Cybersecurity Blog


Subscribe

Posts tagged: NIST

Category: Compliance

Compromised Logins Now the Top Entry Point for Ransomware

Compromised Logins Now the Top Entry Point for Ransomware


Posted July 16, 2026 in Compliance, Ransomware, HIPAA, CMMC, NIST

Compromised logins have overtaken software flaws as the top entry point for ransomware. How credential-driven attacks...

CMMC Phase II Suspended: What Defense Contractors Should Do Now

CMMC Phase II Suspended: What Defense Contractors Should Do Now


Posted July 15, 2026 in CMMC, NIST, Compliance, Cybersecurity, AI

The Department of War suspended CMMC Phase II requirements set for November 10, 2026. What the pause means and what...

CISA warns admins to patch actively exploited SharePoint flaws

CISA warns admins to patch actively exploited SharePoint flaws


Posted July 15, 2026 in Compliance, HIPAA, CMMC, NIST, Cybersecurity

CISA warns admins to patch three actively exploited flaws in on-premises SharePoint Server. Affected versions and...

In Other News: DHS Database Hacked, Canada Disrupts Ransomware

In Other News: DHS Database Hacked, Canada Disrupts Ransomware


Posted July 11, 2026 in Ransomware, Compliance, HIPAA, CMMC, NIST

DHS database hack, Adobe's faster patch cadence, and a Canadian ransomware takedown: this week's security roundup and...

Ransomware Uses a Malicious Driver to Disable Endpoint Defenses

Ransomware Uses a Malicious Driver to Disable Endpoint Defenses


Posted July 9, 2026 in Ransomware, Compliance, HIPAA, CMMC, NIST

A new ransomware family abuses the PoisonX kernel driver to shut down endpoint defenses. How BYOVD attacks work and...

The Gentlemen Ransomware: A Test of Identity and Recovery

The Gentlemen Ransomware: A Test of Identity and Recovery


Posted July 8, 2026 in Ransomware, Compliance, HIPAA, NIST, CMMC

The Gentlemen ransomware tests whether your identity and recovery controls can contain an attacker after initial...

JadePuffer: The First Complete LLM-Driven Ransomware Attack

JadePuffer: The First Complete LLM-Driven Ransomware Attack


Posted July 7, 2026 in AI, Compliance, Ransomware, HIPAA, NIST

JadePuffer is the first fully LLM-driven ransomware attack, exploiting a Langflow flaw end to end. What autonomous...

How We Scored 110 on Our Own CMMC Self-Assessment

How We Scored 110 on Our Own CMMC Self-Assessment


Posted July 1, 2026 in CMMC, Compliance, NIST

Petronella Technology Group earned a perfect 110 SPRS score on its own CMMC Level 2 self-assessment. Five lessons for...

Why CMMC SSPs and POA&Ms Fail at Assessment and How to Pass

Why CMMC SSPs and POA&Ms Fail at Assessment and How to Pass


Posted June 23, 2026 in CMMC, Compliance, NIST, AI, Cybersecurity

Most CMMC System Security Plans fail before the assessor opens them. See exactly what C3PAOs check in your SSP and...

Law Firm Cybersecurity: ABA 1.6(c) Compliance Guide 2026


Posted May 16, 2026 in CMMC, Malware, NIST, Compliance, Penetration Testing

Law firm cybersecurity checklist tied to ABA Model Rule 1.6(c), Formal Opinions 477R and 483, state bar guidance, and...

NIST CSF 2.0 for Boards: Your Practical Cyber Roadmap

NIST CSF 2.0 for Boards: Your Practical Cyber Roadmap


Posted May 13, 2026 in NIST, Compliance, Data Breach

NIST CSF 2.0 in Practice: A Board-Level Cyber Roadmap Board accountability for cybersecurity is no longer an abstract...

NIST 800-50 Rev 1: Awareness Training Blueprint

NIST 800-50 Rev 1: Awareness Training Blueprint


Posted May 6, 2026 in NIST, Compliance, Malware, Data Breach

NIST 800-50 Rev 1 (2024) awareness training blueprint: 3 learning tiers, 4-phase lifecycle, CSF 2.0 mapping, and...