Category: Cybersecurity
-

How the SharePoint Chain Broke on July 14, 2026: CVE-2026-56164, End-of-Support, and What Every On-Prem Operator Should Do This Week
On July 14, 2026, Microsoft patched an actively exploited SharePoint zero-day (CVE-2026-56164), CISA added it to the Known Exploited Vulnerabilities catalog with a 72-hour federal deadline, and support for SharePoint Server 2016 and 2019 officially ended. Three events, one date. Here is what every on-premises operator should do this week.
-

Business Email Compromise at Credit Unions: How Attackers Redirect Wire Payments and What Stops Them
Business email compromise costs U.S. organizations billions each year, and credit unions are prime targets. Here is how attackers redirect wire and ACH payments, the four most common scenarios, and the layered controls (DMARC, out-of-band verification, and staff training) that actually stop them.
-

CMMC Phase II Suspended: What It Means and What to Do Next
On July 13, 2026, the Department of War suspended CMMC Phase II, removing the November 2026 third-party audit deadline. But DFARS 252.204-7012, NIST SP 800-171, and your SPRS self-attestation all still apply. This is schedule relief, not scope relief, and here is what defense contractors should do during the pause.
