• HUNTSVILLE, Ala.—Lasers and high-powered microwaves will need equal standing to traditional weapons when it comes to the Army’s approach to missile defense, the service’s space and missile-defense chief said. But as battlefield tech is developed and integrated, proper training will be key to keeping soldiers safe. 

    “Integrating systems like lasers or high-powered microwaves, there's a pretty significant burden of implementing that across training and organizations,” Lt. Gen. John Rafferty, who leads Army Space and Missile Defense Command, told reporters Tuesday at the Space and Missile Defense Symposium. 

    Rafferty’s top enlisted advisor concurred.  

    “I know everyone's talking about faster, cheaper—all those things are needed. But what's most important is our soldiers need to be trained on it,” Command Sgt. Maj. Rickey Jackson told reporters Tuesday. “We don't want to assume too much risk in that, because the soldiers are the ones that are going to have to use it and implement it. So I look forward to the rest of this week and hearing from industry and how we can do that, because ultimately our soldiers need it.”

    In his keynote, Rafferty said air-defense strategy should balance the use of missiles, which can reach beyond line of sight, and energy weapons, which can be cheaper per round and used for closer ranges

    “We need a more comprehensive missile defeat strategy that focuses on interceptors—equally so on non-kinetic effects, both electronic warfare and directed energy—and the type of targeting [command and control],” on top of the ability to move sensitive data to lower classification levels “and make decisions to engage targets faster,” he said.

    After decades of touting directed energy as a weapon of the future, the Pentagon may at last be on the verge of realizing its vision. Nascent programs such as the Army-Navy Joint Laser Weapon System and the Army’s Enduring High Energy Laser, as well as operational systems such as the Navy’s HELIOS drone-dazzler, suggest that directed-energy weapons may soon go mainstream.

    The Army tested non-kinetic weapons during a recent test at White Sands. They synced C2 systems to get a clear picture of the battlefield and help soldiers pick the right weapon for the incoming threat, Rafferty said. 

    “The individual systems worked, right, because they're all systems that exist right now. That wasn't the trick. The trick was integrating them into a command-and-control system to make sense of and then assign effectors against those against those targets. So that, in a nutshell, is a sort of combined-arms approach to missile defeat or or a comprehensive missile-defeat strategy,” Rafferty told reporters. 

    “I'm not surprised that we could do it, I'm just thrilled that we actually did it, that we decided to integrate multiple C2 systems and figure out how to enable our soldiers to defeat complex threats.”

    The Army has leaned forward on adding lasers to its armory through a directed energy program. 

    But ultimately, the concern isn’t about the Army’s ability to integrate new tech and weapons systems into its operations—it’s training. 

    “Clearly, there are technical challenges to integrating platforms into command-and-control systems and planning software that helps us to integrate the effects at the right place and time,” Rafferty said. “But in terms of our Army being well-equipped and agile enough to do this, I'm 100-percent confident.”

    The challenge comes in making sure there’s an adequate power source, in “maneuvering and supporting” the system, he said. 

    “It's not about the laser anymore. It’s really about putting it together, packaging it, making it ruggedized, and coming up with the doctrine and the techniques…the sustainment that needs to be done to go from a high-end technological capability to a no-kidding weapons system that’s able to be…usable by 20-year-old sergeants,” Tom Karako, a missile defense expert at the Center for Strategic and International Studies, told Fox News in a recent interview. 

    That also means the systems have to work in bad weather and austere conditions, and be repairable in the field, he said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HUNTSVILLE, Ala.—The sprawling Golden Dome missile-defense program is in peril because the White House decided to seek the vast majority of its 2027 funding via a controversial budget maneuver, the program’s leader said Tuesday.

    Gen. Michael Guetlein didn’t explicitly call out the administration’s decision to propose using reconciliation to fund about 97 percent of the program’s $17.5 billion request. But the Space Force four-star did say it creates a “tough budget environment" as lawmakers remain cool to the administration’s request for a third partisan-led defense-funding measure.

    “If they don’t figure it out, there is no Golden Dome,” Guetlein told attendees at the Space and Missile Defense Symposium, “because there is no funding.”

    His public cry for help contrasts sharply with the mysterious gag order imposed by Pentagon leaders at last year’s symposium. 

    And it comes, Guetlein said, as the program makes good progress. He said that 90 percent of the roughly $24 billion allocated for the missile defense program through last year’s reconciliation effort has been obligated. He also said there’s been two “phenomenally successful” tests tied to the effort, and that contracts have been awarded for many of the key parts, such as space-based interceptors, radars, and data networks. 

    The general also warned that progress could stall without consistent funding.

    “So if there's no additional funds, we have to continue to leverage the enormous amount of investment that [Congress] already gave me in reconciliation in FY 25-26, and then leverage that going forward,” Guetlein said.

    One of Golden Dome’s cornerstone capabilities—space-based boost-phase interceptors— could be too costly for the final architecture. Physicists have said such a scheme would require thousands or even tens of thousands of armed satellites to provide 24/7 defense against even a handful of incoming missiles.

    In April, Guetlein told the House Armed Services Strategic Forces subcommittee that if building and deploying satellites armed to down enemy missiles early in flight can’t be done affordably or at scale then “we will not go into production.”

    On the sidelines of the symposium, Guetlein told reporters that he hadn’t seen anything from the defense industry to change his mind on the affordability of space-based interceptors, but added he was impressed with what he’s seen.

    “All of the providers that are part of the competition are progressing exceptionally well,” the general said, adding that he expects those companies developing the technology to progress to the next stage, which involves building the on-orbit capability. He declined to say how Space Systems Command plans to test those interceptors. 

    Guetlein told reporters that the Defense Department is already planning for contingencies if they don’t secure the requested funding in the 2027 budget, but said no final maneuvers have been settled on.

    “There are discussions within the department about how to go forward because we have diversified execution of a lot of these capabilities, and a lot of these capabilities are already requested by combatant commands,” Guetlein said. “There are some alternatives that we can pursue. We have not made any decisions on any pathway.”

    He said, as an example, that some of the capabilities in the Golden Dome program are also being funded by the Space Force, and added that the service could continue to work on those systems.

    Todd Harrison, a defense budget analyst at the American Enterprise Institute, said it isn’t likely that Golden Dome would have to raid various service budgets to continue its progress.

    “I think that Congress would prioritize Golden Dome funding and find it another home, either through a supplemental bill, a smaller reconciliation package, or tuck it into a higher base budget,” Harrison said.

    Earlier this year, Golden Dome’s price tag had already swelled $10 billion over the original $175 billion goal, and the potential long-term costs have already been the focal point of criticisms.

    In the absence of a publicly released architecture, Congressional Budget Office analysts crafted an estimate for a national missile defense system based on Trump’s “Iron Dome for America” executive order. The watchdogs calculated it would cost $1.2 trillion to “develop, deploy, and operate” for 20 years. 

    Guetlein has since gone on defense, publicly pushing back on that trillion-dollar figure and saying that the analysts “did not estimate the architecture that we're building.”

    During his panel at the symposium, Guetlein acknowledged Golden Dome’s steep price tag, but averred its necessity.

    “That’s a lot of money. That’s one of the biggest systems that we’ve ever put together as a nation,” he said. “We got to keep it affordable.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

    Image: Shutterstock, Mallika Home Studio.

    August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.

    Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.

    The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”

    “This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”

    CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

    Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.

    By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.

    Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.

    Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.

    “AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”

    Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go has some organizations struggling to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.

    “If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

    Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.

    For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Expect to see the solicitation for the next iteration of the Pentagon's main cloud-computing contract on Aug. 24.

    The Joint Warfighter Cloud Capability contract is the Defense Department’s vehicle for buying cloud services from the main hyperscalers: Amazon Web Services, Google, Microsoft Azure and Oracle. The Defense Information Systems Agency announced the date as part of its monthly acquisition post

    The new version, called JWCC Unified Cloud Marketplace, will expands what DOD can buy through the vehicle.

    Tier 1 will be for the hyperscalers. Tier 2 covers “everything-as-a-service” including software, platform, and non-hyperscale infrastructure. Tier 3 is reserved for what DISA is calling “Commercial innovators and small businesses”: emerging companies and small businesses.

    DISA has not posted an estimated value for JWCC Unified Cloud Marketplace.

    The current JWCC vehicle had a $9 billion ceiling. AWS has received the most task-order obligations, $526.5 million; followed by Microsoft, $221 million; Oracle, $76.9 million; and Google, $35.9 million, according to Deltak data

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. “Kimwolf v7 adds an HTTP/2-based

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶