
Site technology by Nubivance.
OSINTSights runs on a hybrid edge-and-AI stack: Cloudflare Workers, D1, R2, Vectorize, plus a Hetzner-based pipeline. Nubivance designed and built it.
See what we build →Cybersecurity intelligence, threat analysis, and national security reporting.

Beware of fake developer tools on Open VSX! A recent "evil twin" campaign revealed 77 malicious extensions that masqueraded as legitimate tools, secretly collecting and transmitting sensitive data about your system and development environment.

macOS developers, beware: XCSSET malware is lurking in compromised Xcode projects, infecting unsuspecting victims through a sneaky four-stage infection chain that can deploy 17 distinct modules. This latest variant has been rewritten to dig deep into your workflow and browser, putting your entire development ecosystem at risk.

European countries are pushing for greater autonomy in defense procurement, seeking to buy, sell, and operate military systems without being bound by US export controls, specifically the International Traffic in Arms Regulations (ITAR). The ITAR "see-through rule" is a major pain point, allowing US regulators to track and control American-made components even when they're integrated into foreign-built systems.

ZKPs offer a game-changing solution, allowing companies to securely share proof of vulnerabilities without exposing sensitive data that could be exploited by attackers. By using ZKPs, organizations can demonstrate the truth of a statement, such as confirming a specific vulnerability exists, without revealing confidential details.

Get an exclusive behind-the-scenes look at the Farnborough Airshow as Breaking Defense's Multimedia Director Daniel Woolfolk takes you on a tour of the grounds. In this episode of The Break Out, Daniel gives you a firsthand glimpse of the action on the show floor.

As social media giants face mounting criticism nationwide, a coalition of nearly 100 organizations is urging lawmakers to take bold action, arguing that current laws aren't doing enough to protect users' wellbeing. The Senate Commerce Committee is now taking a major step forward with a package of five bills aimed at overhauling online safety, privacy, and AI regulations.

New research suggests that space operators may be making critical safety decisions based on orbital data that's less reliable than they think, putting them at risk of catastrophic collisions. In fact, a recent analysis found that typical operators are only mitigating a mere 7 percent of actual collision risk.

Lawmakers are pushing for a bill that would provide lifetime identity protection for the 4.2 million federal employees and contractors affected by the 2015 Office of Personnel Management breach, giving them the peace of mind they deserve. The proposed RECOVER PII Act aims to make the currently expiring protection program permanent, ensuring victims are safeguarded against ID theft for life.

OSINTSights runs on a hybrid edge-and-AI stack: Cloudflare Workers, D1, R2, Vectorize, plus a Hetzner-based pipeline. Nubivance designed and built it.
See what we build →
In a major breakthrough, the X-62A aircraft successfully intercepted a target using AI-driven sensor data to guide its moves in real-time, executing 27 flawless intercepts across eight flights. This cutting-edge test, dubbed "Have Heat," marks a significant milestone in the development of autonomous combat capabilities.

Nearly half of malware samples with command-and-control activity connect directly to IP addresses, dodging DNS-based defenses and highlighting a significant blind spot in traditional security measures. This alarming trend was uncovered in an analysis of over 4 million dynamic reports, revealing that 45.32% of malicious code uses direct-to-IP connections to evade detection.

Italy has made a significant move in the Gulf region, deploying around 700 troops in a covert military operation to boost surveillance and defense against Iranian threats. This substantial show of force marks one of Italy's most notable Gulf deployments in years.

INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

In a staggering two-month sprint, Palo Alto Networks' NOVA uncovered 14,090 confirmed vulnerabilities in just 3,915 open-source software projects - a remarkable demonstration of AI-powered vulnerability discovery's rapid impact. This autonomous pipeline is revolutionizing the way we identify and tackle software vulnerabilities.

Reputable cloud platforms have unwittingly become a phishing haven, with threat actors exploiting their trusted reputations, generous free tiers, and instant onboarding to launch attacks - all thanks to lenient security measures that rarely require verification. This has made it alarmingly easy for phishers to bypass multi-factor authentication and wreak havoc.

US senators are warning that the unpredictable approach to AI security is undermining America's competitiveness and inadvertently driving businesses to adopt Chinese alternatives, which could create new security risks. This lack of clarity is prompting concerns that customers may be pushed towards less secure options.

Iran and Oman are cooking up a plan to shake up shipping in the Strait of Hormuz, with vessels entering the Persian Gulf taking one route near Iran's coast and those leaving taking another near Oman. The proposed deal would also involve service fees to cover environmental impact, cargo security, and more.

OSINTSights runs on a hybrid edge-and-AI stack: Cloudflare Workers, D1, R2, Vectorize, plus a Hetzner-based pipeline. Nubivance designed and built it.
See what we build →
China's military reach is expanding at an alarming rate, with the People's Liberation Army now actively projecting power into the Pacific beyond the First Island Chain, a development that Japan's government has identified as a critical threat to its peace and security.

With the federal government's identity protection services set to expire on September 30, 22.1 million breach victims from the 2015 China-linked breaches face a looming gap in lifetime protection. Will they be left vulnerable after a decade of coverage?

When AI systems produce inaccurate responses, the knee-jerk reaction is often to blame the models themselves, but the real issue frequently lies in the data feeding them. As agencies ramp up their AI efforts, they're overlooking a crucial factor: the context and quality of the data, which can make or break the reliability of AI systems.

Colombia's Aerospace Force has sealed a $336 million deal with Embraer for two KC-390 Millennium airlifters, with deliveries set for 2029 and 2030. This strategic move is part of a broader modernization plan, with the FAC choosing the KC-390 after a rigorous analysis.

This week, Las Vegas is buzzing with Hacker Summer Camp, a trio of conferences that bring together the brightest minds in infosec to tackle the hottest topics, including the game-changing impact of autonomous agents and agentic artificial intelligence. From grassroots community rooms to massive corporate expos, the conversation is all about harnessing AI to revolutionize defense and offense in the digital landscape.

Meet Greatness, a phishing-as-a-service powerhouse that's upgraded its game, now offering a one-stop-shop for cybercriminals to mastermind credential theft, device code phishing, and OAuth consent abuse - all from a single, user-friendly dashboard. This commercial crimeware toolkit has evolved into a full-fledged ecosystem, supporting multiple platforms like iCloud, Yahoo, and Google Workspace.

Researchers found that AI guardrails against cyberattacks are surprisingly easy to bypass, with attackers often simply telling the model they're allowed to perform a certain action - and it complies. Simple tactics like reframing requests and claiming certain roles reliably trick AIs into assisting with malicious activities.

Exploiting the N-able flaw can give attackers unrestricted control over your N-central console, putting your entire operation at risk. Federal agencies have just three days to patch this high-severity vulnerability, tracked as CVE-2026-18577, under CISA's Binding Operational Directive 26-04.