• Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which manages shadow page

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. “These vulnerabilities were found

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

    A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Moucka’s arrest. This image was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP).

    The U.S. Justice Department said between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company.

    The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

    Moucka adopted new nicknames frequently — sometimes operating multiple identities concurrently — but two of his best-known monikers were “Judische” and “Waifu.” Judische’s admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in a September 2024 story about the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors into harming themselves or others.

    That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

    The government says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information, “including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.”

    Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department said the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.

    “Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

    One of Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published a deep dive into Kiberphant0m’s various Telegram and Discord identities over the years, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea.

    One of several selfies on the Facebook page of Cameron Wagenius.

    Kiberphant0m also re-extorted victims. Immediately following Moucka’s arrest, Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well schematics allegedly stolen from the U.S. National Security Agency (NSA).

    Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years in prison for extortion in relation to computer fraud, and a mandatory two-year sentence consecutive to any other prison time for aggravated identity theft.

    The third alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the United States after being indicted for his admitted role in a 2021 breach at T-Mobile that exposed the personal information of at least 76 million customers.

    Sources close to the investigation said Binns, also known as “IRDev” and “IntelSecrets,” was until recently incarcerated in a Turkish prison, but that he has since been released and has resurfaced online. Those sources said Binns also recently obtained Turkish citizenship, and under Turkish law a citizen cannot be extradited to a foreign country.

    An image of a passport that Binns shared in an email to KrebsOnSecurity in Feb. 2023.

    Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count, as well as a maximum penalty of 30 years in prison on the remaining counts. Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

    For an interview with Moucka prior to his arrest and a deeper look at Binns, see our original report on Moucka’s arrest.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Three more companies will get Space Force money to build satellites that can track aircraft, a move meant to reduce the service’s reliance on SpaceX for the capability.

    Rocket Lab and STR were awarded firm-fixed-price other-transaction-authority agreements to develop a space-based solution for the military’s airborne moving target indicator mission, or AMTI. A third company was also selected, but officials didn’t name the firm in a press release this week due to “operational security.” More than two months ago, the service awarded SpaceX a $4.16 billion contract to build the emerging technology. 

    Col. Ryan Frazier, acting Space Force Portfolio Acquisition Executive for space-based sensing and targeting, said the service didn’t want to put all its eggs in one basket.

    "The core focus of this second task order is diversifying our capabilities and ensuring we don't rely on a single technical solution,” Frazier said in the news release. “With these new partnerships, we are exploring unique innovations and technologies and fundamentally different ways to accomplish the airborne moving target indication mission. Maturing these varied technical solutions now gives us distinct performance advantages for the future and guarantees we are fielding the absolute best technology available."

    Attention to space-based AMTI has grown after an expensive E-3 Sentry AWACS was heavily damaged during the first weeks of the Iran war. Air Force Secretary Troy Meink said the following month that the incident illustrated the “importance of a survivable platform” and the service later announced it had chosen nine companies to make up the vendor pool for AMTI contracts, but declined to name them. As well, Pentagon leaders who had argued that they didn’t need both air- and space-based AMTI have resumed backing a next-generation airborne warning platform.

    The three new space-based AMTI contracts total $615 million, a mere fraction of the $4 billion given to SpaceX. The bulk of the money, $397 million, went to Rocket Lab, per the company’s press release. The California-based company said it would build and launch its “Flatellites” — a flat satellite to be used in large constellations. 

    “A resilient space architecture demands a robust, competitive industrial base, and tapping into the broader commercial market is how we get there,” Frazier said. 

    It’s not clear what STR or the other unnamed company were building for the space-based system. SpaceX officials, during the company’s most recent earnings call, acknowledged the competition.

    “You can look at those as tranches and beginnings of additional capability that we will bring online, some of which we will have to compete,” said Gwynne Shotwell, the company’s president and CEO. “But fundamentally, we have the contracts in place to fulfill many phenomenologies, both the ones we’ve recently announced as well as additional ones that we’ll be working on going forward.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and leaving customers to migrate a reminder that in this category, vendor viability is a feature. The value verdict: Tufin (now absorbing Skybox’s base) and AlgoSec lead enterprise policy governance, FireMon owns real-time visibility […]

    The post The Best Firewall Management Tools, Compared and Priced (2026) appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Protective DNS is the rare control where the cheap options are genuinely good so this comparison leads with value. The verdict: DNSFilter is the best published-price PDNS for most organizations, Cloudflare Gateway owns the free-to-enterprise arc (and now runs the UK’s national PDNS with Accenture), N-able and ScoutDNS serve MSPs at fair rates, CIRA gives […]

    The post The 12 Best Protective DNS (PDNS) Services, Compared and Priced (2026) appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Trax International Corporation is asking the U.S. Court of Federal Claims to direct the Army to reevaluate bids for mission support services at White Sands Missile Range — in part because the department allegedly misused AI to determine the contract award.

    Trax's complaint, filed in late July, alleges that the Army used AI that hallucinated multiple times, creating the false impression that the company's bid was weaker than rival Southwest Range Services’ successful bid of roughly $450 million. The Government Accountability Office denied Trax’s bid protest in May.

    The lawsuit claims that records the Army provided to GAO did not explain whether assigned strengths for the Southwest Range Services bid came from a human at the Source Selection Evaluation Board or an AI tool. 

    The suit also claims that the Army conceded that one of the weaknesses it identified with Trax’s bid is unsupported by documentation. In fact, the suit said, the purported weakness is a “classic AI hallucination, with made-up references to TRAX’s proposal, that no one on the [Source Selection Evaluation Board] checked.”

    “Given the $29.4 million price premium associated with [Southwest Range Services’] proposal, there is a reasonable possibility that the removal of this Weakness could have changed the award decision,” the lawsuit states.

    The Army declined to comment on the ongoing litigation.

    Trax is not the first contractor to publicly allege that an agency has wrongfully used AI to evaluate contract bids. 

    Salient CRGT alleged that a Defense Department subagency improperly used AI, rather than human employees, to evaluate bids. The Government Accountability Office dismissed the allegation in a decision dated Jan. 5, 2026.

    Contractors will likely continue to scrutinize federal agencies’ use of AI in evaluating bids, according to David Timm, a partner at Burr & Forman.

    In a recent Washington Technology op-ed, Timm raised concerns that few civilian agencies are reporting the use of AI in bid evaluations as “high-impact.” That means agencies have either not implemented minimum risk practices or have not publicly disclosed them if they have, he told Nextgov/FCW in an email.

    The Defense Department has said that it used AI to help evaluate bids in several recent solicitations. But if agencies don’t widely disclose this, it could become harder for contractors such as Salient CRGT and Trax to successfully argue the government misused AI.

    “More bid protests are likely to come as the ungoverned and undisclosed use of GenAI tools results in errors throughout the procurement, but if agencies do not comply with the [Office of Management and Budget] rules it will complicate how contractors prove their allegations,” Timm wrote in the op-ed.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶