LIVE · cybersecurity feed
Live wire
CVE-2026-73570 · Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesCVE-2026-12569 · Cl0p Targets 40+ Organizations Through PTC Windchill FlawCVE-2026-69836 · Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineHackers poison arrayref Rust crate to push infostealer malwareNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsSenators press TikTok over withholding of safety features for some usersAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureChatGPT for Teens tackles risky chats and homework shortcuts
security

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek.

zeroday.news ·

Reports this week indicate a growing confidence among defense contractors regarding their readiness for the Cybersecurity Maturity Model Certification (CMMC) program, even as their actual ability to demonstrate compliance appears to be lagging. This observation stems from the findings of two separate industry surveys, conducted by Kiteworks and CyberSheath, which both point to a consistent trend within the defense industrial base.

The CMMC program, a U.S. Department of Defense (DoD) initiative, is designed to enhance the cybersecurity posture of the defense supply chain. It establishes a tiered framework of cybersecurity standards that contractors must meet to handle sensitive unclassified DoD information, such as Controlled Unclassified Information (CUI). The program mandates third-party assessments for certification, moving beyond a self-attestation model to ensure a more robust and verifiable security baseline.

The discrepancy between perceived readiness and demonstrable compliance suggests that while contractors may understand the general requirements or have implemented some security controls, they might be struggling with the comprehensive documentation, evidence collection, and process maturity necessary for a successful CMMC audit. Achieving CMMC certification involves not only the implementation of technical controls but also the establishment of mature processes, policies, and procedures that can be consistently applied and verified.

For many contractors, particularly small and medium-sized businesses (SMBs), the challenge lies in translating their existing cybersecurity efforts into the structured framework demanded by CMMC. This often requires dedicated resources for gap analysis, remediation planning, and the meticulous collection of artifacts that prove adherence to each practice and process. The complexity can be exacerbated by the need to integrate various security tools and practices into a cohesive and auditable system.

Common mitigation strategies for this type of challenge typically involve engaging with CMMC Third-Party Assessment Organizations (C3PAOs) or consulting firms early in the preparation process. These entities can provide guidance on interpreting CMMC requirements, conducting pre-assessments to identify weaknesses, and assisting with the development of necessary documentation and evidence. Investment in training for internal staff on CMMC specifics and the use of compliance management platforms can also streamline the preparation efforts.

The reported trend highlights a critical phase in the CMMC rollout, where the initial awareness and understanding of the program are solidifying, but the practicalities of achieving and proving compliance are becoming more apparent. As the DoD moves towards full enforcement of CMMC requirements, the ability of contractors to not only implement cybersecurity measures but also to effectively demonstrate their adherence will be paramount for continued participation in the defense supply chain.

This situation underscores a broader challenge in cybersecurity compliance across various sectors: the gap between implementing security controls and being able to effectively prove that those controls are mature, consistently applied, and meet specific regulatory or contractual obligations. As compliance frameworks become more stringent and require third-party validation, organizations are increasingly faced with the need to shift from a purely technical implementation mindset to one that also prioritizes comprehensive documentation, process maturity, and audit readiness.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

vulnerability

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueCon

vulnerability

Microsoft Rolls Out 22 Fresh Security Patches

Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.

cisahigh

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA has issued a directive for immediate patching of critical vulnerabilities affecting TrueConf software. The Head Mare hacktivist group is actively exploiting these flaws to distribute the PhantomCore malware. Organizations using TrueConf are urged to apply the necessary updates to prevent further compromise.

CVE-2026-12569critical

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

The Cl0p ransomware group has claimed responsibility for exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, impacting over 40 organizations. The group is using a custom implant for data theft and extortion, demanding payment from victims. Several major companies, including Shell and Philips, are reportedly among the targeted entities, though most have only acknowledged awareness and are investigating.

gitlab

GitLab 19.3 helps enterprises scale agentic development securely

GitLab's latest update, version 19.3, enhances security and control for enterprises scaling agentic software development. Key features include running GitLab Duo Agent Platform within dedicated single-tenant environments, allowing custom model integration, and keeping AI data within existing security boundaries. The release also introduces improved secrets management, bulk SAST false positive detection, and a Flow Creator Agent for simplified automation.