Edition

InfoSec GRC Brief | July 15, 2026

Mariah Brooks

Updated Jul 15, 2026 Read Time 10 min

InfoSec GRC Brief | July 15, 2026:
DoD Suspends CMMC Phase 2, Treasury Sanctions VPN Provider, and Zero-Day Exploit Hits 100+ Companies

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the first half of July 2026.

Let’s get into it.

Regulatory & Compliance Updates

DoD Suspends CMMC Phase II

DoD announced an immediate suspension of CMMC Phase 2 third-party assessment requirements on July 13. The move comes just months before their November 10, 2026 start date.

While Phase 1 self-assessment obligations under NIST SP 800-171 remain fully in force for the contractors eventually in scope, a new CMMC Reform Task Force has 60 days to recommend a replacement framework prioritizing “tangible cyber hygiene” over third-party audits.

The suspension buys defense contractors time, but it does not remove the work. Any framework the task force proposes will likely still require documented, auditable controls.

Defense contractors can pause Phase 2 assessment spend, keep Phase 1 self-assessments current under NIST SP 800-171, and track the task force’s recommendations before committing further budget. Contractors who let their Phase 1 self-assessments lapse during the pause will have the most catch-up work once the replacement framework arrives.

Read more →

CISA Signals September Deadline for CIRCIA Rule

CISA now expects to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule by September 2026. The announcement comes after the agency missed its October 2025 statutory deadline and held additional stakeholder town halls this June.

Once final, the rule will require critical infrastructure entities across 16 sectors to report major cyber incidents within 72 hours and ransomware payments within 24 hours, a shift from voluntary cooperation to mandatory disclosure.

Compliance teams can finalize incident-classification criteria, build the 72-hour and 24-hour reporting workflows, and assign an owner for each step before the rule publishes in September. Waiting for the final text means building those workflows at the same time the reporting clock starts.

Read more →

Netherlands Adopts NIS2

The Dutch Senate passed the Cyberbeveiligingswet (Cybersecurity Act) on July 7. The ruling transposes the EU’s NIS2 Directive into national law with an August 15, 2026 effective date and no general transition period.

In-scope entities include those with 50+ employees and €10 million+ in turnover across critical sectors like energy, transport, banking, and healthcare. About 8,000 organizations will face compliance backed by fines up to €10 million or 2% of global turnover. Requirements include:

  • Mandatory NCSC registration
  • A duty of care for risk management
  • 24-hour incident reporting
  • Director-level cybersecurity training

This is one of the first NIS2 transpositions to go live with essentially zero runway, and it previews how other member states may implement their own versions in the coming months.

Organizations with Dutch operations can confirm scope against the 50-employee and €10 million thresholds, begin NCSC registration, and stand up 24-hour incident reporting now. Any entity waiting for a grace period already missed it on August 15.

Read more →

23andMe Pays $18M Over Data Breach

A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe’s bankruptcy trustee over the 2023 breach that exposed genetic data belonging to 6.9 million customers.

The settlement imposes enhanced security and privacy obligations on TTAM Research Institute, which acquired 23andMe’s assets out of bankruptcy.

Investigators found the company lacked:

  • Multi-factor authentication (MFA)
  • Credential-stuffing defenses
  • Rate limiting
  • Breach detection.

The investigation also found the company initially denied the breach before shifting blame to customers.

Data custodians can benchmark their authentication and monitoring controls against the specific gaps regulators cited, close any that are missing, and document the review for the next audit. Every control on that list is now a minimum standard, and organizations missing any one of them face the same gaps that cost 23andMe $18 million.

Read more →

NIST Publishes SP 1326

NIST finalized SP 1326 on July 8, a practical quick-start guide for conducting due-diligence cybersecurity supply chain risk assessments of ICT suppliers.

Built on NIST SP 800-161r1, NIST 1326 gives procurement and vendor-risk teams an implementation-ready methodology for right-sizing supplier due diligence. It covers:

  • Foreign ownership and control
  • Provenance
  • Resilience
  • Foundational cyber practices

Procurement and vendor-risk teams can fold SP 1326’s due-diligence methodology into the next questionnaire refresh, map it to their existing supplier tiers, and prioritize the vendors that touch regulated data.

Read more →

GRC Strategies

Oracle PeopleSoft Zero-Day Hits 100+ Companies

ShinyHunters-affiliated actors exploited CVE-2026-35273, a critical remote code execution flaw in Oracle PeopleSoft, between May 27 and June 10, 2026.

The zero-day campaign compromised more than 100 organizations and 300+ individual instances before a coordinated wave of breach disclosures on July 3. Confirmed victims include:

Analysts now frame ERP compromise the way MOVEit reframed file-transfer appliances. One vendor’s flaw becomes an industry-wide event that hits hundreds of companies at once.

Security and IT operations teams can treat internet-facing ERP systems as tier-one attack surface:

  • Inventory every internet-facing ERP instance and gate exposure behind VPN or access controls.
  • Build emergency-patch governance that can override standing change freezes.
  • Pre-map multi-jurisdiction breach-notification obligations ahead of the next disclosure.
  • Rehearse the override process ahead of the next wave.

Organizations that waited until the PeopleSoft wave to build this process spent the disclosure window firefighting instead of patching.

Read more →

Vendor Incidents Prove Point-in-Time Assessments Aren’t Enough

A single July roundup of vendor-risk incidents shows how concentrated third-party exposure has become:

The pattern across all five incidents runs the same way. Annual or point-in-time vendor assessments missed every one of them. The fixes are contractual and continuous:

  • Specify permitted data uses.
  • Require 24-48 hour breach-notification clauses.
  • Mandate data deletion at offboarding.
  • Require vendors to flow down fourth-party obligations.

TPRM owners can audit vendor contracts for breach-notification timelines and offboarding data-deletion clauses, add flow-down requirements for fourth parties, and move high-risk vendors onto continuous monitoring rather than annual reviews.

Read more →

Brussels Issues AI-Era Cyber Risk Playbook

The European Commission presented a coordinating Action Plan on Cybersecurity and Artificial Intelligence on July 7. It addresses how frontier AI models both accelerate cyber defense and lower the bar for attackers.

Rather than creating new binding obligations, it layers new instruments (AI model security evaluation capacity, an EU Grand Challenge on AI-assisted vulnerability remediation, and ENISA testing platforms) on top of the existing AI Act, NIS2, DORA, and Cyber Resilience Act framework.

There is no new compliance deadline yet. The plan still shows where EU enforcement is heading, and organizations that can show structured AI-risk evaluation inside their existing cybersecurity and AI governance programs will be ready for whatever comes next.

Security and AI governance leads can integrate AI-accelerated threat modeling into existing programs, map their controls to other frameworks, and document AI-risk evaluation ahead of any formal EU mandate.

Read more →

Cybersecurity Pros Don’t Trust AI Yet

ISC2 surveyed 856 cybersecurity professionals who use AI in their daily work. The research found:

  • 89% of participants have seen AI recommendations produce incorrect outcomes.
  • 50% of organizations have clear rules for who’s accountable when that happens.
  • 65% of participants now spend more time deciding whether to trust a given AI recommendation.
  • 62% of participants cite over-reliance on AI as a top concern. —

GRC teams can close this accountability gap now. Document explicit human-accountability rules for AI-assisted security decisions, define which calls require human review, and fold both into the next audit cycle.

Read more →

Cyber Incidents & Risk Implications

Oracle E-Business Suite Instances Still Exposed

Attackers began actively exploiting CVE-2026-46817 (CVSS 9.8), an unauthenticated remote takeover flaw in Oracle E-Business Suite’s Payments module, on June 27.

Even though Oracle patched the flaw back in May, researchers identified roughly 950 internet-exposed instances that still remain vulnerable.

EBS Payments handles transaction processing, so this is a financial-controls problem as much as an IT one. It is also the second Oracle flaw driving breaches this month, which puts emergency-patch governance at the center of the response.

SOX and IT operations teams can confirm patch status on every Oracle EBS instance, isolate any unpatched internet-facing instance, and treat it as a financial-controls incident in progress.

Read more →

Treasury Sanctions VPN Provider and Malware Seller Tied to Ransomware Gangs

OFAC sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian malware-cryptor seller Yegeniy Vladimirovich Silayev on July 14.

The action targeted infrastructure that enabled ransomware operations, which caused billions of dollars in losses to U.S. hospitals, financial firms, and municipalities. It followed European law enforcement’s dismantling of 1VPNS’s infrastructure in May under “Operation Saffron,” coordinated with UK and EU sanctions.

Sanctions exposure reaches beyond the ransomware operators themselves to the infrastructure providers underneath them. That’s exactly the kind of designation that can surface unexpectedly in third-party due diligence.

Third-party risk teams can update OFAC screening lists, extend due-diligence checks to the infrastructure providers underneath their vendors, and re-screen any vendor two tiers down from the newly designated entities. A vendor two tiers removed from a sanctioned provider still creates exposure your screening has to catch.

Read more →

New Ransomware Leader Emerges as “The Gentlemen” Overtake Qilin

Bitdefender’s July threat debrief found a new group calling itself “The Gentlemen,” founded by a former Qilin affiliate. The group claimed the top ransomware-as-a-service spot in June with 121 victims, edging out Qilin’s 80 after a year of Qilin dominance.

Separately, the “FortiBleed” campaign abused leaked FortiGate credentials at scale across more than 70,000 devices, without relying on any new CVE at all.

Both stories point to the same underlying risk. Credential hygiene now ranks alongside patching as a primary attack vector, and ransomware-affiliate turnover means the “known” threat-actor landscape can reshuffle within a single month.

Identity and security teams can run a credential-rotation and exposure audit across FortiGate and similar edge devices, enforce MFA on every internet-facing appliance, and set a recurring rotation cadence rather than a one-time reset. Here, credential hygiene carries as much weight as patching.

Read more →

AI Agent Runs Ransomware Attack without Humans

Sysdig documented “JadePuffer,” what researchers describe as the first fully autonomous, LLM-driven ransomware operation.

The AI agent exploited a Langflow RCE vulnerability, harvested credentials, moved laterally to a production database, and encrypted over 1,300 records before demanding a Bitcoin ransom. It recovered from a failed step and adapted its approach in 31 seconds, with no human operator directing any of it.

Most security leaders still treat AI-assisted attacks as a future problem. JadePuffer shows they are happening now, and it turns AI-accountability rules into an immediate need.

Detection and third-party risk teams can close the gap this exposes:

  • Reassess whether the detection stack relies on static signatures or behavioral and identity-based indicators.
  • Add AI-tooling exposure like Langflow to the third-party attack-surface inventory.
  • Apply human-accountability rules to any autonomous agent in the environment.

A detection stack tuned only to known signatures will miss an agent that rewrites its own approach mid-attack.

Read more →

Microsoft’s Largest-Ever Patch Tuesday Fixes 622 Flaws, Two Under Active Attack

Microsoft’s July 2026 Patch Tuesday addressed a record 622 vulnerabilities (416 in Windows, 164 in Office). In addition to a publicly disclosed BitLocker bypass, two of those vulnerabilities are actively exploited zero-days:

  • An Active Directory Federation Services privilege-escalation bug (CVE-2026-56155)
  • An unauthenticated SharePoint Server elevation-of-privilege flaw (CVE-2026-56164)

Partly attributed to Microsoft’s expanded use of AI-driven vulnerability discovery, this scale suggests the volume is the new normal rather than a one-off spike.

For auditors and CISOs, vulnerability-management programs built around monthly patch cycles now need enough throughput to keep pace. A cadence sized for last year’s volume falls behind the moment this becomes routine.

Read more →

SaltyCloud Research

NIST 800-53 Multi-Framework Crosswalk

A spreadsheet that maps each NIST 800-53 control to NIST CSF 2.0, AICPA SOC 2 TSC, ISO 27001:2022, NIST SP 800-171 Rev 3, and HIPAA, for tracking implementation status, assessment objectives, and evidence, all in one place.

Access the Crosswalk →

TPRM Maturity Model for Third-Party Risk: Complete Guide [2026]

A self-assessment framework for measuring how mature a third-party risk management program actually is.

Read the Guide →

NIST 800-171: Complete Guide [2026]

Everything there is to know about NIST SP 800-171, its requirements, who must comply, and how it relates to other frameworks.

Read the Guide →

GRC Tools and Solutions for Mid-Market Companies: Complete Guide [2026]

A guide for mid-market companies in search of dedicated GRC tooling that covers platform categories, evaluation criteria, tier-by-tier comparisons, and organization-type fit.

Read the Guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

InfoSec GRC Brief | August 27, 2026: CMMC Task Force Takes On CUI Markings, EU Cyber Resilience Act Reporting Begins, and CareCloud Breach Impacts...

Edition
09.04.2026

InfoSec GRC Brief | August 13, 2026: CMMC Comment Period Closes, CA Launches DROP Platform, and CISA Sets Cisco Firewall Patch Deadline Welcome back...

Edition
09.04.2026

InfoSec GRC Brief | July 30, 2026: HHS Delays HIPAA Overhaul, FTC Issues $2.25M Fine, and EU Defers AI Act Deadline Welcome back to the InfoSec GRC...

Edition
09.04.2026
The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo