Edition

Pennsylvania Bank’s AI 8-K, Charter’s 40M-Record Breach, and NIST Tightens CUI Rules in SP 800-172r3

SaltyCloud Research Team

Updated May 28, 2026 Read Time 11 min

InfoSec GRC Brief | May 2026:

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the second half of May 2026.

Let’s get into it.

Regulatory & Compliance Updates

US bank reports itself after entering customer data into ‘unauthorized AI app’

Community Bank in Pennsylvania self-disclosed a material cybersecurity incident to the SEC after employees entered customer names, dates of birth, and Social Security numbers into an unapproved AI application. The incident triggered mandatory breach notification and regulatory coordination under existing federal law. While no system disruption occurred, the bank still filed an 8-K, notified customers, and committed to remediation.

This is a clean test case for material disclosure triggered by an AI acceptable-use failure. Federal breach notification frameworks already cover the scenario without any new AI-specific rules, and the ISACA AI Pulse Poll shows that most organizations still lack the comprehensive AI policies that would prevent exactly this outcome.

Organizations can enforce AI acceptable-use policies, maintain an approved tooling list, and run targeted data-handling training before a single employee decision drives an 8-K filing.

Read more →

NIST releases SP 800-172r3 and 172Ar3 for enhanced CUI protection

NIST finalized Revision 3 of SP 800-172 along with the companion assessment guide SP 800-172Ar3. The pair expands enhanced security requirements for non-federal systems handling Controlled Unclassified Information, with new coverage of access controls, network segmentation, asset management, and supply chain security. Both documents align to SP 800-171r3 and SP 800-53.

Organizations in federal supply chains (especially those preparing for CMMC) face a higher evidence bar. The revision leans further toward operational proof, and several control families add explicit testing procedures in the Ar3 companion.

Contractors and subcontractors can run gap assessments against r3 before flow-down clauses cite the new revision. How quickly your DFARS 7012 program absorbs r3 will likely shape your CMMC readiness curve over the next twelve months.

Read more →

EU AI Act: 5 evidence gaps to close before August 2026

The August 2, 2026 deadline for high-risk AI system deployers is still on the books. An IAPP analysis identifies five documentation gaps most SMEs have yet to close:

  • AI system inventories
  • Classification rationale
  • Human oversight records
  • Log-retention evidence
  • Incident-escalation frameworks

As we covered last edition, the EU reached a provisional May 7 deal that could extend certain deadlines to December 2027. Formal adoption remains pending.

Regulators want to see named human reviewers, retrievable logs, and documented kill-switch procedures. Legal interpretation alone will not substitute. SMEs without these artifacts cannot demonstrate conformity even when their AI use is otherwise low-risk.

Deployers can map current AI inventories and oversight records against the five gap categories now. Even though the deadline could move to December 2027, the documentation regulators expect won’t change.

Read more →

CISA tells critical organizations to prepare for cyber outages

CISA’s CI Fortify initiative is pushing critical infrastructure operators, including dams, water utilities, weapons systems, and satellite communications, to develop plans for isolating from third-party networks while sustaining essential operations during a geopolitical cyber crisis.

Targeted readiness assessments have already begun. Acting CISA Director Nick Andersen outlined two objectives:

  • Isolation: Disconnecting from outside networks while maintaining core ops
  • Recovery: Documenting systems, backing up files, and practicing manual procedures

The initiative reframes resilience around operating without trusted external dependencies, a planning assumption many CI operators have not modeled. Vendor isolation capability is now an explicit federal expectation, and the parallel C2 ISAC launch in this edition’s GRC Strategies section signals that critical sectors are building independent capability across both federal and private channels.

CI operators can document which third-party connections are mission-critical, which can be severed, and which manual procedures step in when automated ones go dark. Tabletop exercises that assume isolation as the starting condition will surface gaps that conventional ransomware tabletops miss.

Read more →

HIPAA overhaul likely to finalize in pieces, with encryption and MFA first

HHS OCR‘s May 2026 target date for finalizing the HIPAA Security Rule overhaul has analysts expecting a narrower finalization. Less-controversial portions such as mandatory encryption and MFA are likely to land first, with tiered implementation timelines favoring smaller entities.

If finalized, organizations would have roughly 180 days to comply with sweeping changes that eliminate the required/addressable distinction, mandate written documentation for every security policy, tighten business associate oversight, and require microsegmentation.

Even a partial finalization carries a tight implementation runway. Healthcare entities operating without written policies covering every Security Rule standard face the largest gap. West Pharmaceutical’s ransomware incident (Cyber Incidents section) shows how one supplier outage ripples through the rest of the pharma supply chain, which is why business associate oversight is moving up the regulatory priority list.

Healthcare organizations can treat the proposed requirements as best practices now, regardless of finalization timing. Encryption and MFA are likely day-one obligations if OCR finalizes any portion of the rule this year.

Read more →

CISA contractor exposes internal credentials on public GitHub

A CISA contractor exposed AWS GovCloud authentication keys, Kubernetes configs, RSA private keys, and plaintext credentials for dozens of internal CISA systems via a public GitHub repository. Credentials remained valid for 48 hours after notification, and CISA was still rotating compromised secrets more than a week later. Bipartisan congressional members are demanding accountability from the nation’s cybersecurity agency.

The incident shows that even the federal cybersecurity agency is exposed when contractor secrets-management controls fail. Third-party developer environments remain high-value targets across both government and commercial supply chains.

GRC programs can audit contractor environments for enforced secrets scanning, credential rotation SLAs, and insider-threat monitoring on developer access. If CISA’s own vendors miss these controls, your assumptions about third-party hygiene deserve a second look.

Read more →

GRC Strategies

ISACA’s 2026 AI Pulse Poll shows AI deployment is outpacing AI governance

ISACA’s annual AI governance benchmark surveyed over 3,400 digital trust professionals globally. Only 38% of organizations have comprehensive AI policies despite widespread deployment, 56% cannot say how quickly they could halt a compromised AI system, and 11% strongly agree their organization prioritizes ethical standards in AI. ROI disappointment is widespread. Employee AI use is reported by 90% of organizations, yet only 22% say ROI has met expectations.

In other words, AI deployment is moving far faster than AI governance. Programs that can’t shut down a compromised AI system quickly face heightened exposure when an incident demands rapid containment.

GRC leaders can use these benchmarks to score their own AI governance maturity, close shutdown-capability gaps, and prioritize policy enforcement over additional pilots. Are your AI controls keeping pace with deployment volume, or widening behind it?

Read more →

Telecom sector launches its own private ISAC

AT&T, Charter, Comcast, T-Mobile, Verizon, and four other major carriers launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), led by a former CISA and FBI executive, to share sensitive threat intelligence outside federal government channels following the Salt Typhoon espionage campaign. Unlike the legacy Communications ISAC, C2 ISAC deliberately excludes government agencies to encourage candid sharing of vulnerabilities and attacker TTPs among private carriers.

Last edition covered federal-coordination plays like Five Eyes agentic AI guidance and CISA’s G7 SBOM-for-AI push. C2 ISAC goes the other direction. A private-only ISAC signals that some critical sectors view government information-sharing as insufficient or politically uncertain. The launch parallels CISA’s CI Fortify push in the Regulatory section, with both efforts pointing toward independent operational resilience.

Risk managers in telecom and adjacent supply chains can evaluate sector ISAC membership as a proactive threat-intelligence investment. The Charter breach in this edition’s Cyber Incidents section makes the timing of new telecom threat sharing especially relevant.

Read more →

Two years in, voluntary 8-K filings outpace mandatory cyber disclosures

Two years after the SEC’s cybersecurity disclosure rules took effect, a Debevoise legal tracker reports voluntary Item 8.01 filings (50 total) have outpaced mandatory Item 1.05 material-incident filings (29 total). Companies are favoring the preliminary disclosure route to avoid the materiality call. SEC Chair Paul Atkins is reviewing the rules as part of broader deregulatory efforts, and industry groups are calling for Item 1.05 repeal.

Filing pattern data gives public-company GRC and legal teams real-world benchmarks for their own disclosure playbooks. The pending SEC review could also alter the underlying regime, particularly for Item 1.05.

Public-company teams can calibrate disclosure triggers against the observed 8.01-vs-1.05 split and track the SEC review for material changes. How is your playbook positioned if the materiality trigger shifts mid-year?

Read more →

Cyber Incidents & Risk Implications

2026 is the year of AI-assisted attacks

AI coding capabilities crossed a critical threshold in 2025, enabling non-technical individuals to conduct sophisticated attacks.

  • A 17-year-old extracted data from 7 million users, teenagers attacked Rakuten Mobile 220,000 times, and one actor breached 17 organizations in a month using AI-assisted code.
  • Malicious packages in public repositories grew from 55,000 in 2022 to 454,600 in 2025.
  • Cloud intrusions rose 35%, median time-to-exploit fell to 44 days, and 28.3% of CVEs are exploited within 24 hours.

More people can pull off sophisticated attacks now, and they can do it faster. Risk assessments and patch SLAs built for 2022 conditions can’t keep up. The AI bug-hunter coverage later in this section shows the flip side: AI is also finding new vulnerabilities faster than patch programs can fix them.

GRC programs can compress patch windows, expand supply-chain dependency scanning, and recalibrate risk register assumptions for an environment where novice attackers move at near-professional speed. Fixed SLAs against a moving threat baseline will fall behind.

Read more →

West Pharmaceutical ransomware attack disrupts global operations

West Pharmaceutical Services, a $3+ billion injectable packaging supplier to the global pharmaceutical supply chain, suffered a ransomware attack on May 4 that encrypted systems, exfiltrated data, and disrupted shipping, receiving, and manufacturing operations across 50 global locations while the company isolated on-premise infrastructure. The company filed a material cybersecurity 8-K with the SEC within days, with Palo Alto Unit 42 engaged for investigation.

Ransomware at a pharma supply-chain manufacturer means production stops and disclosure obligations land all at once: SEC filings, customer contract notifications, and sector regulator notices. The CI Fortify initiative targets exactly this isolation-and-continuity scenario.

Pharma supply-chain participants can review continuity-of-operations plans for upstream manufacturer outages, including manual procedures and alternate-source arrangements. A single-vendor dependency is a known risk until your supplier goes offline. Then it’s a known incident.

Read more →

AI models are finding bugs faster than patch programs can fix them

Nearly three dozen bipartisan House members urged the White House to develop a coordinated national strategy for handling vulnerabilities discovered at scale by advanced AI models like Anthropic’s Mythos, which found 75 bugs at Palo Alto and 271 in Firefox. The same roundup covers the Foxconn Nitrogen ransomware attack affecting North American factories, active BitLocker bypass exploits (YellowKey, GreenPlasma), a Nvidia GeForce NOW partner breach, and Škoda Auto customer data exposure.

AI is shrinking the window between disclosure and exploitation. Patch programs built for a slower disclosure cadence will fall behind, raising the bar for model-tier governance just as the EU AI Act deadline approaches.

GRC teams can benchmark current patch SLAs against AI-era disclosure volumes and formalize triage criteria for high-volume model-generated findings. How long does a typical vulnerability sit between disclosure and patch in your environment?

Read more →

Charter confirms data breach after ShinyHunters extortion threat

Charter Communications confirmed a breach of approximately 40 million customer records after ShinyHunters compromised an employee’s Microsoft Entra account via voice phishing on April 1, then exported customer names, addresses, phone numbers, and plan details from Charter’s Salesforce instance. The company disputed that any sensitive CPNI or payment data was taken, contradicting the threat group’s claims.

A single vishing call combined with weak cloud identity controls produced bulk-export of tens of millions of records and mandatory breach notification across dozens of state jurisdictions. Charter is also a founding member of the C2 ISAC launched in this edition’s GRC Strategies section, underscoring why the new sector ISAC has acute timing.

Identity teams can enforce phishing-resistant MFA on cloud-admin roles, rate-limit bulk export tooling, and add behavioral alerting for atypical Salesforce queries. Voice phishing remains a low-cost, high-yield initial access vector when cloud identity controls assume password-and-OTP authentication.

Read more →

SaltyCloud Research

Scoping FCI and CUI for NIST 800-171 and CMMC: Complete Guide

How to track FCI and CUI through your environment, isolate the systems and teams that interact with sensitive data, and use enclaves to make NIST 800-171 and CMMC compliance more feasible and cost-effective.

Read the guide →

Third-Party Security Risk Management (TPSRM): Complete Guide

How to build or optimize a TPSRM program at any team size, including vendor tiering, assessment cadence, evidence collection, and connecting third-party findings back to a live risk register.

Read the guide →

The GRC Buyer’s Guide

A practical evaluation framework for selecting GRC software, covering deployment-timeline expectations, the difference between traditional GRC platforms and GRC Assessment Platforms, and the questions to ask vendors before any commitment.

Access the guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

Plus, the DoD codifies its CMMC Phase 2 suspension, IDScan breach exposes 153M driver's license scans, and NYDFS risk assessment guidance.

Edition
09.17.2026

Plus, inconsistent CUI markings inflate CMMC scope, CareCloud breach impacts 3.7M patients, and NIST SP 1353, an AI quick-start for CSF 2.0.

Edition
09.17.2026

Plus, California's new DROP deletion platform, EU AI Act transparency enforcement begins, and White House-authorized private hacking.

Edition
09.17.2026
Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo