• FARNBOROUGH, UK—U.S. lawmakers sounded alarms about the fate of this year’s Pentagon budget while attending Europe’s largest airshow and said the Trump administration’s top defense priorities, including the Golden Dome missile defense program, are in peril.

    A bipartisian congressional delegation at the Farnborough International Airshow told reporters on Monday that the gridlock surrounding this year’s National Defense Authorization Act, an Iran war supplemental, and additional funding measures likely portends acontinuing resolution: a stopgap funding measure to keep the government open at the current year’s spending levels.

    “We're not going to get an NDAA bill done anytime soon,” Sen. John Kennedy, R-La., said. “Anybody, no offense to anybody, anybody who thinks we're going to do an NDAA in the midterm needs to back off the crank. It's not going to happen.”

    Kennedy later said, “We'll get the NDAA done” and “I hope we’ll have a CR to continue the budget, but after that, I really don't know.”

    Political infighting about the defense budget comes as President Donald Trump has pushed European countries to provide for their own defense and to buy American weapons. Given the gridlock in Washington, the administration has proposed to make heavy, partisan use of an unusual budget maneuver called reconciliation.

    “There's a concern that if you start doing defense and reconciliation, it can create a bad habit, and I get all of that,” Kennedy said on the sidelines of Farnborough. “But the military needs money, and the only way to get it to them in this environment is through reconciliation.”

    Some $350 billion of the administration’s initial $1.5 trillion defense budget request relies on reconciliation, which allows funding legislation to be passed by a simple majority. The sum includes major defense priorities such as munitions, shipbuilding, and autonomous warfare efforts. Congress has since whittled the reconciliation amount to $60 billion, mostly to support the war in Iran.

    “I'd go a little bit heavier on the defense money, but that's just me. I'll take it if that's the best we can do,” Kennedy said.

    Democrats disagree.

    “I think it does set a dangerous precedent, and I think the Appropriations Committee, both Democrats and Republicans, have been pretty clear with the department about that, about concern that if this is a priority, it should go in the base budget,” Sen. Jeanne Shaheen, D-N.H., said in a sideline gaggle with reporters. “There isn’t going to be a third reconciliation package, so anything that's in there is not going anywhere.”

    Golden Dome

    Republican lawmakers are also casting doubt on using reconciliation to pass one of the Trump administration’s biggest defense priorities: the sprawling Golden Dome missile defense program.

    A mere $400 million of the $17.5 billion the Pentagon is seeking for Golden Dome comes from the baseline budget, and the remainder from reconciliation funds. Sen. Deb Fischer, R-Neb., told reporters at Farnborough the secretive missile defense investment “is needed” but is concerned with the administration’s partisan funding maneuvers.

    “I'm worried it's in reconciliation, because I don't know if that's going to happen or not,” Fischer said.

    Todd Harrison, a defense budget analyst at the American Enterprise Institute, said there’s other avenues outside of reconciliation to get the Golden Dome funding the admin wants.

    “I think this is one of the priority items in reconciliation [that] they will find a way to work into a funding bill,” Harrison said. “If not this one, then the base budget or something else.”

    Kennedy, like Fischer, said the missile defense system is needed but added that there’s other more pressing priorities.

    “It's going to be expensive,” Kennedy said of Golden Dome. “Will we get it done in this Congress? I wouldn't bet my house on it. And if I were betting your house on it, it'd be a maybe.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI Delivers Value Only When It’s Built Into the Security Workflow

    Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber

    San Jose, Calif. – Jul. 21, 2026

    Every security leader has heard the promise by now: AI will transform security operations.

    It will reduce alert fatigue. It will accelerate investigations. It will make analysts more productive. It will help teams do more with less.

    The promise is real, but there is a catch. AI does not improve security outcomes simply because a model is available. AI improves outcomes when it has the right context, operates inside the right workflow, follows the right controls, and earns the trust of the people who have to act on its output.

    That is where many AI security conversations fall short. Most SecOps teams are not short on tools. They are short on time, context, consistency, and confidence. Alerts arrive from dozens of sources. Analysts move between consoles. Cases are built manually. Response actions often happen in separate systems. MSSPs have to manage all of this across many customers, each with different tools, data formats, escalation paths, and operating models.

    In that environment, adding a generic AI assistant does not solve the core problem. It may summarize an alert or answer a question, but if it sits outside the actual detection, triage, investigation, and response workflow, it becomes another tool to manage.

    The next phase of AI in security operations is not about adding more AI. It is about making security workflows ready for AI.

    AI Needs More Than a Prompt

    For AI to be useful in SecOps, it needs operational context. It needs to understand the case. It needs access to alert details, affected users, assets, tenants, timelines, telemetry, risk scores, historical activity, and available response options. It also needs to work within clear permissions and boundaries.

    This is especially important for MSSPs and MDR providers. In a multi-tenant environment, AI cannot blur customer boundaries. It cannot act without tenant awareness. It cannot treat all data as equally accessible. It has to respect access control, data separation, customer-specific policies, and operational guardrails.

    That is why Stellar Cyber 6.5 introduces Early Access support for the Stellar Cyber MCP Server, enabling approved AI clients to connect to the Stellar Cyber Platform through the Model Context Protocol.
    The significance is not simply that another AI integration exists. The bigger point is that MCP creates a governed path for AI to interact with structured SecOps context. Instead of treating AI as a disconnected assistant, Stellar Cyber is creating a way for approved AI clients to work with relevant case and alert data, controlled access, and tenant-aware context.

    That is the kind of foundation AI needs if it is going to become part of real security operations.

    The Case Is Where AI Becomes Useful

    Security operations should not revolve around isolated alerts. They should revolve around cases. An alert tells you something happened. A case helps you understand whether it matters.

    Cases bring together related evidence: alerts, observables, users, hosts, network activity, cloud events, identity signals, timelines, MITRE ATT&CK context, risk scores, and response recommendations. That is the right unit of work for AI because it provides the context needed to support triage and investigation.

    Stellar Cyber 6.5 improves the analyst experience inside Cases with real-time triage status updates. Analysts can see when analysis is in progress, when the AI-generated summary is ready, and when the case is prepared for review.

    That may sound like a small workflow enhancement, but it reflects a larger principle: teams need visibility into what AI is doing.

    AI cannot feel like a black box. Analysts need to know when analysis is still running, when the output is ready, and when human review is required. Managers need visibility into progress. MSSPs need repeatable workflows that can scale across tenants and analysts.

    Real-time triage status makes AI-assisted investigation feel less like an external tool and more like part of the operational flow.

    Human-Augmented Autonomy Requires Clear Handoffs

    The future of SecOps will not be fully manual. It also should not be fully autonomous without oversight.

    The practical model is human-augmented autonomy: AI handles repetitive work, accelerates investigation, summarizes evidence, recommends next steps, and supports response, while people remain accountable for high-impact decisions.

    That model only works when the handoff between AI and humans is visible and understandable.
    Analysts need to see what AI reviewed, what it concluded, how confident it is, what evidence supports the conclusion, and what action is recommended. They also need the ability to override, escalate, reopen, or tune the process.

    AI-ready workflows require structured case context, controlled access to security data, tenant-aware governance, evidence-backed summaries, auditability, and clear escalation paths. Without those elements, AI can create more confusion than clarity.

    A Better Starting Point for Analysts

    For MSSPs, this is a scale issue. Every minute spent manually gathering context is a minute that does not scale. Every inconsistent triage decision creates operational risk. Every manual handoff slows response. When AI operates inside a governed case workflow, MSSPs can standardize triage, improve analyst consistency, reduce repetitive work, and support more customers without requiring proportional headcount growth.

    For lean security teams, the same challenge shows up as capacity pressure. A small team may be responsible for monitoring, investigation, response, reporting, and tool administration. They may not have separate Tier 1, Tier 2, threat hunting, detection engineering, and incident response teams.

    For these teams, the value of AI is not replacing people. It is helping people start from a better place.

    Instead of asking, “What is this alert?” the team can begin with, “Here is the case, here is the evidence, here is the likely story, and here are the recommended next steps.”
    That is a different operating model.

    The Bottom Line

    Security teams do not need another AI sidecar. They need AI embedded into the way SecOps actually works.

    Stellar Cyber 6.5 moves in that direction by introducing governed AI connectivity through the MCP Server and improving case workflows with real-time triage status. These enhancements help bring AI deeper into detection, triage, investigation, and response while preserving the visibility and control teams need.

    AI will not transform security operations unless the workflow is ready for AI.
    Stellar Cyber 6.5 helps make that workflow real.

    Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber


    About Stellar Cyber

    Stellar Cyber’s Open XDR Platform delivers comprehensive, unified security without complexity, empowering lean security teams of any skill level to secure their environments successfully. With Stellar Cyber, organizations reduce risk with early and precise identification and remediation of threats while slashing costs, retaining investments in existing tools, and improving analyst productivity, delivering an 8X improvement in MTTD and a 20X improvement in MTTR. The company is based in Silicon Valley. For more information, visit https://stellarcyber.ai.

    The post Security Teams Do Not Need More AI Hype. They Need AI-Ready Workflows. appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to […]

    The post Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as […]

    The post New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. Also patched

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶