• Defense Secretary Pete Hegseth summoned hundreds of admirals, generals, and senior enlisted leaders to Quantico, Virginia, on Tuesday to hear him announce a spate of personnel initiatives around physical fitness and grooming standards, the inspector general process, and mandatory training.

    Some of the 10 initiatives flow from reviews Hegseth has ordered since taking the job in January, including gender-neutral fitness standards for combat jobs and exemptions to facial hair rules. Others take aim at processes that affect or have affected the secretary himself.

    “I don't want my son serving alongside troops who are out of shape, or in a combat unit with females who can't meet the same combat arms physical standards as men, or troops who are not fully proficient on their assigned weapons platform or task, or under a leader who is the first, but not the best,” he told the assembled flag officers and their enlisted advisors, who were ordered to Marine Corps Base Quantico on short notice from commands around the world. 

    Hegseth’s speech functioned as a sort of State of the Union for his culture war at the Pentagon, making baseless claims that fitness standards have dropped to accommodate the integration of women, or that the first women or people of color to hold high-ranking positions were chosen for that reason alone. 

    He called for a review of the inspector general process, including the Equal Opportunity and Military Equal Opportunity complaint processes, which enable troops to anonymously report concerns without fear of retaliation.

    “We are overhauling an inspector general process, the IG, that has been weaponized, putting complainers, ideologues, and poor performers in the driver's seat,” he said.

    Hegseth is under investigation by the department’s inspector general for allegedly using an unsecure, unapproved app to conduct official business in the form of sending strike plans over Signal.

    He also called for a review of the rules governing the retention of “adverse information”—for example, documented misconduct—on personnel records, which can hamstring a service member’s assignment or promotion chances.

    “People make honest mistakes, and our mistakes should not define an entire career,” he said.

    Hegseth has said he resigned from the D.C. National Guard in 2021 after his superiors concluded that his tattoos were associated with white supremacist ideology and barred him from serving at Biden inaugural events.

    Here are the initiatives Hegseth announced Tuesday:

    • All combat arms positions will use the “highest male standard” as their physical fitness requirement.
    • All combat arms units will implement a separate “combat field test.”
    • All service members will take part in physical fitness every duty day, whether as a unit or individually.
    • All service members must complete a height-weight assessment and physical fitness test twice yearly. (This is already policy.) 
    • Beards are banned, except for temporary waivers for pseudofolliculitis barbae. Religious exemptions, such as those for Norse Pagans or Sikhs, are rescinded.
    • The department will review its definitions of “toxic leadership,” hazing, and bullying.
    • A department-wide review of fitness standards.
    • A review of the IG, EO, and MEO processes.
    • Unspecified changes to retention of adverse information in personnel files.
    • Reduction of mandatory training requirements

    “I look out at this group, and I see great Americans, leaders who have given decades to our great Republic, at great sacrifice to yourselves and to your families,” Hegseth said, addressing the assembled senior leaders. “But if the words today are making your heart sink, then you should do the honorable thing and resign.”

    Some of Hegseth’s comments on physical fitness standards, including repeatedly referring to “fat” service members, reinforce policies that already exist but may be unevenly enforced. As an example, members of the military regularly question whether four-star generals and admirals are truly completing their fitness assessments.

    “Frankly, it's tiring to look out at combat formations, or really, any formation, and see fat troops,” the secretary said. “Likewise, it's completely unacceptable to see fat generals and admirals in the halls of the Pentagon and leading commands around the country and the world. It's a bad look.”

    Other comments were flat-out fabrications, such as his assertion that in 2015, “combat arms standards were changed to ensure females could qualify.”

    No service has lowered its fitness standards to accommodate women. In one case, the Army created an entirely new battery – the Occupational Physical Assessment Test – with gender-neutral scoring to determine which types of jobs new recruits are qualified to do. The service then spent years revamping its fitness test, adding events that test strength, power and agility in addition to muscular endurance.

    Hegseth’s review requires a justification for any standards put in place after 1990, suggesting that he prefers a default to that era’s gender- and age-determined scoring of pushups, situps and a run.

    Throughout the secretary’s many public comments alleging lowered fitness standards, he has not specified an instance where it happened. 

    Hegseth also called on the assembled leaders to be honest about the state of the force.

    “We have to say with our mouths what we see with our eyes, just tell it like it is in plain English to point out the obvious things right in front of us,” he said. “That's what leaders must do.”

    That comment came just a month after Hegseth fired Air Force Lt. Gen. Jeffrey Kruse, the director of the Defense Intelligence Agency, whose initial assessments of the bombing of Iran nuclear sites determined that the raid had set back the country’s nuclear ambitions by months, rather than the “obliteration” the administration touted

    The department dropped another memo Tuesday, which Hegseth did not mention in his speech, directing a “cultural refresh” among the civilian workforce, “to address two complementary but distinct objectives: encourage workforce rewards and demystify the removal process.”

    More than 60,000 civilians voluntarily left DOD this year either through the Deferred Resignation Program or Voluntary Early Retirement Authority, in addition to hundreds of probationary employees the Pentagon attempted to lay off and then invited back under a judge’s order.  

    Hegseth previewed another speech next month, saying he’ll “showcase the speed, innovation and generational acquisition reforms we are undertaking urgently,” and “the nature of the threats we face in our hemisphere and in deterring China.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security Operations Centers (SOCs) protect organizations’ digital assets from ongoing cyber threats. To assess their effectiveness, SOCs use key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and False Positive Rate (FPR).

    Although these metrics are often seen as separate, they are closely interconnected; improving one can directly enhance the other.

    By integrating high-fidelity threat intelligence (TI) feeds, SOC teams can significantly lower their MTTD, which in turn helps to drastically reduce the number of false positives that plague their daily operations.

    A false positive occurs when a security tool mistakenly flags harmless activity as malicious. A high FPR is one of the most significant challenges facing modern SOCs. It leads to several detrimental outcomes:

    • Alert Fatigue: Analysts become overwhelmed by a constant stream of irrelevant alerts, leading to burnout and desensitization. This environment makes it more likely that a genuine threat will be overlooked.
    • Wasted Resources: Every false positive requires investigation time from a security analyst, typically at the Tier 1 level. These cycles are costly and divert attention from legitimate threats and proactive threat-hunting activities.
    • Reduced Trust in Security Tools: When a particular security system generates too much noise, analysts may begin to distrust its alerts, lowering their overall confidence in the organization’s security posture.

    How Threat Intelligence Feeds Reduce MTTD

    Mean Time to Detect measures the average time it takes for the SOC to become aware of a security incident. A lower MTTD is crucial because it shortens the window an attacker has to operate within the network.

    Enhance Your SOC Operations With Fresh and Real-Time IoCs With near-zero false positives => Free Trial

    Threat intelligence feeds are real-time streams of Indicators of Compromise (IOCs) such as malicious IP addresses, domains, URLs, and file hashes that are directly integrated into security tools like SIEM, SOAR, and EDR platforms.

    This integration enables the automated, real-time correlation of internal network and endpoint data with a global repository of known threats. When a match occurs, an alert is generated with a high degree of confidence.

    This process reduces detection time from hours or days of manual investigation to mere seconds.The strategy of using TI feeds to lower MTTD directly contributes to a reduced false positive rate through several mechanisms. The key lies in the quality and context of the intelligence provided.

    High-quality TI feeds are curated from verified sources, such as interactive sandbox analysis of real-world malware samples. This means the IOCs within the feed have already been vetted and are confirmed to be malicious.

    When a security tool generates an alert based on a match from a high-fidelity feed, it is, by definition, a true positive. This validation process effectively filters out the noise of ambiguous or low-confidence alerts that would otherwise require manual triage.

    Modern TI feeds do more than just provide a list of IOCs. They enrich alerts with critical context that helps analysts immediately understand the nature and severity of the threat. This context includes:

    • Threat Categorization: The alert is labeled with the associated malware family (e.g., Dridex, Emotet) or threat actor group.
    • Severity Score: A numerical score indicates the risk level of the IOC, allowing for automated prioritization.
    • Timestamps: Information on when the IOC was first and last seen helps determine if the threat is part of an active campaign.
    • Related Artifacts: Links to associated file hashes, domains, or URLs provide a more complete picture of the attack infrastructure.

    This contextual data transforms a generic alert like “Suspicious connection to IP 1.2.3.4” into a high-confidence, actionable insight: “Critical Alert: Outbound C2 communication to 1.2.3.4, confirmed part of active LockBit 3.0 ransomware infrastructure.” This removes ambiguity and confirms the alert’s legitimacy, preventing it from being dismissed as a false positive.

    With the immediate validation and context provided by TI feeds, SOCs can automate the initial triage process. Using SOAR (Security Orchestration, Automation, and Response) playbooks, alerts enriched by high-confidence threat intelligence can trigger automated actions.

    For example, a confirmed malicious IP can be automatically added to a firewall blocklist, and the affected endpoint can be isolated from the network.

    This not only reduces the Mean Time to Respond (MTTR) but also ensures that analyst time is reserved for complex incidents that require human ingenuity rather than validating known threats.

    Threat intelligence feeds also empower Tier 2 and Tier 3 analysts to conduct more effective proactive threat hunting. By providing IOCs and Tactics, Techniques, and Procedures (TTPs) associated with emerging campaigns, feeds allow hunters to build hypotheses and search for threats before they trigger automated alerts.

    For instance, if a feed highlights a new TTP used by a specific threat actor, hunters can search their environment for evidence of that behavior.

    This proactive posture uncovers stealthy threats that might otherwise go undetected and further validates the intelligence being used, reinforcing the cycle of high-confidence detections.

    Enhance Your SOC Operations With Fresh and Real-Time IoCs With near-zero false positives => Free Trial

    The post How SOC Teams Detect Can Detect Cyber Threats Quickly Using Threat Intelligence Feeds appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The nation’s top spy offices are expected to pare certain "non-essential" intelligence-gathering activities if the government shuts down at midnight tonight.

    Under guidance provided by the Defense Department, intelligence work that directly supports active military operations, threat monitoring, or other national-security emergencies is designated “excepted” and would continue if funding lapses.

    But agencies would be required to pause certain longer-term activities. Those include political and economic analysis work unrelated to current crises and intelligence support for weapons acquisition. 

    Political and economic assessments can help military planners understand how foreign governments and global financial conditions shape conflicts, while weapons-acquisition intelligence helps the U.S. design, purchase, and test systems.

    In essence, tactical intelligence collection activities would remain active, though much of the strategic analysis that supports future planning of the DOD’s spying activities would be curtailed until federal funding is restored.

    “Command, control, communications, computer, intelligence, surveillance and reconnaissance activities” remain excepted functions, the document says. That also includes the use of spying capabilities tied to telecommunications infrastructure, which are often used by the National Security Agency to intercept phone calls and other communications as they cross the world’s internet backbone.

    Offices like the National Geospatial-Intelligence Agency, which relies on satellites and imagery analysis to track targets from space, can also continue their core intelligence missions. Other major DOD spying offices include the Defense Intelligence Agency and the National Reconnaissance Office, the latter of which designs and launches the nation’s spy satellites.

    The exemptions would also apply to a slew of other intelligence units housed inside military branches like the Army, Air Force and Navy. 

    Other intelligence offices like the CIA are not housed directly in DOD but coordinate closely with the military on spying matters. Less public information is available on shutdown plans for the CIA and the Office of the Director of National Intelligence, which oversees the nation’s 18 spy agencies.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Grooming standards, “toxic leadership,” and culture wars were the themes Defense Secretary Pete Hegseth chose for his unprecedented short-notice gathering of more than 800 military leaders and their senior enlisted advisors from commands around the world to a Marine base in Virginia Tuesday morning. 

    Shortly before Hegseth spoke, President Donald Trump told reporters the generals and admirals had come to hear “how well we’re doing militarily.” But Hegseth spent most of his time repeating many of the gripes heard during Trump’s presidential campaign. 

    “No more dudes in dresses. No more climate change worship,” Hegseth said in his Tuesday address. “We are done with that shit,” he insisted. “For too long we've promoted too many uniformed leaders for the wrong reasons—based on their race, gender quotas, based on historic so-called ‘firsts,’” said Hegseth, who has fired black and women leaders while offering no evidence that they were inappropriately appointed or had performed poorly. 

    Here are a few other lines from Hegseth’s speech to the highest-ranking members of the U.S. military: 

    • On names: “Welcome to the War Department. Because the era of the Department of Defense is over.”
    • On accountability: “We are overhauling an inspector general process that has been weaponized, putting complainers and poor performers in the driver seat. We are doing the same with the equal opportunity policies. No more frivolous complaints, no more anonymous complaints,” he said, which would seem to protect domestic abusers in the Pentagon’s ranks. 
    • More on accountability: “You should not pay for an earnest mistake for your entire career. That's why today, at my direction, we're making changes to the retention of adverse information on personnel records.” He also said he’s ordered a review of “the department’s definitions of so-called toxic leadership, bullying and hazing to empower leaders to enforce standards without fear of retribution or second guessing.”
    • On fitness: “I don't want my son serving alongside troops who are out of shape or in combat units with females who can't meet the same combat arms physical standards as men.”
    • More on fitness: “Frankly, it's tiring to look out at combat formations and see fat troops. Likewise, it's completely unacceptable to see fat generals and admirals.”
    • On beards: “The era of unprofessional appearance is over. No more beardos…if you don't meet the male-level physical standards for combat positions, cannot pass a PT test or don't want to shave and look professional, it's time for a new position.”
    • On drill sergeants: “We're empowering drill sergeants to instill healthy fear in new recruits, ensuring that future warfighters are forged…they can put hands on recruits.”
    • On ethics in conflict: “We untie the hands of our warfighters to intimidate, demoralize, hunt, and kill the enemies of our country. No more politically correct and overbearing rules of engagement.”
    • On Hegseth’s view of the military: “You kill people and break things for a living. You are not politically correct.”

    President Trump took the podium after Hegseth, and told the crowd, “I've never walked into a room so silent before. Just have a good time. And if you want to applaud, you applaud.”

    He added: “If you don't like what I'm saying, you can leave the room. Of course, there goes your rank. There goes your future. But you just feel nice and loose,” the president told his captive audience. 

    Trump then launched into a speech that wandered among some of his favorite recent topics, including his desire for the Nobel Peace Prize; the Gulf of Mexico; how Democrats are “a lot of bad people”; how “everyone loves my signature”; how he thinks he’s ended eight wars; his desire to make Canada the 51st state; how he believes the U.S. Navy uses “ugly ships” and “I think we should maybe start thinking about battleships”; that he thinks the U.S. is being invaded “from within”; his stated belief that Washington, D.C., is more dangerous than Afghanistan; how he’s ordered U.S. troops to occupy American cities and how that’s “gonna be a major part for some people in this room”; and relatedly, how he thinks “we should use some of these dangerous [U.S.] cities as training grounds for our military.” 

    One lingering question: Was this in-person meeting necessary? After all, “The military is well-equipped to hold meetings online in a secure fashion,” former Justice Department attorney for the Northern District of Alabama. Joyce Vance wrote Monday evening. 

    Reaction from Capitol Hill: 

    • “He billed the taxpayers millions to fly every general to Washington to hear this weirdo drivel,” said Sen. Chris Murphy, D-Conn., writing on social media Tuesday. (One recent estimate put the costs somewhere between three and six million dollars.) Also, “He's telling us what he's doing. Using the military to suppress protest,” Murphy added
    • “We need a Defense Secretary focused on fighting real wars instead of culture wars,” said Delaware Democratic Sen. Chris Coons
    • “America’s military leadership has more important things to do than listen to lectures on character from an unqualified drunk who assaults women,” said Virginia Democratic Rep. Don Beyer. “Any soldier who was as careless as Hegseth was with war plans would be fired if not prosecuted. And everyone in that room knows it.”

    Commentary from a retired Air Force one-star: “Defense Secretary Pete Hegseth’s short-notice, no-explanation summoning of more than 800 general and flag officers from command positions around the world demonstrates a lack of respect for their time and their jobs. It suggests a concomitant lack of respect for their advice”—and that endangers “the civilian-military dialogue, the military itself, and the country.” Read Paula Thornhill’s argument, here.

    One last note: Trump and Hegseth’s forthcoming national defense strategy has raised “serious concerns” among top Pentagon officers, including the chairman of the Joint Chiefs of Staff, Gen. Dan Caine, the Washington Post reported Monday evening. 

    In particular, Trump and Hegseth’s focus “on perceived threats to the homeland, narrowing U.S. competition with China, and downplaying America’s role in Europe and Africa” have fostered a “growing sense of frustration with a plan they consider myopic and potentially irrelevant, given the president’s highly personal and sometimes contradictory approach to foreign policy,” four Post reporters write. Read more (gift link), here

    Additional reading: 


    Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1954, the USS Nautilus submarine was commissioned as the world's first nuclear-powered vessel.

    Shutdown watch

    Read the Defense Department’s shutdown guidance, here. TLDR: Just over 400,000 of DOD’s 741,477 civilian employees will be kept on the job, either because they are “[n]ecessary to protect life and property” or because their salaries are not funded through regular appropriations acts.

    Noted: DOD officials had been unable to provide the current number of DOD civilians when asked about it last week; they declined to provide details about Hegseth’s ongoing efforts to cut the workforce.

    Latest: “All signs point to the government shutting down at midnight Tuesday night,” Politico posted at 8 a.m. on Tuesday. “Just when Monday’s meeting between President Donald Trump and congressional leaders brought a glimmer of a potential offramp—the president expressed openness to extending Obamacare credits, Democrats’ asking price—it was back to the status quo hours later.

    Trump posted a deepfake video Monday night of Senate Minority Leader Chuck Schumer talking about why voters hate Democrats and House Minority Leader Hakeem Jeffries in a sombrero and mustache, which Jeffries called bigoted. Now, just 16 hours until the deadline, there’s no reason to expect a breakthrough. And leaders haven’t set a follow-up meeting on the impasse.” Read on, here.

    Charted: Congress’ struggle to fund the government, in concise yet detailed graphs and text, from the New York Times, here.

    Related reading:Shutdown could erode cyber defenses by sidelining critical staff, experts warn,” Nextgov reported Monday.

    Workforce cuts to take effect today: “This week marks the largest single-year exodus of federal US employees in almost 80 years,” Reuters writes. That’s because the delayed resignations of more than 100,000 federal workers, part of the Trump administration’s effort to shrink the federal workforce, take effect tonight.

    DOD workers account for the lion’s share of workers taking buyouts or early retirement: more than 61,000, officials told Defense One’s Meghann Myers last week.

    Historian’s take: “This year’s cuts to the government workforce will mean the loss of at least 275,000 workers, the largest decline in civilian federal employment in a single year since World War II,” Boston College’s Heather Cox Richardson wrote Monday.

    Related reading: 

    Troops in U.S. streets

    As armed, masked agents patrol downtown Chicago, Illinois governor says National Guard troops could be next. AP: “Trump has waffled on sending the military, but Democratic Gov. JB Pritzker said Monday it appeared the federal government would deploy 100 troops. Pritzker said the Illinois National Guard received word that the Department of Homeland Security sent a memo to the Defense Department requesting troops to protect ICE personnel and facilities.”

    AP’s article also offers “a snapshot of where things stand with federal law enforcement activity in Chicago, Portland, Memphis and New Orleans.” Read more, here

    Louisiana’s Gov. Jeff Landry: “Tonight, we're sending the Department of War a request to send the National Guard, asking them to deploy the National Guard here in Louisiana into our cities like New Orleans and Baton Rouge and others,” the Republican governor said Monday night on Fox TV. 

    Reminder: Landry does not need authorization to activate his own National Guard. He’s in charge of the force. 

    In Oregon: A judge set a Friday hearing for the state’s argument to block Trump’s deployment of National Guard troops, the Oregon Capital Chronicle reported Monday. In the meantime, Sen. Ron Wyden, D-Ore., “who has led the push to force the Treasury to turn over Epstein-related Treasury records of at least $1.5 billion in suspicious transactions to Senate investigators—posted a video of the ICE facility Trump claims is under siege. There were no people there at all,” Richardson wrote.

    Background: 

    Around the world

    Trump secured Netanyahu’s agreement to a Gaza plan that would make the U.S. president the temporary chairman of a board in charge of the redevelopment of the seaside Palestinian territory, the New York Times reported off the leaders’ Monday meeting.

    However, it’s far from clear that Hamas will agree to the plan, although Trump said he would back further Israeli war in Gaza if the group declines. More, here.

    The far-right digital network Black Sun Rising Militia planned to paralyze Europe in a coordinated attack on synagogues, mosques and several Swedish media houses last year, reports SVT Nyheter, the news arm of Swedish public television, after the conviction in Brazil of the network’s leader, a 35-year-old American who had been recruiting people in the Nordic countries on social media. A bit more, here.

    Lastly today: “FBI boss Kash Patel gave New Zealand officials 3D-printed guns illegal to possess under local laws,” AP reported on Tuesday, during his July visit to the country. More on that situation, and the diplomatic discomfort caused by Patel’s remarks on China, here.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA has issued an urgent advisory regarding a critical vulnerability in the Linux and Unix sudo utility CVE-2025-32463 that is currently being exploited in the wild

    This flaw allows local adversaries to bypass access controls and execute arbitrary commands as the root user, even without explicit sudoers privileges.

    Sudo Chroot Bypass (CVE-2025-32463)

    Identified as “Inclusion of Functionality from Untrusted Control Sphere,” CVE-2025-32463 stems from improper validation in the handling of the -R (–chroot) option. 

    When invoked, sudo -R /path/to/chroot command, the utility fails to verify that the target directory is secure. Attackers can craft a malicious chroot environment under their control, often in a directory they own, to trick sudo into executing code with elevated privileges. 

    This control sphere attack vector is catalogued under Related CWE: CWE-829 (Inclusion of Functionality from Untrusted Control Sphere).

    Exploit scenarios include a local user creating a directory with manipulated symbolic links and configuration files.

    Running sudo -R attacker_dir /bin/sh to spawn a root shell regardless of sudoers restrictions and potential integration into post-exploitation toolkits, enabling full system takeover.

    While there are no confirmed reports of integration in known ransomware campaigns to date, the severity of an unprivileged local user gaining root access cannot be overstated. 

    CISA has designated the vulnerability remediation Due Date of 2025-10-20. Systems left unpatched risk complete compromise of confidentiality, integrity, and availability.

    Risk FactorsDetails
    Affected ProductsSudo versions prior to 1.9.14p2 on Linux/Unix
    ImpactLocal privilege escalation—attacker gains root shell
    Exploit PrerequisitesAbility to create a malicious chroot directory
    CVSS 3.1 Score9.3  (Critical)

    Mitigations

    Organizations running any version of sudo shipping prior to patched releases must act immediately:

    • Update to the latest sudo release as detailed in the Sudo project advisory.
    • If patches cannot be deployed, disable the -R option by adding Defaults !use_chroot in /etc/sudoers.
    • For cloud and managed services, follow binding operational directives to ensure secure configuration baselines.
    • Scan systems for unusual chroot usage patterns and review logs for sudo invocations that reference untrusted directories.

    CISA’s alert highlights the importance of vigilant patch management and ongoing monitoring. Administrators should verify compliance with vendor instructions or discontinue vulnerable implementations where mitigations are unavailable. 

    Failure to address this vulnerability by the 2025-10-20 deadline may result in unauthorized root access, data breaches, or system-wide compromise.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Three new vulnerabilities in Google’s Gemini AI assistant suite could have allowed attackers to exfiltrate users’ saved information and location data.

    The vulnerabilities uncovered by Tenable, dubbed the “Gemini Trifecta,” highlight how AI systems can be turned into attack vehicles, not just targets. The research exposed significant privacy risks across different components of the Gemini ecosystem.

    While Google has since patched the issues, the discovery serves as a critical reminder of the security challenges inherent in highly personalized, AI-driven platforms. The three distinct vulnerabilities targeted separate functions within Gemini.

    Gemini Trifecta

    Gemini Cloud Assist: A prompt-injection vulnerability in the Google Cloud tool could have enabled attackers to compromise cloud resources or execute phishing attempts. Researchers found that log entries, which Gemini can summarize, could be poisoned with malicious prompts. This represents a new attack class where log injections can manipulate AI inputs.

    Gemini Search Personalization Model: This search-injection flaw gave attackers the ability to control Gemini’s behavior by manipulating a user’s Chrome search history. By injecting malicious search queries, an attacker could trick Gemini into leaking a user’s saved information and location data.

    Gemini Browsing Tool: A vulnerability in this tool allowed for the direct exfiltration of a user’s saved information. Attackers could abuse the tool’s functionality to send sensitive data to an external server.

    The core of the attack methodology involved a two-step process: infiltration and exfiltration. Attackers first needed to inject a malicious prompt that Gemini would process as a legitimate command.

    Tenable discovered stealthy methods for this “indirect prompt injection,” such as embedding instructions within a log entry’s User-Agent header or using JavaScript to add malicious queries to a victim’s browser history silently.

    Once the prompt was injected, the next challenge was to extract the data, bypassing Google’s security measures that filter outputs like hyperlinks and image markdowns.

    The researchers discovered they could exploit the Gemini Browsing Tool as a side channel. They crafted a prompt that instructed Gemini to use its browsing tool to fetch a URL, embedding the user’s private data directly into the URL request sent to an attacker-controlled server.

    This exfiltration occurred through tool execution rather than response rendering, circumventing many of Google’s defenses.

    Google has successfully remediated all three vulnerabilities. The fixes include stopping hyperlinks from rendering in log summaries, rolling back the vulnerable search personalization model, and preventing data exfiltration through the browsing tool during indirect prompt injections.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Patchwork, the advanced persistent threat (APT) actor also known as Dropping Elephant, Monsoon, and Hangover Group, has been observed deploying a new PowerShell-based loader that abuses Windows Scheduled Tasks to execute its final payload. Active since at least 2015 and focused on political and military intelligence across South and Southeast Asia, Patchwork is renowned for […]

    The post Patchwork APT: Leveraging PowerShell to Create Scheduled Tasks and Deploy Final Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Veeam Backup & Replication, a cornerstone of many enterprises’ data protection strategy, has reportedly become the focus of a new exploit being offered on a clandestine marketplace.

    According to a recent listing, a seller operating under the handle “SebastianPereiro” claims to possess a remote-code-execution (RCE) exploit targeting specific Veeam 12.x builds.

    Dubbed the “Bug of June 2025,” the exploit allegedly bypasses standard authentication mechanisms and grants full server control. Early signs point to a vulnerability with CVE-2025-23121, though no formal proof-of-concept has been released publicly.

    The listing specifies that successful exploitation requires only any valid Active Directory account, significantly lowering the bar for threat actors who have gained domain credentials through phishing or other lateral-movement techniques.

    Payment is set at $7,000 in cryptocurrency, with interested buyers directed to private message the seller.

    While the absence of a publicly shared proof-of-concept limits independent verification, the potential impact on backup infrastructure is profound; compromised systems could be leveraged to exfiltrate, encrypt, or permanently destroy backups.

    ThreatMon analysts noted that enterprises running Veeam Backup & Replication in mixed Windows-Linux environments might be especially vulnerable due to differences in logging and patch-management workflows.

    Organizations delaying patches for test or compliance reasons could inadvertently extend their exposure window, increasing the risk of a successful breach.

    In response, security teams are advised to prioritize audit of Active Directory accounts with elevated privileges, verify patch levels on all Veeam servers, and monitor for anomalous service-account usage.

    Infection Mechanism

    The exploit appears to leverage improper input validation in Veeam’s REST API endpoint. An attacker authenticates with any AD account and submits a specially crafted JSON payload to the /api/sessions/startBackup endpoint, injecting shell commands directly into the backup session creation logic.

    A simplified proof-of-concept in PowerShell might resemble:-

    $uri = "https://veeam-server:4443/api/sessions/startBackup"
    $payload = @{
        jobName = "WeeklyBackup";
        preScript = "powershell -Enc SQBuAG..."  # Base64-encoded malicious command
    } | ConvertTo-Json
    Invoke-RestMethod -Uri $uri -Method Post -Body $payload -Credential (Get-Credential) -UseBasicParsing

    This payload instructs the service to execute arbitrary PowerShell code under the context of the Veeam service account, granting the attacker elevated privileges and full control over backup jobs and repository contents.

    Continuous monitoring of API traffic and strict AD account hygiene are critical to detecting and disrupting this attack vector.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors Allegedly Listed Veeam RCE Exploit for Sale on Dark Web appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • China-linked advanced persistent threat (APT) group Phantom Taurus has intensified espionage operations against government and telecommunications targets across Africa, the Middle East, and Asia, deploying a newly discovered .NET malware suite called NET-STAR. First tracked by Unit 42 in June 2023 as cluster CL-STA-0043 and temporarily designated TGR-STA-0043 (Operation Diplomatic Specter) in May 2024, the […]

    The post New Chinese Nexus APT Group Targeting Organizations to Deploy NET-STAR Malware Suite appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶