Trusted compliance intelligence
for the Defense Industrial Base

Stay ahead of CMMC and DoD cybersecurity developments with AI-powered news aggregation, personalized updates, and source-backed answers.

Latest
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI[Virtual Event] Building a Secure AI Strategy for the EnterpriseArmy Secretary Dan Driscoll submits resignationSharePoint: Site Skills in Copilot in SharePointArmy Secretary Dan Driscoll resignsSBA’s size standard rewrite draws angry, frustrated commentsOMB issues anticipated memo enforcing Login-dot-gov useWhite House mandates agencies use Login.gov for public-facing websitesMcKesson copes with fallout from data theft extortion attackNearly 3,150 Labor employees seeking disability accommodations impacted by data leak, internal memo saysDepartment of War Announces $174 Million Investment to Secure Gallium Supply ChainDepartment of War Invests $22.1 Million to Expand Critical Radiation Testing Infrastructure for Defense Microelectronics

Newsroom

No new filings today, showing this week's developments

Deadlines

Stacy Bostjanick: CMMC phase 1 is still in effect meaning you need to perform a self-assessment and record the score i...

CMMC phase 1 is still in effect meaning you need to perform a self-assessment and record the score in SPRS. You should meet 80% at a minimum and complete all of the requirements within 180 days of that self-attestation. Your compliance is against the NIST...

CMMC Watch · Aug 28, 2026

Rulemaking

The CUI Hotline - Weekly CMMC Q&A Livestream

Not so long ago people started asking what we would talk about after CMMC rulemaking was done. Looking ahead, there are more and larger questions than there ever were before: - How will the DoD handle a discrepancy between the FAR and DFARS requiring different NIST SP 800-171 baselines for the same data on the same contractor systems? The department specifically avoided this problem in 2024 only to reintroduce it as a very real puzzle for contractors with the Phase 2 suspension. - How will the DoD explain scoping for their future requirements? The department has spent the last month and a half saying that CUI-centric requirements "don't go far enough" and that OT security is desperately needed. But most important of all: how should contractors navigate this mess to protect themselves and get back to business? That's why we sit down every Friday to answer your questions live. 10 am PST / 1 pm EST.

Summit 7 (YouTube) · Aug 31, 2026

Have a question about this news? Ask the CMMCSimple Assistant

Chat in plain English and get answers grounded in the latest coverage, with source links. No account needed to try it. News awareness only, not legal or compliance advice.

Ask the assistant

Cyber, Defense & Compliance Intelligence

Newest first, updated continuously

Cyber News

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

The Hacker News · Sep 1, 2026

Cyber News

LastPass enhancements improve visibility, governance, and control

LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landscape. Highlights include new tools that simplify access management, enhancements that help customers get more value from LastPass, and milestones that demonstrate the company’s continued growth and industry leadership. The LastPass commitment to visibility, governance, and control comes at a

Help Net Security · Sep 1, 2026

Cyber News

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup, backed by a $1.1 million pre-seed round, is launching the tool with an international community of early testers and contributors. A SOC analyst can start the day to 50 alerts requiring manual review. An IT manager

Help Net Security · Sep 1, 2026

Cyber News

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes

Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate remediation component sitting in front of the service. Users report what they see back to the project, which curates it into a community blocklist every installation can pull down. Version 1.8.0 landed on August 31.

Help Net Security · Sep 1, 2026

Cyber News

NIS2 compliance: Fixing IAM and access control before the 2026 audit

The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into enforcement. In Austria, the national implementation law enters into force once adopted; in Poland, mandatory self-registration closes on a fixed date set by the national authority. Broader NIS2 non-compliance exposes essential entities to fines up to €10 million

Help Net Security · Sep 1, 2026

Cyber News

What your vendor says about PQC tells you if they are ready

In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto inventory and hybrid key exchange on TLS interfaces, then IPsec links. It also names the

Help Net Security · Sep 1, 2026

Cyber News

Cybersecurity jobs available right now: September 1, 2026

Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Services team. The role includes advising on secure foundational cloud implementations, automated provisioning of infrastructure and applications, and cloud-ready application architectures. Cyber Security Analyst Spait Infotech | Ireland | Hybrid – View job details As a Cyber Security Analyst,

Help Net Security · Sep 1, 2026

Government Cloud

SharePoint: Site Skills in Copilot in SharePoint

The feature introduces enhanced Site Skills management capabilities, including skill editing, version control, publishing, restoration, and cross-site duplication, enabling organizations to govern and reuse skills more effectively across SharePoint sites. GA date: September CY2026

Microsoft 365 for US Government Service Descriptions · Aug 31, 2026

Government Cloud / Cloud Security

Amazon DocumentDB now supports direct major version upgrades to version 8.0

Amazon DocumentDB (with MongoDB compatibility) now supports in-place major version upgrades (MVU) directly from engine versions 3.6 and 4.0 to version 8.0. This upgrade capability removes the need for intermediate version upgrades and allows you to upgrade your version 3.6 or 4.0 clusters while preserving existing data, configurations, and cluster settings. Upgrading to version 8.0 provides access to the latest security patches, performance improvements, and new developer capabilities. Major version upgrades from DocumentDB 3.6 and 4.0 to 8.0 are available in all AWS regions where these versions are currently supported. To learn more about upgrading to Amazon DocumentDB 8.0, including detailed guidance on version differences and upgrade paths, visit the Amazon DocumentDB MVU documentation , review version support dates , and explore the full list of new capabilities on the Amazon DocumentDB 8.0 announcement page .

AWS What's New (Recent Announcements) · Aug 31, 2026

Defense News

Army Secretary Dan Driscoll resigns

Dan Driscoll, a former soldier who came into the roll from the finance world, reportedly had a strained relationship with Defense Secretary Pete Hegseth.

Breaking Defense · Aug 31, 2026

Government Cloud / Cloud Security

Partner Revenue Measurement expands service coverage for User Agent string capability

Partner Revenue Measurement User Agent string now supports additional AWS services. Partner Revenue Measurement allows Partners to better understand their AWS revenue impact and product consumption patterns. Previously, the User Agent string capability measured AWS service consumption across select services. With this expansion, Partners can now measure attributed revenue across additional applicable AWS services that log control plane activity in AWS CloudTrail, significantly increasing the visibility Partners have into the revenue their solutions drive. Partners who have already embedded a user agent (format APN_1.1/pc_<AWS Marketplace product-code>$) in their applications automatically benefit from the expanded coverage with no additional implementation needed. The additional service consumption measured through this expansion is now visible in the Attributed Revenue Dashboard , accessible through Partner Analytics in AWS Partner Central on the AWS Console. This User Agent string method complements Partner Revenue Measurement's Resource Tagging and AWS Marketplace Metering integration capabilities. Partner Revenue Measurement is generally available in all commercial regions. To

AWS What's New (Recent Announcements) · Aug 31, 2026

Government Cloud / Cloud Security

AWS Agent Registry agents and MCP servers now available in Amazon Quick

Today, Amazon Quick announces integration with AWS Agent Registry, enabling users to discover and use resources from their organization's AWS Agent Registry directly within Amazon Quick. AWS Agent Registry supports MCP servers and agents, which users can now search and browse directly within Amazon Quick. After finding the agent or MCP server they need, users can enable it with a few clicks. Connection details are already populated from the registry. Once enabled, these resources can be shared with teams for use across chat, agents, apps, flows, and deep research. This integration bridges the gap between technical teams who build agents with Amazon Bedrock AgentCore and business users who work in Amazon Quick. Organizations no longer need to manually configure connections to agents and tools that already exist in their AWS Agent Registry. Business users get access through their familiar Amazon Quick workspace without duplicate effort. Amazon Quick integration with AWS Agent Registry is available in all AWS Regions where both Amazon Quick and Amazon Bedrock AgentCore are available. This includes US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Tokyo), Eu

AWS What's New (Recent Announcements) · Aug 31, 2026

Government Cloud / Cloud Security

Amazon Redshift now supports AWS IAM Identity Center authentication with enhanced VPC routing

Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). You can access Amazon Redshift with single sign-on with your corporate credentials, and the traffic traverses Amazon Virtual Private Cloud (Amazon VPC) and stays on the AWS network. This is valuable for customers with data residency, regulatory, or network-isolation requirements that mandate no public internet egress for analytics. With Redshift EVR, all traffic between your Redshift warehouse and other AWS services goes through your VPC, where you can govern it with security groups, network ACLs, and endpoint policies, and observe it in VPC Flow Logs. With this launch, Redshift validates and exchanges IAM Identity Center tokens over AWS PrivateLink interface VPC endpoints from inside your VPC, so authentication and authorization follows the same governed network path as the rest of your Redshift traffic. This feature also supports IAM Identity Center multi-Region replication for customers running Redshift in a different Region than their primary Identity Center instance. Read the Amazon Redshift enhanced VPC routing docu

AWS What's New (Recent Announcements) · Aug 31, 2026

Defense Acquisition

Contracts for Aug. 31, 2026

Today's Department of War contracts valued at $7.5 million or more are now live on War.gov.

DoD Contract Announcements · Aug 31, 2026

DoD

DOW Invests to Upgrade Critical Chemical Defense Materiel Facility

The War Department announced the kickoff of a five-year, nearly $19 million investment in Pine Bluff Arsenal, located near White Hall, Ark., for production and facility enhancements to improve smoke grenade and smoke pot production.

DoD News Releases · Aug 31, 2026

Government Cloud

Army R&D team uses agentic engineering to build secure, compliant code

In this post, we explain how the U.S. Army cut critical software delivery process times by up to 75% using AWS GovCloud (US) and AI-powered automation and how your R&D program can overcome lengthy authorization cycles, distributed team collaboration challenges, and Impact Level 5 (IL5) compliance requirements with SPDS.

AWS Public Sector Blog · Aug 31, 2026

Cyber News

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it will train users to ignore critical alerts, which makes them far more susceptible to attacks. The Microsoft release health dashboard update on the issue reported: “After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is functioning correctly and all settings show it as active. These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off. This issue can be observed in any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.” The post added: “We are working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.” It then listed the various Windows client and server versions impa

CSO Online · Aug 31, 2026

Threat Intelligence

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x94; history, filesystem output, working paths, and the agent&#;x26;#;39;s local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

SANS Internet Storm Center · Aug 31, 2026

Government Cloud / Cloud Security

Amazon Timestream for InfluxDB is now available in 8 additional AWS Regions

You can now use Amazon Timestream for InfluxDB in the Africa (Cape Town), Asia Pacific (Bangkok), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Melbourne), Asia Pacific (Seoul), Europe (Zurich), and Israel (Tel Aviv) AWS Regions. Timestream for InfluxDB makes it easy for application developers and DevOps teams to run fully managed InfluxDB databases on AWS for real-time time-series applications using open-source APIs. Timestream for InfluxDB offers Multi-AZ high availability, read replicas, enhanced durability, and multi-node scaling — giving you flexible deployment options to match your workload as it evolves. Whether you're starting with a single-node setup or scaling to a 15-node Enterprise cluster, you can right-size your infrastructure without re-architecting. You can create your InfluxDB databases using the Amazon Timestream for InfluxDB console . AWS CLI, or AWS SDKs . Amazon Timestream for InfluxDB is available in the following AWS Regions . For more information, see the Amazon Timestream for InfluxDB documentation and pricing page .

AWS What's New (Recent Announcements) · Aug 31, 2026

  1. 1Create a free account
  2. 2Pick your topics and platforms
  3. 3Read your tailored feed
  4. 4Ask the CMMCSimple Assistant

Get the feed your contracts depend on

Create a free account, pick your topics, and see your tailored compliance feed today.

Publish with CMMCSimple

Want to publish your news with CMMCSimple? Contact us at news@cmmcsimple.com.

Our RSS source list is reviewed and updated every two weeks on Friday, so newly accepted feeds appear with the next update.

© 2026 CMMCSimple