~/greenteam/nerd

Tuesday, July 14, 2026

Daily digest

The Pentagon's suspension of CMMC Phase 2 third-party assessment requirements is the dominant story for this audience — it directly resets compliance timelines and budget assumptions for any DIB contractor currently preparing for a C3PAO assessment.

cmmc Federal News Network

Pentagon Suspends CMMC Phase 2 Requirements, Launches 60-Day Reform Review

DoD CIO Kirsten Davies has suspended plans to expand CMMC third-party assessments, freezing Phase 2 requirements while a new task force conducts a 60-day review of the program's future. The suspension cites prohibitive costs for small and mid-size defense contractors. Phase 1 self-assessments remain in place during the review period.

Why it matters: If your organization had a C3PAO assessment scheduled or budgeted for the near term, that timeline is now uncertain — but NIST 800-171 compliance obligations under existing DFARS 252.204-7012 remain in force regardless of CMMC program status. Do not stand down controls work; document your posture now while the review plays out.

cybersec The Hacker News

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A phishing-as-a-service platform called Forg365, sold via Telegram for $400/month, combines device code phishing, adversary-in-the-middle session hijacking, AI-generated lures, and antibot evasion to compromise Microsoft 365 accounts. After credential theft, operators conduct post-compromise mailbox operations including email forwarding and data exfiltration. The kit is actively being marketed and used against M365 tenants.

Why it matters: Device code phishing bypasses MFA entirely — Conditional Access policies must explicitly block device code flow for external users in your GCC High tenant. Verify that Entra ID CA policies restrict the 'Device code' authentication flow and confirm Intune-managed device compliance is enforced at token issuance.

cybersec The Hacker News

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity / Defending SaaS Against ShinyHunters OAuth Abuse

Microsoft Threat Intelligence has detailed how ShinyHunters-affiliated actors spent a year compromising corporate Salesforce environments by abusing pre-existing OAuth trust relationships, supply-chain access, misconfigured guest accounts, and voice phishing — without exploiting any Salesforce platform vulnerability. Three distinct attack chains are documented, all relying on legitimate delegated permissions rather than zero-days. Microsoft published a companion blog with defensive guidance.

Why it matters: The same OAuth abuse patterns apply to any SaaS app connected to your M365 GCC High tenant via delegated permissions. Audit third-party OAuth app consents in Entra ID and review guest account configurations — misconfigured guest access is explicitly called out as an entry vector in the Microsoft blog.

infrastructure Microsoft Security Blog

Microsoft Entra ID Makes Passkeys the Default Authentication Method

Microsoft has updated Entra ID so that passkeys (FIDO2) are now the default sign-in experience for new and eligible users, displacing passwords as the primary method. The update also introduces a revised model for SMS and voice authentication, demoting them in the authentication stack. Microsoft's blog post outlines preparation steps for administrators ahead of the rollout.

Why it matters: GCC High tenants typically lag commercial feature rollouts, but this change will arrive — verify whether your Intune-managed Windows 11 fleet is enrolled for FIDO2/passkey support and whether any Conditional Access or authentication strength policies need updating before the default shifts under you.

cybersec Krebs on Security

Lessons Learned from CISA's Recent GitHub Leak of AWS GovCloud Keys

CISA published a postmortem after a contractor inadvertently committed dozens of internal CISA credentials — including AWS GovCloud access keys — to a public GitHub repository, where they remained exposed for nearly six months before KrebsOnSecurity notified the agency. The report identifies gaps in secret scanning, contractor oversight, and incident response that delayed detection. Krebs analyzes the systemic failures and the lessons applicable to all security teams.

Why it matters: This is a direct analog to your AWS GovCloud environment — verify that AWS Secrets Manager or equivalent is used for all credentials, that GitHub Advanced Security secret scanning is enabled on any repos your team uses, and that contractor repository access is reviewed under your supply-chain risk management controls (NIST 800-171 3.13.1/3.13.2).

cybersec BleepingComputer

US and Allies Warn of Russian Critical Infrastructure Attacks via Weak Router Security

A joint advisory from U.S. and eight allied cybersecurity agencies warns that Russian state-sponsored hackers are actively exploiting poorly configured and end-of-life routers to gain footholds in critical infrastructure networks. The advisory was timed alongside EU and UK sanctions against Russian GRU-linked hackers attributed to an attack on Poland's power grid. The guidance covers detection, hardening, and patching recommendations for network edge devices.

Why it matters: Review your network perimeter inventory for end-of-life or default-configured routers and firewalls — this advisory directly supports NIST 800-171 controls 3.13.1 and 3.4.1 and gives you citable threat intelligence to justify a hardening sprint to leadership.

cybersec The Hacker News

Grok Build CLI Was Uploading Entire Git Repositories — Including Files It Was Told to Ignore — to xAI Cloud Storage

xAI's Grok Build coding CLI tool (version 0.2.93) was found to upload entire Git repositories, including full commit history, to an xAI-operated Google Cloud Storage bucket — not just the specific files relevant to the active coding task. A researcher confirmed that files explicitly excluded from the task were still included in the upload. There is no indication users were informed of this behavior.

Why it matters: If anyone on your team is using Grok Build or similar AI coding CLIs against repos containing CUI, infrastructure-as-code, or secrets, this is a potential CUI spillage event — check acceptable use policies for AI coding tools and ensure developer workstations governed by Intune are not running unauthorized agentic AI tools against controlled repositories.

cmmc NextGov

DHS Network Intrusion Twice Dismissed as False Positive Before Breach Confirmed

Suspicious activity on the Homeland Security Information Network (HSIN) was flagged in mid-to-late May but was ruled a false positive on two separate occasions before analysts confirmed an actual intrusion had occurred. The network is currently supporting World Cup logistics across U.S. venues. Details on the scope of the breach and the nature of the access have not been fully disclosed.

Why it matters: This is a process failure as much as a technical one — two false-negative triage decisions delayed response by weeks. It's a concrete case study for reviewing your own SOC escalation and alert triage procedures, especially relevant if you rely on automated tooling for initial alert disposition.

cybersec BleepingComputer

SAP Patches Three Critical Flaws in NetWeaver, Commerce Cloud, and AppRouter

SAP's July 2026 Patch Day addressed 16 vulnerabilities across multiple products, including three rated critical in NetWeaver, Commerce Cloud, and AppRouter. NetWeaver has been a repeated target of active exploitation in 2025–2026. SAP has not publicly confirmed whether any of the July flaws are under active exploitation.

cybersec The Hacker News

Attacker Uses AI-Generated PowerShell Script to Map Active Directory

Researchers documented an intrusion in which the threat actor deployed a PowerShell script assessed to be AI-generated — characterized by verbose comments, structured output, and clean syntax atypical of human-written attack tooling — to enumerate Active Directory, mapping domain controllers, users, computers, and producing an HTML report. The script required no custom exploit code; it leveraged built-in AD querying capabilities. The incident represents a documented in-the-wild use of AI-assisted attacker tooling for reconnaissance.

Why it matters: AI-generated enumeration scripts lower the bar for AD reconnaissance significantly and are likely to evade signature-based detection tuned for known tooling like BloodHound or SharpHound — review PowerShell Script Block Logging and AMSI coverage on your Intune-managed fleet and ensure anomalous AD LDAP query volumes trigger alerting.

cybersec The Hacker News

ModHeader Browser Extension with 1.6M Installs Pulled by Google and Microsoft After Hidden Data Collector Found

Google and Microsoft removed the ModHeader extension from the Chrome Web Store and Edge Add-ons after researchers discovered a dormant browsing-history collector built into the official published version. The collector was controlled by an allow-list that was empty, meaning no data was confirmed to have been sent. The extension had approximately 1.6 million installs across both browsers.

Why it matters: Browser extensions are a persistent blind spot in Intune-managed endpoint hardening — use Intune's browser extension management policies to audit and blocklist unauthorized extensions, and treat this as a prompt to review what extensions are permitted on your managed fleet under NIST 800-171 3.4.6 (least functionality).

cmmc NextGov

AI Can Now Power Every Stage of a Cyberattack With Minimal Human Oversight, Researchers Find

New research published via NextGov documents that AI tools — including both U.S. and Chinese models — have been used across entire cyber operation kill chains: identifying vulnerabilities, generating exploitation commands, and executing portions of intrusions with little human involvement. Previously, AI assistance was largely limited to discrete tasks such as phishing lure generation. Both commercial and open-source models were involved in the documented operations.