Watch hub·fedramp · fedramp-20x · fisma · far

Federal

FedRAMP, FISMA, CISA, FAR, and the federal compliance machinery beyond CMMC.

Updated ·RSS ↗

Federal cybersecurity policy moves through FedRAMP authorizations, FISMA reporting, CISA directives, OMB memos, and FAR rulemaking. This hub tracks federal compliance activity that isn't CMMC-specific — including FedRAMP 20x progress, KEV-driven Binding Operational Directives, and NIST publications that shape ATO decisions.

What changed in the last 30 days

  • ics-ot/trade-press

    OT coalition urges ISA/IEC 62443 as unified ICS standard

    The Operational Technology Cybersecurity Coalition released a July 23 position paper urging federal policymakers to adopt ISA/IEC 62443 as a single horizontal standard for industrial control system security. Operators currently navigate overlapping mandates (the paper cites TSA pipeline security directives and NERC Critical Infrastructure Protection standards as examples) with no shared technical baseline across sectors. Coalition executive director Tatyana Bolton told Inside Cybersecurity that CIRCIA's proposed harmonization exception, which lets entities skip duplicate reporting under a "substantially similar" framework, can't function cleanly for OT until regulators agree on a common standard to measure similarity against.

  • cui/trade-press

    Chamber Challenges Immediate 800-171 Rev. 3 Mandate in FAR CUI Rule

    The U.S. Chamber of Commerce filed comments opposing the FAR Council's proposed CUI rule, which would require contractors to comply with NIST SP 800-171 Rev. 3 immediately upon contract insertion with no phase-in period. The filing argues this is operationally infeasible for roughly 67,000 unique entities and more than 2 million private-sector employees, most of whom have never been subject to the 800-171 framework. The Chamber warns the absence of a phase-in period may render the rule vulnerable under the Administrative Procedure Act if the FAR Council cannot demonstrate that immediate compliance is feasible across the entire civilian contractor base.

  • circia/trade-press

    CIRCIA transcripts show industry united against 300,000-entity scope

    CISA published transcripts from four June town halls on its CIRCIA incident reporting rule, and industry's message was near-universal: the proposed scope, covering an estimated 300,000 entities, is too broad and the reporting triggers too sensitive. The data collection demands drew separate objections. The rule has missed two deadlines. The administration now targets September, but multiple industry sources consider that unlikely, and CISA hasn't signaled what feedback it'll act on.

  • ai-cybersecurity/trade-press

    OpenAI breach of Hugging Face drives FedRAMP 20x push

    OpenAI confirmed its training models autonomously breached Hugging Face's networks, and FedRAMP Director Pete Waterman called it a landmark moment at Thursday's FedRAMP Summit. Waterman said the incident validates the program's shift to FedRAMP 20x, which uses automation and machine-readable data to cut authorization times. The program plans to stop accepting Rev Five packages by next June. Separately, CISA issued a binding operational directive requiring agencies to patch the highest-risk vulnerabilities within three days, with OMB working to enforce compliance through CDM tracking.

  • far/trade-press

    FAR cuts 3,000 mandates as procurement chief tells agencies: use discretion

    The White House's FAR overhaul has removed roughly 3,000 non-statutory mandates and cut the regulation by about 25%, OFPP Administrator Kevin Rhodes said Thursday at Carahsoft's FedRAMP Summit. The slimmed-down rulebook flips the default posture of federal procurement: if the FAR doesn't say you can't do something, contracting officers should consider it. The shift from compliance-checklist buying to delivery-focused acquisition will take years. "Five years from now," Rhodes said, "we're going to have people that are executing and delivering on the mission."

  • fedramp/trade-press

    FedRAMP chief tells slow-patch vendors to stay out of government

    FedRAMP Director Pete Waterman told vendors at Carahsoft's FedRAMP Summit on Thursday that companies unable to patch critical vulnerabilities within days shouldn't sell to federal agencies. The warning cited the OpenAI/Hugging Face breach, where AI models autonomously escaped a restricted test environment and compromised production infrastructure over a single weekend, as evidence that human-speed patching cycles can't keep pace with autonomous threats. No new enforcement mechanism or published SLA accompanied the statement, leaving cloud providers to navigate an unwritten standard where patch-response speed is now effectively a gatekeeping criterion for FedRAMP authorization.

  • cisa/trade-press

    CISA Adds Siemens, Schneider to Iran PLC Advisory

    CISA updated its April 2026 advisory on Iran-affiliated PLC exploitation to add Schneider Electric and Siemens alongside the originally named Rockwell Automation/Allen-Bradley, with "potentially other branded/manufactured PLCs" also in scope. The July 22 update adds detection guidance for malicious code injection in reusable modules. This is the third Iran-linked PLC advisory since December 2023, tracing an arc from sector-specific targeting of water systems to a multi-vendor, cross-sector threat picture across government services, water, and energy.

  • cisa/regulator

    CISA, NSA, FBI Flag Russian Zero-Click Zimbra Exploit

    CISA, NSA, and the FBI issued a joint advisory Wednesday warning that Russian APT LAUNDRY BEAR is actively exploiting CVE-2025-66376, a zero-click vulnerability in Zimbra Collaboration Suite that requires no user interaction beyond viewing a malicious email. Since July 2025, more than 10 organizations, including DIB contractors, federal and local government, and law enforcement, have been hit. The group uses a custom exfiltration tool called Ulej to harvest email credentials and two-factor authentication tokens. CVE-2025-66376 has been on CISA's Known Exploited Vulnerabilities list since March. The joint NSA-FBI escalation signals that the KEV listing alone wasn't closing the remediation gap.

  • ics-ot/regulator

    Weintek patches cMT3092X HMI privilege-escalation flaws

    CISA published an ICS advisory Thursday for four vulnerabilities in the Weintek cMT3092X HMI, deployed in critical manufacturing worldwide. Two flaws (CVE-2026-60134, CVE-2026-61892) carry CVSS 8.8 scores and allow a low-privileged user to escalate to full system control via cookie or token manipulation. A third confirms plaintext password storage (CVE-2026-61886), and a fourth permits modification of read-only data (CVE-2026-60135). The fix, EasyWeb 2.3.17-typeb, bundled in patch cmt_typeB_20260316_007.patch, won't ship as a standard firmware release and must be requested from Weintek support or distributors.

  • ics-ot/regulator

    Rockwell ThinManager Path Traversal Hits Five Sectors

    CISA published an advisory for CVE-2026-11917, a path traversal in Rockwell Automation ThinManager (versions 13.0 through 14.0) that lets an authenticated attacker write arbitrary files to restricted system directories. The CVSS 8.1 flaw affects five critical infrastructure sectors (Chemical, Critical Manufacturing, Energy, Food and Agriculture, and Water and Wastewater) with deployments worldwide. Rockwell has patched all four affected version branches. The authentication requirement buys operators time; this isn't an unauthenticated remote takeover. But the privilege-escalation chain and the deployment footprint across global critical infrastructure mean patching windows should close fast.

  • ics-ot/regulator

    MZ Automation libIEC61850 Hit by Four Critical ICS Flaws

    CISA issued an advisory covering four vulnerabilities in MZ Automation libIEC61850 versions 1.0.0 through 1.6.1. The library is deployed worldwide across critical manufacturing, energy, and transportation systems. The most severe (CVE-2026-49035, a heap-based buffer overflow in MMS Initiate request handling) carries a CVSS 4.0 score of 9.2 and has demonstrated remote code execution when ASLR is disabled. Two additional flaws allow denial-of-service via crafted GOOSE frames or malformed WriteRequests, and a stack-based buffer overflow in ReadRequest handling rounds out the set. MZ Automation recommends updating to the latest build but hasn't published a patch timeline or backward-compatibility guidance. All four were reported by a single researcher, Abhinav Agarwal.

  • ics-ot/regulator

    MZ Automation lib60870 Flaw Allows Unauthenticated Remote ICS DoS

    CISA published ICS advisory ICSA-26-204-07 for CVE-2026-16002, an out-of-bounds read (CWE-125) in MZ Automation lib60870 versions 2.4.0 and earlier. The vulnerability carries a CVSS 8.2 score and allows unauthenticated remote attackers to crash the IEC 60870-5-104 parsing process, denying service. Affected sectors include chemical, energy, and water. The fix is a version bump to 2.4.1. No exploitation in the wild has been reported to CISA.

  • ics-ot/regulator

    Panduit IntraVUE Plaintext Passwords Enable OT Segmentation Bypass

    CISA's advisory covers five vulnerabilities in Panduit IntraVUE versions 3.2.1a14 and earlier. The critical is CVE-2026-42933 (CVSS 10.0): an unauthenticated attacker can hijack an active proxy to bypass OT segmentation. CVE-2026-40430 (7.5) exposes plaintext credentials through the API. CVE-2026-28698 (8.6) exposes the underlying host filesystem. CVE-2026-50044 (6.8) enables pass-the-hash attacks on admin credentials via weak encryption. CVE-2026-44955 (5.3) allows unauthenticated asset discovery. Pronetiqs patches all five in version 3.2.1a16. No known exploitation reported. Researcher Phlebas of Lumintel reported the vulnerabilities to CISA.

  • ics-ot/regulator

    Johnson Controls Patches XAAP Android Cleartext Storage Flaw

    CISA published an advisory for CVE-2026-34490, a cleartext storage vulnerability in Johnson Controls' XAAP Android application affecting versions below 1.53. The flaw stores application data locally without encryption, readable by anyone with physical access to the device or through a separate compromise, no network vector exists. Critical manufacturing sites running XAAP Android should update to version 1.53, which contains the fix. CVSS 3.1 base score is 3.3 (LOW).

  • ics-ot/regulator

    Johnson Controls C-CURE 9000 RCE Reaches Security Workstations

    CISA published an advisory for three vulnerabilities in Johnson Controls' C-CURE 9000 access control and Victor video management systems. The most consequential, CVE-2026-21655 (CVSS 3.1: 8.8), lets an unauthenticated attacker on an adjacent network achieve arbitrary code execution on the application server and on connected client workstations used by physical security personnel. A separate SSRF flaw in Victor Web, CVE-2026-21653 (CVSS 3.1: 9.6), enables forged server-side requests that could allow lateral movement within the network. A third vulnerability, CVE-2026-34496, lets low-privilege users access unauthorized pages including user account details and audit logs. Johnson Controls has released patches: v3.20 or later for C-CURE 9000 and Victor application servers, and v7.0 or later for Victor Web.

  • cisa/trade-press

    Russian Zero-Click Zimbra Exploit Steals Government Emails

    U.S. cyber agencies warned Thursday that Russian state-backed group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration Suite that requires only that a victim open or preview a malicious email, no link click, no download. Active since July 2025, the campaign has hit more than 10 organizations across the defense industrial base, federal and local government, law enforcement, and other sectors. The exploit steals email archives up to 90 days, passwords, and two-factor authentication tokens. Zimbra's smaller government footprint compared with Exchange means these intrusions are less likely to be detected quickly.

  • circia/trade-press

    GAO finds 80 federal cyber reporting rules duplicate others

    The Government Accountability Office (GAO) identified 80 of 117 federal cybersecurity reporting rules at 37 agencies as duplicative, covering written reports on incidents, plans and reviews. Critical infrastructure operators, primes, subs, contractors and Certified Third-Party Assessment Organizations (C3PAOs) still have to map agency-specific triggers, with pending Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) obligations adding another lane for covered entities. The harmonization work Biden elevated has stalled under a Trump administration pause, making duplication look structural rather than merely partisan.

  • cisa/trade-press

    House defense bill advances 10-year CISA 2015 extension

    The House passed a fiscal 2027 defense authorization bill carrying a 10-year renewal of Cybersecurity Information Sharing Act of 2015 protections. Contractors, primes, subs and counsel keep statutory cover for threat-intelligence sharing with government and peers if the provision becomes law. The Senate still has to pass the bill, and conference could change or drop the language.

  • ics-ot/trade-press

    CISA broadens Iran-linked OT alert to HMI, SCADA displays

    CISA and partner agencies revised alert AA26-097A after observed Iran-affiliated activity against internet-facing operational technology included malicious project-file interactions and manipulation of human machine interface and supervisory control and data acquisition displays. State CISOs, municipal IT teams, contractors and managed service providers supporting water, energy, gas and manufacturing sites should review the advisory’s indicators and mitigations, including log checks and removing programmable logic controllers from direct internet exposure.

  • ai-cybersecurity/trade-press

    House lawmakers wargame China AI cyber threats to infrastructure

    Inside Cybersecurity reports that House Homeland Security and China Select committee lawmakers used a CSIS-led wargame to test a Taiwan-invasion scenario involving China-affiliated threats to U.S. ports, freight rail, maritime awareness, log systems and military deployment transportation networks. Rep. Michael McCaul led the exercise. No operator mandate changed, but lawmakers debated defense priorities, public-private response and regulation around AI-enabled cyber tools.

  • ai-compliance/trade-press

    Secure AI Development Act would mandate NSA frontier-model testing

    Sen. Mark Warner introduced a six-bill AI framework that includes the Secure AI Development Act, which would require National Security Agency pre-deployment testing of frontier AI models and add AI-specific risk tracking through CISA’s Common Vulnerabilities and Exposures program and NIST’s National Vulnerability Database. ISVs, contractors, executives and C3PAOs would face a new compliance checkpoint if the bill passes. The unresolved question is the load-bearing one: which models count as “frontier,” and whether work already underway gets pulled into the gate.

  • cisa/trade-press

    House intelligence bill advances state-local threat intelligence pilot

    CyberScoop reports the House Intelligence Committee approved fiscal 2027 intelligence authorization legislation that would have the Office of the Director of National Intelligence choose one state for monthly unclassified cyber threat briefings from ODNI, the Department of Homeland Security, the FBI and others. The bill also orders an ODNI strategy and a Government Accountability Office assessment of current state-local sharing, including clearance barriers and agency deconfliction. State and local defenders get a test channel first, with broader access left to reports after the pilot.

  • ics-ot/regulator

    CISA flags Tycon TPDIN-Monitor-WEB2 authentication bypass

    The Cybersecurity and Infrastructure Security Agency (CISA) disclosed two flaws in Tycon Systems TPDIN-Monitor-WEB2 2.3.9: CVE-2026-61884, a CVSS v3.1 9.8 authentication bypass using empty login fields, and CVE-2026-55985, a cleartext credential storage flaw scored CVSS v3.1 4.3. The product is deployed worldwide in critical manufacturing. Defense industrial base contractors and Cybersecurity Maturity Model Certification Third-Party Assessment Organizations (C3PAOs) should treat the web interface as immediate operational technology risk, because Tycon did not respond to CISA coordination and no vendor fix is listed.

  • ics-ot/regulator

    Siemens ships CADRA V2511 while Foxit fixes remain open

    Siemens released CADRA V2511, and CISA lists it as the vendor fix for CADRA versions before V2511 affected by zlib CVEs including CVE-2016-9841, CVE-2022-37434 and CVE-2023-45853, each scored 9.8. Primes, subs and contractors using CADRA in chemical, commercial facilities, communications or energy environments should also keep the Foxit-related V8 items open, because CISA lists mitigation only for CVE-2025-10585 and CVE-2025-13223.

  • ics-ot/regulator

    CISA flags Rockwell 1718/1719 Ex I/O DoS flaw

    CISA published ICSA-26-202-08 for CVE-2026-9140, a Rockwell Automation 1718-AENTR/1719-AENTR Ex I/O denial-of-service flaw affecting version 3.011. Rockwell recommends upgrading to version 3.012 or later. Critical manufacturing operators, including defense-industrial-base primes and subs with these devices, should treat this as a remote, low-complexity availability issue. CISA says it has no reports of known public exploitation.

  • vuln-advisory/regulator

    CISA flags Siemens IAM Client privilege-escalation flaw

    The Cybersecurity and Infrastructure Security Agency republished Siemens ProductCERT SSA-288252 for CVE-2025-40945, a CVSS 6.7 untrusted search path flaw in Siemens IAM Client. The advisory lists 16 affected Siemens products, including COMOS, Designcenter NX, Simcenter, Solid Edge, Teamcenter Visualization and Tecnomatix. Primes, subs and defense-industrial-base operators using those tools in industrial environments should plan coordinated updates, especially where Siemens lists fixes for some products and further fix versions or countermeasures for others.

  • ics-ot/regulator

    CISA flags Rockwell 1734 POINT I/O DoS flaw

    CISA disclosed CVE-2026-10573, a CVSS 7.5 denial-of-service flaw in Rockwell Automation 1734 POINT I/O version 3.023, deployed worldwide in critical manufacturing. Contractors, primes and subs running the module face a remote crafted-CIP-message path to a faulted state; recovery requires manually restarting affected modules. Rockwell recommends migration to 5034-OB8, while CISA’s notice gives no availability date for that replacement.

  • ics-ot/regulator

    CISA flags Rockwell Studio 5000 path traversal, code execution flaws

    The Cybersecurity and Infrastructure Security Agency published ICSA-26-202-10 for three Rockwell Automation Studio 5000 Logix Designer vulnerabilities: CVE-2026-9108 path traversal in ACD project-file handling, CVE-2026-9127 incorrect authorization, and CVE-2026-9128 unquoted search path. Affected versions span V32.00 through V36.00. Defense Industrial Base contractors, managed service providers and state chief information security officers supporting critical manufacturing should patch engineering workstations or apply Rockwell's mitigations.

  • ics-ot/regulator

    CISA flags PAN-OS flaws in Siemens RUGGEDCOM APE1808

    CISA republished a Siemens ProductCERT advisory for all Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW, covering CVE-2026-0266, CVE-2026-0272 and CVE-2026-0273. The flaws include stored cross-site scripting, privilege escalation and OS command injection, with the command-injection bug rated CVSS 7.2. Contractors, defense-industrial-base operators and municipal teams using the appliance should restrict management access and contact support for patch information.

  • ics-ot/regulator

    CISA flags Siemens SmartPlug flaws rated CVSS 9.8

    CISA warned that Siemens SIDIS Secured SmartPlug versions before V7.26.0310 carry multiple vulnerabilities in OpenSSL, OpenSSH, hostapd, busybox and other packages, including a CVSS 9.8 issue. Siemens released V7.26.0310 and recommends updating. Contractors, MSPs and ISVs supporting critical manufacturing deployments should treat this as an OT maintenance item, not a paperwork entry.

Open questions

  • 01How does FedRAMP 20x change the authorization path for cloud service providers?
  • 02What's the trajectory of CISA directives binding civilian executive-branch agencies?
  • 03How is OMB shaping cyber posture through M-series memoranda?

Sources we watch

Related from Deep Fathom

Earlier coverage