• Fortinet has released security updates to address high-severity vulnerabilities in FortiWeb and FortiClient for Windows. These vulnerabilities could allow unauthenticated attackers to access appliance administration interfaces or execute arbitrary code. The flaws CVE-2026-26035 and CVE-2026-70465 were disclosed as part of an August 2026 patch release that addressed eight security issues across various Fortinet products. The […]

    The post Fortinet FortiWeb and FortiClient Flaws Let Unauthenticated Attackers Gain Access and Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying on a conventional server or domain. The design shifts a core defensive assumption: seizing infrastructure may disrupt payload hosting, but it cannot remove commands that have already been committed […]

    The post Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase Them appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal information of 13,689 customers. Importantly, Trezor’s internal systems, hardware wallets, private keys, wallet backups, and cryptocurrency holdings were not compromised. However, the leaked data poses significant risks to affected users, particularly regarding phishing and […]

    The post Trezor Shipping Provider Data Breach Exposes Personal Data of 13,689 Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Beacon CRM has confirmed that a threat actor likely downloaded a complete copy of its customer database after gaining access to its Amazon Web Services (AWS) environment using a compromised AWS access key. In an incident update published on August 12, Beacon stated that the database contained all customer data stored on the platform, including […]

    The post Beacon CRM Data Breach Exposes Customer Data via Compromised AWS Access Key appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download pages. This malware combines various malicious features, including password theft, browser data collection, persistence, and the hidden remote control of authenticated Chromium browser sessions. Researchers have observed the campaign using a counterfeit GitHub-themed page that displays a “Download […]

    The post New AmnesiaStealer Malware Targets macOS Users via ClickFix Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The recent establishment of a organized-crime task force by U.S. Southern Command is the latest expression of the Donroe Doctrine, the administration's interventionist—some say imperialist—approach to Latin America. But it may also signal a increased desire to work with regional partners—or just to operate inside their countries.

    Last year's launch of Operation Southern Spear marked a return to a more hands-on U.S foreign policy in Latin America. Beginning with U.S Navy strikes against alleged drug-trafficking vessels, it has expanded to encompass the U.S. abduction of Venezuelan President Nicolas Maduro earlier this year and the subsequent re-intensification of U.S economic and military pressure on Cuba.

    But SOUTHCOM has also worked to integrate U.S. forces into local security operations and to bring partner states’ security forces under its operational umbrella. In March, the Americas Counter Cartel Coalition was created as a U.S-led body to coordinate regional actions against transnational organized crime. That same month, SOUTHCOM dispatched forces to help Ecuadorian security forces to take action against an alleged criminal hub inside Ecuador. Now the Joint Task Force Western Hemisphere, stood up on Aug. 4, is meant to facilitate and coordinate action against organized criminal threats by the U.S. military and regional partner states.

    The JTF-WHEM and the A3C suggest SOUTHCOM senses a need for multilateral cooperation. Though several Latin American governments are adopting tougher policies towards organized crime and were broadly sympathetic to Maduro's removal, Southern Spear’s controversial boat strikes and the Maduro operation provoked unease in a region with a long history of U.S. interventionism.

    The task force and the coalition are forums through which U.S. and SOUTHCOM leaders can build and enforce strategic consensus, guide operational planning, mediate disputes among members, and influence non-members. U.S. officials have sought to attract participation through political and material incentives. Diplomats and senior SOUTHCOM personnel have sought to attain regional buy-in, or at least acquiescence, for the United States' larger role in the region—including, perhaps, formal deployments of U.S. troops inside regional partner states. And officials are is increasingly tying security and economic assistance to commitments of cooperation in areas of U.S. interest.

    The JTF-WHEM, at least, appears likely to be put to imminent use. On Aug. 12, Defense Secretary Pete Hegseth announced that Colombia, Honduras, and Guatemala had approved U.S. participation in combined operations against criminal entities.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Private cyber firms will be allowed to take action against foreign threats under a new White House policy, another step into a future where tech developers are ever more closely entwined with military operations, which now evolve faster than governments can keep up.

    Under the policy, announced Wednesday, the U.S. government will pay private cybersecurity companies to “manipulate,” “degrade,” “disrupt,” and “destroy” foreign adversary computer networks. The U.S. government historically reserves the right to take those sorts of actions, although they increasingly do so with help from front-line private workers. 

    The companies will undergo vetting, be supervised by the departments of Justice and Homeland Security, and be forbidden to take actions that could “result in the loss of life or serious injury,” according to the presidential memo. 

    “The United States just revived privateering for the digital age,” wrote Jeff Gray, who led training for DHS’s emergency response team and currently leads incident response training with the Cybersecurity and Infrastructure Security Agency.

    The phrase recalls the 17th and 18th centuries, when governments issued letters of marque that allowed swashbuckling sea captains to attack foreign merchant ships. That official authorization is what distinguished men like Captain Kidd and Henry Morgan as “privateers,” not pirates. But when they lost that marque, many, like Kidd, went on to be pirates anyway.

    Gray acknowledges that the term isn’t a perfect fit; for one thing, letters of marque are granted by Congress, not the president. Nevertheless, he says, “The government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That's privateering.”

    The memo says hiring private hackers is only logical:  “American businesses’ innovative capabilities have historically been underutilized” to “secure a critical offensive cyber advantage for the United States.”

    Russia has been doing this sort of thing for years: enlisting, or coercing, private companies and groups to carry out cyberattacks against Western targets. 

    One cybersecurity exec said the policy makes sense, especially as AI gives adversaries more tools. 

    “There will be more cyberattacks for sure, so I do think you want to expand the takedown activity as well,” said the executive, a founder of a prominent U.S. cybersecurity firm that works with the U.S. government.

    AI-assisted cyberattacks rose 89 percent in 2025, according to a February report from cybersecurity company CrowdStrike.

    Gray also described the strategy as “strategically sound.” But he expects it to provoke a short-term increase in attacks, and over a longer timeframe, to cause adversaries to shift tactics, accelerate operations, and gain additional “cover” to hide their operations.

    Finally, Gray noted that law-enforcement agencies have long hired private firms for this sort of work, particularly taking down botnets. “The work is still the same. But the environment just got more complicated,” he said.

    The cyber exec agreed. “Instead of a law-enforcement person pushing the button, it will be a private-sector person,” said the company founder. “I expect every Israeli cyber startup to jump at the chance.”

    Cyberops and physical war

    The policy is the latest indication that software weapons are evolving to be as crucial as hardware on the modern battlefield—and that is putting private coders and weapon designers closer to real-world operations. In Ukraine, for example, engineers with drone maker Shield AI and other contractors work closely with soldiers, sometimes under fire, to modify weapons based on digital attacks.

    The job of fighting is, more and more, becoming a job of engineering, said one former senior defense official we spoke to in 2025, just after Donald Trump returned to office. The official said that the Pentagon’s new leaders were considering a plan to let drone makers and other tech companies conduct operations under company-owned, company-operated agreements.

    The idea was not without precedent. SpaceX operates the Starlink satellites that connect U.S. troops, rather than allowing U.S. personnel to do so. And under the first Trump administration, the Pentagon paid Anduril to maintain and update drones in the field, deploying along with special operations forces.

    The official said putting engineers in the field is essential to getting new capabilities to the front lines faster. 

    “A lot of these technologies,” they said, are  “super exquisite, they're fragile, they're very technical. The people that built them are the ones that know how they work.” 

    Having the weapons’ makers observe and even operate their products in the field reduced red tape in getting new designs approved, changed, or deployed.

    The official last year acknowledged that most defense firms don’t operate that way, and federal law outlines boundaries on what defense contractors can and can’t do (engaging in combat is in the "can’t do" column). But ultimately, they said, “If you want capability in 2027 the only way you're going to get is if this happens.”

    In April, CENTCOM hired Shield AI to provide intelligence, surveillance, and reconnaissance to U.S. forces with its V-BAT drone, under a contractor-owned, contractor-operated arrangement.

    Brandon Tseng, Shield AI’s co-founder, said of the agreement: “We aren’t just bringing the V-BAT product and service to the Navy; we’re bringing a world-class team with a wealth of operational experience and the ability to produce undeniable outcomes for our warfighters.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HUNTSVILLE, Ala. — Less than a year after President Trump reversed a Biden-era decision to keep U.S. Space Command in Colorado, space intelligence operations are being conducted in existing offices at Redstone Arsenal while a permanent headquarters is built on base.

    By year’s end, SPACECOM plans to have roughly 200 of the 1,800 Colorado-based positions at the Army base. Roughly 50 of those employees are already conducting missions with the command’s Joint Intelligence Support element, or JISE, which is already doing analysis for space operations and coordinating with allies. Those analysts are also coordinating with colleagues working, at least for the next few years, at Space Command’s existing headquarters in Colorado.

    “We've designed our facilities with collaboration spaces and with the collaboration tools that allow our personnel here in Huntsville—of course, those numbers are growing—to work back with our people in Colorado Springs to execute our missions,” Whiting told reporters on Wednesday. “So far, our folks are crushing that, and I'm very proud of how they're performing.”

    Reporters toured the up-and-coming facilities and saw the progress of the new headquarters on Wednesday during the Space and Missile Defense Symposium here. While the personnel moves and construction projects will not be complete until 2032, military officials said that the combatant command remains focused on its mission. 

    In April, Gen. Stephen Whiting, Space Command’s leader, hosted a ribbon-cutting ceremony for the Joint Intelligence Support element on base. Wednesday’s tour was among the first access allowed to media outlets.

    “Make no mistake, the JISE leading this charge serves as a symbol of our commitment to ensuring mission needs are executed flawlessly throughout this move,” Brig. Gen. Nathan Rusin, who leads the USSPACECOM Intelligence Directorate, said in an April press release. 

    In 2021, in the last weeks of his first term, Trump announced that Space Command would move its headquarters from Petersen Space Force Base in Colorado to Redstone Arsenal in Huntsville. Several congressional probes followed. In July 2023, President Biden reversed the decision and said it would stay in Colorado.

    An April 2025 Defense Department Inspector General’s probe wondered why the 2023 basing decision was made by the White House instead of Air Force Secretary Frank Kendall. The service secretary told lawmakers in 2023 he thought “the projected cost savings, together with the availability of potential mitigation measures, outweighed the operational risks that had been identified” for moving the command to Alabama.

    But a May 2025 Government Accountability Office probe showed that if SPACECOM headquarters were to remain in Colorado that “new military construction would be needed to support the headquarters’ operations” and that officials “faced ongoing personnel, facilities, and communications challenges” in setting up a permanent facility out West.

    Whiting told reporters that the goal is to have half of SPACECOM at Redstone Arsenal by 2028 with a full move-in completed by 2032. The command’s joint operations center, the main command-and-control hub for space warfare missions, will remain in Colorado until the completion of the new headquarters. 

    “The opportunity for U.S. Space Command is that we get a purpose-built command and control headquarters out of this, we did not have that in Colorado,” Whiting said. “So to get this facility is going to be an incredible accelerant to our mission.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶