CMMC Phase 2 Is on Pause. Your Obligation to Secure Federal Data Isn’t.
Article Link: https://frsecure.com/blog/cmmc-phase-2-pause/
- The Department of War suspended Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements on July 12, putting the November 10, 2026, deadline for third-party attested cybersecurity assessments on hold for at least 60 days while a newly formed CMMC Reform Task Force reviews the entire program.
- Only the third-party assessment requirement is paused, phase 1 is still in effect. Contractors handling Controlled Unclassified Information must still comply with NIST SP 800-171A, submit self-assessment scores through the Supplier Performance Risk System, and remain subject to select government-led audits during the review period.
- The review aims to align CMMC with the Department’s broader Acquisition Transformation Strategy, which is pushing for faster speed-to-capability, lower barriers for small and non-traditional businesses, and less bureaucracy overall.
- Organizations already pursuing Level 2 certification are advised to keep working rather than pause, using the extra time to close gaps against the 110 NIST SP 800-171 controls and build a realistic compliance roadmap, since the task force’s findings and any new timeline remain unknown.
- Additional information: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail
Article Link: https://www.manifold.security/blog/claude-for-chrome-extension-bypass
- Researchers at Manifold Security disclosed two unpatched vulnerabilities in Anthropic’s Claude for Chrome extension that let any other installed browser extension trigger Claude into reading a victim’s Gmail, Google Docs, and Calendar without their knowledge or consent.
- The first vulnerability is a click-handler that never verifies whether a click is genuinely user-initiated. Any extension with access to claude.ai can fire a synthetic click to trigger one of nine hardcoded prompts.
- The second is a design flaw where Claude’s side panel enters a fully privileged, no-approval mode just by loading a URL with a specific parameter, no user gesture required. Researchers say this turns any future URL-handling bug into a silent, full-account-access exploit.
- These vulnerabilities represent a real-world case of “excessive agency” in AI browser agents. No phishing or malware needed, just a foothold via any other extension already in the browser.
- Both vulnerabilities were reported in May 2026, and Anthropic closed both reports. However, they remain unpatched in the latest version release on July 7, 2026.
The Jalisco Toolkit and AI-Powered Phishing Surge
Article Link: https://reliaquest.com/blog/threat-spotlight-jalisco-toolkit-and-ai-powered-phishing-surge
- ReliaQuest researchers identified two new phishing toolkits, “Jalisco” and “OmegaLord,” being used in active campaigns against Microsoft 365 environments. Both tools are purpose-built to defeat multi-factor authentication (MFA), reflecting a broader shift toward AI-powered phishing-as-a-service (PhaaS) kits that put advanced techniques within reach of low-skill attackers.
- Jalisco is a device-code phishing kit that provisions fresh OAuth codes in real time, bypassing the 15-minute expiration window defenders rely on. Because it steals authentication tokens rather than passwords, password resets don’t remove attacker access. OmegaLord, meanwhile, is a credential harvester that also captures phone numbers, likely to intercept or hijack MFA codes.
- Attackers are increasingly targeting the authentication process itself rather than just credentials. Once inside, they enroll multiple attacker-controlled devices to a victim’s Microsoft Entra ID tenant for persistent access, then exfiltrate sensitive data in as little as six minutes, fueling a reported 1,380% rise in phishing activity between late 2025 and early 2026.
Musk promises purge after Grok Build caught sending entire repos to the cloud
- Cereblab published an analysis revealing that xAI’s Grok Build, a command-line coding assistant, was silently transmitting users’ entire code repositories to a Google Cloud Storage bucket controlled by SpaceXAI. The tool packaged developers’ entire tracked repositories, including full Git history and committed secrets, uploading data at a volume roughly 27,800 times greater than what the coding task actually required.
- The tool’s marketing had explicitly claimed the opposite behavior, and unlike comparable CLI tools that only send files a user actively works on, Grok Build’s background process bundled and exfiltrated data regardless of privacy settings. The tool ignored “Do Not Read” instructions and uploaded historical, deleted secrets and unredacted environment files. Because Git history was included, previously deleted API keys, database passwords, and SSH keys were also exposed.
- Organizations using developer AI tools should treat this as a reminder that privacy toggles and marketing claims don’t guarantee actual data handling behavior. Independent, wire-level verification remains necessary before trusting a vendor’s privacy assertions, especially for tools with deep codebase access.
- xAI implemented a server-side change to stop the uploads, and Musk pledged that all previously uploaded user data will be permanently deleted.
Microsoft Entra ID gets Passkeys default authentication starting September
Article Link: https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/
- Microsoft announced that passkeys will become the default authentication method for Entra ID starting September 2026, automatically enrolling users who currently rely on SMS or voice-based multifactor authentication.
- As the rollout hits organizations, affected users will be prompted to register a passkey the next time they complete multifactor authentication. On February 1, 2027, Microsoft will fully retire its telecom-based SMS and voice authentication delivery.
- The move follows a wave of attacks in which threat actors, including the ShinyHunters extortion gang, targeted Entra single sign-on accounts using stolen credentials and device-code vishing techniques. Microsoft says AI-enabled phishing campaigns are now hitting click-through rates as high as 54%, compared to roughly 12% for traditional phishing.
- Additional information: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
- A federal complaint against an alleged Scattered Spider hacker publicly revealed the existence of Microsoft’s Global Device Identifier, or GDID, a persistent, permanent fingerprint assigned to a Windows installation whenever a user signs in with a Microsoft Account. Outside a single enterprise documentation reference, Microsoft has never disclosed it to end users.
- Investigators used the GDID to trace the suspect’s Windows device across VPNs, proxy servers, and three countries by cross-referencing timestamps when the same identifier appeared alongside logins to his personal accounts, ultimately connecting the device to an $8 million ransom extortion of a US jewelry retailer.
- Unlike Apple’s or Android’s advertising identifiers, the GDID has no consent screen and no user-facing reset control, and reinstalling Windows only generates a new ID that Microsoft can still link back to the same account through OneDrive and activation history.
- Users can’t fully eliminate the GDID but can limit its reach by signing in with a local account instead of a Microsoft Account, disabling optional diagnostic data, turning off personalized ad tracking, and disabling Cloud Content Search under Windows privacy settings.
