• Organizations representing federal workers and good government advocates were quick to decry President Trump’s move this week to formally strip around 8,000 federal workers of their civil service protections, making them at-will employees, though the exact contours of the initiative’s scope remain unclear.

    Wednesday’s executive order implements Schedule Policy/Career, a new job category within the excepted service — formerly known as Schedule F — designed for career employees in “policy-related” positions who lack the removal protections in Title 5 of the U.S. Code and of the right to appeal adverse personnel actions. Under Office of Personnel Management regulations that took effect in March, whistleblower complaints from Schedule Policy/Career employees would no longer go to the U.S. Office of Special Counsel, instead being referred internally to the employing agency’s general counsel for review.

    The edict tasks agencies with reclassifying the roughly 8,000 federal workers into Schedule Policy/Career within seven days — by June 10 — as well as set up a separate bonus pool for those workers to recognize “outstanding work.” And OPM is expected to propose new regulations setting up a new governmentwide presidential award program for the job category.

    Has the return of Schedule Policy/Career affected you or your work? Reach out to Erich Wagner at ewagner@govexec.com or ewagner.47 on Signal to share your story.

    A 200-page appendix accompanying the executive order lists the various positions slated for conversion, subdivided by agency and subcomponent and accompanied by position codes used on an internal basis. As such, the veracity of administration officials’ claims regarding the precise number of impacted employees, or that 97% of them occupy GS-15 or Senior Leader pay grades, remains murky.

    The State Department told employees in an email Thursday that Trump placed 100 positions into Schedule Policy/Career with Wednesday’s order but did not specify how many employees would be affected.

    “Employees encumbering these crucially important positions will be notified by the Bureau of Human Resources within seven work days,” the email stated. “These changes will allow the department to reward high performance and ensure that we are well equipped to promptly and effectively address poor performance and misconduct. These roles remain career positions and will continue to be filled through merit-based hiring procedures.”

    The nonprofit Protect Democracy on Thursday solicited federal employees whose jobs appear in the executive order’s appendix to provide information about their position and duties to better ascertain its scope.

    A Defense Department employee, who declined to be named for fear of retaliation, told Government Executive that while they were not personally set for reclassification into Schedule Policy/Career, each of their supervisors are. None of them influence policy, they said.

    “First line supervisors are responsible for the oversight of their employees’ projects and the successful execution of those,” the employee said. “They hire and evaluate their direct reports annually and handle execution of disciplinary actions as needed. They have ZERO authority to establish policy. All of that is dictated down to them from their senior leadership.”

    Federal employee unions have filed multiple lawsuits challenging the legality of Schedule Policy/Career, filed last year but effectively held dormant until the policy was set for implementation. In statements Thursday, their leaders vowed to block it in court.

    “The administration continues to focus on trying to strip federal workers of the rights that Congress gave them instead of letting them do the jobs that the American people count on them to do,” said National Treasury Employees Union National President Doreen Greenwald. “Now that the administration has officially ordered the transfer of an untold number of employees to Schedule Policy/Career—so that they are, in the administration's view, easier to fire—the litigation surrounding this initiative will resume. NTEU looks forward to aggressively pursuing that litigation and fighting to ensure the American people have their government services delivered by federal employees who were hired based on merit and skill, not partisan affiliation.”

    “The practical implications of this action are clear,” said Everett Kelley, national president of the American Federation of Government Employees. “Workers who once felt comfortable reporting waste, fraud, abuse and mismanagement at their place of employment because they were protected from retaliation will now be afraid for their jobs if they speak out. That is a disservice to them and to the millions of Americans who rely on the federal government every day.”

    And while it appears those legal challenges are set to finally kick off, Stephanie Rapp-Tully, partner at federal employment law firm Tully Rinckey, PLLC, while some may try to challenge their reclassification before the Merit Systems Protection Board, it could take some time before individual employees can file litigation of their own.

    “For an individual to bring an action, they have to have suffered a harm,” she said. “You could be reclassified as Schedule F and maintain your employment, never face an adverse action and retire as planned. That could be your trajectory—you don’t know. It’s not until they pursue an adverse action that someone has suffered a damage.”

    A perhaps overlooked change for Schedule Policy/Career employees is the inability to respond to a proposed adverse personnel action before it takes effect.

    “Agencies are not required to provide advanced notice or ally for a written reply on any disciplinary or adverse actions,” Rapp-Tully said. “[They’re] also not entitled to see the evidence against them, which is a huge component . . . and they couldn’t appeal agency decisions to the MSPB. It’s the true definition of at-will.”

    NextGov/FCW reporter David DiMolfetta contributed to this report. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The complexity of modern software development requires security to be deeply embedded within the engineering pipeline rather than treated as an afterthought. With modern applications consisting of over 80% open-source components, the attack surface has shifted drastically. Whether you are managing extensive codebases or integrating third-party APIs, catching flaws before code is compiled is crucial. […]

    The post Top 10 Best Software Composition Analysis (SCA) Tools for Security Teams in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers are warning businesses about Pink Extortion Group, a threat actor that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that handle sensitive data and require stricter protection guarantees. Lockdown Mode is available to logged-in users across Free, Go, Plus, and Pro, and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A previously disclosed China-linked threat cluster, tracked as OP-512, has been observed deploying a purpose-built web shell framework to compromise Internet Information Services (IIS) servers. Identified by ReliaQuest, the espionage operation targeted a Windows Server 2016 environment running an end-of-life .NET Framework 4.0. Telemetry revealed the threat actors established access 75 days prior to the […]

    The post China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ubiquiti has addressed three critical vulnerabilities within the UniFi OS Server that attackers can chain together to achieve unauthenticated remote code execution (RCE) with root privileges. Disclosed on May 21, 2026, via Security Advisory Bulletin 064 (SAB-064), the flaws are tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. Each vulnerability carries a maximum CVSS 3.1 severity score […]

    The post Critical UniFi OS Auth Bypass Flaws Lead to Unauthenticated Root RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability in SolarWinds Serv-U to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-28318, this flaw allows unauthenticated threat actors to remotely crash the file transfer service. With active exploitation observed in the wild, this development signals a severe risk to enterprise […]

    The post CISA Alerts on Actively Exploited SolarWinds Serv-U Denial-of-Service Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated new malspam campaign is actively exploiting Google’s DoubleClick ad-tracking infrastructure to bypass enterprise email security gateways. Discovered by researchers at Huntress, the attack utilizes highly personalized dynamic lures to initiate a complex, five-stage infection chain that actively dismantles local defenses before deploying process-hollowed payloads. The attack chain begins with a malicious HTML attachment, […]

    The post Malspam Campaign Abuses DoubleClick to Deploy Stealthy .NET Loader appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat cluster UNC3753, widely tracked as Silent Ransom Group or Luna Moth, is actively targeting professional, legal, and financial services in the United States. According to Mandiant’s Google Threat Intelligence Group (GTIG), this financially motivated campaign leverages a highly effective combination of voice phishing, remote monitoring and management abuse, and unprecedented physical office intrusions. Attackers […]

    The post UNC3753 Targets US Law Firms with Vishing, RMM Tools, and Physical Break-Ins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data business Bright Data markets heavily to the AI industry. The company, the successor to Luminati, operates what it calls the largest residential proxy network in the world,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶