• Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a serious vulnerability in Mozilla Firefox’s JavaScript engine. Security researchers at Nebula Security have demonstrated that this flaw is exploitable in Tor Browser because it is built on Firefox’s underlying codebase. Mozilla […]

    The post Hackers Can Compromise Tor Browser Users by Exploiting Firefox JIT Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability in Ruby on Rails’ Active Storage component could allow unauthenticated attackers to read arbitrary files on vulnerable application servers, potentially escalating to remote code execution. This vulnerability is tracked as CVE-2026-66066 and affects Active Storage variant processing in Rails applications configured to use libvips for image manipulation. Rails maintainers disclosed the issue […]

    The post Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Maybe it was just me, but there seemed to be more handshake deals between companies than airplane buys—military and commercial—at last week’s Farnborough International Airshow. 

    As a Farnborough first-timer, I had very few expectations. I guessed there likely wouldn’t be as many aircraft flying because of surging fuel prices and the Iran war. And the NATO Summit already had several major announcements. 

    But given the fanfare, should there have been more big buys trumpeted? Or are industry deals—showcasing how willing companies are to collaborate—the new normal?

    “There are always partnerships being announced, but I think it was more of a lack of the large order announcements that we typically see that made them more visible,” said Grant Holve, a commercial aerospace analyst for Forecast International, a sibling brand of Defense One that provides market analysis and intelligence. “It was a 50-50 split between commercial and defense this year…usually it's like 80-20 or 70-30 tilted toward commercial.”

    The lack of big purchase announcements coupled with the strong European defense spending backdrop seemed curious to me. But a theme emerged: dual-use commercial aircraft venturing into the defense arena.

    “Commercial crossovers into defense aerospace seemed to be an identifiable theme. That was a takeaway I noticed specifically with the ‘contested logistics’ space for air taxi companies,” said Jon Hemler, director of Forecast International's military aerospace and weapons division. 

    Those eVTOL makers definitely made a splash, from Archer Aviation’s snazzy black and gold chalet (and partnership with Anduril) to Sikorsky teaming with Beta Technologies’ MV250 on autonomous cargo aircraft.

    “It's increasingly an area where civil firms can partner with defense companies as an entry point to the market,” Hemler said. 

    Welcome

    You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and song recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!

    A boom for the aerospace supply chain. The more electrified and digitally-infused aircraft get, the more parts they need. That’s good business for distributors like FDH Aero, which team up with multiple suppliers to bulk buy, store and sell parts to customers.  

    • “There's a lot more digital components, connectors, wires than there were two decades ago,” thanks to the electrification of aircraft and increasingly complex digital environments, CEO Ian Walsh told Defense One at the Farnborough airshow. “And because defense and commercial are growing very sharply, there's a huge pull on the supply chain to keep up with that.”
    • That demand can put a lot of strain on suppliers as commercial companies cross over to sell more to militaries.
    • “Imagine an [original equipment manufacturer] that's building helicopters for commercial [customers], and now this military customer wants 250 helicopters…they basically have to double their production, so it's putting a lot of strain on the supply chain to keep up,” he said. “We are seeing and benefiting from the fact that we're really good at what we do. We source long-lead time parts. We know our customers’ build rates in production, so we're really able to plan.”
    • Plus, drones need parts too: “If you'd been here a decade ago, if somebody mentioned the word ‘drone’ or ‘unmanned,’ they would look at you kind of funny. And I think every single booth [here] has some connection or product that's now tied to unmanned drones, eVTOLs. So that's a whole new frontier.”
    • But at the end of the day, while the “brains” of the newer, possibly autonomous, aircraft may differ, “an airframe is an airframe, whether it's going into space or it's landing vertically or landing on a runway. They all have connectors, rivets, bolts, connectors, fasteners—a bunch of little components all over it. I mean, there's just hundreds of thousands of those pieces all over that aircraft.”

    Quick turnaround. Last week’s executive order on critical minerals will push defense contractors to get clear visibility into their supply chains by next year—a timeframe that caused much consternation. But could it be the push that prime contractors need? Can the industrial base risk waiting longer?

    • “It’s a critical element of sovereignty for us to be able to make sure that we can create deterrence through our industrial base,” said Chris Morton, who leads aerospace and defense business for IFS, which provides AI-fueled enterprise software and asset management for industrial businesses. 
    • But “directing prime contractors, essentially, to rationalize their entire supply chain all the way to the bottom…it’s a Herculean undertaking.”
    • Morton said that type of visibility isn’t common among prime defense contractors, but getting that insight could lead the industry to uncomfortable, but necessary discoveries. 
    • “I think there’s gonna be a whole lot of surprises. In the Army, we used to say that one of the first parts of operational planning is knowing yourself. And this effort is really that first step. We may discover some things that we are not happy about. But it’s a critical part of this effort because how can you know what materials you need to source and components you need to manufacture if you don’t really know what goes into your supply chain? We’ll see how the defense primes respond to this, because this is not an easy undertaking, not one bit.”
    • Related reading: In a July 22 report, the Government Accountability Office evaluated ways to reduce imported critical mineral reliance and recommended four policy changes to help that: creating domestic manufacturing capacity; building more infrastructure for battery and semiconductor recycling; making it secure; and investing in research and testing.
    • And another thing: The Trump administration plans to ban robots and inverters made in China and certain other nations, to bolster U.S. efforts in the sector.

    Making moves + other news

    • Defense technology company Tagup wins a Marine Corps contract to help streamline equipment maintenance and repairs for 1st Maintenance Battalion in California. No dollar amount was listed, but Tagup’s Manifest AI platform uses a trove of data to see where all the parts for a given piece of gear come from, anticipate demand in an uncertain environment, and help troops plan for deployments. 
      • “Every maintenance decision requires balancing readiness, cost, and time,” Paul Plemmons, president of Tagup, said in a news release. 
      • “Manifest gives maintainers the decision advantage to weigh those tradeoffs and commit to the course of action that best keeps mission-essential equipment ready and available.”
    • Leonardo DRS to buy tech company Raft for $450 million
    • Leidos wins $717 million Air Force contract for ISR support for Air Combat Command. The contract extends work the company has done since 2019.
    • The think tank Center for Strategic and Budgetary Assessments added Phil Davidson and Anita Antenucci as the board chair and vice chair, respectively. 
      • Davidson is the former commander of Indo-Pacific Command and has been on CSBA’s board for four years. 
      • Antenucci has served on the board for nearly eight years and founded the investment banking firm 3Wire Partners.

    One more thing: A Seasats drone boat caught footage of a Chinese warship near the Philippines, Reuters reported.

    Jennifer Hlad contributed to this report.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DAYTON, Ohio—The ongoing war in Iran has pushed Air Force officials to prioritize battlespace awareness upgrades on the service’s tanker fleet, four months after two KC-135s were involved in a deadly crash during Operation Epic Fury.

    Top acquisitions officials told reporters Tuesday during the Life Cycle Industry Days conference here that upgrading the KC-135, the newest of which was built more than 60 years ago, was a major priority for the service. In March, two of the tankers were involved in a mishap that did not involve “hostile fire or friendly fire,” according to U.S. Central Command. Six airmen died in the crash.

    “We absolutely accelerated [Mobility Air Forces] connectivity because of Operation Epic Fury,” said Col. Paul Tinker, the deputy mobility program acquisition executive. “The MAF is more capable right now than it was, you know, in terms of connectivity, during the start of Epic Fury. We diverted personnel and funding resources to make that happen. It's AMC’s No. 1 priority, and it continues to be their No. 1 priority. We really focused on that for the last couple of months.”

    Shortly following the crash, current and former Air Mobility leaders sounded alarms over the lack of battlespace awareness and connectivity onboard the KC-135. In March, Air Mobility Command said “almost half” of the service’s nearly 400 tankers were connected to Link 16, the military’s secure communications network, through a years-long effort known as real-time information in the cockpit, or RTIC. The service has made progress in just a few months.

    While exact figures weren’t provided, “the majority of the KC-135 fleet is currently equipped with RTIC,” an Air Mobility Command spokesperson told Defense One in an emailed statement Wednesday.

    After the deadly crash, former air mobility commanders told Defense One that KC-135s have standard radios that can provide some encrypted communications and a Traffic Alert and Collision Avoidance System, or TCAS, a transponder meant to prevent mid-air collisions. In chaotic combat zones, crews may decide to go without those systems and rely on visual separation instead.

    The Air Force said increasing the amount of information KC-135 crews can have in the cockpit is a crucial safety upgrade, according to a January Congressional Research Service report.

    “According to the Air Force, the tankers' ability to access tactical data links could increase mission success in contested environments by improving survivability, agility, and situational awareness for command-and-control elements and aircrews,” the report said. “The connectivity could provide aircrews with such information as potential threats, fuel availability, and safer landing sites. In addition, tanker aircraft could serve as a backup information conduit for other aircraft in a degraded communications environment.”

    Col. Melvin Baylon, the Legacy Tankers Division’s senior materiel leader, told reporters the acquisitions arm has been working with Air Mobility Command on several upgrades, including increased access to Link 16.

    “If you would’ve asked me just a few short years ago that we would’ve been integrating as much capability as we are onto the KC-135 platform, I would’ve said there would’ve been no chance,” Baylon said. “The end state is to make sure that we increase battlespace awareness.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In the complex and ever-expanding digital landscape of 2026, a strong cybersecurity posture depends not only on identifying vulnerabilities in software but also on ensuring that systems are correctly and securely configured. Misconfigurations incorrectly set permissions, unhardened systems, enabled insecure services, and default passwords left unchanged have become one of the leading causes of data […]

    The post Top 10 Best Security Configuration Assessment Tools in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A North Korea-linked hacker group has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the publicly known scope of Pyongyang’s efforts to use trusted code to reach large numbers of potential victims and gain access to companies’ systems.

    The assessment for the first time links the same financially-motivated hacking group to compromises of four major JavaScript packages—typo-crypto, debug, chalk and axios—that developers use as building blocks for other software. The axios package alone receives more than 100 million downloads each week, and its compromise had previously been attributed to the North Korean group. 

    Amazon said Wednesday that it had uncovered evidence connecting the actor to the three earlier incidents, based on technical findings that included instances of reused code and similarities in how the attacks were carried out.

    Amazon Threat Intelligence attributed the campaigns to the group with “medium confidence,” according a blog post authored by Amazon Integrated Security CISO CJ Moses scheduled for release Wednesday evening. The cyber intruders are tracked by researchers under several names, including Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon and Alluring Pisces.

    In each incident, the hackers tricked a trusted software maintainer and used the access to publish an update containing malicious code, according to Amazon. Organizations configured to automatically download the latest version of those packages may have pulled the compromised updates directly into their systems. The approach allows hackers to compromise a small number of widely used packages while potentially gaining access to thousands of downstream systems, making it more efficient than targeting organizations individually. 

    Open-source software—code that can be freely inspected, modified and reused—underpins operating systems, web servers, encryption tools and many of the applications businesses rely on daily all over the world. The projects often depend on volunteer maintainers to review proposed changes, fix security flaws and publish updates.

    That model relies heavily on trust. Attackers can spend weeks or months posing as legitimate contributors, fixing bugs and building relationships before attempting to gain control of an established project or publishing a malicious update.

    That dynamic drew widespread attention in 2024, when an account operating under the name “Jia Tan” spent years gaining the trust of other developers before attempting to insert a backdoor into XZ Utils, a widely used data-compression tool included in numerous Linux distributions. The backdoor was discovered before it could be broadly deployed.

    “Quite frankly, the open-source community is looking for good citizens because these packages are often not maintained by people who are getting paid to do that as a full-time job,” Rick Anthony, senior manager for Amazon’s Inspector vulnerability management service, told reporters in Arlington, Va. on Wednesday. “They are very welcoming for anyone who is willing to contribute.”

    North Korea has long treated cyber operations as both an intelligence tool and a source of revenue. Its hackers steal cryptocurrency, conduct espionage and extort victims, while operatives posing as remote IT workers obtain jobs at foreign companies and quietly funnel their salaries back to the regime. Amazon is among those companies, executives said Wednesday. U.S. officials say the proceeds help Pyongyang evade sanctions and finance its nuclear weapons and ballistic missile programs.

    “For a sanctions-constrained regime, generating revenue through these operations means that the greater the efficiency, the more money they get, and the more that they can use that money to do things that got them the sanctions to begin with,” Moses told reporters. “One successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions.”

    The findings also illustrate how open-source attacks are becoming harder to detect.

    Amazon said attackers are increasingly dividing a malicious operation among several packages that appear harmless when reviewed individually. One package may contain encrypted data, another the code needed to unlock it and a third the instructions to download and execute the final payload. The malicious behavior becomes visible only when the components are used together.

    AI is also making malicious software harder to spot, the blog warned. Hackers can use it to create polished-looking code, convincing documentation and fake developer profiles, eliminating many of the obvious mistakes that once raised red flags.

    Attackers can also exploit errors made by AI coding assistants. If an AI tool recommends a software package that does not exist, hackers can register the name and load it with malware, hoping a developer or automated system will download it without realizing the recommendation was wrong.

    Concerns about open-source software security have increasingly drawn attention in Washington. In December, the chairman of the Senate Intelligence Committee asked the White House national cyber director to take steps to address vulnerabilities in open-source projects that help power systems used throughout U.S. military and civilian agencies.

    Last August, Nextgov/FCW first reported that an employee of the Russian technology company Yandex was the sole maintainer of a widely used open-source tool embedded in at least 30 pre-built software packages available to the Defense Department.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DAYTON, Ohio—Up to six designs could be brought to the prototyping phase of the second round of the Air Force’s drone-wingman effort next year, a service official told reporters on Tuesday.

    Increment 2 of the Air Force’s Collaborative Combat Aircraft competition is well underway, Col. Timothy Helfridge, the fighter portfolio acquisition executive, told reporters at the Life Cycle Industry Days conference here. By roughly mid-2027, Helfridge expects, there could be “up to” half a dozen designs.

    “We have another approximately 10 months left of our concept-refinement contract, where we would expect to have the refined attributes as we did before, as well as several closed conceptual designs,” he said. “We're shooting for roughly six, but we'll see what we end up with.”

    In December, the Air Force announced that nine companies had received contracts to refine concepts for Increment 2 CCAs, and that 11 more remain eligible to compete in later phases of the effort. 

    “Increment 2 will be structured similarly to Increment 1, where more than one awardee may be selected for prototyping,” an Air Force official told Defense One late last year. “This approach allows for competitive development and ensures that the Air Force can evaluate various solutions before selecting the final designs to move into production.”

    In 2024, service officials funded initial Increment 1 work by Boeing, Lockheed Martin, and Northrop Grumman, Anduril, and General Atomics, but ultimately only the latter two were chosen to build prototypes and then to begin production.

    Northrop Grumman’s largely self-financed CCA earned its prototype an Air Force designation and made it eligible for the first increment, but it did not win a production contract. 

    Helfrich said other unexpected entrants might eventually compete for Increment 2.

    “We will continue to maximize competition through all the phases of CCA Increment 2. So we may have entrants that come in in a later phase that were not part of concept refinement,” he said. “We have to maximize the learning as soon as we can.”

    This week, just outside of Dayton, Anduril unveiled the first Fury CCA produced at its facility near Rickenbacker Airport in central Ohio. The Air Force has already been experimenting with a prototype Fury and with General Atomics’ Dark Merlin CCA.

    Service officials said in a Tuesday press release that the Air Force used the CCAs as part of a recent multi-day Agile Combat Employment exercise at Creech Air Force Base in Nevada.

    "This exercise was about getting the systems into the hands of the warfighter," Lt. Col. Matthew Jensen, the Experimental Operations Unit commander, said in a press release. "We are focused on operating CCA outside of a traditional test environment so we can continue to learn, inform and rapidly iterate."

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Better authentication UX helps B2B platforms reduce security fatigue, simplify account recovery, protect sensitive data, and keep business users engaged.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶