Run a fresh SPRS calc against your current POA&Ms. Anything in those four families now blocks conditional certification.
via 32 CFR 170
Threat IntelCritical
110d ago
Active exploitation: CVE-2026-1841 in widely deployed VPN gateway
Pre-auth RCE chain observed in production attacks against federal contractors. Maps to AC-17, SC-7, SI-2 across NIST 800-53. Patch available; mitigation requires segmentation review.
NIST 800-53AC-17SC-7SI-2SI-4
Practitioner Takeaway
Document patch + boundary review as evidence for SI-2(2) timeliness and AC-17 remote access controls.
via CISA KEV
AI GovernanceWatch
110d ago
ISO 42001 Annex A.6.2.7 receives interpretation guidance from accreditation bodies
AI impact assessment requirements clarified for high-risk systems. New thresholds for training data documentation align with EU AI Act technical files.
ISO 42001A.6.2.7A.7.4A.8.4
Practitioner Takeaway
If you certified under early ISO 42001, refresh AIIA documentation. Auditors are now scoping training-data lineage.
via IAF MD-AI
EnforcementElevated
110d ago
OCR penalty: $1.85M HIPAA settlement over risk analysis gaps
Mid-size health system penalized for failure to maintain enterprise risk analysis. Settlement includes 2-year corrective action plan.
HIPAA§164.308(a)(1)(ii)(A)§164.308(a)(8)
Practitioner Takeaway
Risk analysis must be living. Annual update + every significant change. Document the trigger, not just the output.
via HHS OCR
FrameworkWatch
110d ago
FedRAMP 20x: First three CSPs achieve automated authorization
PMO reports 65% reduction in time-to-authorization using machine-readable artifacts. SSP-as-code patterns validated across all impact levels.
FedRAMPCA-2CA-7RA-3
Practitioner Takeaway
If you're starting a FedRAMP path now, plan for 20x from day one. Manual SSP edits become technical debt fast.
via FedRAMP PMO
RegulatoryInfo
110d ago
DPDPA Rules notification draft released for public consultation
Indian Data Protection Board publishes draft rules covering consent management, breach notification windows, and Significant Data Fiduciary thresholds.
DPDPA§7§8(6)§10
Practitioner Takeaway
If you process Indian PII, comments due in 45 days. Significant Data Fiduciary criteria likely to capture mid-tier SaaS.
via MeitY
BreachCritical
111d ago
Major SaaS provider breach: 4.2M records via supply chain compromise
Third-party logging library used by IDP vendor was modified to exfiltrate session tokens. Customers in CMMC, FedRAMP, and SOC 2 environments affected.
Cross-frameworkSR-3SR-6SI-7AU-6
Practitioner Takeaway
Inventory which SBOM components you ingest from this vendor. Audit log review for token-replay patterns is the immediate task.
via Vendor disclosure
AI GovernanceElevated
111d ago
NIST AI RMF 2.0 draft expands to operational LLM deployment patterns
New profiles cover RAG architectures, agentic workflows, and multi-model orchestration. Aligns with EU AI Act Article 13 transparency requirements.
NIST AI RMFGV.POMP.4.1MS.3.5
Practitioner Takeaway
If you run RAG in production, the new MP.4.1 subcategory applies. Document retrieval source provenance now.
via NIST AI 100-1
Threat IntelElevated
111d ago
Phishing kit targeting SOC 2 Type II evidence portals
New campaign impersonates audit firm portals to harvest auditee credentials and exfiltrate evidence packages. SOC 2 CC6.1 controls under stress.
SOC 2CC6.1CC6.6CC7.2
Practitioner Takeaway
Verify auditor portal URLs out-of-band. Consider portal access via SSO with phishing-resistant MFA only.
via Threat intel partner
EnforcementWatch
111d ago
RBI imposes monetary penalty on NBFC for IT framework non-compliance
Rs 2 crore penalty levied for gaps in cyber risk framework, vendor risk management, and incident reporting timelines.
Pulse periodically ingests regulatory updates, threat intelligence, enforcement actions, and framework changes from authoritative sources. Each signal is mapped to the controls it affects across your framework portfolio, then rendered for the persona you operate in.
RegulatorsFederal Register, CISA, OCR, RBI, MeitY, EU AI Office
FrameworksCMMC, FedRAMP, ISO 27001, ISO 42001, SOC 2, HIPAA, NIST