๐ค Anthropic still flagged as risk to defense industrial base, US official says
A U.S. defense official says Anthropic remains designated a โSupply Chain Riskโ at the Department of Defense and across the wider defense industrial base. The statement directly rejects claims of easing tensions between the AI company and the administration.
For defense procurement and trusted-tech screening, the designation matters more than public messaging. A standing supply-chain risk flag can shape vendor access, partnership decisions, and integration pathways across contractors handling sensitive programs.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
A U.S. defense official says Anthropic remains designated a โSupply Chain Riskโ at the Department of Defense and across the wider defense industrial base. The statement directly rejects claims of easing tensions between the AI company and the administration.
For defense procurement and trusted-tech screening, the designation matters more than public messaging. A standing supply-chain risk flag can shape vendor access, partnership decisions, and integration pathways across contractors handling sensitive programs.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ ICE exposed restricted data via Palantir app before vetting
ICE deportation officers reportedly received the ELITE app on issued phones as a standard tool, including hires whose background checks were still incomplete. The Palantir-built system aggregates addresses, criminal histories, immigration records, court data, and other personally identifiable information, while DHS has not published a dedicated privacy impact assessment for ELITE.
Operationally, this combines accelerated hiring with immediate access to a sensitive targeting platform. The reported gap is not only personnel vetting, but governance: a fielded AI-enabled enforcement tool handling broad personal data without the full privacy documentation normally meant to define oversight, safeguards, and accountability.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
ICE deportation officers reportedly received the ELITE app on issued phones as a standard tool, including hires whose background checks were still incomplete. The Palantir-built system aggregates addresses, criminal histories, immigration records, court data, and other personally identifiable information, while DHS has not published a dedicated privacy impact assessment for ELITE.
Operationally, this combines accelerated hiring with immediate access to a sensitive targeting platform. The reported gap is not only personnel vetting, but governance: a fielded AI-enabled enforcement tool handling broad personal data without the full privacy documentation normally meant to define oversight, safeguards, and accountability.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ก Air Force accelerates MQ-9 replacement after heavy wartime attrition
The U.S. Air Force is moving faster on the Massed Modular Aircraft program after losing 45 MQ-9A Reapers in Operation Epic Fury, roughly a quarter of the fleet by mid-August. Officials now want at least 180 lower-cost aircraft at about $10 million per air vehicle, using mature technology and accepting reduced performance and survivability to speed fielding.
The shift marks a clear move from small numbers of expensive ISR-strike drones toward attritable capacity. Cost per effect, production volume, and shorter service life are being prioritized over long-term sustainment, indicating combat losses have forced a reassessment of what is operationally replaceable at scale.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
The U.S. Air Force is moving faster on the Massed Modular Aircraft program after losing 45 MQ-9A Reapers in Operation Epic Fury, roughly a quarter of the fleet by mid-August. Officials now want at least 180 lower-cost aircraft at about $10 million per air vehicle, using mature technology and accepting reduced performance and survivability to speed fielding.
The shift marks a clear move from small numbers of expensive ISR-strike drones toward attritable capacity. Cost per effect, production volume, and shorter service life are being prioritized over long-term sustainment, indicating combat losses have forced a reassessment of what is operationally replaceable at scale.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ก U.S. Navy and Quad partners expand AI tracking of dark fleets in the Pacific
NIWC Pacific has awarded Vantor a contract to provide Maritime Sentry for Indo-Pacific maritime domain awareness. The system fuses satellite imagery, SAR, AIS data, and AI-based vessel fingerprinting to detect and track ships that disable, spoof, or never transmit identification signals. The effort will support U.S. and partner workflows, including Indian Navy systems and SeaVision.
The key shift is not just detection but integration: Vantorโs output will feed directly into existing operational platforms used across Quad-linked partners. That improves shared maritime picture-building across a vast theater where non-compliant shipping, sanctions evasion, and covert activity exploit AIS blind spots.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
NIWC Pacific has awarded Vantor a contract to provide Maritime Sentry for Indo-Pacific maritime domain awareness. The system fuses satellite imagery, SAR, AIS data, and AI-based vessel fingerprinting to detect and track ships that disable, spoof, or never transmit identification signals. The effort will support U.S. and partner workflows, including Indian Navy systems and SeaVision.
The key shift is not just detection but integration: Vantorโs output will feed directly into existing operational platforms used across Quad-linked partners. That improves shared maritime picture-building across a vast theater where non-compliant shipping, sanctions evasion, and covert activity exploit AIS blind spots.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ก US military turns off ad trackers on devices amid Middle East targeting reports
The U.S. military has disabled advertising trackers on a range of phones and computers after reports that commercially available location data was used to target American forces in the Middle East. The move surfaced through statements and letters tied to Senator Ron Wyden.
Operationally, this frames ad-tech telemetry as a direct force protection issue rather than a privacy concern alone. It also underlines how routine mobile and device data can become actionable targeting intelligence when aggregated, sold, and matched against military patterns.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
The U.S. military has disabled advertising trackers on a range of phones and computers after reports that commercially available location data was used to target American forces in the Middle East. The move surfaced through statements and letters tied to Senator Ron Wyden.
Operationally, this frames ad-tech telemetry as a direct force protection issue rather than a privacy concern alone. It also underlines how routine mobile and device data can become actionable targeting intelligence when aggregated, sold, and matched against military patterns.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ก Textron expands Navy contractor-run ISR support in the Pacific
Textron Systems received two NAVAIR task orders for contractor-owned, contractor-operated drone ISR services supporting the 7th Fleet and other U.S. forces. The awards, dated Aug. 24 and Aug. 31, carry ceiling values of about $43 million and $42 million over up to five years. The task orders cover Maritime B-Kits providing continuous sensor data and full-motion video, with up to 175 sensor data hours per month.
The move increases maritime ISR capacity without adding Navy-owned airframes or lifecycle burden. Textron says it will use the VTOL Aerosonde Mk. 4.7, aligning with prior Navy demand for runway-independent systems able to operate in austere, adverse-weather and GPS-degraded conditions.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Textron Systems received two NAVAIR task orders for contractor-owned, contractor-operated drone ISR services supporting the 7th Fleet and other U.S. forces. The awards, dated Aug. 24 and Aug. 31, carry ceiling values of about $43 million and $42 million over up to five years. The task orders cover Maritime B-Kits providing continuous sensor data and full-motion video, with up to 175 sensor data hours per month.
The move increases maritime ISR capacity without adding Navy-owned airframes or lifecycle burden. Textron says it will use the VTOL Aerosonde Mk. 4.7, aligning with prior Navy demand for runway-independent systems able to operate in austere, adverse-weather and GPS-degraded conditions.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ UK launches Project PANOPTES for autonomous anti-drone laser defense
The UK Ministry of Defence has opened Project PANOPTES, a ยฃ5 million competition for a vehicle-mounted counter-UAS system able to detect, track, and defeat NATO Class 1 drones autonomously. The requirement explicitly includes repeated, sequential, and simultaneous attacks, with laser directed-energy weapons identified as the preferred effector. First-stage submissions close on 23 September.
The tender shows UK planning is shifting from trials toward fieldable protection against low-cost saturation attacks that can drain conventional interceptors. The emphasis on autonomy, mobility, and non-depleting engagement capacity points to force protection as the immediate priority.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
The UK Ministry of Defence has opened Project PANOPTES, a ยฃ5 million competition for a vehicle-mounted counter-UAS system able to detect, track, and defeat NATO Class 1 drones autonomously. The requirement explicitly includes repeated, sequential, and simultaneous attacks, with laser directed-energy weapons identified as the preferred effector. First-stage submissions close on 23 September.
The tender shows UK planning is shifting from trials toward fieldable protection against low-cost saturation attacks that can drain conventional interceptors. The emphasis on autonomy, mobility, and non-depleting engagement capacity points to force protection as the immediate priority.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Ted Backdoor Patches HAProxy to Intercept Traffic
A newly described implant dubbed Ted is designed to hide inside a victimโs own HAProxy build, giving operators a stealthy position inside the web traffic path. The malware modifies the proxy binary rather than deploying as a separate process, allowing interception within routine application delivery workflows detailed in HAProxy builds already trusted in production.
The tradecraft matters because it shifts detection away from conventional process hunting toward binary integrity checks, build-pipeline validation, and proxy-level telemetry. Any compromise at this layer can expose session data and application traffic while blending into normal load-balancing infrastructure.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
A newly described implant dubbed Ted is designed to hide inside a victimโs own HAProxy build, giving operators a stealthy position inside the web traffic path. The malware modifies the proxy binary rather than deploying as a separate process, allowing interception within routine application delivery workflows detailed in HAProxy builds already trusted in production.
The tradecraft matters because it shifts detection away from conventional process hunting toward binary integrity checks, build-pipeline validation, and proxy-level telemetry. Any compromise at this layer can expose session data and application traffic while blending into normal load-balancing infrastructure.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ CrowdStrike 'FalconFlank' zero-day enables SYSTEM privilege escalation
An exploit dubbed FalconFlank was released by the researcher Nightmare Eclipse, targeting CrowdStrike Falcon on fully updated Windows 11 25H2 and Windows Server 2025 systems. The flaw reportedly abuses Falcon's Office malicious macros remediation path to spawn a command prompt with SYSTEM privileges. CrowdStrike said it is investigating and advised customers to disable the Microsoft Office File Suspicious Macro Removal policy setting.
The issue is significant because it turns a defensive control inside endpoint security software into a local privilege escalation path on current builds. Until a public advisory, CVE, or patch is available, mitigation guidance is limited to configuration changes rather than a vendor fix.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
An exploit dubbed FalconFlank was released by the researcher Nightmare Eclipse, targeting CrowdStrike Falcon on fully updated Windows 11 25H2 and Windows Server 2025 systems. The flaw reportedly abuses Falcon's Office malicious macros remediation path to spawn a command prompt with SYSTEM privileges. CrowdStrike said it is investigating and advised customers to disable the Microsoft Office File Suspicious Macro Removal policy setting.
The issue is significant because it turns a defensive control inside endpoint security software into a local privilege escalation path on current builds. Until a public advisory, CVE, or patch is available, mitigation guidance is limited to configuration changes rather than a vendor fix.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ PostgreSQL flaw enables low-privilege server takeover
PostgreSQL has patched CVE-2026-6471, a flaw present since 2014 that allows accounts with REPLICATION privilege to load arbitrary files via logical decoding plugins and execute code as the database service account. Affected branches include 9.4 through 18, with fixes issued in 18.6, 17.11, 16.15, 15.19, and 14.24.
The issue turns routine replication access used by backup, monitoring, and data pipeline tooling into a direct path to persistent PostgreSQL superuser control and underlying host compromise across Windows, Linux, and macOS. Immediate patching and review of all replication-enabled accounts are now a priority.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
PostgreSQL has patched CVE-2026-6471, a flaw present since 2014 that allows accounts with REPLICATION privilege to load arbitrary files via logical decoding plugins and execute code as the database service account. Affected branches include 9.4 through 18, with fixes issued in 18.6, 17.11, 16.15, 15.19, and 14.24.
The issue turns routine replication access used by backup, monitoring, and data pipeline tooling into a direct path to persistent PostgreSQL superuser control and underlying host compromise across Windows, Linux, and macOS. Immediate patching and review of all replication-enabled accounts are now a priority.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ CISA flags exploited Chromium V8 flaw in KEV
U.S. CISA has added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog after Google confirmed in-the-wild exploitation. The type confusion bug in Chromiumโs V8 engine affects JavaScript and WebAssembly handling and can allow arbitrary code execution inside the browser sandbox via a crafted HTML page. Federal agencies have until 18 September 2026 to remediate.
The KEV addition formalizes the flaw as an active enterprise risk, not just a browser patching issue. It is the sixth exploited Chrome zero-day disclosed by Google in 2026, reinforcing V8 as a recurring attack surface with direct exposure through routine web content.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
U.S. CISA has added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog after Google confirmed in-the-wild exploitation. The type confusion bug in Chromiumโs V8 engine affects JavaScript and WebAssembly handling and can allow arbitrary code execution inside the browser sandbox via a crafted HTML page. Federal agencies have until 18 September 2026 to remediate.
The KEV addition formalizes the flaw as an active enterprise risk, not just a browser patching issue. It is the sixth exploited Chrome zero-day disclosed by Google in 2026, reinforcing V8 as a recurring attack surface with direct exposure through routine web content.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Phishing campaign uses invisible Unicode to scale filter evasion
A newly tracked phishing campaign is sending millions of emails that embed invisible Unicode characters to bypass content filters and detection logic. The technique alters message text without visibly changing it for recipients, allowing payloads and lures to pass through systems that rely on standard string matching.
The operational value is straightforward: a low-visibility modification at text level can degrade email security controls at scale without changing user-facing content. For defenders, this highlights a gap between human-readable inspection and machine parsing in mail filtering pipelines.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
A newly tracked phishing campaign is sending millions of emails that embed invisible Unicode characters to bypass content filters and detection logic. The technique alters message text without visibly changing it for recipients, allowing payloads and lures to pass through systems that rely on standard string matching.
The operational value is straightforward: a low-visibility modification at text level can degrade email security controls at scale without changing user-facing content. For defenders, this highlights a gap between human-readable inspection and machine parsing in mail filtering pipelines.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Congress presses DoD over troop tracking via commercial location data
US lawmakers Ron Wyden and Pat Harrigan have asked the DoD Inspector General to examine why commercially sold mobile location data can still expose US military movements. The Army, Navy, Air Force, Marine Corps, and SOCOM say ad identifiers are now disabled on government devices, but a DoD investigation request says data tied to DoD facilities remains available.
That suggests the exposure may now sit with personal devices, app SDK collection, or newer tracking methods beyond ad IDs, leaving force protection at risk despite branch-level policy changes.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
US lawmakers Ron Wyden and Pat Harrigan have asked the DoD Inspector General to examine why commercially sold mobile location data can still expose US military movements. The Army, Navy, Air Force, Marine Corps, and SOCOM say ad identifiers are now disabled on government devices, but a DoD investigation request says data tied to DoD facilities remains available.
That suggests the exposure may now sit with personal devices, app SDK collection, or newer tracking methods beyond ad IDs, leaving force protection at risk despite branch-level policy changes.
๐ฐ๏ธ Open sources - closed narratives
@sitreports