• HUNTSVILLE, Ala.— Lockheed Martin’s new ICBM killer, ordered two years ago to supersede the oft-troubled GMD interceptor, hit two major milestones this week and is expected to clear the design phase later this year, company officials said.

    The company said last week that its L3Harris Technologies L3Harris Technologies, or NGI, had completed a critical burst test of its second-stage motor case. On Monday, ahead of the Space and Missile Defense Symposium here, Lockheed Martin announced that they had successfully fired its stage 2 rocket motor in a static test. Company officials said NGI, ordered under the Biden administration to replace the nation’s Ground-Based Midcourse Defense System, should clear the critical design review, or CDR, phase by the end of this year.

    “These milestones are major steps toward our path to CDR, confirming our utmost confidence that NGI will meet the demanding performance envelope on track for fielding by 2030,” Christopher Jewell, Lockheed Martin’s NGI vice president, told reporters on Monday evening.

    In 2024, the Missile Defense Agency awarded Lockheed Martin an $18 billion contract to design and build the Next Generation Interceptor. This April, MDA director Gen. Heath Collins told lawmakers the program fell behind schedule by 18 months due to several technical problems, but that it still remained on track to pass the design review in 2026. 

    “We are, as we transition into manufacturing, identifying and finding some issues with some of these new systems — the solid rocket motor, the inertia measurement movement, as well as some in the sensors,” Collins said during an April 30 Senate Armed Services Committee hearing. “And we are working to buy down those risks and move forward as quickly as possible to make sure we pull the day as far to the left as possible.

    The Government Accountability Office’s 2026 weapons system assessment did not include information on the Next Generation Interceptor “due to the lack of long-term cost and schedule baselines, which we could use to measure progress.”

    NGI is slated to be part of the Trump administration's sprawling Golden Dome defense system.

    This week’s Space and Missile Defense Symposium will likely see more discussion of Golden Dome than last year’s conference, when officials were ordered not to talk about it amid a general crackdown on public discussion by Defense Secretary Pete Hegseth. On Tuesday, Gen. Michael Guetlein, the Golden Dome director, is scheduled to update attendees on the program’s progress.

    Collins told lawmakers in April that he, Guetlein, and U.S. Northern Command leader Gen. Gregory Guillot frequently discuss the role that NGI will play in the military’s defense strategy.

    “Gen. Guillot, Gen. Guetlein, and I are regularly talking about Next-Gen Interceptor and the important part it plays in the layered defense of our homeland,” Collins told lawmakers.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • LAS VEGAS — As dozens of small water utilities report cyber intrusions—possibly from Iran-linked groups–an industry association and a university are teaming up to help raise their defenses.

    The Water Watch Center will provide cyber mitigation support to utilities that serve fewer than 10,000 people—that is, most of the nation’s community water systems. Launched at this year’s DEF CON hacker convention, the initiative is a collaboration of the National Rural Water Association and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.

    More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued to operate safely and that there were no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on incident response.

    An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative. 

    “These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,” Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement.

    Paul Nakasone, who led U.S. Cyber Command and the NSA from 2018 to 2024, said at DEF CON this year that water utilities around the country are highly exposed, and he pushed for higher defense standards in the sector.

    “These [programmable logic controllers] should not be exposed to the internet,” Nakasone told reporters in a briefing on Friday, referring to the small computers used to operate pumps, valves, and other equipment inside water facilities.

    Some U.S. officials believe Iran may be responsible, though there has been no definitive public confirmation.

    “I think [the government] is taking a very measured approach to make sure that they have the right actor that’s doing this,” Nakasone said when asked about why Iran hasn’t publicly been linked to the hacks.

    “I look at intent. I look at capability. I look at history. I’m not the person that’s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,” he said. “They certainly have the capability, and I think there’s an intent right now — we’re in conflict with Iran.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • LAS VEGAS — After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico’s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers. 

    The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.

    But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.

    Federal officials initially seemed willing to give them considerably more of it. The company was asked to grow the team working on the effort from roughly 10 people to about 60, according to CEO Jason Wareham. 

    Chief Technology Officer Manbir Gulati also said Mojave received an authorization to proceed with a follow-on effort, hired personnel, and was given funding to acquire equipment for examining more voting systems ahead of the November midterms. A contracting officer had even been brought in to finalize the new agreement, Gulati said.

    Then, as Mojave prepared to move ahead, the work was abruptly shut down.

    Wareham and Gulati recounted the episode on Friday at DEF CON hacker convention’s Voting Village, where they publicly unpacked their technical findings before sitting down with a small group of reporters and onlookers. 

    Their account fills in new details about a federal effort that grew out of the Trump administration’s broader focus on voting machines and election interference, and the political pressures that emerged when Mojave’s findings did not support claims of election manipulation.

    The ODNI request

    Mojave never set out to become an election security provider. Its involvement began last year through the Office of the Director of National Intelligence under then-director Tulsi Gabbard, where it was already performing unrelated technical work for the agency when officials approached the company about examining voting machines and data obtained from Puerto Rico.

    Reuters reported in February that the May 2025 operation was tied to an effort involving ODNI and the FBI to investigate allegations that Venezuela had hacked Puerto Rico’s voting systems, though Gabbard’s office denied that Venezuela drove its work and said the examination was focused on technical vulnerabilities. The probe produced no clear evidence of Venezuelan interference.

    Wareham said at DEF CON that ODNI asked whether his team of reverse engineers and forensic specialists could travel to Puerto Rico and capture an image of a voting system that had actually been used in an election, without the vendor overseeing the process. He agreed, thinking it would be a relatively small addition to Mojave’s existing contract. 

    The assignment instead dropped Mojave into a much larger skirmish over American elections. “Ultimately, I made the worst decision of my life in a business context,” Wareham said. 

    President Donald Trump has spent years falsely maintaining that his 2020 loss was stolen and the product of widespread fraud and foreign interference, claims that have been rejected by courts and officials in his own administration. A 2021 intelligence community assessment found no indication that a foreign actor attempted to alter ballots, vote tabulations or any other technical aspect of the election. 

    Since returning to office, Trump and allies have revived investigations into the 2020 contest and pushed election security back to the center of his administration’s agenda. Gabbard’s ODNI was one part of that effort, hauling off and analyzing voting systems from Puerto Rico and later becoming involved in a federal investigation of 2020 election records in Georgia.

    Wareham said the ODNI officials directly overseeing the company’s technical work wanted the research to continue. Both he and Gulati described the ODNI staff they worked with as professionals who wanted to protect the security of election systems. 

    The resistance, Wareham said, came from a separate White House collective that was repeatedly dissatisfied Mojave had not produced evidence supporting claims that the 2020 election had been manipulated.

    “There was a separate group — let’s call them White House-adjacent — who was dissatisfied,” he said. “They were dissatisfied overall that I was not willing to name and shame at that moment” and declare that Trump had actually won the 2020 election.

    Asked whether he believed Mojave’s government work was axed because it failed to find the “smoking gun” some officials wanted, Wareham said: “I believe that was part of the termination, yes.”

    Reuters reported in April that Kurt Olsen, a prominent 2020 election-denier and Trump adviser involved in efforts to investigate the election, pressed Mojave to broaden its work in search of evidence that could support those claims.

    Olsen, who now works at the Justice Department, turned against the company when its research failed to uncover evidence that the Puerto Rico machines had been hacked. He advocated terminating its work and accused Mojave of secretly receiving money from billionaire George Soros, a frequent target of right-wing conspiracy theories, the news agency reported. ODNI has said Mojave’s contract ended because the company completed its voting-machine analysis.

    Wareham said an ODNI official informed him while Mojave was preparing to expand its work that the company had been accused of receiving Soros funding. The allegation prompted him to compile a detailed accounting of the young company’s funding sources within three days and send it up the government chain. Asked who he was told had made the accusation, he said an ODNI official reported to him that it was Olsen.

    “One, I’m not funded by George Soros,” Wareham said. “Two, it would be great to be funded by George Soros because I would probably not be here, I’d be on a yacht.”

    The company kept moving forward. Wareham said Mojave briefed the White House on some of its findings around September. The firm believed it was heading toward a broader effort to remediate vulnerabilities before the midterms and conduct a deeper analysis for signs that the weaknesses it discovered had ever been actually abused.

    Then came the record-long government shutdown. Wareham said that on the day he expected an expanded contract to move ahead, Mojave instead received a stop-work order and no additional funding.

    “I think the government shutdown was all that was required, really, to have some folks that I didn’t know were still in the game, again, White-House adjacent, to take their shot,” he said. Wareham stopped short of saying he had direct proof that White House officials ordered Mojave removed because of its findings, but said “it was reported to me it was Kurt Olsen” who led the efforts.

    The White House, ODNI and Olsen did not return requests for comment.

    Identified vulnerabilities

    Mojave had found many issues with the machines it examined. Gulati described the Puerto Rico system during the Voting Village presentation as “deeply insecure,” saying it did not meet the security bar he would expect from “an average low-risk application, let alone critical infrastructure.”

    Researchers identified at least 12 major vulnerabilities in commercial software installed on the system, Gulati said. Mojave successfully executed five of them. None were newly discovered flaws, and fixes were already available — in some cases well before the system was used in the election.

    Other weaknesses were rooted more deeply in how the system was built and deployed. Some passwords could be easily cracked and others were embedded directly into software. Firewalls were turned off on critical systems and ports were left open. Gulati was particularly critical of the system’s cryptography, which he described as being “in shambles.” 

    The company does not believe every problem it found necessarily stopped at Puerto Rico, as its formal review covered only one system from one manufacturer in one jurisdiction. Gulati suspects the issues could extend beyond a single voting machine company, though Mojave has not examined enough systems from other manufacturers to establish that. 

    “I don’t expect that the problems are unique to them,” he said. “I think many manufacturers probably exhibit the same problems.”

    Mojave produced an approximately 100-page document of the Puerto Rico findings. Gulati said Mojave has been in discussions with Liberty Vote — which acquired Dominion’s election business last year — and that Liberty told the researchers it does not plan to make changes before November.

    Liberty said it has not received Mojave’s report.

    “Liberty Vote is not in receipt of any such report so, therefore, we cannot provide any comment,” a spokesperson said. “As always, Liberty Vote is committed to advancing the future of secure American elections.”

    No evidence of vote tampering 

    Looking at the systems headed into the midterms, Gulati said, “I do know that as of now, the state that we have described is going to be pretty similar to what will be deployed in November.” 

    Despite the extensive findings, Gulati repeatedly returned to what the researchers did not establish: “We found extensive and largely unacceptable weaknesses,” he said in the presentation. “But we did not find evidence that those weaknesses were actively exploited or that votes were altered.”

    That distinction has drawn renewed attention as Trump and his allies again focus on election matters.

    Last month, the president used a prime-time White House address to release newly declassified intelligence he said showed China interfered in the 2020 election. Among several disclosures, Trump pointed to intelligence showing Beijing had acquired personal information on roughly 220 million American voters. But the documents did not show China altered votes or gained the ability to manipulate voting systems.

    Gulati echoed those conclusions Friday when asked about the declassification.

    “The China thing isn’t really much of anything,” he said, arguing that a large amount of the voter information at issue could be obtained commercially and should not be confused with access to election systems in ways that can manipulate votes. 

    “There is no evidence that I know of that says China successfully or any other country has successfully infiltrated our systems and manipulated votes in any way,” he added.

    Wareham called the 100-page document a preliminary report and said the firm had wanted another six months to a year to dig deeper into the underlying data. 

    Gulati said the company’s interactions with the ODNI employees overseeing that work were markedly different from the political pressure the researchers later encountered. “We were never pressured to put anything in our reports that was untrue or politically leaning in a certain way,” he said of those officials.

    Wareham said Friday that Mojave itself has pushed for its report to be made public for roughly a year and has recently been told it could soon emerge through a Freedom of Information Act request. Nextgov/FCW could not immediately determine the origin of the FOIA requester. As of publishing time, ODNI’s FOIA logs are available up until January 2025.

    “I’m a little annoyed that we are very close to midterms and we had a whole year to freaking figure this out,” Wareham said. 

    With their government work scrapped, he announced at the Voting Village that he had filed paperwork to create the Machine Assurance Institute, seeking to bring together cybersecurity researchers and election technology companies to examine and independently verify voting infrastructure.

    “We wanted to be the national security answer, and put to bed, finally, discussions about prior elections and/or accusations of voter fraud,” said Wareham. “Because, believe it or not, I find it fairly national security-destabilizing to constantly accuse each other of cheating.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary’s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. “StormEncryptor is written in C++ and appends the file name extension .encrypted

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet […]

    The post Android Banking Droppers Surge as Malware Operators Change Packaging Tactics appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Aug. 10, 2026

    Cybercrime Magazine YouTube channel

    Out of the pure play cybersecurity b2b focused media outlets and event producers with YouTube channels listed by their number of subscribers (minimum of 1,000 subscribers), Cybercrime Magazine is far and away the top channel based on number of subscribers (1.2 million), and views per video.

    The editors at Cybercrime Magazine compiled the list by searching on all cybersecurity focused media outlets (b2b media / news sites and event producers) that we are aware of, and then looking up their channel for the publicly displayed subscriber counts reported by YouTube.

    Many media outlets do not have a YouTube channel, or they had one previously but no longer produce videos there, or they have less than 1,000 subscribers. Excluded from this list are solo / independent (non-company) video producers and channels that are focused mainly on consumers, training and education, and other non-corporate / business media.

    Coming in at second is Black Hat with 260,000 subscribers, and RSAC is in third with 101,000 subscribers. Security Weekly has 51,000 subscribers, and Recorded Future has 4,100.

    Visit the Cybercrime Magazine YouTube channel



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post Top 5 B2B Cybersecurity YouTube Channels In 2026 appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable appliances, posing a significant risk to organizations that expose LoadMaster […]

    The post CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a 

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶