BOISE, Idaho, May 21, 2025 (GLOBE NEWSWIRE) — Micron Technology, Inc. (Nasdaq: MU) announced today that it will hold its fiscal third quarter earnings conference call on Wednesday, June 25, 2025, at 2:30 p.m. Mountain time.
The call will be webcast live at http://investors.micron.com/. Webcast replays of presentations can be accessed from Micron’s Investor Relations website for approximately one year after the call.
About Micron Technology, Inc. We are an industry leader in innovative memory and storage solutions transforming how the world uses information to enrich life for all. With a relentless focus on our customers, technology leadership, and manufacturing and operational excellence, Micron delivers a rich portfolio of high-performance DRAM, NAND and NOR memory and storage products through our Micron® and Crucial® brands. Every day, the innovations that our people create fuel the data economy, enabling advances in artificial intelligence (AI) and compute-intensive applications that unleash opportunities — from the data center to the intelligent edge and across the client and mobile user experience. To learn more about Micron Technology, Inc. (Nasdaq: MU), visit micron.com.
Source: Independent Petroleum Association of America
Headline: IPAA Urges Preservation of Carried Interest Tax Provision
May 21, 2025 IPAA Urges Preservation of Carried Interest Tax Provision
Dear Speaker Johnson and Majority Leader Thune:
On behalf of America’s independent oil and natural gas producers, the Independent Petroleum Association of America (IPAA) urges you to help preserve the current tax treatment of carried interest to protect energy investment, support job creation, and ensure the continued growth of a resilient, domestically powered energy economy. …
The carried interest structure is a well-established mechanism that rewards long-term investment and risk-taking. It is particularly critical in the oil and natural gas industry, where smaller, independent companies often partner with private equity investors to raise the capital needed to explore, drill, and produce America’s energy resources. Nowhereisthismodelmoreembedded-or morevital-thanintheGulfCoast states,wherethesepartnerships driveinnovation, economic growth,andenergyresilience. …
A “health financing emergency” must drive country-led, data-driven solutions
Ministers from multiple countries hit by the abrupt cuts in external funding for health agreed on the urgent need for country-owned and implemented strategies – and a laser-sharp focus on health data – at a ministerial dialogue co-hosted by WHO and the Susan Thompson Buffett Foundation at the Seventy-eighth World Health Assembly.
Opening remarks by Professor Senait Fisseha, Vice President of Global Programs at the Susan Thompson Buffett Foundation, and Dr Tedros Adhanom Ghebreyesus, WHO Director-General, set the tone by noting that the crisis presents an opportunity for a turnaround in how health financing policies and health data systems are built and operated.
Specifically, this is a time for countries to reduce their reliance on external health information systems and external financing; build out their domestic data infrastructure, from vital statistics to downstream impact and return-on-investment; and establish resilient systems designed to withstand shocks, so that access to essential services is protected.
Professor Fisseha called on countries “to use this moment to rethink data and financing in a way that best meets your needs and the needs of your people […] For countries to truly lead and for funders and development partners to start to learn how to follow. Data and financing are a natural place to start because that is where ministers are telling us to start.”
Dr Tedros said, “From expanding domestic financing to pioneering real-time data systems, many of you are advancing solutions that are scalable, sustainable and rooted in equity. Data and sustainable financing are not just technical matters. They are political choices. They shape who is reached, how quickly, and with what quality of care. And they determine whether we progress or fall behind.”
Ministers from Barbados, Central African Republic, Egypt, Liberia, Malawi, Rwanda and Sierra Leone, and representatives from the African Union and the World Bank, among others, shared experiences and advice on concrete actions to strengthen data systems, health financing and planning – urging intensified collaboration in the future. They also spoke of the need to leverage the digital transformation and thereby increase transparency and accountability.
Also discussed: strategies to improve domestic financing capacity while maximizing impact include: strengthening tax administration; exploring revenue sources such as taxes on such items as food, alcohol and tobacco; setting up population-wide mandatory health coverage schemes, coupled with subsidies for low-income households and vulnerable population groups; promoting strategic purchasing of health supplies; prioritizing health in public spending; and integrating externally-funded programmes into domestic financing systems and priorities.
Later this week the Assembly will take up the proposed WHA Health Financing Resolution.
Report on the health conditions in the occupied Palestinian territory, including east Jerusalem, and in the occupied Syrian Golan
On 21 May 2025, the Seventy-eighth World Health Assembly noted a report from the Director-General, outlining WHO’s humanitarian and emergency health response in the occupied Palestinian territory, including east Jerusalem, and in the occupied Syrian Golan, from January 2024 to February 2025.
A report on the health conditions in the occupied Syrian Golan couldn’t be provided this year again due to the ongoing situation and the lack of disaggregated health data on the Syrian population. Member States were invited to provide guidance on how to support WHO and partners to restore essential health services across Syria and enable a WHO field-assessment mission to the occupied Syrian Golan.
Member States expressed grave concerns over the deterioration of the health system in Gaza, including forced displacement, overcrowding and deteriorating sanitation, and attacks on health, stressing the need for concerted action to address the dire health needs.
A number of Member States presented draft decisions asking the Director-General to continue reporting on the health conditions in the occupied Palestinian territory, including east Jerusalem, and in the occupied Syrian Golan, and more specifically on food insecurity and malnutrition in the Gaza Strip, and to continue supporting the Palestinian and Syrian health systems. The decision was adopted.
Related documents
A78/16: Health conditions in the occupied Palestinian territory, including east Jerusalem, and in the occupied Syrian Golan
A78/B/CONF./1: Health conditions in the occupied Palestinian territory, including east Jerusalem, and in the occupied Syrian Golan
A78/B/CONF./1 Add.1: Financial and administrative implications for the Secretariat of decisions proposed for adoption by the Health Assembly
Source: United States Senator for Arkansas Tom Cotton
FOR IMMEDIATE RELEASE Contact: Caroline Tabler or Patrick McCann (202) 224-2353 May 21, 2025
Cotton Introduces Bill to Make Food Inspection Safe and More Efficient
Washington, D.C. — Senator Tom Cotton (R-Arkansas) today introduced the Study And Framework for Efficiency in Food Oversight and Organizational Design (SAFE FOOD) Act, legislation that would direct the Department of Agriculture to conduct a study on the consolidation of federal agencies that have a primary role in ensuring food safety into a single agency.
“Current food safety oversight is spread across multiple federal, state, and local agencies which decreases efficacy, creates gaps, and slows response times to potential public health risks. My bill is a commonsense step to expanding government efficiency and enhancing public health protection by unifying our food safety agencies,” said Senator Cotton.
Full text of the bill may be found here.
The SAFE FOOD Act would:
Direct the USDA to conduct a study on the consolidation of federal food safety agencies into a single agency.
Restructure the federal food safety system to enhance public health protections through a more unified and efficient system.
Provide Congress necessary recommendations to improve American food safety.
Source: United States Senator MarkWayne Mullin (R-Oklahoma)
ICYMI: Mullin Tells Hannity: “Trump is putting a cast together that is going to Make America Great Again.”
“The good thing is we got a leader in President Trump that has truly put a cabinet in place that not only can deliver what the American people want, they can also defend themselves along the way.”
Washington, D.C. – On Tuesday, U.S. Senator Markwayne Mullin (R-OK) joined Fox News’s Sean Hannity on Hannity to discuss the Trump administration’s efforts to slash government waste, fraud, and abuse, and the recent liberal tirades against Secretary of State Marco Rubio, and Health and Human Services Secretary Robert F. Kennedy, in congressional hearings. Highlights below.
Sen. Mullin’s full interview can be found here.
On how department secretaries are cutting absurd amounts of government spending:
“The State Department’s budget has doubled in the last four years. Literally, it was $41 billion it’s nearly $82 billion today. And is the country and the world safer because we invested in DEI [Diversity, Equity, and Inclusion]? Because $73 million through that budget went directly to DEI stuff. And so, if you’re going to really try to defend what you spent your money on, you can’t…
“That’s why they were upset, because Marco Rubio and JFK [sic] are trying to truly cut spending, and that’s what—or RFK I’m sorry—they’re truly trying to cut spending, and they are going to do it. You just talk about HHS, where Bobby’s trying to actually cut spending too, their budget is $1.67 trillion. Now that is more than the sixth largest country in the world. That’s bigger than their entire budget $1.67 trillion and what have we got? An increase in the last four years by 38% and we are no closer to solving any chronic diseases than we were four years ago, and this is what they’re pushing back on.”
On how Democrats are losing their minds at the idea of cutting waste, fraud, and abuse:
“The Democrats are truly losing their ever-loving mind over it and saying that we’re making children sicker, and that we’re killing children around the world because we’re cutting DEI funding. It’s indefensible by the Democrats and I’m glad to see RFK and Marco go right back at them and put them in their place.”
On the all-star team of cabinet officials President Trump has built:
“The good thing is we got a leader in President Trump that has truly put a cabinet in place that not only can deliver what the American people want, they can also defend themselves along the way. And this is why President Trump said he’s putting a cast together that is going to Make America Great Again.”
Source: United States House of Representatives – Congressman Randy Weber (14th District of Texas)
Rep. Weber Announces $138 Million in Army Corps Funding for Southeast Texas Projects
Washington, May 16, 2025
Washington, D.C. – Today, U.S Rep. Randy Weber (TX-14) announced that Southeast Texas waterway projects will receive $138,380,000 in funding in the U.S. Army Corps of Engineers FY 2025 Army Civil Work Plan.
“This is great news for Southeast Texas, America’s energy capital,” said Rep. Weber. “Our ports and waterways are the lifeblood of our economy and keeping them well-maintained is critical to preserving our nation’s leadership in commerce and energy. I’m grateful the Trump administration recognizes the strategic importance of our region. I will continue fighting for the infrastructure investments our communities deserve.:
Operation & Maintenance projects in Texas’ 14th District were awarded:
$900,000 for the Channel to Port Bolivar. The Channel to Port Bolivar shallow-draft navigation project consists of a 14-foot deep by 200-foot wide channel that is 950 feet long. It extends from the entrance to Galveston Bay (Bolivar Roads) northward to the west point of Bolivar Island. The channel is heavily utilized by the Texas Department of Transportation and the Galveston-to-Port Bolivar Ferry System.
$13,150,000 for Freeport Harbor. The Freeport Harbor deep-draft navigation project consists of a 45-foot deep by 400-foot wide channel that is 8.5 miles long, extending from the Gulf of America, through a jetty-protected inlet, to a turning basin at the Freeport port facilities. The project also includes two rock jetties, 1.46 and 1.64 miles in length.
$47,975,000 for Galveston Harbor and Channel. The Galveston Entrance Channel is the main entrance for Galveston, Texas City, and the Houston Ship Channel. This deep-draft project includes a 45-foot deep by 800-foot wide channel that is 23.9 miles long, stretching from the Gulf of America through a jetty-protected inlet into Galveston Bay, to the port facilities at Galveston Harbor.
$50,000 for Chocolate Bayou. The Chocolate Bayou navigation project is a shallow-draft waterway, 13 feet deep by 125 feet wide and approximately 8.2 miles long. It extends from the Gulf Intracoastal Waterway (GIWW) at Mile Marker 376 through Chocolate Bay and Chocolate Bayou to port facilities located between Galveston and Freeport in Brazoria County, Texas.
$40,550,000 for the Gulf Intracoastal Waterway. The Texas portion of the GIWW extends from the Sabine River to Port Isabel, Texas, and includes several tributary channels. It features a 12-foot deep by 125-foot wide, shallow-draft channel stretching 423 miles along the Texas Coast. The GIWW includes flood gates at the Brazos River and navigation locks at the Colorado River, along with mooring basins and buoys at 11 locations supporting heavy barge traffic.
$25,075,000 for the Sabine-Neches Waterway. The Sabine-Neches Waterway (SNWW) is a federally constructed deep-draft navigation project serving the Ports of Port Arthur, Beaumont, and Orange in Jefferson and Orange Counties, Texas, and Cameron and Calcasieu Parishes, Louisiana. The waterway includes 97 miles of navigation channels in three main segments: a jetty-protected entrance channel 42 feet deep and 500 to 800 feet wide; a 40-foot deep, 400-foot wide channel to Beaumont via the Neches River; and a 30-foot deep, 200-foot wide channel to Orange via the Sabine River.
$10,680,000 for the Texas City Ship Channel. The Texas City Ship Channel deep-draft navigation project includes a 45-foot deep by 400-foot wide and 9.4-mile-long channel, extending from the intersection of Galveston Harbor and the Houston Ship Channel to a turning basin and Industrial Canal at the Port of Texas City.
Rep. Weber added: “This is not just about dredging or infrastructure—it’s about jobs, national security, and Texas leading the way. I will always stand up for the hardworking men and women who rely on these waterways to fuel our economy and keep America strong.”
Source: United States House of Representatives – Congressman Jared Huffman Representing the 2nd District of California
May 21, 2025
Washington, D.C. – Today, Congressional Freethought Caucus Co-Chairs Jared Huffman (CA-02) and Jamie Raskin (MD-08) released the following statement regarding House Republicans’ plan to divert billions of dollars in public funds to private, religious schools through a voucher tax giveaway in the new reconciliation package:
“Republicans once again are showing the American people where their priorities lie: with the wealthy and well-connected, rather than with working families —especially rural families. Buried in their reconciliation package is a deeply harmful proposal— the Educational Choice for Children Act (ECCA)—which would create a completely new dollar-for-dollar tax credit and corporate stock windfall scheme—for individuals and corporations that funnel money to organizations providing scholarships or vouchers for private or religious K-12 schools.
“Pulled directly from the Project 2025 playbook, this policy move is a billion-dollar backdoor scheme to drain public resources from neighborhood schools to fund private institutions that aren’t required to provide a free and appropriate public education to all students. This bill would send federal funds to private and parochial institutions that are not required to follow basic standards of accountability, transparency, and nondiscrimination. These institutions can—and often do—exclude students, families, and staff based on religion, disability, gender identity, or sexual orientation. Using public dollars to support such discriminatory practices and sectarian instruction is a clear violation of the separation of church and state. It’s a gift-wrapped tax break for the wealthy masqueraded as education policy.
“When given the opportunity to vote on these schemes, voters from Colorado and Kentucky to ruby-red Nebraska rejected voucher programs. Voucher programs do not improve students’ academic achievement, and they don’t offer real options for low-income or rural families who lack access to private schools. Taxpayer funds should serve the public good—not subsidize private institutions that serve only a select few.”
Source: US Department of Health and Human Services
Agency Will Begin Auditing All Eligible Medicare Advantage Contracts Each Payment Year and Add Resources to Expedite Completion of 2018 to 2024 Audits
Today, the Centers for Medicare & Medicaid Services (CMS) announced a significant expansion of its auditing efforts for Medicare Advantage (MA) plans. Beginning immediately, CMS will audit all eligible MA contracts for each payment year in all newly initiated audits and invest additional resources to expedite the completion of audits for payment years 2018 through 2024.
CASPER, Wyo. — The Wyoming Veterans Commission concluded its inaugural Veteran Services Symposium at Casper College, Casper, Wyoming, bringing together more than 150 service providers, advocates and leaders from across the state to strengthen the network of care for Wyoming’s veterans.
The event centered on working together and capacity-building, providing attendees with tools to better serve veterans and their families. The two-day agenda featured keynote presentations, workshops, and discussions on topics such as post-traumatic stress disorder and moral injury, grant writing, veteran caregiving, personality types in team dynamics, and even emerging risks related to artificial intelligence scams.
Wyoming Governor Mark Gordon joined the event to present six peer-nominated individuals and organizations with the prestigious “Excellence in Service to Veterans” award. The award recipients are as follows: Tami Dietz, Wyoming Military Department Soldier and Family Readiness; Todd Bray, DownRange Warriors; Scott O’Hare, Volunteers of America Northern Rockies; Darrell Haugen, Veterans’ Rock; Charlie & Jennifer Wilson, Soldiers House of Fremont County; Dr. John R. McPherson, D.D.S., P.C & Staff, McPherson Dental.
“These awards are about more than recognition—they’re a testament to the dedication of those who choose to stand beside our veterans every day,” Gordon said. “Wyoming owes a great debt to those who have served, and events like this are how we make sure we’re doing everything possible to support them.”
Sandy McFarland, Deputy Director of the Wyoming Veterans Commission and lead organizer of the event, said the symposium exceeded expectations and highlighted the collective will across Wyoming to do better for its veterans.
“This event was about moving from isolated effort to coordinated impact,” McFarland said. “We want to empower the people who serve veterans—whether they work for the VA, a nonprofit, or in a local community—to build partnerships that truly change lives.”
Among the sessions were presentations from Val Burgess, who shared the preserved voices and stories of World War II POWs from Stalag Luft III, and a workshop hosted by Ben Patton, founder of the Patton Veterans Project, which uses filmmaking as a method to reduce isolation for veterans coping with PTSD.
“The strength of this symposium was in the real stories,” said Tim Shepherd, Director of the Veterans Commission. “You couldn’t walk away from those sessions without a deeper understanding of what our veterans have endured—and how we can meet them where they are.”
The symposium concluded with a Veteran Resource Fair, where federal, state, and nonprofit partners came together for a one-stop-shop event providing VA benefit support, legal resources, mental health access and more.
Looking ahead, the Wyoming Veterans Commission intends to build on this momentum, making the Veteran Services Symposium an annual event.
“This is just the beginning,” McFarland added. “We are building a statewide movement rooted in empathy, coordination, and results. Veterans deserve nothing less.”
CHEYENNE, Wyo. – On May 10, 2025, the State of Wyoming paid tribute to its Veterans in a series of ceremonies as part of the annual Veterans Welcome Home Day.
Gov. Mark Gordon, U.S. Senator John Barrasso and U.S. Representative Harriet Hageman joined leaders from the Wyoming Military Department and the Wyoming Veterans Commission, traveled across the state to thank those who served—especially Veterans from the Korean and Vietnam Wars who were never properly welcomed home.
The daylong journey began at sunrise in Cheyenne and included four official ceremonies in Afton, Riverton, Sheridan and concluded in Wheatland. At each stop, the Governor, First Lady Jennie Gordon, Maj. Gen. Greg Porter, Adjutant General of Wyoming, and other dignitaries met with Veterans and their families, delivering remarks and expressing gratitude for their service.
Speaking to a room filled with Veterans and their loved ones, Porter reflected on the significance of the moment by connecting it to the broader legacy of American service. He reminded attendees that just weeks earlier, on April 19, the nation had observed the 250th anniversary of the “shot heard ‘round the world” at Lexington and Concord—an event that began a long lineage of Americans willing to fight for freedom.
“Over that time, America’s done a pretty good job of bringing its [servicemembers] home—with two exceptions: the Korean War and the Vietnam War,” Porter said. “Our Vietnam Veterans faced a far different return. They probably wished for an apathetic return. They faced derision, sarcasm, and hate in some cases—certainly disrespect. The purpose of these Welcome Home ceremonies is to take a moment to pause and recommit that we will never let that happen again as a nation.”
Gordon echoed that message, “This day is about saying, ‘Thank you for your service—welcome home.’ That gratitude extends to the families, too. Our Veterans carry a legacy that began with citizens who marched barefoot through snow because they believed in what this country stood for. In the military, we never leave anyone behind. As a nation, we should never leave a Veteran behind.”
As part of the ceremony, the official proclamation was read declaring March 30, 2025, as Wyoming Veterans Welcome Home Day, recognizing the moment in history when U.S. troops completed their withdrawal from Vietnam in 1973. The proclamation recounts how many Veterans returned to a country divided by politics and conflict, and how they were met not with honor—but with silence, scorn or worse.
“Members of the United States armed forces who served bravely and faithfully for the United States were caught in the crossfire of public debate about the involvement of the United States in the Vietnam War, and many were met with such disrespect that military leaders recommended Soldiers not wear their military uniforms as they returned home.”
The proclamation goes on to honor all Veterans, particularly those from the Korean and Vietnam Wars, and urges citizens to recognize their service “not just today but every day.”
After the speeches concluded, Governor Gordon took time to greet each Veteran in attendance, shaking hands and presenting a personalized challenge coin as a token of thanks.
Also present were Wyoming Veterans Commission Chairman Command Sgt. Maj. (Ret.) Ken Persson, Sr., and Director Col. (Ret.) Tim Sheppard, both of whom played key roles in organizing the day’s events and honoring those who once returned home without recognition.
As the day came to a close, the message that echoed from community to community was simple but profound: Wyoming remembers. Wyoming is grateful. And Wyoming will never forget.
For more information on Veterans Welcome Home Day or to learn about available resources for Veterans, contact the Wyoming Veterans Commission at (307) 777-8152.
Source: United States Bureau of Alcohol Tobacco Firearms and Explosives (ATF)
RICHMOND, Va. – A Richmond man was sentenced today to five years in prison for possession of a firearm by a convicted felon.
According to court documents, on March 16, 2023, Richmond Police detectives performed a traffic stop on a vehicle with no front license plate. James Marvin Smith, 43, was driving the vehicle. While speaking with Smith and a passenger, the detectives observed a crumpled lottery ticket near the cupholders and noticed that the passenger had white powder on his nose. The detectives asked Smith and the passenger to get out of the car.
While searching the vehicle for drug evidence, a detective found a firearm and a detached extended magazine. The firearm had one round of ammunition in the chamber and the magazine was loaded with 21 rounds of ammunition.
Prior to his arrest, Smith had been convicted of, among other crimes, possession of heroin, obstruction of justice, resisting arrest with force, possession of cocaine, breaking and entering, using a firearm in the commission of a felony, robbery, unlawful wounding, illegal possession of a firearm, assault and battery, possession of a firearm by a convicted violent felon, and grand larceny. As a previously convicted felon, Smith cannot legally possess a firearm or ammunition.
Erik S. Siebert, U.S. Attorney for the Eastern District of Virginia; Anthony A. Spotswood, Special Agent in Charge of the Bureau of Alcohol, Tobacco, Firearms and Explosives Washington Field Division; Rick Edwards, Chief of Richmond Police; and Colette Wallace McEachin, Commonwealth’s Attorney for the City of Richmond, made the announcement after sentencing by Senior U.S. District Judge John A. Gibney Jr.
Special Assistant U.S. Attorney Katherine E. Groover, an Assistant Commonwealth’s Attorney with the Richmond Commonwealth’s Attorney Office, prosecuted the case.
This case is part of Project Safe Neighborhoods (PSN), a program bringing together all levels of law enforcement and the communities they serve to reduce violent crime and gun violence, and to make our neighborhoods safer for everyone. On May 26, 2021, the Department launched a violent crime reduction strategy strengthening PSN based on these core principles: fostering trust and legitimacy in our communities, supporting community-based organizations that help prevent violence from occurring in the first place, setting focused and strategic enforcement priorities, and measuring the results.
A copy of this press release is located on the website of the U.S. Attorney’s Office for the Eastern District of Virginia. Related court documents and information are located on the website of the District Court for the Eastern District of Virginia or on PACER by searching for Case No. 3:24-cr-23.
Source: United States Bureau of Alcohol Tobacco Firearms and Explosives (ATF)
CHARLOTTE, N.C. – A man who used a privately made and unregistered firearm, commonly known as a “ghost gun,” to carjack a vehicle on a college campus was sentenced yesterday to seven years in prison for a firearms offense, announced Russ Ferguson, U.S. Attorney for the Western District of North Carolina. Mark Jordan Williams, 37, was also ordered to serve three years of supervised release following the completion of his prison term.
Alicia Jones, Special Agent in Charge of the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), Charlotte Field Division, joins U.S. Attorney Ferguson in making today’s announcement.
According to court documents and court proceedings, on March 23, 2023, an individual identified as L.C. was sitting in a Jeep Wrangler, parked on the campus of the University of North Carolina-Charlotte. Court records show that Williams approached the vehicle, pointed a handgun at L.C. and ordered L.C. out of the car. Williams then took L.C.’s phone, got into the Jeep, and drove away. Williams was located and arrested later that evening while inside the Jeep. When Williams was arrested, a .40 caliber Polymer 80 handgun was recovered from inside the vehicle as well. During the investigation, law enforcement determined that Williams has multiple prior criminal convictions and he prohibited from possessing a firearm.
On January 9, 2025, Williams pleaded guilty to possession and brandishing of a firearm in furtherance of a crime of violence. He is in federal custody and will be transferred to the custody of the Federal Bureau of Prisons upon designation of a federal facility.
The ATF investigated the case and the U.S. Attorney’s Office in Charlotte handled the prosecution.
Source: United States Bureau of Alcohol Tobacco Firearms and Explosives (ATF)
Jacksonville, Florida – U.S. District Judge Harvey Schlesinger has sentenced Alton Wayne Cope, III (64, St. Augustine) to four years and three months in federal prison for possessing a firearm as a convicted felon and conspiring to deal firearms without a license. Cope entered a guilty plea in October 2024.
According to court documents, agents began investigating Cope and a co-conspirator when agents learned that Cope may have been illegally selling firearms. During the summer of 2024, agents conducted multiple controlled purchase operations during which they purchased 11 firearms from Cope and a co-conspirator. Throughout the investigation, agents learned that Braden Hobbs was the original purchaser of multiple firearms purchased from Cope and a co-conspirator. Cellphone records later showed that the co-conspirator regularly purchased firearms from Hobbs. Additionally, at least two of the firearms sold by Cope and a co-conspirator had previously been reported stolen. In August 2024, agents executed a federal search warrant at Cope’s residence. During the search, agents found an additional firearm in his bedroom.
Although he engaged in the business of dealing firearms, Cope is not a federally licensed firearms dealer, as required by federal law. Additionally, Cope was previously convicted of multiple felonies, including two counts of possession of cocaine and possession of a firearm by a convicted felon. Therefore, he is prohibited from possessing firearms or ammunition under federal law.
In related court proceedings, co-conspirator Braden Hobbs has been charged by indictment and is scheduled for trial later this year. If convicted, Hobbs faces a minimum sentence of 5 years, up to 95 years, in federal prison. An indictment is merely a formal charge that a defendant has committed one or more violations of federal criminal law, and every defendant is presumed innocent unless, and until, proven guilty.
This case was investigated by the Bureau of Alcohol, Tobacco, Firearms and Explosives, the Internal Revenue Service – Criminal Investigation, the United States Secret Service, the North Florida HIDTA Tri-County Narcotics Task Force with the Florida Department of Law Enforcement, the St. Johns County Sheriff’s Office, and the Jacksonville Sheriff’s Office. It is being prosecuted by Assistant United States Attorney Elisibeth Adams.
This case is part of Project Safe Neighborhoods (PSN), a program bringing together all levels of law enforcement and the communities they serve to reduce violent crime and gun violence, and to make our neighborhoods safer for everyone. On May 26, 2021, the Department launched a violent crime reduction strategy strengthening PSN based on these core principles: fostering trust and legitimacy in our communities, supporting community-based organizations that help prevent violence from occurring in the first place, setting focused and strategic enforcement priorities, and measuring the results.
As soon as snow melted from Russia’s Zabaykal’skiy Kray in mid-March 2025, satellites began detecting large numbers of wildland fires burning in the grasslands and forests surrounding Chita, the territory’s capital. Two months later, fires continued to rage around the city. The MODIS (Moderate Resolution Imaging Spectroradiometer) on NASA’s Aqua satellite captured this image of smoke streaming from multiple fires near Chita on May 19, 2025. The city, a stop along the Trans-Siberian Railway, has a population of about 350,000. News reports indicate that fires were active on the city’s outskirts on May 20 and were edging closer to the city center as firefighters worked amid dry, windy conditions. On May 20, 2025, Russia’s Aerial Protection Service reported 49 fires burning across nearly 700,000 hectares (2,700 square miles) in six regions of the country. Thirty-three fires were in Zabaykal’skiy (also called Transbaikal) and nine in Buryatiya, both of which border Mongolia. Russian officials reported deploying 2,700 personnel and 13 aircraft to fight the fires, including more than 1,000 paratroopers and airborne troops in Zabaykal’skiy. NASA Earth Observatory image by Michala Garrison, using MODIS data from NASA EOSDIS LANCE and GIBS/Worldview. Story by Adam Voiland.
This article is for students grades 5-8. The surface of the Moon is covered in a thick layer of boulders, rocks, and dust. This dusty, rocky layer is called lunar regolith. It was created a long time ago when meteorites crashed into the Moon and broke up the ground. NASA scientists study the regolith to learn more about the Moon’s history. But the smallest parts of the regolith make exploring the Moon very hard! That is why scientists are working to understand it better and to keep astronauts safe during future lunar missions.
Lunar regolith is full of tiny, sharp pieces that can act like little bits of broken glass. Unlike the dust and soil on Earth, the smallest pieces of regolith have not been worn down by wind or rain. These bits are rough, jagged, and cling to everything they touch – boots, gloves, tools, and even spacecraft! In pictures it might look like soft, harmless gray powder, but it is actually scratchy and can damage lunar landers, spacesuits, and robots. This makes working on the Moon a lot harder than it looks!
The small parts of lunar regolith get stuck on spacesuits and can be brought inside the spacecraft. Once it is inside, it can cause some serious problems. The tiny, sharp pieces can make astronauts’ skin itchy, irritate their eyes, and even make them cough. If it gets into their lungs, it can make them sick. Scientists worry the damage from breathing in lunar regolith could keep bothering astronauts for a long time, even after they are back on Earth. That is why NASA scientists and technologists are working hard to find smart ways to deal with regolith and protect astronauts!
Regolith doesn’t just cause trouble for astronauts. It can also damage important machines! It can scratch tools and cover up solar panels, causing them to stop working. It can also clog radiators, which are used to keep machines cool. The small bits of regolith can make surfaces slippery and hard to walk on. It can even make it tough for robots to move around. Unlike Earth’s soil, the Moon’s regolith isn’t packed down. Any time we move things around on the Moon’s surface, we spread the rough, dusty particles around. Can you imagine what a mess launching and landing a spacecraft would make? All of this can make exploring the Moon much more difficult and even dangerous!
NASA is building many cool technologies to help deal with the harm regolith can cause. One of the tools technologists have already developed is call an Electrodynamic Dust Shield (EDS). It uses electricity to create a kind of force field that pushes the small particles away from tools on the Moon! There are many ways NASA is working to understand lunar regolith. One interesting way is by using special cameras and lasers on landers to watch how the regolith moves when a spacecraft lands. This system is called SCALPPS, which stands for Stereo Cameras for Lunar Plume-Surface Studies. SCALPSS helps scientists see how the lunar regolith gets blown around during landings. It helps scientists to measure the size of the regolith pieces and the amount that flies up into the air during landing. The more NASA knows about how regolith behaves, the better they can plan for safe missions!
Many types of scientists and engineers work together to understand lunar regolith. If you want to study space, here are some cool jobs you could have! Planetary Geologist: These scientists are like detectives. They study how the things in space were formed, how they have changed, and what they can tell us about the rest of the solar system. Their work helps us understand what is in space. Chemist: Chemists look at space rocks and space dust. They want to know what these materials are made of and how they were created. Astrobiologist: Astrobiologists are studying to find clues of life beyond Earth. They study space to find out if life ever existed – or could exist – somewhere else in the universe. Planetary Scientist: These scientists use pictures, data from spacecraft, and even samples from rocks and dust to learn about other worlds. They explore space without ever leaving Earth! Remote Sensing Scientist: These scientists use satellites, drones, and special cameras to study planets from far away. It is like being a space spy who looks for clues from above. Engineers: Engineers solve problems! Civil engineers, materials engineers, and geotechnical engineers work together to understand how regolith can best be used for building materials and get useful resources on the Moon.
Making Regolith Activity Watch: Mitigating Lunar Dust Watch: NASA SCALPSS Watch: Surprisingly STEM: Exploration Geologist Surprisingly STEM: Moon Rock Processors
strong>LOS ANGELES – The two Disaster Recovery Centers (DRCs) for the Los Angeles Wildfires are permanently closing Saturday, May 31, 2025, at 4 p.m. and federal resources will be transitioning to new locations. Current DRC Locations and Hours UCLA Research Park West 10850 West Pico Blvd. Los Angeles, CA 90064 Monday-Friday: 9 a.m. – 6 p.m. and Saturday: 9 a.m. – 4 p.m. Altadena Disaster Recovery Center540 West Woodbury Rd. Altadena, CA 91001 Monday-Friday: 9 a.m. – 6 p.m. and Saturday: 9 a.m. – 4 p.m. The Federal Emergency Management Agency (FEMA) and Small Business Administration (SBA) will be transitioning from the current DRC locations to county and city run facilities. Federal resources will be available at their new locations beginning Monday, June 2, 2025. Services Will Continue at: One Stop Rebuilding Center1828 Sawtelle Blvd.Los Angeles, CA 90025 Monday-Friday: 9 a.m. – 5 p.m. Closed weekends. Altadena Community Center730 E. Altadena Dr.Altadena, CA 91001Monday-Friday: 9 a.m. – 5 p.m. Closed weekends. If you applied for FEMA assistance, it’s important to stay in touch with FEMA to track and update your application should you receive an insurance settlement or denial and as your situation changes to work through any approval processes. FEMA representatives can explain available assistance programs and help you with resources for your recovery needs. Rental Assistance is available for eligible individuals and families who were displaced by the wildfires. If you were displaced and need assistance covering housing costs, you should contact FEMA to determine your eligibility for this program. SBA’s Customer Service Representatives are available at the Centers to answer questions, help applicants complete their disaster loan application, accept documents, and provide updates on an application’s status. Additional Resources
California Governor’s Office of Emergency Services (CalOES)Resources offered by State agencies are available online and at some existing field offices. Survivors can find a complete list of recovery related services on the CA.gov/LAfires Recovery Services Finder page, including how to contact each agency and their office locations. U.S. Army Corps of Engineers (USACE)For help answering questions regarding debris removal, please call: 213-308-8305. The call center is available daily from 6 a.m. to 6:30 p.m. For more information, you can also visit the USACE Los Angeles County Wildfire Debris Removal Mission. One-Stop Permitting CentersFor unincorporated LA County communities, One-Stop Permit Centers are also available in Calabasas and Altadena for residents impacted by the Palisades and Eaton fires. LA County permitting agencies, including Fire Department, Regional Planning, Public Health, Public Works Geotechnical and Materials Engineering Division and Public Works Building and Safety, are available to guide owners and their representatives through the rebuild process and answer any questions they may have. Walk-ins are welcome and consultation appointments can be scheduled. More information including days and hours of operation, can be found here: recovery.lacounty.gov/rebuilding/one-stop-permit-centers.
Follow FEMA online, on X @FEMA or @FEMAEspanol, on FEMA’s Facebook page or Espanol page and at FEMA’s YouTube account. For preparedness information follow the Ready Campaign on X at @Ready.gov, on Instagram @Ready.gov or on the Ready Facebook page.
California is committed to supporting residents impacted by the Los Angeles Hurricane-Force Firestorm as they navigate the recovery process. Visit CA.gov/LAFires for up-to-date information on disaster recovery programs, important deadlines, and how to apply for assistance.
In a first, researchers from NASA and Virginia Tech used satellite data to measure the height and speed of potentially hazardous flood waves traveling down U.S. rivers. The three waves they tracked were likely caused by extreme rainfall and by a loosened ice jam. While there is currently no database that compiles satellite data on river flood waves, the new study highlights the potential of space-based observations to aid hydrologists and engineers, especially those working in communities along river networks with limited flood control structures such as levees and flood gates. Unlike ocean waves, which are ordinarily driven by wind and tides, and roll to shore at a steady clip, river waves (also called flood or flow waves) are temporary surges stretching tens to hundreds of miles. Typically caused by rainfall or seasonal snowmelt, they are essential to shuttling nutrients and organisms down a river. But they can also pose hazards: Extreme river waves triggered by a prolonged downpour or dam break can produce floods. “Ocean waves are well known from surfing and sailing, but rivers are the arteries of the planet. We want to understand their dynamics,” said Cedric David, a hydrologist at NASA’s Jet Propulsion Laboratory in Southern California and a coauthor of a new study published May 14 in Geophysical Research Letters.
Measuring Speed and Size To search for river waves for her doctoral research, lead author Hana Thurman of Virginia Tech turned to a spacecraft launched in 2022. The SWOT (Surface Water and Ocean Topography) satellite is a collaboration between NASA and the French space agency CNES (Centre National d’Études Spatiales). It is surveying the height of nearly all of Earth’s surface waters, both fresh and salty, using its sensitive Ka-band Radar Interferometer (KaRIn). The instrument maps the elevation and width of water bodies by bouncing microwaves off the surface and timing how long the signal takes to return. “In addition to monitoring total storage of waters in lakes and rivers, we zoom in on dynamics and impacts of water movement and change,” said Nadya Vinogradova Shiffer, SWOT program scientist at NASA Headquarters in Washington. Thurman knew that SWOT has helped scientists track rising sea levels near the coast, spot tsunami slosh, and map the seafloor, but could she identify river height anomalies in the data indicating a wave on the move? She found that the mission had caught three clear examples of river waves, including one that arose abruptly on the Yellowstone River in Montana in April 2023. As the satellite passed overhead, it observed a 9.1-foot-tall (2.8-meter-tall) crest flowing toward the Missouri River in North Dakota. It was divided into a dramatic 6.8-mile-long (11-kilometer-long) peak followed by a more drawn‐out tail. These details are exciting to see from orbit and illustrate the KaRIn instrument’s uniquely high spatial resolution, Thurman said. Sleuthing through optical Sentinel-2 imagery of the area, she determined that the wave likely resulted from an ice jam breaking apart upstream and releasing pent-up water. The other two river waves that Thurman and the team found were triggered by rainfall runoff. One, spotted by SWOT starting on Jan. 25, 2024, on the Colorado River south of Austin, Texas, was associated with the largest flood of the year on that section of river. Measuring over 30 feet (9 meters) tall and 166 miles (267 kilometers) long, it traveled around 3.5 feet (1.07 meters) per second for over 250 miles (400 kilometers) before discharging into Matagorda Bay. The other wave originated on the Ocmulgee River near Macon, Georgia, in March 2024. Measuring over 20 feet (6 meters) tall and extending more than 100 miles (165 kilometers), it traveled about a foot (0.33 meters) per second for more than 124 miles (200 kilometers). “We’re learning more about the shape and speed of flow waves, and how they change along long stretches of river,” Thurman said. “That could help us answer questions like, how fast could a flood get here and is infrastructure at risk?” Complementary Observations Engineers and water managers measuring river waves have long relied on stream gauges, which record water height and estimate discharge at fixed points along a river. In the United States, stream gauge networks are maintained by agencies including the U.S. Geological Survey. They are sparser in other parts of the world. “Satellite data is complementary because it can help fill in the gaps,” said study supervisor George Allen, a hydrologist and remote sensing expert at Virginia Tech. If stream gauges are like toll booths clocking cars as they pass, SWOT is like a traffic helicopter taking snapshots of the highway. The wave speeds that SWOT helped determine were similar to those calculated using gauge data alone, Allen said, showing how the satellite could help monitor waves in river basins without gauges. Knowing where and why river waves develop can help scientists tracking changing flood patterns around the world. Orbiting Earth multiple times each day, SWOT is expected to observe some 55% of large-scale floods at some stage in their life cycle. “If we see something in the data, we can say something,” David said of SWOT’s potential to flag dangerous floods in the making. “For a long time, we’ve stood on the banks of our rivers, but we’ve never seen them like we are now.” More About SWOT The SWOT satellite was jointly developed by NASA and CNES, with contributions from the Canadian Space Agency (CSA) and the UK Space Agency. NASA’s Jet Propulsion Laboratory, managed for the agency by Caltech in Pasadena, California, leads the U.S. component of the project. For the flight system payload, NASA provided the Ka-band radar interferometer (KaRIn) instrument, a GPS science receiver, a laser retroreflector, a two-beam microwave radiometer, and NASA instrument operations. The Doppler Orbitography and Radioposition Integrated by Satellite system, the dual frequency Poseidon altimeter (developed by Thales Alenia Space), the KaRIn radio-frequency subsystem (together with Thales Alenia Space and with support from the UK Space Agency), the satellite platform, and ground operations were provided by CNES. The KaRIn high-power transmitter assembly was provided by CSA. News Media Contacts Jane J. Lee / Andrew WangJet Propulsion Laboratory, Pasadena, Calif.818-354-0307 / 626-379-6874Written by Sally Younger2025-074
NASA’s X-59 quiet supersonic research aircraft successfully completed a critical series of tests in which the airplane was put through its paces for cruising high above the California desert – all without ever leaving the ground. The goal of ground-based simulation testing was to make sure the hardware and software that will allow the X-59 to fly safely are properly working together and able to handle any unexpected problems. Learn more about this series of exercies, dubbed “aluminum bird” testing by engineers. Image credit: Lockheed Martin/Garry Tice
How big is space? Space is really big. Thinking about our solar system, let’s imagine you could get in a car and drive to Pluto at highway speeds. It would take you about 6,000 years to get there. When we start to think about other stars outside of our solar system, we need to think about another unit of distance. This is why astronomers use the unit light-years. Light travels at 186,000 miles per second. One light year is about 6 trillion miles. The closest star to our Sun is about four light years away. Our own Milky Way galaxy is about 100,000 light-years across. We know from deep field images of the universe that there are hundreds of billions, perhaps a trillion other galaxies. Using some of the deepest images yet from the James Webb Space Telescope, we’ve been able to see galaxies that emitted their light about 13 and a half billion years ago. Now, here’s a really important thing. Because the universe is expanding, those most distant galaxies are actually much further away than 13 and a half billion light years. I’m glossing over some math here, but we can estimate that the observable universe is about 92 billion light-years across. But we’re pretty sure that the universe is even bigger than what we can see. And here’s where things get really weird, we don’t actually know if the universe is finite or infinite. As much as we’ve learned about the universe, science has no reliable estimate of the actual size of the entire universe. [END VIDEO TRANSCRIPT] Full Episode List Full YouTube Playlist
The rover took the image — its fifth since landing in February 2021 — between stops investigating the Martian surface. A Martian dust devil photobombed NASA’s Perseverance Mars rover as it took a selfie on May 10 to mark its 1,500th sol (Martian day) exploring the Red Planet. At the time, the six-wheeled rover was parked in an area nicknamed “Witch Hazel Hill,” an area on Jezero Crater’s rim that the rover has been exploring over the past five months. “The rover self-portrait at the Witch Hazel Hill area gives us a great view of the terrain and the rover hardware,” said Justin Maki, Perseverance imaging lead at NASA’s Jet Propulsion Laboratory in Southern California, which manages the mission. “The well-illuminated scene and relatively clear atmosphere allowed us to capture a dust devil located 3 miles to the north in Neretva Vallis.” The selfie also gives the engineering teams a chance to view and assess the state of the rover, its instruments, and the overall dust accumulation as Perseverance reached the 1,500-sol milestone. (A day on Mars is 24.6 hours, so 1,500 sols equals 1,541 Earth days.)
The bright light illuminating the scene is courtesy of the high angle of the Sun at the time the images composing the selfie were taken, lighting up Perseverance’s deck and casting its shadow below and behind the chassis. Immediately in front of the rover is the “Bell Island” borehole, the latest sampling location in the Witch Hazel Hill area. How Perseverance Did It This newest selfie, Perseverance’s fifth since the mission began, was stitched together on Earth from a series of 59 images collected by the WATSON (Wide Angle Topographic Sensor for Operations and eNgineering) camera at the end of the robotic arm. It shows the rover’s remote sensing mast looking into the camera. To generate the version of the selfie with the mast looking at the borehole, WATSON took three additional images, concentrating on the reoriented mast.
“To get that selfie look, each WATSON image has to have its own unique field of view,” said Megan Wu, a Perseverance imaging scientist from Malin Space Science Systems in San Diego. “That means we had to make 62 precision movements of the robotic arm. The whole process takes about an hour, but it’s worth it. Having the dust devil in the background makes it a classic. This is a great shot.”
The dust covering the rover is visual evidence of the rover’s journey on Mars: By the time the image was captured, Perseverance had abraded and analyzed a total of 37 rocks and boulders with its science instruments, collected 26 rock cores (25 sealed and 1 left unsealed), and traveled more than 22 miles (36 kilometers). “After 1,500 sols, we may be a bit dusty, but our beauty is more than skin deep,” said Art Thompson, Perseverance project manager at JPL. “Our multi-mission radioisotope thermoelectric generator is giving us all the power we need. All our systems and subsystems are in the green and clicking along, and our amazing instruments continue to provide data that will feed scientific discoveries for years to come.” The rover is currently exploring along the western rim of Jezero Crater, at a location the science team calls “Krokodillen.” News Media Contacts DC AgleJet Propulsion Laboratory, Pasadena, Calif.818-393-9011agle@jpl.nasa.gov Karen Fox / Molly WasserNASA Headquarters, Washington202-358-1600karen.c.fox@nasa.gov / molly.l.wasser@nasa.gov 2025-073
A newly discovered planetary system, informally known as 2M1510, is among the strangest ever found. An apparent planet traces out an orbit that carries it far over the poles of two brown dwarfs. This pair of mysterious objects – too massive to be planets, not massive enough to be stars – also orbit each other. Yet a third brown dwarf orbits the other two at an extreme distance.
In a typical arrangement, as in our solar system, families of planets orbit their parent stars in more-or-less a flat plane – the orbital plane – that matches the star’s equator. The rotation of the star, too, aligns with this plane. Everyone is “coplanar:” flat, placid, stately. Not so for possible planet 2M1510 b (considered a “candidate planet” pending further measurements). If confirmed, the planet would be in a “polar orbit” around the two central brown dwarfs – in other words, its orbital plane would be perpendicular to the plane in which the two brown dwarfs orbit each other. Take two flat disks, merge them together at an angle in the shape of an X, and you have the essence of this orbital configuration. “Circumbinary” planets, those orbiting two stars at once, are rare enough. A circumbinary orbiting at a 90-degree tilt was, until now, unheard of. But new measurements of this system, using the ESO (European Southern Observatory) Very Large Telescope in Chile, appear to reveal what scientists previously only imagined.
The method by which the study’s science team teased out the planet’s vertiginous existence is itself a bit of a wild ride. The candidate planet cannot be detected the way most exoplanets – planets around other stars – are found today: the “transit” method, a kind of mini-eclipse, a tiny dip in starlight when the planet crosses the face of its star. Instead they used the next most prolific method, “radial velocity” measurements. Orbiting planets cause their stars to rock back and forth ever so slightly, as the planets’ gravity pulls the stars one way and another; that pull causes subtle, but measurable, shifts in the star’s light spectrum. Add one more twist to the detection in this case: the push-me-pull-you effect of the planet on the two brown dwarfs’ orbit around each other. The path of the brown dwarf pair’s 21-day mutual orbit is being subtly altered in a way that can only be explained, the study’s authors conclude, by a polar-orbiting planet.
Only 16 circumbinary planets – out of more than 5,800 confirmed exoplanets – have been found by scientists so far, most by the transit method. Twelve of those were found using NASA’s now-retired Kepler Space Telescope, the mission that takes the prize for the most transit detections (nearly 2,800). Scientists have observed a small number of debris disks and “protoplanetary” disks in polar orbits, and suspected that polar-orbiting planets might be out there as well. They seem at last to have turned one up.
An international science team led by Thomas A. Baycroft, a Ph.D. student in astronomy and astrophysics at the University of Birmingham, U.K., published a paper describing their discovery in the journal “Science Advances” in April 2025. The planet was entered into NASA’s Exoplanet Archive on May 1, 2025. The system’s full name is 2MASS J15104786-281874 (2M1510 for short).
News In Brief – Source: US Computer Emergency Readiness Team
Executive Summary
This joint cybersecurity advisory (CSA) highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies. This includes those involved in the coordination, transport, and delivery of foreign assistance to Ukraine. Since 2022, Western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165—tracked in the cybersecurity community under several names (see “Cybersecurity Industry Tracking”). The actors’ cyber espionage-oriented campaign, targeting technology companies and logistics entities, uses a mix of previously disclosed tactics, techniques, and procedures (TTPs). The authoring agencies expect similar targeting and TTP use to continue.
Executives and network defenders at logistics entities and technology companies should recognize the elevated threat of unit 26165 targeting, increase monitoring and threat hunting for known TTPs and indicators of compromise (IOCs), and posture network defenses with a presumption of targeting.
This cyber espionage-oriented campaign targeting logistics entities and technology companies uses a mix of previously disclosed TTPs and is likely connected to these actors’ wide scale targeting of IP cameras in Ukraine and bordering NATO nations.
The following authors and co-sealers are releasing this CSA:
United States National Security Agency (NSA)
United States Federal Bureau of Investigation (FBI)
United Kingdom National Cyber Security Centre (NCSC-UK)
Germany Federal Intelligence Service (BND) Bundesnachrichtendienst
Germany Federal Office for Information Security (BSI) Bundesamt für Sicherheit in der Informationstechnik
Germany Federal Office for the Protection of the Constitution (BfV) Bundesamt für Verfassungsschutz
Czech Republic Military Intelligence (VZ) Vojenské zpravodajství
Czech Republic National Cyber and Information Security Agency (NÚKIB) Národní úřad pro kybernetickou a informační bezpečnost
Czech Republic Security Information Service (BIS) Bezpečnostní informační služba
Poland Internal Security Agency (ABW) Agencja Bezpieczeństwa Wewnętrznego
Poland Military Counterintelligence Service (SKW) Służba Kontrwywiadu Wojskowego
United States Cybersecurity and Infrastructure Security Agency (CISA)
United States Department of Defense Cyber Crime Center (DC3)
United States Cyber Command (USCYBERCOM)
Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
Canadian Centre for Cyber Security (CCCS)
Danish Defence Intelligence Service (DDIS) Forsvarets Efterretningstjeneste
Estonian Foreign Intelligence Service (EFIS) Välisluureamet
Estonian National Cyber Security Centre (NCSC-EE) Küberturvalisuse keskus
French Cybersecurity Agency (ANSSI) Agence nationale de la sécurité des systèmes d’information
Netherlands Defence Intelligence and Security Service (MIVD) Militaire Inlichtingen- en Veiligheidsdienst
Download the PDF version of this report:
Russian GRU Targeting Western Logistics Entities and Technology Companies (PDF, 1,081KB)
For a downloadable list of IOCs, visit:
Introduction
For over two years, the Russian GRU 85th GTsSS, military unit 26165—commonly known in the cybersecurity community as APT28, Fancy Bear, Forest Blizzard, BlueDelta, and a variety of other identifiers—has conducted this campaign using a mix of known tactics, techniques, and procedures (TTPs), including reconstituted password spraying capabilities, spearphishing, and modification of Microsoft Exchange mailbox permissions. In late February 2022, multiple Russian state-sponsored cyber actors increased the variety of cyber operations for purposes of espionage, destruction, and influence—with unit 26165 predominately involved in espionage. [1] As Russian military forces failed to meet their military objectives and Western countries provided aid to support Ukraine’s territorial defense, unit 26165 expanded its targeting of logistics entities and technology companies involved in the delivery of aid. These actors have also targeted Internet-connected cameras at Ukrainian border crossings to monitor and track aid shipments. Note: This advisory uses the MITRE ATT&CK® for Enterprise framework, version 17. See Appendix A: MITRE ATT&CK tactics and techniques for a table of the threat actors’ activity mapped to MITRE ATT&CK tactics and techniques. This advisory uses the MITRE D3FEND® framework, version 1.0.
Description of Targets
The GRU unit 26165 cyber campaign against Western logistics providers and technology companies has targeted dozens of entities, including government organizations and private/commercial entities across virtually all transportation modes: air, sea, and rail. These actors have targeted entities associated with the following verticals within NATO member states, Ukraine, and at international organizations:
Defense Industry
Transportation and Transportation Hubs (ports, airports, etc.)
Maritime
Air Traffic Management
IT Services
In the course of the targeting lifecycle, unit 26165 actors identified and conducted follow-on targeting of additional entities in the transportation sector that had business ties to the primary target, exploiting trust relationships to attempt to gain additional access [T1199].
The actors also conducted reconnaissance on at least one entity involved in the production of industrial control system (ICS) components for railway management, though a successful compromise was not confirmed [TA0043].
The countries with targeted entities include the following, as illustrated in Figure 1:
Bulgaria
Czech Republic
France
Germany
Greece
Italy
Moldova
Netherlands
Poland
Romania
Slovakia
Ukraine
United States
Figure 1: Countries with Targeted Entities
Initial Access TTPs
To gain initial access to targeted entities, unit 26165 actors used several techniques to gain initial access to targeted entities, including (but not limited to):
The actors abused vulnerabilities associated with a range of brands and models of small office/home office (SOHO) devices to facilitate covert cyber operations, as well as proxy malicious activity via devices with geolocation in proximity to the target [T1665]. [2]
Credential Guessing/Brute Force
Unit 26165 actors’ credential guessing [T1110.001] operations in this campaign exhibit some similar characteristics to those disclosed in the previous CSA “Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments.” [3] Based on victim network investigations, the current iteration of this TTP employs a similar blend of anonymization infrastructure, including the use of Tor and commercial VPNs [T1090.003]. The actors frequently rotated the IP addresses used to further hamper detection. All observed connections were made via encrypted TLS [T1573].
Spearphishing
GRU unit 26165 actors’ spearphishing emails included links [T1566.002] leading to fake login pages impersonating a variety of government entities and Western cloud email providers’ webpages. These webpages were typically hosted on free third-party services or compromised SOHO devices and often used legitimate documents associated with thematically similar entities as lures. The subjects of spearphishing emails were diverse and ranged from professional topics to adult themes. Phishing emails were frequently sent via compromised accounts or free webmail accounts [T1586.002, T1586.003]. The emails were typically written in the target’s native language and sent to a single targeted recipient.
Some campaigns employed multi-stage redirectors [T1104] verifying IP-geolocation [T1627.001] and browser fingerprints [T1627] to protect credential harvesting infrastructure or provide multifactor authentication (MFA) [T1111] and CAPTCHA relaying capabilities [T1056]. Connecting endpoints failing the location checks were redirected to a benign URL [T1627], such as msn.com. Redirector services used include:
Webhook[.]site
FrgeIO
InfinityFree
Dynu
Mocky
Pipedream
Mockbin[.]org
The actors also used spearphishing to deliver malware (including HEADLACE and MASEPIE) executables [T1204.002] delivered via third-party services and redirectors [T1566.002], scripts in a mix of languages [T1059] (including BAT [T1059.003] and VBScript [T1059.005]) and links to hosted shortcuts [T1204.001].
CVE Usage
Throughout this campaign, GRU unit 26165 weaponized an Outlook NTLM vulnerability (CVE-2023-23397) to collect NTLM hashes and credentials via specially crafted Outlook calendar appointment invitations [T1187]. [4],[5] These actors also used a series of Roundcube CVEs (CVE-2020-12641, CVE-2020-35730, and CVE-2021-44026) to execute arbitrary shell commands [T1059], gain access to victim email accounts, and retrieve sensitive data from email servers [T1114].
Since at least fall 2023, the actors leveraged a WinRAR vulnerability (CVE-2023-38831) allowing for the execution of arbitrary code embedded in an archive as a means of initial access [T1659]. The actors sent emails with malicious attachments [T1566.001] or embedded hyperlinks [T1566.002] that downloaded a malicious archive prepared using this CVE.
Post-Compromise TTPs
After an initial compromise using one of the above techniques, unit 26165 actors conducted contact information reconnaissance to identify additional targets in key positions [T1589.002]. The actors also conducted reconnaissance of the cybersecurity department [T1591], individuals responsible for coordinating transport [T1591.004], and other companies cooperating with the victim entity [T1591.002].
The actors used native commands and open source tools, such as Impacket and PsExec, to move laterally within the environment [TA0008]. Multiple Impacket scripts were used as .exe files, in addition to the python versions, depending on the victim environment. The actors also moved laterally within the network using Remote Desktop Protocol (RDP) [T1021.001] to access additional hosts and attempt to dump Active Directory NTDS.dit domain databases [T1003.003] using native Active Directory Domain Services commands, such as in Figure 2: Example Active Directory Domain Services command:
C:Windowssystem32ntdsutil.exe "activate instance ntds" ifm "create full C:temp[a-z]{3}" quit quit
Figure 2: Example Active Directory Domain Services command
Additionally, GRU unit 26165 actors used the tools Certipy and ADExplorer.exe to exfiltrate information from the Active Directory. The actors installed python [T1059.006] on infected machines to enable the execution of Certipy. Accessed files were archived in .zip files prior to exfiltration [T1560]. The actors attempted to exfiltrate archived data via a previously dropped OpenSSH binary [T1048].
Incident response investigations revealed that the actors would take steps to locate and exfiltrate lists of Office 365 users and set up sustained email collection. The actors used manipulation of mailbox permissions [T1098.002] to establish sustained email collection at compromised logistics entities, as detailed in a Polish Cybercommand blog. [6]
After initial authentication, unit 26165 actors would change accounts’ folder permissions and enroll compromised accounts in MFA mechanisms to increase the trust-level of compromised accounts and enable sustained access [T1556.006]. The actors leveraged python scripts to retrieve plaintext passwords via Group Policy Preferences [T1552.006] using Get-GPPPassword.py and a modified ldap-dump.py to enumerate the Windows environment [T1087.002] and conduct a brute force password spray [T1110.003] via Lightweight Directory Access Protocol (LDAP). The actors would additionally delete event logs through the wevtutil utility [T1070.001].
After gaining initial access to the network, the actors pursued further access to accounts with access to sensitive information on shipments, such as train schedules and shipping manifests. These accounts contained information on aid shipments to Ukraine, including:
sender,
recipient,
train/plane/ship numbers,
point of departure,
destination,
container registration numbers,
travel route, and
cargo contents.
In at least one instance, the actors attempted to use voice phishing [T1566.004] to gain access to privileged accounts by impersonating IT staff.
Malware
Unit 26165’s use of malware in this campaign ranged from gaining initial access to establishing persistence and exfiltrating data. In some cases, the attack chain resulted in multiple pieces of malware being deployed in succession. The actors used dynamic link library (DLL) search order hijacking [T1574.001] to facilitate malware execution. There were a number of known malware variants tied to this campaign against logistics sector victims, including:
HEADLACE [7]
MASEPIE [8]
While other malware variants, such as OCEANMAP and STEELHOOK, [8] were not directly observed targeting logistics or IT entities, their deployment against victims in other sectors in Ukraine and other Western countries suggest that they could be deployed against logistics and IT entities should the need arise.
Persistence
In addition to the abovementioned mailbox permissions abuse, unit 26165 actors also used scheduled tasks [T1053.005], run keys [T1547.001], and placed malicious shortcuts [T1547.009] in the startup folder to establish persistence.
Exfiltration
GRU unit 26165 actors used a variety of methods for data exfiltration that varied based on the victim environment, including both malware and living off the land binaries. PowerShell commands [T1059.001] were often used to prepare data for exfiltration; for example, the actors prepared zip archives [T1560.001] for upload to their own infrastructure.
The actors also used server data exchange protocols and Application Programming Interfaces (APIs) such as Exchange Web Services (EWS) and Internet Message Access Protocol (IMAP) [T1114.002] to exfiltrate data from email servers. In multiple instances, the actors used periodic EWS queries [T1119] to collect new emails sent and received since the last data exfiltration [T1029]. The actors typically used infrastructure in close geographic proximity to the victim. Long gaps between exfiltration, the use of trusted and legitimate protocols, and the use of local infrastructure allowed for long-term collection of sensitive data to go undetected.
Connections to Targeting of IP Cameras
In addition to targeting logistics entities, unit 26165 actors likely used access to private cameras at key locations, such as near border crossings, military installations, and rail stations, to track the movement of materials into Ukraine. The actors also used legitimate municipal services, such as traffic cams.
The actors targeted Real Time Streaming Protocol (RTSP) servers hosting IP cameras primarily located in Ukraine as early as March 2022 in a large-scale campaign, which included attempts to enumerate devices [T1592] and gain access to the cameras’ feeds [T1125]. Actor-controlled servers sent RTSP DESCRIBE requests destined for RTSP servers, primarily hosting IP cameras [T1090.002]. The DESCRIBE requests were crafted to obtain access to IP cameras located on logically distinct networks from that of the routers that received the request. The requests included Base64-encoded credentials for the RTSP server, which included publicly documented default credentials and likely generic attempts to brute force access to the devices [T1110]. An example of an RTSP request is shown in Figure 3.
Successful RTSP 200 OK responses contained a snapshot of the IP camera’s image and IP camera metadata such as video codec, resolution, and other properties depending on the IP camera’s configuration.
From a sample available to the authoring agencies of over 10,000 cameras targeted via this effort, the geographic distribution of victims showed a strong focus on cameras in Ukraine and border countries, as shown in Table 1:
Table 1: Geographic distribution of targeted IP cameras
Country
Percentage of Total Attempts
Ukraine
81.0%
Romania
9.9%
Poland
4.0%
Hungary
2.8%
Slovakia
1.7%
Others
0.6%
Mitigation Actions
General Security Mitigations
Architecture and Configuration
Employ appropriate network segmentation [D3-NI] and restrictions to limit access and utilize additional attributes (such as device information, environment, and access path) when making access decisions [D3-AMED].
Consider Zero Trust principles when designing systems. Base product choices on how those products can solve specific risks identified as part of the end-to-end design. [9]
Ensure that host firewalls and network security appliances (e.g., firewalls) are configured to only allow legitimately needed data flows between devices and servers to prevent lateral movement [D3-ITF]. Alert on attempts to connect laterally between host devices or other unusual data flows.
Use automated tools to audit access logs for security concerns and identify anomalous access requests [D3-RAPA].
For organizations using on-premises authentication and email services, block and alert on NTLM/SMB requests to external infrastructure [D3-OTF].
Utilize endpoint, detection, and response (EDR) and other cybersecurity solutions on all systems, prioritizing high value systems with large amounts of sensitive data such as mail servers and domain controllers [D3-PM] first.
Perform threat and attack modeling to understand how sensitive systems may be compromised within an organization’s specific architecture and security controls. Use this to develop a monitoring strategy to detect compromise attempts and select appropriate products to enact this strategy.
Collect and monitor Windows logs for certain events, especially for events that indicate that a log was cleared unexpectedly [D3-SFA].
Enable optional security features in Windows to harden endpoints and mitigate initial access techniques [D3-AH]:
Enable attack surface reduction rules to prevent executable content from email [D3-ABPI].
Enable attack surface reduction rules to prevent execution of files from globally writeable directories, such as Downloads or %APPDATA% [D3-EAL].
Unless users are involved in the development of scripts, limit the local execution of scripts (such as batch scripts, VBScript, JScript/JavaScript, and PowerShell [10]) to known scripts [D3-EI], and audit execution attempts.
Disable Windows Host Scripting functionality and configure PowerShell to run in Constrained mode [D3-ACH].
Where feasible, implement allowlisting for applications and scripts to limit execution to only those needed for authorized activities, blocking all others by default [D3-EAL].
Consider using open source SIGMA rules as a baseline for detecting and alerting on suspicious file execution or command parameters [D3-PSA].
Use services that provide enhanced browsing services and safe link checking [D3-URA]. Significant reductions in successful spearphishing attempts were noted when email providers began offering link checking and automatic file detonation to block malicious content.
Where possible, block logins from public VPNs, including exit nodes in the same country as target systems, or, if they need to be allowed, alert on them for further investigation. Most organizations should not need to allow incoming traffic, especially logins to systems, from VPN services [D3-NAM].
Educate users to only use approved corporate systems for relevant government and military business and avoid the use of personal accounts on cloud email providers to conduct official business. Network administrators should also audit both email and web request logs to detect such activity.
Many organizations may not need to allow outgoing traffic to hosting and API mocking services, which are frequently used by GRU unit 26165. Organizations should consider alerting on or blocking the following services, with exceptions allowlisted for legitimate activity [D3-DNSDL].
*.000[.]pe
*.1cooldns[.]com
*.42web[.]io
*.4cloud[.]click
*.accesscan[.]org
*.bumbleshrimp[.]com
*.camdvr[.]org
*.casacam[.]net
*.ddnsfree[.]com
*.ddnsgeek[.]com
*.ddnsguru[.]com
*.dynuddns[.]com
*.dynuddns[.]net
*.free[.]nf
*.freeddns[.]org
*.frge[.]io
*.glize[.]com
*.great-site[.]net
*.infinityfreeapp[.]com
*.kesug[.]com
*.loseyourip[.]com
*.lovestoblog[.]com
*.mockbin[.]io
*.mockbin[.]org
*.mocky[.]io
*.mybiolink[.]io
*.mysynology[.]net
*.mywire[.]org
*.ngrok[.]io
*.ooguy[.]com
*.pipedream[.]net
*.rf[.]gd
*.urlbae[.]com
*.webhook[.]site
*.webhookapp[.]com
*.webredirect[.]org
*.wuaze[.]com
Heuristic detections for web requests to new subdomains, including of the above providers, may uncover malicious phishing activity [D3-DNRA]. Logging the requests for each sub-domain requested by users on a network, such as in DNS or firewall logs, may enable system administrators to identify new targeting and victims.
Identity and Access Management
Organizations should take measures to ensure strong access controls and mitigate against common credential theft techniques:
Use MFA with strong factors, such as passkeys or PKI smartcards, and require regular re-authentication [D3-MFA]. [11], [12] Strong authentication factors are not guessable using dictionary techniques, so they resist brute force attempts.
Implement other mitigations for privileged accounts: including limiting the number of admin accounts, considering using hardware MFA tokens, and regularly reviewing all privileged user accounts [D3-JFAPA].
Separate privileged accounts by role and alert on misuse of privileged accounts [D3-UAP]. For example, email administrator accounts should be different from domain administrator accounts.
Reduce reliance on passwords; instead, consider using services like single sign-on [D3-TBA].
For organizations using on-premises authentication and email services, plan to disable NTLM entirely and migrate to more robust authentication processes such as PKI certificate authentication.
Do not store passwords in Group Policy Preferences (GPP). Remove all passwords previously included in GPP and change all passwords on the corresponding accounts [D3-CH]. [13]
Use account throttling or account lockout [D3-ANET]:
Throttling is preferred to lockout. Throttling progressively increases time delay between successive login attempts.
Account lockout can leave legitimate users unable to access their accounts and requires access to an account recovery process.
Account lockout can provide a malicious actor with an easy way to launch a Denial of Service (DoS).
If using lockout, then allowing 5 to 10 attempts before lockout is recommended.
Use a service to check for compromised passwords before using them [D3-SPP]. For example, “Have I Been Pwned” can be used to check whether a password has been previously compromised without disclosing the potential password.
Change all default credentials [D3-CRO] and disable protocols that use weak authentication (e.g., clear-text passwords or outdated and vulnerable authentication or encryption protocols) or do not support multi-factor authentication [D3-ACH] [D3-ET]. Always configure access controls carefully to ensure that only well-maintained and well-authenticated accounts have access. [13]
IP Camera Mitigations
The following mitigation techniques for IP cameras can be used to defend against this type of malicious activity:
Ensure IP cameras are currently supported. Replace devices that are out of support.
Apply security patches and firmware updates to all IP cameras [D3-SU].
Disable remote access to the IP camera, if unnecessary [D3-ITF].
Ensure cameras are protected by a security appliance, if possible, such as by using a firewall to prevent communication with the camera from IP addresses not on an allowlist [D3-NAM].
If remote access to IP camera feeds is required, ensure authentication is enabled [D3-AA] and use a VPN to connect remotely [D3-ET]. Use MFA for management accounts if supported [D3-MFA].
Disable Universal Plug and Play (UPnP), Peer-to-Peer (P2P), and Anonymous Visit features on IP cameras and routers [D3-NI].
Turn off other ports/services not in use (e.g., FTP, web interface, etc.) [D3-ACH].
If supported, enable authenticated RTSP access only [D3-AA].
Review all authentication activity for remote access to make sure it is valid and expected [D3-UBA]. Investigate any unexpected or unusual activity.
Audit IP camera user accounts to ensure they are an accurate reflection of your organization and that they are being used as expected [D3-UAP].
Configure, tune, and monitor logging—if available—on the IP camera.
Indicators of Compromise (IOCs)
Note: Specific IoCs may no longer be actor controlled, may themselves be compromised infrastructure or email accounts, or may be shared infrastructure such as public VPN or Tor exit nodes. Care should be taken when basing triaging logs or developing detection rules on these indicators. GRU unit 26165 almost certainly uses extensive further infrastructure and TTPs not specifically listed in this report.
Utilities and scripts
Legitimate utilities
Unauthorized or unusual use of the following legitimate utilities can be an indication of a potential compromise:
ntdsutil – A legitimate Windows executable used by threat actors to export contents of Active Directory
wevtutil – A legitimate Windows executable used by threat actors to delete event logs
vssadmin – A legitimate Windows executable possibly used by threat actors to make a copy of the server’s C: drive
ADexplorer – A legitimate window executable to view, edit, and backup Active Directory Certificate Services
OpenSSH – The Windows version of a legitimate open source SSH client
schtasks – A legitimate Windows executable used to create persistence using scheduled tasks
whoami – A legitimate Windows executable used to retrieve the name of the current user
tasklist – A legitimate Windows executable used to retrieve the list of running processes
hostname – A legitimate Windows executable used to retrieve the device name
arp – A legitimate Windows executable used to retrieve the ARP table for mapping the network environment
systeminfo – A legitimate Windows executable used to retrieve a comprehensive summary of device and operating system information
net – A legitimate Windows executable used to retrieve detailed user information
wmic – A legitimate Windows executable used to interact with Windows Management Instrumentation (WMI), such as to retrieve letters assigned to logical partitions on storage drives
cacls – A legitimate Windows executable used to modify permissions on files
icacls – A legitimate Windows executable used to modify permissions to files and handle integrity levels and ownership
ssh – A legitimate Windows executable used to establish network shell connections
reg – A legitimate Windows executable used to add to or modify the system registry
Note: Additional heuristics are needed for effective hunting for these and other living off the land (LOTL) binaries to avoid being overwhelmed by false positives if these legitimate management tools are used regularly. See the joint guide, Identifying and Mitigating Living Off the Land Techniques, for guidance on developing a multifaceted cybersecurity strategy that enables behavior analytics, anomaly detection, and proactive hunting, which are part of a comprehensive approach to mitigating cyber threats that employ LOTL techniques.
Malicious scripts
Certipy – An open source python tool for enumerating and abusing Active Directory Certificate Services
Get-GPPPassword.py – An open source python script for finding insecure passwords stored in Group Policy Preferences
ldap-dump.py – A script for enumerating user accounts and other information in Active Directory
Hikvision backdoor string: “YWRtaW46MTEK”
Suspicious command lines
While the following utilities are legitimate, and using them with the command lines shown may also be legitimate, these command lines are often used during malicious activities and could be an indication of a compromise:
edge.exe “-headless-new -disable-gpu”
ntdsutil.exe “activate instance ntds” ifm “create full C:temp[a-z]{3}” quit quit
Disclaimer: These IP addresses date June 2024 through August 2024. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.
June 2024
July 2024
August 2024
192[.]162[.]174[.]94
207[.]244[.]71[.]84
31[.]135[.]199[.]145
79[.]184[.]25[.]198
91[.]149[.]253[.]204
103[.]97[.]203[.]29
162[.]210[.]194[.]2
31[.]42[.]4[.]138
79[.]185[.]5[.]142
91[.]149[.]254[.]75
209[.]14[.]71[.]127
46[.]112[.]70[.]252
83[.]10[.]46[.]174
91[.]149[.]255[.]122
109[.]95[.]151[.]207
46[.]248[.]185[.]236
83[.]168[.]66[.]145
91[.]149[.]255[.]19
64[.]176[.]67[.]117
83[.]168[.]78[.]27
91[.]149[.]255[.]195
64[.]176[.]69[.]196
83[.]168[.]78[.]31
91[.]221[.]88[.]76
64[.]176[.]70[.]18
83[.]168[.]78[.]55
93[.]105[.]185[.]139
64[.]176[.]70[.]238
83[.]23[.]130[.]49
95[.]215[.]76[.]209
64[.]176[.]71[.]201
83[.]29[.]138[.]115
138[.]199[.]59[.]43
70[.]34[.]242[.]220
89[.]64[.]70[.]69
147[.]135[.]209[.]245
70[.]34[.]243[.]226
90[.]156[.]4[.]204
178[.]235[.]191[.]182
70[.]34[.]244[.]100
91[.]149[.]202[.]215
178[.]37[.]97[.]243
70[.]34[.]245[.]215
91[.]149[.]203[.]73
185[.]234[.]235[.]69
70[.]34[.]252[.]168
91[.]149[.]219[.]158
192[.]162[.]174[.]67
70[.]34[.]252[.]186
91[.]149[.]219[.]23
194[.]187[.]180[.]20
70[.]34[.]252[.]222
91[.]149[.]223[.]130
212[.]127[.]78[.]170
70[.]34[.]253[.]13
91[.]149[.]253[.]118
213[.]134[.]184[.]167
70[.]34[.]253[.]247
91[.]149[.]253[.]198
70[.]34[.]254[.]245
91[.]149[.]253[.]20
Detections
Customized NTLM listener
rule APT28_NTLM_LISTENER {
meta:
description = "Detects NTLM listeners including APT28's custom one"
( any of ($sysinternals_*) and any of ($psexec_*) )
or
( 2 of ($network_*) and 2 of ($psexec_*))
)
}
The cybersecurity industry provides overlapping cyber threat intelligence, IOCs, and mitigation recommendations related to GRU unit 26165 cyber actors. While not all encompassing, the following are the most notable threat group names related under MITRE ATT&CK G0007 and commonly used within the cybersecurity community:
APT28 [14]
Fancy Bear [14]
Forest Blizzard [14]
Blue Delta [15]
Note: Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.
Further Reference
To search for the presence of malicious email messages targeting CVE-2023-23397, network defenders may consider using the script published by Microsoft: https://aka.ms/CVE-2023-23397ScriptDoc.
For the Impacket TTP, network defenders may consider using the following publicly available Impacket YARA detection rule: https://github.com/Neo23x0/signature-base/blob/master/yara/gen_impacket_tools.yar
Works Cited
[1] Microsoft. Defending Ukraine: Early Lessons from the Cyber War. 2022. https://blogs.microsoft.com/on-the-issues/2022/06/22/defending-ukraine-early-lessons-from-the-cyber-war/ [2] FBI et al. Russian Cyber Actors Use Compromised Routers to Facilitate Cyber Operations. 2024. https://media.defense.gov/2024/Feb/27/2003400753/-1/-1/0/CSA-Russian-Actors-Use-Routers-Facilitate-Cyber_Operations.PDF [3] NSA et al. Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. 2021. https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/0/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF [4] ANSSI. Campagnes d'attaques du mode opératoire APT28 depuis 2021. 2023. https://cert.ssi.gouv.fr/cti/CERTFR-2023-CTI-009/ [5] ANSSI. Targeting and compromise of french entities using the APT28 intrusion set. 2025. https://cert.ssi.gouv.fr/cti/CERTFR-2025-CTI-007/ [6] Polish Cyber Command. Detecting Malicious Activity Against Microsoft Exchange Servers. 2023. https://www.wojsko-polskie.pl/woc/articles/aktualnosci-w/detecting-malicious-activity-against-microsoft-exchange-servers/ [7] IBM. Israel-Hamas Conflict Lures to Deliver Headlace Malware. 2023. https://securityintelligence.com/x-force/itg05-ops-leverage-israel-hamas-conflict-lures-to-deliver-headlace-malware/ [8] CERT-UA. APT28: From Initial Attack to Creating Domain Controller Threats in an Hour. 2023. https://cert.gov.ua/article/6276894 [9] NSA. Embracing a Zero Trust Security Model. 2021. https://media.defense.gov/2021/Feb/25/2002588479/-1/-1/0/CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF [10] NSA et al. Keeping PowerShell: Security Measures to Use and Embrace. 2022. https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/0/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF [11] National Institute of Standards and Technology (NIST). Special Publication 800-63B: Digital Identity Guidelines – Authentication and Lifecycle Management. 2020. https://pages.nist.gov/800-63-3/sp800-63b.html [12] NSA. Selecting Secure Multi-factor Authentication Solutions. October 16, 2020. https://media.defense.gov/2024/Jul/31/2003515137/-1/-1/0/MULTIFACTOR_AUTHENTICATION_SOLUTIONS_UOO17091520.PDF [13] NSA and CSA. NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations. 2023. https://media.defense.gov/2023/Oct/05/2003314578/-1/-1/0/JOINT_CSA_TOP_TEN_MISCONFIGURATIONS_TLP-CLEAR.PDF
[14] Department of Justice. Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU). 2024. https://www.justice.gov/archives/opa/pr/justice-department-conducts-court-authorized-disruption-botnet-controlled-russian [15] Recorded Future. GRU’s BlueDelta Targets Key Networks in Europe with Multi-Phase Espionage Campaigns. 2024. https://go.recordedfuture.com/hubfs/reports/CTA-RU-2024-0530.pdf
Disclaimer of endorsement
The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.
Purpose
This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.
Contact
United States organizations
National Security Agency (NSA)
Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI)
U.S. organizations are encouraged to reporting suspicious or criminal activity related to information in this advisory to CISA via the agency’s Incident Reporting System, its 24/7 Operations Center (report@cisa.gov or 888-282-0870), or your local FBI field office. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment user for the activity; the name of the submitting company or organization; and a designated point of contact.
Department of Defense Cyber Crime Center (DC3)
United Kingdom organizations
Germany organizations
Czech Republic organizations
Poland organizations
Australian organizations
Visit cyber.gov.au or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.
Canadian organizations
Estonia organizations
French organizations
French organizations are encouraged to report suspicious activity or incident related to information found in this advisory by contacting ANSSI/CERT-FR by email at cert-fr@ssi.gouv.fr or by phone at: 3218 or +33 9 70 83 32 18.
See Table 2 through Table 14 for all the threat actor tactics and techniques referenced in this advisory.
Table 2: Reconnaissance
Tactic/Technique Title
ID
Use
Reconnaissance
TA0043
Conducted reconnaissance on at least one entity involved in the production of ICS components for railway management.
Conducted contact information reconnaissance to identify additional targets in key positions.
Gather Victim Org Information
T1591
Conducted reconnaissance of the cybersecurity department.
Gather Victim Org Information: Identify Roles
T1591.004
Conducted reconnaissance of individuals responsible for coordinating transport.
Gather Victim Org Information: Business Relationships
T1591.002
Conducted reconnaissance of other companies cooperating with the victim entity.
Gather Victim Host Information
T1592
Attempted to enumerate Real Time Streaming Protocol (RTSP) servers hosting IP cameras.
Table 3: Resource development
Tactic/Technique Title
ID
Use
Compromise Accounts: Email Accounts
T1586.002
Sent phishing emails using compromised accounts.
Compromise Accounts: Cloud Accounts
T1586.003
Sent phishing emails using compromised accounts.
Table 4: Initial Access
Tactic/Technique Title
ID
Use
Trusted Relationship
T1199
Conducted follow-on targeting of additional entities in the transportation sector that had business ties to the primary target, exploiting trust relationships to attempt to gain additional access.
Phishing
T1566
Used spearphishing for credentials and delivering malware to gain initial access to targeted entities.
Phishing: Spearphishing Attachment
T1566.001
Sent emails with malicious attachments.
Phishing: Spearphishing Link
T1566.002
Used spearphishing with included links to fake login pages. Sent emails with embedded hyperlinks that downloaded a malicious archive.
Phishing: Spearphishing Voice
T1566.004
Attempted to use voice phishing to gain access to privileged accounts by impersonating IT staff.
External Remote Services
T1133
Exploited Internet-facing infrastructure, including corporate VPNs, to gain initial access to targeted entities.
Exploit Public-Facing Application
T1190
Exploited public vulnerabilities and SQL injection to gain initial access to targeted entities.
Content Injection
T1659
Leveraged a WinRAR vulnerability allowing for the execution of arbitrary code embedded in an archive.
Table 5: Execution
Tactic/Technique Title
ID
Use
User Execution: Malicious Link
T1204.001
Used malicious links to hosted shortcuts in spearphishing.
User Execution: Malicious File
T1204.002
Delivered malware executables via spearphishing.
Scheduled Task/Job: Scheduled Task
T1053.005
Used scheduled tasks to establish persistence.
Command and Scripting Interpreter
T1059
Delivered scripts in spearphishing. Executed arbitrary shell commands.
Command and Scripting Interpreter: PowerShell
T1059.001
PowerShell commands were often used to prepare data for exfiltration.
Command and Scripting Interpreter: Windows Command Shell
T1059.003
Used BAT script in spearphishing.
Command and Scripting Interpreter: Visual Basic
T1059.005
Used VBScript in spearphishing.
Command and Scripting Interpreter: Python
T1059.006
Installed python on infected machines to enable the execution of Certipy.
Enrolled compromised accounts in MFA mechanisms to increase the trust-level of compromised accounts and enable sustained access.
Hijack Execution Flow: DLL Search Order Hijacking
T1574.001
Used DLL search order hijacking to facilitate malware execution.
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
T1547.001
Used run keys to establish persistence.
Boot or Logon Autostart Execution: Shortcut Modification
T1547.009
Placed malicious shortcuts in the startup folder to establish persistence.
Table 7: Defense Evasion
Tactic/Technique Title
ID
Use
Indicator Removal: Clear Windows Event Logs
T1070.001
Deleted event logs through the wevtutil utility.
Table 8: Credential access
Tactic/Technique Title
ID
Use
Brute Force
Sent requests with Base64-encoded credentials for the RTSP server, which included publicly documented default credentials, and likely were generic attempts to brute force access to the devices.
Brute Force: Password Guessing
T1110.001
Used credential guessing to gain initial access to targeted entities.
Brute Force: Password Spraying
T1110.003
Used brute force to gain initial access to targeted entities. Conducted a brute force password spray via LDAP.
Multi-Factor Authentication Interception
Used multi-stage redirectors to provide MFA relaying capabilities in some campaigns.
Input Capture
Used multi-stage redirectors to provide CAPTCHA relaying capabilities in some campaigns.
Forced Authentication
Used an Outlook NTLM vulnerability to collect NTLM hashes and credentials via specially crafted Outlook calendar appointment invitations.
OS Credential Dumping: NTDS
T1003.003
Attempted to dump Active Directory NTDS.dit domain databases.
Unsecured Credentials: Group Policy Preferences
T1552.006
Retrieved plaintext passwords via Group Policy Preferences using Get-GPPPassword.py.
Table 9: Discovery
Tactic/Technique Title
ID
Use
Account Discovery: Domain Account
T1087.002
Used a modified ldap-dump.py to enumerate the Windows environment.
Table 10: Command and Control
Tactic/Technique Title
ID
Use
Hide Infrastructure
T1665
Abused SOHO devices to facilitate covert cyber operations, as well as proxy malicious activity, via devices with geolocation in proximity to the target.
Proxy: External Proxy
T1090.002
Actor-controlled servers sent RTSP DESCRIBE requests destined for RTSP servers.
Proxy: Multi-hop Proxy
T1090.003
Used Tor and commercial VPNs as part of their anonymization infrastructure
Encrypted Channel
T1573
Connected to victim infrastructure using encrypted TLS.
Multi-Stage Channels
T1104
Used multi-stage redirectors for campaigns.
Table 11: Defense evasion (mobile framework)
Tactic/Technique Title
ID
Use
Execution Guardrails
Used multi-stage redirectors to verify browser fingerprints in some campaigns.
Execution Guardrails: Geofencing
T1627.001
Used multi-stage redirectors to verify IP-geolocation in some campaigns.
Table 12: Lateral movement
Tactic/Technique Title
ID
Use
Lateral Movement
Used native commands and open source tools, such as Impacket and PsExec, to move laterally within the environment.
Remote Services: Remote Desktop Protocol
T1021.001
Moved laterally within the network using RDP.
Table 13: Collection
Tactic/Technique Title
ID
Use
Email Collection
Retrieved sensitive data from email servers.
Email Collection: Remote Email Collection
T1114.002
Used server data exchange protocols and APIs such as Exchange Web Services (EWS) and IMAP to exfiltrate data from email servers.
Automated Collection
Used periodic EWS queries to collect new emails.
Video Capture
Attempted to gain access to the cameras’ feeds.
Archive Collected Data
Accessed files were archived in .zip files prior to exfiltration.
Archive Collected Data: Archive via Utility
T1560.001
Prepared zip archives for upload to the actors’ infrastructure.
Table 14: Exfiltration
Tactic/Technique Title
ID
Use
Exfiltration Over Alternative Protocol
Attempted to exfiltrate archived data via a previously dropped OpenSSH binary.
Scheduled Transfer
Used periodic EWS queries to collect new emails sent and received since the last data exfiltration.
Appendix B: CVEs exploited
Table 15: Exploited CVE information
CVE
Vendor/Product
Details
CVE-2023-38831
RARLAB WinRAR
Allows execution of arbitrary code when a user attempts to view a benign file within a ZIP archive.
CVE-2023-23397
Microsoft Outlook
External actors could send specially crafted emails that cause a connection from the victim to an untrusted location of the actor’s control, leaking the Net-NTLMv2 hash of the victim that the actor could then relay to another service to authenticate as the victim.
CVE-2021-44026
Roundcube Webmail
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search params.
CVE-2020-35730
Roundcube Webmail
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16 and 1.4.x before 1.4.10, where a plaintext email message with JavaScript in a link reference element is mishandled by linkref_addindex in rcube_string_replacer.php.
CVE-2020-12641
Roundcube Webmail
Roundcube Webmail before 1.4.4 allows arbitrary code execution via shell metacharacters in a configuration setting for im_convert_path or im_identify_path in rcube_image.php.
Appendix C: MITRE D3FEND Countermeasures
Table 16: MITRE D3FEND countermeasures
Countermeasure Title
ID
Details
Network Isolation
Employ appropriate network segmentation. Disable Universal Plug and Play (UPnP), Peer-to-Peer (P2P), and Anonymous Visit features on IP cameras and routers.
Access Mediation
Limit access and utilize additional attributes (such as device information, environment, and access path) when making access decisions. Configure access controls carefully to ensure that only well-maintained and well-authenticated accounts have access.
Inbound Traffic Filtering
Implement host firewall rules to block connections from other devices on the network, other than from authorized management devices and servers, to prevent lateral movement.
Resource Access Pattern Analysis
Use automated tools to audit access logs for security concerns and identify anomalous access requests.
Outbound Traffic Filtering
Block NTLM/SMB requests to external infrastructure.
Platform Monitoring
Install EDR/logging/cybersecurity solutions onto high value systems with large amounts of sensitive data such as mail servers and domain controllers.
System File Analysis
Collect and monitor Windows logs for certain events, especially for events that indicate that a log was cleared unexpectedly.
Application Hardening
Enable optional security features in Windows to harden endpoints and mitigate initial access techniques.
Application-based Process Isolation
Enable attack surface reduction rules to prevent executable content from email.
Executable Allowlisting
Enable attack surface reduction rules to prevent execution of files from globally writeable directories, such as Downloads or %APPDATA%.
Execution Isolation
Unless users are involved in the development of scripts, limit the execution of scripts (such as batch, JavaScript, and PowerShell) to known scripts.
Application Configuration Hardening
Disable Windows Host Scripting functionality and configure PowerShell to run in Constrained mode. Disable protocols that use weak authentication (e.g., clear-text passwords, or outdated and vulnerable authentication or encryption protocols) or do not support multi-factor authentication. Turn off other ports/services not in use (e.g., FTP, web interface, etc.).
Process Spawn Analysis
Use open source SIGMA rules as a baseline for detecting and alerting on suspicious file execution or command parameters.
URL Reputation Analysis
Use services that provide enhanced browsing services and safe link checking.
Network Access Mediation
Do not allow incoming traffic, especially logins to systems, from public VPN services. Where possible, logins from public VPNs, including exit nodes in the same country as target systems, should be blocked or, if allowed, alerted on for further investigation. Ensure cameras and other Internet of Things devices are protected by a security appliance, if possible.
DNS Denylisting
D3-DNSDL
Do not allow outgoing traffic to hosting and API mocking services frequently used by malicious actors.
Domain Name Reputation Analysis
Heuristic detections for web requests to new subdomains may uncover malicious phishing activity. Logging the requests for each sub-domain requested by users on a network, such as in DNS or firewall logs, may enable system administrators to identify new targeting and victims.
Multi-factor Authentication
Use MFA with strong factors and require regular re-authentication, especially for management accounts.
Job Function Access Pattern Analysis
D3-JFAPA
Implement other mitigations for privileged accounts: including limiting the number of admin accounts, considering using hardware MFA tokens, and regularly reviewing all privileged user accounts.
User Account Permissions
Separate privileged accounts by role and alert on misuse of privileged accounts. Audit user accounts on all devices to ensure they are an accurate reflection of your organization and that they are being used as expected.
Token-based Authentication
Reduce reliance on passwords; instead, consider using services like single sign-on.
Credential Hardening
Do not store passwords in Group Policy Preferences (GPP). Remove all passwords previously included in GPP and change all passwords on the corresponding accounts.
Authentication Event Threshholding
Use account throttling or account lockout. Throttling progressively increases time delay between successive login attempts. If using account lockout, allow between 5 to 10 attempts before lockout.
Strong Password Policy
Use a service to check for compromised passwords before using them.
Credential Rotation
Change all default credentials.
Encrypted Tunnels
Disable protocols that use weak authentication (e.g., clear-text passwords, or outdated and vulnerable authentication or encryption protocols). Use a VPN for remote connections to devices.
Software Update
Apply security patches and firmware updates to all devices. Ensure devices are currently supported. Replace devices that are end-of-life.
Agent Authentication
Ensure authentication is enabled for remote access to devices. If supported on IP cameras, enable authenticated RTSP access only.
User Behavior Analysis
Review all authentication activity for remote access to make sure it is valid and expected. Investigate any unexpected or unusual activity.
News In Brief – Source: US Computer Emergency Readiness Team
Today, CISA, the National Security Agency, the Federal Bureau of Investigation, and other U.S. and international partners released a joint Cybersecurity Advisory, Russian GRU Targeting Western Logistics Entities and Technology Companies.
This advisory details a Russian state-sponsored cyber espionage-oriented campaign targeting technology companies and logistics entities, including those involved in the coordination, transport, and delivery of foreign assistance to Ukraine.
Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center, military unit 26165 cyber actors are using a mix of previously disclosed tactics, techniques, and procedures (TTPs) and are likely connected to these actors’ widescale targeting of IP cameras in Ukraine and bordering NATO nations.
Executives and network defenders at logistics entities and technology companies should recognize the elevated threat of until 26165 targeting, increase monitoring and threat hunting for known TTPs and indicators of compromise, and posture network defenses with a presumption of targeting. For more information on Russian state-sponsored threat actor activity, see CISA’s Russia Cyber Threat Overview and Advisories page.
Montpelier, Vt. – Governor Phil Scott announced action on the following bills, passed by the General Assembly.
On May 21, Governor Scott signed bills of the following titles:
H.398, An act relating to the Vermont Economic Development Authority
H.493, An act relating to making appropriations for the support of the government
S.44,An act relating to authorization to enter into certain immigration agreements
S.56,An act relating to creating an Office of New Americans
When signing H.493, Governor Scott sent the following letter to the General Assembly:
Dear Ms. Wrask:
Today, I’m signing H.493, An act relating to making appropriations for the support of government.
I appreciate that this budget makes important affordability investments – most notably the $77 million general fund transfer to the education fund to help stabilize property taxes this year, and $13.5 million in much needed, targeted tax relief for young families, lower income, working Vermonters and seniors on fixed incomes.
However, affordability must also be about getting state government and public education on a sustainable fiscal path; fixing systemic policy issues that make homebuilding, homeownership and rent far too expensive; and keeping and attracting the workers and employers we need for a strong economy. While I can support this budget, we have not yet done nearly enough to address these other areas.
Specifically, although this budget spends $30 million less in general fund base compared to the Senate version, it still spends $20 million more than my proposal. It also creates roughly 70 unique one-time appropriations. Neither would be sustainable under a more modest – and typical – revenue environment.
Outside of the budget, we must complete the work to transform our education system, starting with H.454, An act relating to transforming Vermont’s education governance, quality and finance systems. I proposed the $77 million transfer in the budget as a bridge to a structurally transformed and fiscally efficient public education system in the near term.
We need to follow through on reform.
And I urge the Legislature to pass the housing legislation I proposed at the start of the session so the housing Vermonters so desperately need can be built.
While not perfect, H.493 makes critical investments in affordability, housing, education and public safety. But we must focus on the policy bills that fix what’s broken so the funding can have its intended impact.
Sincerely,
/s/
Philip B. Scott
Governor
To view a complete list of action on bills passed during the 2025 legislative session,click here.
Lt. Gov. Luke – VNR – Hawaiʻi Schools Win ‘Super Sleuth’ Award in Internet Speeds Mapping Effort
Posted on May 20, 2025 in Latest Department News, Newsroom
STATE OF HAWAIʻI KA MOKU ʻĀINA O HAWAIʻI
SYLVIA LUKE LIEUTENANT GOVERNOR KE KEʻENA O KA HOPE KIAʻĀINA
FOR IMMEDIATE RELEASE
May 20, 2025
Hawaiʻi Schools Win ‘Super Sleuth’ Award in Internet Speeds Mapping Effort
Connect Kākou’s Digital Detectives Initiative included 6,000 participants statewide
Lt. Gov. Luke with Robert Louis Stevenson Middle School (left) and Kona Pacific Charter School (right).
(Videos/Photos Courtesy: Connect Kākou)
HONOLULU – Lieutenant Governor Sylvia Luke announced today that more than 6,000 Hawaiʻi residents, many of them students, participated in the Digital Detectives campaign to map internet speeds across the state. Part of the Connect Kākou initiative, Digital Detectives aimed to close the digital divide by identifying areas in need of urgent broadband infrastructure improvements.
By taking a simple 30-second internet speed test last October, residents provided valuable data to help ensure federal funding is directed where it is most needed. Classes from Robert Louis Stevenson Middle School and Kona Pacific Charter School received the top Digital Detectives Super Sleuth Awards for student participation and classroom reporting. The classes received a visit from Lieutenant Governor Luke and a gift card for classroom supplies.
“Thanks to the thousands of students and their teachers who participated in Digital Detectives, we now have a clearer picture of Hawaiʻi’s internet speeds and where improvements are most needed,” said Lieutenant Governor Luke. “Reliable internet is crucial for education, future careers, and so much more. We were thrilled to see so many students taking part in shaping a more connected future for our state.
“Digital Detectives encouraged our students to become active participants in expanding internet access for their communities,” said Ken Hiraki, executive director of the Public Schools Foundation. “By turning a simple classroom activity into meaningful data for our state, students had a front row seat to civic engagement and real-world impact.”
Results from the internet speed tests have been aggregated to provide a more comprehensive view of connectivity across the state. Construction of fiber-optic internet lines in underserved areas is expected to begin as early as this year.
Connect Kākou is a State of Hawai‘i initiative led by Lieutenant Governor Luke, in collaboration with the Hawai‘i Broadband and Digital Equity Office (HBDEO), the University of Hawai‘i, the Department of Hawaiian Home Lands (DHHL), and multiple state and county agencies. Connect Kākou is working to ensure people from all walks of life have reliable access to high-speed internet and the tools and knowledge to safely and confidently use the internet. Visit www.connectkakou.org to learn more.
DBEDT NEWS RELEASE: HAWAI‘I APRIL UNEMPLOYMENT RATE REMAINS AT 2.9 PERCENT
Posted on May 20, 2025 in Latest Department News, Newsroom
STATE OF HAWAIʻI
KA MOKU ʻĀINA O HAWAIʻI
JOSH GREEN, M.D. GOVERNOR
KE KIAʻĀINA
DEPARTMENT OF BUSINESS, ECONOMIC DEVELOPMENT ANDTOURISM
KA ʻOIHANA HOʻOMOHALA PĀʻOIHANA, ʻIMI WAIWAI A HOʻOMĀKAʻIKAʻI
RESEARCH AND ECONOMIC ANALYSIS DIVISION
JAMES KUNANE TOKIOKA
DIRECTOR
KA LUNA HOʻOKELE
EUGENE TIAN
CHIEF STATE ECONOMIST
HAWAI‘I APRIL UNEMPLOYMENT RATE REMAINS AT 2.9 PERCENT
Jobs Increased by 17,000 Year-Over-Year
FOR IMMEDIATE RELEASE
May 20, 2025
HONOLULU — The Hawai‘i State Department of Business, Economic Development and Tourism (DBEDT) today announced that the seasonally adjusted unemployment rate for April was 2.9 percent, the same as in March. In April, 668,650 persons were employed and 19,650 were unemployed, for a total seasonally adjusted labor force of 688,300 statewide. Nationally, the seasonally adjusted unemployment rate was 4.2 percent in April, the same as in March.
The unemployment rate figures for the state of Hawai‘i and the U.S. in this release are seasonally adjusted in accordance with U.S. Bureau of Labor Statistics (BLS) methodology. The not-seasonally adjusted rate for the state was 2.5 percent in April, compared to 2.4 percent in March.
Industry Payroll Employment (Establishment Survey)
In a separate measure of employment, total nonagricultural jobs increased by 1,500 month-over-month, from March 2025 to April 2025. Job gains were experienced in Leisure & Hospitality (+1,900); Private Education & Health Services (+1,100); Trade, Transportation & Utilities (+500); Professional & Business Services (+400); Construction (+300); and Information (+100). Within Leisure & Hospitality, the rise in employment primarily occurred in Food Services & Drinking Places. Within Private Education & Health Services, the bulk of job gains were spread out over the subsectors of Health Care & Social Assistance. Employment in Manufacturing remained unchanged. Job losses occurred in Financial Activities (-200); and Other Services (-200). Government employment went down by 2,400 jobs, primarily due to below average over-the-month change in staffing at both the Department of Education and the University of Hawai‘i system. Year-over-year, nonfarm jobs have gone up by 17,000, or 2.7 percent.
Technical Notes:
Labor Force Components
The concepts and definitions used by the Local Area Unemployment Statistics (LAUS) program are the same as those used in the Current Population Survey for the national labor force data:
Civilian labor force. Included are all persons in the civilian noninstitutional population ages 16 and older classified as either employed or unemployed. (See the definitions below.)
Employed persons. These are all persons who, during the reference week (the week including the twelfth day of the month), (a) did any work as paid employees, worked in their own business or profession or on their own farm, or worked 15 hours or more as unpaid workers in an enterprise operated by a member of their family, or (b) were not working but who had jobs from which they were temporarily absent because of vacation, illness, bad weather, childcare problems, maternity or paternity leave, labor-management dispute, job training, or other family or personal reasons, whether or not they were paid for the time off or were seeking other jobs. Each employed person is counted only once, even if he or she holds more than one job.
Unemployed persons. Included are all persons who had no employment during the reference week, were available for work, except for temporary illness and had made specific efforts to find employment sometime during the four-week period ending with the reference week. Persons who were waiting to be recalled to a job from which they had been laid off need not have been looking for work to be classified as unemployed.
Unemployment rate. The unemployed percent of the civilian labor force [i.e., 100 times (unemployed/civilian labor force)].
Seasonal Adjustment
The seasonal fluctuations in the number of employed and unemployed persons reflect hiring and layoff patterns that accompany regular events such as the winter holiday season and the summer vacation season. These variations make it difficult to tell whether month-to-month changes in employment and unemployment are due to normal seasonal patterns or to changing economic conditions. Therefore, the BLS uses a statistical technique called seasonal adjustment to address these issues. This technique uses the history of the labor force data and the job count data to identify the seasonal movements and to calculate the size and direction of these movements. A seasonal adjustment factor is then developed and applied to the estimates to eliminate the effects of regular seasonal fluctuations on the data. Seasonally adjusted statistical series enable more meaningful data comparisons between months or with an annual average.
Current Population (Household) Survey (CPS)
A survey conducted for employment status in the week that includes the twelfth day of each month generates the unemployment rate statistics, which is a separate survey from the Establishment Survey that yields the industry job counts. The CPS survey contacts approximately 1,000 households in Hawai‘i to determine an individual’s current employment status. Employed persons consist of 1) all persons who did any work for pay or profit during the survey reference week, 2) all persons who did at least 15 hours of unpaid work in a family owned enterprise operated by someone in their household and 3) all persons who were temporarily absent from their regular jobs, whether they were paid or not. Persons considered unemployed are those that do not have a job, have actively looked for work in the prior four weeks and are available for work. Temporarily laid-off workers are counted as unemployed, whether or not they have engaged in a specific job-seeking activity. Persons not in the labor force are those who are not classified as employed or unemployed during the survey reference week.
Benchmark Changes to Local Area Unemployment Statistics Data
Statewide and sub-state data for 2019 to 2024 have revised inputs and data for 1990 to 2024 have been re-estimated to reflect revised population controls and model re-estimation.
Change to Monthly Employment Estimates
This release incorporates revised job count figures for the seasonally adjusted series. The revised data reflects historical corrections applied to unadjusted super sector or sector-level series dating back from 2018 through 2024. For years, analysts with the state of Hawai‘i Department of Labor and Industrial Relations Research and Statistics Office have developed monthly employment estimates for Hawai‘i and its metropolitan areas. These estimates were based on a monthly survey of Hawai‘i businesses and analysts’ knowledge about our local economies. Beginning with the production of preliminary estimates for March 2011, responsibility for the production of state and metropolitan area (MSA) estimates were transitioned from individual state agencies to the U.S. Bureau of Labor Statistics (BLS).
For Hawai‘i, this means the transition of statewide, Honolulu and Kahului-Wailuku MSA estimates for both the seasonally adjusted and not-seasonally adjusted areas are produced by BLS. State agencies will continue to provide the BLS with information on local events that may affect the estimates, such as strikes or large layoffs/hiring at businesses not covered by the survey and to disseminate and analyze the Current Employment Statistics (CES) estimates for local data users. BLS feels this change is designed to improve the cost efficiency of the CES program and to reduce the potential bias in state and area estimates. A portion of the cost savings generated by this change is slated to be directed toward raising survey response rates in future years, which will decrease the level of statistical error in the CES estimates. Until then, state analysts feel this change could result in increased month-to-month variability for the industry employment numbers, particularly for Hawai‘i’s counties and islands. BLS can be reached at 202-691-6555 for any questions about these estimates.
The not-seasonally adjusted job estimates for Hawai‘i County, Kaua‘i County, Maui, Moloka‘i and Lāna‘i are produced by the state of Hawai‘i Department of Business, Economic Development and Tourism.
Labor Force Estimates for Small Areas
Labor Force estimates for the islands within Maui County (Maui, Moloka‘i and Lānai) are produced by the state of Hawai‘i Department of Business, Economic Development and Tourism.
Seasonally Adjusted Labor Force and Unemployment Estimates for Honolulu and Maui County
BLS publishes smoothed seasonally adjusted civilian labor force and unemployment estimates for all metropolitan areas, which includes the City and County of Honolulu and Maui County.
BLS releases this data each month in the Metropolitan Area Employment and Unemployment news release. The schedule is available at http://www.bls.gov/news.release/metro.toc.htm.
Alternative Measures of Labor Underutilization
Alternative Measures of Labor Underutilization for States, Second Quarter of 2024 through First Quarter of 2025 Averages
Area
Measure
U-1
U-2
U-3
U-4
U-5
U-6
United States
1.5
2.0
4.1
4.3
5.0
7.7
Hawai‘i
0.7
1.2
3.0
3.1
3.9
6.2
The six alternative labor underutilization state measures based on the Current Population Survey (CPS) and compiled on a four-quarter moving-average basis defined as:
U-1, persons unemployed 15 weeks or longer, as a percent of the civilian labor force;
U-2, job losers and persons who completed temporary jobs, as a percent of the civilian labor force;
U-3, total unemployed, as a percent of the civilian labor force (this is the definition used for the official unemployment rate);
U-4, total unemployed plus discouraged workers, as a percent of the civilian labor force plus discouraged workers;
U-5, total unemployed, plus discouraged workers, plus all other marginally attached workers*, as a percent of the civilian labor force plus all marginally attached workers; and
U-6, total unemployed, plus all marginally attached workers, plus total employed part-time for economic reasons, as a percent of the civilian labor force plus all marginally attached workers.
*Individuals who want and are available for work, and who have looked for a job sometime in the prior 12 months (or since the end of their last job if they had one within the past 12 months) but were not counted as unemployed because they had not searched for work in the four weeks preceding the survey, for such reasons as childcare or transportation problems, for example. Discouraged workers are a subset of the marginally attached.
Please note that the state unemployment rates (U-3) that are shown are derived directly from the CPS. As a result, these U-3 measures may differ from the official state unemployment rates for the latest four-quarter period. The latter are estimates developed from statistical models that incorporate CPS estimates, as well as input data from other sources, such as state unemployment claims data.
# # #
Media contacts:
Dr. Eugene Tian
Chief State Economist
Research and Economic Analysis Division
Department of Business, Economic Development and Tourism, State of Hawai‘i
Phone: 808-586-2470
Email: [email protected]
Laci Goshi
Communications Officer
Department of Business, Economic Development and Tourism, State of Hawai‘i
DLNR News Release – ADDITIONAL TEMPORARY CLOSURES AT DIAMOND HEAD STATE MONUMENT IN JUNE, May 20, 2025
Posted on May 20, 2025 in Latest Department News, Newsroom
STATE OF HAWAIʻI
KA MOKUʻĀINA O HAWAIʻI
JOSH GREEN, M.D.
GOVERNOR
KE KIAʻĀINA
DEPARTMENT OF LAND AND NATURAL RESOURCES
KA ‘OIHANA KUMUWAIWAI ‘ĀINA
DAWN N.S. CHANG
CHAIRPERSON
KA LUNA HOʻOKELE
ADDITIONAL TEMPORARY CLOSURES AT DIAMOND HEAD STATE MONUMENT IN JUNE
FOR IMMEDIATE RELEASE
May 20, 2025
HONOLULU – More full-day closures are forthcoming to Diamond Head State Monument (DHSM) next month. The DLNR Division of State Parks (DSP) announces park closures for ongoing rockfall mitigation work from June 17-20 and 24-27 at the popular O‘ahu landmark.
During these full closures, access to the park will be restricted and no visitors will be allowed entry. Employees will access the crater via the Kapahulu Tunnel between 6 a.m. and 6 p.m. A guard will be stationed at the entry gate leading to the tunnel for the duration of the closures.
On Monday June 16 and 23, the park will maintain its current partial closure hours from 6 a.m. – 2 p.m. All other days in June will continue with the current schedule: weekdays with closure at 2 p.m. and weekends with closure at 6 p.m.
DSP appreciates the patience of residents and visitors through this process to create a safer, more enjoyable experience at Diamond Head. The estimated project completion date is July 25, 2025.
# # #
RESOURCES
(All images/video courtesy: DLNR)
HD Video – Diamond Head rockfall mitigation project (February 7, 2025):
Source: United States Senator for New Hampshire Maggie Hassan
WASHINGTON – U.S. Senator Maggie Hassan (D-NH), Ranking Member of the Senate Finance Subcommittee on Health, responded to a new analysis from the non-partisan Congressional Budget Office finding that the plan put forward by President Trump and Congressional Republicans to give corporate special interests and billionaires a tax break increases the deficit by $2.3 trillion, which will trigger a $490 billion automatic cut to Medicare over the next 10 years.
“Seniors pay into Medicare their entire life, based on the promise that it will provide them with health care when they retire. It is absolutely ridiculous that Republicans want to take hundreds of billions of dollars away from Medicare in order to provide more tax giveaways to corporate special interests and billionaires,” said Senator Hassan, Ranking Member of the Senate Finance Subcommittee on Health. “At a time when we should be working to make health care more affordable, Congressional Republicans instead continue to push ahead with this partisan tax giveaway paid for by exploding the deficit and cutting Medicare, Medicaid, and Affordable Care Act, which will only increase health care costs for millions of Americans across the country.”
The non-partisan Congressional Budget Office analysis finds that because the Congressional Republican plan increases the deficit by $2.3 trillion, it will trigger automatic cuts of $490 billion to Medicare. More than 60 million American seniors are enrolled in Medicare. An additional recent non-partisan analysis of the Republican tax plan finds that the legislation will also result in 13.7 million Americans losing their health insurance by 2034 because of proposed cuts to Medicaid and the Affordable Care Act.
Source: United States Senator for Commonwealth of Virginia Mark R Warner
WASHINGTON – U.S. Sens. Mark R. Warner (D-VA), Tim Kaine (D-VA), and Michael Bennet (D-CO) issued the statement below after the Department of Defense (DoD) announced immediate modifications to the military’s broken moving system, which handles servicemember relocations. These modifications follow close advocacy by the senators, who have pushed for months to address the delays, poor communication, and repeated issues under the Global Household Goods Contract.
“Military members and their families sacrifice so much in service to our country, including every time they relocate and integrate into a new community. After pushing for months, we’re pleased to see the Department of Defense move to address ongoing challenges with the contract tasked with moving household goods for military members and families in the process of relocating.
“As these policy changes are implemented, we will continue to work with the Department of Defense and TRANSCOM to ensure that servicemembers and military families who are already well into the relocation process are not left in the lurch. Additionally, as these shifts put more pressure on federal employees to adapt to this change, we will continue to push for adequate federal staffing levels and against Trump’s senseless hiring freeze, which continues to prevent critical positions from being filled across government.”
In February, Sen. Warner requested a briefing from USTRANSCOM and sounded the alarm about missed household goods pickups, delivery issues, and communication difficulties with HomeSafe Alliance, the contractor responsible for the moves. Earlier this month, the lawmakers raised their concerns, reiterating the ongoing delays and confusion being faced by military families, and requesting additional information from TRANSCOM on its plan to address these issues.