-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-28318 (CVSS score: 7.5), is a denial-of-service (DoS) bug that causes the service to crash
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent. The same week, Google shipped Chrome 149 with patches for 429 security bugs, the most ever in a single release. Only the FFmpeg bugs were found by AI.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per OpenSourceMalware. The development has GitHub to disable access to those repositories. “Access to this
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types – On-Prem Deployment Cisco SD-WAN Cloud-Pro Cisco SD-WAN Cloud (Cisco Managed) Cisco SD-WAN for Government (FedRAMP) “A
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
32 Red Hat npm packages compromised by Miasma malware expose cloud tokens, CI/CD secrets and developer credentials in supply chain attack.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
When the Army launched its “transformation initiative” a year ago, lawmakers immediately implored service leaders to show their work as they made plans to buy new things and get rid of old ones, including the cost tradeoffs and a timeline. They didn’t get those answers, so House lawmakers have inserted a requirement for an annual report and briefing into this year’s defense authorization bill.
On Thursday, the House Armed Services Committee completed its markup on the bill, adding detailed instructions for an annual update on the Army Transformation Initiative—and also the Army’s Transformation-in-Contact/Continuous Transformation efforts, requiring specifics on new capabilities and ones that have been phased out.
The goal of the Initiative “was to position the Army for future fights, streamline force structure, and eliminate wasteful spending,” Rep. Mike Rogers, R-Ala., said during a May 15 hearing of the HASC, which he chairs. “Congress shares those goals, but as questions arose, it became clear that the Army hadn't done all of its homework.”
The provision in the House’s version of the National Defense Authorization Act would require the Army to provide an annual report, on or by Feb. 15, “detailing the programmatic choices made to implement.”
By March 15, the service would also have to brief the committee on:
- How any changes to the National Defense Strategy, or other DOD planning document, informed the Army’s choices.
- An “inventory and assessment” of all exercises related to Army transformation since 2023.
- An inventory of all capabilities or capacity phased out as part of Army transformation, with a timeline and assessment of how they have affected readiness.
- An inventory of planned investments with an assessment of how they will contribute to the joint force.
The service did send experts for closed-door briefings to lawmakers over the past year, a U.S. official told Defense One, in an attempt to provide details and explain the rationale for its plans.
“We initially saw a ton of support from members of Congress, until it potentially impacted a parochial interest,” said the official, who was granted anonymity because they were not authorized to speak on the record about the matter. “That's when they got all sticky about it.”
The Army’s helicopter purchases were of particular concern to House members both last year and this year, as the service’s budget request included funding to buy just one UH-60 Black Hawk and five MH-47 Chinooks. Army officials said it made sense to buy fewer older aircraft as the MV-75 Cheyenne II approaches.
In hearings, lawmakers expressed concern that reducing purchases would undermine the helicopters’ supply chains.
In May, the House’s first NDAA mark-up bumped up procurement to seven Black Hawks and 12 Chinooks.
“Nobody's saying we don't need Chinooks or Black Hawks or Apaches, we don't need to modernize, etc.,” the official said. “But we have so many more, based on the force-structure side, than we think is required to fight a conflict.”
The question went to Defense Secretary Pete Hegseth during his May 12 testimony before the House Appropriations Committee, where he announced that the Defense Department would be taking a second look at the initiative.
“There are some very good things in the Army Transformation Initiative, and there are some things that we needed to get another look at,” Hegseth said. “And so I think you'll see a review of some of those things, and we’ll get back to you.”
The Pentagon refused to provide any details on what that review looked like or whether Hegseth had his eye on other updates. A few days later, Army Secretary Dan Driscoll testified before HASC, apparently unaware of Hegseth’s concerns.
“I don't know all the depth of what was implied, but I absolutely agree that we will take a hard look with the Office of Secretary of War and make sure that we are synced with their strategy and their plans as they look across the joint force and balance their requirements and needs of the military as a whole,” he said.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the information stealer “scrapes every secret it can find on a developer’s machine, hides behind an eBPF kernel rootkit, and
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025, with each attack wave making use of distinct websites mimicking utilities, war-related updates, and a government news source: govlens[.]net, which
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers are leaning harder on legitimate, preinstalled, or widely used system tools to deliver and operate notorious malware families, creating a stealthy, high-velocity threat that outpaces many traditional defenses. The operational logic for attackers is straightforward. Native utilities such as PowerShell, Windows Management Instrumentation (WMI), certutil, mshta, and JavaScript execution contexts already enjoy elevated privileges […]
The post Hackers Weaponize Trusted Tools to Deploy Notorious Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


