Jen.Jiji GSDF Member Brings Malware-Infected USB to Headquarters
Article Content
- •A malware-infected USB was brought into GSDF headquarters by a service member.
- •The USB had been in use since April 2024 for official work related to a natural disaster.
- •GSDF prohibits personal devices, raising questions about compliance and security protocols.
Japan's Ground Self-Defense Force (GSDF) reported that a service member brought a malware-infected USB memory stick into its Middle Army headquarters. The GSDF is currently investigating how the USB stick was obtained, as it had been in use since April 2024 for tasks related to the January 2024 Noto Peninsula earthquake. The malware was detected in February 2025, raising concerns about the security protocols surrounding personal devices. The GSDF has strict regulations prohibiting the use of personal USB drives, managing officially procured devices through a registry. The incident highlights potential vulnerabilities in the GSDF's cybersecurity measures and device management practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ground Self-Defense Force in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…