Edition

Banking Agencies Rewrite Third-Party Risk, DoD Locks In CMMC Phase 2 Pause, and IDScan Breach Exposes 153 Million IDs

SaltyCloud Research Team

Updated Sep 15, 2026 Read Time 14 min

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the infosec GRC news worth sharing from the first half of September.

Let’s get into it.

Regulatory & Compliance Updates

DoD Codifies CMMC Phase 2 Suspension

On September 3, a memo from John Tenaglia, the Defense Department’s principal director for defense pricing, contracting and acquisition policy, turned the CMMC Phase 2 suspension into a class deviation. Under DFARS, contracting officers are directed to omit CMMC third-party certification requirements from new solicitations, and amend active solicitations that still carry them. More specifically:

  • DFARS 252.204-7012 cybersecurity requirements stay in effect under the DoD’s implementing procedures.
  • NIST SP 800-171 Rev 2 compliance still runs through Level 1 and Level 2 self-assessment, plus select government-led assessments.
  • Program managers cannot designate Level 2 or Level 3 assessments and must amend active solicitations that call for one, with no waivers.

So, the requirement stayed, but the assessor went away. What’s left is a self-assessment score that no C3PAO will check. Now, the risk of certification failure is being replaced by the risk of misrepresentation. Yet DoD CIO Kirsten Davies said on September 9 that the task force has already taken in more than 1,100 responses totaling over 10,000 pages, and more than half of respondents back the hold.

On September 11, the 60-day review that decides what comes next closed. Its report goes to Davies before anything reaches the public, and she decides whether the recommendations are released at all. A public determination may not land until October, as a result. In the meantime, contractors can confirm their SPRS score rests on evidence an assessor would accept.

Read more →

FTC Finalizes Orders Over “Active Listening” AI Claims

On August 27, the FTC voted 2-0 to finalize consent orders against three organizations marketing an “Active Listening” service. That includes:

  • Cox Media Group for $880,000
  • MindSift for $25,000
  • 1010 Digital Works for $25,000

All three companies claimed that the service could listen to conversations through smart devices to target advertising, but it did no such thing.

According to the complaints, the Active Listening service used no voice data at all and amounted to reselling email lists bought from data brokers at a significant markup. Each company also told customers that consumers had opted in, when what they really meant was that they had accepted the app’s terms of service.

The Commission rejected that outright, holding that clicking through mandatory terms of service does not constitute opt-in consent for an invasive service or for voice data from inside someone’s home. The FTC also added that, had the service worked as advertised, collecting voice data on that basis would itself have violated Section 5.

Notably, that puts the marketing team within scope of AI governance. Most programs review models, training data, and deployment decisions, but very few review what sales says the model does or what the privacy notice claims the user agreed to.

Before the next datasheet ships, organizations marketing AI capabilities can:

  • Route capability claims through the same substantiation review product security claims get.
  • Keep the supporting evidence on file for as long as the claim runs.
  • Confirm no claim outruns what the model was actually tested to do.

Read more →

NIST Closes Comment on AI Data Center Security Draft

On September 25, the comment period for NIST SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach is closing. Released on July 27, the initial public draft identifies key threats facing AI data centers and possible solutions.

The draft is more specific than other AI governance frameworks. It:

  • Runs a threat and security gap analysis of data centers purpose-built for model training and inference.
  • Compares them against traditional HPC systems across system architecture, hardware, software stacks, workflows, and data storage.
  • Proposes a paired solution for each threat that emerges from those differences.

NIST SP 800-239 carries no requirements today, but its gap analysis could still shape what assessors ask about AI infrastructure in the near future. The current comment window may be the only opportunity practitioners get to influence it.

Read more →

Irish DPC Fines the HSE €645,000 Over Paper Records

On September 2, Ireland’s Data Protection Commission closed its inquiry into the Health Service Executive, issuing a reprimand and €645,000 in fines. Investigators found patient records in:

  • Disused bathrooms
  • A shipping container inside a turf shed
  • Rooms with no working light or heat
  • Derelict buildings

Deputy Commissioner Graham Doyle described documents “damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to storage environment or water damaged.” As a result:

  • Security failures drew €300,000, under Articles 5(1)(f) and 32(1).
  • Storage limitation drew another €300,000, under Article 5(1)(e).
  • Late notification to the DPC added €30,000, under Article 33(1).
  • Failing to tell affected patients added €15,000, under Article 34(1).

The DPC also ordered the HSE to audit every storage facility, move records out of unfit ones, and run regular compliance testing.

Even though retention failures cost the same as security failures, most programs instrument retention for digital systems only. But in this case, leaving physical records to facilities management put the larger half of the penalty outside anyone’s control testing.

Any organizations holding regulated records on paper should consider pulling physical storage on the same retention schedule and breach-notification clock their digital estate already runs on.

Read more →

California Requires Risk Assessments Before AI Chatbot Rollouts

On September 10, California’s Governor Gavin Newsom signed a package of AI and social media laws. Now, companies must:

  • Run risk assessments before rolling out AI chatbots.
  • Build crisis-response protocols that flag emotional distress in minors.
  • Face fines reaching $1 million per child for violations.

A companion measure also directs the state to stand up a registry of independent AI safety auditors.

With the assessment requirement, California has made a pre-deployment review a condition of launch — the same move made by the EU AI Act, and the first time a US state has made it for consumer chatbots.

California will also decide who counts as a qualified assessor. Independent assessment only works when there is a supply of assessors, and a state-maintained registry is where that supply gets named. That’s exactly how third-party assessment regimes typically begin.

Organizations shipping consumer-facing AI can inventory which products reach minors, confirm a documented pre-deployment assessment exists for each, and track the registry as it populates.

Read more →

GRC Strategies

DORA Report Logs 3,383 Significant ICT Incidents

The European Supervisory Authorities’ first report under DORA counted 3,383 significant information and communications technology (ICT) incidents across EU financial services. Nearly 29% of those incidents traced back to third-party providers.

DORA Articles 28 through 30 require a vendor register that counts how many providers a firm uses. But it doesn’t show which failures spread from one provider to the next. Instead, dependency concentration tends to show up in infrastructure well before it ever shows up in a contract. Common examples include:

  • Nominally separate vendors running on the same control plane
  • A single identity provider authenticating users across many services
  • A handful of external APIs serving several critical processes at once

A register sorted by contract value won’t show whether ten vendors sharing one authentication path carry the risk of a single provider. In response, financial institutions can map dependencies at the architecture level, and then rank third parties by what breaks when they fail.

Read more →

NYDFS Publishes Guidance on Cybersecurity Risk Assessments

On September 10, NYDFS published an Industry Letter with guidance for covered entities to design, document, and maintain the risk assessments Part 500 already requires. In it, NYDFS asks for a “clear and repeatable methodology for identifying, analyzing, and prioritizing actions to address cybersecurity-related risks.” In practice, that means:

  • Combining threat intelligence, vulnerability scans, and penetration test results.
  • Defining likelihood and impact with consistent rating criteria.
  • Evaluating internal threats alongside external ones.

The Industry Letter also sets governance requirements, including:

  • Annual approval for written policies by a senior officer or the senior governing body.
  • Process ownership by the CISO or senior officer.
  • Participation from business units, compliance teams, and legal departments.
  • Minimum annual review for assessments plus re-assessment following any material changes in business or technology operations.

The guidance does not create any new obligations. But it does give covered entities a closer look at what examiners will look for in regards to the rules already in force. And the traceability it describes between identified risks and implemented controls is a fair benchmark for any risk assessment methodology, regulated or not.

Whether or not NYDFS Part 500 applies, GRC teams can still read it as a gap checklist against their current methodology.

Read more →

Banking Agencies Propose Replacing Third-Party Risk Guidance

On September 11, the OCC, the Federal Reserve, the FDIC, and the NCUA jointly requested comment on proposed guidance that would rescind and replace the 2023 Interagency Guidance on Third-Party Relationships, the 2024 community bank guide, and the 2024 joint statement on bank-fintech deposit arrangements. The new framework includes four components:

  • Risk identification and assessment
  • Risk oversight
  • Residual risk acceptance
  • Governance

Among other things, the proposal moves oversight away from broad labels and toward the magnitude and likelihood of harm a specific relationship can cause. For lower-risk vendors, it supports lighter diligence, reserving deeper oversight for relationships that could cause material legal, financial, operational, or customer harm.

With the NCUA joining the framework for the first time, credit unions now face the same third-party risk expectations as banks. However, since the guidance is non-binding, deviating from it is not a basis for supervisory action.

In the interim, institutions can model what harm-based tiering would change and file any findings in a comment, due 60 days after publication in the Federal Register.

Read more →

Cyber Incidents & Risk Implications

CISA Adds Eleven Exploited Flaws in Back-to-Back KEV Batches

CISA added eleven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog across two September batches. Seven landed on September 2, and three of those sat in AI and machine learning infrastructure:

On September 8, four more followed:

Under Binding Operational Directive 26-04, federal agencies had until September 5 to patch or mitigate five of the first seven, with the Starlette and LiteLLM pair due September 16.

Because organizations tend to inherit Starlette as a dependency of something else instead of installing it directly, the affected version usually sits in a lockfile rather than a software inventory. So, a patch program working from that inventory can’t say whether the organization is affected. Since inventories built around endpoints, network gear, and business applications rarely list model gateways, model-serving frameworks, or MCP servers, the same blind spot covers the rest of the AI stack.

Outside government, teams can:

  • Treat the KEV catalog as a prioritization input.
  • Pull AI pipeline components into existing patch service levels.
  • Add dependency scanning for the parts of the stack an inventory will never show.

Read more →

McKesson Breach Exposes 6.4 Million Email Addresses

On August 25, McKesson, one of the largest US distributors of pharmaceuticals and medical supplies, detected an intrusion. It then confirmed that attackers took data from its Oncology & Multispecialty and Medical-Surgical units.

After claiming the attack, extortion group ShinyHunters demanded a $55.2 million ransom for a purported 284 million records. Once the deadline passed, Have I Been Pwned logged 6.4 million unique email addresses in the published corpus, including marketing recipients, patients, staff, and healthcare provider contacts.

Of the 284 million records, HIBP counted 6.4 million unique email addresses in the published dump, and none of the Social Security numbers ShinyHunters claimed. Remember, extortion groups have every incentive to inflate such figures. Since the two counts measure different things, notification scope must rest on forensics rather than on either number alone.

The attack began with voice phishing calls to employees that produced Okta SSO credentials. From there, the attackers reached Salesforce and Snowflake. Since federated access works as-designed for anyone with valid credentials, and because both platforms sat behind the same login, one account opened several data stores. Technically, nothing failed, which is why this failure mode has no patch.

Instead, organizations with federated access to platforms that hold regulated data can:

  • Test help desk identity verification against a vishing attempt.
  • Map which downstream systems one compromised SSO account reaches.
  • Confirm bulk exports from those platforms generate an alert someone reviews.

Read more →

ChainDrop Worm Reaches 444 npm Packages

A self-propagating worm called ChainDrop compromised 444 npm packages — including keyv, flat-cache and cache-manager — collectively downloaded about 2 billion times a month. Once the worm harvests npm and GitHub credentials from the machines it lands on, it republishes poisoned versions without an operator.

Instead of committing to the source repository, ChainDrop rebuilds published tarballs. Because the source never changes, the repo shows nothing wrong. The worm also plants startup hooks in repository configuration files that developer tooling runs automatically. Because no dependency scanner treats a config file as code, those hooks execute without ever being reviewed.

So, even if a compromised artifact no longer matches the source it came from, teams that review sources, pin versions, and trust the registry can still install it.

Organizations running Node.js dependencies can:

  • Check every branch for unexpected tooling configuration files.
  • Cross-reference installed versions against the published list of compromised packages.
  • Rotate any npm or GitHub token that touched an affected build.
  • Treat repository-supplied configuration as executable content in the threat model.

Read more →

IDScan Breach Exposes 153 Million Driver’s License Scans

On September 4, IDScan.net, a Louisiana identity verification vendor that runs ID checks for car rental companies, retailers, and cannabis dispensaries, confirmed that an unauthorized third party may have copied customer data from its cloud platform.

The announcement came after Nexus, a dark-web service, had listed scans of identity documents belonging to more than 170 million people across the US and Canada, including:

  • 153 million driver’s license scans
  • 10 million ID cards
  • 3 million travel documents
  • 579,000 medical cards

Security journalist Brian Krebs verified the listing after a source flagged it on August 31, tracing the records back to IDScan. Shortly after his report ran, Nexus disappeared from the dark web and the FBI’s New Orleans field office opened an investigation.

Still, IDScan’s own notice describes the exposure as names and government-issued ID numbers, which is narrower than what a scan actually holds. A front-and-back license image also carries a photograph, address, date of birth, and barcode data. Since none of that information can be reissued the way a password can, exposure runs for the life of the document.

Organizations using a third party for identity verification can:

  • Confirm what that vendor retains and for how long.
  • Check whether the contract obliges notification on a breach of document images specifically.
  • Treat ID-document processors as a distinct tier in the vendor register, instead of as ordinary SaaS.

Read more →

SaltyCloud Research

NIST CSF 2.0 Readiness Scorecard

A free NIST CSF 2.0 self-assessment that scores cybersecurity maturity and prioritizes next steps.

Access the Scorecard →

CMMC: Complete Guide [2026]

A full overview of the Cybersecurity Maturity Model Certification program, its three levels, and how each one maps to NIST 800-171.

Read the Guide →

CIS Controls: Complete Guide [2026]

A walkthrough of the prioritized control set from the Center for Internet Security, what each control covers, and where to start implementation.

Read the Guide →

Wrapping Up

Most stories in this edition turn on scope — assets that weren’t enrolled, records and vendors that weren’t tiered, and claims and decisions that weren’t reviewed. In each of those cases, risk sat outside a boundary the program had drawn for itself.

The programs that can name what’s in scope and prove it will spend the next quarter meeting deadlines instead of learning, one incident at a time, what they left out.

If you’re on LinkedIn, follow SaltyCloud for more insights and updates between newsletters. And, as always, feel free to reply to this email with comments, questions, concerns, ideas, or memes. We’re always listening.

Thanks for being part of our community and for letting us be part of your day. We’ll keep doing our part to deliver content that’s as essential as salt itself.

Wishing you resilience and security,

The SaltyCloud Research Team

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Learn More
Our GRC Resources

Dive into our research-backed resources–from product one pagers and whitepapers, to webinars and more–and unlock the transformative potential of powerfully simple GRC.

Learn More
Past Editions

Plus, inconsistent CUI markings inflate CMMC scope, CareCloud breach impacts 3.7M patients, and NIST SP 1353, an AI quick-start for CSF 2.0.

Edition
09.17.2026

Plus, California's new DROP deletion platform, EU AI Act transparency enforcement begins, and White House-authorized private hacking.

Edition
09.17.2026

Plus, a $2.25M FTC fine over FCRA failures, high-risk EU AI Act deadlines deferred to 2027, and GAO on FAA and TSA aviation cyber gaps.

Edition
09.17.2026
Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo