Monthly Threat Intelligence
Monthly Threat Intelligence
Monthly coverage of cybersecurity incidents, vulnerabilities, and compliance developments relevant to defense contractors and businesses navigating CMMC, NIST SP 800-171, and federal supply chain requirements.
- Active Threats
- Critical CVEs
- Compliance Updates
- DIB Supply Chain
Latest Issue
Latest
September Roundup 2026
September 2026 in six bites: MFA bypass phishing, a poisoned website widget, a saved password breach, a record Patch Tuesday, firewall flaws, and CMMC.
Previous Issues
August Roundup 2026
Metabase and N-able N-central were exploited in the wild, Microsoft patched a zero-day attackers were already using, and CMMC Phase 2 was suspended for review. Six bites for small businesses and defense suppliers, each with one thing to do.
July Roundup 2026
July 2026 in seven bites: CMMC Phase 2 suspended, a supply chain order, PLM data theft, a record Patch Tuesday, and ransomware hitting production.
June Roundup 2026
June 2026 in six bites: Check Point VPN, PTC Windchill, UniFi and SimpleHelp flaws under attack, ransomware claims, and where CMMC stood.
May Roundup 2026
May 2026 in six bites: two exploited Palo Alto firewall flaws, an Exchange email flaw, a poisoned DAEMON Tools installer, ransomware claims, and CMMC.
April Roundup 2026
Seven bites from April 2026: Iranian-affiliated PLC attacks, exploited Fortinet and Cisco flaws, a SharePoint zero-day, the Vercel OAuth breach, Axios and cPanel.
March Roundup 2026
Six bites from March 2026: the Tycoon 2FA takedown, a Cisco firewall zero-day used by ransomware, NetScaler, a poisoned Trivy release and exploited AI workflow tools.
February Roundup 2026
Six bites from February 2026: Windows zero-days, ransomware on remote support tools, a Cisco SD-WAN emergency directive, a payment outage and a hijacked updater.
January Roundup 2026
January 2026 in six bites: ransomware crews stealing design files, a federal contractor breach, Fortinet and Office flaws, and where CMMC stood.
December Roundup 2025
December 2025 in six bites: React2Shell, exploited Fortinet and WatchGuard firewalls, a Windows zero-day, an insider breach, and vendor account risks.
November Roundup 2025
November 2025 in seven bites: CMMC Phase 1 begins, the Akira ransomware advisory, exploited Windows and FortiWeb flaws, and two vendor breaches.
October Roundup 2025
Ten sourced October 2025 items: F5 BIG-IP, VMware, Oracle EBS, Conduent, Qilin, Akira, and the ransomware payment rate.
27 October 2025
WSUS emergency patch, CoPhish OAuth phishing, LastPass death-claim emails, and the 183 million credential set, each with its source.
20 October 2025
F5 BIG-IP exposure, Adobe AEM Forms, October Patch Tuesday, and the Prosper and SimonMed breaches, each with its source.
13 October 2025
Four sourced items from the week of October 6, 2025: Oracle E-Business Suite on CISA's list, SonicWall's backup scope, and new exploited flaws.
6 October 2025
Six sourced items from the week of September 29, 2025: Clop extortion emails on Oracle E-Business Suite, Asahi's factory shutdown, Red Hat's GitLab breach, and more.
Concerned about your cybersecurity posture?
CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.
Or email info@cybergrantsalliance.org or call +1 (888) 323-9991
