• A combination of strains are threatening morale and even long-term capabilities at the National Security Agency, former U.S. national security officials and others with knowledge of changes there told Nextgov/FCW. Among them are leadership gaps, program cuts, buyouts, and the government shutdown that has furloughed workers.

    The Pentagon's top signals-intelligence agency has been without a permanent leader since Gen. Timothy Haugh was unexpectedly fired in April, and the White House recently backed down on its plans to elevate Lt. Gen. William Hartman, who has led the NSA and U.S. Cyber Command in an acting capacity ever since, said a person with knowledge of the matter. The reversal was first reported by The Record, the news unit of cybersecurity firm Recorded Future.

    The NSA’s top lawyer, April Falcon Doss, was also let go on the advice of right-wing activist Laura Loomer, and other leading officials have chosen to leave the agency and the combatant command. A search to find candidates for various leadership positions at the agency continues, The Record reported last week.

    “The morale inside the organization is rather depressed. It’s been depressed for a series of months at this point. That’s what happens when your boss disappears, and then some of your lead unicorns also disappear,” said a person familiar with the agency’s disposition, referring to uniquely talented leaders within the agency. 

    That person, as well as most sources for this story, requested anonymity because they were not authorized to publicly share their knowledge and perspectives on the internal posture of a major U.S. intelligence unit.

    The sprawling spy agency has employs hacking, codebreaking, and eavesdropping capabilities to gather intelligence on adversaries around the world. It’s often dubbed a combat support agency that has legal authorities to intercept foreign communications deemed valuable to U.S. interests. The agency’s collections contribute to the president’s daily security briefings.

    “NSA is one of our country’s most important lines of defense, and it depends on a strong, steady leadership team and a workforce that can focus on mission without fear of political interference,” Senate Intelligence Committee Vice Chairman Mark Warner, D-Va., told Nextgov/FCW in an email.

    “Unfortunately, this administration’s pattern of firing seasoned intelligence leaders, leaving critical leadership posts vacant and publicly disparaging the intelligence community sends exactly the wrong message to those serving in silence to keep our nation safe,” added Warner. “That kind of instability is not just bad for morale, it’s bad for national security.”

    Nextgov/FCW has reached out to the NSA and the Defense Department requesting comment.

    Long-term capabilities

    Agency staff deemed non-essential have been furloughed during the shutdown. One person with knowledge of NSA work said that although the shutdown hasn't much affected the agency’s short-term capabilities, long-term planning is degrading, putting many analysts into a “reactive mode.”

    That person could not add more details, but the NSA possesses a suite of pristine hacking tools, and is constantly storing or developing new exploits to breach targets’ systems.

    As the shutdown persists, routine spying activities conducted by NSA and other DOD elements are continuing, but some forward-looking planning has been halted, according to a public Pentagon document that dictates shutdown plans. Paused longer-term activities include political and economic analysis work unrelated to current crises and intelligence support for weapons acquisition, though it’s not clear how much of that work directly falls on NSA analysts’ desks.

    But NSA staff and people working in numerous other intelligence agencies have also been extended offers to leave federal service early, and NSA has set goals to shed some 2,000 civilian workers by the end of the year. 

    The combination of deferred resignations and furloughs has left unclear how many of the agency’s core specialists remain to shoulder its hacking and codebreaking missions.

    As part of their day-to-day work, some agency analysts may be cultivating long-term relationships on dark web forums, fusing together a mix of human intelligence and computer-access skills that require months of frequent attention and communications with targets of interest, one former senior official said.

    “It's not as easy as in the movies where they say, ‘Get me on so-and-so’s system ASAP’ and then you just break into it,” said the ex-official. “You have to have that person on your radar … and you have to be in the right place at the right time to understand when that bad guy screws up so you can exploit that to conduct a cyber operation against them.”

    If those analysts are away from their workstations because they’ve been deemed non-essential, or have left their roles altogether, those access opportunities ebb. 

    “In order to have more of those opportunities available, you really need to have undercovers and sources established ahead of time, and as those wind down, you lose the ability to start.” that former official said.

    A diminished workforce also creates a perilous trickle-down effect on other units of the U.S. military. The dual-hatted nature of NSA and Cyber Command means that civilian analysts are constantly developing hacking toolkits and other capabilities alongside DOD cyber warriors, another former intelligence official said. If Pentagon cyber operatives are deployed overseas and face any technical difficulties, they could have trouble remediating them.

    That concern, this former intelligence official said, especially applies to hunt forward operations, where U.S. cyber warriors from the Cyber National Mission Force physically deploy to allied host nations to observe and detect malicious cyber activity on their networks.

    “We very likely have teams that are deployed right now. Those hunt forward teams are reliant on supporting elements from their home service right now,” they said. “If you’ve got a team deployed in Ukraine, they’re calling back to their home service if their kit doesn’t work, or if there’s some issue and they need to troubleshoot … and they also provide that on-call support for anything that goes wrong. Well, right now, those teams are depleted.”

    Hunt forward missions helped the U.S. uncover Chinese malware activity in Latin American nations, Joint Chiefs Chairman Gen. Dan Caine told Congress earlier this year. While still in service, Haugh told Congress that hunt forward missions were deployed 22 times to 17 countries in 2023.

    “[NSA] is a highly functional federal agency, and therefore it needs its people. It has its technology, it has its policies and processes,” said Mark Montgomery, a former Navy rear admiral who is now senior director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, a national security think tank in Washington. 

    “Other federal agencies can gain and lose people, and you may or may not see the change in output,” he said. That doesn’t apply to NSA, which “relies on and benefits from an extremely purpose-built workforce, and so any perturbations will have an impact,” Montgomery added. “Morale is probably damaged by everything that’s happened over the last eight months,” he said, though it’s not necessarily “unrecoverable.”

    The degree of turnover observed within the agency makes it difficult to adapt and evolve, especially for mid-level agency leadership, another person familiar with changes in NSA said. “The intelligence community needs to be taking risks,” said the person. “What keeps people working is a sense of mission. But when you get to higher-ups, the turnover makes them feel like they don’t have the ability or the buy-in to innovate.”

    Attorney recruitment 

    There are also legal policy implications for the signals intelligence titan. This year, the NSA has paused recruiting young attorneys fresh out of law schools for its Legal Honors Program, according to another former senior national security official and the former intelligence official. 

    That has a “pronounced effect” with long-term implications, one of them said. “You certainly want those kinds of people there, because the kind of problems … NSA is facing are cutting-edge legal problems.”

    Much of the NSA’s mission sits where intelligence work and privacy concerns meet. Its lawyers regularly prepare filings for the secretive Foreign Intelligence Surveillance Court, using precise legal and technical language to request permission to monitor and collect communications tied to specific targets.

    There’s a ripple effect within law schools too, the former official added. “It affects the second- and first-year law students who think, ‘I’m not going to even apply to that, because I heard some third-year guys got turned down.’ Even if you reinstate the program, it’ll take two, three, four or even five years to rebuild.”

    A similar dynamic has played out among recipients of the CyberCorps scholarship on college campuses, which for years has placed talented students into government cybersecurity roles.

    One major open question is how NSA staff affected by deferred resignation offers are handling their transition out of government. The Trump administration has made it a point to say that, in initiating sweeping cuts to the federal enterprise, they would want more people in private sector jobs.

    But when affected staff are unexpectedly forced to look for jobs in industry, they’ve found the market is too saturated, and that their pristine, tailored skill sets built up inside Fort Meade don’t align directly with industry demands. 

    “As an employee of those agencies, you are told you are the cream of the crop,” said the person who spoke about the depressed morale in the agency. “You’re told that you’re the best of the best, that you work in the most exquisite intel agency on the planet, that you are awesome.”

    The person, recounting a recent retirement event for one senior officer who left NSA, put it bluntly: “They’re struggling to find work, and it was very depressing to be there.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Nine people have been arrested in connection with a coordinated law enforcement operation that targeted a cryptocurrency money laundering network that defrauded victims of €600 million (~$688 million). According to a statement released by Eurojust today, the action took place between October 27 and 29 across Cyprus, Spain, and Germany, with the suspects arrested on charges of involvement in

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Delaware, United States, November 4th, 2025, CyberNewsWire

    Brinker, the narrative intelligence company dedicated to combating disinformation and influence campaigns, announced today that Bob Flores, former Chief Technology Officer of the U.S. Central Intelligence Agency, has joined its advisory board.

    His appointment strengthens Brinker’s mission to transform the fight against disinformation, moving from detection to real-time, technology-driven mitigation at global scale.

    “Most disinformation efforts fail because they rely on manual operations that can’t match the speed and scale of today’s influence campaigns,” said Bob Flores.

    “Brinker’s AI-native approach enables responses that were previously impossible, turning real-time analysis and large-scale mitigation into a reality.”

    Founded by Benny Schnaider, Daniel Ravner, and Oded Breiner, Brinker was built from the ground up as a Native AI platform that identifies, analyzes, and neutralizes harmful narratives across platforms, languages, and geographies.

    Its proprietary, battle-proven LLM traces how stories evolve and spread over time, uncovering connections that traditional tools take weeks to detect.

    “Bob’s expertise in intelligence and technology will help Brinker accelerate its global impact,” said Daniel Ravner, CEO of Brinker.

    Oded Breiner, CTO, added: “Bob’s technological experience and understanding of mission-critical systems can help take Brinker’s automated OSINT technology to the next level, ensuring our platform continues to meet the operational demands of U.S. and global government partners, turning what was once a reactive process into a real-time defense capability.”

    Flores brings decades of experience in national security and enterprise technology innovation. As the CIA’s former CTO, he led digital transformation and information-sharing initiatives across U.S. intelligence agencies.

    He currently serves as Founder and President of Applicology Inc., a Virginia-based security advisory firm.

    This appointment follows the addition of Avi Kastan, former CEO and Co-Founder of Sixgill (acquired in 2024), further strengthening Brinker’s advisory board with deep expertise in intelligence, cybersecurity, and threat analysis.

    About Brinker

    Brinker is an award-winning disinformation threat mitigation platform built to combat malicious narratives and influence campaigns using proprietary narrative intelligence technology.

    The SaaS platform delivers AI-powered detection, context analysis, and automated OSINT investigations.

    A suite of mitigation tools is available at the press of a button, including pre-legal actions, media publications, content removal, and counter-narratives. Brinker serves governmental intelligence agencies, major enterprises, law firms, and NGOs.

    More information is available at www.brinker.ai

    Contact

    Daniel Ravner

    Brinker

    daniel@brinker.ai

    The post Bob Flores, Former CTO of the CIA, Joins Brinker appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Delaware, United States, November 4th, 2025, CyberNewsWire Brinker, the narrative intelligence company dedicated to combating disinformation and influence campaigns, announced today that Bob Flores, former Chief Technology Officer of the U.S. Central Intelligence Agency, has joined its advisory board. His appointment strengthens Brinker’s mission to transform the fight against disinformation, moving from detection to real-time, […]

    The post Bob Flores, Former CTO of the CIA, Joins Brinker appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical vulnerabilities in Microsoft Teams, a platform central to workplace communication for over 320 million users worldwide, enable attackers to impersonate executives and tamper with messages undetected.

    These vulnerabilities, now patched by Microsoft, allowed both external guests and insiders to spoof identities in chats, notifications, and calls, potentially leading to fraud, malware distribution, and misinformation.

    Check Point disclosed the issue to Microsoft responsibly in March 2024. The issues highlight how trust in collaboration tools can be weaponized by sophisticated threat actors targeting remote work infrastructure.

    Launched in 2017 as part of Microsoft 365, Teams integrates chat, video calls, file sharing, and apps, making it indispensable for businesses from startups to Fortune 500 companies.

    Check Point’s investigation focused on the web version’s JSON-based architecture, where messages include parameters like content, messagetype, clientmessageid, and imdisplayname.

    Attackers exploited these to edit messages without the “Edited” label by reusing clientmessageids, effectively rewriting history without traces.

    Notifications could be manipulated by altering imdisplayname, making alerts appear from high-level executives like CEOs, exploiting users’ instinctive trust in urgent pings.

    In private chats, modifying conversation topics via a PUT endpoint changed display names, misleading participants about the sender’s identity, as shown in before-and-after screenshots of altered interfaces.

    Call initiations via POST /api/v2/epconv allowed forging displayName in participant sections, spoofing caller identities during audio or video sessions.

    One flaw, notification spoofing, was tracked as CVE-2024-38197, a medium-severity issue (CVSS 6.5) affecting iOS versions up to 6.19.2, where sender fields lacked proper validation.​

    Microsoft Teams Vulnerability Attack Scenarios

    These vulnerabilities erode the core trust in Teams, turning it into a deception vector for advanced persistent threats (APTs), nation-state actors, and cybercriminals.

    External guests could infiltrate as insiders, impersonating finance leads to harvest credentials or push malware-laden links disguised as executive directives.

    Insiders might disrupt briefings by spoofing calls, spreading confusion in sensitive discussions, or enabling business email compromise (BEC) schemes.

    Real risks include financial fraud, where fake CEO notifications prompt wire transfers; privacy breaches from falsified conversations; and espionage via manipulated histories in supply chain attacks.

    Threat actors, including groups like Lazarus, have long targeted such platforms for social engineering, as seen in recent reports of Teams abuse in ransomware and data exfiltration.

    The ease of chaining these flaws, for instance, spoofing a notification followed by a forged call, amplifies dangers, potentially fooling users into revealing secrets or executing harmful actions.​

    Check Point disclosed the flaws on March 23, 2024, with Microsoft acknowledging them on March 25 and confirming fixes progressively.

    The message editing issue was resolved by May 8, 2024; private chat alterations by July 31; notifications (CVE-2024-38197) by September 13, after an August rollout; and call spoofing by October 2025.

    All issues are now addressed across clients, requiring no user action beyond updates. However, organizations should layer defenses: implement zero-trust verification for identities and devices; deploy advanced threat prevention to scan payloads in Teams; enforce data loss prevention (DLP) policies; and train staff on out-of-band validation for high-stakes requests.

    Critical thinking remains key to always verifying suspicious communications, even from apparent trusted sources. As collaboration tools evolve, securing human trust is as vital as patching code.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Can Exploit Microsoft Teams Vulnerabilities to Manipulate Messages and Alter Notifications appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Details have emerged about a now-patched critical security flaw in the popular “@react-native-community/cli” npm package that could be potentially exploited to run malicious operating system (OS) commands under certain conditions. “The vulnerability allows remote unauthenticated attackers to easily trigger arbitrary OS command execution on the machine running react-native-community/cli’s

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers have successfully stolen more than $100 million by exploiting a critical vulnerability in the Balancer protocol.

    Balancer, a leading DeFi platform known for its automated market-making pools, confirmed that only its V2 Composable Stable Pools were affected by the exploit. The remainder of its pools, including Balancer V3 and other older pools, remain untouched and fully secure.

    The impacted pools had been active on the blockchain for several years and, due to their age, many were outside of Balancer’s “pause window” a built-in feature allowing emergency halts to prevent damage during attacks.

    Balancer DeFi Protocol Exploited

    The pools that could be paused were quickly taken offline and are currently in recovery mode while the investigation continues.

    The Balancer team responded rapidly, working in collaboration with experienced security researchers to analyze the incident. A full post-mortem report with technical details will be provided once the investigation has progressed.

    Balancer emphasized its longstanding commitment to security, highlighting extensive third-party audits and robust bug bounty programs designed to encourage independent researchers to uncover vulnerabilities before hackers do.

    Legal and security professionals are now working closely to enhance protection for users and to track down the attackers. In the wake of the incident, the Balancer team issued an urgent warning about fraudulent communications.

    Malicious actors are already sending fake messages pretending to represent the Balancer Security Team, seeking to further exploit concerned users. Balancer stressed that official updates will be shared only through its official X (Twitter) account and Discord server.

    Users are strongly cautioned not to trust unsolicited messages or click on unknown links, as these could be part of phishing schemes aimed at stealing more funds.

    As the investigation proceeds, Balancer has reassured the community that they are devoted to operational security and user protection.

    The DeFi community and partners are actively supporting the team. Users are encouraged to stay tuned for further updates as more details surrounding the exploit and future preventive measures are released.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Stolen Over $100 Million by Exploiting Balancer DeFi Protocol appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Baltimore, USA, November 4th, 2025, CyberNewsWire

    The new 2025 Insider Risk Report, produced by Cybersecurity Insiders in collaboration with Cogility, highlights that nearly all security leaders (93%) say insider threats are as difficult or harder to detect than external cyberattacks.

    Yet only 23% express strong confidence in stopping them before serious damage occurs.

    The report warns that most organizations remain reactive despite a surge in AI-driven risks and the increasing prevalence of decentralized workforces.

    The report, which surveyed 635 CISOs and cybersecurity professionals, highlights an urgent industry contradiction: while there is high awareness of insider risks, the capabilities to anticipate and prevent them are dangerously limited.

    Without stronger behavioral intelligence and predictive modeling, organizations risk being blindsided by trusted insiders misusing powerful new tools.

    Key findings include:

    • Flying blind against insiders: 93% of organizations find insider attacks as hard or harder to detect than external threats. At the same time, fewer than one in four are confident in preventing them before major damage.
    • Behavioral blind spots: Only 21% extensively integrate HR, financial stress, or psycho-social signals into detection, leaving most programs relying solely on technical anomalies.
    • Predictive defenses are missing: Only 12% have mature predictive risk models, leaving the majority in reactive mode, while AI-enabled insider risks accelerate.

    “Insider threats don’t announce themselves with alarms – they unfold quietly, in plain sight,” said Holger Schulze, founder of Cybersecurity Insiders.

    “Without context like financial stress or behavioral shifts, security teams are watching shadows on the wall while the real danger moves unchecked. If organizations fail to evolve, they’ll be reading about their data on the dark web before they ever see it in their logs.”

    The full report can be read here.

    About Cybersecurity Insiders

    Cybersecurity Insiders is the trusted intelligence source for CISOs and cybersecurity decision-makers seeking strategic clarity in a complex, fast-moving industry.

    Backed by more than a decade of analyst-led research and a global community of over 600,000 cybersecurity professionals, we deliver evidence-based insights, original data, and expert commentary to help leaders navigate threats, assess emerging technologies, and shape forward-looking security strategies. More: https://cybersecurity-insiders.com

    About Cogility

    Cogility’s continuous Decision Intelligence Platform, Cogynt, provides an advanced decision intelligence and decision support streaming analytic solution for government and commercial organizations — allowing our customers to get left of harm or ahead of opportunity.

    A cloud-scalable, proven solution, Cogynt enables organizations to efficiently and effectively manage complex intelligence challenges with high-confidence, predictive, and explainable insights required to become proactive versus reactive in highly complex and high consequence environments.

    To learn more, users can visit www.cogility.com.

    Contact

    Head of Research

    Holger Schulze

    Cybersecurity Insiders

    contact@cybersecurity-insiders.com

    The post 2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Baltimore, USA, November 4th, 2025, CyberNewsWire The new 2025 Insider Risk Report, produced by Cybersecurity Insiders in collaboration with Cogility, highlights that nearly all security leaders (93%) say insider threats are as difficult or harder to detect than external cyberattacks. Yet only 23% express strong confidence in stopping them before serious damage occurs. The report […]

    The post 2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft is implementing a significant security enhancement to its Authenticator app, introducing automatic detection of jailbroken and rooted devices for Microsoft Entra credentials.

    Beginning in February 2026, the company will automatically delete all Microsoft Entra credentials stored on jailbroken iOS devices and rooted Android devices to prevent unauthorized access and strengthen the organization’s security posture.

    The move represents Microsoft’s commitment to protecting enterprise credentials from potential compromise on compromised devices.

    Jailbroken and rooted devices bypass built-in security controls, making them vulnerable to credential theft and malicious software installation.

    By wiping credentials on these devices, Microsoft eliminates a significant attack vector that threat actors could exploit to gain unauthorized access to sensitive organizational resources.

    Jailbreak and Rooted Device Detection

    The security feature will be automatically deployed across all Authenticator installations and requires no administrative configuration or IT team control.

    This means organizations don’t need to adjust settings or deploy policies to activate the protection. The change applies uniformly to both iOS and Android platforms, ensuring consistent security across all mobile operating systems.

    Microsoft designed this capability as secure by default, meaning the protection activates immediately without any manual intervention.

    This approach reduces the burden on IT administrators while ensuring that all users receive the same level of protection regardless of their organization’s technical readiness or configuration.

    Importantly, this change applies only to Microsoft Entra credentials and will not affect personal Microsoft accounts or third-party accounts stored in the Authenticator app.

    This targeted approach allows users to maintain access to personal accounts on their devices while protecting organizational credentials from compromise.

    The distinction ensures that the security enhancement doesn’t unnecessarily restrict access to non-enterprise accounts that don’t require the same level of protection. Microsoft emphasizes that organizations should notify end users about this upcoming change before February 2026 arrives.

    Users currently relying on Authenticator for Microsoft Entra credentials on jailbroken or rooted devices must understand that their credentials will cease functioning once the update deploys.

    This advance notification prevents confusion and support tickets when users suddenly find themselves unable to authenticate with their organizational accounts.

    Organizations should provide clear guidance to users about the options available, including upgrading to non-jailbroken devices or removing the jailbreak or root modifications to maintain access to corporate resources. The notification period gives users adequate time to prepare and adjust their device management practices.

    This update aligns with industry best practices for securing mobile device credentials. Jailbreaking and rooting devices fundamentally compromise the security model that protects stored credentials and sensitive data.

    By preventing Microsoft Entra credentials from functioning on these devices, Microsoft reinforces that enterprises require baseline device security standards for organizational access.

    The implementation reflects growing recognition that mobile devices serve as critical access points to corporate networks and sensitive information.

    Protecting credentials at the application level represents a practical security measure that organizations can enforce without relying on complex MDM policies or user compliance.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft Entra Credentials in the Authenticator App on Jail-Broken Devices to be Wiped Out appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶