• Six F-35Bs were spotted landing in Puerto Rico on Saturday as the Trump administration continues using the military to fight drug trafficking around Latin America, Reuters and The War Zone reported Saturday. Four more are reportedly on the way. 

    President Trump last week ordered 10 of the cutting-edge aircraft to the region just days after the U.S. military said its troops killed 11 people in a speedboat allegedly transporting drugs to the U.S., though no evidence has been provided to back up those claims, as the New York Times reported Wednesday following a Pentagon briefing on Capitol Hill. 

    For what it’s worth, “the F-35s seen landing…have no unit markings on their tails. This could be [a] force protection/security tactic, but the reason isn’t clear at this time,” TWZ’s Howard Altman observed. 

    There are already at least eight U.S. Navy vessels in the region, including a nuclear-powered submarine. “A second flight of four F-35s from MCAS Yuma is also headed toward Puerto Rico,” Altman reported, citing open-source flight trackers like this

    New: Venezuelan officials say the U.S. Navy raided a tuna boat in Venezuelan waters on Saturday. Eighteen U.S. troops reportedly boarded the vessel during an “illegal” search that lasted around eight hours, the Associated Press reports, citing Venezuelan Foreign Minister Yván Gil. The nine fishermen onboard the vessel “were then released under escort by the Venezuelan navy,” AP writes.


    Welcome to this Monday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson with Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1916, tanks were first used in war at the Battle of Flers-Courcelette during the Battle of the Somme.

    Around the world

    Another Russian drone breached NATO airspace last week, prompting Romania to scramble two F-16 fighter jets after radar detected a Russian drone in Romanian airspace at about 6 p.m. local time. 

    The drone incursion lasted 50 minutes, and didn’t cause any damage or casualties, Foreign Minister Oana-Silvia Țoiu said.  

    “This is Russia’s second incursion into NATO airspace over the course of four days,” analysts at the Washington-based Institute for the Study of War noted in their latest assessment. It’s also the 11th incursion into Romanian airspace since Russia launched its full-scale Ukraine invasion in 2022, Romanian officials told ABC News. Reuters has a bit more. 

    Update: Trump backed off his latest promise to sanction Russia further, writing Saturday online that he wants all NATO allies to stop buying Russian oil and place 50 to 100% tariffs on China first—then he said he’d be “ready to do major Sanctions on Russia.” The New York Times reports “The condition is almost certain not to be met, which Mr. Trump and his advisers know.”

    Background: “The European Union had been heavily dependent on Russian energy before Moscow's invasion of Ukraine. It has taken steps to reduce those purchases, but they have not disappeared entirely,” NPR explains. For example, behind China and India, Turkey is Russia’s third-largest importer of oil, followed closely by Hungary.

    Panning out: “Trump has repeatedly threatened to punish Russia with new sanctions if it refuses to reach an agreement with Ukraine, but has failed to follow through as Moscow has ignored several deadlines,” Time magazine writes

    Big-picture consideration: “Trump telegraphed great strength and vowed he could end Russia’s war against Ukraine with a single phone call,” Boston College historian Heather Cox Richardson explained Saturday. “When he failed to get any buy-in at all from Russia’s president Vladimir Putin for his proposals, Trump threatened to impose strong new sanctions against Russia. This afternoon he backed away from that altogether,” she said, citing Saturday’s developments. 

    Meanwhile for Ukraine, future attack drone swarms may come in the form of first-person-shooter drones produced in the country, Defense One’s Patrick Tucker reports. Those swarms could also come via new platforms Western defense companies are putting into the mix. But it’s also possible they’ll be a combination of both—old and new drones working together with minimal human interaction, according to a Ukrainian startup called Swarmer, which is pioneering software that can work with virtually any platform.  

    The drones linked together via Swarmer’s software can “exchange the targets, or they can choose the appropriate payload. Different drones can use and carry different kinds of payloads for different targets,” founder Serhii Kupriienko told Tucker. “They can execute complicated scenarios like [target] discovery, and they can give you visual confirmation of the damage [after the strike]. It could be done by the group of drones.” Continue reading, here

    Typhon missile debuts in Japan, drawing China’s ire. Monday’s appearance of the U.S. Army’s newest intermediate-range missile system in an exercise in Western Japan “underscor[es] Washington and Tokyo's growing willingness to field weapons that Beijing has condemned as destabilising,” writes Reuters. That follows the launcher’s 2024 deployment to the Philippines, “a move that drew sharp criticism from Beijing and Moscow, which accused the U.S. of fuelling an arms race.”

    Expert reax: “In the past, these deployments would have been nixed by DC and Tokyo bureaucrats out of fear of the Chinese reaction. You can see that's less of an issue than it was, say five years ago,” said Grant Newsham, a Japan Forum for Strategic Studies research fellow and retired U.S. Marine Corps colonel who worked alongside the Japanese military. Read on, here.

    From the region: Australian government pledges $12B to nuclear submarine precinct ahead of PM’s US visit,” the Sydney Morning Herald reported Saturday. 

    Around the Defense Department

    Drone boats, new landing craft get Army Pacific tryouts. “Robot boats. Counter-drone systems. A prototype Army landing craft. A million dollars in cash prizes. It’s all part of the Army’s effort to overcome logistics challenges in the Indo-Pacific and get new technology in the hands of soldiers more quickly,” writes Defense One’s Jennifer Hlad, reporting from Honolulu. Read on, here.

    What does the White House’s “Department of War” push mean for the Pentagon’s networks? Officials aren’t quite sure. The short-notice and so-far-unofficial change has IT leaders scrambling to rename networks and services—and avoid unfortunate rebrandings such as “DOWNet” for the nascent DODNet network. Defense One’s Lauren C. Williams has more on the uncertainty, here

    Trump 2.0

    After declaring nine “national emergencies,” Trump on Monday threatened to declare a tenth—this one doubling down on the “crime emergency” declared for the District of Columbia. The reason? The mayor said last week that its police would not cooperate with Immigration and Customs Enforcement. 

    “If I allowed this to happen, CRIME would come roaring back,” the president wrote on his social media platform Monday morning. “To the people and businesses of Washington, D.C., DON’T WORRY, I AM WITH YOU, AND WON’T ALLOW THIS TO HAPPEN. I’ll call a National Emergency, and Federalize, if necessary!!!”

    Rewind: Just last month, Reuters reminds readers, Trump ordered “the metropolitan police department under direct federal control and sent federal law enforcement, including members of the Immigration and Customs Enforcement, to police the streets. It is unclear when their mission will end.”

    It’s also not clear just what role ICE has played in arrests during the takeover, the Washington Post reported Sunday in an analysis of arrest statistics.

    Reminder: Trump offered false and exaggerated crime statistics to justify the National Guard’s deployment to D.C. and a takeover of the local police. 

    Related reading:How Trump’s Crime Crackdown Muted Other Parts of D.C. Life,” via the New York Times, reporting Thursday.  

    A study finds more than 100 court cases in which the Trump administration has undermined the “presumption of regularity,” a legal doctrine that prescribes a benefit of the doubt for the U.S. government—or, as the study’s half-dozen authors write for Just Security, an assumption that Justice Department officials act inside the courtroom “with procedural regularity and with bona fide, non-pretextual reasons.” 

    Among the findings: 

    • Judges said they did not trust information from the Trump administration in more than three dozen different cases, including allegations of “false sworn statements, contradictions with the record, refusals or inability to answer basic questions,” and more; 
    • Courts found administration officials acted in either an “arbitrary” or “capricious” manner in more than 50 cases; 
    • And courts found administration officials did not comply with judges’ orders in at least 15 cases involving an explicit violation of a court order—either through “willful disobedience, ignoring court-imposed deadlines, [and/or] refusing to provide court-ordered information.” 

    Why it matters: In short, it breaks long-held norms that helped the executive branch move cases along. Or as the authors write, “since the presumption of regularity is based on the notion that agencies generally follow regular procedures, what happens if the baseline order of business is different? What if arbitrary and capricious conduct was instead widespread or pervasive?” In those instances, “The application of the presumption would lose the basis for its support,” and the administration may have to work harder to justify its allegations in court. 

    Additional reading: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has resolved a significant audio bug in Windows 11 version 24H2 that prevented Bluetooth headsets and speakers from functioning correctly on certain devices.

    The issue, which first appeared in December 2024, has now been fixed through a new driver update, and the company has lifted the temporary block that prevented affected users from installing the latest version of the operating system.

    The problem originated from a software incompatibility on a specific set of devices from a single manufacturer that utilize Dirac Audio technology.

    After installing the Windows 11 24H2 update, users on these machines reported a complete loss of audio output. The issue affected integrated speakers, connected Bluetooth speakers, and wireless headsets, with applications failing to recognize the audio hardware.

    Microsoft’s investigation identified the root cause as a conflict with the cridspapo.dll file, a software component associated with the Dirac Audio processing suite, which is designed to enhance sound clarity and precision.

    To prevent more users from encountering the audio failure, Microsoft initiated a “compatibility safeguard hold” on December 18, 2024. This measure automatically blocked devices containing the problematic cridspapo.dll file from receiving the Windows 11 24H2 update through the standard Windows Update channel.

    Users with affected hardware would see a message in their settings indicating that the upgrade was on its way but temporarily paused, directing them to more information about the specific safeguard hold (ID: 54283088). This proactive step ensured the issue remained contained while a permanent solution was developed.

    As of September 12, 2025, the audio issue is officially resolved. Microsoft has released a new version of the audio driver via Windows Update that corrects the incompatibility. Consequently, the company removed the safeguard hold on September 11, 2025.

    Users with previously affected devices should now be able to install Windows 11, version 24H2, without issue, provided no other compatibility holds are in place.

    Microsoft advises that it may take up to 48 hours for the update to become available to all eligible devices, and a simple system restart might help expedite the process. Users are encouraged to install the latest security updates to receive this and other important fixes.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Microsoft Fixes Windows 11 24H2 Audio Issue that Stops Bluetooth Headsets and Speakers Working appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Burger King has invoked the U.S. Digital Millennium Copyright Act (DMCA) to force the removal of a security researcher’s blog post that exposed critical vulnerabilities in its drive-thru “Assistant” system. 

    The move has caused a debate over the use of copyright law to suppress legitimate cybersecurity disclosures.

    Key Takeaways
    1. Burger King issued a DMCA takedown of AWS Cognito drive-thru flaw research.
    2. RBI fixed the bugs but the takedown sparked widespread reposting.
    3. Critics warn this restricts open security disclosure.

    BobDaHacker discovered multiple vulnerabilities in the still-in-beta “Assistant” platform, built on AWS Cognito, which is being piloted at select Burger King and Popeyes locations. 

    A researcher wrote a blog post called “We Hacked Burger King.” In it, they explained a security problem that allowed anyone to sign up for an account without proper checks. This flaw also resulted in sending user credentials in plain text through email.

    Exploiting this, BobDaHacker accessed the entire system, leveraging a GraphQL mutation to escalate to administrator privileges across all connected restaurants. 

    From that vantage, the researcher could add or remove stores, view and edit employee accounts, and even interact with drive-thru audio devices.

    Despite following responsible disclosure protocols, reporting the flaws to Restaurant Brands International (RBI) just one hour after discovery, BobDaHacker received a takedown notice from threat intelligence firm Cyble. 

    The notice alleged trademark infringement and accused the researcher of promoting illegal activity and disseminating false information. 

    The complaint, marketed as “brand protection,” cited unauthorized use of the “Burger King” trademark and threatened legal action under “gross unfair competition.”

    Within hours of the DMCA notice, multiple cybersecurity professionals began sharing archived copies of the original report on Mastodon, invoking the Streisand effect.

    Screenshots of Barbra Streisand meme references underscored the backlash against using DMCA to stifle security research.

    An RBI spokesperson told Information Security Media Group that the Assistant program is in early testing and retains neither customer identities nor long-term data. 

    “The intent of this test program is to help team members deliver a better guest experience,” the statement read.  RBI stressed features such as order accuracy verification and real-time equipment notifications, but declined to comment on the legal notice or Cyble’s involvement.

    BobDaHacker maintains that no sensitive customer data was stored or exfiltrated during testing. 

    RBI patched the reported flaws the same day BobDaHacker disclosed them. Yet, the swift DMCA action has raised concerns about whether companies might weaponize copyright claims to avoid reputational damage instead of engaging with the security community. 

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Burger King Uses DMCA Complaint to Take Down Blog Post Detailing Security Flaws on Drive-Thru Systems appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In mid-July 2025, a novel campaign emerged in which cybercriminals weaponized generative AI to fabricate deepfake images of government IDs, embedding them within spear-phishing messages that bypassed traditional antivirus safeguards.

    These emails impersonated military and security institutions, complete with convincing visual assets generated by ChatGPT.

    Recipients were urged to review “draft” ID cards, triggering the download of malicious archives that executed obfuscated scripts.

    The sophistication of this operation underscores a troubling evolution in adversary tactics, blending artificial intelligence with legacy evasion techniques to infiltrate sensitive networks.

    Attack Scenario (Source – Genians)

    The threat actor, attributed to the Kimsuky group, leveraging both AutoIt and PowerShell, delivered a multi-stage payload from South Korean C2 servers.

    Initially, a compressed archive contained a shortcut file masquerading as a legitimate document.

    Impersonating a Draft Review Request for Military Employee ID Cards (Source – Genians)

    When opened, this shortcut invoked a batch command via cmd[.]exe to assemble malicious instructions stored in an environment variable.

    These commands drove a series of HTTP requests to retrieve a deepfake PNG file and a batch script, both of which executed immediately upon arrival.

    Genians analysts identified that the batch script employed environment-variable slicing—extracting characters one at a time using expressions like "% ab901ab [:] ~ 7,1 %"—to reconstruct the commands required for payload deployment.

    This technique not only conceals malicious intent from signature-based engines but also evades heuristic detection by delaying visible actions until the full command string is built.

    Metadata within the downloaded image confirmed its AI-generated origin, flagging it as a deepfake with 98% probability when analyzed through a specialized detector.

    Despite its reliance on advanced AI heuristics, the campaign still hinged on classic persistence and obfuscation strategies.

    Victims’ machines registered scheduled tasks under the guise of legitimate software updates, ensuring the payload ran at regular intervals.

    The combined use of generative-AI assets and automated scripting created a hybrid threat that challenges conventional antivirus products.

    Security teams must therefore augment their defenses with behavioral analysis and endpoint detection and response (EDR) solutions capable of monitoring script activity and scheduled-task creation in real time.

    Infection Mechanism

    The initial wave began with a spear-phishing email disguised as a draft review of government ID cards.

    Recipients clicking the link received a ZIP archive named Government_ID_Draft[.]zip containing Government_ID_Draft[.]lnk.

    This shortcut launched cmd[.]exe with a long string assigned to an environment variable, then leveraged character slicing to rebuild the malicious PowerShell command dynamically.

    Upon reconstruction, the script fetched two payloads: a deepfake PNG file rendered by ChatGPT and an accompanying batch script.

    AI-Generated Virtual ID Card (Source – Genians)

    The batch script then created a scheduled task named "HncAutoUpdateTaskMachine", disguised as a Hancom Office update, to execute HncUpdateTray[.]exe and its accompanying config[.]bin on a seven-minute interval.

    Obfuscation persisted within the AutoIt-compiled script, which used a variation of the Vigenère cipher to encrypt configuration strings and hinder static analysis.

    This layered approach to infection and persistence illustrates a new level of adversary innovation, integrating generative AI with traditional malware delivery pipelines.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Hackers Using Generative AI ‘ChatGPT’ to Evade Anti-virus Defenses appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Sidewinder, a well-known advanced persistent threat (APT) group, has adapted its tactics to exploit the ongoing protests in Nepal, deploying a coordinated campaign of mobile and Windows malware alongside credential phishing. By masquerading as respected national institutions and figures, the group seeks to harvest sensitive data from users tracking the nation’s political turmoil. The protests, […]

    The post Sidewinder Hackers Weaponize Nepal Protests to Spread Cross-Platform Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The BlackNevas ransomware group has emerged as a significant threat since November 2024, continuously launching devastating attacks against businesses and critical infrastructure organizations across Asia, North America, and Europe.

    This sophisticated malware operation combines file encryption with data theft tactics, threatening to leak stolen information if ransom demands are not met within seven days.

    The ransomware demonstrates a particularly aggressive targeting strategy, with approximately 50% of its attacks focused on the Asia-Pacific region.

    Countries including Japan, Thailand, and South Korea have experienced substantial impacts, while European targets span Western Europe and the Baltic Sea region, including the United Kingdom, Italy, and Lithuania. In North America, the group has specifically targeted organizations in Connecticut.

    Threat actor’s Telegram address within the ransom note (Source – ASEC)

    ASEC researchers identified that BlackNevas operates independently without following the traditional Ransomware-as-a-Service model.

    The threat actors maintain their own data leak site and claim partnerships with affiliated groups to pressure victims into compliance.

    The malware appends the distinctive “.-encrypted” extension to compromised files, making the encryption immediately apparent to victims.

    Unlike many ransomware variants that incorporate anti-debugging or sandbox evasion techniques, BlackNevas takes a different approach by supporting multiple command-line arguments that modify its behavior.

    The malware includes parameters such as “/fast” for encrypting only one percent of file content, “/full” for complete file encryption, and “/stealth” for changing extensions and creating ransom notes during the encryption process.

    Advanced Encryption Implementation and File Targeting Strategy

    The ransomware employs a sophisticated dual-encryption approach combining AES symmetric keys with RSA public key cryptography.

    During the encryption process, BlackNevas generates a unique AES key for each file, encrypts the content, then secures the AES key using an embedded RSA public key before appending it to the end of the encrypted file.

    The malware demonstrates selective targeting by excluding critical system files to maintain system stability.

    Test environment after encryption is complete and the desktop is changed (Source – ASEC)

    Protected extensions include sys, dll, exe, log, bmp, vmem, vswp, vmxf, vmsd, scoreboard, nvram, and vmss files, along with specific files like “NTUSER.DAT” and its own ransom note “how_to_decrypt.txt”.

    Interestingly, BlackNevas creates two distinct filename patterns during encryption: standard files receive randomized names with the “-encrypted” extension, while specific document types including doc, docx, hwp, jpg, pdf, png, rtf, and txt files are prefixed with “trial-recovery” as a demonstration of decryption capabilities.

    Ransom note (Source – ASEC)

    The encryption verification process involves checking 8-byte values at file endings to determine encryption status and file type classification.

    This methodology eliminates local decryption possibilities, as the RSA private key remains exclusively with the attackers, making file recovery impossible without paying the ransom or possessing advanced cryptographic capabilities.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated phishing operation in which attackers deploy remote monitoring and management (RMM) tools—ITarian (formerly Comodo), PDQ Connect, SimpleHelp, and Atera—to gain persistent remote access to compromised systems. By disguising malicious installers as legitimate browser updates, meeting or party invitations, and government forms, adversaries exploit users’ trust in commonly used IT administration software. Security researchers […]

    The post Phishing Campaigns Exploit RMM Tools to Sustain Remote Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Burger King has invoked the Digital Millennium Copyright Act to force the removal of a security researcher’s blog post that disclosed serious vulnerabilities in its new drive-thru “Assistant” system. Ethical hacker BobDaHacker published a report showing how attackers could bypass authentication, listen in on customer orders, and access employee records before a takedown notice took […]

    The post Burger King Uses DMCA to Remove Blog Exposing Drive-Thru System Security Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity landscape witnessed a significant escalation in July 2025 when the China-aligned threat actor Hive0154, commonly known as Mustang Panda, deployed sophisticated new malware variants designed to breach air-gapped systems.

    This advanced persistent threat group introduced SnakeDisk, a novel USB worm, alongside an updated Toneshell9 backdoor, representing a calculated evolution in their cyber espionage capabilities targeting East Asian networks.

    The campaign demonstrates Mustang Panda’s strategic focus on circumventing traditional network security measures through physical propagation methods.

    SnakeDisk operates with geographical precision, executing only on systems with Thailand-based IP addresses, suggesting highly targeted operations coinciding with recent geopolitical tensions between Thailand and Cambodia.

    The malware’s selective activation mechanism reflects the group’s sophisticated operational security and desire to minimize exposure while maximizing impact against specific targets.

    IBM analysts identified these malware variants through a comprehensive analysis of weaponized archives uploaded from Singapore and Thailand throughout mid-2025.

    The researchers discovered that SnakeDisk shares significant code overlaps with previous Tonedisk variants while introducing enhanced evasion techniques and air-gap penetration capabilities.

    The USB worm’s deployment alongside the Yokai backdoor indicates a multi-stage infection strategy designed to establish persistent access across isolated network environments.

    The threat actor’s operational methodology involves distributing weaponized archives through cloud storage platforms like Box, often disguised as legitimate documents from government agencies.

    These archives contain trojanized software that sideloads malicious DLLs, initiating the infection chain. Once established, the malware establishes persistence through scheduled tasks and registry modifications, ensuring continued access even after system reboots.

    PDF containing download link for weaponized archive deploying Toneshell7 (Source – IBM)

    The emergence of these tools coincides with escalating border conflicts between Thailand and Cambodia, suggesting state-sponsored motivations behind the campaign.

    Mustang Panda’s ability to develop geographically-targeted malware demonstrates their advanced technical capabilities and strategic intelligence gathering operations.

    Advanced USB Propagation and Air-Gap Penetration Mechanisms

    SnakeDisk employs sophisticated techniques to weaponize USB devices and penetrate air-gapped systems.

    The malware begins execution by parsing a configuration file using a custom two-phase XOR decryption algorithm with a 320-byte key.

    This configuration contains 18 string values that define the worm’s operational parameters, including directory structures, file names, and persistence mechanisms.

    The USB infection process starts with comprehensive device detection using the Windows API IOCTL_STORAGE_GET_HOTPLUG_INFO to identify removable storage devices.

    Upon detecting a USB drive, SnakeDisk creates a sophisticated file structure that hides the user’s original files within subdirectories while placing a weaponized executable in the root directory.

    The malware uses both SHFileOperationW and robocopy commands to relocate existing files, as demonstrated in the following operation:

    robocopy <drive_letter>:\ <drive_letter>:\<urd>\<uud>\ /XD "<drive_letter>:\<urd>\" /XF "<drive_letter>:\<unendl_org>" /E /MOVE

    This process creates multiple hidden directories with SYSTEM and HIDDEN attributes, effectively concealing the malicious infrastructure while maintaining the appearance of a normal USB device.

    The worm establishes a Windows message loop to monitor for WM_DEVICECHANGE events, enabling real-time detection of USB insertion and removal events.

    When a device is removed, SnakeDisk triggers payload execution, dropping the Yokai backdoor into the C:\Users\Public\ directory through a series of concatenated encrypted files that reconstruct the final malicious executable upon deployment.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Mustang Panda With SnakeDisk USB Worm and Toneshell Backdoor Seeking to Penetrate Air-Gap Systems appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Red AI Range (RAR), an open-source AI red teaming platform, is transforming the way security professionals assess and harden AI systems. 

    Designed to simulate realistic attack scenarios, RAR streamlines the discovery, analysis, and mitigation of AI-specific vulnerabilities by leveraging containerized architectures and automated tooling. 

    Key Takeaways
    1. Arsenal/Target buttons spin up isolated AI testing containers.
    2. Recording, status dashboard, and compose export optimize workflows.
    3. Training modules plus remote GPU agents scale AI red teaming.

    By integrating RAR into critical infrastructure testing pipelines, organizations can proactively identify weaknesses in machine learning models, data handling processes, and deployment configurations before adversaries exploit them.

    Architecture Enhance AI Vulnerability Assessment

    At the core of Red AI Range is a sophisticated Docker-in-Docker implementation that isolates conflicting dependencies across multiple AI frameworks. RAR’s docker-compose.yml defines services such as:

    AI Red Teaming Tool “Red AI Range”

    This configuration ensures that each simulated AI target and testing tool runs in its own container, preserving environmental consistency and enabling rapid resets to baseline.

    Using the “Arsenal” and “Target” buttons in the web UI, red teamers can deploy vulnerability scanners, adversarial-attack frameworks, and intentionally vulnerable AI models, each appended with _arsenal or _ai_target to their stack name for clear identification.

    Once containers are up, RAR’s interactive dashboard displays real-time activity status showing Active, Exited, and Inactive environments—and provides controls to convert running instances into reusable Docker Compose files. 

    The integrated session recorder effectively captures video recordings and timestamped logs of red teaming exercises, thereby facilitating comprehensive post-test analysis and knowledge transfer. This tool is accessible from GitHub.

    Integrated Training Modules 

    Beyond its core deployment capabilities, Red AI Range offers a comprehensive suite of training modules that cover foundational AI security concepts through advanced adversarial techniques. 

    Module topics range from poisoning attacks, such as clean-label backdoor injection, to evasion methods like Projected Gradient Descent (PGD) and Carlini & Wagner (C&W) attacks.

    Each module provides Jupyter Notebook tutorials, enabling practitioners to experiment interactively with code examples in a controlled environment.

    RAR also supports a remote agent architecture, allowing teams to distribute testing workloads across GPU-enabled hosts on AWS or on-premises GPU clusters. 

    Secure authentication between the central RAR console and remote agents ensures that large-scale vulnerability assessments, especially those targeting LLMs or high-compute models, can be coordinated seamlessly. 

    Agents register via a token-based handshake, after which they appear in the Agent Control Panel for deployment orchestration.

    By consolidating AI-specific vulnerabilities, automation tools, and training resources into a unified framework, Red AI Range empowers security teams to elevate their AI red teaming operations. 

    As enterprises continue to adopt AI in critical systems, integrating RAR into regular security workflows will be essential for uncovering hidden risks, refining mitigation strategies, and maintaining trust in AI-driven services.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post New Red Teaming Tool “Red AI Range” Discovers, Analyze, and Mitigate AI Vulnerabilities appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶