Home / Episodes / Jul 15, 2026
Episode show notesJul 15's Top Cyber News NOW! - Ep 1174
At a glance
Pentagon suspends CMMC Phase 2 compliance deadlines after finding only 1% of contractors ready. Researchers discover context bombing—using AI-generated prompts as defensive shields against adversarial agents. Old UEFI boot shims bypass secure boot despite Microsoft patches. Attackers validate millions of stolen Microsoft Entra credentials without triggering alerts. And Iran-linked actors exploit SS7 to track US military phones via ad data.
Stories covered
Does Pentagon's CMMC Phase 2 suspension give contractors breathing room?
What happened: DoD postponed CMMC Phase 2 requirements—originally due November 2026—citing prohibitive compliance costs and bureaucratic burden. Only 1% of contractors were ready for third-party audits that would have affected roughly 80,000 of 220,000 defense industrial base companies.
Why it matters: Compliance timelines slip, but threat actors don't. Security practitioners must balance regulatory relief with maintaining continuous risk reduction, not using postponement as cover for security gaps.
What to do: Use the reprieve to audit your current security posture against CMMC controls. Don't wait for new deadlines; build incrementally now so you're ahead when Phase 2 resets.
How are Iran-linked actors tracking US military phones via ad data?
What happened: Iranian cyber actors exploited SS7 signaling protocol to ping telecom networks across the Middle East, attempting to locate US personnel roaming outside home networks. Secondary attacks leveraged commercial ad-tech databases to track device movements based on advertising IDs—data available for purchase.
Why it matters: Nation-states are weaponizing publicly available ad data and legacy telecom protocols. Mobile devices used by travelers become operational security vulnerabilities that bypass typical network defenses.
What to do: Model traveling employees' mobile exposure in your threat assessment. Consider requiring device-side ad blocking or limiting ad ID tracking for high-risk travelers. Document phone usage policies for personnel in sensitive regions.
Can context bombing defend against AI agent attacks?
What happened: Researchers at Trace Bit demonstrated context bombing—injecting prompts into data stores that cause LLM-based agents to shut down. Testing showed the technique reduced unauthorized admin access rates from 57% to 5% across five leading AI models.
Why it matters: AI-powered attacks are escalating; defensive AI is playing catch-up. Autonomous agents running unchecked are now target surfaces requiring active defense, not just monitoring.
What to do: Sandbox AI agents and limit their execution scope. Implement human-in-the-loop approval for sensitive actions. Red-team your deployed chatbots and LLM integrations before production. Treat agents like privileged users: minimize permissions, monitor behavior, revoke immediately if suspicious.
Do old UEFI shims still bypass secure boot protections?
What happened: ESET identified 11 legacy Microsoft-signed UEFI shims that can bypass secure boot on fully patched systems if older, still-trusted binaries remain. Attackers need only the binary and basic knowledge of UEFI shimming; no novel exploit required. Microsoft revoked them in June 2026 patches.
Why it matters: Supply chain hygiene matters: trusted-but-old code is a persistent boot-level threat vector. Patch status of firmware and boot components often lag OS patches.
What to do: Verify firmware and UEFI component versions in your asset inventory. Ensure BIOS/firmware updates are applied alongside OS patches. Monitor boot-level binaries if your organization maintains legacy systems.
Can spoofed OAuth client IDs validate stolen credentials undetected?
What happened: Proof Point identified OAuth client ID spoofing—attackers test stolen Microsoft Entra credentials at scale by rotating randomized client IDs, triggering different error responses that reveal valid usernames and passwords without generating sign-in alerts. Two campaigns tested over 700,000 and 3.7 million spoofed IDs respectively in 2025–2026.
Why it matters: Credential validation is now stealthier. Standard detections keyed to specific application sign-ins miss spoofed traffic, and defenders see no audit trail of the enumeration.
What to do: Monitor for high-velocity OAuth authentication failures grouped by source IP, even without application context. Implement conditional access policies that flag unusual client IDs. Log and alert on authentication error patterns, not just successes.
Are LastPass and Bitwarden users targeted by DocuSign phishing?
What happened: Phishing campaigns impersonating LastPass and Bitwarden sent emails about policy changes following "recent security events," redirecting to fake DocuSign pages that drop malware on Windows and Mac. No internal compromise confirmed.
Why it matters: Post-breach phishing exploits user paranoia and legitimacy of prior breaches. Attackers rely on users' reluctance to question additional security workflows after known incidents.
What to do: Educate users that legitimate policy updates arrive through in-app alerts or verified portal logins, never DocuSign embeds. Monitor for lookalike DocuSign and password manager domains in email gateways. Flag emails referencing "recent security events" for review.
Why is Progress Software shutting down ShareFile storage controllers?
What happened: Progress Software identified a high-severity path traversal vulnerability (CVE pending) in ShareFile Storage Zone Controller versions 5 and 6. Customers required to shut down affected servers until patches deployed. No active exploitation reported at time of disclosure.
Why it matters: Zero-day forced downtime disrupts production before fixes exist. Organizations with unpatched legacy controller versions faced business continuity decisions under uncertainty.
What to do: Patch immediately once Progress releases CVE details and patches. If you cannot patch within 48 hours, isolate affected controllers behind network segmentation or take them offline. Maintain a dependency map of ShareFile controllers before the next incident.
Is FirstVPN sanctioned for enabling ransomware operations?
What happened: US Treasury OFAC sanctioned FirstVPN and its Ukrainian administrator for providing anonymity services to ransomware operators over a decade. The service advertised on cybercrime forums and refused law enforcement cooperation. Victims included US hospitals, municipalities, and financial institutions. The admin was arrested by Europol in May 2026.
Why it matters: Governments are shifting enforcement from endpoint attackers to infrastructure providers. Sanctioning VPN services signals intent to disrupt ransomware ecosystems upstream, though alternatives proliferate.
What to do: Monitor for ransom notes and incident data linked to FirstVPN. Assume ransomware crews will migrate to other anonymity services; do not overestimate disruption. Focus on detection and segmentation rather than relying on infrastructure takedowns.
Key takeaways
- Compliance windows are negotiable; cyber risk is not. CMMC Phase 2's delay doesn't reduce the security controls you need—use the reprieve to build incrementally.
- Operational security is shifting mobile. Traveling employees' devices leak location and identity via ad-tech and telecom protocols; model this in threat assessment.
- AI agents need defense-in-depth. Prompt injection, context bombing, and credential spoofing all exploit AI systems' opacity. Sandboxe, limit scope, audit, and red-team before deployment.
- Boot-level and firmware patches lag OS patches. Legacy UEFI shims and unsigned binaries remain persistent threats; inventory and prioritize firmware updates alongside security patches.
- Post-breach phishing is stealthier and more effective. Social engineering exploiting user anxiety after known incidents bypasses technical controls; rely on user education and sender verification.
Topics covered
cmmc, compliance, iran, ss7, mobile security, location tracking, ai agents, prompt injection, context bombing, uefi, secure boot, oauth spoofing, entra id, credentials, phishing, lastpass, bitwarden, progress software, sharefile, ransomware, firstVPN, zero trust, supply chain security
Want the live experience? The Daily Cyber Threat Brief airs live every weekday at 5am PT / 8am ET on YouTube. 400+ practitioners join the chat in real time.