• 7-Zip’s default configuration allows files extracted from internet-delivered archives to shed the Mark of the Web (MotW), meaning Windows SmartScreen never runs its reputation check and unsigned payloads can execute without a “Windows protected your PC” warning. That behavior, long treated as a red-team trick, is now formally recognized and tracked in multiple 7-Zip vulnerabilities, […]

    The post 7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The UK AI Security Institute (AISI) has reported a serious incident involving autonomous AI agents that were conducting cybersecurity evaluations. These agents crossed their intended test boundaries and performed unauthorized actions on the live internet. During tests between July 25 and 28, 2026, the institute identified 19 incidents across 122 attempts in which the agents […]

    The post Mythos 5 and GPT-5.6-Sol AI Agents Broke Cyber Test Boundaries and Targeted Real Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was stopped in just 128 seconds. The mshta.exe process reached out to attacker-controlled infrastructure, retrieved a remote second-stage payload, and began […]

    The post Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Botnet operators are systematically probing router diagnostic interfaces for OS command injection flaws, chaining default credentials, legacy CGI endpoints, and weak command execution patterns to gain full remote control and deploy Mirai‑like payloads. Recent scan telemetry shows concentrated HTTP requests targeting a tight set of “diagnostic” URLs on internet‑exposed routers, including /apply.cgi, /cgi-bin/diagnostic.cgi, /cgi-bin/adv_ping.cgi, /DiagnosticsMsg.cgi, […]

    The post Botnet Scans Router Diagnostic Tools for OS Command Injection Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine developer action into a complete compromise of their endpoint. A victim simply needs to click […]

    The post 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A controlled proof-of-concept by Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Copilot access can serve as a powerful launchpad for business email compromise (BEC). This scenario ultimately enables attackers to impersonate a CEO and redirect a $247,500 wire transfer. Research published on August 4, 2026, warns that AI-enabled email accounts […]

    The post Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Pentagon’s counterdrone task force awarded Kaizen Laboratories $15 million to build a “two-way” marketplace designed, in part, to make selling tech to foreign militaries easier. 

    The site was built from a “blank slate” and developed to facilitate the Pentagon’s Foreign Military Sale Fast Lane Initiative, Nikhil Reddy, Kaizen’s co-founder and CEO, told reporters ahead of the announcement. 

    “We just launched it, and we'll continue to bring on more partner nations, a ton more vendors to the system,” Reddy said. 

    The AI-backed marketplace has been online for about two weeks, but details of the contract weren’t publicly released until late Monday. The Pentagon awarded Kaizen the contract on May 8 through a rapid acquisition tool called an other transaction agreement.

    The new marketplace aims to provide a single point of purchase for the U.S. military and allies and partners, while helping them find the right technology that’s also interoperable. State and local agencies are also being onboarded, Mike Obadal, the Army undersecretary, said at a Center for Strategic and International Studies event Thursday.

    “Networked air defense, whether it's counter-UAS or ballistic missile, is critical because everyone has to be able to see the same picture,” which can mean sharing or having “commonality” in information and equipment where possible, Obadal said. 

    The Defense Department, other federal agencies, and certain “foreign governments are able to go on the counter-UAS marketplace, where we have a number of different industrial options. We've got all kinds of AI workflows in there. You can say: ‘Here's the problem I'm trying to solve, and it'll set up a package for you.’” 

    The platform is particularly helpful with foreign military sales, for which the portal and its Amazon Web Services backbone allows the Pentagon to “start the paperwork for a foreign military partner that immediately becomes a letter of intent or a letter of request,” Obadal said. “The initial ask from a foreign government is, ‘we would like to investigate these capabilities.’ Traditionally, that goes into our FMS, our foreign military sales process, which takes months at best to get to the other end.”

    Australia, Poland, Republic of Korea, Romania, and the United Kingdom are currently approved to use the marketplace, which could help the U.S. align its counterdrone tech with their militaries.  

    “Allowing them access to the pricing, the availability, the capabilities, all on a digital database … And then the backside of that, generating the FMS process and starting that FMS process is incredibly powerful,” Obadal said. “And so now we can come together with an informed discussion on how do we network counter-UAS between our countries, our deployed forces, our partners…That's what we're trying to promote with the use of modern tools like the marketplace.” 

    Reddy said he wants to make the marketplace the best “on the internet,” with lots of features, such as integrating test data, that he hopes to add in a matter of weeks. 

    “There's a ton of agentic tooling that we want to build into the platform, discovery, comparison of products…Testing integration so that you purchase an asset and you can immediately see testing and integration data to ensure that compliance is there,” Reddy said. “We've met with logistics leaders across the military that want repairability information and right-to-repair catalogs built into the marketplace. So all of that is coming.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Years after federal regulators invoked national security to push three Chinese state-owned telecommunications providers out of the American market, the companies never fully left, a new House probe has found.

    China Telecom, China Mobile, and China Unicom retained equipment, data-center space and connections to other networks in the United States after the Federal Communications Commission denied or revoked their authority to provide certain telecommunications services, according to a nearly 50-page bipartisan House China Committee investigation planned for release Tuesday and first seen by Nextgov/FCW.

    From 2019 to 2022, the FCC denied China Mobile USA’s application to provide international service; it revoked  related authorizations held by China Telecom Americas and China Unicom Americas. But those actions did not require the companies to remove equipment, leave data centers, or sever private network links, so the carriers continued offering enterprise networking, internet transit and other services, the panel found.

    The committee argues that those remaining footholds could give Beijing’s cyberspies visibility into sensitive traffic, help keep malicious infrastructure online and create opportunities to reroute data or reach U.S. targets. American officials regard China as the country’s leading cyber adversary, with a record of targeting critical infrastructure and stealing military, commercial and personal data.

    The three carriers did not respond to detailed requests for comment.

    Nextgov/FCW also sought comment from the FBI, the Cybersecurity and Infrastructure Security Agency, and several U.S. spy agencies. The Defense Intelligence Agency, which produces intelligence findings for the Pentagon, declined to comment.

    A spokesperson for China’s embassy in Washington said Beijing “firmly opposes the U.S. overstretching the concept of national security and going after Chinese companies,” adding that China would defend its “legitimate and lawful rights and interests.”

    The remaining network ties took on added significance in the committee’s review of Salt Typhoon, the sweeping Chinese espionage campaign uncovered in 2024 where hackers breached major telecom carriers in the United States and abroad. The intrusion reached systems used to comply with court-authorized wiretap requests and allowed the cyberspies to target the communications of senior U.S. officials, including President Donald Trump and Vice President JD Vance.

    Reviewing routing data from Sept. 22 to 25, 2024, just as the Salt Typhoon campaign became public, the committee identified 58 groups of internet addresses that CISA had linked to Salt Typhoon servers. China Mobile International’s network appeared in routes to those servers at least 192 times, helping keep the attacker infrastructure reachable as U.S. defenders sought to shut it down, the report said.

    The committee does not allege that China Mobile USA employees knew about or participated in the campaign, and it says the routing evidence does not definitively link the company to Salt Typhoon. But the panel argues that the overlap shows how China Mobile’s remaining network ties could help sustain malicious infrastructure.

    That finding came from a broader analysis that identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese or Hong Kong-linked networks allegedly claimed U.S. internet addresses without authorization, potentially diverting American traffic through their systems. The committee classified them as high-confidence hijacks of the Border Gateway Protocol, a bedrock system that directs traffic across networks, but acknowledged that some may have resulted from mistakes or poor network management.

    More than 4,200 of the incidents involved China Mobile-controlled networks. In September 2024, eight originated from the same network that appeared in routes to Salt Typhoon servers and diverted traffic belonging to unnamed U.S. network operators, the committee said.

    Addressing the threat

    Telecommunications networks have long been prized intelligence targets because they can expose private conversations and reveal what political and diplomatic leaders are thinking. Such concerns are compounded by China’s 2017 National Intelligence Law, which requires companies and citizens to assist state intelligence work. Beijing denies that the law compels companies to participate in illegal espionage.

    “China’s state telecommunications carriers for too long have enjoyed non-reciprocal access to U.S. domestic networks, but the seriousness of Salt Typhoon gives the FCC and other agencies more than enough justification to restrict or expel them,” said James Mulvenon, a leading authority on Chinese national security issues and vice president of intelligence at risk advisory firm Pamir Consulting.

    The committee recommends giving federal agencies greater authority over equipment and private network arrangements that remain after a license revocation, along with targeted removal funding, stronger routing protections and logging requirements for foreign-controlled operators.

    Marc Rogers, a veteran telecommunications expert who helped develop the mobile internet in the 2000s and has spent roughly two decades consulting governments and companies on telecom cybersecurity, agreed with many of the panel’s recommendations. Those include treating core telecom systems as high-risk targets requiring closer oversight, strengthening checks on how traffic moves across networks and tightening rules on the foreign-made equipment U.S. carriers can use.

    But Rogers disputed the panel’s call to expand “rip and replace” telecom equipment, calling such programs  economically unrealistic and could disrupt carrier operations.

    “On paper it sounds great, until you get someone with operational experience,” Rogers said. “Then they realize you’re basically talking about bulldozing an entire city and building a new one.”

    Rogers also said the panel’s recommendations resemble measures in British telecom security law but warned that they would work only if countries act together. 

    “If only one country takes a strong position, China will just maneuver around them,” he said, adding that the proposals are largely aimed at tactics China has already used. Policymakers should learn from those incidents, Rogers said, while also preparing for how Beijing’s methods may evolve.

    The findings underscore the difficulty of removing operators deemed national security risks from a telecommunications ecosystem built on private infrastructure and decades of commercial ties. Regulators can ban specific services without necessarily reaching the equipment, leases and private agreements that preserve connectivity.

    The committee based its report on subpoenaed company records, eight interviews conducted under oath, federal records, routing data and network infrastructure scans. It said Cloudflare and unnamed outside cybersecurity experts independently reviewed and verified portions of its routing analysis.

    Parent company control and U.S. footprint

    Across all three companies, the committee found U.S. subsidiaries that remained dependent on parent or affiliate entities in China or Hong Kong for important technical and operational functions while retaining equipment and network connections inside the United States.

    At China Telecom Americas, requests involving connections between U.S. and overseas networks were handled by personnel in Shanghai, Hong Kong or Beijing, according to testimony cited in the report. Service orders could also flow through a parent-controlled system to Shanghai Telecom without a separate contract. The U.S. subsidiary did not keep independent traffic-flow records, leaving employees unable to determine whether a parent or affiliate had changed routes involving equipment in the United States.

    China Telecom Americas identified 10 active points of presence — sites where a carrier keeps equipment and connects with other networks — across seven metropolitan areas. A senior engineering official also told the committee that about a quarter of the company’s U.S. transmission hardware was still made by Huawei, whose equipment the FCC has deemed a national security risk.

    China Mobile USA, meanwhile, was described by one witness as “basically a sales team,” while another said it had no network engineers. Orders for data center space and network connections were approved at its Hong Kong headquarters, and witnesses could not identify a network operations team based elsewhere. 

    Despite this, China Mobile USA’s records contained 39 point-of-presence entries across 27 data-center and interconnection facilities. The committee said those sites connected it to carrier backbones, internet exchanges and private networks used by major U.S. technology companies. Investigators identified at least 143 active China Mobile network assets in U.S. facilities.

    China Unicom Americas disclosed that seven of its eight directors and two of its three senior managers were Chinese Communist Party members. Its U.S. employees used parent-controlled email and computer systems, and evidence indicated that they operated under cybersecurity, administrative and privacy policies issued by China Unicom Global.

    A compliance official told the report’s authors the subsidiary could guarantee its own adherence to U.S. law, but not its parent’s.

    A China Unicom Americas compliance official also acknowledged that the subsidiary did not know the identities of some third parties in China that ultimately received services ordered through China Unicom Global. The company had equipment and active connections in roughly 10 U.S. data centers.

    Other carrier relations

    The report also describes relationships between the three Chinese carriers and companies linked by U.S. authorities to Chinese hacking operations.

    China Mobile, in one case, acted as a middleman for CloudRadium, a Hong Kong hosting provider whose infrastructure has repeatedly surfaced in malicious cyber activity, the committee said. Subpoenaed records showed that China Mobile purchased U.S. data center space and network connections on CloudRadium’s behalf, including through a four-year contract valued at $480,000.

    The report also links CloudRadium to a Wyoming company of the same name and GlobalData Investments, a California corporation that markets hosting and data center services under the CeraNetworks name. Nextgov/FCW found that the companies’ websites used similar logos, layouts and animations. An email sent to an address listed for Steven Beals, identified online as GlobalData Investments’ chief operating officer, was returned as undeliverable.

    The committee also details China Unicom’s relationships with Integrity Technology Group and i-SOON, two Chinese cybersecurity contractors U.S. authorities have linked to state-backed hacking.

    A 2024 U.S. advisory identified Integrity Tech infrastructure as the control layer for a botnet of compromised routers and other internet-connected devices operated by Flax Typhoon, a Chinese state-sponsored hacking group. China Unicom Beijing network addresses were used to manage the botnet and connect it to other attack infrastructure and, according to the committee’s report, China Unicom and Integrity Tech formalized a cooperation agreement in November 2023 while the botnet was operating.

    China Unicom separately appeared as a corporate partner of i-SOON. The company drew international scrutiny after a large collection of purported internal documents appeared on GitHub in 2024, exposing details about its hacking tools, targets and work for Chinese police and intelligence agencies. 

    The Justice Department later charged eight i-SOON employees and two Chinese police officers in a years-long hacking campaign, alleging that the company worked with at least 43 intelligence or police bureaus. The charges have not been proven in court.

    Integrity Tech’s website was unavailable when Nextgov/FCW attempted to contact the company, and a functioning corporate website for i-SOON could not be located.

    “China has been conducting an escalating campaign of cyberattacks on U.S. networks as a form [of] operational preparation of the battlefield,” said Jack Burnham, a senior research analyst in the China Program at the Foundation for Defense of Democracies whose work focuses on China’s military, emerging technologies and science and technology policy.

    “Key to these efforts is Beijing’s capacity to access core domestic networks, either via installed equipment, routing relationships, or other interconnections,” Burnham said. “While the FCC has sought to tamp down on Chinese state-owned telecoms firms that pose a national security threat, there is clearly more work to be done, both in terms of regulation and rip-and-replace, to properly handle these threats.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶