Latest Analysis
Cybersecurity intelligence, threat analysis, and national security reporting.

Malvertising Campaign Exploits Browsers to Assemble Malware in Memory
Meet the sneaky malvertising campaign that's turning web browsers into malware factories, assembling attacks entirely in memory using fake pages for popular services like Solana, Luno, and TradingView. This stealthy operation has been active since late 2024, targeting users across 12 countries and 25 languages.

ShinyHunters data leaks fuel sextortion scam targeting breach victims
Beware of sextortion scam emails claiming to be from ShinyHunters, a hacking group that's actually being impersonated by copycats using leaked data to threaten victims. These scammers are sending convincing but fake messages, trying to extort money by claiming they've recorded compromising information about you.

Fastjson Vulnerability Exploited in Targeted Attacks
A critical vulnerability in Fastjson, tracked as CVE-2026-16723, has been exploited in targeted attacks, with a severity score of 9.0 out of 10. Attackers are actively probing for exposed paths in Fastjson 1.x, commonly used in Spring Boot deployments.

DevMan Ransomware Operation Centralizes Affiliate Payouts, Victim Management
Meet the DevMan Ransomware Operation's game-changing portal, where affiliates can now streamline payouts and victim management in one centralized hub. This all-in-one platform combines build generation, finance, victim chat, and support, making it a one-stop-shop for ransomware attacks.

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive
PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited vulnerabilities.

Insurance Phishing Evolves Into Real-Time Account Hijacking
Insurance phishing attacks have taken a sinister turn, now using real-time account hijacking to actively engage with victims throughout the authentication process. Cybercriminals are using sponsored Google ads to launch these attacks, luring users with offers like car insurance comparisons and then diverting them into sophisticated phishing flows.

ChatGPT Disrupted Globally as OpenAI Confirms Outage
ChatGPT is currently down worldwide, leaving users in the US, Europe, India, Japan, Australia, and beyond unable to access the popular AI chatbot. OpenAI has confirmed the outage and is actively investigating the issue.

GitLab RCE Exploit Published, Targets Unpatched Servers
A security researcher has just published a working exploit that can execute commands on unpatched GitLab servers, putting sensitive data and systems at risk. If your GitLab server is unpatched, it's crucial to update now to prevent potential code execution and data breaches.

China's PLA Unveils Advanced Landing Barges in Strategic Photos
Get a first look at China's PLA's latest game-changer: the advanced landing barge, East Engineering 403, revealed in stunning strategic photos. This sleek vessel's name holds secrets about its fleet and function, decoded through PLAN naming conventions.

US Coast Guard Targets Tech to Counter Uncrewed Underwater Vehicles
The US Coast Guard is on the hunt for cutting-edge tech to outsmart uncrewed underwater vehicles (UUVs), seeking solutions that go beyond detection to effectively neutralize these stealthy threats. They're calling on innovators to submit ideas for systems that can defeat UUVs, a crucial step in protecting maritime operations.

AI's Unintended Actions Demand New 'Genie Coefficient' Metric
Imagine asking a question and getting a technically correct but utterly useless response - like telling someone there's water in the fridge, but only in the cells of an eggplant. This quirky example highlights the challenge of artificial intelligence understanding human intent, and the need for a new metric to measure AI's unintended actions.

US Submarine Deployment Exposes Australia's War Planning Dilemma
Australia is set to host a powerful US submarine force at HMAS Stirling from 2027, raising crucial questions about how this combat squadron would be deployed in war and how it aligns with Australia's commitments. A US Submarine Rotational Force–West will be established, consisting of up to four attack submarines with supporting infrastructure and facilities.

Thailand Bolsters Military with Chinese VN-1C Armored Vehicles
Thailand is boosting its military firepower with a 1 billion baht deal for VN-1 armored vehicles from China, enhancing its combat capabilities under the 2025 defense budget. This significant procurement comes as part of efforts to modernize the Royal Thai Army's arsenal.

CISA Faces Industry Pushback on Cyber Incident Reporting Rule
Industry leaders are pushing back on a proposed cyber incident reporting rule, arguing it casts too wide a net, with one critic saying it would ensnare far too many companies. The rule, aimed at bolstering national security, has sparked concerns about its broad scope and reporting requirements.

Ejection Seat Makers Adapt to Pilotless Battlefield Era
As the battlefield goes pilotless, ejection seat makers like Martin-Baker are shifting gears, leveraging their life-saving expertise to support drone manufacturers and stay ahead of the curve. With a legacy of saving over 7,800 aviators, Martin-Baker is now offering its engineering and electronics prowess to help shape the future of unmanned aircraft.

Army Bolsters Readiness with CBRN Training Exercises
Soldiers from the 14th Brigade Engineer Battalion gear up for a high-stakes mission, navigating a cave to conduct crucial Chemical, Biological, Radiological, and Nuclear (CBRN) operations as part of Rotation 25-11. This intense training exercise at the National Training Center, Fort Irwin, Calif., is just one example of how the Army is bolstering its readiness.

Pope's Prayer App Leaks 700K Users' Info Amid Security Vulnerability
A shocking security breach has been uncovered in the Pope's official prayer app, Click To Pray, exposing the sensitive information of over 719,000 registered users for months due to a vulnerability that allowed anyone to access account data. The flaw, discovered by an ethical hacker, highlights the alarming risks of unsecured personal data.

Europol Disrupts The Com's Online Ecosystem with 4,340 URL Takedowns
In a major crackdown, Europol and its partners have taken down 4,340 URLs linked to The Com, a notorious online network accused of radicalizing young people and facilitating illicit activity. This coordinated effort is part of a broader mission to protect vulnerable youth and disrupt the online ecosystem of recruiters and extortionists.

US Eases Export Curbs to Boost UAE's Drone, AI Tech Production
The US has just made it easier for the UAE to supercharge its drone and AI tech production by easing export restrictions, giving them cleaner access to cutting-edge dual-use technology. This game-changing upgrade is set to take their defense capabilities to the next level.

Pentagon Urged to Reassess Costs of Advanced Energetic Materials
The US military's critical munitions come with a hefty price tag - over $1 million each. Can the Pentagon afford to keep shelling out big bucks for these pricey explosives and propellants?

Pentagon Launches Ground-Launched Precision Strike Challenge
The Defense Innovation Unit is launching the Ground-Based Affordable Mass (G-BAM) challenge, seeking cutting-edge long-range precision strike systems that can be rapidly demonstrated and delivered to production in record time - within 12-18 months. This initiative aims to harness mature, cost-effective solutions that minimize logistical burdens while maximizing impact.

Ukraine Deploys Dutch-Made Ruta Block 1 Cruise Missiles in Operational Strike
Ukraine has taken a significant step in its military operations by deploying the Dutch-made Ruta Block 1 cruise missiles in a recent strike, as revealed by newly surfaced footage. The images, shared on Russian Telegram channels, show wreckage identified as the missile, sparking insights into its capabilities and use.

Pentagon Consolidates Oracle Software Buys in $7 Billion Deal
The Department of Defense has secured a $7 billion deal with Oracle to centralize software purchases, a move that's expected to save taxpayers at least $441 million while better supporting military personnel. This unified agreement streamlines Oracle buying across the DoD, bringing transparency to enterprise usage and spending.

US Air Force Weighs Expanding B-21 Raider Fleet Beyond 100 Aircraft
Northrop Grumman and the US Air Force are working together to analyze the possibility of expanding the B-21 Raider Fleet beyond 100 aircraft, thanks to a flexible production agreement that allows for accelerated production. This comes on the heels of a 25 percent boost in annual B-21 production capacity.