- 1Create a free account
- 2Pick your topics and platforms
- 3Read your tailored feed
- 4Ask the CMMCSimple Assistant
Get the feed your contracts depend on
Create a free account, pick your topics, and see your tailored compliance feed today.
Stay ahead of CMMC and DoD cybersecurity developments with AI-powered news aggregation, personalized updates, and source-backed answers.
Deadlines
Jacob Horne: The cyber requirements mismatch problem that DoD successfully avoided in 2024 is back on the menu th...The cyber requirements mismatch problem that DoD successfully avoided in 2024 is back on the menu thanks to the CMMC Phase 2 suspension. 📺 Watch here: https://lnkd.in/gWdYN6ys Some context: DFARS clause 252.204-7012 doesn't specify a NIST SP 800-171...
CMMC Watch · Sep 3, 2026
Ecosystem
The Cyber AB Launches New Training and Certification Subsidiary - September 28, 2022The Cyber AB — Training, Certification & Press
Ecosystem
Inaugural Certified Third-Party Assessment Organization Enters the CMMC Marketplace - June 09, 2021Ecosystem
CMMC Accreditation Body Launches Industry Advisory Council Backed by Thought Leaders from across... - April 06, 2021Deadlines
So is anything really going to happen after the 60 days or will we all be just waiting in limbo for a lot longer than that?CMMC Watch · Sep 2, 2026
CMMC Watch · Sep 2, 2026

Redspin Training & CMMC Newsroom · Sep 2, 2026
CMMC Watch · Sep 3, 2026
Chat in plain English and get answers grounded in the latest coverage, with source links. No account needed to try it. News awareness only, not legal or compliance advice.

Cyber News
Dark Reading · Nov 12, 2026

Cyber News
Dark Reading · Oct 8, 2026

Cyber News
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
BleepingComputer · Sep 8, 2026

Government Contracting
The “too close at hand” principle allows GAO or the court to find an evaluation unreasonable where an agency fails to consider past performance information it was aware of – even if that information was not in the offeror’s proposal. The principle originates from GAO’s 1997 decision in International Business Systems, Inc. , where GAO sustained a protest after finding that an agency unreasonably failed to consider past performance information that “involved the same agency, the same contracting officer, and virtually the same services” as the procurement at issue. GAO held that “some information is simply too close at hand to require offerors to shoulder the inequities that spring from an agency’s failure to obtain, and consider, the information.” Since that decision, the argument has become a common tool in protesters’ challenges to past performance evaluations, though as discussed in “ Bid Protest Pitfalls: Three Commonly Misused Arguments at GAO ,” the argument is frequently misused by protesters unfamiliar with GAO’s precedent on the issue. By 2000, the Court of Federal Claims (COFC) had also begun considering the too close at hand doctrine. For example, in Seattle Sec. Serv
Government Contracts Legal Forum · Sep 8, 2026
Cyber News
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Dark Reading · Sep 8, 2026

Defense News
Hanwha representatives said the vehicle is fitted with a more powerful version of the stationary Cheongwang laser that protects the presidential compound.
Defense News · Sep 8, 2026

Cyber News
On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it without checking those dependencies and the security team may cause the outage it intended to prevent. That is the implementation problem inside joint cybersecurity advisory AA26-231A , issued on August 19 by the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency. The agencies warn of active targeting of Siemens S7 programmable logic controllers and recommend patching, removing internet exposure, strengthening access controls, monitoring S7 communications and disabling unnecessary services. Every recommendation is reasonable. Several can affect production if they are implemented without understanding the plant. The warning is not a patch notice The advisory covers all CPU variants in the S7-200, S7-300 and S7-400 series, the S7-1200 compact CPUs listed in the advisory and all S7-1500 variants, including F-series safety controllers. These generations do not provide identical security fu
CSO Online · Sep 8, 2026

Defense News
The U.S. Air Force plans to acquire anti-aircraft guns to protect its overseas bases following Iranian attacks on U.S. bases in the Middle East.
Defense News · Sep 8, 2026
Cyber News
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...
Schneier on Security · Sep 8, 2026

Defense News
“At a time when Europe faces its most serious security challenges for generations, the opening of MBDA’s new site demonstrates that the relationship between our two nations has never been more important,” said UK Minister of State for Defence Readiness and Industry Luke Pollard.
Breaking Defense · Sep 8, 2026

Cyber News
Public negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most — but not all — of what they took.
The Record · Sep 8, 2026

Cyber News
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.
SecurityWeek · Sep 8, 2026

Cyber News
Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix.
SecurityWeek · Sep 8, 2026

Cyber News
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
BleepingComputer · Sep 8, 2026

Cyber News
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files.
BleepingComputer · Sep 8, 2026

Cyber News
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
The Hacker News · Sep 8, 2026

Defense News
The space industry lauded a new Trump administration 1,000-launches-a-year space policy, but experts told Breaking Defense that the current space infrastructure doesn’t have enough capacity and someone’s going to have to pay, potentially a lot, to change that.
Breaking Defense · Sep 8, 2026
Government Cloud
The new 1Password SaaS Manager integration for Google Chat helps teams streamline IT and HR processes by bringing notifications, actions and approvals directly within Chat. With this integration, teams can build automated workflows for common employee access scenarios, including provisioning and deprovisioning membership across Google Chat spaces. Managers and approvers can review requests and take action directly from interactive Google Chat messages, helping reduce delays and keeping access decisions moving without switching tools. Getting started Admins: Admins can install the 1Password Saas Manager Chat app on their users’ behalf. Visit the Help Center to learn more about installing Marketplace apps for your organization . End users: End users need a 1Password SaaS Manager account to use this app. They can also search for the 1Password Chat App under Apps > Find apps. Visit the Google Workspace Marketplace to learn more and install the 1Password Chat app . Rollout pace Rapid Release and Scheduled Release domains: Available now Availability Available to all managed Google Workspace business or organizational accounts Resources 1Password Help Center 1Password Saas Manager Chat
Google Workspace Updates / Product Announcements · Sep 8, 2026
Government Cloud / Cloud Security
Starting today, Amazon Relational Database Service (Amazon RDS) for MariaDB now supports MariaDB minor versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, and 12.3.3, the latest minors released by community MariaDB. In addition to operational improvements, these minor versions introduce support for post-quantum TLS (PQ-TLS) key exchange, providing you with post-quantum cryptography options for encrypting your data in-transit. We recommend upgrading to the newer minor versions to accept fixes for Common Vulnerabilities and Exposures (CVEs) in prior versions of MariaDB and to benefit from bug fixes, performance improvements, and new functionality added by the MariaDB community. Learn more about the enhancements in RDS for MariaDB in the RDS MariaDB release notes. You can upgrade your database using Amazon RDS Blue/Green Deployments , in-place upgrade, or restore from a snapshot. To simplify operations at scale, enable automatic minor version upgrades and use the AWS Organizations Upgrade Rollout Policy to orchestrate upgrades across your clusters in phases. Learn more about performing version upgrades in the Amazon RDS User Guide . You can also migrate to RDS for MariaDB from external Mar
AWS What's New (Recent Announcements) · Sep 8, 2026

Government Contracting
On August 20, 2026, the Small Business Administration (SBA) proposed to materially amend the way it establishes size standards for purposes of federal procurement. SBA simultaneously issued two rulemakings. First, SBA published the 2026 Revised Size Standards Methodology white paper (2026 White Paper), which explains the proposed changes to SBA’s methodology for establishing size standards. Second, SBA published a proposed rulemaking that applies the revised methodology and shows the substantial impact the changed methodology would have. The proposed methodological changes would result in 114,541 additional businesses becoming eligible as “small” for a total of 6,459,508 potential small businesses. This is an increase of almost 2% from the previous count of 6,344,967. SBA has explained that the proposed changes are meant to simplify size standards and reflect current industry and market conditions. Simplification is meant to aid both contractors and agencies. For contractors, the changes should reduce confusion that may have served as unintentional hurdles to participation. (SBA pointed to the example of an entity unsure of whether it falls under Ship Building (1,300 employees) or
Government Contracts Legal Forum · Sep 8, 2026
Cyber News
Medical device giant warns August intrusion will hit Q3 and full-year sales and earnings as recovery drags on
The Register - Security · Sep 8, 2026

Cyber News
Security researchers warned the company of unusual threat activity in a recently patched N-able environment.
Cybersecurity Dive · Sep 8, 2026

Government Contracting
On September 1, 2026, the Eleventh Circuit issued its long-anticipated decision in United States v. Florida Medical Associates, LLC , – F.4th –, 2026 WL 2581886 (11th Cir. Sept. 1, 2026) (the “ Zafirov appeal”) overturning the district court and holding that the qui tam provisions of the False Claims Act (“FCA”) do not violate the Appointments Clause of Article II of the United States Constitution because relators are not officers of the United States that occupy “continuing positions.” The Eleventh Circuit did not reach other arguments made by the parties and remanded the case to the District Court for the Middle District of Florida to address two other constitutional arguments challenging the FCA’s qui tam provisions based on Article II’s Vesting and Take Care Clauses. In the September 2024 decision underlying the Zafirov appeal, Judge Kathryn Kimball Mizelle of the Middle District of Florida dismissed relator Clarissa Zafirov’s case and held that the qui tam provisions are unconstitutional under Article II’s Appointments Clause because it found relators to be “officers” of the United States and, as such, must be appointed by the Executive. Because qui tam relators are self-appoi
Government Contracts Legal Forum · Sep 8, 2026

CMMC
Cyber insurance renewals have changed, have you noticed?
Schellman Blog · Sep 8, 2026

Government Contracting
On Tuesday, August 25, 2026, the U.S. Department of Justice (DOJ) announced that Deloitte LLP and several of its subsidiaries agreed to pay, collectively, $21.5 million to resolve allegations that Deloitte violated the False Claims Act (FCA) by failing to comply with new anti-discrimination requirements incorporated into its federal contracts, by discriminating against employees and applicants on the basis of race and sex, and by allocating and seeking reimbursement for costs related to those practices under its federal government contracts. This resolution is the second of its kind under DOJ’s recently launched Civil Rights Fraud Initiative , following a similar settlement by IBM in April 2026. The Deloitte Settlement The settlement resolves allegations that, from 2017 to the present, Deloitte falsely certified compliance with equal opportunity and anti-discrimination requirements while engaging in discriminatory race- and sex-based employment practices. The government alleged that Deloitte allocated costs relating to these discriminatory practices to its federal government contracts and sought payment and reimbursement from the government for such costs. Specifically, the governm
Government Contracts Legal Forum · Sep 8, 2026

Cyber News
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.
BleepingComputer · Sep 8, 2026

Cyber News
The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud.
SecurityWeek · Sep 8, 2026

Government Cloud
Learn how Amazon PreDepart has successfully met the technical requirements of the Universal Postal Union (UPU) TechCert Programme for information technology integration and interoperability with UPU technology.
AWS Public Sector Blog · Sep 8, 2026

Cyber News
Mars Security , an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published threat intelligence advisories into production-ready, validated detection rules within minutes of release. Developed by former military red team operators, the capability systematically ingests threat reports from organizations such as CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence. The platform translates raw indicators and adversary techniques into native, MITRE ATT&CK-mapped detection logic across an enterprise’s active security infrastructure—including CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, and data lakes like Snowflake and Databricks. Every generated rule is automatically benchmarked against 30 days of the organization’s historic telemetry prior to deployment, eliminating the need for data ingestion or infrastructure changes. Accelerating the Pipeline From Threat Advisory to Active Defense Enterprises invest heavily in threat intelligence feeds, yet
CSO Online · Sep 8, 2026

Government Cloud
Google Sheets now supports the full Google Fonts web font library directly within charts. Users can now select “More fonts” from any font dropdown inside the chart editor sidebar to search, add, and apply custom web fonts across key chart text elements. This expanded font support is available for: Chart titles and subtitles Horizontal and vertical axis titles and labels Data labels Legend text Additionally, this launch enhances import and export compatibility with Microsoft Excel to preserve a wider range of fonts across both platforms. Previously, importing Excel files containing charts with custom fonts would result in missing or fallback font substitutions. Now, custom fonts present in both platforms are seamlessly preserved during file import and export, ensuring visual consistency and brand fidelity when moving spreadsheets between Google Sheets and Microsoft Excel. User selecting a custom web font in the Google Sheets chart editor Getting started Admins: There is no admin control for this feature. End users: Visit the Help Center to learn more about adding and editing a chart in Google Sheets . Rollout pace Rapid Release domains: Gradual rollout (up to 15 days for feature vis
Google Workspace Updates / Product Announcements · Sep 8, 2026
Cyber News
SPONSORED FEATURE: With regulators tightening rules and attack surfaces widening, meeting-room kit must bake in security without pushing users toward workarounds
The Register - Security · Sep 8, 2026

Cyber News
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
BleepingComputer · Sep 8, 2026

Cyber News
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.
SecurityWeek · Sep 8, 2026

Cyber News
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
The Hacker News · Sep 8, 2026

Defense News
The proliferation of AI is forcing the USAF to rethink cyber defense, and a new regional defense pact could shake up arms sales in the Middle East.
Breaking Defense · Sep 8, 2026

Cyber News
Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools. A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily. “Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.” While others start every test blind, Reflectiz already knows the website. Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pa
CSO Online · Sep 8, 2026

Cyber News
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities.
BleepingComputer · Sep 8, 2026

Defense News
Polish defense firm PGZ said the next step will be to build a couple fully functional prototypes for testing.
Breaking Defense · Sep 8, 2026

Federal Policy
Select agencies and partners can preview MDASH, which uses teams of AI agents to find software flaws and test whether attackers could exploit them.
Nextgov/FCW · Sep 8, 2026
DoD
Space Training and Readiness Command’s 33rd Range and Aggressor Squadron supported advanced cyber training at Patrick Space Force Base, Florida, Aug. 24–28, preparing Space Force and Navy cyber operators to defend critical launch infrastructure against realistic digital attacks and establishing combat credibility across the joint force. The exercise, named Cosmic Chimera, brought together the 33rd RGS, a unit under Space Delta 11, with Space Systems Command’s 645th Cyberspace Squadron and a cyber protection team of remote observers from Naval Network Warfare Command. Training focused on defensive cyberspace operations: detecting, analyzing and neutralizing cyber threats before they disrupt operational missions.
DVIDS · Sep 8, 2026

Cyber News
After a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability
Infosecurity Magazine · Sep 8, 2026

Cyber News
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
The Hacker News · Sep 8, 2026
Cyber News
Claims follow scrutiny over monitors installing adware without user consent
The Register - Security · Sep 8, 2026

Cyber News
Simple attacks remain far more consequential than anything AI is doing, government and industry leaders said.
Cybersecurity Dive · Sep 8, 2026

Cyber News
Two populous states and two large cities are among the U.S. jurisdictions where leaders have taken direct action to address criticisms of automated license plate readers (ALPRs).
The Record · Sep 8, 2026

Cyber News
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
The Hacker News · Sep 8, 2026

Cyber News
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagements, threat actor tracking, and live platform defenses. Researchers observed attackers moving from basic prompts toward workflows where AI systems handle several connected tasks. A six-hour credential theft campaign In Q2 2026, Mandiant investigated a suspected financially
Help Net Security · Sep 8, 2026

Cyber News
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and other intelligence sources into MITRE ATT&CK-mapped detection rules across CrowdStrike, Wiz, Splunk, and cloud telemetry, each one tested against 30 days of the customer’s own data before it goes live. Mars believes it is the first platform
Help Net Security · Sep 8, 2026

Cyber News
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of each user, and uses the saved contacts to propagate itself further, potentially reaching millions of devices within hours. The worm can hop from smartphone to smartphone, regardless of whether they are running
Help Net Security · Sep 8, 2026

Cyber News
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
BleepingComputer · Sep 8, 2026
Create a free account, pick your topics, and see your tailored compliance feed today.
Want to publish your news with CMMCSimple? Contact us at news@cmmcsimple.com.
Our RSS source list is reviewed and updated every two weeks on Friday, so newly accepted feeds appear with the next update.
© 2026 CMMCSimple