Tuesday, June 23, 2026
Daily digest
Two executive orders signed this week accelerate the federal government's post-quantum encryption migration — this is the most compliance-relevant development of the day for defense contractors and GCC High tenants who will face downstream requirements.
Trump Signs Two Executive Orders to Accelerate Post-Quantum Encryption Migration
President Trump signed two executive orders directing the federal government to accelerate its transition to post-quantum cryptographic standards while also boosting domestic quantum computing industry. The orders set deadlines for federal agencies to migrate away from classical encryption algorithms and direct intelligence agencies to protect quantum research from foreign adversaries. A companion NextGov report indicates DoD and DoE are tasked with building and hosting quantum computing infrastructure for scientific discovery.
Why it matters: Defense contractors operating under CMMC L2 should expect NIST 800-171 and related DFARS clauses to eventually reflect post-quantum cryptography requirements — now with a White House-mandated federal timeline in place, downstream contract language updates are more likely and sooner than previously anticipated. Begin inventorying cryptographic dependencies in your M365 GCC High, AWS GovCloud, and Nutanix environments now.
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
A heap over-read vulnerability in Squid web proxy, traceable to a 1997 FTP-parsing code change, can leak a user's cleartext HTTP request — including credentials and session tokens — to any other user permitted to send traffic through the same proxy. The flaw exists in Squid's default configuration and was publicly disclosed by researchers at Calif.io in June. No CVE number was provided in the snippet but the researchers named it 'Squidbleed.'
Why it matters: If Squid is deployed anywhere in your environment as a forward or caching proxy — including on RHEL/CentOS-based infrastructure or within containerized workloads — this is an unauthenticated credential-leak risk that should be patched or mitigated immediately. Review any Squid instances running in your Nutanix AHV VMs or AWS GovCloud environments.
FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials
SOCRadar researchers have detailed how the large-scale FortiBleed campaign targeting Fortinet FortiGate devices deployed custom packet-sniffing tools post-compromise to harvest authentication credentials from firewall traffic. Attackers leveraged previously disclosed FortiGate vulnerabilities to gain initial access before installing the bespoke credential-harvesting sniffer. The campaign affected a broad range of organizations that had not patched known FortiGate flaws.
Why it matters: If FortiGate appliances are part of your network perimeter, this campaign confirms that unpatched devices are being actively exploited for credential theft — not just lateral movement. Any FortiGate credentials that transited a potentially compromised device should be treated as compromised and rotated, and CMMC AC/IA controls require you to document and respond to this class of incident.
Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution (AutoJack)
A chained vulnerability dubbed 'AutoJack' in Microsoft's AutoGen Studio — a web-based interface for prototyping AI agents — allowed an attacker to manipulate an AI agent into executing arbitrary commands on its host system by simply getting a victim to visit a malicious webpage. Microsoft has issued a fix for the flaw. The vulnerability required no special privileges beyond the ability to influence the agent's prompt context.
Why it matters: If your team has deployed AutoGen Studio locally or on any internal server as part of a self-hosted AI stack, this is a critical patch — prompt injection leading to host-level code execution is a high-severity risk in a CMMC environment where CUI may be accessible on the same system.
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
Researchers discovered three malicious npm packages — including 'postcss-minify-selector' and 'postcss-minify-selector-parser' — published by a single threat actor that masquerade as legitimate PostCSS tooling while delivering a Windows-based remote access trojan. The packages accumulated over 1,000 combined downloads before discovery. All were published within the past month by an npm user with no prior history.
Why it matters: If your Ansible playbooks, CI/CD pipelines, or developer workstations pull npm packages for front-end build tooling, verify your dependency trees for these package names and audit your package-lock files. A RAT installed on a developer workstation that touches GCC High or CUI-handling systems is a CMMC incident-response trigger.
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Multiple paid WordPress plugins from vendor ShapedPlugin were compromised when attackers gained access to the vendor's build and distribution pipeline and injected backdoor code into Pro plugin releases pushed through official licensed update channels. Wordfence confirmed the supply-chain compromise affected organizations that received updates through legitimate channels. The specific plugins affected are detailed in the Wordfence analysis.
Why it matters: If any public-facing WordPress sites in your environment use ShapedPlugin Pro products and received automatic updates in the affected window, treat those servers as potentially backdoored. Even if WordPress is not a primary workload, a compromised web server in your network boundary is relevant to CMMC boundary scoping and incident reporting obligations.
AWS Debuts Lambda MicroVMs With Up to 8 Hours Runtime
AWS has announced Lambda MicroVMs, a new execution mode for AWS Lambda that provides stronger isolation via lightweight virtual machines and supports runtimes of up to 8 hours — a major extension from the previous 15-minute limit. The feature is positioned for use cases involving untrusted code execution, long-running AI agents, and extended automation tasks. MicroVMs use Firecracker-based isolation.
Why it matters: For AWS GovCloud workloads running long-duration automation or AI agent tasks via Lambda, this removes a significant architectural constraint and may simplify Ansible-triggered serverless workflows. The stronger Firecracker-based isolation boundary is also a meaningful improvement for CUI-adjacent workloads where compute isolation is a CMMC SC control consideration.
AWS Security Blog: Prevent Data Exfiltration With AWS Egress Controls for Cloud Workloads
AWS published detailed guidance on configuring outbound traffic controls to prevent data exfiltration from cloud workloads, covering VPC endpoint policies, network firewall rules, service control policies, and S3 bucket policies. The post emphasizes that outbound controls are frequently left open by default and argues this represents an underappreciated exfiltration risk. The guidance is oriented toward production workload hardening.
Why it matters: CMMC L2 requires data loss prevention and boundary protection controls (SC.3.177, SC.3.183) — this AWS-native guidance maps directly to those requirements for GovCloud environments and is practical reference material for both implementation and assessor documentation.
Five Eyes Agencies Warn AI Can Escalate Cybersecurity Incidents Into 'Major Operational and Financial Crises'
Intelligence agencies from the Five Eyes alliance published a joint advisory warning that AI is amplifying the speed, scale, and severity of cyberattacks to the point where routine security incidents can rapidly escalate into major operational and financial crises. The advisory calls on organizational leadership — not just security teams — to take direct responsibility for cybersecurity posture. It emphasizes AI-accelerated attack automation as the primary concern.
Why it matters: Five Eyes guidance carries direct weight in CMMC and NIST 800-171 risk management contexts — this advisory may be cited in future assessment guidance or DIBCAC review discussions. It also reinforces the case for executive-level CMMC sponsorship and incident response planning that accounts for AI-accelerated threat timelines.
Researchers Disclose 'DifyTap' Flaws Allowing Cross-Tenant AI Chat Exfiltration Without Authentication
Zafran Security disclosed four vulnerabilities collectively named DifyTap in Dify, a widely used open-source platform for building and managing AI agent workflows with over 146,000 GitHub stars. The flaws allow unauthenticated attackers to silently read AI conversation histories from other tenants' applications within the same Dify deployment. No authentication is required to exploit the vulnerabilities.
Why it matters: If Dify is part of your self-hosted AI stack — a plausible choice given its popularity for agentic workflows — any multi-tenant or shared deployment must be treated as compromised until patched. Conversations routed through Dify that contain CUI or sensitive operational data would represent a reportable disclosure under CMMC incident handling requirements.
FAR Overhaul Moves to Formal Rulemaking: Four Proposed Rules Covering 13 FAR Parts Published
A sweeping overhaul of the Federal Acquisition Regulation has entered formal rulemaking, with four proposed rules covering 13 FAR parts — totaling over 1,000 pages — published for public comment. The rulemaking is described as the most significant FAR restructuring in decades. Additional rules covering small business provisions are forthcoming.
Why it matters: FAR changes can affect how cybersecurity requirements, including CMMC flow-downs, are structured in future contracts and subcontracts. Organizations should monitor the public comment period to understand whether proposed changes alter DFARS 252.204-7012 or related cyber clauses, and consider submitting comments if contract cybersecurity requirements are materially affected.
Microsoft Security Blog: One Intrusion, Two Cyberattackers — Uncovering Parallel Threat Activity
Microsoft's security researchers documented a ransomware incident in which two separate threat actors were simultaneously active within the same compromised environment, blending TTPs and evasion techniques in ways that caused each actor's signals to partially mask the other's activity. The case study illustrates how siloed detection of individual IOCs can cause analysts to miss the full scope of a compromise. Microsoft uses the case to argue for correlated, behavior-based detection across the entire kill chain.