• The nation’s largest military shipbuilder sees maritime drones producing “modest” revenue now, but expects that to grow as the Navy builds its unmanned fleet, HII’s chief executive said during Thursday’s earnings call. 

    “We know it’s going to become more of the Navy fleet because [unmanned systems] can do excess missions and expand the fleet size such that they can do things that large capital ships can’t do and take the place of large capital ships in some of the missions,” said Chris Kastner, HII’s CEO and president. “From a revenue standpoint right now, it’s pretty modest.” 

    Kastner went on to say that HII’s unmanned business, which is part of the Mission Technologies division, is growing quickly. Earlier this month, the Navy extended its Lionfish unmanned undersea contract that was originally awarded in 2023 for nearly $350 million

    “I don’t really want to comment on how large it’s going to be, but I’ll tell you one thing—it’s the fastest-growing business unit we have,” Kastner said, adding that the company is competing for the Navy’s medium unmanned surface vehicle program.

    “The international and domestic pipeline is strong, we’re going to pursue those…It’s a good business unit. It’s a growing business unit. The profitability should be solid because it’s firm fixed-price contracts. We think we’re very competitive, and we’re going to continue to invest in it and watch it grow. Now, is it going to be a billion-dollar battleship? No. We think it’s going to grow. We think there’s significant opportunity, and we think it’s going to be a greater part of the fleet.”

    Sea drones have become increasingly visible on the battlefield as navies use them for surveillance, rescues, and kinetic strikes. And more companies have entered the sector as the Navy boosts its unmanned systems budget and homes in on how it wants to integrate them into its fleet—while pushing companies to grow the capacity to build them quickly.

    HII has emphasized its tech business more in recent years, often stressing the segment’s poised growth. Mission Technologies had $760 million in second-quarter revenue this year, an approximate $31 million and nearly 4 percent drop compared to last year. 

    That’s “primarily due to lower volumes in all domain operations in global security, partially offset by higher volumes in warfare systems and unmanned systems,” Tom Stiehle, HII’s chief financial officer and executive vice president, said during Thursday’s call. 

    The Mission Technologies business is expected to grow about 5 percent in the next five years and generate up to $3.2 billion in revenue for fiscal year 2026, according to the company’s earnings update.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Disclosure: This article was created in collaboration with Status Labs.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anthropic’s flagship artificial intelligence model Claude gained unauthorized access to the networks of three different organizations, the company announced following internal cybersecurity audits of its routine model evaluations. 

    In a press release posted Thursday, Anthropic said that, following the containment breach of OpenAI’s ChatGPT-5.6 and subsequent attack on Hugging Face’s systems, Anthropic conducted an audit of its own model evaluations. The findings revealed that, out of 141,006 examined evaluations of Claude models dating back to April, there were three incidents where a model accessed the internet from within or while interacting with the third-party evaluators. 

    Each attack occurred during a “capture-the-flag” scenario where the models are asked to find hidden information housed within a different node.

    In the blog post, Anthropic blamed a “misunderstanding” between them and their third-party evaluators that granted the models internet access. The models were told in prompts that they would not have real internet access and therefore operated under the premise that all accessible systems were part of the test environment.

    “Operating under the false belief that all accessible entities were intended to be in-scope for the exercise, Claude compromised the impacted organizations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints,” the post reads. “It did not find or exploit any complex vulnerabilities, and in each case, Claude continued working to complete only the specific capture-the-flag task its evaluation had assigned.”

    The models involved in the incidents were Opus 4.7, Mythos 5, and an unnamed internal research test model that isn’t planned for release. Anthropic stated that, despite accessing the internet as part of its cybersecurity testing, the models did not deliberately attempt to leave their training environments; accessing the internet only occurred as they looked to complete their tasks. 

    In one incident, Opus 4.7 executed the task on the real-world networks of a company once it realized it could via internet access. 

    A second incident was more extensive. Mythos 5 sought to find information by referencing software development instructions inside a fictional environment. It used these instructions to install a Python package from a public registry that didn’t actually exist in the hopes that the fictional company would automatically download it, thus granting the model access to its networks. In order to do this, it created login credentials a human user would need. 

    That Python package was inadvertently uploaded to the internet, where 15 systems downloaded it and compromised their systems. 

    The third incident saw the prototype model scan real targets after being unable to find the fictional target included in the test. 

    Anthropic noted that, when the models were able to discern that the attacks affected real systems, they halted their testing processes—something that, in part, the company said, gives it “cautious optimism.”

    “Several defense-in-depth measures, on both our side and our partner’s, could have prevented these incidents or at least reduced their likelihood of occurring,” the post read. “Both we and our partner also could have reviewed evaluation transcripts or network logs more thoroughly. It’s also possible that a prompt which told Claude it did have internet access would have changed how Claude behaved when it came into contact with real systems.”

    In the aftermath of the breaches, Anthropic is working with its evaluation partner, Irregular, and METR, an independent AI evaluation organization, to continue conducting reviews. It is also working alongside affected companies whose systems were compromised. 

    Anthropic concluded by saying it encourages other AI developers to conduct similar audits and that evaluation exercises in general need stronger oversight and safeguards. 

    “Ultimately, many factors contributed to these incidents, but, consistent with a blameless postmortem culture, we’re approaching the fixes as if the responsibility were ours alone,” the post reads. 

    Industry peers characterized Anthropic’s revelations on the heels of OpenAI’s incident as a burgeoning pattern cyberdefenders should heed. 

    Tom Kellermann, the vice president of AI Security and Threat Research at TrendAI, said that these incidents underscore the continued need for safeguards even in secure sandbox environments.

    “Anthropic and OpenAI just proved that when you strip guardrails for testing, you’re not creating a sandbox, you’re inviting systemic risk,” Kellermann said in a statement to Nextgov/FCW. “Every organization deploying agentic AI needs to ask itself if their evaluation environment is actually contained. Containment and monitoring are no longer optional.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Jul. 31, 2026

    Listen to the podcast

    The exploit lands before the fix even ships,” says John Vecchi, CMO at Mitiga, a leader in zero-impact breach prevention for cloud, SaaS, identity and AI.

    The mean time to exploit is now negative seven days, Vecchi tells Mitiga’s Field CISO Brian Contos on the latest episode of Mitiga Mic, a new series on the Cybercrime Magazine Podcast. In 2018, defenders had about 63.

    Vecchi and Contos get into what changed and what Mitiga’s place in Anthropic’s Cyber Verification Program has to do with it. The CVP is like a background check for defenders. It lets vetted security teams use Claude’s full reasoning for the attacker-minded analysis the models block by default, while dangerous capabilities stay blocked for everyone, permanently.

    “You can’t patch your way to safety fast enough now. The math doesn’t work,” says Contos.

    Keep preventing. You still need that layer, but assume the attacker gets in, and start measuring yourself by blast radius instead of the perimeter. Or as Vecchi says, “the gap is the strategy.”

    A new episode of Mitiga Mic airs every month on the Cybercrime Magazine Podcast.

    Listen to the Podcast episode



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Digging Into Anthropic’s Cyber Verification Program appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by researcher Enzo Mongin from Escape Research, also known as Orionexe. The vulnerability was reported to the Keycloak team on July 18, 2026, acknowledged […]

    The post Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶