~/greenteam/nerd

Weekly review

Week of May 25-31, 2026

A high-tempo week dominated by sustained Cisco SD-WAN exploitation by a China-nexus threat actor (UAT-8616), cascading software supply chain attacks across npm and GitHub, and a wave of AI-assisted vulnerability discovery that is compressing the window from disclosure to exploitation to hours. CMMC Phase 2 pressure is mounting with the November 10, 2026 deadline approaching and only ~1,200 of the estimated 8,000 required contractors currently certified.

What you might have missed

Stories not surfaced in this week's daily digests.

cmmc Federal News Network

OMB Rescinds Biden-Era Logging Rules, Issues New Risk-Based Federal Cyber Logging Mandate (M-26-14)

OMB Director Russ Vought issued Memorandum M-26-14 on May 22, formally rescinding the SolarWinds-era M-21-31 logging directive and replacing it with a risk-based framework centered on two objectives: continuous event monitoring (CEM) and threat hunting, investigation, response and forensics (THIRF). The memo tasks CISA with producing a government-wide Logging Reference Architecture within 90 days, after which agencies face a phased maturity timeline (120/180/320 days), and explicitly extends requirements to IoT and OT environments. The policy also applies to contractors via FAR flow-downs, with a November 1, 2026 baseline compliance target and estimated remediation costs of $50K–$250K for small contractors.

Why it matters: M-26-14 directly modifies federal and contractor logging obligations under FAR/DFARS, creates new SSP update requirements before November 2026, and introduces a potential visibility gap risk if agencies de-prioritize logs for systems not in their risk matrix — a gap that adversaries exploiting the week's SD-WAN and supply chain vectors are well-positioned to exploit.

cybersec SecurityWeek

CISA Emergency Directive 26-03 and UAT-8616's Full Cisco SD-WAN Campaign — Seven Zero-Days, China-Nexus Actor, Fabric-Wide Configuration Compromise

The digests covered CVE-2026-20245 (CVSS 7.8, unpatched) in isolation, but the broader picture — confirmed by CISA Emergency Directive 26-03 and Cisco Talos — is that UAT-8616, a highly sophisticated China-nexus threat actor whose infrastructure overlaps with monitored ORB networks, has been exploiting Cisco SD-WAN since at least 2023 across seven distinct CVEs. CVE-2026-20182 (CVSS 10.0, now patched) allows unauthenticated remote attackers to inject SSH keys and issue arbitrary NETCONF commands, effectively reconfiguring the entire SD-WAN fabric; post-compromise, the actor clears syslog, wtmp, lastlog, bash_history, and cli-history to erase forensic evidence. Ten additional threat clusters distinct from UAT-8616 are also actively exploiting the CVE-2026-20133/20128/20122 chain using public PoC code.

Why it matters: The Emergency Directive 26-03 framing — mandatory FCEB agency inventory, update, and compromise assessment — combined with confirmed FedRAMP SD-WAN for Government exposure means this campaign has direct implications for federal network architecture reviews, not just routine patching; organizations should audit auth.log for unauthorized vmanage-admin public-key logins and review SD-WAN fabric configuration integrity.

cybersec The Register

UN World Food Programme Breach Exposes PII of 600,000 Gaza Households — Including Names, ID Numbers, and Location Data

The World Food Programme confirmed unauthorized access to its Palestine self-registration application (SRA) on May 14, exposing names, identification numbers, mobile phone numbers, and neighborhood-level location data for approximately 600,000 Gazan households — potentially the largest breach of humanitarian beneficiary data on record. The WFP suspended the platform, but a whistleblower account cited by The New Humanitarian claimed a researcher had alerted WFP to SRA vulnerabilities two days before the attack. No threat actor has claimed responsibility and an investigation is ongoing.

Why it matters: The combination of location data and ID numbers in a conflict zone creates physical-safety risks beyond conventional identity theft, and the 17-day disclosure gap to affected beneficiaries illustrates a broader pattern of delayed humanitarian-sector breach notification; for IT administrators managing systems for NGOs or government agencies with beneficiary databases, this underscores the need for vulnerability disclosure intake processes and faster breach notification workflows.

cybersec BleepingComputer

Device Code Phishing Surges 37x — EvilTokens PhaaS Kit Commoditizes MFA Bypass at Criminal Scale

Push Security and BleepingComputer reported that device code phishing attacks abusing the OAuth 2.0 Device Authorization Grant have surged 37.5x in 2026, driven by at least 14 distinct phishing-as-a-service kits, with EvilTokens the most prevalent. The technique bypasses non-phishing-resistant MFA entirely by abusing legitimate OAuth flows in already-authenticated sessions, yielding persistent access and refresh tokens that survive password resets. Targets are primarily Microsoft 365, Entra ID, Teams, and SharePoint environments; nation-state actors (Storm-2372, linked to Russia) and criminal groups (Scattered Lapsus$ Hunters) have both operationalized the technique at scale.

Why it matters: The digest covered Kali365's device code feature as a footnote, but the 37x surge data from Push Security represents a structural shift — device code phishing has crossed from espionage-grade tradecraft to criminal commodity — making Conditional Access policy enforcement to restrict device code flow an urgent priority in M365 GCC High and CMMC-scoped environments that rely on standard MFA.

infrastructure Cisco Newsroom

Cisco Live: Cisco Cloud Control, Quantum-Safe Boot on New Hardware, and Quantum Ready Assessments Announced

At Cisco Live US on June 2, Cisco unveiled Cloud Control, a unified agentic platform for managing and defending IT infrastructure that bridges human operators and AI agents under an 'AgenticOps' model. Cisco also announced that all newly introduced campus, branch, and data center routers, switches, and firewall series will ship with quantum-safe secure boot, and introduced Quantum Ready Assessments — available through Cisco IQ — to identify assets most exposed to 'harvest now, decrypt later' attacks, with global availability planned for July 2026. A Quantum Resilience Framework and Live Protect runtime protection expansion (patching without reboots) round out the announcements.

Why it matters: For IT administrators managing Cisco-heavy network infrastructure, the quantum-safe secure boot commitment means hardware refresh planning should now account for post-quantum cryptography readiness timelines, and the Quantum Ready Assessments tool offers a concrete starting point for identifying 'harvest now, decrypt later' exposure in environments handling CUI.

Themes this week

Patterns observed across coverage.

Cisco SD-WAN as a Sustained, Nation-State-Targeted Critical Infrastructure Attack Surface

Seven exploited zero-days in Cisco Catalyst SD-WAN in 2026, a confirmed China-nexus threat actor (UAT-8616) operating since at least 2023, ten additional criminal clusters exploiting public PoC code, and a CISA Emergency Directive all point to SD-WAN management planes becoming a high-priority persistent target — not a one-off disclosure event. Organizations running any Cisco SD-WAN deployment, including FedRAMP SD-WAN for Government, should treat this as an ongoing campaign requiring log audits, IoC hunting, and fabric configuration verification rather than a patch-and-move-on response.

AI Is Simultaneously Compressing Exploitation Windows and Discovering Vulnerabilities at Machine Speed

This week surfaced AI on both sides of the threat equation: an autonomous agent found 21 FFmpeg zero-days, another found a two-year-old Redis RCE, and researchers demonstrated that open-source models suffice to build self-spreading worms — while defenders noted that fewer than 10% of SOCs report AI delivering excellent value. The exploitation timeline compression from weeks to hours driven by AI-assisted weaponization is fundamentally breaking patch-cycle-based vulnerability management programs that assumed days of lead time, and CMMC Level 2 organizations need to reassess patch SLAs accordingly.

OAuth Token Theft and Device Code Phishing Replacing Credential Theft as the Primary Cloud Access Vector

From the 37x surge in device code phishing (EvilTokens) to the M365 Android debug-flag OAuth token theft, the Brickstorm/Plenet/AgentPSD backdoor chain targeting M365 GCC High, the five-month Outlook mailbox access via OAuth abuse, and the Kali365 platform adding device code flows, this week's stories converge on a clear pattern: attackers have shifted from stealing passwords to stealing tokens, which survive MFA, password resets, and many standard incident response playbooks. Conditional Access restrictions on device code grant flows and continuous OAuth token auditing are now baseline requirements, not hardening options.

Software Supply Chain as the Week's Dominant Initial Access Vector Across npm, GitHub, and PyPI

The Miasma worm hitting 73 Microsoft GitHub repositories, IronWorm poisoning 50+ npm packages, the Red Hat @redhat-cloud-services namespace compromise, a malicious PyPI package stealing developer credentials, and the OpenAI Codex token-stealing npm package collectively demonstrate that the open-source software supply chain is now the primary initial access vector targeting developer and CI/CD environments. CMMC supply chain requirements (SR.1.001, SR.2.002) are directly implicated, and dependency locking, registry integrity verification, and SBOM generation are no longer optional hygiene practices.

Suggested new sources

Worth considering for your feed list. Review and add manually.

The Record by Recorded Future

Cybersecurity news with a particular depth in nation-state threats, government policy, law enforcement actions, and geopolitical cyber operations — areas directly relevant to CMMC and GovCloud environments.

The Record consistently breaks stories on federal cyber policy (it covered the CISA AI directive, WFP breach, and OMB logging memo with original sourcing) that do not appear in the digest's current feed mix, and its nation-state threat coverage of Chinese, Russian, and North Korean APT activity directly complements the CMMC and M365 GCC High threat picture; it fills the gap between The Hacker News's vulnerability focus and Federal News Network's policy focus.

RSS: https://therecord.media/feed

Risky Business News (Newsletter + Podcast)

Authoritative weekly cybersecurity news analysis and policy commentary by Patrick Gray and Tom Uren, covering threat intelligence, geopolitics, vendor announcements, and security industry dynamics with practitioner-level depth.

Risky Business News provides the analytical layer missing from straight news feeds — it contextualizes why stories like the UAT-8616 SD-WAN campaign or the device code phishing surge matter strategically, not just operationally, making it ideal for IT administrators who need to communicate risk to leadership and inform compliance roadmap decisions; the podcast format also surfaces stories the written digest misses.

RSS: https://news.risky.biz/rss

Industrial Cyber

Dedicated OT/ICS and critical infrastructure cybersecurity news covering policy, incidents, vendor developments, regulatory changes (NERC CIP, TSA directives, CISA advisories), and sector-specific threat intelligence.

This week's ATG/fuel tank gauge exposure story and the broader OT convergence theme were underserved in the digest's current feeds; Industrial Cyber covers OT/ICS incidents, CISA critical infrastructure advisories, and sector-specific compliance developments (including energy, water, and defense-adjacent OT environments) that complement the IT-heavy existing feed mix and are directly relevant to CMMC Level 2 organizations with any physical infrastructure or building management system exposure.

RSS: https://industrialcyber.co/feed