Cyberuptive

Insights

Practical cybersecurity analysis. Pacific perspective.

Buyer's guides, compliance breakdowns, and field-tested perspectives from a working MSSP, written by the people who run the SOC, not the marketing team.

  • NewCMMC Level 2NIST SP 800-171

    Does CMMC Level 2 Use NIST SP 800-171 Revision 2 or Revision 3?

    NIST finalized Revision 3 in 2024 and a civilian FAR rule already points to it, but CMMC Level 2 still runs on Revision 2 under a standing DoD deviation. Here’s what changed, why the transition stalled, and what to track next.

  • Post-Quantum CryptographyExecutive Order 14412

    Post-Quantum Migration: A Realistic Timeline for Mid-Market Teams

    A June 2026 executive order set 2030 and 2031 federal deadlines for post-quantum cryptography, with a contractor compliance rule coming behind it. Here's a phased migration timeline that doesn't wait for the federal clock to force the question.

  • CISA KEVCVE-2026-20079

    Cisco Secure FMC CVE-2026-20079: Three Threat Actors, Zero Workarounds

    A CVSS 10.0 authentication bypass gives root access to Cisco's firewall management console. CISA's federal deadline was today — and three separate threat actors, including one tied to Sandworm, are already inside unpatched boxes.

  • Financial ServicesDORA

    DORA Compliance Deadlines in 2026: What US-Based Vendors Serving EU Financial Clients Need to Know

    DORA does not regulate US companies directly — it forces your EU financial-entity customers to flow its contract requirements onto you. Here is exactly what changed as oversight went live in 2026.

  • Buyer EducationMSSP

    Evaluating an MSSP: The Questions Your Shortlist Should Not Be Able to Dodge

    Every finalist claims 24/7 SOC coverage and fast response times. Here are the specific staffing, containment, and exit-clause questions that separate a real security operations center from a reseller.

  • CISA KEVCVE-2026-83548

    SonicWall SMA1000 CVE-2026-83548: A Third Zero-Day Chain in Seven Weeks

    CISA gave federal agencies a 3-day deadline on this SSRF-to-RCE pair. It is the second SMA1000 zero-day chain in seven weeks — here is exactly what to patch, what to check for compromise, and why.

  • InsuranceUnderwriting

    Cyber Insurance Underwriting in 2026: What Carriers Require to Bind

    Insurers have moved from general attestations to control-by-control checklists. See exactly what Beazley, Travelers, and CISA guidance require on MFA, backups, EDR, and patching before you bind or renew.

  • DIBCMMC

    DFARS 252.204-7012 Flow-Down: What Subcontractors Owe Primes

    CMMC Phase 2 is suspended, but DFARS 252.204-7012 is not. Here is exactly which NIST SP 800-171 controls, 72-hour incident-reporting duties, and flow-down obligations subcontractors still owe their primes today.

  • AI SecurityGovernance

    AI Security in Regulated Industries: A Pre-Deployment Checklist

    Federal bank regulators exempted generative AI and agentic AI from their April 2026 model risk rules, promising to address it later. Banks, health systems, and defense contractors are not waiting. Here is the governance, logging, and access-control checklist to require before you deploy an LLM anyway.

  • Threat IntelligenceCISA KEV

    Citrix NetScaler CVE-2026-8452: DoS on Paper, Root RCE in the Wild

    Citrix classifies CVE-2026-8452 in NetScaler ADC and Gateway as a denial-of-service bug. watchTowr Labs proved it is actually a pre-authentication heap overflow that grants unauthenticated root code execution, and CISA gave federal agencies a three-day KEV deadline under its new BOD 26-04 risk model. What to patch, hunt for, and report today.

  • Federal ComplianceCMMC 2.0

    CMMC Phase II Is Paused. Pacific Contractors Still Need to Move Forward.

    On July 13, 2026 the Department of War suspended CMMC Phase II. Phase I self-assessments and DFARS 252.204-7012 remain in force. What that changes for Pacific defense contractors this quarter, and what to keep doing anyway.

  • CanadaPIPEDA

    PIPEDA Safeguards: What a Canada MSSP Still Has to Prove

    Safeguards, RROSH reporting, and a record of every incident. What Toronto and Canada mid-market teams should demand from an MSSP before the Commissioner asks.

  • HawaiiMDR

    Hawaii MDR and 24/7 SOC: What Local Coverage Actually Changes

    HST never shifts. Mainland SOC night shifts do. What that means for detection, CMMC self-assessment evidence after the July 2026 Phase II pause, and who is allowed to touch CUI.

  • Federal ComplianceFedRAMP

    FedRAMP Program Certification: What Changes in 2026

    FedRAMP’s Notice NTC-0008 confirms FedRAMP Ready retires July 28, 2026, FedRAMP Certification becomes the authorization label, and a tightly scoped sponsorless Rev5 Program Certification path opens for some providers. How Certification Classes A through D map to historical impact levels, who qualifies for Stage 2, and what evidence to clean up before CR26 lands.

  • Cloud SecurityCISA KEV

    CISA KEV: Linux CVE-2022-0492 Container Risk

    CISA added Linux kernel CVE-2022-0492 to the KEV catalog on June 2, 2026 with a June 5 federal due date. Why an old cgroups v1 release_agent flaw still matters for container hosts, how to inventory affected kernels, patch cloud and Kubernetes nodes, reduce container-escape preconditions, and document remediation evidence.

  • Cloud SecurityVulnerability Management

    Cisco Secure Workload CVE-2026-20223: What to Fix

    Cisco disclosed a critical Cisco Secure Workload vulnerability affecting internal REST APIs that can give an unauthenticated remote attacker Site Admin access across tenant boundaries. How to confirm your deployment model, patch self-managed clusters to 3.10.8.3 or 4.0.3.1, validate API reachability, and govern the platform as security control-plane infrastructure.

  • Cloud SecurityConfidential Computing

    NIST IR 8320E: Confidential Computing for Cloud

    NIST published the IR 8320E initial public draft on May 29, 2026, with comments due July 13. A readiness guide for regulated cloud and AI teams: how to select candidate workloads, define the trusted execution environment boundary, govern keys, require attestation evidence, and align confidential computing with zero trust.

  • Vulnerability ManagementCISA KEV

    PAN-OS CVE-2026-0257: GlobalProtect KEV Guide

    CISA added PAN-OS GlobalProtect CVE-2026-0257 to KEV on May 29, 2026 with a June 1 federal due date. How to verify internet-facing exposure, check the authentication override cookie configuration, patch to the fixed PAN-OS or Prisma Access release, and review VPN authentication evidence for suspicious cookie-based access.

  • ComplianceNIST

    NIST SP 800-172r3: What CUI Teams Should Do Now

    NIST finalized SP 800-172r3 and SP 800-172Ar3 in May 2026. Where enhanced CUI requirements may apply, how to map evidence to SP 800-172Ar3 assessment methods, and how to tighten segmentation, privileged access, and supplier controls before agencies select enhanced requirements in your contracts.

  • Software Supply ChainCISA KEV

    CISA KEV: Nx and TanStack Supply-Chain Response

    CISA added Nx Console (CVE-2026-48027) and TanStack (CVE-2026-45321) to KEV on May 27, 2026 with a June 10 federal due date. How to verify developer and CI exposure, rotate the credentials the install paths could reach, and harden IDE extensions, lifecycle scripts, and build runners against repeat incidents.

  • Vulnerability ManagementMicrosoft Exchange

    Exchange OWA CVE-2026-42897: Mitigation and Verification Guide

    Microsoft confirms exploitation of CVE-2026-42897 in on-prem Exchange OWA, and the permanent patch is still pending. How to verify EEMS coverage, run EOMT in disconnected environments, work around the Internet Explorer Mode gap, and cut residual OWA risk while waiting for the update.

  • Vulnerability ManagementOT Security

    CVE-2026-8153: PolyScope 5 RCE Risk in Manufacturing

    Universal Robots patched CVE-2026-8153 in PolyScope 5.25.1, a critical OS command injection in the Dashboard Server. The manufacturing remediation plan, upgrade, disable, segment, and how to validate without exploit testing on production cells.

  • Vulnerability ManagementOracle

    Oracle CSPU May 2026: What Security Teams Should Do Now

    Oracle’s first Critical Security Patch Update lands May 28, 2026, with a third-Tuesday cadence and a Thursday pre-release announcement. The CSPU operating calendar, three-lane SLA model, and the readiness questions CISOs should ask before release day.

  • Vulnerability ManagementCISA KEV

    Cisco SD-WAN KEV: Patch First, Then Hunt

    CISA added Cisco Catalyst SD-WAN CVE-2026-20182 to the KEV catalog with a May 17, 2026 federal due date. Why Cisco tells operators to upgrade before waiting for TAC results, and the operational checklist for control components, TAC engagement, and cloud-hosted SD-WAN posture.

  • Vulnerability ManagementCISA KEV

    Exchange CVE-2026-42897: What to Verify Now

    CISA added Microsoft Exchange CVE-2026-42897 to the KEV catalog with a May 29, 2026 due date. How to verify EEMS/EOMT mitigation, capture per-server evidence, and prepare patch governance for the permanent update, without inventing IoCs or weaponizing the response.

  • Vulnerability ManagementOracle

    Oracle Monthly CSPUs: What Changes for Patch Governance

    Oracle monthly Critical Security Patch Updates begin May 28, 2026. How to update vulnerability management policy, patch SLAs, testing tiers, and audit evidence before the cadence changes, without turning monthly patches into monthly deferrals.

  • Buyer's GuideMSSP

    MDR vs MSSP vs SIEM: a 2026 Buyer's Guide

    The acronyms are not interchangeable. Buying the wrong one wastes a year and leaves you exposed. Plain-English definitions, a 60-second comparison table, when you need each, and the four questions that actually decide.

  • Industry ComparisonMSSP

    Top MSSP Providers in 2026: An Honest Comparison

    Arctic Wolf, eSentire, Expel, Trustwave, Critical Start, and Cyberuptive scored against six criteria, response authority, identity coverage, analyst geography, compliance evidence, mid-market fit, and transparency. Pay-to-play this is not.

  • ClarifierMSSP

    MSSP Software vs MSSP Service: You Probably Want the Service

    Searched for "MSSP software" and got a confusing mix of results? Most buyers want a service, not a tool. Here's the distinction between SIEM, EDR, MSP platform software, and what an actual MSSP delivers.

  • Federal ComplianceFedRAMP

    FedRAMP 2026 Rules Preview: What CSPs Should Do Now

    FedRAMP published a public preview of its 2026 consolidated rules. What is changing, when rules take effect in July 2026, and how CSPs and agency buyers should prepare evidence, decision records, and continuous monitoring workflows.

  • Financial ServicesThird-Party Risk

    Credit Unions Are in the Crosshairs: What the 2024–2026 Breach Wave Is Teaching Us

    Patelco, MemberSource, Marquis, Ongoing Operations, the last 24 months show credit unions are being hit through their vendors as often as their own networks. Four named incidents, NCUA’s 72-hour rule, and a five-action playbook for the quarter.

  • ComplianceNIST

    NIST SP 800-70r5: Secure Configuration Checklist Guide

    NIST finalized SP 800-70r5 with updates for automation, traceability, and modern cloud, IoT, and AI environments. How to operationalize baselines and produce the deployed-and-maintained evidence FedRAMP and CMMC assessors expect.

  • Supply ChainIncident Response

    OpenSearch npm compromise: who’s affected and what to do

    OpenSearch disclosed compromised npm dev packages on May 11, 2026. Who’s affected, what to check in your pipeline, and how to harden CI/CD against the next supply chain incident.

  • Threat IntelligenceSupply Chain

    Mini Shai-Hulud: When SLSA-Signed Packages Carry Malware

    The TanStack npm compromise (CVE-2026-45321) abused GitHub OIDC and trusted publishing to ship credential-stealing malware with valid SLSA L3 provenance. What changed, what to block, and what mid-market and DIB teams should do this week.

  • Zero TrustNetwork Security

    Are Hardware Firewalls Still Relevant in Zero Trust?

    Zero trust did not kill hardware firewalls. It changed their job from perimeter gatekeeper to segmentation, telemetry, and resilience control, here's where they still earn their place.

  • AI SecurityMDR

    Trellix Wise vs. CrowdStrike Charlotte AI vs. SentinelOne Purple AI: Why Wise Wins for the Modern SOC

    An MSSP's hands-on comparison of the three biggest AI security analysts on the market, and why Trellix Wise is the better fit for Pacific defense contractors and medium and large businesses that need full-attack-surface, FedRAMP-ready coverage.

  • DoW ContractorsCMMC

    CMMC Phase 2 Pause: What Pacific Subcontractors Still Owe

    CMMC Phase II was suspended July 13, 2026. Phase I self-assessments and DFARS 7012 still apply. What Pacific subcontractors should do this quarter.

  • AI SecurityThreat Intelligence

    Anthropic's Mythos and the Dawn of AI-Driven Offense: What It Means for Defense Contractors and Mid-Market Organizations

    Anthropic's Mythos AI can find software vulnerabilities at machine scale, and unauthorized users have already touched it. Here's what changes for mid-market organizations, MSPs, and DoW subcontractors.

  • CMMCDoW

    CMMC timeline for Pacific contractors after the Phase 2 pause

    Phase II is paused. Phase I self-assessments and DFARS 7012 still apply. The Pacific contractor timeline after July 13, 2026.

  • Managed SOCPricing

    How Much Does a Managed SOC Cost in 2026? A Buyer's Guide for Medium and Large Businesses

    What managed SOC actually costs medium and large businesses in 2026, pricing models, what drives variance, in-house comparison, and red flags to watch when comparing providers.

  • MSSPPacific

    Why Honolulu Defense Contractors Need a Pacific-Based MSSP

    Time zone, US-persons handling, and INDOPACOM-AOR awareness are not optional. Why Hawaii defense subcontractors should be skeptical of mainland-based MSSP relationships.

Aloha, let's talk

Ready to talk to someone who actually answers the phone?

Whether you're scoping a CMMC assessment, evaluating a managed SOC, or just trying to get through your next audit: we can help. No sales theater. No offshore tier-1.