New York.

    Developing: The Pentagon will widely deploy new AI tools for logistics, intelligence analysis, and combat planning in mere days or weeks, its research-and-engineering chief said Monday, adding that wide deployment of artificial intelligence now tops his list of “critical technologies,” Defense One’s Patrick Tucker reports

    The department has chosen Gemini for Government as the platform that will support DOD’s first department-wide rollout of AI tools, Google and defense officials announced Tuesday morning. The moves come after the Defense Innovation Unit, the Chief Digital and Artificial Intelligence Office, or CDAO, and others were combined under Emil Michael, defense undersecretary for research and engineering, in a bid to accelerate deployment of AI and other technologies. He said that he will likely reduce the number of technology areas that DIU is working on as well.

    The advent of large-language-model tools such as ChatGPT, Claude, and Gemini have made it possible—and necessary—to develop AI tools faster, Michael told reporters at the Defense Writers Group on Monday. “The explosion of capabilities has been enormous, and we're just catching up to that,” he said. “Now we can take CDAO and actually try to use it to push the capability into the Department for actual use cases.” Read more, here

    Big-picture analysis: The U.S. military needs to reinvent itself to deter future wars, the New York Times editorial board argues in a new roundup of many national security dynamics Defense One readers will be probably familiar with. A few of the more salient points include the following reminders: 

    • The Pentagon has an “overreliance on expensive, vulnerable weapons as adversaries field cheap, technologically advanced ones.”
    • “An entrenched oligopoly of five large defense contractors, down from 51 in the early 1990s, has an interest in selling the Pentagon ever-costlier evolutions of the same ships, planes and missiles.”
    • The “Ford [carrier], which is currently deployed in the Caribbean, is fatally vulnerable to new forms of attack. China in recent years has amassed an arsenal of around 600 hypersonic weapons, which can travel at five times the speed of sound and are difficult to intercept. Other countries possess quiet diesel-electric submarines capable of sinking American carriers.”
    • And as the latest NDAA makes its way through congress, the Times editorial board notes “The Trump administration wants to increase defense spending in 2026 to more than $1 trillion. Much of that money will be squandered on capabilities that do more to magnify our weaknesses than to sharpen our strengths.”

    “This is the first of a series of editorials examining what’s gone wrong with the U.S. military—technologically, bureaucratically, culturally, politically and strategically,” the Times writes. Read the rest, here

    Additional reading: 

    • Tom Wright of Brookings argues the White House’s new strategy “Ignores the Real Threats” facing the U.S., including “silen[ce] on Beijing’s ambition to displace Washington as the world’s leading power,” and “nothing about the Russian threat to U.S. interests.” Read his Monday response in The Atlantic, here.
    • See also “The Origin of Hegseth’s Anti-Beard Obsession,” via former Pentagon official Alex Wagner, writing Saturday in The Atlantic;
    • And “General Dynamics wants to turn competitors into teammates,” Defense One’s Lauren C. Williams reported Monday. 

    Trump 2.0

    “Worst of the Worst” site skips evidence. A new Department of Homeland Security website purports to list the worst “criminal aliens” arrested by ICE. The website names more than 9,800 of the “hundreds of thousands” of people taken into custody by Immigration and Customs Enforcement in the past 11 months. Each name is presented, information-card style, with their countries of origin and one or more alleged crimes. Most include a formal or informal mug shot; some, oddly, do not.

    For the vast majority of people, no corroboration is given of their purported criminality. Among the first 1,200 names, just 4% link to DHS press releases; no other kind of documentation is offered. (The site is “all about transparency,” a DHS spokesperson said in a press release.)

    Best of the worst of the worst? Many of the names are listed with one or more awful crimes: homicide, sexual assault, human trafficking, and more. But the sample also includes more than a handful of people whose only listed crimes were far more minor: shoplifting, marijuana possession, traffic offenses. Nearly 5% were accused solely of (felony) illegal re-entry.

    Finally, more than two dozen names have quietly been removed from the site since it went up on Monday, according to a Defense One analysis of the site. No explanation is given. 

    Most people arrested by ICE this year had no criminal record at all, Axios reported last week off a new tranche of data released by the agency. That wasn’t the case until May, when the White House reportedly ordered ICE to triple its daily quota of arrests from 1,000 to 3,000. “Now, agents have a broader mandate and have been encouraged to make more ‘collateral arrests,’ apprehending undocumented people who happen to be with someone on a target list, such as people in the same household,” Axios wrote.

    That’s especially true in Washington, D.C., the first city to see an unprecedented deployment of federal troops under Trump. “More than 80 percent of the immigrants arrested in D.C. during the surge in federal law enforcement this year had no prior criminal record,” the Washington Post reported on Thursday. 

    “The new data confirms that the Trump administration isn't focused on legitimate public safety risks, but rather on hitting politically motivated arrest targets,” Aaron Reichlin-Melnick, senior fellow at the American Immigration Council, told Axios last week.

    Related reading: 

    Additional reading:  

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model. The threat actor behind CastleLoader has been assigned the name GrayBravo by Recorded Future’s Insikt Group, which was previously tracking it as TAG-150. The

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The threat actor known as Storm-0249 is likely shifting from its role as an initial access broker to adopt a combination of more advanced tactics like domain spoofing, DLL side-loading, and fileless PowerShell execution to facilitate ransomware attacks. “These methods allow them to bypass defenses, infiltrate networks, maintain persistence, and operate undetected, raising serious concerns for

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Dec. 9, 2025

    Read the full story from Wiz

    Due to their cascading effect, supply chain attacks are costlier than most, with vendors and customers both bearing the brunt. Global costs of software supply chain attacks alone are estimated at $60 billion in 2025, and they’re expected to reach a whopping $138 billion by 2031, according to Cybersecurity Ventures.

    Wiz breaks down three types of supply chain attacks:

    Software supply chain attacks infiltrate software vendor systems to deliver compromised software to thousands of customers;

    Hardware supply chain attacks involve adversaries introducing counterfeit devices into the global supply chain;

    Third-party service attacks target customers of cloud service providers (CSPs), managed service providers (MSPs), SaaS platforms, and AI vendors by compromising software updates, API keys, or service integrations.

    Comprehensive supply chain security requires visibility across the entire code-to-cloud lifecycle, and Wiz breaks that down for CISOs and security leaders in a blog post that includes a handy cheat sheet with best practices.

    Read the Full Story



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Global Costs of Software Supply Chain Attacks On The Rise appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zero Trust helps organizations shrink their attack surface and respond to threats faster, but many still struggle to implement it because their security tools don’t share signals reliably. 88% of organizations admit they’ve suffered significant challenges in trying to implement such approaches, according to Accenture. When products can’t communicate, real-time access decisions break down. The

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google on Monday announced a set of new security features in Chrome, following the company’s addition of agentic artificial intelligence (AI) capabilities to the web browser. To that end, the tech giant said it has implemented layered defenses to make it harder for bad actors to exploit indirect prompt injections that arise as a result of exposure to untrusted web content and inflict harm. Chief

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Canadian organizations have emerged as the focus of a targeted cyber campaign orchestrated by a threat activity cluster known as STAC6565. Cybersecurity company Sophos said it investigated almost 40 intrusions linked to the threat actor between February 2024 and August 2025. The campaign is assessed with high confidence to share overlaps with a hacking group known as Gold Blade, which is also

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered two new extensions on Microsoft Visual Studio Code (VS Code) Marketplace that are designed to infect developer machines with stealer malware. The VS Code extensions masquerade as a premium dark theme and an artificial intelligence (AI)-powered coding assistant, but, in actuality, harbor covert functionality to download additional payloads, take

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶