~/greenteam/nerd

Monday, July 6, 2026

Daily digest

cmmc Schneier on Security

France to Stop Certifying Non-Quantum-Safe Encryption

France's national cybersecurity agency ANSSI announced it will halt certification of security products that do not include quantum-resistant encryption. The move compels government bodies and critical infrastructure operators in France to begin migrating away from classical cryptographic systems. The announcement was made at the France Quantum conference by ANSSI's chief of staff.

Why it matters: NIST finalized its first PQC standards in 2024 and DoD/CMMC guidance on post-quantum migration is expected to follow; France's hard certification cutoff signals the direction U.S. federal compliance requirements are heading, making it worth accelerating your own PQC readiness review for GCC High and AWS GovCloud workloads now rather than at deadline.

cmmc FedScoop

FedRAMP 2026 is not a compliance update — it's a new operating model

A former DHS CISO argues in FedScoop that FedRAMP's 2026 direction represents a structural shift away from point-in-time, static documentation toward continuous evidence collection and real-time compliance demonstration. Cloud service providers and agencies are expected to operationalize ongoing evidence pipelines rather than periodic audit packages. The piece frames this as an operating model change, not merely a documentation update.

Why it matters: CMMC Level 2 is already pushing toward continuous compliance posture; if your AWS GovCloud or M365 GCC High services run on FedRAMP-authorized platforms, this shift means your CSPs' authorization posture will change and your own evidence collection practices should align — periodic screenshots and static SSP exports will not be sufficient.

cybersec The Hacker News

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Researchers at LevelBlue have identified QuimaRAT, a Java-based remote access trojan sold as a malware-as-a-service offering at price points ranging from $150 per month to $1,200 for lifetime access. The RAT targets Windows, Linux, and macOS, making it a cross-platform threat. Its MaaS distribution model lowers the barrier for less sophisticated threat actors to deploy it broadly.

Why it matters: Java-based payloads run on any host with a JRE — including Linux-based Nutanix AHV VMs and any macOS admin workstations in your environment — so endpoint detection coverage should not be assumed to stop at Windows; verify your Intune/EDR policy extends to all managed OS types.

cybersec The Hacker News

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Researchers at Hong Kong University of Science and Technology demonstrated that static scanners designed to detect malicious "skills" (plugins/extensions) for AI coding agents can be bypassed using a self-extracting packing technique they call SkillCloak. The strongest variant evaded all tested scanners more than 90% of the time. The same research team developed a runtime-based checker that catches most of the obfuscated samples.

Why it matters: If your environment runs a self-hosted AI stack with agent/plugin capabilities, static scanning of third-party skills or extensions provides weaker assurance than assumed; consider runtime behavioral monitoring as the primary control rather than relying on scan-at-install gates.

cybersec The Hacker News

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

Researchers at Shandong University demonstrated TrojPix, a covert data exfiltration technique that modulates on-screen pixel patterns imperceptibly to the eye, causing the video cable to emit decodable radio frequency signals receivable by a nearby device. The technique requires malware to already be present on the target system and achieves meaningful data throughput rates. It represents a new class of air-gap bridging attack alongside prior acoustic and power-based methods.

Why it matters: For CMMC L2 environments handling CUI on air-gapped or physically isolated workstations, TrojPix is a reminder that physical separation alone is not sufficient if host-level malware controls are weak — TEMPEST shielding requirements and strict application whitelisting on isolated systems become more relevant.

cybersec The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A suspected Chinese state-affiliated threat cluster, tracked by Seqrite Labs under the name Operation DragonReturn, has been running a multi-stage spear-phishing campaign against Indian taxpayers, tax professionals, and corporate finance teams. Attackers impersonate India's Income Tax Department to deliver DcRAT, a remote access trojan capable of stealing sensitive data from compromised hosts. The campaign uses trojanized lookalike tax utility software as the primary lure.

cybersec The Hacker News

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

A vulnerability in Opera GX allowed malicious websites to silently install a browser extension without user interaction and use it to exfiltrate data from subsequently visited pages. In a proof-of-concept, researchers reconstructed a signed-in user's full Gmail address from a single page visit with no clicks required. Opera has patched the flaw and states it found no evidence of active exploitation.

cybersec The Register

Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert

ShinyHunters, a prolific threat actor group, has leaked data from approximately 2.3 million accounts following a cyberattack on Moody Bible Institute. The exposed data includes names, addresses, dates of birth, and additional personally identifiable information. The institution disclosed the breach and is notifying affected individuals.

cybersec BleepingComputer

Flipper Zero firmware development continues with community help

Flipper Devices has confirmed that official firmware development for the Flipper Zero multi-tool security device will continue, though with a reduced internal engineering team and increased reliance on open-source community contributions. The company did not announce end-of-life for the product. No timeline for specific feature releases was provided.