CGA Weekly · Threat Intelligence

Monday Threat Intelligence

Weekly coverage of cybersecurity incidents, vulnerabilities, and compliance developments relevant to defense contractors and businesses navigating CMMC, NIST SP 800-171, and federal supply chain requirements.

Active Threats Critical CVEs Compliance Updates DIB Supply Chain
Latest Issue
Latest September 1, 2026

August Roundup 2026

The CMMC Reform Task Force's RFI window closes with no word from DoD, a pre-auth Kiteworks Secure File Gateway RCE gets exploited within days of disclosure, ransomware holds near its 2026 highs, and CGA splits its Gap Assessment Grant into separate Level 1 and Level 2 tracks.

Read this issue →
Previous Issues
August 1, 2026
July Roundup 2026
DoD suspends the CMMC Phase 2 third-party certification requirement, Microsoft ships a record-breaking 570-CVE Patch Tuesday, Clop affiliates exploit PTC's Windchill PLM software across the aerospace and defense supply chain, and ransomware climbs to its second-highest month of 2026.
Read →
July 1, 2026
June Roundup 2026
761 ransomware incidents hold at record pace, critical VMware vCenter and Microsoft zero-days exploited in the wild, Volt Typhoon persists in U.S. defense infrastructure, and CMMC Phase 2 enforcement now under five months away.
Read →
June 1, 2026
May Roundup 2026
748 ransomware incidents, Palo Alto PAN-OS zero-day, Chinese DIB supply chain targeting, and CMMC Phase 2 under six months away
Read →
May 1, 2026
April Roundup 2026
Record ransomware, CVSS 10.0 Cisco zero-day, Canvas LMS breach, and CMMC updates
Read →
April 1, 2026
March Roundup 2026
Top incidents, vulnerabilities, and CMMC compliance updates
Read →
March 3, 2026
February Roundup 2026
Ransomware surges and CMMC 2.0 updates
Read →
February 3, 2026
January Roundup 2026
New year threats targeting the DIB
Read →
January 6, 2026
December Roundup 2025
Year-end CVEs and compliance shifts
Read →
December 3, 2025
November Roundup 2025
Supply chain risks and patch alerts
Read →
November 1, 2025
October Roundup 2025
APT activity and federal advisories
Read →
October 27, 2025
27 October 2025
Critical exploits and NIST guidance
Read →
October 20, 2025
20 October 2025
Ransomware trends and new CVE alerts
Read →
October 13, 2025
13 October 2025
Active threats and compliance news
Read →
October 6, 2025
6 October 2025
Inaugural issue: DIB threat briefing
Read →

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.

View Grant Programs