• Google has released an emergency security update for Chrome across all platforms, rolling out version 142.0.7444.134 and 142.0.7444.135 to address five critical and medium-severity vulnerabilities. The update addresses urgent security concerns identified in the browser’s WebGPU implementation and other core components that could expose users to remote code execution attacks. The emergency release came on […]

    The post Google Issues Emergency Chrome Update to Fix Critical RCE Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Threat Intelligence Group (GTIG) has unveiled details of an experimental malware family called PROMPTFLUX, which leverages the company’s Gemini AI API to dynamically rewrite its own code, marking a chilling evolution in AI-assisted cyber threats.

    This development, detailed in GTIG’s latest AI Threat Tracker report released on November 4, 2025, highlights how adversaries are shifting from mere productivity tools to embedding large language models (LLMs) directly into malware for real-time adaptation and evasion.

    While still in testing phases and not yet capable of widespread compromise, PROMPTFLUX represents the first observed instance of “just-in-time” AI integration in malicious software, potentially paving the way for more autonomous attacks.​

    PROMPTFLUX operates as a VBScript-based dropper, initially masquerading as innocuous installers like “crypted_ScreenRec_webinstall” to trick users across various industries and regions.

    Its core innovation lies in the “Thinking Robot” module, which uses a hard-coded Gemini API key to query the “gemini-1.5-flash-latest” model for obfuscated VBScript code designed to bypass antivirus detection.

    PROMPTFLUX Malware Using Gemini API

    The malware prompts the LLM to generate self-contained evasion scripts, outputting only the code without extraneous text, and logs responses in a temporary file for refinement.

    In advanced variants, it rewrites its entire source code hourly, embedding the original payload, API key, and regeneration logic to create a recursive mutation cycle that ensures persistence via the Windows Startup folder.

    GTIG notes that while features like the self-update function remain commented out, indicating early development, the malware also attempts lateral spread to removable drives and network shares.

    This approach exploits AI’s generative power not just for creation, but for ongoing survival, differing from static malware that relies on fixed signatures easily detected by defenders.​

    The emergence of PROMPTFLUX aligns with a maturing cybercrime marketplace where AI tools flood underground forums, offering capabilities from deepfake generation to vulnerability exploitation at subscription prices.

    GTIG’s analysis reveals state-sponsored actors from North Korea, Iran, and China, alongside financially motivated criminals, increasingly abusing Gemini across the attack lifecycle from phishing lures to command-and-control setups.

    PROMPTFLUX Malware Using Gemini API
    PROMPTFLUX Malware Using Gemini API

    For instance, related malware like PROMPTSTEAL, linked to Russia’s APT28, queries Hugging Face’s Qwen2.5 LLM to generate reconnaissance commands disguised as image tools.

    Attackers are also employing social engineering in prompts, posing as CTF participants or students to circumvent AI safeguards and extract exploit code.

    As these tools lower barriers for novice actors, GTIG warns of heightened risks, including adaptive ransomware like PROMPTLOCK that dynamically crafts Lua scripts for encryption.

    In response, Google has swiftly disabled associated API keys and projects, while DeepMind enhances Gemini’s classifiers and model safeguards to block misuse prompts.

    The company emphasizes its commitment to responsible AI via principles that prioritize robust guardrails, sharing insights through frameworks like Secure AI (SAIF) and tools for red-teaming vulnerabilities.

    Innovations such as Big Sleep for vulnerability hunting and CodeMender for automated patching underscore efforts to counter AI threats proactively.

    Though PROMPTFLUX poses no immediate compromise risk, GTIG predicts rapid proliferation, urging organizations to monitor API abuses and adopt behavioral detection over signatures.

    As AI integrates deeper into operations, this report signals an urgent need for ecosystem-wide defenses to stay ahead of evolving adversaries.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Warns of New PROMPTFLUX Malware Using Gemini API to Rewrite its Own Source Code appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a resurgent Gootloader malware campaign employing sophisticated new evasion techniques that exploit ZIP archive manipulation to evade detection and analysis. Credit for uncovering this latest threat goes to security researcher RussianPanda and the team at Huntress, identified the campaign actively targeting victims through compromised websites. Despite previous disruption efforts earlier this […]

    The post Gootloader Returns with a New ZIP File Tactic to Conceal Malicious Payloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Tenable have uncovered a series of critical vulnerabilities in OpenAI’s ChatGPT that could allow malicious actors to steal private user data and launch attacks without any user interaction. The security flaws affect hundreds of millions of users who interact with large language models daily, raising significant concerns about the safety of AI. […]

    The post HackedGPT: New Vulnerabilities in GPT Models Allow Attackers to Launch 0-Click Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SonicWall has formally implicated state-sponsored threat actors as behind the September security breach that led to the unauthorized exposure of firewall configuration backup files. “The malicious activity – carried out by a state-sponsored threat actor – was isolated to the unauthorized access of cloud backup files from a specific cloud environment using an API call,” the company said in a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated espionage campaign targeting recruitment professionals has emerged, with the APT-C-60 threat group weaponizing VHDX files to compromise organizations.

    The threat actors impersonate job seekers in spear-phishing emails sent to recruitment staff, exploiting trust relationships to deliver malicious payloads.

    While earlier campaigns directed victims to download VHDX files from Google Drive, recent attacks have evolved to attach the malicious VHDX file directly to emails.

    Once a victim opens the weaponized VHDX file and clicks the embedded LNK file, a malicious script executes via Git, a legitimate application, initiating a multi-stage infection process that deploys sophisticated data-stealing malware.

    JPCERT analysts identified this campaign targeting East Asian regions, particularly Japan, between June and August 2025.

    The threat group demonstrates advanced operational security by leveraging legitimate services like GitHub and statcounter to maintain command-and-control infrastructure.

    The attacks showcase technical sophistication through multi-layered obfuscation techniques, including XOR encoding with the key “sgznqhtgnghvmzxponum” for initial payloads and AES-128-CBC encryption for secondary stage downloads.

    The malware identifies compromised machines using volume serial numbers and computer names, enabling precise victim tracking.

    The infection chain begins when the LNK file executes gcmd.exe, a legitimate Git component, which runs the script glog.txt stored within the VHDX file.

    This script displays a fabricated resume as a decoy while simultaneously creating WebClassUser.dat (Downloader1) and registering it in the system registry at HKCU\Software\Classes\CLSID\{566296fe-e0e8-475f-ba9c-a31ad31620b1}\InProcServer32.

    Persistence is established through COM hijacking, ensuring the malware executes automatically during system operations.

    Downloader1 communicates with statcounter using specially crafted referrer headers in the format ONLINE=>[Number1],[Number2] >> [%userprofile%] / [VolumeSerialNumber + ComputerName].

    The threat actors monitor these referrer values and upload corresponding files to GitHub repositories. Downloader1 retrieves files from URLs like https://raw.githubusercontent.com/carolab989/class2025/refs/heads/main/[VolumeSerialNumber+ComputerName].txt, which contain instructions for downloading Downloader2.

    Infection Mechanism and Payload Deployment

    The infection mechanism employs a cascading deployment strategy with multiple encoded layers.

    Downloader2 downloads and deploys SpyGlace malware, utilizing dynamic API resolution with an encoding scheme combining ADD and XOR operations.

    Flow of malware infection (Source - JPCert)
    Flow of malware infection (Source – JPCert)

    The current version applies XOR 0x05 after ADD 0x04, representing an evolution from earlier variants. Files retrieved by Downloader2 are XOR-decoded using the key “AadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE” before execution through COM hijacking.

    SpyGlace versions 3.1.12 through 3.1.14 have been observed implementing comprehensive data exfiltration capabilities through 17 distinct commands.

    The malware communicates with command-and-control servers at IP address 185.181.230.71 using modified RC4 encryption combined with BASE64 encoding.

    The modified RC4 implementation increases Key Scheduling Algorithm cycles and performs additional XOR operations.

    SpyGlace employs a characteristic encoding scheme combining single-byte XOR with SUB instructions for string obfuscation and API resolution.

    The download command retrieves encrypted files and decrypts them using AES-128-CBC with the hardcoded key B0747C82C23359D1342B47A669796989 and IV 21A44712685A8BA42985783B67883999, creating files at %temp%\wcts66889.tmp.

    The malware establishes persistence by changing its automatic execution path from %public%\AccountPictures\Default\ in version 3.1.13 to %appdata%\Microsoft\SystemCertificates\My\CPLs in version 3.1.14.

    SpyGlace implements comprehensive surveillance capabilities, including remote shell access, file manipulation, process control, disk enumeration, and automated screenshot capture through the screenupload command, which calls the Clouds.db module at %LocalAppData%\Microsoft\Windows\Clouds\Clouds.db with the export function mssc1.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has rolled out an urgent security patch for its Chrome browser, addressing five vulnerabilities that could enable attackers to execute malicious code remotely.

    The update, version 142.0.7444.134/.135 for Windows, 142.0.7444.135 for macOS, and 142.0.7444.134 for Linux, targets critical flaws in core components like WebGPU and the V8 JavaScript engine.

    The patch arrives amid heightened scrutiny of browser security, as WebGPU, a modern API for GPU-accelerated web applications, has become a prime target for sophisticated exploits.

    Remote code execution vulnerabilities in such components could allow malicious websites to hijack user systems without any interaction beyond visiting a compromised page.

    Google emphasized that the fixes were developed in collaboration with external researchers, preventing these issues from reaching a wider audience. The update will propagate gradually over the coming days and weeks to ensure stability across millions of devices worldwide.

    Key Vulnerabilities Patched in Chrome 142

    Among the five security fixes, three stand out for their high severity, including the out-of-bounds write in WebGPU and inappropriate implementations in V8 and Views.

    These flaws, if unpatched, could lead to memory corruption, enabling attackers to run arbitrary code, steal sensitive data, or install malware. The remaining two medium-severity issues affect the Omnibox address bar, potentially exposing users to phishing or injection risks.

    For a detailed breakdown, the following table summarizes the CVEs, their severity, affected components, and technical details based on Google’s disclosures:

    CVE IDSeverityAffected ComponentDescription and ImpactCVSS v3.1 Score (Estimated)Reported ByDate Reported
    CVE-2025-12725HighWebGPUOut-of-bounds write flaw allowing memory corruption and remote code execution via malicious web content. Affects rendering of GPU-accelerated graphics in web apps.8.8 (High)Anonymous2025-09-09
    CVE-2025-12726HighViewsInappropriate implementation leading to UI manipulation and potential remote code execution through crafted web pages. Impacts browser’s visual rendering engine.8.1 (High)Alesandro Ortiz2025-09-25
    CVE-2025-12727HighV8Inappropriate implementation in JavaScript engine enabling heap corruption and remote code execution. Exploitable via specially crafted scripts on websites.8.8 (High)303f06e32025-10-23
    CVE-2025-12728MediumOmniboxInappropriate implementation allowing address bar spoofing, which could facilitate phishing attacks. No direct code execution but aids social engineering.6.5 (Medium)Hafiizh2025-10-16
    CVE-2025-12729MediumOmniboxSimilar implementation flaw in address bar, enabling URL manipulation for deceptive user interfaces.6.1 (Medium)Khalil Zhani2025-10-23

    These estimates for CVSS scores align with typical ratings for similar browser flaws, emphasizing the urgency of the high-severity issues. Google has restricted full bug details until most users update, a standard practice to limit exploit development.

    This update highlights the vulnerabilities inherent in modern web standards like WebGPU, which promise enhanced performance for gaming and AI applications but introduce new attack surfaces.

    V8, powering Chrome’s JavaScript execution, remains a frequent target due to its ubiquity across web ecosystems. Security tools such as AddressSanitizer and libFuzzer played a crucial role in detecting these bugs during development, showcasing proactive measures in Chromium’s pipeline.

    Users should immediately check for updates via Chrome’s settings menu under “About Chrome” to apply the patch. Enterprises relying on Chrome for corporate environments are advised to enforce auto-updates and monitor for signs of exploitation, such as unusual browser crashes or network anomalies.

    As cyber threats evolve, this incident serves as a reminder of the importance of timely patching in safeguarding digital lives.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—Pacific Air Forces’s massive REFORPAC exercise in the Pacific this summer “identified the capabilities that we need to win in this theater,” the command’s deputy leader said last week: namely, artificial intelligence, autonomy, machine learning; improved command and control capabilities; and resilient cyber networks “that can communicate securely in expeditionary environments and survive relentless attacks.”

    Speaking at the AFCEA TechNet Indo-Pacific conference, Lt. Gen. Laura Lenderman said that while “revisionist autocracies” want to “upend the security, freedom, and prosperity” of the Indo-Pacific, there is “another chapter we’re writing…filled with optimism and clarity, that strengthens deterrence, inspires progress and reinforces our shared vision of the future.” 

    That vision was “on full display” during Exercise Resolute Pacific, Lenderman said.

    The exercise included 4,000 sorties at 50 locations that spanned 6,000 miles. Shortly after it kicked off in July, Pacific Air Forces Commander Gen. Kevin Schneider said in an interview that this region “is critically important, not only to the nations in the region that touch the Pacific Ocean, but to the world.”

    However, Schneider said, “from an operational perspective, the geography of this theater is incredibly challenging…so, our ability to command and control, to operate, to move with speed, scale, and agility across the vastness of this area is probably the most challenging thing that we do in not only the United States Air Force, but across all branches of the United States military.”

    Maj. Gen. Anthony Mastalir, who was then commander of U.S. Space Forces Indo-Pacific, noted in the same July interview that space capabilities are also critical in the theater.

    “If you’re going to project power, you have to have space. Space is the force multiplier that will allow us to project power great distances. So being able to close those gaps over the vast Pacific Ocean…in this theater, space superiority over the INDOPACOM AOR is a precondition for Joint Force success, period.”

    In REFORPAC and Resolute Space, an exercise that ran concurrently, tested the ability of airmen and guardians “to conduct sustained, complex military operations involving large numbers of forces in situations where we contested air and space superiority, power projection, and global mobility, Lenderman said.

    It was also critical training, Command Sgt. Major Katie McCool, command chief for Pacific Air Forces, said in July. “We want our airmen to be prepared on Day One to go into any type of contingency and be able to execute,” she said. And while those airmen and guardians are learn concepts and tactics in their initial training, “you cannot recreate the conditions there that we have here, from small islands to Alaska.”

    Command Sgt. Maj. Jason Childers, the senior enlisted leader for U.S. Space Forces Indo-Pacific, had a similar take.

    “You have Guardians that usually sit inside of ops centers located and distributed around the world, often not even seeing the light of day, working 24/7, operating systems that are in the space domain, so they can’t really see, taste, touch, hear, or smell the environment that they’re operating in. So, to be able to conduct exercises like this… certainly helps to robust and enhance our readiness.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • When Defense Secretary Pete Hegseth takes the National War College stage to talk about proposed acquisition reforms on Friday, he will have the full attention of many companies aiming to boost their sales to the Pentagon. The list includes both newer and more established defense contractors, as well as notable consumer tech companies like Facebook parent company Meta and consumer AI company Anthropic. 

    At least some of Hegseth’s proposed changes are laid out in a six-page draft memo to senior Pentagon leaders, combatant commanders, and defense agency directors. Defense One obtained a copy of the draft memo, which has been circulating in the runup to his Nov. 7 speech. Six of the company invitees, under condition of anonymity, did tell Defense One that they plan to attend the event. An official at one attending company said the expectation among the invitees is that it would be a “listening session,” (similar to the speech Hegseth delivered to a room of reticent general and flag officers in September.)

    The memo, which draws attention to “unacceptably slow acquisition fielding times” represents a dramatic restructuring of the way the Pentagon buys and builds things, moving away from the sorts of large-scale, multi-year programs that produce fighter jets, aircraft carriers, tanks, and personnel carriers, toward smaller, faster contracting vehicles, which are more representative of software design and re-design. 

    The list includes the so-called prime defense contractors such as Lockheed Martin, Northrop Grumman, GDIT, and Boeing. But it also includes a good sampling of the newer defense startups, such as ShieldAI, which specializes in drones as well as autonomy software, and drone-maker Anduril. Both work in an ongoing way with Ukrainians, who are forced to update and change drone designs and tactics at speeds far faster than the typical plodding pace of established defense contractors working with the government. 

    Major cloud companies such as Google, Microsoft, AWS, and Oracle are also on the list, and are all part of the Pentagon’s $9 billion dollar Joint Warfighting Cloud Capability cloud contract and data software maker Palantir. Among the other notable invitees are AI company Anthropic, which, along with Google Cloud and others, received $200 million from the Pentagon in July for AI research efforts, and Meta.

    Among the invitees: 

    1. Anduril Industries
    2. Anthropic 
    3. Amazon Web Services (AWS)
    4. BAE Systems
    5. Boeing
    6. Castelion
    7. Divergent 
    8. EaglePicher Technologies 
    9. Epirus 
    10. General Dynamics 
    11. Google Cloud 
    12. Google Public Sector
    13. HII (Huntington Ingalls Industries) 
    14. Honeywell International
    15. Hermeus
    16. Karman Space & Defense
    17. L3Harris Technologies 
    18. Leidos
    19. Lockheed Martin 
    20. Meta (Facebook)
    21. Microsoft
    22. Nammo Defense Systems
    23. Northrop Grumman
    24. Oracle
    25. Pacific Scientific Energetic Materials
    26. Palantir Technologies
    27. Rivet Industries
    28. RTX (Raytheon Technologies)
    29. Saronic Technologies
    30. Shield AI
    31. Sierra Nevada Corporation (SNC)
    32. SpaceX 
    33. Textron Inc.
    34. Ursa Major Technologies

    Frank Konkel contributed to this post.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Some experts see promise in the sweeping acquisition reforms prescribed by a draft Pentagon memo that is circulating ahead of the defense secretary’s planned Friday speech on the topic, but others see risk.

    Defense One reviewed and verified a copy of the six-page draft on Tuesday, which pitched the overhaul as a “historic opportunity to restore deterrence in the face of an increasingly dangerous security environment” by cutting internal review processes, reorganizing acquisitions efforts, and doling out harsher punishments for companies that go over budget on defense contracts. 

    Kingsley Wilson, a Pentagon spokesperson, said the Defense Department would not comment on the “pre-decisional” document. 

    The draft memo, addressed to combatant commanders and senior Pentagon leaders, says, “Today’s unacceptably slow acquisition fielding times stem from three systemic challenges: fragmented accountability where no single leader can make trades between speed, performance and cost; broken incentives that reward completely satisfying every specification at significant cost to on time delivery; and procurement patterns that disincentivize industry investment, leading to constrained industrial capacity that cannot surge or adapt quickly.”

    The draft memo lays out several initiatives, including creating “Portfolio Acquisition Executives” who will have more autonomy over major program decisions, relying on “scorecards” to evaluate each portfolio’s progress, and levying “time-indexed incentives” to keep defense contractors on time and on budget. It also orders the office of the defense undersecretary for acquisition and sustainment to issue guidance for cross-cutting transformation within 45 days. Within 60 days, each military department is required to submit their implementation plans.

    Politico first reported on the draft memo, which has emerged ahead of Defense Secretary Pete Hegseth’s scheduled address to top defense industry leaders on Friday. The Trump administration has made acquisition reform a top priority, with a Pentagon memo on fast software buying and a flurry of White House executive orders earlier this year. 

    Lawmakers, defense-budget analysts, and former officials say the acquisition process has long needed an overhaul. Many defense programs blow their budgets and schedules. Last year, the Air Force’s Sentinel ICBM program ran 81 percent over initial cost estimates, breaking the Nunn-McCurdy Act threshold. Before that, the Pentagon paid Lockheed Martin on-time bonuses for F-35s delivered late.

    But some said methods prescribed in the draft memo could reduce the quality of procured goods and lead to more, not fewer, cost overruns.

    Todd Harrison, a defense budgeting expert and senior fellow at the American Enterprise Institute, pointed to the “time-indexed incentives” espoused in the memo.

    “That is a huge change from things like fixed-price contracts that incentivize controlling costs,” Harrison said. “It's a big shift towards holding contractors responsible for keeping to schedule, but it comes with some big risks. It may incentivize companies to deliver poor-quality products before they are ready for prime time just to stay on schedule and not be penalized for being late.”

    One former defense official had “some concerns” about the discouragement of Federal Acquisition Regulation-based contracts, which they said could lead companies to promise unrealistically quick deliveries.

    “I'm not sure, honestly, that it's going to have the desired effects, but I do think that that's notable,” the official said. 

    Change on the horizon?

    But others hailed the memo’s emphasis on a more portfolio-based approach, which is intended to enable smoother shifting of money between programs as technology and needs change. 

    Arnold Punaro, a defense consultant and former staff director for the Senate Armed Services Committee, welcomed the “ambitious” suite of reforms outlined in the memo, along with recent changes to federal acquisition regulations and the requirements process and yet more changes proposed in the draft National Defense Authorization Act.

    "If fully implemented, these reforms will finally break the long-standing paradigm that has defined and constrained defense acquisition for decades and replace it with a model that delivers greater capability, faster, and at lower cost,” Punaro said by email.

    Lawmakers in Congress have long called for acquisition reforms, though they have also expressed reluctance to allow the Pentagon to move money around without their approval.

    Rep. Donald Norcross, D-New Jersey, told Defense One that fellow members of the House Armed Services Committee have been working for nearly two years on defense acquisition reform, but also highlighted the need to keep costs low and quality high.

    “It is encouraging to see that the Secretary of Defense wants to improve the speed at which we deliver capabilities to our warfighters, a critical national security challenge in need of reform,” Norcorss told Defense One in an emailed statement, “but we cannot lose sight of the importance of also delivering better capabilities at a reasonable cost to American taxpayers."

    Overall, the memo echoes recommendations various people and organizations have offered over the years. But there’s still a “bold” element, especially in the tight implementation timelines, said Eric Fanning, the president and chief executive officer of the Aerospace Industries Association.

    “As we're looking at this, there's not necessarily any big, new things [the administration] haven't been talking about already. But it's still bold because they have packaged it together, to me, in a really interesting, exciting way. There's no ‘new industry versus old industry.’ There's no ‘government versus the industrial base.’ It's a forward-looking draft that has a lot of things in it that I think Pentagon officials, acquisition officials have been excited about [across] administrations—from both parties—for a long time,” Fanning said. “I think they're focused on the right things: accountability, incentives, and procurement patterns.” 

    That means driving the defense industrial base and government workers to move quickly, while also encouraging private investment. 

    “We've got a system right now that discourages investment because they don't know if there's a return on investment over the horizon. So I read the memo and got pretty excited about it,” Fanning said. 

    A new incentive structure could foster more competition, holding companies accountable for program delays and push the Pentagon to eliminate chokepoints on their side. 

    “It's okay to penalize [a company for] being behind schedule if there's two elements to it: the Pentagon is balancing a reward for being ahead of schedule and, if there’s a delay, the Pentagon is bringing that company in and saying ‘you're behind schedule, tell me why’” and then if it’s the government’s fault saying “we'll fix that.”

    That dovetails into the memo’s directive to shake up how the Pentagon trains contracting workers.

    “You need to teach the Pentagon workforce what authorities they have, teach them that they're going to be held accountable for delivery…because that's really what's going to be the most critical. And so when you're holding companies accountable for timelines, you're also holding yourself accountable for timelines hopefully,” Fanning said.

    And if it works the result will be “everybody identifying what is slowing you down instead of what could go wrong.” 

    OTAs and other changes

    Other pointed to other important changes: a mandate for dual-sourcing many purchases, so multiple contractors can provide urgently needed technologies; much greater use of fast-track contracting methods like Other Transactions Authorities that use smaller awards to bypass traditional rules and get money to contractors faster; and preference for modular, open-source designs, which are more adaptable and much more in line with the way the tech community designs software. 

    A former Defense Department official said of the new provisions in the memo, “this was necessary and we are headed in the right direction.” 

    A former military official who worked in drone design and purchasing described the new draft guidance as a long-overdue fix for slow, out-of-date processes, as in old rules that protect established defense prime contractors and shut smaller, more innovative players out of the Pentagon. The former official described themselves as “salty” on the issue after seeing how DOD's method of buying and building slowed the deployment of vital arms and gear.

    These longstanding problems are exemplified by the many easily-defeatable drones that the United States has sent to Ukraine, the former official said. 

    “I've got pictures on pictures on Signal of warehouses” full of useless donated drones, he said. “They'd rather have it, even if only 10 percent of it works. They'll accept the other 90 percent of the garbage because they need it that bad.” 

    What new startups have long needed, the former official said, was “top cover” for risk-taking from the department. They pointed to the Defense Innovation Unit and the Fuze and University Accelerator efforts as vital Band-Aids. 

    The former official also said DOD often fails to provide clear demand signals, making it nearly impossible for companies to plan for workforce needs. 

    “No responsible executive wants to hire hundreds of people just to lay them off when Congress can’t pass a budget,” they said.

    It’s just one of the ways the Pentagon’s buying process crowds out small, innovative companies in favor of larger companies that have the workforce and processes to weather lags in budget approval.

    A boost to new players

    The new guidance follows two other key steps the Pentagon has taken to speed tech buying; a March memo that prioritizes the purchase of dual-use technology and already-built software over software that the Pentagon would pay a contractor to write and implement for them, and July guidance that gave battalion-level commanders far more authority and influence over what they purchase by re-categorizing various types of weapons, such as drones, more like bullets or artillery shells than aircraft. 

    The latter, in particular, is a reflection of realities of the Ukrainian battlefield where innovation and product update cycles happen in days or even hours. 

    Those sorts of changes are enabling a new class of defense tech startup willing to do the work, go to Eastern Europe, and develop relationships with Ukrainian front-line operators. 

    One such company is Aurelius Systems, a startup with 16 people, but also Ukrainian partners. Aurelius makes directed-energy weapons to take down drones, an economically-attractive alternative to missiles, especially for a country like Ukraine where both soldiers and civilians live under constant drone bombardment. They rely largely on parts and supplies that are already in the U.S. medical and industrial base, lowering cost.

    “We do a lot of testing in the U.S., at test ranges with emitters that really they're not representative of that environment,” due, in part, to U.S. laws that govern the electromagnetic spectrum, said Dustin Hicks, the company’s head of growth. So experience in Ukraine has been invaluable, an impression that is shared by U.S. commanders in the region, such as NATO Supreme Commander U.S. Gen. Alexus Grynkewich

    Right: Aurelius Systems founder Michael LaFramboise

    Michael LaFramboise, the company’s 29-year-old founder, told Defense One on Tuesday that “We started our company doing a ton of user research with Ukrainian frontline operators, seeing what was being used, what was coming down the pike, and kind of what their development cycle is like. That was the initial genesis of the company, getting a glimpse into what the next conflict might look like.” 

    LaFamboise didn’t speak directly to the memo, but he said private capital markets are now much more interested in funding new defense tech startups, lessening the financial burden of having to do research and development. But, in terms of testing which products actually work in a real-world environment, Ukraine is providing a real advantage for those American firms willing to work with them. 

    “For the Ukrainians, obviously, there is [a huge need] to revamp how you do military development,” he said. “They’re willing to take risks.” 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶