• U.S. national security requires three deployed ARG/MEUs, Marine Corps commandant argues in Defense One. That’s Amphibious Ready Groups and Marine Expeditionary Units, like the one built around the amphibious assault ship Iwo Jima that has been sailing in the Caribbean since August.

    Once the United States could keep three such groups at sea, ready to respond to conflict or other need, Gen. Eric Smith writes. “But as the nation focused on extended land campaigns in the Middle East, the amphibious fleet was deprioritized. By 1997, that number had dropped to 40, and by 2016 it stood at just 31. Today the amphibious fleet has 32 ships whose average readiness hovers around 45 percent. Shipyards are strained, timelines are slipping, and hulls are aging faster than we can replace them.

    Sustaining a 3.0 ARG/MEU presence will require 31 amphibious ships at 80 percent readiness. The recent LHA/LPD block buy was a step in the right direction, but we must continue to build on this momentum.” Read how, here.

    Developing: Former U.S. military bases in Panama and Puerto Rico are returning to service as the Trump administration eyes possible military action in Venezuela amid its new war on alleged drug trafficking-boats around Latin America, Task & Purpose reported Friday. 

    This includes Naval Station Roosevelt Roads in Puerto Rico and Fort Sherman in Panama. If these sound familiar, Reuters mapped the ongoing U.S. military build-up in the region in a special report published two weeks ago, here

    Update: The Pentagon wanted to stage at an old base in Ecuador but voters there rejected the proposal on Sunday, AP reports from Quito—calling the decision “a significant defeat for President Daniel Noboa, a conservative who is closely aligned with the Trump administration.”

    Also: The Pentagon says it killed three more people it claims were trafficking drugs on Saturday. Like nearly all the other U.S. attacks since September, this strike hit a small boat traveling off the coast of Latin America—this time on the Pacific side. That makes 21 known strikes that have killed at least 83 people. 

    ICYMI: American Marines in Haiti exchanged gunfire with suspected gang members near the U.S. Embassy in Port-au-Prince on Thursday, the Washington Post reported Saturday. 

    The Marines returned fire; none were harmed in the incident, a spokesman for the service told the Associated Press in a very brief follow-up. 


    Welcome to this Monday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1856, the U.S. Army established a post called Fort Buchanan in southern Arizona to control new land acquired from Mexico two years earlier. The fort was officially abandoned five years later. 

    Around the Defense Department

    Army unveils its own acquisition reform. Among other moves, it’s “gathering up the many offices that weigh in on requirements and stacking them under a new program office structure,” Defense One’s Meghann Myers reported on Friday. The previous dozen Program Executive Offices will be compressed under six Portfolio Acquisition Executives (Fires; Maneuver Ground; Maneuver Air; Command and Control and Counter Command and Control; Agile Sustainment and Ammo; and Layered Protection and Chemical, Biology, Radiological and Nuclear Defense). Read on, here.

    One-stop shopping for counter-drone gear? That’s what the Army’s-led Joint Interagency Task Force 401 is working on as it pushes to improve the military’s counter-drone defenses. Myers reports on that and other steps, here.

    B-21, ICBM construction projects. The deal that reopened the government included some $850 million for 11 construction projects related to the Air Force’s nascent strategic bomber and its under-development ICBM, Defense One’s Thomas Novelly reported on Friday. Learn what and where, here.

    Update: Changing the Defense Department’s name to the War Department could cost as much as $2 billion, NBC News reported Wednesday, noting this “estimate for renaming the Pentagon comes as Trump has promised to cut back on federal spending.”

    For the record, changing the actual name of the department requires an act of Congress. And while it is true that President Trump has ordered the executive branch to refer to the Defense Department as the “War Department” and to Defense Secretary Pete Hegseth as “Secretary of War,” Trump’s Sept. 5 executive order does not formally change the name of the department. 

    Trump’s own order acknowledges this, saying: “The Secretary of Defense is authorized the use of this additional secondary title—the Secretary of War—and may be recognized by that title in official correspondence, public communications, ceremonial contexts, and non-statutory documents within the executive branch.” 

    Changing “New department letterhead and signage alone could cost about $1 billion,” NBC reports. But “rewriting digital code for all of the department’s internal and external facing websites, as well as other computer software on classified and unclassified systems” could cost more, four senior congressional staffers said. 

    Survey: Do you approve of DoD to DoW name change? Overall 54% opposed while just 22% supported, with the rest undecided, according to a survey of 2,542 people by political scientists Don Casler and Robert Ralston. Only 42% of Republicans overall expressed support for the name change, they said. More, here

    Additional reading: 

    Trump 2.0

    Update: The Pentagon pulled hundreds of National Guard soldiers from Chicago and Portland beginning this weekend, ABC News reported Saturday. That includes ​​200 federalized California Guard soldiers in Portland and 200 more Texas troops sent to Chicago early last month. 

    Northern Command officials teased the reductions in a vague social media post Friday night, writing, “in the coming days, the Department will be shifting and/or rightsizing our Title 10 footprint in Portland, Los Angeles, and Chicago to ensure a constant, enduring, and long-term presence in each city.” That leaves around 300 activated Illinois Guard soldiers on standby for Chicago, and another 100 Oregon Guard troops will stay near Portland, the New York Times reported Sunday. 

    “While they deployed to the two cities, the troops never carried out operations because of several legal rulings that placed a hold on their deployment,” ABC explains. A federal judge in Portland blocked the Guard from deploying to the city after protests outside an Immigration and Customs Enforcement facility led the president to declare Portland a "war-ravaged" combat zone. The judge disagreed. Meanwhile in Illinois, an appeals court upheld a federal judge's temporary restraining order blocking those Guard troops from deploying to Chicago. That decision has now moved to the Supreme Court. 

    By the way: Less than 3% of the 600-plus people arrested during DHS’s “Operation Midway Blitz” in Chicago had criminal histories, the Chicago Tribune reported Friday, citing Justice Department statistics. 

    Related reading:Immigration crackdown inspires uniquely Chicago pushback that’s now a model for other cities,” AP reported Sunday. 

    The Border Patrol arrested 81 people on its first day of a new immigration crackdown in Charlotte, North Carolina, Reuters reported Monday. Homeland Security officials surged to the city, arresting most of those over a five-hour span Saturday in an effort dubbed “Operation Charlotte’s Web.” NPR has a short history of naming such operations, here

    Related reading:Homeland Security Missions Falter Amid Focus on Deportations,” five writers for the New York Times reported Sunday in a big-picture analysis. 

    Developing: Energy Department officials want to “tamp down Trump’s idea of explosive nuclear testing,” and they could have that conversation with National Security Council officials quite soon, CNN reported Friday. 

    The gist: “Energy Secretary Chris Wright, National Nuclear Security Administration leader Brandon M. Williams and officials from the US National Laboratories are planning to inform the White House that they do not think blowing up weapons for nuclear warhead testing, as Trump suggested last month, is tenable,” CNN reported citing two sources familiar with the matter. 

    Happening today: Trump welcomes Saudi Prime Minister Mohammed bin Salman Al Saud to the White House for talks about AI and nuclear energy, Reuters reports. AP, the New York Times and Fox have more.

    Additional reading: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Menlo Park, California, USA, November 17th, 2025, CyberNewsWire

    AccuKnox, a global leader in Zero Trust Cloud-Native Application Protection Platforms (CNAPP), today announced its distributor partnership with Frentree, a leading cybersecurity solutions provider in South Korea.

    The collaboration aims to strengthen cloud, container, and AI workload security for enterprises across the region by combining Frentree’s strong market presence with AccuKnox’s advanced Zero Trust security capabilities.

    The partnership was finalized after detailed technical and strategic discussions, during which Frentree expressed strong confidence in AccuKnox’s architecture, runtime protection depth, and alignment with Korean enterprise security needs.

    Frentree’s Decision to Partner with AccuKnox

    As cloud adoption accelerates across financial and enterprise sectors in Korea, Frentree sought a platform that could deliver comprehensive visibility, scalable runtime protection, and automated compliance across complex, hybrid environments.

    AccuKnox emerged as the ideal partner based on its engineering sophistication and its alignment with Zero Trust security models.

    Leadership Comments

    “At Frentree, we aim to introduce world-class cybersecurity technologies to Korean enterprises,” said CY Jang, CEO, Frentree.

    “AccuKnox’s platform stands out for its depth and scalability with advanced AI security. “South Korea is a highly sophisticated and discerning market,” said Nat Natraj, CEO, AccuKnox.

    Frentree has immense expertise in Cloud Security, we are very excited about our partnership with Frentree and serving clients and partners in South Korea. 

    “Our distributor partnership with Frentree is a significant step in expanding our global partner ecosystem,” added Syed Hadi, Senior Marketing Manager, AccuKnox.

    “Frentree’s strong regional presence and long-standing trust with large financial and enterprise customers make them an ideal partner for accelerating Zero Trust adoption in South Korea.”

    About Frentree

    Founded in 2013, Frentree is a cybersecurity solutions provider based in Seoul specializing in cloud security, privacy, and compliance.

    With partnerships across leading global security vendors, Frentree serves major financial institutions and enterprise customers in Korea.

    About AccuKnox

    AccuKnox is a Zero Trust CNAPP platform that delivers runtime protection, agentless risk assessment, and deep visibility across cloud, container, API and AI workloads.

    As a core contributor to CNCF open-source projects KubeArmor and ModelArmor, AccuKnox empowers enterprises to achieve measurable risk reduction and automated compliance.

    Contact

    PMM

    Syed Hadi

    AccuKnox

    syed.hadi@accuknox.com

    The post Frentree Partners with AccuKnox to Expand Zero Trust CNAPP Security in South Korea appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Menlo Park, California, USA, November 17th, 2025, CyberNewsWire AccuKnox, a global leader in Zero Trust Cloud-Native Application Protection Platforms (CNAPP), today announced its distributor partnership with Frentree, a leading cybersecurity solutions provider in South Korea. The collaboration aims to strengthen cloud, container, and AI workload security for enterprises across the region by combining Frentree’s strong […]

    The post Frentree Partners with AccuKnox to Expand Zero Trust CNAPP Security in South Korea appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new open-source security tool, TaskHound, helps penetration testers and security professionals identify high-risk Windows scheduled tasks that could expose systems to attacks.

    The tool automatically discovers tasks running with privileged accounts and stored credentials, making it a valuable addition to security assessments.

    What Makes TaskHound Different?

    TaskHound stands out by automating the discovery of dangerous scheduled tasks across Windows networks.

    Instead of manually searching through system logs, the tool scans remote machines over SMB and parses task XML files to identify security weaknesses.

    FeatureUse Case
    Tier 0 DetectionIdentify high-value administrative account exposure
    BloodHound IntegrationCorrelate tasks with attack paths for risk assessment
    Password AnalysisWork with the existing BloodHound infrastructure
    Offline AnalysisAnalyze tasks in OPSEC-conscious environments
    BOF ImplementationBeacon-based operations without direct network access
    Credential Guard DetectionEvaluate DPAPI dump success likelihood
    SID ResolutionImprove readability in mixed SID/username environments
    Multi-format SupportWork with existing BloodHound infrastructure
    Flexible AuthenticationFlexible authentication for various network scenarios
    Multiple Output FormatsIntegrate findings into security workflows and reporting

    It looks for tasks running as administrative accounts, privileged users, or Tier 0 accounts, typically the highest-value targets for attackers.

    The tool integrates with BloodHound, a popular network security visualization platform.

    This integration enables security teams to automatically correlate scheduled tasks with BloodHound’s attack path data, revealing which tasks pose the most significant risk in their environment.

    TaskHound includes several powerful features for threat hunters. It automatically detects tasks assigned to Tier 0 users, such as Domain Admins and Enterprise Admins.

    The tool analyzes when credentials were last changed compared to when tasks were created, helping identify old passwords that could be vulnerable to offline cracking.

    The platform supports both modern BloodHound Community Edition and legacy BloodHound formats, making it compatible with existing security infrastructure.

    TaskHound can also work offline, analyzing previously collected XML files without requiring direct network access.

    For operators using AdaptixC2, the tool includes a Beacon Object File implementation. During a penetration test, TaskHound quickly identifies exploitation opportunities.

    Tasks running under compromised accounts can be manipulated to gain system access.

    The tool provides detailed reporting showing task locations, associated credentials, creation dates, and recommended next steps for each finding.

    Taskhound tool output
    Taskhound tool output

    The creator emphasizes strict OPSEC (operational security) considerations. Since the tool relies on standard SMB operations, network defenders could detect its activity.

    For sensitive assessments, users can employ the standalone BOF version or manually collect tasks for offline analysis.

    The project roadmap includes a direct BloodHound database connector and a dedicated NetExec module to expand integration with other popular security frameworks.

    The GitHub developer also plans automated credential extraction for offline decryption.

    TaskHound fills an essential gap in Windows privilege-escalation assessment, automating a tedious manual process while providing actionable intelligence to security teams protecting enterprise networks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post TaskHound Tool – Detects Windows Scheduled Tasks Running with Elevated Privileges and Stored Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical logic flaw discovered in the widely used mPDF PHP library could expose internal networks and sensitive services on approximately 70 million devices worldwide. The vulnerability stems from improper regular expression parsing, which allows attackers to issue unauthorized web requests even when user input appears sanitized. mPDF, an open-source PHP library for generating PDFs […]

    The post 70 Million Devices Vulnerable Due to Logic Flaw Exposing Internal Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cyber threats don’t always come with warning signs. Sometimes, they arrive as sponsored ads. Since mid-2023, a financially motivated network has been quietly hijacking payroll systems, credit unions, and trading platforms across the United States. Their method? Malvertising. Their goal? Money. Their name? Payroll Pirates. This isn’t a one-off campaign. It’s a coordinated operation that’s […]

    The post Payroll Pirates: Inside the Criminal Networks Hijacking Payroll Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new phishing campaign has emerged that weaponizes Microsoft Entra guest user invitations to deceive recipients into making phone calls to attackers posing as Microsoft support.

    The attack leverages a critical security gap in how Microsoft Entra communicates with external users, turning a legitimate collaboration feature into a delivery mechanism for sophisticated social engineering attacks.

    This campaign represents an evolution in TOAD (Telephone Oriented Attack Delivery) tactics, combining cloud-based credential systems with traditional phone-based scams to compromise organizational security.

    Michael Taggart, a security analyst and researcher, identified this novel attack vector after discovering multiple phishing campaigns exploiting the guest invitation system.

    The malware campaign uses Microsoft Entra tenant invitations sent from the legitimate invites@microsoft[.]com address to bypass email filters and establish trust with targets.

    Attackers register fake organizational tenants with names like “Unified Workspace Team,” “CloudSync,” and “Advanced Suite Services” to impersonate legitimate Microsoft entities.

    The attack chain demonstrates sophisticated coordination between cloud infrastructure abuse and social engineering.

    Once recipients receive the invitation email, they encounter a convincing message claiming their Microsoft 365 annual plan requires renewal processing, complete with fabricated transaction details including reference numbers, customer IDs, and billing amounts of approximately $446.46.

    The message instructs users to contact a phone number listed as Microsoft Billing Support, which actually connects them directly to attackers who proceed with credential harvesting and account takeover attempts.

    Detection Evasion Through Legitimate Infrastructure

    The infection mechanism exploits a fundamental weakness in Entra’s design: the Message field in guest user invitations accepts arbitrarily long text, allowing attackers to embed extensive phishing content without triggering traditional security alerts.

    Entra Guest user invitations (Source – Taggart-Tech)

    Since the invitation originates from Microsoft’s legitimate infrastructure, email security systems rarely flag these communications as malicious.

    The attackers register multiple fake tenant domains, including x44xfqf.onmicrosoft[.]com, woodedlif.onmicrosoft[.]com, and xeyi1ba.onmicrosoft[.]com, creating a network of persistent infrastructure for continuous campaign deployment.

    Organizations should implement immediate detection measures by searching email logs for indicators, including the sender address invites@microsoft[.]com, subject line keywords like “invited you to access applications within their organization,” and known attacker tenant names.

    Network administrators can block the phone numbers associated with these campaigns while educating users about verifying Microsoft communications through official support channels rather than responding to invitation-based requests.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Hackers Leverages Microsoft Entra Tenant Invitations to Launch TOAD Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA has issued an urgent alert about a critical vulnerability in Fortinet’s FortiWeb Web Application Firewall (WAF), actively exploited by threat actors to seize administrative control of affected systems.

    Tracked as CVE-2025-64446, the flaw stems from a relative path traversal issue (CWE-23) that enables unauthenticated attackers to execute arbitrary administrative commands through specially crafted HTTP or HTTPS requests.

    Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on November 14, 2025, the vulnerability carries a due date of November 21 for federal agencies to apply mitigations or discontinue use.

    Fortinet’s advisory (FG-IR-25-910) confirms the issue affects multiple FortiWeb versions, including those running firmware up to 7.4.7 and 7.6.5. Attackers can exploit it without authentication, potentially leading to complete system compromise, data exfiltration, or deployment of malware.

    While it’s unknown whether the vulnerability has been tied to ransomware campaigns, security researchers have reported real-world exploitation in the wild targeting organizations in sectors like finance and healthcare.

    FortiWeb WAF Vulnerability Exploited in the Wild

    “This path traversal bug is a classic but dangerous oversight in file handling,” said cybersecurity expert Maria Chen, a vulnerability researcher at a leading threat intelligence firm. “Unauthenticated access to admin functions turns a WAF meant to protect web apps into a backdoor for attackers.”

    Fortinet urges immediate patching to the latest versions, such as 7.4.8 or 7.6.6, and recommends restricting administrative access via network segmentation.

    For cloud-deployed instances, CISA advises adherence to Binding Operational Directive (BOD) 22-01, which mandates timely remediation of vulnerabilities in federal systems.

    Organizations unable to patch should isolate affected devices and monitor for indicators of compromise, such as unusual HTTP traffic patterns or unauthorized command execution.

    The flaw highlights ongoing risks in network security appliances, which are prime targets for advanced persistent threats (APTs). As exploitation ramps up, experts warn that unpatched FortiWeb deployments could amplify broader attack chains, such as lateral movement in enterprise networks. Fortinet has not disclosed the initial discovery method but emphasizes that no customer data was breached during its investigation.

    With the patch deadline looming, affected users are racing to update. Delays could expose sensitive infrastructure to persistent threats, underscoring the need for proactive vulnerability management in an era of zero-day exploits.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert regarding multiple vulnerabilities affecting General Industrial Controls’ Lynx+ Gateway device. Released on November 13, 2025, under alert code ICSA-25-317-08, these flaws pose significant risks to industrial control systems. They could enable remote attackers to access sensitive information or disrupt critical operations. CVE […]

    The post CISA Alerts on Critical Lynx+ Gateway Flaw Leaks Data in Cleartext appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week showed just how fast things can go wrong when no one’s watching. Some attacks were silent and sneaky. Others used tools we trust every day — like AI, VPNs, or app stores — to cause damage without setting off alarms. It’s not just about hacking anymore. Criminals are building systems to make money, spy, or spread malware like it’s a business. And in some cases, they’re using the same

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶