- InfoSec GRC Brief | July 15, 2026: DoD Suspends CMMC Phase 2, Treasury Sanctions VPN Provider, and Zero-Day Exploit Hits 100+ Companies
- Regulatory & Compliance Updates
- GRC Strategies
-
Cyber Incidents & Risk Implications
- Oracle E-Business Suite Instances Still Exposed
- Treasury Sanctions VPN Provider and Malware Seller Tied to Ransomware Gangs
- New Ransomware Leader Emerges as “The Gentlemen” Overtake Qilin
- AI Agent Runs Ransomware Attack without Humans
- Microsoft’s Largest-Ever Patch Tuesday Fixes 622 Flaws, Two Under Active Attack
- SaltyCloud Research
InfoSec GRC Brief | July 15, 2026:
DoD Suspends CMMC Phase 2, Treasury Sanctions VPN Provider, and Zero-Day Exploit Hits 100+ Companies
Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the first half of July 2026.
Let’s get into it.
Regulatory & Compliance Updates
DoD Suspends CMMC Phase II
DoD announced an immediate suspension of CMMC Phase 2 third-party assessment requirements on July 13. The move comes just months before their November 10, 2026 start date.
While Phase 1 self-assessment obligations under NIST SP 800-171 remain fully in force for the contractors eventually in scope, a new CMMC Reform Task Force has 60 days to recommend a replacement framework prioritizing “tangible cyber hygiene” over third-party audits.
The suspension buys defense contractors time, but it does not remove the work. Any framework the task force proposes will likely still require documented, auditable controls.
Defense contractors can pause Phase 2 assessment spend, keep Phase 1 self-assessments current under NIST SP 800-171, and track the task force’s recommendations before committing further budget. Contractors who let their Phase 1 self-assessments lapse during the pause will have the most catch-up work once the replacement framework arrives.
CISA Signals September Deadline for CIRCIA Rule
CISA now expects to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule by September 2026. The announcement comes after the agency missed its October 2025 statutory deadline and held additional stakeholder town halls this June.
Once final, the rule will require critical infrastructure entities across 16 sectors to report major cyber incidents within 72 hours and ransomware payments within 24 hours, a shift from voluntary cooperation to mandatory disclosure.
Compliance teams can finalize incident-classification criteria, build the 72-hour and 24-hour reporting workflows, and assign an owner for each step before the rule publishes in September. Waiting for the final text means building those workflows at the same time the reporting clock starts.
Netherlands Adopts NIS2
The Dutch Senate passed the Cyberbeveiligingswet (Cybersecurity Act) on July 7. The ruling transposes the EU’s NIS2 Directive into national law with an August 15, 2026 effective date and no general transition period.
In-scope entities include those with 50+ employees and €10 million+ in turnover across critical sectors like energy, transport, banking, and healthcare. About 8,000 organizations will face compliance backed by fines up to €10 million or 2% of global turnover. Requirements include:
- Mandatory NCSC registration
- A duty of care for risk management
- 24-hour incident reporting
- Director-level cybersecurity training
This is one of the first NIS2 transpositions to go live with essentially zero runway, and it previews how other member states may implement their own versions in the coming months.
Organizations with Dutch operations can confirm scope against the 50-employee and €10 million thresholds, begin NCSC registration, and stand up 24-hour incident reporting now. Any entity waiting for a grace period already missed it on August 15.
23andMe Pays $18M Over Data Breach
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe’s bankruptcy trustee over the 2023 breach that exposed genetic data belonging to 6.9 million customers.
The settlement imposes enhanced security and privacy obligations on TTAM Research Institute, which acquired 23andMe’s assets out of bankruptcy.
Investigators found the company lacked:
- Multi-factor authentication (MFA)
- Credential-stuffing defenses
- Rate limiting
- Breach detection.
The investigation also found the company initially denied the breach before shifting blame to customers.
Data custodians can benchmark their authentication and monitoring controls against the specific gaps regulators cited, close any that are missing, and document the review for the next audit. Every control on that list is now a minimum standard, and organizations missing any one of them face the same gaps that cost 23andMe $18 million.
NIST Publishes SP 1326
NIST finalized SP 1326 on July 8, a practical quick-start guide for conducting due-diligence cybersecurity supply chain risk assessments of ICT suppliers.
Built on NIST SP 800-161r1, NIST 1326 gives procurement and vendor-risk teams an implementation-ready methodology for right-sizing supplier due diligence. It covers:
- Foreign ownership and control
- Provenance
- Resilience
- Foundational cyber practices
Procurement and vendor-risk teams can fold SP 1326’s due-diligence methodology into the next questionnaire refresh, map it to their existing supplier tiers, and prioritize the vendors that touch regulated data.
GRC Strategies
Oracle PeopleSoft Zero-Day Hits 100+ Companies
ShinyHunters-affiliated actors exploited CVE-2026-35273, a critical remote code execution flaw in Oracle PeopleSoft, between May 27 and June 10, 2026.
The zero-day campaign compromised more than 100 organizations and 300+ individual instances before a coordinated wave of breach disclosures on July 3. Confirmed victims include:
- Nissan
- Kubota North America
- Aflac Japan
- The National Association of Insurance Commissioners (which lost 3.1 TB of statutory financial data)
Analysts now frame ERP compromise the way MOVEit reframed file-transfer appliances. One vendor’s flaw becomes an industry-wide event that hits hundreds of companies at once.
Security and IT operations teams can treat internet-facing ERP systems as tier-one attack surface:
- Inventory every internet-facing ERP instance and gate exposure behind VPN or access controls.
- Build emergency-patch governance that can override standing change freezes.
- Pre-map multi-jurisdiction breach-notification obligations ahead of the next disclosure.
- Rehearse the override process ahead of the next wave.
Organizations that waited until the PeopleSoft wave to build this process spent the disclosure window firefighting instead of patching.
Vendor Incidents Prove Point-in-Time Assessments Aren’t Enough
A single July roundup of vendor-risk incidents shows how concentrated third-party exposure has become:
- A healthcare AI vendor phishing breach exposed 1.4 million patient records across seven hospital systems, including some that had already terminated the vendor relationship but left data behind.
- An OAuth-token compromise at a fourth-party vendor exposed LastPass customer data.
- The same Oracle PeopleSoft flaw disrupted NAIC’s credit-rating data feeds.
- A compromised frontend supplier let attackers defraud Polymarket users of $3 million.
The pattern across all five incidents runs the same way. Annual or point-in-time vendor assessments missed every one of them. The fixes are contractual and continuous:
- Specify permitted data uses.
- Require 24-48 hour breach-notification clauses.
- Mandate data deletion at offboarding.
- Require vendors to flow down fourth-party obligations.
TPRM owners can audit vendor contracts for breach-notification timelines and offboarding data-deletion clauses, add flow-down requirements for fourth parties, and move high-risk vendors onto continuous monitoring rather than annual reviews.
Brussels Issues AI-Era Cyber Risk Playbook
The European Commission presented a coordinating Action Plan on Cybersecurity and Artificial Intelligence on July 7. It addresses how frontier AI models both accelerate cyber defense and lower the bar for attackers.
Rather than creating new binding obligations, it layers new instruments (AI model security evaluation capacity, an EU Grand Challenge on AI-assisted vulnerability remediation, and ENISA testing platforms) on top of the existing AI Act, NIS2, DORA, and Cyber Resilience Act framework.
There is no new compliance deadline yet. The plan still shows where EU enforcement is heading, and organizations that can show structured AI-risk evaluation inside their existing cybersecurity and AI governance programs will be ready for whatever comes next.
Security and AI governance leads can integrate AI-accelerated threat modeling into existing programs, map their controls to other frameworks, and document AI-risk evaluation ahead of any formal EU mandate.
Cybersecurity Pros Don’t Trust AI Yet
ISC2 surveyed 856 cybersecurity professionals who use AI in their daily work. The research found:
- 89% of participants have seen AI recommendations produce incorrect outcomes.
- 50% of organizations have clear rules for who’s accountable when that happens.
- 65% of participants now spend more time deciding whether to trust a given AI recommendation.
- 62% of participants cite over-reliance on AI as a top concern. —
GRC teams can close this accountability gap now. Document explicit human-accountability rules for AI-assisted security decisions, define which calls require human review, and fold both into the next audit cycle.
Cyber Incidents & Risk Implications
Oracle E-Business Suite Instances Still Exposed
Attackers began actively exploiting CVE-2026-46817 (CVSS 9.8), an unauthenticated remote takeover flaw in Oracle E-Business Suite’s Payments module, on June 27.
Even though Oracle patched the flaw back in May, researchers identified roughly 950 internet-exposed instances that still remain vulnerable.
EBS Payments handles transaction processing, so this is a financial-controls problem as much as an IT one. It is also the second Oracle flaw driving breaches this month, which puts emergency-patch governance at the center of the response.
SOX and IT operations teams can confirm patch status on every Oracle EBS instance, isolate any unpatched internet-facing instance, and treat it as a financial-controls incident in progress.
Treasury Sanctions VPN Provider and Malware Seller Tied to Ransomware Gangs
OFAC sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian malware-cryptor seller Yegeniy Vladimirovich Silayev on July 14.
The action targeted infrastructure that enabled ransomware operations, which caused billions of dollars in losses to U.S. hospitals, financial firms, and municipalities. It followed European law enforcement’s dismantling of 1VPNS’s infrastructure in May under “Operation Saffron,” coordinated with UK and EU sanctions.
Sanctions exposure reaches beyond the ransomware operators themselves to the infrastructure providers underneath them. That’s exactly the kind of designation that can surface unexpectedly in third-party due diligence.
Third-party risk teams can update OFAC screening lists, extend due-diligence checks to the infrastructure providers underneath their vendors, and re-screen any vendor two tiers down from the newly designated entities. A vendor two tiers removed from a sanctioned provider still creates exposure your screening has to catch.
New Ransomware Leader Emerges as “The Gentlemen” Overtake Qilin
Bitdefender’s July threat debrief found a new group calling itself “The Gentlemen,” founded by a former Qilin affiliate. The group claimed the top ransomware-as-a-service spot in June with 121 victims, edging out Qilin’s 80 after a year of Qilin dominance.
Separately, the “FortiBleed” campaign abused leaked FortiGate credentials at scale across more than 70,000 devices, without relying on any new CVE at all.
Both stories point to the same underlying risk. Credential hygiene now ranks alongside patching as a primary attack vector, and ransomware-affiliate turnover means the “known” threat-actor landscape can reshuffle within a single month.
Identity and security teams can run a credential-rotation and exposure audit across FortiGate and similar edge devices, enforce MFA on every internet-facing appliance, and set a recurring rotation cadence rather than a one-time reset. Here, credential hygiene carries as much weight as patching.
AI Agent Runs Ransomware Attack without Humans
Sysdig documented “JadePuffer,” what researchers describe as the first fully autonomous, LLM-driven ransomware operation.
The AI agent exploited a Langflow RCE vulnerability, harvested credentials, moved laterally to a production database, and encrypted over 1,300 records before demanding a Bitcoin ransom. It recovered from a failed step and adapted its approach in 31 seconds, with no human operator directing any of it.
Most security leaders still treat AI-assisted attacks as a future problem. JadePuffer shows they are happening now, and it turns AI-accountability rules into an immediate need.
Detection and third-party risk teams can close the gap this exposes:
- Reassess whether the detection stack relies on static signatures or behavioral and identity-based indicators.
- Add AI-tooling exposure like Langflow to the third-party attack-surface inventory.
- Apply human-accountability rules to any autonomous agent in the environment.
A detection stack tuned only to known signatures will miss an agent that rewrites its own approach mid-attack.
Microsoft’s Largest-Ever Patch Tuesday Fixes 622 Flaws, Two Under Active Attack
Microsoft’s July 2026 Patch Tuesday addressed a record 622 vulnerabilities (416 in Windows, 164 in Office). In addition to a publicly disclosed BitLocker bypass, two of those vulnerabilities are actively exploited zero-days:
- An Active Directory Federation Services privilege-escalation bug (CVE-2026-56155)
- An unauthenticated SharePoint Server elevation-of-privilege flaw (CVE-2026-56164)
Partly attributed to Microsoft’s expanded use of AI-driven vulnerability discovery, this scale suggests the volume is the new normal rather than a one-off spike.
For auditors and CISOs, vulnerability-management programs built around monthly patch cycles now need enough throughput to keep pace. A cadence sized for last year’s volume falls behind the moment this becomes routine.
SaltyCloud Research
NIST 800-53 Multi-Framework Crosswalk
A spreadsheet that maps each NIST 800-53 control to NIST CSF 2.0, AICPA SOC 2 TSC, ISO 27001:2022, NIST SP 800-171 Rev 3, and HIPAA, for tracking implementation status, assessment objectives, and evidence, all in one place.
TPRM Maturity Model for Third-Party Risk: Complete Guide [2026]
A self-assessment framework for measuring how mature a third-party risk management program actually is.
NIST 800-171: Complete Guide [2026]
Everything there is to know about NIST SP 800-171, its requirements, who must comply, and how it relates to other frameworks.
GRC Tools and Solutions for Mid-Market Companies: Complete Guide [2026]
A guide for mid-market companies in search of dedicated GRC tooling that covers platform categories, evaluation criteria, tier-by-tier comparisons, and organization-type fit.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.