
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Wednesday, July 15, 2026. I'm Rich Strofalino. Pentagon Suspends CMMC Phase 2 Requirements the second phase of the Cybersecurity Maturity Model certification, or CMMC, was due to go into effect on November 10, 2026. Phase one of CMMC allowed companies, specifically contractors, to self report their cybersecurity compliance levels. The second phase would require contractors who handle sensitive information for DoD applications to have their compliance checked by an outside company. DoD estimated this would have impacted roughly 80,000 of the at least 220,000 companies participating in the US defense industrial base. CMMC rollout would eventually lead to a phase four rollout in 2028 that would require all contractors and subcontractors to maintain compliance. The DoD suspended the rollout, saying it created prohibitive compliance costs and bureaucratic burdens and will instead establish a CMMC reform task force to conduct a review of the program. U.S. troop location data under Attack in Iran According to data from the Mobile Surveillance Monitoring Research Project seen by the Financial Times, several regional telecom networks in the Middle east fended off a wave of SS7 ping requests that were seeking to track down the location of specific phones roaming outside of home networks. These were reportedly attempts to exploit provisions in roaming agreements with local phone providers to locate U.S. personnel. Based on the point of origin and nature of the SS7 pings, these appear to be highly targeted. This doesn't appear to be an isolated attempt to track movements either, a second source said they believe threat actors linked to Iran abused adtech databases to track phones in Iraqi Kurdistan. Context Bombing Flips the Script on prompt Injections Researchers at tracebit released details about a new defensive use of prompt injections called context bombing. They found that by including prompts within cloud buckets, they could effectively disarm adversarial agents trying to access that data. This is done by including prompts that ask the LLM to perform actions that go against agent guardrails. When this happens, the general response for agents is to just shut down. One example was including References to the 1989 Tiananmen Square massacre hidden among legitimate passwords and crypto keys. I wonder who that agent belonged to. Testing across five leading AI models, the researchers found that including context bombs like these reduced the rate at which agents gained full account admin access from 57% to just 5%. Old eufy apps can bypass secure boot Researchers at ESET released a report detailing 11 old Microsoft signed unified extensible Firmware interface shims that are able to bypass secure boot on systems that trust the Microsoft Corporation EUFY CA 2011 Third Party EUFY Certificate Authority certificate Regardless of the OS installed, these shims serve as a lightweight bootloader that sits between firmware and the os, with each link in the chain validating the next before the boot completes. These shims can then be used to execute arbitrary boot kits, even with secure boot protections enabled. Microsoft revoked the affected shims in its June 2026 Patch Tuesday update for following Responsible Disclosure back in February. ESET stresses that no novel exploit is required here, just possession of an old but still trusted shim binary and a basic understanding of how UEFY shims work. And now, thanks to Today's episode sponsor ThreatLocker, every security leader is being asked the same question right now. How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption, behind AI, behind automation, and behind every major technology decision. ThreatLocker helps organizations take a zero trust approach to that challenge, giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support cybersecurity headlines, because security works best when innovation and control move together. VPN Service sanction for Working with Ransomware the US Treasury's Office of Foreign Asset Control sanctioned First VPN Services and its Ukrainian administrator for allegedly selling services to ransomware operators. While many VPNs offer anonymity services, First VPN advertised itself on online cybercrime forums for over a decade and actively touted its refusal to cooperate with law enforcement. The treasury said that victims of ransomware attacks utilizing First VPN services included US Businesses, financial services companies, hospitals, and municipal governments. Back in May, Europol authorities said they arrested the admin of First VPN but did not name the individual. OAuth client ID spoofing lets attackers validate stolen Entra credentials Researchers at Proofpoint identified a technique called OAuth client ID spoofing that allows attackers to check stolen Microsoft Entra ID credentials at scale without triggering a sign in event that would alert defenders. Because Entra returns different error responses depending on whether a supplied OAuth client ID is valid, attackers can infer valid usernames and correct passwords without ever registering an application. Proofpoint tracked two campaigns using this method. One used over 700,000 spoofed client IDs with AWS infrastructure to target more than a million accounts between January and March 2026, while a second used Cloudflare infrastructure and 3.7 million randomized spoofed IDs to hit over 2 million users beginning in December 2025. Because spoofed client IDs do not include an application name in the sign in log, detections built around specific application activity can miss it entirely. LastPass and Bit Warden users hit with fake security alerts LastPass began warning users about a phishing campaign that sends emails resembling legitimate corporate communications about policy changes. Clicking on a checkbox to review access terms referenced in the email takes the users to an impersonated DocuSign, which attempts to download a malicious file on both Windows and macOS. LastPass confirmed that its systems have not been compromised and that the emails do not originate internally from themselves. Bleeping Computer reports that it saw a similar campaign being spread to Bitwarden users with an almost identical lure Zero Day behind Storage Zones Shutdown earlier this week we covered progress software urging customers to shut down Windows Servers using ShareFile Storage zone controllers to due to a credible external security threat. The company updated customers this week, saying it identified a high severity path traversal vulnerability impacting versions 5 and 6 of the ShareFile storage zone controller. Progress software released, patch versions and servers can be brought back online. Once patched, a CVE for the vulnerability will be published within two weeks. Right now, there's no evidence of any unauthorized access or any active exploitation of this vulnerability. Remember to register for this week's Super Cyber Friday event. Hacking the Shift in Security Work in the last five years, it's not just AI that's changed the game. Where and how we work has fundamentally changed and we're breaking down what that means for the work of security. Register for Super Cyber Friday on our events page@cisoseries.com and if you have some thoughts about the news from today or about the show in general, be sure to reach out to us feedbacksoseries.com we'd love to hear from you. Reporting for the CISO series, I'm Rich Stroffelino, reminding you to have a super sparkly day.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Cybersecurity Headlines – July 15, 2026
Host: Rich Stroffelino | CISO Series
Today’s episode delivers rapid-fire updates on pressing cybersecurity news, including the Pentagon’s sudden suspension of CMMC Phase II requirements, novel attacks and defenses in mobile tracking and AI security, and pivotal product vulnerabilities affecting global organizations. The episode explores not just the threats but evolving defense tactics, regulatory responses, and ongoing challenges for security practitioners.
[00:09]
“The DoD suspended the rollout, saying it created prohibitive compliance costs and bureaucratic burdens and will instead establish a CMMC reform task force.” – Host [00:38]
[01:05]
[02:03]
“They found that by including prompts within cloud buckets, they could effectively disarm adversarial agents trying to access that data.” – Host [02:11]
“I wonder who that agent belonged to.” – Host, lightly alluding to government ties [02:23]
[02:45]
“No novel exploit is required here, just possession of an old but still trusted shim binary and a basic understanding of how UEFI shims work.” – Host [03:36]
[04:09]
[04:46]
“Detections built around specific application activity can miss it entirely.” – Host [05:31]
[05:44]
[06:20]
"The DoD suspended the rollout, saying it created prohibitive compliance costs and bureaucratic burdens..." – Host [00:38]
"Including prompts within cloud buckets, they could effectively disarm adversarial agents trying to access that data." – Host [02:11] “I wonder who that agent belonged to.” – Host’s aside [02:23]
"No novel exploit is required here, just possession of an old but still trusted shim binary..." – Host [03:36]
"Detections built around specific application activity can miss it entirely." – Host [05:31]
Listeners are encouraged to read more at CISOseries.com for deeper dives on these stories and to register for upcoming cybersecurity events.