No-frills tech news

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller. "They also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller," ESET security researcher Jakub Souček said in a report shared with The Hacker News. "These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied legitimate certificates and icons." The Slovakian cybersecurity company also called out the ransomware crew for its ability to "unusually quickly operationalize" newly disclosed proof-of-concept (PoC) exploits related to an attack technique called the bring your own vulnerable driver (BYOVD) technique, in many cases within days of their public release. Since its emergence in March 2025, The Gentlemen has swiftly risen up the ranks and made a name for itself as one of the most active ransomware groups. Per data from Ransomware.live, the group has claimed 504 victims to date, with most of them located in Southeast Asia, South America, and Western Europe. Recent reports from cybersecurity journalist Brian Krebs and PRODAFT have revealed that a 36-year-old Russian national named Alexander Andreevich Yapaev (aka hastalamuerte) has been leading the operation, after acting as an affiliate for other ransomware schemes, including Qilin. ESET has described The Gentlemen as one of the most technically agile RaaS groups, using a set of techniques to ensure that the compiled EDR killer samples sidestep detection. This includes binary protection using Enigma or Themida and using file names that resemble well-known cybersecurity vendors, right down to their version information, digital signatures, and icons. The most prevalent of them is GentleKiller, which comes in

Naples Chamber to focus on <b>cybersecurity</b> threats | GB Daily | gulfshorebusiness.com

Greater Naples Chamber will host its next Wake Up Naples program on July 15, focusing on cybersecurity risks and strategies for protecting businesses in an increasingly digital environment. The event, titled Protecting Your Business in a Digital Age, begins at 7:30 a.m. at the Hilton Naples, 5111 Tamiami Trail N. Panelists will discuss preventing cyberattacks through artificial intelligence-driven security tools, protecting financial assets from fraud and responding to cyber incidents. Chamber officials say the program is designed to help business owners understand emerging threats and strengthen their organizations' defenses. Tickets are $55 for chamber members and $65 for nonmembers. To register, click here. Naples Chamber to focus on cybersecurity threats - By Adam Regan - 0 (0) comments Welcome to the discussion. Log In Keep it Clean. Please avoid obscene, vulgar, lewd, racist or sexually-oriented language. PLEASE TURN OFF YOUR CAPS LOCK. Don't Threaten. Threats of harming another person will not be tolerated. Be Truthful. Don't knowingly lie about anyone or anything. Be Nice. No racism, sexism or any sort of -ism that is degrading to another person. Be Proactive. Use the 'Report' link on each comment to let us know of abusive posts. Share with Us. We'd love to hear eyewitness accounts, the history behind an article.

DHS continues to make workforce decisions for FEMA, lawsuit contends

Getty Images/kellyvandellen National Park Service employees vote to unionize Federal Newscast Read more AP Photo/Mark Schiefelbein The ‘new’ Schedule F will NOT, necessarily, politicize the civil service Commentary Read more

New <b>cybersecurity</b> measures could mean more research funding for UWM

In an era when federal funding for research is scarce, UW-Milwaukee has taken steps toward a data security certification that will make its researchers eligible for a wider range of federal projects. The Office of Research hopes it also offers area companies new ways to collaborate with UWM. Cybersecurity Maturity Model Certification (CMMC) is a set of federal data security protocols required for universities and companies involved in defense-related projects. UWM achieved the Level 1 certification in January and is working to reach Level 2 certification by November, said Ali Abedi, vice chancellor for research. By opening a potential source of research funding, CMMC could aid the university’s efforts to retain its status as a “highest research activity” institution, often called R1. To achieve Level 1 certification, UWM had to confirm that it uses cybersecurity practices that keep even non-classified research information secure. These measures include university policies and basic tools such as door locks, cameras in some research-related spaces and access control lists that give only certain people access to labs. Level 2 certification is more rigorous and expensive to achieve. It involves building secure lab spaces and creating a secure data enclave, an isolated portion of the university’s computer network. Simply accessing calls for proposals for these federal projects requires a secure channel, Abedi said. He intends to apply for grants to fund the Level 2 upgrades. No other universities in Wisconsin currently have Level 2 certification, although UW-Madison and UWM are both working toward it. “We are trying to work together as much as possible,” Abedi said, to find cost savings. For example, the two universities could share the consultants needed to achieve the certification. Bringing more defense-industry jobs to Wisconsin UWM and WisPolitics recently co-hosted a panel discussion that considered ways universities and industry can cooperate

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use. This is not a remote attack. It requires physical possession of the device, which must be in DFU mode and connected via USB to a dedicated RP2350-based microcontroller board. With that setup, the exploit finishes in under two seconds, before Apple's signed boot chain loads. The full technical write-up and a working proof of concept went public on June 18, 2026, following coordinated disclosure with Apple Product Security. Affected Devices The public PoC supports A12, A13, S4, and S5 SoCs. A12X and A12Z support is described as theoretically possible but not yet implemented. Device families in that range include the iPhone XS, XS Max, and XR; the iPhone 11, 11 Pro, 11 Pro Max; the iPhone SE (2nd generation); the iPad Air 3rd gen, iPad mini 5th gen, and iPad 8th gen; Apple Watch Series 4 and 5; the first-generation Apple Watch SE; the HomePod mini; and other Apple products built on those chips. A11 is not affected. A14 and later appear to be out of reach for this exploit path. The Bug The root issue is a hardware flaw in the Synopsys DWC2 USB controller. The controller stores incoming USB Setup packets via DMA, buffers up to three, then resets its write pointer on the fourth by decrementing it by a fixed 24 bytes. It also accepts smaller-than-standard packets, incrementing the pointer only by the actual bytes written. That mismatch accumulates into a repeatable buffer underflow, stepping the write pointer backwards through memory 12

SimpleHelp patched CVE-2026-48558, a critical authentication bypass vulnerability ...

Initiatives for As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here. - Last update: 18/06/2026 - Affected software: → SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions.- Type: authentication bypass vulnerability - CVE/CVSS → CVE-2026-48558 CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) SimpleHelp - https://simple-help.com/security/simplehelp-security-update-2026-05 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OpenID Connect (OIDC) authentication flow. The vulnerability can be exploited in specific conditions depending on the server's settings and network context. SimpleHelp is a commercial remote support and remote access platform used by IT administrators, managed service providers (MSPs), help desks, and organisations to remotely connect to and manage. Successful exploitation of the vulnerability could allow unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, install programs; or view, change, or delete data. A video demonstrating the exploitation of the vulnerability was published, increasing the risk of exploitation. CVE-2026-48558 (CVSS 10) is a critical vulnerability in SimpleHelp that allows for OIDC authentication bypass. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication, by accepting forged tokens without verifying their cryptographic signatures. Patch SimpleHelp addressed the vulnerability in a security advisory with updated versions. The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing. Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. In case

AI Monitoring: Key Concepts and Best Practices | CrowdStrike

AI tools are everywhere now. Employees use them to draft emails or summarize documents. Developers use them to write code. Engineering teams build AI-powered applications. Autonomous AI agents are starting to take real actions inside real business systems, such as booking meetings or querying databases. All of this is genuinely useful. However, it creates a security problem that most organizations haven't fully reckoned with yet. AI monitoring is the practice of observing, logging, and analyzing how AI systems behave to help security teams detect threats, enforce policy, and maintain visibility. The term covers two distinct things that are easy to conflate: - Using AI as a tool to help find threats faster - Monitoring your AI systems to make sure they're behaving as intended. Both matter and require attention, but they're different problems that call for different thinking. Introducing the new AI attack surface For most of the history of cybersecurity, the things defenders had to protect were relatively well understood: endpoints, networks, identities, cloud workloads, etc. The advent of AI added a new layer that didn't fit neatly into any of those categories. Vulnerabilities in AI agents and tools When a user types a prompt into a generative AI (GenAI) tool, or when an AI agent reads a document and decides what to do next, something is happening that most traditional security tools can't see. That interaction layer — between users, models, agents, and data — is where a new category of attacks is taking shape. Adversaries noticed the gap quickly. According to the CrowdStrike 2026 Global Threat Report, attacks by AI-enabled adversaries increased by 89% in 2025. This number reflects something important: AI isn't just helping a handful of sophisticated nation-state threat actors move faster; it's raising the floor for everyone. Less-skilled adversaries can now use AI to

MSSP sales best practices: How to close more <b>cybersecurity</b> business

The 2026 MSSP Alert Ranking Survey is now live. Submit your MSSP here and get recognized for being a top security provider in the world. Many business owners and C-suite executives still view cybersecurity through the lens of familiar tools: antivirus, firewalls, backups, and endpoint protection. Although those controls still matter, they don't address the questions that should keep business leaders up at night.Who is watching for threats after hours? How quickly would the company know if an attacker gained access? What would happen if a critical system went down? Could the business prove to an insurer, auditor, or customer that it had taken reasonable steps to reduce risk?That disconnect leads to a real sales problem for MSSPs (managed security services providers). The challenge for MSSPs is two-fold. First, helping prospective clients understand why basic defenses are no longer enough. And second, positioning the MSSP as a trusted advisor that can address business risk and improve operational resilience across the business. Ritchie said MSSPs need to show value through customer trust, transparency, and reduced risk.“To me, ROI in cybersecurity is measured by reduced risk, better visibility, stronger uptime, and more confidence in decision-making. Also, customers feeling like they finally understand and control their own IT environment,” he said.That framing matters for executives, who want to understand value, risk, and business impact before technical detail.“That is the kind of language that appeals to a business owner or C-suite executives,” Ritchie said. “Business owners do not always want every technical detail first; they want to understand the value, the risk, the impact, and whether they can trust the person sitting across from them.” The challenge for MSSPs is two-fold. First, helping prospective clients understand why basic defenses are no longer enough. And second, positioning the MSSP as a trusted advisor that can

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways. To defend against this malicious cyber activity, CISA urges impacted Fortinet customers with FortiGate appliances and associated secure sockets layer (SSL) VPN gateways to immediately: - Terminate sessions and reset credentials. Terminate all active SSL VPN and administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies. - Ensure secure credential storage. Confirm your organization’s use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes per Fortinet’s guidance (see, Fortinet's Technical Tip: Enforcing PBKDF2 as hash function for administrator accounts in FortiOS v7.2.11 and later). - Review logs. Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes. - Enable phishing-resistant multifactor authentication (MFA). Require phishing-resistant MFA on all remote access and administrative accounts and ensure it is enforced on all external gateways and administrative interfaces. - Reduce the attack surface and lock down management access. Ensure the administration of your firewall is inaccessible from the public internet; restrict Fortinet management interfaces to trusted internal networks; and remove or disable any unauthorized or unnecessary accounts. See the following resources to determine your organization’s potential impact and find additional guidance on the credentials compromised: - Tech Times: Fortinet FortiGate Credential Leak Hits 73,932 Firewalls: Half the Internet-Facing Fleet - SOCRadar: FortiBleed: The Compromise of 80,000+ Fortinet Firewalls - Hudson Rock: FortiBleed: 75,000 Fortinet Firewalls Compromised:

Mirva consolidates <b>cybersecurity</b> and backup operations with Acronis to deliver secure ...

Swedish MSP unifies backup, cybersecurity and service delivery through a single platform — enhancing efficiency, visibility and client trust. Mirva, an MSP with offices across Stockholm, Uppsala, Gävle and Sundsvall, specializes in delivering cloud, infrastructure, security and consulting services. Mirva needed a reliable, scalable solution to simplify operations and strengthen cybersecurity. The company turned to Acronis to unify backup and cybersecurity management on a single platform. Mirva partnered with Gridheart, a Sweden-based cloud distributor and Acronis partner, to support implementation and ongoing operations. Gridheart provided technical expertise, simplified billing and local-language support, ensuring smooth deployment and long-term success. KEY CHALLENGES - Fragmented systems required technicians to switch between multiple platforms, reducing operational efficiency. - Lack of integration between tools created risks and reduced visibility across client environments. KEY REQUIREMENTS - A scalable, unified platform to manage backup, cybersecurity and endpoints from a single interface. - Simplified operations with improved visibility across all client environments, including servers, endpoints and Microsoft 365 in a unified user interface. THE SOLUTION Mirva chose Acronis for its integrated backup and cybersecurity platform, gaining centralized visibility across servers, endpoints and Microsoft 365. The unified interface reduced tool switching, improving efficiency and streamlining workflows. THE IMPACT - Streamlined operations by consolidating multiple tools with one unified platform. - Improved technician efficiency and reduced administrative overhead. - Enhanced visibility and control across all client environments. - Strengthened cybersecurity posture with natively integrated cyber protection. “What made the difference was Acronis managed to gather all functionality into one system. We no longer had to jump between different platforms or adapt to different logics. Everything is connected, making it easier and safer.”

Kodak investigating <b>cybersecurity</b> breach of 'limited amount of company data'

Kodak investigating cybersecurity breach of ‘limited amount of company data’ ROCHESTER, N.Y. — Kodak is investigating after a third party illegally gained access to a “limited amount of company data”, the company confirmed on Thursday. Kodak is working with cybersecurity experts for its investigation, but it says it’s “confident” that the breach was limited and now contained. The film and photography company says there was no threat to its systems or operations. Kodak has also notified law enforcement, which is also investigating. The company says it will share more updates once it can. Other recent data breaches News10NBC has covered several recent data breaches recently, including Rochester Regional Health, the medical supply fulfillment services company Fieldtex Products in Henrietta, and the Rochester Philharmonic Orchestra. The Cybersecurity and Infrastructure Security Agency says the best way to protect data is by using strong passwords with two-factor authentication, being aware of email phishing scams, and maintaining offline, encrypted backups of sensitive data in case of a ransomware attack.

EU Gets a Head Start in Developing 6G Network Security

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific EU Gets a Head Start in Developing 6G Network Security "Shield-6G" will combine AI threat detection, digital twins, honeypots, and more, to help carriers protect 6G networks against the threats of tomorrow. European academics and researchers are already working on securing 6G communications in anticipation of a widening attack surface, increased interconnectivity, and classic nation-state threats. Did you know that 6G is already a thing? Word on the street is that it might get rolled out globally around 2030. In anticipation of that near future, 19 organizations have signed onto the "Shield-6G" project — a European Union (EU)-funded venture to develop 6G cybersecurity. The ultimate goal is to develop a cyber threat intelligence platform across network operators, securing the future of mobile communications by the time it arrives. "6G is way more complex than 5G, because it manages more devices, and there's more automation, and with automation there come problems," says Bart Siniarski, director at MBP Network Technology, a Shield-6G member organization. "The attack surface will be extended by a couple of magnitudes. So when we step into 6G — which is, to me, 5G on AI steroids — there are going to be problems at the beginning. And then over time [the goal is that] we are comfortable using 6G in critical infrastructure like hospitals or factories or maybe in shipping and militaries." What's Going to Change with 6G Siniarksi points to the Internet of Things (IoT) and industrial IT as drivers for this next generation of wireless networking. "There's going to be a huge number of interconnected devices [in the near future] — like cars that need to talk to each

SLHRD Hosts RESS NSF Launch Event Highlighting AI and <b>Cybersecurity</b> Education

SLHRD Hosts RESS NSF Launch Event Highlighting AI and Cybersecurity Education June 18, 2026 Baton Rouge, LA - The School of Leadership & Human Resource Development hosted the Robert Noyce Research Experiences in STEM Settings (RESS) Launch Event on May 31, 2026, bringing together grant participants, LSU & Louisiana education leaders, program faculty, and invited guests to formally begin the next phase of an innovative National Science Foundation (NSF)-supported teacher development initiative. Led by Petra A. Robinson, PhD, the event marked the launch of the Robert Noyce Teacher Scholarship Program: Research Experiences in STEM Settings (RESS), a multi-year project designed to prepare middle school STEM teachers to integrate research, artificial intelligence, and cybersecurity concepts into classroom instruction. Hosted in the iconic Huey P. Long Ballroom on LSU’s campus, the evening introduced participants to the project’s goals, instructional team, and upcoming learning experiences. A central focus of the event was the program’s emphasis on AI and cybersecurity education. Through the RESS initiative, participating teachers will engage in on-campus summer intensives, applied research experiences, and professional development activities that connect emerging technologies with practical STEM teaching strategies. The project aims to help educators bring future-focused AI and cybersecurity learning into middle school classrooms across Louisiana. Participants represented the Zachary Community School District and East Baton Rouge Parish School System, including educators from Belfair Montessori Magnet, Coppermill Elementary, Glasgow Magnet, LSU University Lab School, Northwestern Middle, Park Forest Middle, and Woodlawn Middle School. Several distinguished guests attended in support of the launch, including Roland Mitchell, PhD, Dean of the LSU College of Human Sciences & Education; Troy Blanchard, PhD, Interim Senior Vice Chancellor for Academic Affairs & Provost; Rebecca Boniol, Esq., LSU Board of Supervisors; Ronnie Morris of the Louisiana Board of Elementary and Secondary Education (BESE); and Ben Necaise, Superintendent of the

Are we facing a <b>cybersecurity</b> crisis?

THE TIMES CEO SUMMIT Are we facing a cybersecurity crisis? With the release of Anthropic’s Mythos, new threats are emerging from AI — but we haven’t fixed the old ones yet, industry experts warn Previous Article Next Article

Inexpert Supervision: Field Evidence on Boards' Oversight of <b>Cybersecurity</b>.

JOURNAL ARTICLE Inexpert Supervision: Field Evidence on Boards' Oversight of Cybersecurity. - Published In: Management Science (INFORMS), 2026, v. 72, n. 2. P. 783 1 of 3 - Database: Business Source Ultimate 2 of 3 - Authored By: Lowry, Michelle R.; Vance, Anthony; Vance, Marshall D. 3 of 3 Abstract This article examines how cybersecurity expertise among corporate board directors influences the substantive versus symbolic nature of their oversight of cybersecurity risk, an emerging and complex area where expertise is scarce. Through qualitative interviews with 20 directors (both expert and nonexpert), 11 cybersecurity executives, and 7 consultants, the study finds that while all directors generally seek to perform diligent oversight, nonexpert directors often engage in legitimate but largely symbolic practices that lack depth and independence, such as asking superficial questions and relying heavily on CISOs for guidance. In contrast, directors with cybersecurity expertise are better able to ask incisive questions, detect management’s filtering of information, and provide substantive oversight, highlighting a gap in oversight effectiveness linked to expertise. The study also explores reasons why boards do not prioritize appointing cybersecurity experts, noting practical constraints and nonexpert directors’ confidence in their general business experience as sufficient for oversight. These findings contribute to corporate governance literature by contextualizing agency and institutional theories in cybersecurity oversight and inform ongoing debates about the need for board-level cybersecurity expertise. Additional Information - Source:Management Science (INFORMS). 2026/02, Vol. 72, Issue 2, p783 - Document Type:Article - Subject Area:Information Technology - Publication Date:2026 - ISSN:0025-1909 - DOI:10.1287/mnsc.2023.04147 - Accession Number:191433159 - Copyright Statement:Copyright of Management Science (INFORMS) is the property of INFORMS: Institute for Operations Research & the Management Sciences and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any

Got $1000? 1 Unstoppable <b>Cybersecurity</b> Pioneer to Buy Hand Over Fist and Never Sell

CrowdStrike (NASDAQ:CRWD | CRWD Price Prediction) is a stock worth owning for decades because cybersecurity has quietly become a non-negotiable utility, and the Falcon platform now sits at the center of how the world’s largest enterprises secure both their existing infrastructure and the new wave of AI workloads that businesses cannot switch off even during a downturn. For a retirement-focused investor who has been burned chasing trends, the appeal here is the structural reality that long-term tech analysts keep returning to: cybersecurity has shifted from a discretionary corporate expense to a non-negotiable utility, and CrowdStrike stands out as the gold standard in end-user and cloud security thanks to its cloud-native Falcon platform. Pillar 1: Durability of the Business CrowdStrike’s revenue is overwhelmingly recurring. In the most recent quarter, $1.32 billion of $1.39 billion in Q1 revenue came from subscriptions, and total ARR reached $5.51 billion, up 24% year over year. Customers are deepening their commitment: 51% of customers now run 6 or more modules, 35% run 7 or more, and 25% run 8 or more. The platform is wired into AWS, Microsoft, NVIDIA, Google Cloud, OpenAI, Anthropic, IBM, and Salesforce, which makes Falcon less a vendor and more a layer of enterprise plumbing. CEO George Kurtz framed the position bluntly: “CrowdStrike is AI security infrastructure, critical to successful AI adoption.” That is the language of a utility. Pillar 2: Compounding Through Free Cash Flow CrowdStrike pays no dividend, so the compounding case rests on free cash flow and buybacks. Q1 free cash flow reached $468.5 million, up 66.76% year over year, at a 34% margin. Full-year FY26 free cash flow was $1.24 billion, and the company holds $4.55 billion in cash against $949.4 million remaining under its share repurchase program. Management already repurchased $175.6 million of stock in Q1 FY27.

Huntsville defense contractor agrees to pay more than $500K over <b>cybersecurity</b> violations

Huntsville defense contractor agrees to pay more than $500K over cybersecurity violations HUNTSVILLE, Ala. (WAFF) - A Huntsville-based defense contractor, LOGZONE Inc., has agreed to pay over 500K to resolve False Claims Act. The company will pay $507,144 for allegedly failing to comply with cybersecurity requirements in two contracts with the Navy. “Government contractors that obtain sensitive defense information in administering their contracts must follow required cybersecurity standards,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements in order to protect this critical information from external threats.” “The protection of sensitive defense information by government contractors is critical to national security,” said U.S. Attorney Phillip W. Williams Jr. for the Northern District of Alabama. “Adherence to the cybersecurity provisions of contracts with the federal government must be a priority for all contractors, and this enforcement action should serve as a reminder of that.” “The cybersecurity provisions of federal contracts are critical to protecting sensitive information that may be transmitted in carrying out the mission of the contracts,” said Navy Vice Admiral Stephen Tedford, Director of the Defense Contract Management Agency. “DCMA will continue to ensure that contractors are fulfilling these obligations.” The settlement will resolve the allegations against LOGZONE, stating that it did not submit false or fraudulent claims for payment on two Navy contracts for which LOGZONE had not complied with the contracts’ cybersecurity requirements. The matter was handled by Fraud Section Trial Attorney Graham D. Welch and Assistant U.S. Attorney Don Long for the Northern District of Alabama. Click Here to Subscribe on YouTube: Watch the latest WAFF 48 news, sports & weather videos on our YouTube channel! Copyright 2026 WAFF. All rights reserved.

Alabama Defense Contractor Agrees to Pay $507144 to Resolve False Claims Act Liability ...

Press Release Alabama Defense Contractor Agrees to Pay $507,144 to Resolve False Claims Act Liability Relating to Cybersecurity Violations For Immediate Release Office of Public Affairs Defense contractor LOGZONE Inc. of Huntsville, Alabama has agreed to pay $507,144 to resolve its liability under the False Claims Act for knowingly failing to comply with cybersecurity requirements in contracts with the Department of the Navy. “Government contractors that obtain sensitive defense information in administering their contracts must follow required cybersecurity standards,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements in order to protect this critical information from external threats.” “The protection of sensitive defense information by government contractors is critical to national security,” said U.S. Attorney Phillip W. Williams Jr. for the Northern District of Alabama. “Adherence to the cybersecurity provisions of contracts with the federal government must be a priority for all contractors, and this enforcement action should serve as a reminder of that.” “The cybersecurity provisions of federal contracts are critical to protecting sensitive information that may be transmitted in carrying out the mission of the contracts,” said Navy Vice Admiral Stephen Tedford, Director of the Defense Contract Management Agency. “DCMA will continue to ensure that contractors are fulfilling these obligations.” The settlement resolves allegations under the False Claims Act that LOGZONE knowingly submitted false or fraudulent claims for payment on two Navy contracts for which LOGZONE had not complied with the contracts’ cybersecurity requirements. From May 2021 to March 2025, LOGZONE allegedly failed to implement certain cybersecurity controls in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 that, if not implemented, could lead to significant exploitation of the system or exfiltration of sensitive defense information. These issues were

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's machine, building a way back in that did not run through the C2 at all. When the Havoc server went offline the next day, his access did not. Eighteen days later, the C2 came back, his agents reconnected on their own, and he carried on. Cato Networks captured the whole operation command by command, 339 of them over 33 days, after the operator left his SSH keys and a step-by-step playbook in an open storage bucket. The write-up, published Tuesday by Cato CTRL researcher Vitaly Simonovich, is a rare view of an intrusion from the operator's keyboard rather than the forensic leftovers. Researchers' lesson is blunt: pulling a C2 server offline is not remediation if the attacker has already built a separate door. The actor, handle "Poisson," is not an APT. Researchers describe a junior operator on what looks like a school schedule, active after 3 p.m. CET with a long midday gap, all of it running on free-tier kit: DuckDNS, Backblaze B2, and a cheap IONOS VPS in Berlin. His tradecraft was thin. He leaked his home directory five times, named his storage buckets after his own handle, and left a test file of his own keystrokes typed over and over inside the keylogger package. He failed at roughly half of what he tried. He compromised four machines anyway. The chain The malware ran almost entirely in memory. A VBScript stager with a sandbox-evasion delay decrypted a PowerShell loader, which pulled down a .NET loader that ran Havoc's Demon agent without dropping the implant to disk. For elevation,