Policy & Government
Pentagon Suspends CMMC Phase 2 Requirements for Defense Contractors
A CMMC-framework pause from the Pentagon — defense-contractor compliance work re-scoped this week.
Policy & Government
A CMMC-framework pause from the Pentagon — defense-contractor compliance work re-scoped this week.
Policy & Government
A US Treasury sanctions package targeting VPN and cryptor infrastructure that reportedly supports ransomware — regulatory coverage this week.
Vulnerabilities
A message-queue vulnerability with OAuth and multi-tenancy implications — defender review for RabbitMQ deployments this week.
Vulnerabilities
A seven-flaw Avi Load Balancer patch cycle from VMware — defender verification this week.
Vulnerabilities
Two Joomla-extension zero-days under active attack — Joomla operators accelerate patch verification this week.
Vulnerabilities
Two SonicWall SMA zero-days under active attack — immediate defender posture review this week.
Vulnerabilities
Adobe's ColdFusion patch cycle continues — defender verification across deployments this week.
Vulnerabilities
A CVSS 9.9 NetWeaver ABAP flaw anchors SAP's critical patch cycle — defender verification across products this week.
Vulnerabilities
Eleven old Microsoft-signed shims land as bypasses of Secure Boot — Linux-boot defender review this week.
Vulnerabilities
A decade-old Secure Boot revelation — lifecycle-security implications for defender teams this week.
Vulnerabilities
A SharePoint JWT auth bypass patched in July's Patch Tuesday — defender verification this week.
Vulnerabilities
Microsoft's July Patch Tuesday breaks its own record — 622 CVEs, two zero-days under active attack, and defender triage stakes rise this week.