LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
security

US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate

Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high

zeroday.news ·

US defense contractors are reporting a significant increase in their self-assessed cybersecurity scores, reaching a five-year high, yet their confidence in the accuracy of these scores has sharply declined. This trend emerges from the 2026 State of the DIB Report, published on August 20 by CyberSheath, which surveys the cybersecurity posture of the US defense industrial base (DIB).

The average Supplier Performance Risk System (SPRS) score, a self-assessment framework used by contractors for the Cybersecurity Maturity Model Certification (CMMC), rose to +51. This marks a substantial increase from +33 in 2025, which was the first positive score recorded in the report's history. CMMC is a Department of Defense (DoD) program designed to improve cyber hygiene for contractors handling federal contract information (FCI) and controlled unclassified information (CUI). Compliance with the Defense Federal Acquisition Regulation Supplement (DFARS) makes CMMC a binding legal requirement for securing DoD contracts.

Contractors use SPRS to assess their adherence to 110 security controls outlined in NIST SP 800-171, a standard from the US National Institute of Standards and Technology (NIST), with a perfect score being 110. While self-reporting is currently the only mandate under CMMC Phase I, Phase II was intended to introduce independent assessments by Certified Third-Party Assessment Organizations (C3PAOs) to verify compliance. However, CMMC Phase II, originally slated for November 10, 2026, was suspended by the Trump administration in July 2026.

Despite the reported rise in self-assessment scores, the CyberSheath study, based on a May 2026 survey of 302 US defense contractors conducted by Merrill Research, revealed a concerning drop in confidence. Only 65% of contractors expressed extreme or very high confidence in the accuracy of their scores, a significant decrease from 89% in 2025 and 94% in 2024. This 24-percentage-point decline highlights a growing tension between reported progress and belief in its veracity.

The study also found that only 1% of contractors believe they are completely prepared for CMMC certification, a figure unchanged from an October 2025 CyberSheath study. The primary obstacle does not appear to be financial, as 53% of respondents felt their budgets were "just right," and 24% considered them more than sufficient. DFARS compliance budgets saw a sharp increase this year, averaging $155,204 annually.

The report suggests that the core challenge for the DIB is not merely the amount spent on cybersecurity, but the effectiveness of these investments in translating into implemented, sustainable, and verifiable security measures. While 52% of DIB members fear losing contracts due to non-compliance, a vast majority (90%) still support a legal mandate for minimum cybersecurity standards.

Furthermore, 77% of contractors believe DFARS compliance meaningfully enhances national security, yet they are calling for changes to its implementation. Specifically, 74% desire easier implementation processes, and 70% seek more vendor options to support compliance efforts.

Emil Sayegh, CEO of CyberSheath, emphasized that most DIB contractors are manufacturers, engineers, and specialized businesses focused on supporting military operations, not on becoming cybersecurity experts. He advocated for federal administration reform of the CMMC program to simplify effective cybersecurity consumption while maintaining objective, verifiable assurance that protections are operational. He concluded that regardless of CMMC's evolution, meaningful verification and accountability must remain central to ensuring reported compliance reflects actual operational cybersecurity.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.

malwarehigh

Malware Hijacks Android Car Head Units

Researchers have identified new Android malware that hijacks car head units by exploiting their official update mechanisms. The malware installs proxy software, turning vehicles into nodes for the BADBOX botnet, primarily for ad fraud and to provide anonymized internet connections. This marks the first documented instance of malware specifically targeting car head units through their native update channels.

malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

nasacritical

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical vulnerability has been discovered in NASA/JPL's open-source AIT-GUI software, which is used to control spacecraft instruments. The flaw allows unauthenticated attackers to execute arbitrary commands, run server-side scripts, and manipulate command sequences by exploiting a lack of authentication, session checks, and CSRF protection. Researchers confirmed the issue, which has a CVSS score of 9.4, and a fix is available in version 2.5.2.

CVE-2026-73570critical

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

CISA has added a critical vulnerability in Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-73570, allows unauthenticated remote code execution and is being actively exploited by threat actors. Zimbra released a patch for the vulnerability less than a month before exploitation was confirmed.

breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough