Category: Government

  • Pentagon Suspends CMMC Phase II Rollout as Reform Task Force Reviews Program

    Pentagon Suspends CMMC Phase II Rollout as Reform Task Force Reviews Program

    The Department of Defense has suspended Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that were scheduled to take effect November 10, 2026, while a reform task force reviews the program, according to an August 31, 2026 report from Security Info Watch. Phase I self-assessments and current NIST SP 800-171 Revision 2 obligations remain in effect for defense contractors.

    What’s Paused, What Isn’t

    Level 1 self-assessments covering 15 safeguarding requirements from FAR clause 52.204-21 continue on their annual cycle, and Level 2 self-assessments against the 110 security requirements in NIST SP 800-171 Rev. 2 continue every three years with annual affirmation, with results still required in the Supplier Performance Risk System (SPRS). For contracts under DFARS clause 252.204-7012, contracting officers must still verify a current SPRS assessment score before certain awards, extensions or option exercises. Only the timing of third-party CMMC Phase II assessments has changed, not the underlying obligation to safeguard Controlled Unclassified Information, Bill Osborne, vice president of Defense Sector Services at Magna5, told the publication.

    Why It Matters

    The pause gives contractors more time to fix gaps in scope, documentation and System Security Plans before a Third-Party Assessment Organization is engaged, rather than a reason to slow readiness work altogether. Compliance requirements of this kind sit alongside physical protections for critical infrastructure and defense-linked targets that state-linked threat actors continue to probe.

  • CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    CISA Ends Six Free Cybersecurity Assessments for Critical Infrastructure Operators

    The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed it is ending six free assessment programs long used by critical infrastructure operators to evaluate their cybersecurity posture, Cybersecurity Dive reported.

    What’s New

    CISA’s regional field staff will no longer conduct Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys. All six relied on CISA’s Cyber Security Evaluation Tool (CSET). Acting Cybersecurity Division head Chris Butera said eliminating the “legacy assessments” would “reduce redundancy for CISA and organizations requesting an assessment,” adding that operators can instead reference CISA’s Cybersecurity Performance Goals.

    Why It Matters

    Experts told Cybersecurity Dive that the Cybersecurity Performance Goals are not a substitute for the hands-on, in-person guidance the discontinued assessments provided. Tatyana Bolton, executive director of the OT Cyber Coalition, said “severe budget cuts have forced CISA into a corner where they can no longer provide the level of hands-on, operational support to critical infrastructure that they once did.” The change follows a reported loss of roughly a third of CISA’s workforce and comes as small utilities and rural operators — among the heaviest users of the free assessments — face rising cyber and physical threats with fewer federal resources to call on.

  • Philippine Nuclear and Naval Targets Hit by Suspected Chinese-Speaking Operator

    Philippine Nuclear and Naval Targets Hit by Suspected Chinese-Speaking Operator

    A suspected Chinese-speaking threat actor breached Philippine nuclear research and naval-related organizations by exploiting known vulnerabilities in internet-facing ownCloud and WordPress systems, stealing sensitive data including nuclear reactor component databases and personnel records, according to Security Affairs and independent research from Hunt.io.

    Known Vulnerabilities, High-Value Targets

    The intrusions exploited two previously disclosed vulnerabilities — CVE-2023-49105 and CVE-2024-28000 — rather than a novel zero-day, underscoring how unpatched, internet-exposed systems remain a viable entry point into sensitive government and defense-adjacent networks years after fixes became available. Hunt.io researchers linked the activity to infrastructure including an IP address at 31.58.209[.]241, and found that stolen data was organized using Chinese-language folder and file names, including terms corresponding to “Nuclear Material Accounts” and “IT Planning,” along with code comments and docstrings that strongly suggest the operator is a native Chinese speaker or highly fluent in the language.

    Intelligence Collection, Not Opportunistic Crime

    Researchers characterized the operation as consistent with targeted intelligence collection against high-value defense and scientific institutions rather than financially motivated cybercrime. The theft of nuclear reactor component data and personnel records from two organizations raises particular concern given the sensitivity of nuclear material accounting information, which is typically subject to international safeguards and non-proliferation reporting requirements.

    Recommended Response

    Security Affairs and Hunt.io both recommend that organizations running ownCloud and WordPress promptly apply available patches, upgrade to supported versions, and enforce strong authentication measures given the continued exploitation of these older, publicly known flaws. The incident adds to a broader pattern of suspected Chinese state-linked operators targeting critical infrastructure and defense-adjacent organizations across the Indo-Pacific region, an area of persistent concern for U.S. and allied cybersecurity agencies monitoring pre-positioning activity ahead of potential regional conflict scenarios.

  • Public Transit and Bus Depot Security Technology

    Public Transit and Bus Depot Security Technology

    Public transit systems present a distinct security challenge: they must remain open, accessible and fast-moving for millions of daily riders while simultaneously protecting vehicles, depots, stations and passengers from crime, vandalism and, in rarer cases, deliberate attack. Unlike a controlled-access facility, a transit network is deliberately porous by design, which shapes the technology choices operators make.

    Onboard and Station Video Surveillance

    Modern transit fleets deploy multi-camera systems on every vehicle, covering the driver compartment, passenger cabin, doors and exterior approach zones, with footage typically recorded locally and synchronized to a central video management system whenever the vehicle returns to a depot or passes through a wireless upload zone. Stations and platforms are covered by fixed and pan-tilt-zoom cameras integrated with the same VMS, allowing operators to follow an incident across a rider’s entire journey rather than reviewing disconnected clips from separate systems.

    Depot and Yard Perimeter Protection

    Bus and rail depots concentrate high-value rolling stock, fuel or charging infrastructure, and maintenance facilities in a single location, making perimeter security a priority distinct from the open transit network itself. Depots typically combine fenced perimeters, access-controlled gates, license plate recognition for fleet and visitor vehicles, and video analytics tuned to detect loitering or unauthorized entry after operating hours, when yards are otherwise unattended.

    Real-Time Operator Communication and Panic Alerts

    Driver safety technology has become a growing focus as assaults on transit operators have drawn regulatory and labor attention. Systems now commonly include silent panic buttons that alert dispatch and trigger live video and audio streaming from the vehicle, GPS-based location tracking integrated with computer-aided dispatch, and in some deployments, driver-facing barriers combined with intercom systems that let control center staff communicate directly with passengers without requiring the driver to intervene.

    Access Control for Employee and Maintenance Areas

    Depots and control centers restrict access to maintenance bays, parts storage and operations rooms using badge-based or biometric access control, often layered with visitor management systems for contractors and vendors who require temporary, auditable access to secure areas.

    Integration With City-Wide Public Safety Systems

    Because transit incidents frequently require a coordinated response involving both transit security and municipal police, many agencies now integrate their video and alert systems with city-wide public-safety platforms, allowing real-time video sharing and location data to reach first responders faster than a traditional phone-based incident report would allow.

  • Trump Signs Executive Order Establishing US Space Academy to Build Civil and Military Space Workforce

    Trump Signs Executive Order Establishing US Space Academy to Build Civil and Military Space Workforce

    President Trump signed an executive order on August 28, 2026, establishing a Presidential Commission on the United States Space Academy, a proposed institution intended to train a pipeline of engineers, operators, and service members for civil, military, and commercial space work, according to the White House’s own text of the order and reporting from NASA, CBS News, and Space.com.

    Trump announced the order during an event at NASA’s Johnson Space Center in Houston, where he also awarded the Congressional Space Medal of Honor to the four-person crew of Artemis II. The commission will be chaired by the NASA administrator, with the assistants to the president for economic policy and for science and technology serving as vice chairs; other members include the secretaries of defense and of the Air Force.

    120-Day Deadline for Recommendations

    The order gives the commission 120 days to submit a report recommending a governance framework for the academy, service obligations for graduates, a physical location, and any legislative changes needed to establish it. The initiative reflects growing federal attention to workforce gaps in space-related fields as commercial companies take on work that historically sat inside government agencies, and follows a year of expanded national-security focus on space and satellite infrastructure.

    No timeline for the academy’s opening has been set; officials said that will depend on the commission’s recommendations and any subsequent congressional action.

  • Asheville City Council Votes to End Flock Safety Camera Contract, Remove All 11 License-Plate Readers

    Asheville City Council Votes to End Flock Safety Camera Contract, Remove All 11 License-Plate Readers

    The Asheville, North Carolina City Council voted on Tuesday, August 25, 2026, to terminate the city’s contract with license-plate reader vendor Flock Safety and remove all 11 of its cameras from city streets, according to local reporting from WLOS.

    Mayor Esther Manheimer said the decision reflected growing concerns about how Flock manages the data its cameras collect and who can access it, framing the vote as an attempt to balance public-safety utility against privacy risk. Rondell Lance, president of the local Fraternal Order of Police chapter, opposed the removal, arguing the system had given investigators an efficient way to narrow suspect vehicles by characteristics rather than manually checking every potential match.

    Part of a Wider Pattern of Contract Reviews

    Asheville’s vote follows a period of intensifying scrutiny of automated license-plate reader networks nationally, after Flock Safety itself cut its default data-retention window to seven days earlier this month in response to similar pressure. Other jurisdictions, including communities in the Chicago suburbs, have faced comparable public fights over whether to keep, expand, or cancel Flock deployments amid concerns that plate-reader data could be accessed for purposes such as immigration enforcement or unauthorized personal tracking by officers.

    Asheville’s existing contract with rival vendor Axon includes provisions for stationary license-plate readers, though none are currently installed; city officials said any future deployment would require new privacy policies to be established first.

  • TSA Unveils Horizon 25 Strategy to Modernize Checkpoints and Expand Counter-Drone Capabilities

    TSA Unveils Horizon 25 Strategy to Modernize Checkpoints and Expand Counter-Drone Capabilities

    The Transportation Security Administration launched a new strategic plan called Horizon 25 on August 24, 2026, timed to the agency’s 25th anniversary, outlining three priorities: modernizing checkpoint technology, improving the traveler experience, and hardening security across multiple transportation modes, according to TSA’s own press release and reporting from International Airport Review and Federal News Network.

    TSA Administrator David P. Cummins said the plan is intended to streamline how the agency acquires new screening technology, including next-generation scanners and biometric identity-verification systems, as well as expand TSA’s capability to detect and respond to unmanned aircraft near airports and other transportation facilities. The agency has been steadily rolling out Credential Authentication Technology 2 units, which pair document scanning with live facial comparison, as part of a broader $781 million technology-modernization program already underway.

    Gold+ Program to Be Replaced

    As part of Horizon 25, TSA said it will retire its existing Gold+ program and replace it with an evolved Screening Partnership Program, expanding the role private security contractors play in airport checkpoint operations under federal oversight. The agency framed the changes as part of a longer-term effort to reduce checkpoint friction for low-risk travelers while concentrating resources on higher-risk threats, including the small-drone threat vector that has drawn increasing federal attention this year.

    TSA said further implementation details will be worked out with field and headquarters staff in September, with the counter-UAS and technology-acquisition components expected to roll out in phases rather than all at once.

  • Berlin State Government Refuses to Pay Extortionists After State Network Breach

    Berlin State Government Refuses to Pay Extortionists After State Network Breach

    Berlin’s state government confirmed on August 28, 2026 that it is the target of an extortion attempt following the compromise of the city-state’s administrative network earlier in August, and said it will not meet the attackers’ demands, according to a Senate Chancellery statement and reporting by The Hacker News. The same statement disclosed that forensic investigators had found further data outflows tied to the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated between August 7 and August 12, 2026.

    The Senate Chancellery said the affected department first reported an outflow on August 7 and was cut off from the network on August 14, seven days later. Berlin has not published a figure for how much data left the network; the only itemized account in circulation is from the attackers’ own leak-site post, indexed on August 28. The Chancellery said personal or other non-public data cannot be excluded from what was taken, and that the scope and content of the breach are still being examined.

    Refusing extortion demands after a confirmed government network breach carries operational risk if attackers publish or sell stolen data, but security officials increasingly favor the approach to avoid funding further attacks and to preserve credibility with other public bodies watching how governments respond. The case adds Berlin to a growing list of European state and municipal governments that have had to publicly navigate ransomware extortion decisions on live, unresolved incidents this year.

  • ATF Confirms Cyberattack on Standalone System Containing Investigation Targets, Calls It a Major Incident

    ATF Confirms Cyberattack on Standalone System Containing Investigation Targets, Calls It a Major Incident

    The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed on August 27, 2026 that a standalone computer system containing information about targets of ATF investigations was breached, designating the incident a “major incident” under federal guidelines, according to an agency statement and reporting by Recorded Future News. The Justice Department component had appeared on the leak site of the Qilin ransomware gang earlier in the week, though the group did not publish samples of stolen data.

    An ATF spokesperson said the affected system “was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems,” and that it was shut down as soon as the breach was discovered. The agency said its investigative and operational missions were not disrupted, and that the Justice Department is investigating the incident. Qilin has been among the most active ransomware operations of the past two years, with previously claimed attacks on Kuala Lumpur International Airport, beverage maker Asahi, a Texas municipal government and several U.S. power cooperatives.

    The incident adds to a run of cyberattacks affecting Justice Department components in recent years, including earlier breaches involving the U.S. Marshals Service and the federal courts’ docketing system. For law enforcement and government facilities, the case underscores a recurring theme in ransomware incidents: segmenting sensitive investigative systems from broader case-management and operational networks can limit the blast radius of an attack even when a breach cannot be entirely prevented.

  • ATF Confirms Data Breach After Ransomware Group Claims Access to Investigation Data

    ATF Confirms Data Breach After Ransomware Group Claims Access to Investigation Data

    The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack affected a system containing information about the targets of its investigations, following claims by a ransomware group that it had gained access to the agency’s data, Reuters reported.

    What’s New

    According to court documents and public reporting, the ransomware group gained access to a computer system holding information related to ATF investigative targets. The agency confirmed the breach but has not disclosed the full scope of the data involved or attributed the intrusion to a specific threat actor.

    Why It Matters

    A breach touching active investigation data raises risks beyond typical data-exposure incidents, potentially compromising ongoing law enforcement operations and the safety of investigative targets and personnel if the information is misused or leaked. The incident adds to a string of confirmed breaches at U.S. federal agencies this year and comes weeks after the Justice Department and FBI moved to disrupt state-sponsored hacking infrastructure targeting other parts of the federal government.