• The U.S. military left another survivor after destroying four more boats off the Latin American coast Monday, Pentagon chief Pete Hegseth announced Tuesday on social media in a 28-second video of the fiery attacks. 

    Three U.S. strikes targeted the boats, which Hegseth said were “operated by Designated Terrorist Organizations (DTO) trafficking narcotics in the Eastern Pacific,” though he did not provide supporting evidence. “Eight male narco-terrorists were aboard the vessels during the first strike. Four male narco-terrorists were aboard the vessel during the second strike. Three male narco-terrorists were aboard the vessel during the third strike,” the defense secretary said on Twitter. 

    “Regarding the survivor,” Hegseth said, U.S. military officials from Southern Command “immediately initiated Search and Rescue (SAR) standard protocols; Mexican SAR authorities accepted the case and assumed responsibility for coordinating the rescue.” 

    So far, the U.S. has attacked at least 13 boats, killing at least 57 people near Latin America since September 1. And with Hegseth’s order to send the USS Gerald R. Ford out of the Mediterranean Sea and toward Venezuela means the U.S. is about to be in the “fairly unusual position of having only a single aircraft carrier deployed and none in the waters off both Europe and the Middle East,” the Associated Press reported Wednesday. 

    New: NDAs at the Pentagon for Trump’s war on drug boats. “U.S. military officials involved with President Donald Trump's expanding operations in Latin America have been asked to sign non-disclosure agreements,” which is “highly unusual, given that U.S. military officials are already required to shield national security secrets from public view,” Reuters reported Tuesday. 

    Notable legal context for U.S. troops and civilians involved in the boat strikes: “Any military officials involved in the clearly legally controversial Venezuelan boat strikes must negotiate their twin duties of following a superior order and not following a patently illegal order,” like killing civilians who may not in fact be drug smugglers or terrorists, writes former Pentagon counsel Jack Goldsmith. 

    However, the Justice Department’s Office of Legal Counsel is sitting on a classified, unpublished memo that amounts to a “golden shield” of immunity, as Charlie Savage of the New York Times reported Friday. That memo effectively “immunizes the officer (and everyone else) who relies on it from subsequent punishment,” Goldsmith writes. 

    “And then, of course, there is the president’s pardon power, the after-action and more powerful equivalent of the before-action OLC golden shield…I expect Trump to issue hundreds and possibly thousands of preemptive pardons to everyone in his administration who may conceivably be subject to future investigation or prosecution,” Goldsmith reminds his readers. The result would seem to be the unrestrained executive Trump himself described when he said six years ago, “I have an Article II, where I have the right to do whatever I want as president.”

    Related reading:Irreconcilable Presidential Determinations: On Tren de Aragua and the Venezuelan Government,” which comes from more recent former Pentagon counsel Ryan Goodman along with Michael Schmitt and Anna Jimenez, writing Wednesday in Just Security

    In other legal concerns: “Two Illinois National Guard members told CBS News they would refuse to obey federal orders to deploy in Chicago as part of President Trump's controversial immigration enforcement mission,” CBS reported Tuesday. 

    “[I]t's really hard to be a soldier right now…we have somebody in power who's actively dismantling our rights—free speech, due process, freedom of the press,” one of the soldiers said. “I signed up to defend the American people and protect the Constitution.”

    “It's a slow normalization of using the military in American cities,” the soldier said. “Today it's Chicago. Tomorrow it could be somewhere else…Crime is down. This is not about safety—it's about control."

    Related:Appeals court will reconsider decision that allowed Trump to deploy National Guard troops to Portland,” CNN reported Tuesday. Oregon Public Broadcasting has similar coverage, here

    Coverage continues below…


    Welcome to this Wednesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson with Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1929, “Black Tuesday” marked the start of America’s Great Depression.

    President Trump made at least 11 false claims while speaking to U.S. troops stationed in Japan, CNN’s Daniel Dale reported in an abbreviated fact check on Tuesday. “This is not a comprehensive list of the falsehoods in the speech.”Misinformed topics included the 2020 election, grocery prices, inflation, and a cluster of inaccuracies regarding former President Biden. 

    From Capitol Hill: Senators challenge Hegseth’s bottleneck on communications with Congress. Two senators raised concerns on Tuesday about a new Pentagon policy—first reported last week by Breaking Defense—that could bar defense personnel and military commanders from communicating with lawmakers without prior approval, Defense One’s Lauren C. Williams reported from a hearing to consider nominees for several senior Defense Department roles. 

    “I'm concerned about the October 15 memo from the secretary, which basically throttles communication between people working at the Pentagon and Congress, including this committee. And I hope that's something to discuss and consider,” said Sen. Angus King, I-Maine, the ranking member on the Senate Armed Services Committee’s strategic forces panel.

    Sen. Roger Wicker, R-Miss., who chairs the committee, concurred. “It has been suggested that that memo was misconstrued, and it may need to be clarified. So, thank you for bringing that up,” Wicker said.

    About the document: It says that “unauthorized engagements” with lawmakers could “undermine Department-wide priorities critical to achieving our legislative objectives” and heighten tensions between the Pentagon and Capitol Hill. Republican and Democratic lawmakers have lambasted the policy change, saying the move could ultimately stymie the Pentagon’s legislative goals. More, here

    Related expert reax: “Reduced information flow from DoD could result in more confusion regarding the DoD’s plans and may weigh on the contractors’ abilities to attract capital for investment,” said analyst Byron Callan, writing (PDF) Tuesday.

    Developing: The Pentagon is trying to fire allegedly underperforming civilian personnel with “speed and conviction,” according to a Sept. 30 memo (PDF), The Hill and the Washington Post reported Tuesday. “Employees targeted for firing now have just seven days to challenge unfavorable review,” The Hill writes. 

    On Friday, the Navy launched a review of Marines’ and sailors’ personal social media posts, Task & Purpose reported Tuesday. Officials will be looking for “social media activity that is misaligned with the [Navy’s] current social media guidance,” Navy Secretary John Phelan said in a message to the force Friday. 

    For what it’s worth: “Phelan’s message comes as elections are scheduled throughout the country for next week.” More, here

    Additional reading: 

    Industry

    General Dynamics CEO warns of government shutdown effects. General Dynamics boasted nearly $12.91 billion in revenue in the third quarter of 2025 as well as increased submarine production, according to the company’s earnings call Friday. But gains were tempered by worries about the potential effects of an extended government shutdown, Defense One’s Williams reported Tuesday. 

    “On a company-wide basis, we see annual revenue of around $52 billion and margins of around 10.3 percent,” CEO Phebe Novakovic said of the company’s outlook for the rest of the year. But, she added, “Let me remind you that we’re in the midst of a government shutdown with no end in sight. The longer it lasts, the more it will impact us, particularly the shorter cycle businesses. So forecasts in this environment are difficult at best, and less reliable than one would hope.”

    Should the shutdown extend into next year, she said, “that increases the likelihood that it’ll have additional impacts on particular lines of business that begin to run out of funding.

    About GD’s portfolio: Shipbuilding saw about $4.1 billion in revenue growth in the third quarter, up by about $497 million from the same quarter last year, with “increased throughput” in construction of the Columbia-class and Virginia-class submarines, Novakovic said. The firm also highlighted steady build progress for the first Columbia-class submarine, saying they expect all major modules to be delivered to the Electric Boat facility in Groton, Conn. Read more, here

    Commentary: “Don’t give up the shipyards,” argues Hunter Stires, Project Director of the U.S. Naval Institute’s Maritime Counterinsurgency Project and Maritime Strategist to the 78th Secretary of the Navy Carlos Del Toro, writing Tuesday in Defense One.

    And from last week, Trump Pushes for New Classes of Navy Warships,” the Wall Street Journal reported Friday. 

    Lastly, Boeing Defense workers’ strike is nearing the three-month mark after they rejected Boeing’s offer over the weekend, Reuters reported Monday. 

    At issue: “IAM leaders have pressed the planemaker for higher retirement plan contributions and a ratification bonus closer to the $12,000 that Boeing gave to union members on strike last year in the company's commercial airplane division in the Pacific Northwest.” 

    Background: About 3,200 St. Louis-area workers have been on strike since August 4, which has contributed to delays in sending F-15EX fighters to the Air Force. Read more, here

    Additional reading: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have flagged a new security issue in agentic web browsers like OpenAI ChatGPT Atlas that exposes underlying artificial intelligence (AI) models to context poisoning attacks. In the attack devised by AI security company SPLX, a bad actor can set up websites that serve different content to browsers and AI crawlers run by ChatGPT and Perplexity. The technique has been

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The npm ecosystem faces a sophisticated new threat as ten malicious packages have emerged, each designed to automatically execute during installation and deploy a comprehensive credential harvesting operation.

    This attack campaign represents a significant evolution in supply chain compromises, combining multiple layers of obfuscation with cross-platform compatibility to target developers across Windows, Linux, and macOS environments.

    The malware employs typosquatting techniques to mimic popular JavaScript libraries, making detection particularly challenging for unsuspecting developers.

    Published on July 4, 2025, these packages have remained active for over four months, accumulating more than 9,900 downloads collectively before Socket.dev analysts identified their malicious nature.

    The threat actor, operating under the alias andrew_r1 with the email address parvlhonor@gmx[.]com, crafted each package to closely resemble legitimate libraries including discord.js, ethers.js, TypeScript, and other commonly used development dependencies.

    This typosquatting approach capitalizes on common spelling mistakes and variations that developers might inadvertently introduce when installing packages.

    Each malicious package leverages npm’s postinstall lifecycle hook to execute immediately upon installation, launching in a new terminal window to avoid detection during the installation process.

    The malware’s design ensures it runs independently of the npm install command, minimizing the likelihood that developers will notice unusual activity.

    The packages include sophisticated platform detection capabilities, automatically identifying the victim’s operating system and deploying the appropriate execution method for Windows command prompts, Linux terminals, or macOS Terminal.app.

    The campaign demonstrates advanced technical capabilities through its implementation of four distinct obfuscation layers.

    These include a self-decoding eval wrapper that prevents cursory code inspection, XOR decryption with dynamically generated keys based on the decoder function’s source code, URL encoding of payload strings, and control flow obfuscation using switch-case state machines with mixed hexadecimal and octal arithmetic.

    This multi-layered approach makes static analysis extremely difficult without full JavaScript evaluation.

    Upon successful installation, the malware presents victims with a fake CAPTCHA prompt designed as a social engineering component.

    This element serves multiple purposes: making the package appear legitimate, delaying execution to obscure its connection to npm install, requiring user interaction that may bypass automated security scans, and convincing developers they are interacting with a reputable security measure.

    Multi-Stage Infection and Credential Harvesting Mechanism

    The malware’s infection mechanism operates through a carefully orchestrated multi-stage process that combines deception with sophisticated data extraction capabilities.

    Following the fake CAPTCHA presentation, the system performs IP fingerprinting by sending the victim’s address to http://195[.]133[.]79[.]43/get_current_ip, enabling the threat actor to log installations, potentially filter by geographical location, and track security researcher activity.

    Once the victim interacts with the CAPTCHA prompt, the malware automatically downloads and executes a 24MB PyInstaller-packaged binary called data_extracter.

    Wireshark capture showing HTTP GET request to 195[.]133[.]79[.]43 get_current_ip (Source – Socket.dev)

    This cross-platform information stealer targets multiple credential storage mechanisms across all major operating systems.

    The binary includes platform-specific implementations for Linux SecretService D-Bus API and GNOME Keyring, macOS Keychain Services API, and Windows Credential Manager, ensuring comprehensive credential extraction regardless of the victim’s environment.

    // Detects platform and spawns new terminal window
    const platform = os.platform();
    if (platform == 'win32') {
        exec('start cmd /k "node app.js"');
    } else if (platform == 'linux') {
        exec('gnome-terminal -- bash -c "node app.js"', (error) => {
            if (error) exec('x-terminal-emulator -e "bash -c \'node app.js\'"');
        });
    } else if (platform == 'Darwin') {
        exec(`osascript -e 'tell app "Terminal"
            do script "node '$(pwd)/app.js'"  
        end tell'`, () => {});
    }

    The data_extracter binary performs extensive file system reconnaissance, systematically scanning for credential stores in browser profile directories, SSH key directories, AWS credentials files, Kubernetes configuration files, and Docker registry credentials.

    It targets SQLite databases containing browser cookies and passwords, JSON configuration files with API keys, SSH private keys for Git authentication, and OAuth/JWT tokens that provide long-term access to cloud services and development platforms.

    This comprehensive approach ensures the attacker captures not only interactive credentials but also service account credentials and automation keys used in modern development workflows.

    Upon completion of credential harvesting, the malware packages all extracted data into a compressed archive that is transmitted back to the threat actor’s command and control server at 195[.]133[.]79[.]43.

    The stolen credentials provide immediate access to corporate email systems, cloud infrastructure, internal networks, production databases, and authenticated web applications, while session cookies enable account takeover without triggering password reset notifications.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post 10 Malicious npm Packages with Auto-Run Feature on Install Deploys Multi-Stage Credential Harvester appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A public exploit code demonstrating how attackers could exploit CVE-2025-40778, a critical vulnerability in BIND 9 that enables DNS cache poisoning.

    The Internet Systems Consortium (ISC) initially disclosed this flaw on October 22, revealing a dangerous weakness in the world’s most widely used DNS software.

    The vulnerability allows remote, unauthenticated attackers to inject forged DNS records into resolver caches, potentially redirecting millions of users to malicious infrastructure without any user interaction or special network access.

    DNS Cache Poisoning Vulnerability Bypasses

    The flaw affects supported BIND 9 versions ranging from 9.11.0 through 9.21.14, impacting any resolver performing recursive queries. Fortunately, authoritative-only servers remain unaffected by this issue.

    The vulnerability exploits BIND’s handling of unsolicited resource records, allowing attackers to bypass modern DNS security defenses that were implemented following the infamous 2008 Kaminsky vulnerability.

    That earlier flaw led to randomized query IDs and source ports, protections that CVE-2025-40778 circumvents entirely.

    CVE DetailsInformation
    CVE IDCVE-2025-40778
    Affected VersionsBIND 9.11.0 through 9.21.12
    Vulnerability TypeDNS Cache Poisoning
    CVSS v3.1 Score8.6 (High)

    By crafting specially formatted DNS responses, attackers can poison resolver caches and redirect legitimate traffic to attacker-controlled servers.

    The attack carries a CVSS 3.1 severity score of 8.6, classified as high severity, reflecting its potential for widespread impact across internet infrastructure.

    The consequences of successful exploitation could be severe. Attackers could redirect all DNS traffic from an affected resolver to malicious endpoints, enabling phishing campaigns, malware distribution, and traffic interception.

    Given BIND’s ubiquitous role in internet operations, a single compromised resolver could affect thousands or millions of downstream users and systems. ISC has released patched versions addressing this vulnerability: version 9.18.41, 9.20.15, and 9.21.14.

    The company responsible coordinated disclosure through a responsible timeline, issuing early notifications on October 8, revising patch details on October 15, and finalizing disclosure on October 22. Unfortunately, no known workarounds exist for this vulnerability, making immediate patching the only effective mitigation strategy.

    As of October 28, no active exploitation in the wild has been confirmed, though the public release of exploit code significantly increases the likelihood of opportunistic attacks.

    Security administrators managing recursive DNS resolvers should prioritize immediate upgrades to patched versions matching their deployed BIND installations.

    Organizations should implement Domain Name System Security Extensions (DNSSEC) where feasible and conduct comprehensive audits of resolver configurations to ensure recursive queries are disabled on authoritative-only servers.

    Network monitoring for anomalous DNS behavior and rapid deployment of security patches remain critical for minimizing exposure to this threat.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post PoC Exploit Released for BIND 9 Vulnerability that Let Attackers Forge DNS Records appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Exchange servers in Germany are still running without security updates, just weeks after the official end of support for key versions.

    The Federal Office for Information Security (BSI) issued a stark warning on October 28, 2025, revealing that 92% of approximately 33,000 known on-premise Exchange servers with internet-exposed Outlook Web Access (OWA) are running version 2019 or older.

    This vulnerability leaves critical infrastructure across sectors such as healthcare, education, and public administration at heightened risk of cyberattacks.

    The BSI’s analysis reveals a troubling picture of widespread non-compliance with end-of-support deadlines.

    Support for Exchange Server 2016 and 2019 officially ended on October 14, 2025, meaning Microsoft will no longer provide patches for bugs or security flaws.

    Of the monitored servers, over 45% run version 2019 and about 40% use 2016, with only a fraction, around 2,500, upgraded to the supported Exchange Server Subscription Edition (SE).

    These outdated systems are predominantly found in hospitals, doctors’ offices, schools, universities, social services, law firms, utilities, and municipal governments, amplifying the potential for widespread disruption.

    The BSI’s CERT-Bund team has long notified operators about older versions like 2010 and 2013, and now extends alerts to 2016 and 2019 instances exposed online.

    Looming Risks Of Unpatched Systems

    The implications are severe, as any new critical vulnerability similar to past exploits like ProxyLogon or Hafnium cannot be remediated, potentially forcing servers offline and crippling email communications.

    Compromised Exchange servers often lead to full network breaches due to flat architectures and poor segmentation, enabling data exfiltration, ransomware deployment, and prolonged outages.

    Historical incidents underscore this danger; in 2021, thousands of global Exchange servers, including over 20,000 in Germany, fell victim to state-sponsored hacks exploiting unpatched flaws.

    Moreover, processing personal data on these servers violates the General Data Protection Regulation (GDPR), exposing organizations to legal penalties.

    To avert disaster, the BSI urges immediate upgrades to Exchange Server SE or migration to cloud alternatives like Exchange Online.

    Microsoft’s Extended Security Updates (ESU) program offers paid patches for critical issues until April 14, 2026, but this merely delays the inevitable at additional cost.

    Beyond upgrades, the agency recommends restricting OWA access via IP whitelisting or VPNs, avoiding direct internet exposure, and consulting BSI’s IT-Grundschutz guidelines for email security.

    With attackers constantly probing for weaknesses, German organizations must prioritize these steps to safeguard operations and data integrity in an increasingly hostile digital environment.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Thousands of Exchange Servers in Germany Still Running with Out-of-Support Versions appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The threat landscape continues to evolve as Gunra ransomware emerged in April 2025, establishing itself as a significant threat to organizations worldwide.

    This dual-platform attack group has demonstrated a systematic approach to compromising both Windows and Linux environments, making their campaign one of the more noteworthy distributed ransomware operations in recent months.

    Organizations across multiple industries and sectors have reported successful infection attempts, with damage cases extending into the Asia-Pacific region, including South Korea.

    Gunra operates with a familiar yet effective ransomware model: encrypt critical files on infected systems, exfiltrate sensitive data from compromised organizations, and demand ransom payments with threats of public disclosure if demands are not met.

    What distinguishes Gunra from other ransomware operators is its deliberate development of platform-specific variants. The group distributes their malware in two distinct formats: executable files for Windows environments and ELF binaries for Linux systems.

    Encryption key storage method according to the –store argument value (Source – ASEC)

    This strategic approach allows them to maximize their attack surface and penetrate diverse infrastructure environments that many organizations maintain.

    ASEC analysts identified that the Gunra ransomware operates through a command-line interface requiring multiple parameters to execute its encryption routines.

    The malware performs validity checks on provided arguments before initializing its main execution routine, ensuring all necessary parameters are present and valid.

    This structured approach demonstrates the sophistication and careful engineering behind the campaign.

    Cryptographic Weakness and Decryption Vulnerability

    The technical analysis reveals a critical vulnerability in the ELF version of Gunra ransomware that fundamentally weakens its encryption scheme.

    ASEC researchers discovered that the malware utilizes the ChaCha20 encryption algorithm with a cryptographically insecure random number generation function.

    The vulnerability stems from the seed generation process, which relies on the time() function to create predictable values for the rand() function.

    The flaw becomes apparent when examining how the 32-byte encryption key and 12-byte nonce values are generated. When multiple encryption iterations occur within extremely short time intervals, the seed value remains identical across different execution threads.

    This causes the rand() function to produce identical byte sequences, resulting in encryption keys and nonce arrays containing repeated byte patterns.

    Consequently, the ChaCha20 keys become cryptographically weak and susceptible to brute-force attacks across 256 possible byte values.

    The ChaCha20 encryption algorithm (Source – ASEC)

    This cryptographic oversight enables file decryption with high probability using brute-force techniques based on byte values ranging from 0x00 to 0xFF.

    In stark contrast, the Windows EXE version implements ChaCha8 encryption with key generation through the CryptGenRandom() API, employing cryptographically secure random number generation that makes decryption virtually impossible.

    This disparity between implementations highlights the varying security postures across different platforms.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Gunra Ransomware Leveraging Attacking Windows and Linux Systems with Two Encryption Methods appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical security vulnerability was discovered when a complete 4-terabyte SQL Server backup belonging to Ernst & Young (EY), one of the world’s Big Four accounting firms, was found publicly accessible on Microsoft Azure. The exposure was identified by security researchers during routine internet mapping operations and has since been remediated following responsible disclosure protocols. […]

    The post Massive 4TB EY Database Backup Found Publicly Accessible on Azure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russian-linked attackers have intensified their targeting of Ukrainian organizations through sophisticated intrusions that rely heavily on legitimate Windows tools rather than malware. The attackers demonstrated remarkable restraint in their malware deployment, instead leveraging living-off-the-land tactics and dual-use tools to evade detection while accomplishing their objectives. A recent investigation by our Threat Hunter Team revealed two […]

    The post Russian Hackers Target Government with Stealthy “Living-Off-the-Land” Tactics appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In response to escalating threats of credential theft, Google, through its Mandiant cybersecurity division, has unveiled a detailed guide to help defenders monitor and secure privileged accounts across modern IT environments.

    This resource emphasizes practical strategies to mitigate risks posed by stolen credentials, which accounted for 16% of intrusions in 2024, according to Mandiant’s M-Trends report.

    As cloud migrations expand attack surfaces with human and non-human identities, the guide positions privileged access management (PAM) as a cornerstone of organizational resilience.

    The guide highlights how adversaries increasingly exploit privileged accounts for initial access, lateral movement, and mission completion, often via infostealer malware or social engineering enhanced by AI.

    Stolen credentials enable breaches with a median dwell time of 11 days, underscoring the need for an assume-breach mindset.

    Google’s Guide for Defenders

    Mandiant structures its recommendations around three pillars: prevention through securing access pathways, detection via visibility engineering, and response with rapid remediation tactics.

    Prevention starts with defining privileged accounts broadly, encompassing service accounts, API keys, and developers’ cloud access beyond traditional domain admins.

    It advocates tiering accounts by impact (T0 for crown jewels like domain controllers, T1 for core platforms, T2 for workstations) and mapping dependencies like jump servers.

    Organizations are urged to advance PAM maturity from uninitiated (manual, spreadsheet-based tracking) to an iterative, automated, analytics-driven approach.

    Key controls include multifactor authentication (MFA) on all admin paths, just-in-time/just-enough administration (JIT/JEA), and privileged access workstations (PAWs) on segmented networks.

    Dedicated PAM tools like CyberArk or Google’s own Privileged Access Manager are recommended for vaulting credentials, enforcing rotations, and session recording.

    For detection, the guide stresses high-fidelity monitoring in tools like Google SecOps, distinguishing privileged anomalies from general IAM abuse through behavioral analytics and machine learning.

    Specific hunts target brute-force on Tier-0 accounts, GPO modifications, and service account deviations. In incidents, immediate isolation network pulls, token revocation pairs with coordinated credential resets via PAM.

    Remediation involves enterprise-wide password rotations and forensics on attack paths, including malware scans on developer systems. Recovery planning covers hardening virtualization (e.g., ESXi Lockdown Mode) and backups with immutable storage.

    By integrating SoD, zero-standing privileges, and automated responses, the guide equips defenders to shrink blast radii and comply with standards like NIST and PCI DSS.

    Released amid rising insider and third-party risks, this framework empowers security teams to protect the “keys to the kingdom” effectively.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Unveils Guide for Defenders to Monitor Privileged User Accounts appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released comprehensive guidance on protecting privileged accounts, recognizing that stolen credentials have become one of the most dangerous attack vectors facing modern organizations. The new recommendations address how attackers increasingly exploit these “keys to the kingdom” to breach sensitive systems and steal valuable data. According to recent threat intelligence, stolen credentials now rank […]

    The post Google Publishes New Guide to Help Defenders Monitor Privileged Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶