policy Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules The Pentagon is delaying the second phase of the Cybersecurity Maturity Model Certification (CMMC) program, intended to streamline contractor cybersecurity rules and address a shortage of qualified third-party assessors.… SecurityWeek · Jul 14, 2026 Info cmmccybersecuritycontractor
threat-intel Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions Russia’s FSB, specifically its Center 16 signals intelligence arm, has been formally blamed for a cyberattack that threatened to cut heating to half a million people in Poland last winter. Following this attribution, the… The Record · Jul 12, 2026 High RUPOFRcyberattackcybercrimeespionage
threat-intel NSA revives 'Tailored Access Operations' name for elite hacking unit The National Security Agency (NSA) has revived its elite hacking unit, formerly known as TAO (Tailored Access Operations), as part of a reorganization aimed at bolstering its capabilities against evolving cyber threats f… The Record · Jul 9, 2026 High IRCHNOhackingcyber espionagenational security
threat-intel Cybersecurity and the Gap Between Skill and Ability A joint statement from the Five Eyes intelligence alliance warned of escalating cyber risks due to the increasing capabilities of AI models, particularly their ability to autonomously carry out cyberattacks. The statemen… Schneier on Security · Jul 8, 2026 High UNCAAUaicybersecuritythreat intelligence
threat-intel CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws The US Cybersecurity and Infrastructure Security Agency (CISA) is leveraging Anthropic’s AI model, Mythos, to proactively scan federal government software for security vulnerabilities. This initiative is part of a broade… SecurityWeek · Jul 7, 2026 Medium USaiintelligencevulnerability
threat-intel CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker This article profiles Tarah Wheeler, CISO at TPO Group and previously holding leadership roles at Red Queen Technologies and EFF. It highlights her unique background, blending her passion for social science and writing w… SecurityWeek · Jul 7, 2026 Medium CHRUNOsocial sciencehuman behaviorpolicy
threat-intel An intelligence budget 'super user' job is now in the hands of Russ Vought This article reports that Russ Vought, Donald Trump’s former budget chief, has taken over managing the classified spending plans of major U.S. intelligence agencies, including the CIA and NSA. This shift follows the depa… The Record · Jun 30, 2026 Medium USpoliticalbudgetintelligence
threat-intel Meta Is Testing Facial Recognition for Police and Military Meta is reportedly developing facial recognition technology, initially for use by law enforcement and the military. This development involves a prototype being tested with a Pentagon supplier, raising concerns about the… Schneier on Security · Jun 26, 2026 Medium facial recognitionsurveillancemeta
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
threat-intel DHS chief says president has met with potential CISA nominee; agency plans to hire 600 The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is seeking to rebuild its workforce following significant layoffs and a prolonged period without a Senate-confirmed direc… The Record · Jun 25, 2026 Medium CHUScisacybersecurityhomeland security
threat-intel Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Anthropic’s Mythos AI model identified vulnerabilities within several U.S. government computer systems during a testing exercise conducted in collaboration with intelligence agencies. While the model quickly detected wea… SecurityWeek · Jun 24, 2026 High UNaivulnerabilitysecurity
threat-intel FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists The FortiBleed campaign, spearheaded by threat actors likely originating from Russia, has compromised over 430,000 FortiGate firewalls globally, resulting in the theft of more than 110 million credentials. Attackers util… Dark Reading · Jun 23, 2026 High USRUINcredential theftfirewallauthentication
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
threat-intel AI Use by the US Government This article details the widespread and largely undocumented use of Artificial Intelligence (AI) by the US government under both the Trump and Biden administrations. The Office of Management and Budget (OMB) revealed a m… Schneier on Security · Jun 17, 2026 Medium USaigovernmentautomation
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
threat-intel Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models A coalition of cybersecurity executives and experts is urging the Trump administration to reverse its restrictions on Anthropic’s AI models, specifically Fable 5 and Mythos 5. The group argues that limiting access to the… SecurityWeek · Jun 16, 2026 Medium CHUNaiartificial intelligencecybersecurity
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
threat-intel Hackers pose as women seeking romance to spy on Russian soldiers A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence… The Record · Jun 9, 2026 High RUespionagesocial-engineeringmobile-malware