Watch hub·fedramp · fedramp-20x · fisma · far

Federal

FedRAMP, FISMA, CISA, FAR, and the federal compliance machinery beyond CMMC.

Updated ·RSS ↗

Federal cybersecurity policy moves through FedRAMP authorizations, FISMA reporting, CISA directives, OMB memos, and FAR rulemaking. This hub tracks federal compliance activity that isn't CMMC-specific — including FedRAMP 20x progress, KEV-driven Binding Operational Directives, and NIST publications that shape ATO decisions.

What changed in the last 30 days

  • vuln-advisory/standards

    CISA puts first PAN-OS GlobalProtect auth bypass on KEV

    CISA added CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect portal and gateway interfaces, to its Known Exploited Vulnerabilities catalog on June 22 based on evidence of active exploitation. The vulnerability affects PAN-OS 10.2, 11.1, and 11.2 across dozens of patch trains when GlobalProtect is configured with authentication override cookies enabled and a specific certificate configuration present. Palo Alto Networks reports limited exploit attempts in the wild. Prisma Access customers are on a managed upgrade schedule; self-managed PAN-OS instances require immediate patching.

  • ai-cybersecurity/trade-press

    AI sharpens threat to underfunded commercial critical infrastructure

    John Garstka, director of cyber warfare under the Pentagon's acquisition arm, warned at the Billington Cybersecurity Summit on Sept. 8 that AI is compounding the cybersecurity challenges facing commercially owned critical infrastructure providers, the same entities the Defense Department depends on for missions like those of U.S. Transportation Command. Garstka said providers "below the cybersecurity poverty line" are most exposed, and noted that Iranian nation-state actors are already creating effects against commercial critical infrastructure. DOD has run workshops with the Maryland National Guard on water, wastewater, and energy sectors to help operators build continuity plans for cyber attacks.

  • cisa/trade-press

    CISA's Andersen warns technical debt risks 'the worst that could happen'

    CISA Acting Director Nick Andersen delivered a blunt warning at the Billington CyberSecurity Summit on Wednesday: decades of bad IT decisions and overwhelming technical debt have left the country exposed to serious cyberattacks, and the AI threat is shrinking the window to respond. The agency is hiring about 250 screened staff who are awaiting security clearances, part of a broader push to refill roughly 600 positions after DOGE-related cuts and attrition. Andersen also confirmed a binding operational directive on AI and vulnerability management is due this week, telling reporters the government needs to move faster than the threat.

  • ai-cybersecurity/trade-press

    FBI tells defenders AI hasn't changed the kill chain

    FBI deputy assistant director Jason Bilnoski said Tuesday that AI is accelerating attacker speed and capability but isn't altering the fundamental nature of intrusions. "What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday," he told CyberScoop and the Billington CyberSecurity Summit, pointing to the Bureau's 10-item cyber-hygiene basics list. Colleen Ferranti, assistant section chief for cyber engagement, added that quarterly patching is no longer viable given AI's vulnerability-discovery pace, pushing organizations toward continuous, risk-based patching. The remarks came ahead of an FBI cyber strategy release Wednesday.

  • cisa/trade-press

    Microsoft ships record 973 patches; CISA flags two actively exploited flaws

    Microsoft's September Patch Tuesday landed at 973 vulnerabilities, the fourth consecutive record-breaking month. CISA added two of them, CVE-2026-81963 and CVE-2026-85880, to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22 to patch under BOD 22-01. CVE-2026-81963 is the more alarming of the two: it lives in the Windows update stack, the mechanism that installs patches. As Automox engineer Serena DiPenti put it, "an attacker who owns the update stack owns the thing you'd use to evict them."

  • ai-cybersecurity/regulator

    NSA, CISA, FBI Name Six Chinese Firms Running Industrial AI Distillation

    NSA, CISA, and the FBI identified six Chinese AI firms, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, conducting industrial-scale knowledge distillation of U.S. frontier AI models since at least late 2024. The advisory says distillation forms "the critical core" of these firms' development strategy, not a supplement to it. The companies used proxy "transfer stations," bulk-purchased premium subscriptions shared across developer teams, and automated failover between pathways to extract billions of tokens across millions of requests from Claude, GPT, Gemini, and Grok variants. The agencies recommend U.S. AI vendors implement anomalous-prompt detection, deploy targeted response alterations to degrade distillation payoffs, and establish cross-organization intelligence sharing.

  • ai-cybersecurity/trade-press

    NSA turns to AI to triage intelligence data faster

    NSA is exploring AI tools to accelerate how analysts triage the enormous volumes of intercepted communications and electronic signals the agency collects daily, cybersecurity directorate chief David Imbordino said Tuesday at the Billington Cybersecurity Summit. "Volume has always been a problem," Imbordino told the Five Eyes panel, framing AI as a way to surface "the nuggets" faster than methods that currently take days or weeks. The effort sits alongside NSA's broader role implementing a June executive order that directs national security agencies to create classified tests for frontier AI models with advanced cyber capabilities.

  • ics-ot/regulator

    CareCam IP Camera Bootloader Uses Hardcoded Credential

    CISA published an advisory for CVE-2026-85083, a hardcoded-credential vulnerability in the bootloader of CareCam Pro IP cameras running on ANJIA AJL33PC0801 hardware with firmware compiled August 2020. An attacker with physical access can gain privileged bootloader access and compromise the device completely, modify firmware, alter configuration, take full control. CareCam didn't respond to CISA's coordination attempts, so no vendor fix has been announced. The vulnerability isn't remotely exploitable, but organizations using these cameras in commercial facilities worldwide have no remediation path beyond network segmentation and physical access controls.

  • ics-ot/trade-press

    IST sprints to build AI-OT cyber framework for cash-strapped operators

    The Institute for Security and Technology launched a 100-day initiative on August 27 to produce policy guidance for OT/ICS operators who are "target rich, cyber poor", lacking dedicated cybersecurity talent, budget, or tools. Five working groups will address consequence analysis, sector engagement, pragmatic guidance for those operators, novel mitigations, and policy-incentive design, with a report due December 10. IST's framing acknowledges a gap between existing CISA and NIST AI-security guidance and the operational reality of cash-constrained critical-services providers facing AI-enabled threats.

  • ics-ot/regulator

    ArmorStart LT Gets Stored XSS, DoS Patches in v2.002

    CISA published advisory ICSA-26-246-04 for Rockwell Automation ArmorStart LT, covering two vulnerabilities in firmware v2.001 and earlier. CVE-2026-19471 lets an unauthenticated attacker plant stored cross-site scripting payloads on the embedded webserver (CVSS 7.3). CVE-2026-19472 crashes that same webserver via a crafted HTTP PUT request (CVSS 7.5). Both are network-accessible and require no authentication. Rockwell shipped the fix in v2.002 and recommends all users update. The advisory is a republication of Rockwell's own disclosure; no known public exploitation has been reported to CISA.

  • ics-ot/regulator

    ControlFLASH installer grants Everyone write access to directory

    CISA republished a Rockwell Automation advisory for ControlFLASH ≤v15.07: the installer grants the "Everyone" group write permissions on the product installation directory, enabling arbitrary code execution at the logged-in user's privilege level. Version 15.08 removes the permission. Organizations that can't patch immediately can strip the Everyone group from the folder manually. Critical manufacturing, energy, and water systems are the affected sectors. No known public exploitation, and the vulnerability is local, not remotely exploitable.

  • ics-ot/regulator

    Rockwell 1756-ENBT module has no-patch DoS vulnerability

    CISA published an advisory for CVE-2025-10478, a denial-of-service vulnerability affecting all versions of the Rockwell Automation 1756-ENBT EtherNet/IP bridge module. A single crafted CIP packet can remotely crash the device; recovery requires a physical restart. Rockwell has discontinued the 1756-ENBT and won't issue a patch. The recommended path is an upgrade to the 1756-EN2T or 1756-EN4TR, but no migration timeline, cost guidance, or compatibility verification process has been published for operators running legacy ControlLogix environments.

  • cisa/regulator

    Ignition 8.1.53 ships blank project-creation role, CISA flags CVE-2026-77393

    CISA disclosed CVE-2026-77393 in Inductive Automation Ignition 8.1.53 and earlier: the "Create Project Role(s)" setting shipped blank, so any authenticated user who can execute gateway scripts can create projects. The flaw is a default-configuration issue, not a broken access control, populate the setting and the vulnerability closes. Inductive Automation recommends upgrading to 8.1.54, which restricts project creation to Designer sessions and drops reliance on the setting entirely. The 8.3 series is unaffected. CVSS 3.1: 8.8. Critical manufacturing and energy environments are the primary concern.

  • ics-ot/regulator

    Tycon TPDIN-Monitor-WEB3 firmware patches hard-coded creds, CSRF, missing auth

    CISA disclosed three vulnerabilities in Tycon Systems TPDIN-Monitor-WEB3 firmware ≤2.2.9: hard-coded credentials (CVE-2026-77847, CVSS 6.5), cross-site request forgery (CVE-2026-82712, CVSS 8.8), and missing authorization (CVE-2026-82684, CVSS 8.1). The devices are deployed worldwide in critical manufacturing and energy networks. Tycon released firmware v2.4.2, but units on v2.2.9 can't ingest the signed .tfw container, they need the legacy Intel HEX build, which means a direct, out-of-band flash for every fielded unit.

  • ics-ot/regulator

    Silent 9.8 Buffer Overflow Found in Pyramid NetStaX Stack

    CISA published an advisory September 3 for CVE-2026-78012, a stack-based buffer overflow (CVSS 9.8) in Pyramid Solutions' NetStaX EtherNet/IP Stack affecting all eight product variants below v5.6.1, the Adapter and Scanner Development Kits and DLL Kits, spanning critical manufacturing, energy, water, and chemical sectors. A large Class 3 explicit-message request overflows the receive buffer without generating a CIP error or warning; the originating device gets no indication the request failed. NetStaX v5.6.1 adds a compile-time assertion paired with a runtime payload-size check, plus clearer documentation of packet and buffer-size constant relationships.

  • vuln-advisory/regulator

    IXON VPN Client CRLF injection flaw scores 9.6 CVSS

    CISA published ICS Advisory ICSA-26-246-02 for CVE-2026-75925, a CRLF injection vulnerability in IXON VPN Client versions below 1.4.7. An unauthenticated attacker can inject configuration directives that a privileged subprocess later executes as root or SYSTEM. The injected configuration persists across restarts. IXON's cloud began rejecting connections from unpatched clients on August 5, 2026, so unpatched installations can no longer complete the exploit chain. Legacy installations that were already compromised before the cloud-side block, however, retain any injected backdoors, and the cloud rejection does nothing to remove them.

  • ics-ot/regulator

    OPC UA LDS installer flaw lets local attackers hijack high-privilege sessions

    CISA published an advisory for CVE-2026-77477, a privilege-escalation vulnerability in OPCFoundation OPC UA LocalDiscoveryServer installers prior to version 1.04.420. A local attacker with keyboard and display access during installation can intercept a high-privilege console window and run arbitrary commands. Affected sectors include chemical, energy, water, food and agriculture, and critical manufacturing. OPCFoundation recommends updating to the 1.04.420 installer. The vulnerability carries a CVSS 3.1 score of 4.6, low severity on paper, but the LDS ships inside SIMATIC NET PC Software, WinCC, PCS 7, and a long tail of industrial products where installers may have been run once and forgotten.

  • nist/regulator

    CISA and G7 Issue Joint Call for PQC Transition

    CISA and the G7 Cyber Security Working Group jointly released a post-quantum cryptography transition framework urging organizations and governments to begin migrating cryptographic systems now. The call to action sets out five priorities: awareness, national strategies, R&D, public-private partnerships, and integrating PQC into procurement requirements. It's the first time the quantum threat has been framed as a coordinated international demand rather than a single-nation research program. The framework doesn't impose mandates, but its procurement language arrives alongside CISA's January 2026 product-category list, which says agencies should acquire only PQC-capable products in categories where they're widely available.

  • cisa/trade-press

    Thompson pushes DHS worldwide threats hearing on Iran cyber campaign

    House Homeland Security ranking member Bennie Thompson (D-MS) is pressing Chairman Andrew Garbarino (R-NY) to convene a worldwide threats hearing, citing the July 22 update to CISA's joint advisory on Iran-affiliated actors exploiting internet-connected PLCs across U.S. critical infrastructure. Thompson also flags AI and quantum computing risks, the loss of nearly one-third of CISA's workforce over 18 months, and a DHS shutdown that Noem acknowledged has hampered the agency's threat-sharing with critical infrastructure stakeholders.

  • cisa/trade-press

    CISA 2015 liability shield extended to Dec. 11 in stopgap spending bill

    The House approved a continuing resolution that extends the Cybersecurity Information Sharing Act of 2015's liability and antitrust protections through December 11. The Senate added the CISA 2015 extension to the CR in August; the House had omitted it from its July version. The stopgap now heads to the White House. Without the extension, the law's protections would lapse September 30. The House-passed fiscal 2027 NDAA includes a nine-year CISA 2015 reauthorization, but the Senate hasn't acted on it, leaving a narrow window and no clear legislative vehicle for a permanent fix before the December cliff.

  • cisa/regulator

    CISA and FBI Release Crisis Comms Guidance for IT/OT Outages

    CISA and the FBI published joint guidance on crisis communications for service providers managing IT and OT outages. The document walks through core messaging principles (clarity, accountability, transparency) and stresses the need to plan for cascading disruptions and unreliable telecoms during incidents. It's advisory, not a mandate. No templates, no specific notification timelines for customers or law enforcement, and no framework for resolving the tension between early disclosure and investigative holds. Providers who already have a crisis comms plan won't find new obligations here; those who don't have a starting point.

  • cisa/trade-press

    Congress Punts CISA 2015 to December in Fourth Short-Term Patch

    Congress extended the Cybersecurity Information Sharing Act of 2015 through early December in the continuing resolution passed Tuesday, the fourth short-term patch in 18 months for the law that underpins threat-data sharing between government and industry. The liability and privacy protections enable programs including Treasury's Gold Eagle AI vulnerability clearinghouse. Senate Homeland Security Chairman Rand Paul (R-Ky.) remains the obstacle to long-term reauthorization, holding out for free-speech restrictions on CISA. Practitioners get 90 days of certainty and the same open question they've had since last fall.

  • procurement/independent

    CAS Board Doubles Full-Coverage Threshold to $100M

    The CAS Board published two final rules September 1, effective October 1, that double the full-coverage threshold from $50M to $100M, raise the basic coverage threshold from $2.5M to $35M, and eliminate the trigger-contract framework. The Board also rescinded CAS 407, which governed standard-cost accounting for direct material and direct labor. More than 200 entities stand to shed full CAS obligations. But the rules cut both ways: single-award IDCs will now be assessed for CAS applicability at the ceiling value, not the task-order level, meaning some contractors will face full CAS on vehicles they'd structured to stay under the old threshold.

  • cisa/standards

    PowerShell RAT and Dual RMM Tools Target SLTT Governments

    CIS CTI identified an active phishing campaign targeting U.S. SLTT governments with a custom PowerShell WebSocket RAT and dual remote monitoring and management tools for persistence. The adversary chains a PowerShell backdoor with two separate RMM installations, betting that under-resourced government IT teams won't detect all three. The dual-RMM approach echoes CISA's 2023 advisory on malicious RMM use, but the deliberate redundancy signals an adversary who expects endpoint monitoring gaps and builds around them.

  • ics-ot/regulator

    Rockwell Historian ME Hit by RCE and DoS Bugs

    CISA and Rockwell Automation disclosed two vulnerabilities in Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 is an out-of-bounds write that allows a low-privilege authenticated attacker on an adjacent network to achieve remote code execution (CVSS 8.6). CVE-2026-12661 is a stack-based buffer overflow that lets a network-adjacent authenticated attacker crash the device via crafted web-interface requests (CVSS 4.8). The advisory lists corrected versions but doesn't specify version numbers or a patch timeline. Affected sectors include chemical, critical manufacturing, food and agriculture, healthcare, and water and wastewater systems worldwide.

  • ics-ot/regulator

    Rockwell RSLinx Classic needs 4.60 upgrade to fix four DoS flaws

    CISA issued an advisory covering four denial-of-service vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and earlier. Each can be triggered remotely by sending a malformed CIP packet to the affected service, no authentication required. The fix is an upgrade to version 4.60. The product is deployed globally across critical manufacturing, and the two highest-severity CVEs (CVE-2026-9621, CVE-2026-9622) score 9.2 under CVSS v4.0. Rockwell hasn't published a timeline for mitigations on systems that can't move off 4.50.

  • ics-ot/regulator

    CISA Flags High-Severity DoS Flaw Across Rockwell Logix Platform

    CISA published an advisory for CVE-2021-42260, a high-severity denial-of-service vulnerability in Rockwell Automation ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480 controllers. Corrupt crafted data can trigger a major nonrecoverable fault (MNRF). Safety controllers require a full program download to recover; non-safety controllers need a stage 2 reset. Rockwell recommends updating to firmware versions 34.015, 35.014, 36.013, or 37.011 and later. The advisory covers firmware lines 34 through 37 across all five current-generation Logix families.

  • ics-ot/regulator

    Logix Platform DoS Hits ControlLogix, CompactLogix, GuardLogix

    CISA released an advisory for CVE-2026-9637, an uncontrolled resource consumption vulnerability in Rockwell Automation's Logix platform (ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380) affecting versions through V36.x. The flaw is exploitable remotely with low attack complexity (CVSS 7.5 under v3.1, 8.7 under v4.0) and produces a denial-of-service condition requiring a power cycle to recover. Remediation is a firmware upgrade to V37.011 or patched versions V34.015, V35.014, and V36.013. No public exploitation has been reported to CISA.

  • ics-ot/regulator

    Rockwell FactoryTalk Activation Manager gets privilege escalation patch

    CISA published an advisory for CVE-2026-16675 (CVSS 7.8), a privilege escalation vulnerability in Rockwell Automation FactoryTalk Activation Manager V5.02 and below. The flaw arises from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair. An authenticated attacker with Windows credentials can hijack those windows to obtain a SYSTEM-level command prompt, gaining full access to local files, processes, and system resources. Rockwell recommends updating to V5.03. No known public exploitation has been reported to CISA.

  • far/regulator

    OMB Raises Cost Accounting Standards Thresholds, Clarifies IDC Rules

    OMB's Cost Accounting Standards Board published a final rule increasing CAS monetary thresholds and clarifying how exemptions apply to indefinite delivery contracts. Contractors whose negotiated contract values previously triggered CAS coverage may now fall below the updated thresholds. The IDC clarification addresses whether exemptions are evaluated at the task-order level or against aggregate contract value, a distinction that determines whether a contractor faces CAS compliance obligations at all. The rule also increases agency waiver authority thresholds.

Open questions

  • 01How does FedRAMP 20x change the authorization path for cloud service providers?
  • 02What's the trajectory of CISA directives binding civilian executive-branch agencies?
  • 03How is OMB shaping cyber posture through M-series memoranda?

Sources we watch

Related from Deep Fathom

Earlier coverage