- 1Create a free account
- 2Pick your topics and platforms
- 3Read your tailored feed
- 4Ask the CMMCSimple Assistant
Get the feed your contracts depend on
Create a free account, pick your topics, and see your tailored compliance feed today.
Stay ahead of CMMC and DoD cybersecurity developments with AI-powered news aggregation, personalized updates, and source-backed answers.
Deadlines
Stacy Bostjanick: CMMC phase 1 is still in effect meaning you need to perform a self-assessment and record the score i...CMMC phase 1 is still in effect meaning you need to perform a self-assessment and record the score in SPRS. You should meet 80% at a minimum and complete all of the requirements within 180 days of that self-attestation. Your compliance is against the NIST...
CMMC Watch · Aug 28, 2026

Rulemaking
The CUI Hotline - Weekly CMMC Q&A LivestreamNot so long ago people started asking what we would talk about after CMMC rulemaking was done. Looking ahead, there are more and larger questions than there ever were before: - How will the DoD handle a discrepancy between the FAR and DFARS requiring different NIST SP 800-171 baselines for the same data on the same contractor systems? The department specifically avoided this problem in 2024 only to reintroduce it as a very real puzzle for contractors with the Phase 2 suspension. - How will the DoD explain scoping for their future requirements? The department has spent the last month and a half saying that CUI-centric requirements "don't go far enough" and that OT security is desperately needed. But most important of all: how should contractors navigate this mess to protect themselves and get back to business? That's why we sit down every Friday to answer your questions live. 10 am PST / 1 pm EST.
Summit 7 (YouTube) · Aug 31, 2026
Ecosystem
The Cyber AB's Response to the DoW's "Reforming CMMC and Reducing Compliance Burden (RFI)" - August 14th, 2026Ecosystem
SCF Council Partners With The Cyber AB On SCF CAP - December 18, 2024Ecosystem
Jacob Horne: Overheard at one of the DoD's CMMC Listening Sessions. From a company that has been a defense contr...
Summit 7 (YouTube) · Aug 27, 2026

Washington Technology · Aug 26, 2026
CMMC Watch · Aug 26, 2026

RealClearDefense · Aug 26, 2026
CMMC Watch · Aug 25, 2026
CMMC Watch · Aug 25, 2026
CMMC Watch · Aug 25, 2026
CMMC Watch · Aug 25, 2026
NIST CSRC Publications · Aug 26, 2026
CMMC Watch · Aug 25, 2026

Summit 7 (YouTube) · Aug 25, 2026
CMMC Watch · Aug 26, 2026
Chat in plain English and get answers grounded in the latest coverage, with source links. No account needed to try it. News awareness only, not legal or compliance advice.

Cyber News
Dark Reading · Nov 12, 2026

Cyber News
Dark Reading · Oct 8, 2026

Cyber News
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
BleepingComputer · Sep 1, 2026

Cyber News
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
The Hacker News · Sep 1, 2026

Threat Intelligence
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Securelist · Sep 1, 2026

Cyber News
LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landscape. Highlights include new tools that simplify access management, enhancements that help customers get more value from LastPass, and milestones that demonstrate the company’s continued growth and industry leadership. The LastPass commitment to visibility, governance, and control comes at a
Help Net Security · Sep 1, 2026

Cyber News
Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup, backed by a $1.1 million pre-seed round, is launching the tool with an international community of early testers and contributors. A SOC analyst can start the day to 50 alerts requiring manual review. An IT manager
Help Net Security · Sep 1, 2026

Cyber News
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
SecurityWeek · Sep 1, 2026

Cyber News
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate remediation component sitting in front of the service. Users report what they see back to the project, which curates it into a community blocklist every installation can pull down. Version 1.8.0 landed on August 31.
Help Net Security · Sep 1, 2026

Cyber News
The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into enforcement. In Austria, the national implementation law enters into force once adopted; in Poland, mandatory self-registration closes on a fixed date set by the national authority. Broader NIS2 non-compliance exposes essential entities to fines up to €10 million
Help Net Security · Sep 1, 2026

Cyber News
In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto inventory and hybrid key exchange on TLS interfaces, then IPsec links. It also names the
Help Net Security · Sep 1, 2026

Cyber News
Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Services team. The role includes advising on secure foundational cloud implementations, automated provisioning of infrastructure and applications, and cloud-ready application architectures. Cyber Security Analyst Spait Infotech | Ireland | Hybrid – View job details As a Cyber Security Analyst,
Help Net Security · Sep 1, 2026

Threat Intelligence
SANS Internet Storm Center · Sep 1, 2026

Threat Intelligence
Introduction
SANS Internet Storm Center · Aug 31, 2026

Defense News
Driscoll’s move to resign follows reports of long-standing tensions between the Army boss and Defense Secretary Pete Hegseth.
DefenseScoop · Aug 31, 2026
Government Cloud
The feature introduces enhanced Site Skills management capabilities, including skill editing, version control, publishing, restoration, and cross-site duplication, enabling organizations to govern and reuse skills more effectively across SharePoint sites. GA date: September CY2026
Microsoft 365 for US Government Service Descriptions · Aug 31, 2026
Government Cloud / Cloud Security
Amazon DocumentDB (with MongoDB compatibility) now supports in-place major version upgrades (MVU) directly from engine versions 3.6 and 4.0 to version 8.0. This upgrade capability removes the need for intermediate version upgrades and allows you to upgrade your version 3.6 or 4.0 clusters while preserving existing data, configurations, and cluster settings. Upgrading to version 8.0 provides access to the latest security patches, performance improvements, and new developer capabilities. Major version upgrades from DocumentDB 3.6 and 4.0 to 8.0 are available in all AWS regions where these versions are currently supported. To learn more about upgrading to Amazon DocumentDB 8.0, including detailed guidance on version differences and upgrade paths, visit the Amazon DocumentDB MVU documentation , review version support dates , and explore the full list of new capabilities on the Amazon DocumentDB 8.0 announcement page .
AWS What's New (Recent Announcements) · Aug 31, 2026

Defense News
Dan Driscoll, a former soldier who came into the roll from the finance world, reportedly had a strained relationship with Defense Secretary Pete Hegseth.
Breaking Defense · Aug 31, 2026
Cyber News
McKesson admits breach as ShinyHunters demands $55.2M
The Register - Security · Aug 31, 2026

Government Contracting
Critics say the rule would turn the small business program into a marketplace dominated by the biggest players.
Washington Technology · Aug 31, 2026
Government Cloud / Cloud Security
Partner Revenue Measurement User Agent string now supports additional AWS services. Partner Revenue Measurement allows Partners to better understand their AWS revenue impact and product consumption patterns. Previously, the User Agent string capability measured AWS service consumption across select services. With this expansion, Partners can now measure attributed revenue across additional applicable AWS services that log control plane activity in AWS CloudTrail, significantly increasing the visibility Partners have into the revenue their solutions drive. Partners who have already embedded a user agent (format APN_1.1/pc_<AWS Marketplace product-code>$) in their applications automatically benefit from the expanded coverage with no additional implementation needed. The additional service consumption measured through this expansion is now visible in the Attributed Revenue Dashboard , accessible through Partner Analytics in AWS Partner Central on the AWS Console. This User Agent string method complements Partner Revenue Measurement's Resource Tagging and AWS Marketplace Metering integration capabilities. Partner Revenue Measurement is generally available in all commercial regions. To
AWS What's New (Recent Announcements) · Aug 31, 2026

Federal Policy
The White House hit send on a memo to agencies pushing for Login to be the single sign-on option for public-facing federal websites.
FedScoop · Aug 31, 2026

Federal Policy
The Trump administration will still allow agencies to use commercial credential service providers in addition to the in-house capability, but it is strongly encouraging them to promote Login.gov.
Nextgov/FCW · Aug 31, 2026

Cyber News
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility.
CyberScoop · Aug 31, 2026

Federal Policy
A recently disclosed data leak impacts employees who have submitted reasonable accommodation requests since October 2023.
Government Executive · Aug 31, 2026
DoD
The War Department announced an estimated $174 million equity financing investment to construct a new gallium production facility at Alcoa's alumina refinery in Wagerup, Australia.
DoD News Releases · Aug 31, 2026
DoD
The War Department announced the award of a $22.1 million, 24-month contract that will significantly expand and enhance domestic radiation testing infrastructure necessary for qualifying radiation-hardened microelectronics.
DoD News Releases · Aug 31, 2026

Cyber News
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading · Aug 31, 2026
Defense News
The Pentagon's framework agreements with General Dynamics and Lockheed include tripling Patriot production and quadrupling THAAD interceptor output.
Defense News · Aug 31, 2026

Federal Policy
Critics of President Trump’s plan to keep most federal employees’, save for federal law enforcement officers and military service members, pay at 2026 levels say it picks winners and losers.
Government Executive · Aug 31, 2026
Government Cloud / Cloud Security
Today, Amazon Quick announces integration with AWS Agent Registry, enabling users to discover and use resources from their organization's AWS Agent Registry directly within Amazon Quick. AWS Agent Registry supports MCP servers and agents, which users can now search and browse directly within Amazon Quick. After finding the agent or MCP server they need, users can enable it with a few clicks. Connection details are already populated from the registry. Once enabled, these resources can be shared with teams for use across chat, agents, apps, flows, and deep research. This integration bridges the gap between technical teams who build agents with Amazon Bedrock AgentCore and business users who work in Amazon Quick. Organizations no longer need to manually configure connections to agents and tools that already exist in their AWS Agent Registry. Business users get access through their familiar Amazon Quick workspace without duplicate effort. Amazon Quick integration with AWS Agent Registry is available in all AWS Regions where both Amazon Quick and Amazon Bedrock AgentCore are available. This includes US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Tokyo), Eu
AWS What's New (Recent Announcements) · Aug 31, 2026

Federal Policy
After months of security testing, Pentagon adds an OpenAI product to the list of AI tools approved for unclassified work.
Nextgov/FCW · Aug 31, 2026
Government Cloud / Cloud Security
Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). You can access Amazon Redshift with single sign-on with your corporate credentials, and the traffic traverses Amazon Virtual Private Cloud (Amazon VPC) and stays on the AWS network. This is valuable for customers with data residency, regulatory, or network-isolation requirements that mandate no public internet egress for analytics. With Redshift EVR, all traffic between your Redshift warehouse and other AWS services goes through your VPC, where you can govern it with security groups, network ACLs, and endpoint policies, and observe it in VPC Flow Logs. With this launch, Redshift validates and exchanges IAM Identity Center tokens over AWS PrivateLink interface VPC endpoints from inside your VPC, so authentication and authorization follows the same governed network path as the rest of your Redshift traffic. This feature also supports IAM Identity Center multi-Region replication for customers running Redshift in a different Region than their primary Identity Center instance. Read the Amazon Redshift enhanced VPC routing docu
AWS What's New (Recent Announcements) · Aug 31, 2026

Defense News
Sources shared new details about this long-anticipated integration, which DOD officials announced on Monday.
DefenseScoop · Aug 31, 2026
Defense Acquisition
Today's Department of War contracts valued at $7.5 million or more are now live on War.gov.
DoD Contract Announcements · Aug 31, 2026
DoD
The War Department announced a $37.2 million contract with Principal Mineral Company Inc. of Southlake, Texas, bringing the total investment in Camden Copper to $74.9 million to revitalize domestic production of defense-grade electrodeposited copper foil.
DoD News Releases · Aug 31, 2026

Cyber News
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million.
BleepingComputer · Aug 31, 2026
DoD
The War Department announced the kickoff of a five-year, nearly $19 million investment in Pine Bluff Arsenal, located near White Hall, Ark., for production and facility enhancements to improve smoke grenade and smoke pot production.
DoD News Releases · Aug 31, 2026

Government Cloud
In this post, we explain how the U.S. Army cut critical software delivery process times by up to 75% using AWS GovCloud (US) and AI-powered automation and how your R&D program can overcome lengthy authorization cycles, distributed team collaboration challenges, and Impact Level 5 (IL5) compliance requirements with SPDS.
AWS Public Sector Blog · Aug 31, 2026

Cyber News
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
The Record · Aug 31, 2026

Government Contracting
An agency spokesperson said the four-year Learning Insights for Action project “will enable CMS to efficiently target resources across models with varying periods of performance and support cross-model learning.”
Washington Technology · Aug 31, 2026
Cyber News
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading · Aug 31, 2026

Cyber News
Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it will train users to ignore critical alerts, which makes them far more susceptible to attacks. The Microsoft release health dashboard update on the issue reported: “After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is functioning correctly and all settings show it as active. These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off. This issue can be observed in any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.” The post added: “We are working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.” It then listed the various Windows client and server versions impa
CSO Online · Aug 31, 2026

Defense News
U.S. Air Force Chief of Staff Ken Wilsbach visited Israel recently and met with Israel Defense Forces and Israeli Air Force top officials.
Defense News · Aug 31, 2026

Threat Intelligence
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x94; history, filesystem output, working paths, and the agent&#;x26;#;39;s local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
SANS Internet Storm Center · Aug 31, 2026
Government Cloud / Cloud Security
You can now use Amazon Timestream for InfluxDB in the Africa (Cape Town), Asia Pacific (Bangkok), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Melbourne), Asia Pacific (Seoul), Europe (Zurich), and Israel (Tel Aviv) AWS Regions. Timestream for InfluxDB makes it easy for application developers and DevOps teams to run fully managed InfluxDB databases on AWS for real-time time-series applications using open-source APIs. Timestream for InfluxDB offers Multi-AZ high availability, read replicas, enhanced durability, and multi-node scaling — giving you flexible deployment options to match your workload as it evolves. Whether you're starting with a single-node setup or scaling to a 15-node Enterprise cluster, you can right-size your infrastructure without re-architecting. You can create your InfluxDB databases using the Amazon Timestream for InfluxDB console . AWS CLI, or AWS SDKs . Amazon Timestream for InfluxDB is available in the following AWS Regions . For more information, see the Amazon Timestream for InfluxDB documentation and pricing page .
AWS What's New (Recent Announcements) · Aug 31, 2026

Cyber News
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
The Record · Aug 31, 2026

Federal Policy
The AbilityOne Commission countered that “many of the compliance concerns cited by [the Office of Special Counsel] occurred during periods of operational disruption, including the pandemic.”
Government Executive · Aug 31, 2026
DoD
The War Department announced that it made a $4 million investment in a national initiative to strengthen America's manufacturing and defense industrial base.
DoD News Releases · Aug 31, 2026
Create a free account, pick your topics, and see your tailored compliance feed today.
Want to publish your news with CMMCSimple? Contact us at news@cmmcsimple.com.
Our RSS source list is reviewed and updated every two weeks on Friday, so newly accepted feeds appear with the next update.
© 2026 CMMCSimple