• Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authentication remote code execution (RCE) chains affecting Bonita BPM and Apache OFBiz. Researchers Lidor Ben Shitrit and Assaf Levkovich demonstrated how seemingly minor middleware vulnerabilities, such as differences in URL parsing, incomplete servlet protections, hardcoded cryptographic […]

    The post Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor’s agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it is—so leaders can decide which risks to fix, transfer, accept, […]

    The post What Is Cyber Security Risk Assessment? A Complete Guide (2026) appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizing recent emails, into a cross-account takeover scenario. The research reveals how untrusted content viewed by an AI browser agent can exploit authenticated browser sessions to steal email-delivered verification secrets and compromise accounts on services […]

    The post Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. “The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Seasats CEO Mike Flanigan isn’t really interested in building ship-sized drone boats. 

    “We don't plan to build bigger systems,” Flanigan told Defense One

    Instead, Seasats is all in on small unmanned surface vessels with three variants: Lightfish, which is about 12 feet long; the 20-foot Quickfish; and Heavyfish, the company’s largest offering at 35 feet long. The latter will make its water debut later this year. 

    “All of our substantial business is on Lightfish, so that's really where 95 percent of our focus is. That's what's supporting Marine Corps, Navy, Special Forces…what we're doing internationally,” he said. 

    Quickfish, which is in production, serves as a “reactionary tool” that can be used to reposition an asset or intercept a target. And Heavyfish is “essentially a Lightfish, but stretched out, where you don't need an expeditionary force to carry it off a beach with no equipment,” Flanigan said. “You can fit significant amounts of payloads, both subsea and aerial.”

    The San Diego-based company has long been working with the Navy and other militaries; one of its Lightfish vessels used for surveillance recently spotted a Chinese warship near the Philippines. Last year, a Lightfish traversed the Pacific from San Diego to mainland Japan autonomously. 

    There’s admittedly a lot of excitement, churn and chatter around larger USVs, but for Flanigan, smaller can be strategically important and avoid some of the pitfalls of building bigger. 

    “All of these platforms have this long endurance characteristic to them,” he said. “Small USVs have a strategic advantage against large platforms. [Vessels] under 40 feet are much harder to spot. They're much faster to build. You can use them with much less regret. So you actually end up with strategic value over something larger, like over 100 feet.”

    And now that Navy doctrine and planning is starting to include maritime drones in more detail, there’s a rush to adopt. 

    “There's some understanding now that's like, oh, you can put vessels that are 12 feet long anywhere in the world,” Flanigan said. 

    And that’s good for business.

    “Right now we're seeing huge adoption…definitely, we're in the thick of scaling and hiring” as “people are trying to move faster than each other.”

    Welcome

    You’ve reached the Defense Business Brief, where we dig into what the Pentagon buys, who they’re buying from, and why. Send along your tips, feedback, and song recommendations to lwilliams@defenseone.com. Check out the Defense Business Brief archive here, and tell your friends to subscribe!

    Sticker shock: President Donald Trump’s battleship costs keep growing. The Congressional Budget Office estimated the nuclear-powered ship program would cost about $275 billion, with the first battleship costing about $23.4 billion—up significantly from the administration’s original $15.1 billion estimate. That cost would drop to about $18 billion per ship as the fleet of 15 are built through 2056, according to the CBO report released this week. Sen. Jeff Merkley, D-Ore., and the ranking member of the Senate Budget Committee, ordered the CBO analysis.

    • For comparison: “A new DDG-51 destroyer costs more than $3 billion. Thus, if the average BBGN cost about $18 billion, the Navy could buy five destroyers for the price of one battleship.”
    • But those five destroyers would have higher maintenance and operational costs due to the need for more sailors and running on fossil fuel, the report states. 
    • And any cost savings with respect to nuclear-powered versus fuel are undeterminable at the moment: “Switching to nuclear power would reduce the battleship’s operating costs over time by eliminating the need to purchase fuel. CBO does not have enough information to estimate those potential savings, which would depend on the final design of the ship and the specifications of the conventional propulsion plant it otherwise would have used.”
    • Related: In last week’s earnings call, HII CEO Chris Kastner said the company started initial “design work for the battleship” with the Navy “on a limited basis.” 
    • The CBO report comes as the Pentagon pushes for a $1.5 trillion budget, ramped up weapons production, ambitious new programs like Golden Dome, and existing programs with cost overruns—even amid underlying concerns around transparency
    • In the back of my mind: The White House push towards manufacturing is exposing a dearth of workers who can build the nation’s weapons systems—especially at an accelerated pace.

    Making moves + other news

    • James Rainey, former commanding general of Army Futures Command, is now at Bain Capital. 
    • Hadrian secured a $1.37 billion Series D funding round, pushing its valuation to just under $8 billion. The AI-factory builder plans to expand, adding new factories and production lines for things like munitions and autonomous systems. 
    • Lockheed Martin is looking for domestic critical minerals suppliers. The defense giant signed a memorandum of understanding with NioCorp for the rare-earth metal scandium. Lockheed is also in talks with two companies, Teck Resources and 5N Plus, to supply germanium, Reuters reported. 
    • Ondas landed a $50 million contract for the Army’s Lethal Unmanned Systems (LUS) program. The company’s prime defense contractor, Mistral, received the award as part of a $982 million contract for the program. Ondas also hired David Barnea, former director of Mossad, to be the company’s global president and chairman. 
    • The Navy used a Saildrone USV to aid in a drug bust last year. The Voyager drone has been operating with Fourth Fleet for the past three years to support intelligence gathering and surveillance operations and was recently linked with an $81 million cocaine bust from a ship interdiction in October 2025.  
    • Blue Water Autonomy will join a $40 million IDIQ contract to map the ocean floor with uncrewed surface vessels. The multiyear contract with the Naval Oceanographic Office involves multiple vendors that will compete for task orders.
    • The energy company Fuse inked a research deal with the Nevada National Security Site. “Fuse has built commercial capabilities at the frontier of pulsed power technologies, creating a unique opportunity to advance the field through collaborative research,” Daniel Lowe, NNSS’s chief scientist, said in a news release. “By combining Fuse’s demonstrated hardware with NNSS's technical expertise, we'll be able to evaluate emerging technologies, explore new approaches to dense plasma focus systems and generate insights that benefit both national security missions and the broader fusion community.”
    • Tiberius Aerospace is working with the Army to further develop the company’s “next-generation precision-guided, ramjet-powered 155mm artillery munition,” called Sceptre. The company signed a CRADA, or cooperative research and development agreement, with Army Combat Capabilities Development Command Armaments Center. 
    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—Heavy seas didn’t stop Firestorm Labs from printing “thousands” of unique parts aboard the USS Essex amphibious assault ship on the way to the Rim of the Pacific naval exercise here, the expeditionary manufacturing company announced this week.

    “We were told it was the roughest water off the California coast in the last five years,” Firestorm CEO Dan Magy told Defense One. The company has an exclusive arrangement with HP, which uses a type of 3D printing called multi-jet fusion, “and what we’ve found is that the systems and the machines are quite resilient.”

    “We think we’re building a contested logistics solution that is going to be scalable across all branches of the Department of War,” Magy said. “If we’ve seen anything from Ukraine and now from Iran… we need to rethink warfare from the ground up. We are increasingly dealing with contested environments where—you know, look at what just a blockade in one part of the world has caused to the ability to get products out, oil prices. Heaven forbid something like that happened in the South China Sea, where 70 percent of the things we all buy in the world are produced.”

    Magy believes their xCell additive manufacturing unit—composed of two 20-foot containers that can go anywhere—"really represents a leap forward in how we're thinking about solving, maintaining legacy systems, but also building attritable systems like drones closer to the need.”

    During a tour of the xCell unit used aboard the Essex, Duane Blank, field operations manager for Firestorm, showed off some of the parts printed at sea, including stops made to protect Apache helicopter rotors from scraping against the ship’s non-skid coating.

    The nylon composite the company uses for printing works for “everything within the entire spectrum of warfare,” Blank said, from prosthetics to drones to humanitarian assistance and disaster relief items.

    Among the items printed while pitching through Sea State 5 were a dozen Squall first-person-view drones, Blank said, which were later used as adversary aircraft during a counter-drone exercise as part of RIMPAC.  

    The “beauty of 3D printing,” he said, is the “ability to iterate” and get troops what they need “at the point of need.”

    Magy said it’s a top concern.   

    “The No. 1 thing we're hearing from folks across the service is, ‘It's great if you make it in a factory in Alabama or California or Texas. What happens if the thing breaks on the battlefield? I have to put it in a box now for four months.’”

    Sustainment wasn’t what the company initially set out to address, he said, “but it has become increasingly important for all of our customers, because there are a number of legacy systems that like, the supply chain just isn’t there anymore. Let alone the supply chain for something in Okinawa or in Bahrain.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A Google dork is an advanced search query that combines Google’s search operators (such as site:, intitle:, inurl:, and filetype:) to surface information that is publicly indexed but hard to find through normal searching. Security professionals use Google dorking (also called Google hacking) for OSINT, reconnaissance, and to discover—and fix—their own exposed files, login pages, […]

    The post 1000 Best Google Dorks List (Google Hacking Guide) – 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and […]

    The post Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶