DefScoop The Marine Corps received its 359th MV-22B Osprey on Tuesday, marking the completion of the tiltrotor’s program of record
Air Force Must Fix Fleet Age, Size, Readiness Issues, Undersecretary Says
NDM Air Force Undersecretary Matthew Lohmeier during a keynote speech July 27 gave a blunt assessment of the service’s current state, calling it “older, smaller and less ready than it needs…
Pentagon Unveils New Agreements for Patriot, THAAD Production
Aviation Week The Pentagon on July 27 announced another new agreement with key companies to expand munition production
Contrast CVE Shield aims to protect applications while security teams deploy patches
Contrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects…
Fincantieri profit triples in first half as backlog nears $74bn
Italian shipbuilder logs record profit on back of orders stretching out to 2039
CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the FBI, and international partners, has released new joint guidance titled “CI Fortify – Advice for Isolating Vital Systems.” T…
In 2018, an undocumented migrant scaled a Paris apartment building to save a four-year-old boy hanging from a fourth-floor balcony, earning the nickname ‘Spider-Man of Paris’
Mamadou Gassama, an African migrant, rescued a child hanging from a Paris balcony. His brave actions led to him being honoured by the French president. Gassama received French citizenship and an internship with firefighters. This incident brought Gas…
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirming the models responsible didn’t just wander into Hugging Face’s systems. They […]
Iraq eyes supplying Turkey with 1 million oil barrels a day amid Hormuz crisis
Iraqi Prime Minister Ali Zeydi visited Ankara for his first talks with Erdoğan since taking office, offering to supply Turkey with 1 million barrels of oil per day as Ankara seeks to reduce its dependence on disrupted Gulf routes.
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence.
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.
The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them…