- InfoSec GRC Brief | April 2026
-
Regulatory & Compliance Updates
- NIST Overhauls NVD Operations — Prioritizes KEV and Federal-Use CVEs as Record Volumes Overwhelm Enrichment
- California’s Cybersecurity Audit Rule Creates New Litigation Exposure
- Microsoft Ships Second-Largest Patch Tuesday on Record — 167 Flaws, Two Zero-Days, Six CISA KEV Additions
- NIST Launches AI Risk Management Framework Profile for Critical Infrastructure
- CIRCIA Final Rule Likely to Slip Past May 2026 as CISA Rebuilds After Eight-Week Shutdown
-
GRC Strategies
- Boards Are Falling Short on Cybersecurity — And Compliance Is Not the Fix
- CSA Publishes Zero Trust Guidance That Reframes Resilience as an Ecosystem Property
- EU AI Act High-Risk Compliance Deadline Is Four Months Away — And the Guidance Is Still Missing
- Only 8% of Defense Contractors Hold CMMC Level 2 Certification with Seven Months to Go
-
Cyber Incidents & Risk Implications
- Iranian APT Campaigns Against U.S. PLCs Validate the Case for OT Network Segmentation
- European Commission Cloud Breach Turns a Trusted Security Scanner into a Supply Chain Weapon
- Adobe Acrobat Zero-Day Exploited for Four Months Before Emergency Patch
- Signature Healthcare Ransomware Attack Forces Hospital onto Paper Records for 10+ Days
- Docker Authorization Bypass Opens a New Attack Surface: AI Agents Exploiting Container Escapes
- SaltyCloud Research
InfoSec GRC Brief | April 2026
Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the first half of April 2026.
Let’s get into it.
Regulatory & Compliance Updates
NIST Overhauls NVD Operations — Prioritizes KEV and Federal-Use CVEs as Record Volumes Overwhelm Enrichment
NIST changed how its National Vulnerability Database enriches newly disclosed vulnerabilities. Effective April 15, full analysis (CVSS scores, CWE mappings, CPE data) now goes first to CVEs in CISA’s KEV catalog, CVEs in federal government software, and CVEs in products classified as critical under Biden-era executive orders. Everything else enters a lower-priority queue.
Record CVE submission volumes drove the change. Lower-profile CVEs may now sit unenriched for weeks or months, which means organizations can no longer assume NVD enrichment will appear promptly for every new vulnerability. If your patching or risk-scoring workflows rely on NVD-supplied CVSS data, that dependency is now a gap.
Vendor advisories, CISA KEV, and commercial threat feeds are the obvious supplements. The question is whether those sources are already integrated into your scoring models or sitting in a separate tab.
California’s Cybersecurity Audit Rule Creates New Litigation Exposure
The CPPA’s mandatory annual cybersecurity audit requirement, effective January 1, 2026, covers 18 technical and organizational components. Courts have generally declined to protect audit materials from discovery in class action litigation. Plaintiffs’ attorneys are already positioning to use audit findings as evidence of known deficiencies.
IAPP recommends a two-track approach: separate privileged legal counsel assessments from compliance documentation, and proactively leverage audit results demonstrating alignment with NIST CSF, ISO 27001, or CIS Controls as a negligence defense.
Microsoft Ships Second-Largest Patch Tuesday on Record — 167 Flaws, Two Zero-Days, Six CISA KEV Additions
Microsoft’s April 2026 Patch Tuesday addresses 167 vulnerabilities including two zero-days: CVE-2026-32201(SharePoint Server spoofing, actively exploited) and CVE-2026-33825 (Windows Defender privilege escalation, publicly disclosed). Eight critical RCE flaws affect Active Directory, Remote Desktop, Word, Excel, and TCP/IP. Separately, Adobe patched CVE-2026-34621, an Acrobat Reader zero-day exploited since November 2025.
CISA added six vulnerabilities to the KEV catalog on April 14, including a FortiClient EMS SQL injection flaw (CVE-2026-21643) exploited by ransomware actors since March 24 with a federal patch deadline of April 16. All other KEV additions are due April 27. The record volume is partly driven by AI-assisted vulnerability detection, which suggests high-volume cycles are the new baseline, not an anomaly.
NIST Launches AI Risk Management Framework Profile for Critical Infrastructure
NIST’s Information Technology Laboratory released a concept note for a new AI Risk Management Framework Profile targeting critical infrastructure operators across all 16 CI sectors. The profile addresses AI risks across IT, OT, and industrial control systems throughout the AI and CI lifecycles, including supply chain AI dependencies. NIST is forming a public Community of Interest for industry, regulator, and academic input.
This shifts AI governance from general principles to sector-specific, operationally grounded risk management. The profile will likely become a de facto audit benchmark alongside the NIST Cybersecurity Framework. With the EU AI Act’s high-risk compliance deadline arriving in August (more on that below), organizations operating in both U.S. and EU jurisdictions now face converging AI governance requirements on separate regulatory tracks.
CIRCIA Final Rule Likely to Slip Past May 2026 as CISA Rebuilds After Eight-Week Shutdown
CISA’s final CIRCIA regulations, which require 72-hour incident reports and 24-hour ransomware payment reports, now target May 2026 after the agency canceled sector-specific town halls due to federal appropriations lapses. A further extension is increasingly likely. CISA operated at reduced capacity for nearly eight weeks during a congressional funding lapse, with personnel recalled only in mid-April. The shutdown paused proactive threat hunting, vulnerability assessments, and state/local government engagement — gaps that persist during recovery.
The 72-hour clock starts when an organization “reasonably believes” an incident occurred, not after investigation confirms it. That distinction matters because incident classification workflows need to be operational before the rule takes effect, not built in response to it.
GRC Strategies
Boards Are Falling Short on Cybersecurity — And Compliance Is Not the Fix
Harvard Business Review research finds board cybersecurity governance has improved only marginally, held back by three gaps: insufficient expertise, AI security blindness, and the conflation of compliance with actual security. Of 239 board members across 62 firms, the study found one director with formal cybersecurity education, five with certifications, and 16 with practical experience. The FBI’s 2024 Internet Crime Report shows cybercrime losses rose 33% year-over-year.
With the NIST AI RMF critical infrastructure profile and EU AI Act high-risk deadlines both looming, AI risk now belongs on the standing board agenda. Boards can treat AI as a strategic opportunity (without ignoring the security implications) by identifying, empowering, and overseeing effective cybersecurity executives, applying the same leadership evaluation skills directors already use for other C-suite hires.
CSA Publishes Zero Trust Guidance That Reframes Resilience as an Ecosystem Property
The Cloud Security Alliance released guidance extending Zero Trust into enterprise-wide operational resilience. It introduces a Cyber Resilience Capability Maturity Model (CR-CMM) spanning ten domains and four maturity stages, plus a Business Impact Analysis methodology defining resilience targets through Service Delivery Objectives, Maximum Tolerable Loss, and Minimum Viable Service Levels. The guidance maps to NIST 800-53, ISO 27001, and DORA Articles 6, 9, 11, 13, and 26.
The central argument is that resilience is “an ecosystem property, not just an enterprise property.” The data backs that up. Thirty percent of incidents now originate from third parties, double the prior year.
For organizations building or refining resilience programs during DORA’s first full enforcement year, the CR-CMM provides a structured maturity path that regulators and auditors can actually evaluate.
EU AI Act High-Risk Compliance Deadline Is Four Months Away — And the Guidance Is Still Missing
August 2, 2026 enforces the EU AI Act’s high-risk framework, including risk management documentation, data governance, human oversight, conformity assessments, and post-market monitoring. Penalties reach 30 million EUR or 6% of global annual turnover. The European Commission missed its own February 2 deadline to publish Article 6 guidance on classifying high-risk systems, leaving organizations unable to definitively determine scope.
The missing guidance is not a reason to wait. The Annex III high-risk categories are already published, and internal AI inventories paired with conformity assessment documentation using the NIST AI RMF can bridge the gap where EU-specific standards remain under development. A Digital Omnibus proposal may link obligations to harmonized standards and adjust enforcement timelines. Planning around regulatory delays that may not materialize is its own risk.
Only 8% of Defense Contractors Hold CMMC Level 2 Certification with Seven Months to Go
Only 8% of defense contractors required to achieve CMMC Level 2 certification have done so as of February 2026. The November 2026 enforcement deadline requires C3PAO assessments on all contracts handling Controlled Unclassified Information. Another 42% report “in progress,” but projected C3PAO backlogs of 24 to 30 months mean contractors not already in the assessment queue face a mathematically disqualifying timeline.
Prime contractors and program managers who have not started tracking subcontractor certification status are accumulating risk that surfaces as contract performance failures when DoD begins enforcement. CMMC certification status warrants the same supply chain risk weight as financial viability or delivery capacity.
If your subcontractors aren’t in the queue yet, that’s a conversation worth having with program leadership — before contract renewal season.
Cyber Incidents & Risk Implications
Iranian APT Campaigns Against U.S. PLCs Validate the Case for OT Network Segmentation
CISA and partner agencies issued advisory AA26-097A warning that an Iranian-affiliated APT has exploited internet-exposed programmable logic controllers, primarily Rockwell Automation/Allen-Bradley systems, across government facilities, water and wastewater systems, and energy infrastructure since at least March 2026. Attackers manipulated PLC project files, altered HMI and SCADA displays to present false operational data, and established persistent access via Dropbear SSH. The advisory carries immediate BOD 22-01 compliance implications.
The Waterfall 2026 OT Threat Report confirms the broader pattern: nation-state attacks on critical infrastructure doubled year-over-year. OT threats are shifting from opportunistic ransomware to persistent operations designed to compromise physical processes.
HMI display manipulation is the detail that matters most here. It undermines operator situational awareness, the human layer that serves as OT’s last line of defense. Network segmentation, OT asset inventories, and remote access controls are now auditable compliance controls.
European Commission Cloud Breach Turns a Trusted Security Scanner into a Supply Chain Weapon
CERT-EU confirmed that threat group TeamPCP breached the European Commission’s AWS environment by compromising Trivy, the widely used open-source vulnerability scanner from Aqua Security. Attackers stole AWS API credentials through the compromised Trivy version, used TruffleHog to harvest additional secrets, validated credentials via AWS Security Token Service, and created new access keys across multiple EC AWS accounts. ShinyHunters leaked approximately 340 GB of stolen data on March 28: personal data from 42 Commission departments, over 51,000 outbound email files, and bounce-back notifications containing user-submitted content.
Trivy scans container images and infrastructure-as-code for vulnerabilities and runs with elevated access to codebases, CI/CD pipelines, and cloud credentials. That trust posture is exactly what made it a high-value supply chain target.
SBOMs and vendor questionnaires alone don’t cover this class of risk. Runtime integrity verification, credential scoping, and least-privilege principles need to extend to security tooling itself — not just the systems that tooling monitors. The CSA Zero Trust guidance covered earlier puts a number on it: 30% of incidents now originate from third parties.
Adobe Acrobat Zero-Day Exploited for Four Months Before Emergency Patch
Adobe issued an emergency patch for CVE-2026-34621 (CVSS 8.6), a critical JavaScript prototype-pollution vulnerability in Acrobat DC, Reader DC, and Acrobat 2024. Opening a weaponized PDF triggered malicious code execution. EXPMON researcher Haifei Li confirmed exploitation since at least November 2025, four months before the patch. Malicious samples used privileged Acrobat APIs to exfiltrate local files and system fingerprints to a C2 server before delivering secondary payloads.
CISA added CVE-2026-34621 to the KEV catalog on April 13 with a federal deadline of April 27. The zero-click exploitation path and evidence of sophisticated operators make this an immediate priority for any organization running Adobe Reader in enterprise environments.
Signature Healthcare Ransomware Attack Forces Hospital onto Paper Records for 10+ Days
Signature Healthcare’s Brockton Hospital in Massachusetts, hit by a cyberattack starting April 6, remained on downtime procedures through mid-April: clinical staff on paper records, pharmacy systems offline, ambulance diversions active. The Anubis ransomware group claimed responsibility and alleged theft of 2 TB of patient data. A one-week ultimatum passed without public resolution.
The incident triggers parallel notification obligations — HIPAA’s Breach Notification Rule requires notifying HHS and affected individuals within 60 days of discovery if patient data was compromised, while Massachusetts law adds a 30-day consumer notification deadline. This attack lands as HHS OCR processes 4,700 comments on the proposed HIPAA Security Rule update that would mandate encryption as a baseline standard.
Docker Authorization Bypass Opens a New Attack Surface: AI Agents Exploiting Container Escapes
CVE-2026-34040 (CVSS 8.8) lets attackers bypass Docker Engine authorization plugins by padding container creation requests beyond 1 MB. The oversized body drops before reaching the AuthZ plugin while the Docker daemon processes the full request. The flaw is an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability from July 2024. Docker Engine 29.3.1 patches the issue.
The AI agent vector is what sets this CVE apart. Cyera found that AI coding agents in Docker-based sandboxes discover and trigger the bypass autonomously, whether through prompt injection via poisoned repositories or self-directed exploration during debugging. The agent constructs the oversized HTTP request as a natural troubleshooting step. No specialized exploit code required.
Autonomous software agents that can exploit infrastructure vulnerabilities without human direction is a new attack surface category. For organizations running AI coding assistants or agentic workflows in containers, the patch is step one. The harder question to answer is how AI agent permissions interact with container security boundaries, and whether your current model accounts for agents that troubleshoot their way into privilege escalation.
SaltyCloud Research
NIST CSF 2.0 Readiness Scorecard
Score your organization’s alignment to the six CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, and Recover — and identify the highest-priority gaps before your next assessment.
NIST 800-53 Assessment: Complete Guide [2026]
NIST 800-53 assessment planning, control selection, and audit preparation for organizations building or maturing federal compliance programs.
GLBA Compliance Checklist
A ready-to-use checklist covering the Safeguards Rule, Financial Privacy Rule, and Pretexting Protection requirements — built for compliance teams preparing for exams or standing up a GLBA program.
The HECVAT: Complete Guide [2026]
What higher education institutions and technology vendors need to know about the Higher Education Community Vendor Assessment Toolkit — questionnaire structure, response strategy, and assessment preparation.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.