• Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent or synthetic account registrations to accumulate promotional credits offered by cloud providers. The […]

    The post Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access control bypass, unauthorized privilege escalation, and exposure of sensitive data. The most severe vulnerabilities are CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each with a maximum CVSS v3.1 score of 9.9. Critical Cisco SD-WAN Flaws These vulnerabilities were […]

    The post Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The United States would run out of the interceptors it needs to take down Chinese missiles “within days” of a conflict, according to a new report from the Heritage Foundation. It's the latest in a series of warnings from experts and commanders highlighting a critical gap. 

    The White House, Congress, and defense contractors have taken steps to address it. But the ongoing war with Iran has exposed those efforts as insufficient, experts say.

    It’s not a new problem. A 2023 report from the Center for Strategic and International Studies concluded that the U.S. would “within the first week of a Taiwan conflict” run out of key munitions, such as Patriot Advanced Capability-3 Missile Segment Enhancements, Terminal High Altitude Area Defense interceptors, and SM-6 and SM-3 Standard missiles. In May, CSIS reported that the United States will be in “a window of vulnerability for several years, until inventories return to their previous levels, and another several years before they get to the levels that war planners desire.” 

    The Trump administration is trying to wring more production out of industry. In January, the White House cut a deal with Lockheed Martin intended to triple annual production of PAC-3 missiles to 2,000. On Monday, the Pentagon announced a related seven-year, $3 billion deal with Lockheed and Northrop Grumman to boost the production of PAC-3 solid rocket motors. The deal is also intended to help “quadruple” annual production of THAAD interceptors.

    A Northrop spokesperson said a billion-dollar investment in its Allegany Ballistics Laboratory has enabled the company to double annual production of motors since 2021, and that the company aims to triple production by 2027.

    And yet these deals—and the goals the Pentagon set in January—are too small to quickly restore an arsenal depleted by Trump's war on Iran. “Those metrics that were set prior to [Operation Epic Fury]. That was before we just lit off billions of dollars in a decade worth of production per work in some cases,” said Tom Karako, who leads CSIS' Missile Defense Project.

    The Heritage report makes its own estimate of weapons expended in the war: “During the first four days of Operation Epic Fury, U.S. and allied forces used approximately 1,738 theater surface-to-air munitions to defend against 565 Iranian ballistic missiles and 57 cruise missiles.” 

    The report says the Pentagon currently has “less than 10 percent" of the PAC-3 MSE, THAAD, SM-6, and SM-3 interceptors "required to deter or, if necessary, prevail, in a protracted, high-intensity conflict with China.”

    The Heritage report is dire, but it may not go far enough, as it does not factor in how China may use low-cost drone warfare to further frustrate U.S. operations in the region. 

    In an April hearing, U.S. Indo-Pacific Command leader Adm. Sam Paparo also communicated his concerns about missile shortfalls and a lack of solutions for countering cheap drones. “Current production timelines are misaligned with operational expenditures and the threats we face,” Paparo said.

    Ukraine's shortage of Patriot interceptor missiles is reducing its ability to fight off Russian ballistic missiles. On July 28, Ukrainian President Volodymyr Zelenskyy met with Lockheed Martin representatives to discuss the possibility of license-building a Ukrainian version of the PAC-3. But such an agreement would not produce usable missiles until 2030. 

    The White House has gone back and forth on the issue. But Ukraine has gotten further with President Donald Trump than it did with his predecessor, Zelenskyy said in May: “I started this conversation with President Biden and I will continue with President Trump. Ukraine has not received a license to manufacture PAC-3. I believe that in the future, perhaps we will obtain one or there will be our own system.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The United States would run out of the interceptors it needs to take down Chinese missiles “within days” of a conflict, according to a new report from the Heritage Foundation—the latest in a series of warnings from experts and commanders highlighting a critical inventory gap. 

    The White House, Congress, and defense contractors have taken steps to address it. But the ongoing war with Iran has exposed those efforts as insufficient, experts say.

    It’s not a new problem. A CSIS report from 2023 concluded that the U.S. would deplete inventories of key missiles, such as Patriot Advanced Capability-3 Missile Segment Enhancements, Terminal High Altitude Area Defense interceptors, and Standard Missiles (SM-6 and SM-3), “within the first week of a Taiwan conflict.” A report from May concludes “there will be a window of vulnerability [in terms of U.S. operations in the Pacific] for several years, until inventories return to their previous levels, and another several years before they get to the levels that war planners desire.” 

    In January, the White House established a new framework to “triple” the production of PAC-3 missiles from 600 to 2,000 yearly, according to Defense Department estimates. To meet those higher production expectations, leading defense contractors are forming new partnerships with one-time rivals.

    On Monday, Northrop Grumman, Lockheed Martin, and the Department of Defense announced a $3 billion agreement to produce more solid rocket motors for PAC-3s, and to “quadruple” the number of THAAD interceptors over the next seven years. A Northrop Grumman spokesperson pointed to a billion-dollar investment in its Allegany Ballistics Laboratory as a key to allowing the company to double the number of such motors since 2021. Now, the company says it is on track to triple production by 2027.

    But even with new agreements and increased contractor investment in factories and labs, the goal the Pentagon set in January is too low, said Tom Karako, director of the Missile Defense Project at the Center for Strategic and International Studies—especially when the war with Iran is factored in. “Those metrics that were set prior to [Operation Epic Fury]. That was before we just lit off billions of dollars in a decade worth of production per work in some cases.”

    The Heritage Foundation report adds some specifics to the war’s cost so far: “During the first four days of Operation Epic Fury, U.S. and allied forces used approximately 1,738 theater surface-to-air munitions to defend against 565 Iranian ballistic missiles and 57 cruise missiles.” 

    As a result, the United States has “less than 10 percent of the … interceptors required to deter or, if necessary, prevail, in a protracted, high-intensity conflict with China,” it says, naming PAC-3 MSEs, THAADs, SM-6s, and SM-3s.

    The Heritage report is dire, but it may not go far enough, as it does not factor in how China may use low-cost drone warfare to further frustrate U.S. operations in the region. 

    In an April hearing, U.S. Indo-Pacific Command leader Adm. Sam Paparo also communicated his concerns about missile shortfalls and a lack of solutions for countering the threat of cheap drones. “Current production timelines are misaligned with operational expenditures and the threats we face,” he said.

    Ukraine is facing those threats as a reality right now. Leaders there have said they urgently need Patriot missiles to defend against continued Russian ballistic missile attacks, despite Ukraine’s successes in leveling the drone warfare playing field.

    Ukrainian President Volodymyr Zelenskyy met with Lockheed Martin on July 28 to discuss the possibility of building its own version of the PAC-3 under a license, which would directly address supply-chain gaps for parts in the long term. But such an agreement would not produce usable missiles until 2030. 

    The White House has gone back and forth on the issue. But Ukraine has gotten further with President Donald Trump than it did with his predecessor, Zelenskyy said in May: “I started this conversation with President Biden and I will continue with President Trump. Ukraine has not received a license to manufacture PAC-3. I believe that in the future, perhaps we will obtain one or there will be our own system.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Rocket Lab’s announcement that it would launch suborbital rockets from Alaska could ultimately give the Pentagon a much-needed new option for national-security launches, the company and space experts told Defense One.

    Last week, the Space Force’s acquisitions arm announced a $266 million, multi-launch contract with the California-based rocket company. That will cover 12 to 18 launches, which will start this year and “primarily take place from a new Rocket Lab location at the Pacific Spaceport Complex-Alaska (PSCA) in Kodiak," the company said. 

    These missile-defense missions will be handled by the company’s HASTE rocket, a suborbital variant of its Electron

    Both rockets “use the same launch infrastructure so yes, operating out of Alaska naturally opens the door to a broader range of possibilities including orbital launch,” a Rocket Lab spokesperson said. “It’s important to remember too that the core systems, infrastructure, and expertise we build and refine in Alaska aren’t tied to just one location.”

    Top Space Force officials and lawmakers are concerned that the Cape Canaveral and Vandenberg bases will be unable to handle the projected increase in military-satellite launches. The Space Force expects to launch more than 100 rockets a year within five years and potentially thousands a year by 2036.

    An Arctic national-security launch site would reduce the bottleneck and help the military reach polar orbits, said Clayton Swope, the deputy director of CSIS’ Aerospace Security Project.

    “Putting something in Alaska, you kind of get both of those things,” Swope said. “You get this diversification away from the two main launch sites we have, and you are creating a launch site that is more optimized around a different type of use, which is related to the orbit, the inclination.”

    The state-owned spaceport where Rocket Lab will host its new launch location boasts “a low population density, manageable air and maritime routes” that would distinguish it from some other launch facilities. But it has hosted just nine orbital missions since it was founded in 1998.

    Charles Galbreth, a retired Space Force colonel who directs space studies at  the Mitchell Institute, said the Rocket Lab expansion “could potentially be very helpful” for small and medium national-security launches—eventually.

    “It's a capacity or a capability waiting for a demand signal,” Galbreth said. “So there's got to be the combination.”

    Alaska can be an important addition, yet its isolation will present challenges, said Brian Weeden, who directs civil and commercial policy for the Aerospace Corporation’s Center for Space Policy and Strategy.

    “I certainly think there is room for an expansion of different kinds of launch activity in Alaska. I don't think it's going to probably take the place of also standing in other areas,” Weeden said. “You're still going to need power. You're going to need to get rocket fuel up there. You're going to get the payloads transported up there, and that may be a little bit harder to do in a more remote location like Kodiak, as opposed to a place like Cape Canaveral or Vandenberg, where a lot of infrastructure already exists.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • At least 206 people worked for the Department of Government Efficiency, but much remains unknown about the Trump administration's government-overhaul effort because federal agencies refused to fully cooperate with a Congressionally-ordered inquest.

    In a new report published on Wednesday, the Government Accountability Office said it was largely unable to determine whether DOGE employees completed required ethics training and paperwork. GAO looked specifically at employees who worked for DOGE in the Executive Office of the President or were detailed from EOP between Jan. 20, 2025, and Jan. 31, 2026.

    GAO identified 206 such people and that at least 128 of them had left by Jan. 31, 2026. 

    At least 27 were special government employees who were limited to serving 130 days during any one-year period. One prominent SGE was Elon Musk, the former de facto head of DOGE, whose companies received billions of dollars in federal contracts during his government service. 

    Investigators were not able to determine the appointment type, such as Schedule C political appointee or noncareer Senior Executive Service, for more than 150 of the personnel because many agencies did not provide the requested information. 

    “This total includes the 127 [U.S. DOGE Service] employees who held titles as digital services experts or consultants within USDS,” according to the report. “Although USDS has stated that USDS positions last no more than 4 years, we were unable to determine whether these USDS employees or other personnel had held such time-limited appointments.”

    In total, 10 agencies and the EOP did not respond to requests from GAO for records that these DOGE employees participated in ethics training and completed financial disclosure reports. 

    “As a result, we are not able to determine the total number of DOGE personnel who held positions within EOP who received trainings or who completed financial disclosures at those 10 agencies or at EOP,” investigators wrote. 

    Nine agencies, covering 64 DOGE employees, did submit information about whether the staffers did such training and reports. But GAO argued that much of the documentation was incomplete. For example, the Agriculture Department provided an “ethics-related presentation” for Trump appointees but didn’t offer evidence for when, or if, the DOGE staffers received the training. 

    The White House did not respond to a request for comment. 

    While “the U.S. DOGE Service Temporary Organization” terminated on July 4, pursuant to the executive order establishing it, GAO pointed out that the directive permanently renamed an existing White House office as the U.S. DOGE Service. 

    “Since the EO does not call for the termination of the broader USDS entity, it is possible that USDS and personnel at federal agencies could continue to do work that advances some of these initiatives after the temporary organization’s termination,” investigators wrote. 

    DOGE spearheaded many of the civil service reductions that took place last year, resulting in a decrease of more than 350,000 to the federal employee headcount

    GAO in April reported that the Treasury Department and DOGE did not follow all security protocols with respect to granting access to government payment systems.
     

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • No one is saying, officially, what was decided when top frontier AI labs—Google, OpenAI, Anthropic, and Meta—met with White House officials on Tuesday to discuss voluntary guidelines for testing new models.

    But Democratic lawmakers described the Trump administration's approach to regulation as “ad-hoc and unpredictable,” and said it’s likely to boost global adoption of rival Chinese models at the worst possible time.

    Two officials with one of the labs said that Google, Anthropic, and OpenAI submitted a joint draft of the regulation around nine days ago and then began to work with each other and with the White House to find points of agreement. According to the officials, the labs all agreed they should be able to continue A/B testing as part of the process for developing models, and the White House concurred. 

    Companies that agree to the framework will submit their models to U.S. inspectors to be evaluated for safety for 30 days before those companies can receive federal funding—including from the Defense Department, whose 2027 budget request seeks more than $54 billion for AI companies, according to the officials.

    A June White House executive order adds that models from participating companies would get extra intellectual property protection from Chinese competitors or others who might seek to steal secrets.

    The White House is not commenting on how it will conduct the inspections. One of the officials said the the Office of Science and Technology Policy is still trying to set testing standards and how bodies like the National Institute of Standards and Technology and the Cybersecurity and Infrastructure Security Agency will conduct or design tests. 

    The murkiness around the policy’s details has angered some top lawmakers. In a Tuesday letter, Senate Democrats ask the White House to “provide an unclassified response, with a classified annex if necessary, clarifying the Administration’s current policy and approach to limiting access to advanced AI models.”

    The lawmakers also evinced concern about the models' new abilities to defy easy inspection, scrutiny, and limitation. 

    “During an internal evaluation [in July] OpenAI models escaped their testing environment and used high-level technical capabilities to compromise a third party’s network without any instructions to take those actions,” the letter reads. “The Federal Government cannot be passive as these capabilities emerge.”

    AI’s Jurassic Park moment

    Last week, Chinese company Moonshot AI released a new open-weight model, Kimi 3, that performs as well as some top U.S. models and is being offered to consumers around the world at a far lower price.

    Lawmakers and others are increasingly worried the United States could fall behind China in a race to develop faster, more efficient, more profitable models and to shape the way global populations use, buy, sell, and even build AI. Open weight models have become a key point of contention. 

    Anthropic wants more scrutiny of open-weight models and more efforts to curb sales of high-performance chips to China to thwart distillation attacks. But others in the industry are taking a more supportive view of open weights.

    A former senior White House official and a former senior defense official with direct knowledge of the discussion said Anthropic pushed for more language in the framework to address open-weight security, but came away disappointed.

    Anthropic did not comment for this story. 

    In recent months, several of the newest AI models have broken out of their virtual testing containers.

    Anthropic disclosed the first such incident in April, when an early version of their Mythos model was able to “autonomously write some remarkably sophisticated exploits,” including one that allowed it to escape an isolated testing environment that programmers use to test code for effectiveness and safety before it’s released. 

    Anthropic pulled the model from general release, but made it available under "Project Glasswing" so the government and a handful of large companies could find and fix vulnerabilities in their software.

    The White House responded with an export-control ban on June 12, barring access to the model not just to foreign countries but even foreigners in the United States. That meant that Anthropic’s own researchers, many of whom were born outside of the United States, could not work on the model. The White House reversed the ban on June 30.

    In July, tensions around a national AI safety strategy, or lack thereof, grew hotter. Both Anthropic and OpenAI revealed new incidents in which models breached their containment. It came as no surprise to many veteran cybersecurity experts. AI researcher and author Gary Marcus, in 2022, predicted such a possibility on his blog, describing it as an “AI’s Jurassic Park Moment.”

    Last week, AWS Chief Security Officer Stephen Schmidt told reporters: “Containers are not security boundaries. I actually have a T-shirt that says that, which I started wearing about three years ago.” 

    AWS hosts multiple models for users through its Bedrock platform. Schmidt said the AI Mythos era requires a far more vigilant approach to cybersecurity, especially for researchers. 

    “One of the reasons that we built the virtualization infrastructure for AWS using our own Nitro Hypervisors so many years ago was we realized that containers were not an appropriate security boundary then. The same is true for AI. You cannot use an AI container as a security boundary.”

    In March, a group of British researchers calculated the sandbox breakout period for various large language models, which proved very accurate months later.

    A follow-on paper published this week by the same group describes how to build better containment environments for the models emerging today.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶