
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it alongCybersecurity intelligence, threat analysis, and national security reporting.

Imagine discovering hidden ads that can influence the output of entire AI models, allowing advertisers to reach a vast audience with a single placement - and get their message served up as fact. German developer Vincent Schmalbach stumbled upon these secret ads, cleverly disguised as FAQs, embedded in Time Magazine articles served to crawlers.

Meet Maj. Alex "Trippin" Boules, one of the last A-10 weapons instructor pilots, who shares what makes the A-10 Weapons School a game-changer: teaching pilots to master their aircraft and seamlessly integrate with larger operations. The school's legacy, built over nearly 50 years, is a testament to the power of expert training.

Ransomware gangs are now taking a sniper approach, targeting mid-level managers with precision to get payments faster. This new tactic is a far cry from the scattergun methods of the past, with one recent campaign hitting 351 victims across 334 organizations in just a month.

China's elite artillery brigade has just leveled up with the cutting-edge PHL-191 rocket system, marking a new era for a unit with a storied 80-year history that dates back to the 1950s when it first introduced Katyusha rockets to the PLA.

Russia is taking a dramatic step to protect its nuclear submarines from drone threats, as seen in recent satellite images showing multiple subs at a key base on the Kamchatka Peninsula completely covered in netting. This unusual move suggests a growing concern about the vulnerability of its underwater fleet.

The Senate has just approved a stopgap funding bill, passing it with a strong bipartisan vote of 90-6-1 to keep federal agencies funded until December 11. This temporary measure averts an immediate shutdown risk, but sets a new deadline for September showdowns.

Hackers have breached TrueConf servers by exploiting a gaping security hole - an open TCP port that lets them in without needing a password, then using trojanized updates to deploy backdoors and take control. This sneaky attack vector has been used by threat actors like Head Mare to spread malware and gain unauthorized access.

Researchers analyzed 1.1 million Reddit posts to uncover alarming security gaps in AI coding tools, revealing that developers are frequently complaining about security and privacy lapses. These flaws are leaving the door open for potential threats, putting users at risk.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Researchers have discovered alarming proof-of-concept techniques that allow attackers to exploit styled HTML in emails, breaking through webmail defenses to steal passwords, tokens, and even hijack trusted actions. This vulnerability affects major email services including Outlook, Gmail, and Yahoo Mail, and public proof-of-concept code is readily available.

A critical flaw in Atlassian's Rovo assistant could allow attackers to siphon off sensitive Jira and Confluence data, thanks to a prompt injection vulnerability that two separate security teams were able to exploit. Fortunately, Atlassian has patched one of the two paths used to carry out the attack, but the incident highlights the risks of data exposure via AI-powered tools.

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

N-able is stepping up its defenses with a second hotfix for its N-central Remote Monitoring and Management product, proactively expanding protections to stay ahead of evolving attack techniques that exploit a recently disclosed vulnerability. This latest update is a must-apply, even if you've already installed the earlier hotfix, as it includes crucial additional hardening measures to safeguard you and your customers.

A critical zero-day vulnerability in Metabase allows hackers to gain admin access and wreak havoc on your data, with a perfect 10.0 CVSS score highlighting the severity of this threat. Attackers can inject malicious SQL, steal sensitive credentials, and export data, making immediate patching a top priority.

The Senate has finally confirmed key leaders for the Pentagon, Space Force, and National Reconnaissance Office, including Jules "Jay" Hurst as Pentagon comptroller, ending an 18-month wait and setting the stage for critical budget decisions. With a narrow 51-47 vote, Hurst and 74 other nominees, including Erich Hernandez-Baquero and Roger Mason, are now cleared to take on their new roles.

The Army is shaking things up to speed up interceptor missile development - they're opening up five testing ranges to private industry, slashing wait times from 12-18 months to just 30 days. This move aims to get innovative defense firms, especially smaller players, quicker access to test their promising interceptors.

General Dynamics Information Technology has landed a $1.3 billion contract to bolster the Army National Guard's IT and cybersecurity defenses, ensuring resilient networks that support communities, government partners, and national security. This major deal, dubbed the Enterprise Network Operations and Cybersecurity Support contract, will safeguard the nation's interests with cutting-edge tech.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Investors are sounding the alarm over a new ICE contract with Thomson Reuters Special Services, which for the first time includes voter fraud investigations, and are demanding clarity on the agreement. The contract aims to provide ICE with easy access to credit card records to tackle voter fraud, immigration fraud, and national security threats.

The Pentagon is making swift strides in implementing Zero Trust principles for its IT systems, focusing on users and devices, and is now poised to take this momentum to the next level. A upcoming webinar will assess progress and explore the future of Zero Trust across the Department of Defense.

US Marines with 3d Reconnaissance Battalion, 3d Marine Division, trained alongside Korean forces in a high-stakes exercise at Camp Stanley, navigating underground tunnels and honing their skills in a show of strength and cooperation. This semi-annual Korean Marine Exercise Program helps the two nations stay ready and united in the face of evolving threats.

Western tech is facing a shocking internal threat that's hindering national security interests - and it's coming from within. Incumbent tech companies and new entrants are locked in a fierce battle for survival, creating an uneven playing field that's putting Western strategy at risk.

Nearly 9 out of 10 cyber incidents involve identity compromise, with attackers exploiting weaknesses in credentials, multifactor authentication, and social engineering to gain access to enterprise environments. Identity has become the new front door for cyber threats, making it a critical area of focus for protecting your organization's security.

OpenAI is stepping up security for its advanced AI model Astra, implementing stricter controls such as isolated testing environments and enhanced encryption to prevent potential cyber threats. The company has flagged Astra as a model that may possess critical cyber capabilities, requiring extra precautions to ensure safety.

Retired General and ex-NSA chief Paul Nakasone warns that water systems are vulnerable to cyber threats, urging stricter defenses and cautioning that PLCs should be kept offline. He calls for higher standards and new partnerships to protect critical infrastructure.

Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.