1010.cx

  • Actively Exploited ASUS Vulnerability Added to CISA’s KEV List

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical ASUS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in the wild. CVE-2025-59374 affects ASUS Live Update software and stems from a sophisticated supply chain compromise that embedded malicious code into legitimate software distributions. Supply Chain Attack Details The vulnerability involves […]

    The post Actively Exploited ASUS Vulnerability Added to CISA’s KEV List appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Trump rebrands Congressionally-approved troop housing subsidy as ‘warrior dividend’ bonus

    ·

    Policy
    This is a developing story; please check back for updates.

    President Donald Trump’s $1,776 checks for 1.45 million troops announced Wednesday come from Congressionally-allocated reconciliation funds intended to subsidize housing allowances for service members, a senior administration official confirmed.

    During a prime-time TV address, Trump said he was “proud to announce” that  “1,450,000 military service members will receive a special, we call ‘warrior dividend’ before Christmas” adding that to honor the nation’s founding “we are sending every soldier $1,776. Think of that. And the checks are already on the way.” 

    The senior administration official told Defense One in an emailed statement late Wednesday evening that Defense Secretary Pete Hegseth directed the Pentagon to “disburse $2.6 billion as a one-time basic allowance for housing supplement” to all eligible service members ranks 0-6 and below.

    “Congress appropriated $2.9 billion to the Department of War to supplement the Basic Allowance for Housing entitlement within The One Big Beautiful Bill,” the senior official said. “Approximately 1.28 million active component military members and 174,000 Reserve component military members will receive this supplement.”

    Top Congressional leaders have repeatedly pushed Pentagon officials during confirmation hearings to commit to lawmaker guidance for the more than $150 billion in defense priorities identified in the “One, Big, Beautiful Bill” reconciliation legislation. The $2.9 billion meant to subsidize the basic allowance for housing, the monthly payment to cover off-base expenses such as rent, mortgage, and utilities known as BAH, comes as some service members have struggled to make the most of the benefit. A Jan. 27 Rand report examining the adequacy of BAH for Army personnel said the Defense Department should better assess methodology amid rapid changes to the housing market.

    “BAH is generally adequate for Army personnel, though not necessarily when the housing market is changing rapidly and dramatically, as it has in recent years,” the report read. “Furthermore, while our analysis of housing choices and expenditures among military

    personnel and of their locational amenities points to an overall positive picture with respect to BAH, a substantial, though minority, share of members report dissatisfaction with BAH.”

    Active-duty, and reserve troops on active-duty orders 31 days or more in duration as of Nov. 30, 2025, are eligible for the benefit if they’re an 0-6 or below, the senior administration official said.

    “President Trump’s administration recognizes the hard work of our service members with this one-time Warrior Dividend, which places funds directly in the hands of our military members and their families, helping to improve their housing and quality of life,” the senior administration official said.

    Last week, the Defense Department announced the 2026 BAH rates, which are set to increase by an average of 4.2 percent as of Jan. 1, 2026.

    During hearings, Senate Armed Services Chairman Sen. Roger Wicker, R-Miss., has said “much of the funding of the defense reconciliation bill is unspecific and will technically be at the discretion of [the Defense Department].” He has repeatedly asked nominees if they “commit to follow the Congress' spending recommendations and defense reconciliation, unequivocally.”

    Others, like SASC Ranking Member Sen. Jack Reed, D-R.I., have reportedly expressed skepticism that the Pentagon will follow intended plans for the funds.

    “My sense is they already have an idea of what they want to do, and they’ll try to do it,” Reed said. “Some of it will be consistent with what we’re doing, but some things, I think inevitably, will be their own initiatives, their own sense of what’s important, even if we don’t agree or don’t support it.”

    Spokespeople for the Senate Armed Services Committee did not immediately return a request for comment.

    Some lawmakers have been scrutinizing the Trump administration’s reallocation of military funding. Sen. Elizabeth Warren, D-Mass., and Rep. John Garamendi, D-Calif., issued a report last week highlighting $2 billion diverted away from the Defense Department and Homeland Security Department for border enforcement—including redirecting funds for barracks, maintenance hangers, and elementary schools.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit

    ·

    cyber security, Cyber Security News

    TEL AVIV, Israel, Dec. 17, 2025 Miggo Security has released a comprehensive benchmark study revealing critical gaps in Web Application Firewall (WAF) protection, with the discovery of React2Shell (CVE-2025-55182) serving as a stark real-world validation of these vulnerabilities. The research, titled “Beat the Bypass: A Benchmark Study of WAF Weaknesses and AI Mitigation,” demonstrates that traditional […]

    The post New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    SonicWall has issued an urgent security advisory warning of active exploitation of a local privilege escalation vulnerability affecting its SMA1000 appliances. The flaw, tracked as CVE-2025-40602, enables attackers with management console access to gain elevated privileges and potentially achieve complete system control. The vulnerability stems from insufficient authorization checks in the SonicWall SMA1000 Appliance Management […]

    The post Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Chinese Ink Dragon Breaches European Government Networks, Affecting Asia and South America

    ·

    cyber security, Cyber Security News

    Ink Dragon, a Chinese espionage group, has significantly expanded its operational reach from Southeast Asia and South America into European government networks, according to ongoing research by Check Point Research. The threat actor employs a methodical approach that combines strategic server compromises with sophisticated relay infrastructure to maintain persistent access and support global operations. The […]

    The post Chinese Ink Dragon Breaches European Government Networks, Affecting Asia and South America appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Apache Commons Text Flaw Lets Hackers Execute Remote Code

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A critical remote code execution vulnerability has been discovered in Apache Commons Text, affecting all versions prior to 1.10.0. The flaw, tracked as CVE-2025-46295, poses a significant security risk to organizations relying on the widely-used Java library for text manipulation and processing. The vulnerability resides in Apache Commons Text’s interpolation features, which are designed to […]

    The post Critical Apache Commons Text Flaw Lets Hackers Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

    ·

    The North Korean threat actor known as Kimsuky has been linked to a new campaign that distributes a new variant of Android malware called DocSwap via QR codes hosted on phishing sites mimicking Seoul-based logistics firm CJ Logistics (formerly CJ Korea Express). “The threat actor leveraged QR codes and notification pop-ups to lure victims into installing and executing the malware on their mobile

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Phantom Stealer Targeting Users to Steal Sensitive Data

    ·

    cyber security, Cyber Security News

    Sophisticated malware employs a multi-stage infection chain and advanced evasion techniques to exfiltrate sensitive information. Phantom, a sophisticated stealer malware variant, is conducting targeted attacks to harvest sensitive data from infected systems, including passwords, browser cookies, credit card information, and cryptocurrency wallet credentials. Security researchers have identified Version 3.5 of the malware, which employs a […]

    The post Phantom Stealer Targeting Users to Steal Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Node.js Library Flaw Lets Hackers Execute Remote Commands on Windows

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A severe command injection vulnerability has been discovered in systeminformation, a widely-used Node.js library for retrieving system information. The flaw, tracked as CVE-2025-68154, allows attackers to execute arbitrary commands on Windows systems when applications pass user input to the vulnerable function. The vulnerability exists in the fsSize() function, which retrieves disk space information but fails […]

    The post Critical Node.js Library Flaw Lets Hackers Execute Remote Commands on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft 365 Outage Disrupts Teams, Outlook, and Copilot in Japan and China

    ·

    cyber security, Cyber Security News

    Thousands of users across Japan and China experienced significant disruptions to Microsoft 365 services on Thursday morning due to a critical routing issue affecting the company’s infrastructure. The outage affected essential workplace tools, including Teams, Outlook, OneDrive, and Copilot, resulting in widespread operational challenges for enterprises in the Asia-Pacific region. Service Disruption Details The incident […]

    The post Microsoft 365 Outage Disrupts Teams, Outlook, and Copilot in Japan and China appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 111 112 113 114 115 … 539
Next Page

1010.cx

cybersecurity / defense / intelligence