• A significant issue has been disclosed that affects multiple versions of the identity and access management platform.

    The flaw stems from a hardcoded default encryption key used for password storage, allowing attackers with database access to recover plaintext passwords.

    The vulnerability impacts Apache Syncope when configured to store user passwords in the internal database with AES encryption.

    Apache Syncope Vulnerability

    While this configuration option is not enabled by default, organizations that have specifically enabled this feature face a serious risk.

    When AES encryption is active, the system relies on a hardcoded default key value embedded directly in the source code.

    This design flaw means that any attacker gaining access to the internal database can easily reconstruct the original cleartext password values using the publicly known default encryption key.

    The vulnerability does not affect encrypted plain attributes, which use a separate AES encryption mechanism and remain secure even in compromised scenarios.

    ParameterDetails
    CVE IDCVE-2025-65998
    Vulnerability TitleApache Syncope Hardcoded Encryption Key Allows Password Recovery
    Affected ProductsApache Syncope (org.apache.syncope.core:syncope-core-spring)
    Vulnerability TypeUse of Hardcoded Cryptographic Key (CWE-798)
    ImpactConfidentiality Breach – Password Recovery
    CVSS v3.1 Base Score7.5 (High) – Database Compromise

    Organizations running these versions with AES password encryption enabled should prioritize immediate remediation. Apache Syncope has released patched versions addressing this vulnerability.

    Users should upgrade to version 3.0.15 or 4.0.3, which completely fixes this issue. Administrators should first inventory their deployments to identify whether AES password encryption is currently enabled.

    If enabled, upgrading to the patched versions is critical to prevent password compromise. This vulnerability has a significant severity rating due to its potential for widespread credential theft.

    Any attacker with database access can leverage the hardcoded encryption key to decrypt stored passwords, potentially compromising all user accounts in affected systems.

    This is particularly dangerous for organizations that manage large user populations or handle sensitive identity data.

    Organizations using Apache Syncope should immediately review their encryption configuration and apply the latest security patches.

    Security teams should also conduct password audits for users whose credentials may have been exposed during the vulnerable period.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Apache Syncope Vulnerability Allows Attacker to Access Internal Database Content appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Air Force aims to keep its aging C-5 and C-17 airlifters flying years longer than planned as it awaits a next-gen replacement, officials said in recently released documents. That’s alarming some former mobility leaders.

    A Nov. 19 solicitation memo says the C-5 Galaxy will fly until 2045 and the C-17 Globemaster until 2075, longer than previously planned, to ensure that the Air Force has enough airlift capacity while it waits for the Next-Generation Airlift aircraft. 

    NGAL is to reach production no earlier than 2038 and initial operating capacity three years after that. “To mitigate risks associated with acquisition delays, funding uncertainties, or technological challenges, the existing C-5M and C-17A fleets’ operational viability must be maintained until a fully capable replacement is fielded, which may require extending the service life and associated Military Type Certificate (MTC) of each platform,” the memo states.

    The plan is to retire one C-5 as each new NGAL arrives, then do the same with the C-17s.

    But keeping some of the Air Force’s oldest transport airframes in the skies is already a major effort, former service officials told Defense One. Maintenance hurdles, mission-capability rates, and recent mishap stats add to the concerns.

    “Why would this approach to this old problem deliver a different result than what has already happened?” said Mike Minihan, who retired last year after leading Air Mobility Command. “Have we done the analysis to ensure that the capability that we're delivering with this upgrade is actually what the warfighter needs?”

    Minihan said he supports the Air Force’s efforts to field NGAL. (In May, he became an adviser to Radia, which aims to field the world’s largest cargo plane.) He also praised the memo’s acknowledgement that “uninterrupted inter-theater airlift capacity is paramount for global operations,” 

    But Minihan said the service needs to prioritize its future airlift capabilities, not just modernizing aging aircraft.

    “I'm extremely worried about what I call the equilibrium. The equilibrium between the force that supports and the force that needs supporting, or the strike forces,” Minihan said. “So you're going to have fifth- and sixth-generation bombers and fighters, and you're still on generation-two airlifters and tankers.”

    The C-5 entered service in 1970. After the AIr Force concluded in 2004 that the Galaxy still had decades of life, the remaining 52 airframes were re-engined and upgraded between 2006 and 2018. But last year, the type managed only a 48 percent mission-capable rate, thanks to  maintenance and supply-chain problems that kept some airframes in the depot for 900 days. The Air Force Life Cycle Management even started a campaign, “Drive to 55.” to boost that rate to 55 percent. 

    Minihan has publicly argued that the Air Force should sell its C-5s to private companies, then charter them from time to time, as a way to “relieve the C-17.”

    The C-17, which entered service in 1995, has a more reliable mission-capable rate of 75 percent. But in the past four years, Globemasters have been involved in 21 class-A mishaps—the deadliest and costliest incidents—more than any of the military’s most-used planes.

    Jessica Ruttenber, a former Air Force pilot and program manager who oversaw the C-5 and C-17 portfolios, said she was unsurprised by the service’s call to extend the life of the two transports, but said the cost of doing so would continue to be high.

    “It’s a grandfather jet, so it doesn’t surprise me one bit,” Ruttenber said. “The thing that concerns me for the C-5 and the C-17…is the maintenance cost and the upkeep.”

    Responses to the NGAL solicitation are due in about two months, and the analysis of alternatives is to take place in 2027, the memo said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russia’s war on Ukraine has yielded troves of battlefield data, but Kyiv has no efficient way to share it with NATO friends. The alliance aims to fix that in the new year.

    “Ukraine has a lot of data that they want to give to NATO” as part of a joint training center in Poland, said Tom Goffus, the alliance’s assistant secretary general for operations, during a Missile Defense Advocacy Alliance virtual event on Monday. “We're doing a cloud solution for that…to be able to handle large amounts of data from the Ukraine battlefield. And we're hoping that it's going to be operational on NATO cloud in January of 2026.”

    The final hurdle involves process, not technology.

    “They've got all the equipment to do it,” Goffus said. “What we don't have…is we don't yet have a policy on how to accredit it. How can you accredit this system in order to use it in a safe manner? All of our tools are designed for network-centric security, and we want to go to cloud-centric security, and so that's one of our biggest challenges.” 

    The plan is to learn from big cloud service providers in the U.S. that operate classified clouds for national security. The Pentagon has also been working on improving secure communications with allies and partners. 

    “I'm going to be talking to some of the hyperscalers who have done this already in the U.S. system. There are secure clouds out there, nationally, at the secret and even higher level. So this is figuring out an accreditation process to go along with the capability and essentially get the culture, the process and the policy to catch up with what's available out there.”

    Goffus said the goal is to build everything from scratch to avoid inheriting the “limitations” of existing networks. Also, while the aim is to use commercially available systems with open architecture—that is, they can interface with products regardless of what company made them—the government has to be the owner, ultimately. 

    “It has to be brand-new. It is not system-of-systems. It's not a federated system of systems—many of our federated system-of-systems are actually proprietary, which makes it harder for things to talk to each other,” he said. “But I do want to stress that this has to, in the end, be government defined and government owned, though it is commercial solutions. And we need to be the gatekeepers on that.”

    The proliferation of data generated and used on the modern battlefield from fighter jets to drones to ships has increased the need for militaries to be able to access, analyze and transfer information quickly (even for medical responses). 

    And for NATO, the vision is to integrate the data from partner nations and provide that central cloud-based solution, Goffus said. 

    “I think NATO needs to have a cloud solution, [an] open architecture way of integrating things that the nations buy. The nations buy the sensors. They buy that sensor suite, sensor system that feeds the data. But NATO does the data integration and makes it all good,” he said. “The strategy overall right now would be more in that line, and that common funding would go to help make sure that we have that data backbone, that common data layer that everybody can pull from.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • U.S. soldiers deployed to Europe had a busy November testing out counter-drone systems that the service hopes to get into the hands of more NATO allies, as well as with units and allies as far away as the Indo-Pacific. 

    First Polish, Romanian, and American troops trained together Nov. 18 in Poland on Merops, an AI-enabled, pickup-truck-transportable system that identifies enemy drones, then launches a cheap fixed-wing drone to ram them. At the same time, the Army held Operation Flytrap 4.5 in Germany, a competition of 20 cUAS contenders in a competition for one of four $350,000 prizes.

    “It also demonstrated our capability, just as Flytrap did, to integrate with industry, to move very quickly to employ a capability that's lethal,” Brig. Gen. Curt King, who leads the 10th Army Air and Missile Defense Command in Germany, told reporters Tuesday. “It can defeat the Shahed-type threats, but also it demonstrates our ability to place capabilities that are much cheaper than some of our other previous systems that we've been using to date, to ensure that we are  able to build the capacity against the drone threats that could be placed into the air.”

    The U.S. has been using air defense systems to shoot down drones, with missiles that cost millions of dollars each. A Merops interceptor drone costs about $15,000, about half the price of the Shaheds that Ukrainians have been shooting down with it. 

    “The other thing that we demonstrated with Flytrap, and that Ukraine has shown us … is the technology is rapidly evolving so that we can get to enhanced decision aids and autonomy, which Ukraine has been rapidly developing, so that I don't need 10 soldiers to do a function,” King said. 

    Both events included the team from the Global Tactical Edge Acquisition Directorate, a nascent procurement system that plans to create a marketplace where units can buy the systems that are vetted and approved through events like Project Flytrap.

    “We're not just stopping with the counter-UAS fight,” Col. Christopher Hill, senior director of the GTEAD, told reporters. “Next up on the list is ground autonomy and ground launched effects, as I mentioned earlier, the offensive systems that we're going to use to create a dilemma for our adversaries. Then we're going to move to air autonomy and air-launched effects—again, another offensive system to provide a dilemma.”

    The team is expanding to Indo-Pacific Command early next year, Hill said.

    “We're going to replicate the same processes there in the Pacific region, in order to not only support our U.S. unit there, but also our international partners in Australia, in South Korea and in Japan, and other partners there in the region,” he said.

    Beyond demonstrations, GTEAD plans to have soldiers lead assessments and give feedback so that systems can be tweaked and then put on the marketplace.

    “On the back end of these demonstrations, be prepared, from an acquisition standpoint, to actually put dollars towards these capabilities and give these companies something to look forward to from a contract standpoint,” he said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Horsham, United Kingdom, November 25th, 2025, CyberNewsWire Detego Global, the company behind the award-winning Unified Digital Forensics Platform, is proud to announce the launch of Detego Case Manager for DFIR, a powerful, purpose-built platform designed to meet the evolving demands of digital forensics and incident response (DFIR) teams worldwide. Developed in close collaboration with investigative […]

    The post Detego Global Launches Case Management Platform for Digital Forensics and Incident Response Teams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Horsham, United Kingdom, November 25th, 2025, CyberNewsWire

    Detego Global, the company behind the award-winning Unified Digital Forensics Platform, is proud to announce the launch of Detego Case Manager for DFIR, a powerful, purpose-built platform designed to meet the evolving demands of digital forensics and incident response (DFIR) teams worldwide.

    Developed in close collaboration with investigative professionals, Detego Case Manager for DFIR addresses the real-world challenges of managing high-volume, complex digital investigations across multiple locations and touchpoints, whether on scene or in the laboratory.

    Detego Global’s new platform delivers full-spectrum case management from a tailored perspective. It brings together evidence tracking, audit logging, workflow automation, task and performance management, compliance controls, and more, all within one secure and highly auditable system.

    Team leaders and administrators can access instant metrics on all cases within seconds, providing real-time visibility into efficiency and enabling swift, data-backed decision-making.

    “We’ve worked hand in hand with digital forensic investigators, incident responders, law enforcement, military, and corporate professionals to design a platform that truly meets the operational demands they face every day,” said Alex Kirk, Global Sales Director of Detego Global.

    “Detego Case Manager for DFIR reflects the practical input of experts worldwide, combining streamlined workflows with powerful data insights and compliance features that modern investigations require.”

    Key features include:

    • Fully compliant/audit-friendly investigation management with timestamped notes and specifics, full audit trails, and an unbroken chain of custody
    • Customisable, pre-built workflows designed by DFIR experts and a visual workflow builder to streamline and accelerate investigations
    • Centralised evidence and data collection, unifying physical and digital exhibits, ISO-compliant forms, and seamless integration of evidence from third-party tools
    • Smart task management with Kanban-style tracking, automation, role-based permissions, escalation paths, and collaboration tools for full visibility and accountability
    • Entity management that maps and traces relationships across people, devices, locations, and cases to uncover hidden links and patterns
    • Built-in insights and reporting, including real-time performance metrics, case timelines, dashboards, and logs to support informed decision-making, efficient resource allocation, and early identification and elimination of bottlenecks

    The platform is available as an on-premise or cloud-hosted solution and includes optional add-ons such as custom workflow development and database integrations.

    Detego Case Manager for DFIR can be deployed rapidly, with tailored onboarding, user guides and ongoing support to ensure immediate operational impact. A fully functional 30-day trial is also available.

    Detego Case Manager for DFIR sets a new benchmark in digital investigation management, delivering control, clarity, and consistency across every stage of the forensic life cycle.

    To request a trial, users can visit: https://detegoglobal.com/cmtrial/

    https://player.vimeo.com/video/1111243018 (embedded video)

    About Detego Global

    Detego Global is the company behind the Detego Unified Digital Forensics Platform and Detego Case Manager. These solutions are trusted by military, law enforcement, and enterprise teams in more than 70 countries.

    The company’s technologies enable investigators to swiftly triage devices, rapidly extract and analyse digital evidence at scale, and streamline every aspect of investigations.

    Detego Global enables investigative teams to combat serious crimes, including child exploitation, human trafficking, terrorism, and fraud, with greater speed and accuracy.

    Contact

    Director of Marketing

    Buddhika Karunasekara

    Detego Global

    budd.karunasekara@detegoglobal.com

    The post Detego Global Launches Case Management Platform for Digital Forensics and Incident Response Teams appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A major accounting and financial services provider disclosed a significant data breach affecting client business records and sensitive corporate documents.

    The incident occurred on or about November 12, 2025, but the company only announced the breach publicly on November 22, 2025.

    The breach exposed accounting records and legal agreements belonging to SitusAMC clients. The company confirmed that specific corporate data associated with clients’ relationships with the firm was compromised.

    Client Accounting Records Compromised in Major Breach

    Additionally, data relating to some clients’ customers may have been affected, though the full scope remains under investigation.

    SitusAMC stressed that no encrypting malware was involved in the attack, and their services remain fully operational.

    The company worked with leading cybersecurity experts and federal law enforcement to contain the incident immediately after detection.

    Following the discovery, SitusAMC launched an immediate investigation with third-party security advisors and notified federal law enforcement authorities.

    The company implemented several security hardening measures, including credential resets, turning off remote access tools, updating firewall rules, and strengthening security settings across its systems.

    “We take this matter and the security of our clients’ information very seriously,” SitusAMC stated in a customer notice.

    The company maintained that all systems were secured and services remained uninterrupted throughout the incident. SitusAMC confirmed that it has directly communicated with affected clients about the breach.

    The company acknowledged that while certain client data was compromised, the specific nature and extent of the impact remain under investigation.

    Clients were instructed to contact the company’s security team at securitynotice@situsamc.com for additional information or concerns.

    The 10-day gap between discovery (November 12) and public disclosure (November 22) allowed SitusAMC time to investigate the incident and notify law enforcement before disclosing the breach.

    The company indicated it would provide additional updates as the investigation progresses and new information becomes available.

    This breach highlights the ongoing security risks facing financial services companies and the importance of robust data protection measures for firms handling sensitive accounting and legal documents.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Retail Finance Giant SitusAMC Data Breach Exposes Accounting Records and Legal Agreements appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New research has found that organizations in various sensitive sectors, including governments, telecoms, and critical infrastructure, are pasting passwords and credentials into online tools like JSONformatter and CodeBeautify that are used to format and validate code. Cybersecurity company watchTowr Labs said it captured a dataset of over 80,000 files on these sites, uncovering thousands of

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A non-profit dental insurance provider based in Roanoke, Virginia, disclosed a significant data breach affecting over 145,900 individuals.

    The external system breach exposed customers’ personal information, prompting immediate notification and protective measures.

    The breach occurred on March 21, 2025, but wasn’t discovered until August 22, 2025, a delay of over five months. This extended detection window raised concerns about the organization’s security monitoring capabilities.

    Delta Dental notified affected consumers on November 21, 2025, through written notices, providing customers with critical information about the incident and available protections.

    Healthcare Data Incident Impacts

    The compromised personal details included names and additional personal identifiers, though specific data elements remain partially redacted in public disclosures. The breach affected 145,918 individuals across multiple states, including 222 Maine residents.

    The external hacking attack targeted Delta Dental’s systems, allowing unauthorized access to sensitive customer information stored on their network.

    Recognizing the severity of the incident, Delta Dental of Virginia partnered with TransUnion to offer complimentary identity theft and credit protection services to affected customers.

    This proactive approach helps customers monitor their financial accounts and detect any suspicious activity resulting from the compromised information.

    The organization’s legal representatives, including attorney Lindsay Nickle from Constangy, Brooks, Smith & Prophete, LLP, coordinated the breach notification process with state regulators and affected consumers.

    Regulatory notification requirements were met, with formal notices filed in states where residents were affected, including Maine.

    The incident highlights ongoing vulnerabilities in healthcare and insurance industry systems. The months-long detection delay suggests potential gaps in security monitoring and incident response procedures.

    How Is Delta Dental Responding

    Delta Dental’s breach joins growing numbers of healthcare-related data incidents affecting millions annually.

    Organizations in this sector remain attractive targets for cybercriminals seeking valuable personal and medical information for identity theft, fraud, and resale on underground markets.

    Affected individuals should regularly monitor their credit reports, consider placing fraud alerts with the credit bureaus, and take advantage of TransUnion’s protection services.

    Consumers should remain vigilant for phishing attempts and suspicious communications referencing the breach, as fraudsters often exploit incidents to target victims further.

    The incident underscores the importance of robust cybersecurity practices, including regular security assessments, employee training, and rapid incident detection and response capabilities within healthcare and insurance organizations.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Delta Dental of Virginia Data Breach Exposes 146,000+ Customers Personal Details appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Developing: United States and Ukrainian officials have made some progress in talks to wind down Russia’s Ukraine invasion, Kyiv’s national security advisor announced Tuesday morning. “Our delegations reached a common understanding on the core terms of the agreement discussed in Geneva,” said Rustem Umerov, writing on social media. “We now count on the support of our European partners” and “look forward to organizing a visit of Ukraine’s President to the US at the earliest suitable date in November to complete final steps and make a deal with President Trump,” he said. 

    It’s unclear just yet what terms the U.S. and Ukrainians agreed to on Monday. (The Washington-based Institute for the Study of War rounded up various reports from European and U.S. press with a variety of possible suggestions at play, here.) President Trump’s negotiator Steve Witkoff reportedly drafted a 28-point framework document alongside his Russian counterpart last month. After removing elements unrelated to Ukraine, those 28 points were reduced to 19 on Monday, according to the Financial Times and Washington Post

    The U.S. side included Army Secretary Dan Driscoll, who met late Monday and into Tuesday with Russian negotiators in Abu Dhabi, Reuters reports. 

    Ukrainian President Volodymir Zelenskyy hasn’t yet confirmed his full support for a U.S.-brokered peace plan, writing on social media Tuesday four hours after Umerov’s message, “Communication with the American side continues, and I am grateful for all of America’s efforts and personally for President Trump’s efforts.”

    Meanwhile, Russian attacks on Ukraine continue, with at least seven people killed in the capital city of Kyiv during overnight strikes involving 460 drones and at least 22 missiles, the Associated Press reports, citing Ukrainian officials. The attacks left more than 100,000 people without power across five regions of Ukraine. 

    “Neighboring countries Romania and Moldova reported that a handful of drones violated their airspace, with one each landing on their territory,” AP writes. Reuters has a bit more on that. 

    Zelenskyy: “If there are negotiations, if there is constructive engagement, if we are truly ending the war—then there must be no missiles, no massive strikes on Ukraine, on our people,” the Ukrainian president said Monday evening on social media. “This can indeed be ensured by those who are really strong in the world. And much depends on America. Russia started this war, and it is Russia that must end it,” he stressed. 

    Counter-drone warfare at scale is getting a little closer, as shown by a recent demonstration in northern Germany last week. The U.S. Army’s Project Flytrap assembled 20 vendors of anti-drone sensors, systems, and weapons—and within days, had an on-site network up and running. 

    Reporting from Truppenübungsplatz Putlos Training Ground: “In a grassy field near the Baltic Sea, U.S. soldiers used net-shooting hunter drones, specially outfitted 557 rifles, and .50-caliber machine guns to drop dozens of drones, large and small, into the cold mud. For the U.S. Army, the daylong event marked the beginning of the end of firing $4-million missiles at $20,000 drones; for its European counterparts, it showed off options to counter Russia’s accelerating threat,” writes Defense One’s Patrick Tucker, here.

    Related reading: 


    Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1864, eight arsonists aligned with the Confederacy tried but failed to burn down New York City. 

    Around the Defense Department

    Monitoring: The U.S. military’s Southern Command is allegedly “restricting [or] limiting leave over the Thanksgiving and Christmas holidays, in preparation for possible land strikes in the next 10 days to two weeks,” Kellie Meyer of NewsNation reported on social media Monday. 

    Meanwhile: Trump reportedly says he’s ready to speak with Venezuelan dictator Nicholas Maduro, Marc Caputo of Axios reported Monday. “Word of Trump's interest in talking coincides with the State Department's decision Monday to label an alleged drug cartel in Venezuela as a ‘Foreign Terrorist Organization,’ which provides the U.S. more of a pretext to take military action in and around the South American nation.” 

    It also follows a trip to Puerto Rico by Joint Chiefs Chairman Gen. Dan Caine on Monday, “Caine’s second visit to the region since the U.S. military started building up its presence, which now includes the nation’s most advanced aircraft carrier,” AP reports. 

    Trump’s Pentagon says it will investigate former astronaut and current Sen. Mark Kelly, D-Ariz., over his participation in a video last week urging troops to refuse “illegal orders.” The Defense Department announced on Twitter Monday that “military retirees remain subject to the UCMJ for applicable offenses, and federal laws such as 18 U.S.C. § 2387 prohibit actions intended to interfere with the loyalty, morale, or good order and discipline of the armed forces. Any violations will be addressed through appropriate legal channels.” 

    Defense Secretary Pete Hegseth chimed in, too, calling the lawmakers in last week’s video the “Seditious Six.” According to Hegseth, “Five of the six individuals in that video do not fall under [Defense Department] jurisdiction (one is CIA and four are former military but not ‘retired’…However, Mark Kelly (retired Navy Commander) is still subject to [Uniform Code of Military Justice]—and he knows that.” 

    Legal expert reax: “Having a United States senator subject to discipline at the behest of the secretary of defense and the president—that violates a core principle of legislative independence,” Georgia State University constitutional law professor Anthony Michael Kreis told AP. “Any way you cut it, the Constitution is fundamentally structurally designed to prevent this kind of abuse from happening.”

    Historian reax: For the White House, “It’s a convoluted argument, one that administration officials are using to claim that the lawmakers’ reminder that troops must not obey an unlawful order is actually encouragement not to obey lawful orders,” Heather Cox Richardson of Boston College wrote Monday. But “Attacking Kelly appeals to Trump’s base” in part because “Turning to military tribunals harks back to QAnon, a conspiracy theory that took off in 2017. It maintained Trump was leading a fight against an international ring of pedophiles that he would bring to justice through military tribunals.”

    Kelly’s response: “If this is meant to intimidate me and other members of Congress from doing our jobs and holding this administration accountable, it won’t work. I’ve given too much to this country to be silenced by bullies who care more about their own power than protecting the Constitution,” he said in a statement Monday. 

    Hegseth responded again on social media Tuesday morning, threatening the much-decorated Kelly with a uniform inspection. 

    Foreign spies see opportunity in fed workers' uncertainty, warns Army deputy chief for intelligence. In a Nov. 13 message to more than a million soldiers, civilian employees, and family members, Lt. Gen. Anthony R. Hale warned against foreign agents pretending to offer jobs or other deals.

    Why now? “Especially in the context of the recent lapse in appropriations and government shutdown, our adversaries are looking online to identify individuals seeking new employment opportunities, expressing dissatisfaction or describing financial insecurity,” Hale said. Nextgov’s David Dimolfetta has more, here.

    China

    China is building a “counter-AI warfare” playbook. “The People’s Liberation Army is teaching troops to fight the model as much as the soldier. Forces are learning to alter how vehicles appear to cameras, radar, and heat sensors so the AI misidentifies them, to feed junk or poisoned data into an opponent’s pipeline, and to swamp battlefield computers with noise. Leaders are drilling their own teams to spot when their own machines are wrong. The goal is simple: make an enemy’s military AI chase phantoms and miss the real threat,” write BluePath Labs’ Tye Graham and New America’s Peter Singer in the latest edition of The China Intelligence column. 

    Also: Trump said he spoke with Xi Monday, and that the two leaders will host reciprocal visits next year. 

    Related reading:

    Trump 2.0

    Update: DOGE is no longer a “centralized entity” with “centralized leadership,” the head of the government’s personnel agency told Reuters. But the principles of the Department of Government Efficiency office “remain alive and well,” and the White House’s DOGE tech team continues to work on technology modernization projects throughout federal agencies. Nextgov’s Natalie Alms has more, here

    And from the seemingly ever-expanding world of social media,America’s Polarization Has Become the World's Side Hustle,” 404 Media reported Monday after a Twitter update apparently revealed the locations of many top users and influencers—showing, e.g., that most do not seem to reside inside the U.S. at all. “A huge amount of the viral content about American politics and American news on social media is from sock puppet and bot accounts monetized by people in other countries,” Jason Koebler of 404 writes. 

    What’s going on? “The rise of easy to use, free AI generative tools have supercharged this effort, and social media monetization programs have incentivized this effort and are almost entirely to blame.” The Atlantic’s Charlie Warzel has more on the topic, here.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶