Category: Uncategorized

  • Trump’s big speech will be delivered to a changed nation and a Congress he has sidelined

    Trump’s big speech will be delivered to a changed nation and a Congress he has sidelined


    WASHINGTON (AP) — President Donald Trump will stand before Congress on Tuesday to deliver the annual State of the Union address to a suddenly transformed nation.

    One year back in office, Trump has emerged as a president defying conventional expectations. He has executed a head-spinning agenda, upending priorities at home, shattering alliances abroad and challenging the nation’s foundational system of checks and balances. Two Americans were killed by federal agents while protesting the Trump administration’s immigration raids and mass deportations.

    As the lawmakers sit in the House chamber listening to Trump’s agenda for the year ahead, the moment is an existential one for the Congress, which has essentially become sidelined by his expansive reach, the Republican president bypassing his slim GOP majority to amass enormous power for himself.

    “It’s crazy,” said Nancy Henderson Korpi, a retiree in northern Minnesota who joined an Indivisible protest group and plans to watch the speech from home. “But what is disturbing more to me is that Congress has essentially just handed over their power.”

    She said, “We could make some sound decisions and changes if Congress would do their job.”

    The state of the union is upheaval

    The country is at a crossroads, celebrating its 250th anniversary while experiencing some of the most significant changes to its politics, policies and general mood in many Americans’ lifetimes.

    The president muscled his agenda through Congress when he needed to — often pressuring lawmakers with a phone call during cliffhanger votes — but more often avoided the messy give-and-take of the legislative process to power past his own party and the often unified Democratic opposition.

    Trump’s signature legislative accomplishment so far is the GOP’s big tax cuts bill, with its new savings accounts for babies, no taxes on tips and other specialty deductions, and steep cuts to Medicaid and SNAP food aid. It also fueled more than $170 billion to Homeland Security for his immigration deportations.

    But the GOP-led Congress has largely stood by as Trump dramatically seized power through hundreds of executive actions, many being challenged in court, and a willingness to do whatever it takes to impose his agenda.

    “Retrieving a lost power is no easy business in our constitutional order,” wrote Justice Neil Gorsuch in the Supreme Court’s landmark rebuke of Trump’s tariffs policy on Friday.

    Gorsuch said that without the court stepping in on major questions, “Our system of separated powers and checks-and-balances threatens to give way to the continual and permanent accretion of power in the hands of one man.”

    Trump goes it alone, with or without Congress

    From slashing the federal workforce to upending the childhood vaccine schedule to attacking Venezuela and capturing that country’s president, Trump’s reach appeared to know no bounds.

    His administration launched investigations of would-be political foes, imposed his name on historic buildings, including the storied John F. Kennedy Center for the Performing Arts, and perhaps most visibly has been rounding up people and converting warehouses into detention holding centers for deportations.

    At almost every step of the way, there were moments when Congress could have intervened but did not.

    Democrats, in the minority, often tried to push back, including by halting routine Homeland Security funds unless there are restraints on the immigration actions.

    But Republicans believe the country elected the president and gave their party control of Congress to align with his agenda, according to one senior GOP leadership aide who insisted on anonymity to discuss the dynamic.

    House Speaker Mike Johnson of Louisiana has said Trump will be the “most consequential” president of the modern era.

    Democrats plan to either boycott the speech or sit in stony silence.

    “The state of the union is falling apart,” said House Democratic Leader Hakeem Jeffries of New York.

    Congress asserts itself, at times

    There have been times when Congress held its own against the White House, but they have been rare — as in the high-profile bipartisan push from Reps. Thomas Massie, R-Ky., and Rep. Ro Khanna, D-Ca., to force the release of the Jeffrey Epstein files, over the objections of Johnson and GOP leadership.

    The flex of congressional power has more often come from a few renegade Republicans joining with most Democrats to put a check on the president, as when the House voted to block Trump’s tariffs on Canada. The Senate advanced a war powers resolution to prevent military action in Venezuela without congressional approval, but backed off after Trump intervened.

    Those have been mostly symbolic votes, because Congress would not have the numbers to overcome any expected Trump veto.

    More often, the Congress has accommodated Trump, by rolling back already approved bipartisan funding for USAID foreign aid or public broadcasting or failing to stop the U.S. military strikes on alleged drug-smuggling boats that killed two survivors in the Caribbean. When Trump issued a Day One pardon of some 1,500 people charged in the Jan. 6, 2021 attack on the Capitol, the Republicans in Congress did not object.

    And as Trump’s Department of Government Efficiency with billionaire Elon Musk started firing federal workers, GOP lawmakers signaled approval by forming their own DOGE caucus on Capitol Hill.

    “The central question for us is does the public understand what’s at stake” said Max Stier, CEO of the Partnership for Public Service, a nonprofit organization focused on government management and democracy. “We are in the midst of the most significant transformation of our government and our public servants in our history as a country.”

    He said some 300,000 federal employees were fired or moved on, while 100,000 new hires or rehires have largely gone to Homeland Security.

    Checks and balances are being challenged

    In courtrooms across the country, cases are being filed against the administration at record levels, as Congress was “asleep at the wheel,” said Skye Perryman, president of Democracy Forward, which has filed more than 150 cases against the administration, part of the largest legal effort against an executive branch in U.S. history.

    But the judicial system has been under strain, and the White House has not always abided by court rulings. GOP lawmakers have joined Trump’s criticism of the courts, displaying outside their offices posters of judges they want to impeach.

    A next big test will be over a proof-of-citizenship voting bill that Trump wants ahead of the midterm elections.

    The House has passed the SAVE America Act, which would require birth certificates or passports to register to vote in federal elections and a photo ID at the polls. Supporters say it’s needed to crack down on fraud, while critics argue it will shut millions of Americans out of voting because they don’t have citizenship documents readily available.

    The Senate has a majority to pass the measure but not the necessary 60 votes to overcome an expected Democratic-led filibuster.

    Trump has vowed executive actions if Congress fails to approve legislation.

    ___

    Follow the AP’s coverage of President Donald Trump at https://apnews.com/hub/donald-trump.



    Source link

  • Winter storm covers parts north-east US in snow

    Winter storm covers parts north-east US in snow


    Footage shows snow covering parts of the US as an intense winter storm hits multiple US states including Connecticut and New Jersey.

    A full travel ban has been in place in New York City from 21:00 local time (02:00 GMT) on Sunday to 12:00 local time (17:00 GMT) on Monday.

    Mayor Zohran Mamdani said schools will be closed and all streets, highways and bridges will be shut to traffic – besides for emergencies.

    It is expected to be the most powerful nor’easter storm in nearly a decade for much of the region, bringing snow, fierce winds and coastal flooding.



    Source link

  • Under the Hood of DynoWiper, (Thu, Feb 19th)

    Under the Hood of DynoWiper, (Thu, Feb 19th)


    [This is a Guest Diary contributed by John Moutos]

    Overview

    In this post, I'm going over my analysis of DynoWiper, a wiper family that was discovered during attacks against Polish energy companies in late December of 2025. ESET Research [1] and CERT Polska [2] have linked the activity and supporting malware to infrastructure and tradecraft associated with Russian state-aligned threat actors, with ESET assessing the campaign as consistent with operations attributed to Russian APT Sandworm [3], who are notorious for attacking Ukrainian companies and infrastructure, with major incidents spanning throughout years 2015, 2016, 2017, 2018, and 2022. For more insight into Sandworm or the chain of compromise leading up to the deployment of DynoWiper, ESET and CERT Polska published their findings in great detail, and I highly recommend reading them for context.

    IOCs

    The sample analyzed in this post is a 32-bit Windows executable, and is version A of DynoWiper.

    SHA-256 835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5 [4]

    Initial Inspection

    To start, I ran the binary straight through DIE [5] (Detect It Easy) catch any quick wins regarding packing or obfuscation, but this sample does not appear to utilize either (unsurprising for wiper malware). To IDA [6] we go!

    Figure 1: Detect it Easy

    Figure 1: Detect It Easy

    PRNG Setup

    Jumping right past the CRT setup to the WinMain function, DynoWiper first initializes a Mersenne Twister PRNG (MT19937) context, with the fixed seed value of 5489 and a state size of 624.

    Figure 2: Main Function

    Figure 2: Main Function
     

    Figure 3: Mersenne Twister Init

    Figure 3: Mersenne Twister Init

    The MT19937 state is then re-seeded and reinitialized with a random value generated using std::random_device, the 624 word state is rebuilt, and a 16-byte value is generated.

    Figure 4: Mersenne Twister Seed

    Figure 4: Mersenne Twister Seed

    Data Corruption

    Immediately following the PRNG setup, the data corruption logic is executed.

    Figure 5: Data Corruption Logic

    Figure 5: Data Corruption Logic

    Drives attached to the target host are enumerated with GetLogicalDrives(), and GetDriveTypeW() is used to identify the drive type, to ensure only fixed or removable drives are added to the target drive vector.

    Figure 6: Drive Enumeration

    Figure 6: Drive Enumeration

    Directories and files on said target drives are walked recursively using FindFirstFileW() and FindNextFileW(), while skipping the following protected / OS directories to avoid instability during the corruption process.

    Excluded Directories
    system32
    windows
    program files
    program files(x86)
    temp
    recycle.bin
    $recycle.bin
    boot
    perflogs
    appdata
    documents and settings

    Figure 7: Directory Traversal (1)

    Figure 8: Directory Traversal (2)

    Figures 7-8: Directory Traversal

    For each applicable file, attributes are cleared with SetFileAttributesW(), and a handle to the file is created using CreateFileW(). The file size is obtained using GetFileSize(), and the start of the file located through SetFilePointerEx(). A 16 byte junk data buffer derived from the PRNG context is written to the start of the file using WriteFile(). In cases where the file size exceeds 16 bytes, pseudo-random locations throughout the file are generated, with the count determined by the file size, and a maximum count of 4096. The current file pointer is again repositioned to each generated location with SetFilePointerEx(), and the same 16 byte data buffer is written again, continuing the file corruption process.

    Figure 9: Random File Offset Generation

    Figure 9: Random File Offset Generation

    Figure 10: File Corruption

    Figure 10: File Corruption

    Data Deletion

    With all the target files damaged and the data corruption process complete, the data deletion process begins

    Figure 11: Data Deletion Logic

    Figure 11: Data Deletion Logic

    Similar to the file corruption process, drives attached to the target host are enumerated, target directories are walked recursively and target files are removed with DeleteFileW() instead of writing junk data, as seen in the file corruption logic

    Figure 12: File Deletion

    Figure 12: File Deletion

    To finish, the wiper obtains its own process token using OpenProcessToken(), enables SeShutdownPrivilege through AdjustTokenPrivileges(), and issues a system reboot with ExitWindowsEx().

    Figure 13: Token Modification and Shutdown

    Figure 13: Token Modification and Shutdown

    MITRE ATT&CK Mapping

    • Discovery (TA0007)
      • T1680: Local Storage Discovery
      • T1083: File and Directory Discovery 
    • Defense Evasion (TA0005)
      • T1222: File and Directory Permissions Modification
        • T1222.001: Windows File and Directory Permissions Modification
      • T1134: Access Token Manipulation
    • Privilege Escalation (TA0004)
      • T1134: Access Token Manipulation
    • Impact (TA0040) 
      • T1485: Data Destruction
      • T1529: System Shutdown/Reboot

    References

    [1] https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/
    [2] https://cert.pl/uploads/docs/CERT_Polska_Energy_Sector_Incident_Report_2025.pdf
    [3] https://www.welivesecurity.com/2022/03/21/sandworm-tale-disruption-told-anew
    [4] https://www.virustotal.com/gui/file/835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5
    [5] https://github.com/horsicq/Detect-It-Easy
    [6] https://hex-rays.com

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.



    Source link