• Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued on August 17, 2026, include iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and security fixes for older devices with iOS 18.7.10 and iPadOS 18.7.10. The patches impact a wide range of supported Apple […]

    The post Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs, raising fresh supply-chain security concerns around vendor-hosted driver downloads. The company said the affected file was confined to a legacy resource, not its current support portal or factory-installed Windows images. The incident came […]

    The post Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems during controlled cybersecurity testing. This issue, which has since been resolved, stemmed from a single evaluation scenario in which internet access was permitted and a fictional target name overlapped with a real domain. Irregular stated that […]

    The post AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python […]

    The post CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still […]

    The post JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • I built the Cybersecurity Maturity Model Certification because self-attestation was failing our war industrial base. Contractors could simply promise they were following basic cybersecurity practices, with no verification behind that promise. Our adversaries noticed that gap long before Washington did—and they have not eased up since. If anything, the opposite is true. 

    Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago. This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did.

    But defending a program doesn't mean pretending it's perfectly aimed. Now that CMMC is a final rule moving into real contracts, it's the right time to ask: are we targeting it precisely enough? I don't think we are yet—and artificial intelligence, used correctly, can help fix that without touching the cybersecurity bar itself.

    The problem is targeting, not the standard

    CMMC's requirements hinge on controlled unclassified information. But CUI determinations across the war industrial base are inconsistent: Two subcontractors doing nearly identical work can end up with completely different assessments because the call still depends on manual judgment with incomplete visibility into how data actually flows down. Some small businesses get pushed into heavy assessment burdens for data that isn't really CUI. Others handling real, sensitive data slip through with a lighter requirement. Neither outcome helps national security; the first wastes compliance dollars, the second leaves real exposure unaddressed.

    AI can do the first-pass sorting here—flagging likely CUI from contract language and statements of work and catching mismatches between what a prime contract designates and what actually flows down to subcontractors — far more consistently than today's patchwork of manual reviews. In this scenario, a human with contracting authority still makes the final call. But that human should be working from a much better starting point than we give them now.

    Small business is the economy, not just the supply chain

    Small businesses are 99.9% of American companies and employ nearly half the private workforce. And right now, they face threats most aren't equipped to handle: ransomware that can shut down operations overnight; AI-enabled fraud that's harder to spot every year, and a coming reckoning when quantum computing breaks today's standard encryption. The quantum threat is already real, since data harvested now can simply be decrypted later.

    I'm glad the Small Business Administration is leaning into this. Its Cybersecurity for Small Business Pilot Program has done real work funding training through state partners. But training grants aren't capital, and no amount of counseling gets a small manufacturer through a ransomware recovery or a quantum-resistant encryption upgrade. Small businesses can't get favorable financing for cybersecurity the way they can for equipment because most lenders don't know how to underwrite it.

    We need a dedicated SBA loan program for cybersecurity investment—open to every small business, not just those working with the Department of War—to fund things like multi-factor authentication rollouts, endpoint detection, incident response, and early migration toward quantum-resistant encryption, before it's an emergency instead of a plan.

    Same mission, two fronts

    Inside the war industrial base, use AI to make sure CUI calls and flow-down match reality. Outside it, give the broader small business economy the capital to defend itself against adversaries who are only getting more aggressive. I still believe unverified promises are not a security strategy. But precision and support aren't the enemies of security—they're what make it sustainable.

    Sharpen how we target CMMC, and open the door for every small business to invest in its own war footing. That's not lowering the bar. That's making sure the bar is doing its job.

    Katie Arrington is a former South Carolina state legislator and cybersecurity executive who served as DOD CISO for Acquisition and Sustainment starting in 2019, and later returned as DOD CISO/PTDO DOD CIO under the second Trump administration. She spearheaded the Pentagon’s initial efforts to create the CMMC program for defense contractors beginning in 2019, driven by a conviction that contractors needed to actually prove — not just self-attest to — their cybersecurity compliance in order to protect sensitive defense data from adversaries. Her commitment to the program has been described as stemming from a deeply personal mission to secure the Defense Industrial Base from cyber threats that jeopardize national security.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Army officials plan to resume Apache training flights in days, after the fleet was grounded following a crash that left two soldiers dead in Texas, according to an internal memo reviewed by Defense One.

    The two soldiers, Chief Warrant Officer 2 Deontre T. Huey and Warrant Officer Seth L. Olmstead, died during a maintenance test flight out of Fort Hood on Aug. 12. On Friday, Army officials announced a stand down of AH64 Apache training flight operations and said in a news release it “will remain in effect until we have a better understanding of the root cause of the accident.” 

    However, a widely circulated internal Aug. 14 memo reviewed by Defense One said the grounding “concludes on midnight Tuesday,” with plans for “flight operations resuming on Wednesday 19 August.” The document acknowledges that from fiscal year 2023 through this year, the Army had nine fatalities from nineteen Class A mishaps, the term used for the service's deadliest and costliest incidents. 

    “During the Army aviation AH-64 fleet safety stand down, commands will focus on aviation academics and safety related topics,” the memo states. “Senior commanders will be involved during the aviation safety stand down. Opening remarks shall be provided by general officers, who will articulate the importance of this event. Commanders will review, brief, and discuss an overview of current safety statistics and trends.” 

    Safety stand downs are common after military crashes, but the current Apache grounding marks the latest in a recent string of safety mishaps for the storied attack helicopter. Three months ago, Defense One exclusively revealed a transmission problem that could “result in loss of tail rotor thrust, electrical power, and hydraulics. Some of the AH-64 Echo models had to be grounded as a result. Prior to that investigation, there had been at least three Apache incidents—including one crash during a maintenance flight out of Fort Hood, according to photos and information from a pilot.

    While investigations into the crash are ongoing, a U.S. official told Defense One the service  was “able to eliminate the transmission as a causal factor.” The official confirmed the Apache fleet would resume training flights this week.

    A Boeing executive told Defense One on the sidelines of the Farnborough International Air Show in the United Kingdom last month that they couldn’t share the progress on fixing those transmission problems.

    “Boeing does have crews that are there working with the U.S. Army on some of those components,” said Mark Ballew, Boeing Defense, Space, and Security’s senior director of business development and strategy for vertical lift. “So our team's been there, they’ve been working there for the last month-plus on that.” 

    A Boeing spokesman told Defense One on Sunday the company is still working with the Army on the transmission problem.

    Apaches are being relied on heavily during the ongoing war in Iran, are part of major foreign military sales this year, and have been used for high-level transportation of Defense Department leaders and celebrities. 

    Officials wrote in Friday’s memo that “CENTCOM deployed formations are exempt from the safety stand down requirements.” 

    In June, an Apache went down near the coast of Oman while “patrolling international waters,” according to U.S. Central Command. After the helicopter was reportedly struck by an Iranian drone, the U.S. military deployed a Navy drone boat to rescue the downed crew

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶