-
CISOs know their field. They understand the threat landscape. They understand how to build a strong and cost-effective security stack. They understand how to staff out their organization. They understand the intricacies of compliance. They understand what it takes to reduce risk. Yet one question comes up again and again in our conversations with these security leaders: how do I make the impact
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in NVIDIA’s NVDebug tool could allow attackers to gain elevated system access, execute code, or tamper with data. NVIDIA released a security bulletin on September 8, 2025, reporting three distinct flaws in the NVDebug tool and urging all users to update to version 1.7.0 or later. Failure to update may expose systems […]
The post NVIDIA NVDebug Tool Vulnerability Lets Attackers Gain Elevated System Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he terms “gross cybersecurity negligence,” accusing the tech giant of knowingly shipping its Windows operating system with a dangerously outdated form of encryption that has enabled devastating ransomware attacks on U.S. critical infrastructure, including major healthcare systems.
In a letter addressed to FTC Chair Andrew N. Ferguson on September 10, 2025, Senator Wyden argued that Microsoft’s insecure default settings have created a fertile ground for cybercriminals, directly threatening U.S. national security.
The letter highlights a hacking technique known as “Kerberoasting,” which exploits Microsoft’s continued support for RC4, an obsolete encryption technology developed in the 1980s.
While modern and secure encryption standards like the Advanced Encryption Standard (AES) are available, Microsoft has not made them the default requirement in its widely used Active Directory software.
The Ascension Ransomware Attack
The letter details a 2024 ransomware attack on Ascension, one of the largest non-profit health systems in the United States, as a prime example of Microsoft’s alleged failures.
The incident began when a contractor clicked on a malicious link from a Microsoft Bing search result, inadvertently downloading malware.
From this single entry point, hackers moved across Ascension’s network and used the Kerberoasting technique to exploit the weak RC4 encryption in the organization’s Microsoft Active Directory server.
This allowed them to gain administrative privileges, deploy ransomware across thousands of computers, and steal the sensitive data of 5.6 million patients.
The attack severely disrupted Ascension’s ability to provide patient care.
Senator Wyden’s office stated it had urged senior Microsoft officials in July 2024 to issue clear warnings about the threat posed by Kerberoasting.
In response, Microsoft published a highly technical blog post in October 2024, recommending mitigation steps and promising a future software update to disable the vulnerable RC4 encryption.
However, Wyden criticized the company’s disclosure as inadequate, noting it was posted on an obscure part of its website without meaningful publicity.
Furthermore, eleven months later, the promised security update has yet to be released, leaving countless organizations vulnerable.
The Senator pointed out the hypocrisy of Microsoft’s inaction, as U.S. cybersecurity agencies, including CISA, the FBI, and the NSA, have all issued public guidance specifically warning against Kerberoasting and advising the disabling of RC4 encryption.
A comprehensive guide from CISA and the NSA, authored by Australian national security agencies in September 2024, identified Kerberoasting as the top threat against Microsoft’s Active Directory software.
Wyden also referenced a Cyber Safety Review Board report that found Microsoft’s security culture “inadequate and requires an overhaul,” a finding that followed a major hack of U.S. government agencies by China in July 2023.
The Senator concluded by accusing Microsoft of profiting from its own insecure products by selling add-on cybersecurity services, comparing the company to “an arsonist selling firefighting services to their victims.”
He urged the FTC to take immediate action to hold Microsoft accountable for its monopolistic and negligent practices.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
The post Senator Calls for FTC Investigation into Microsoft’s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Senator Ron Wyden has formally requested the Federal Trade Commission investigate Microsoft for cybersecurity negligence that has enabled ransomware attacks against critical infrastructure organizations nationwide. In a September 10 letter to FTC Chair Andrew Ferguson, Wyden detailed how Microsoft’s dangerous software engineering decisions have made Windows systems extremely vulnerable to sophisticated cyberattacks. The senator’s investigation […]
The post Wyden Urges FTC to Investigate Microsoft Over Weak RC4 Encryption Enabling Kerberoasting appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
FastNetMon today announced that it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe. The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed. The malicious traffic was primarily a UDP flood launched from compromised customer-premises equipment (CPE), including IoT devices and […]
The post 1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
FastNetMon today announced that it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe.
The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed. The malicious traffic was primarily a UDP flood launched from compromised customer-premises equipment (CPE), including IoT devices and routers, across more than 11,000 unique networks worldwide.
The disclosure comes only days after Cloudflare reported mitigating an 11.5 Tbps DDoS attack, showing how attackers are pushing both packet and bandwidth volumes to unprecedented levels.
“This event is part of a dangerous trend”, said Pavel Odintsov, Founder of FastNetMon. “When tens of thousands of CPE devices can be hijacked and used in coordinated packet floods of this magnitude, the risks for network operators grow exponentially. The industry must act to implement detection logic at the ISP level to stop outgoing attacks before they scale.”
FastNetMon Advanced platform is designed to handle attacks of this size. Using highly optimised C++ algorithms for real-time network visibility, FastNetMon enabled its customer to automatically detect the flood within seconds — preventing disruption to the target service.
About FastNetMon
FastNetMon is a leading solution for network security, offering advanced DDoS detection and mitigation. With real-time analytics and rapid response capabilities, FastNetMon helps organisations protect their infrastructure from evolving cyber threats. For more information, users can visit fastnetmon.
The post 1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two intelligence-coordination centers would shrink or be closed under a reorganization plan that some observers say will hinder the U.S. ability to counter spies and terrorists.
The Office of the Director of National Intelligence is considering either closing or greatly reducing the National Counterintelligence and Security Center and the National Counterterrorism Center, according to two current officials, several former senior intelligence officials, and others with direct knowledge. It’s the latest move in a broad restructuring of the U.S. intelligence community.
Certain elements of that restructuring, which spans ODNI, CISA, the FBI, NSA, CIA, and other agencies, are already harming information sharing with partner intelligence agencies around the world, multiple sources told Defense One. The changes, they say, are exposing the U.S. government, businesses, and civilians to a wide range of new espionage threats.
Established in 2004, the National Counterrorism Center houses some of the most secret and valuable intelligence under government control, the Terrorist Identities Datamart Environment. The center fuses information across intelligence agencies to produce new insights into potential threats and strategies for preventing or deterring terrorism.
And while the existence of the National Counterintelligence and Security Center at ODNI is not widely known, it plays a key role in U.S. understanding of how spies are spying on us, as one source succinctly put it. So while it rarely makes big headlines, the failure of counterintelligence operations could result in the loss of critical U.S. secrets.
The counterintelligence center’s most important role, according to former senior intelligence officials, is coordinating counterintelligence activities across the government, essentially ensuring that those who “run double agents against bad guys” are aligned and not working at cross-purposes.
But the center performs a wide variety of other tasks as well. It coordinates intelligence from within the U.S. government and from foreign intelligence entities in order to build a broad picture of emerging espionage campaigns. One example is the ongoing Chinese government efforts to recruit scientists and technical workers in key industrial areas, which would leave U.S. companies with fewer qualified personnel. NCSC has also revealed investment campaigns in which the Chinese government’s ownership share in non-Chinese companies grows steadily over time.
Officials said they expect severe budget cuts to the NCSC, on top of a dramatic diminishment in the office’s size from a few months ago, when it went from five directors to just one.
“They are downgrading,” one former senior official said.
Another former senior official confirmed that both NCSC and NCTC faced severe cuts in a second round of restructuring, following the first round of program cuts in August.
“They are making those cuts,” said a source on Capitol Hill with direct knowledge.
The Senate has confirmed George Wesley Street to serve as the next director of the center, and officials said it cannot officially be closed without congressional action. But it can still be effectively ended or severely curtailed, similar to Voice of America and other agencies or offices that were targeted by the administration and today exist only as shells of their former selves.
A “chilling effect”
Since the start of President Donald Trump’s current term, the administration has taken dozens of actions to close intelligence offices, reduce intelligence capabilities, and push out officers through early retirement offers or outright firing. Those terminations are “extraordinarily dangerous,” one former senior intelligence official said, and are likely to cause intelligence workers to downplay threats if they believe acknowledging them might anger the White House.
“It doesn’t matter how many assets they have at that point,” the official said. “They’re just essentially saluting to a message that has been predetermined.”
Current and former officials agreed that some reforms could be helpful to remove bureaucratic barriers and make intelligence sharing more effective. But they said the manner in which the administration has pursued “efficiency” has been destructive and will leave the intelligence community hobbled for years to come. They pointed in particular to the decision to end ODNI’s Cyber Threat Intelligence Integration Center, or CTIIC, and the ODNI Foreign Malign Influence Center. Officials said CTIIC is critical for facilitating cyber information sharing across the U.S. government and other governments.
The Foreign Malign Influence Center, which was originally housed in the Counterintelligence Center, rose up in response to Russia’s foreign election interference efforts in the 2016 election. It was seen as one of the few remaining government centers that actually monitored how adversarial states might be trying to corrupt U.S. elections.
Another major misstep, they said, was a recent FBI decision to reassign agents who were specialists in foreign election interference and money laundering to other activities and departments.
The combination of these moves, they said, has greatly reduced the ability of the U.S. intelligence community to share information internally and with the public. But they are not sure why the changes have been made.
“There’s nobody who says that the foreign threats are diminishing. There’s nobody out there who says the risk of Chinese malicious activity, cyber activity, is going down or that the risk of Russian disinformation and cyber maliciousness is going down. It’s the exact opposite. Everyone agrees, across the board, across the political spectrum, that the foreign threats we face are on the increase—and a significant increase. So it’s perverse,” said one former senior official.
The Cyber Threat Intelligence Center, for instance, was able to synthesize information across agencies in order to reach high-confidence conclusions from all-source intelligence—conclusions that could then be presented to lawmakers and the public. The threat now, said several former officials, is that agencies will miss key trends or clues that could reveal future cyber attacks.
“Some things are just going to get left on the cutting room floor,” one official said.
That type of coordination that happened between the CTIIC, the Counterintelligence Center, the FBI, and other agencies is critical, former officials said. The recently disclosed Salt Typhoon attack, a Chinese state-backed data theft campaign targeting the personal information of millions of Americans, provides a vivid example of why. China has also launched a cyberespionage campaign targeting U.S. trade representatives, precisely the sort of broad foreign that the Counterintelligence Center and Cyber Threat Intelligence Integration Center, working together with other entities, would have been responsible for predicting, stopping, or responding to, they said.
Additionally, several officials said they had been in touch with foreign intelligence partners, including from the Five Eyes alliance, who have pulled back from sharing information with the United States because of the recent changes. That information can be crucial, especially for understanding the cyber campaigns adversaries like China may plan to use against the United States.
One former senior official said China routinely tests cyber strategies in places like Australia and New Zealand before turning them against the United States: “They might see problems or trends before we would, but we had the capability to help them,” the official said.
Much of the pullback in information sharing was not the result of political animosity against Trump, officials said, so much as logistics: partners literally do not know who to call.
The same problem can affect Americans who have information on foreign money-laundering or influence campaigns. One former senior official recounted an anecdote about an acquaintance trying to contact the FBI regarding a counterintelligence investigation. The person was told, “The entire office is out patrolling the streets of Washington, D.C. We don’t know when we’re going to be back.”
Fallout
The consequences of diminished intelligence capability may not be felt right away, two former senior officials said. In fact, the entire point of campaigns like Salt Typhoon and Volt Typhoon is to collect information and pre-position malware in the event of “some contingency or crisis in the defense of Taiwan or the defense of Japan or the defense of Hawaii,” one former senior official said.
Eventually, they worry, the United States could struggle to maintain peace, and U.S. companies could be unable to outcompete foreign rivals.
“We’re just going to find, across the board, an overall weakening of our security posture and a reduction of our leverage in international affairs, because we won’t have that power and that stability,” one official said.
ODNI did not respond to request for comment.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in the Cursor AI Code Editor exposes developers to stealthy remote code execution (RCE) attacks when opening code repositories, security researchers warn. The flaw, discovered by Oasis Security, allows attackers to deliver and run harmful code automatically, with no warning prompt, putting vital secrets and cloud access at risk. Vulnerability Breakdown Cursor, […]
The post Cursor AI Code Editor RCE Flaw Allows Malicious Code to Autorun on Machines appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
External penetration testing is a crucial practice for any organization aiming to validate its security posture against real-world threats. In 2025, with the proliferation of cloud services, SaaS applications, and remote work, an organization’s external attack surface is larger and more complex than ever. An external penetration test simulates a real-world cyber attack, targeting public-facing […]
The post Top 10 Best External Penetration Testing Companies in 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
FastNetMon today announced it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe. The attack peaked at 1.5 billion packets per second (1.5 Gpps), making it one of the largest packet-rate floods ever publicly disclosed. The malicious traffic was primarily a UDP flood launched from […]
The post DDoS Mitigation Provider Hit by Massive 1.5 Billion Packets Per Second Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


