Category: Compliance & Risk
-

The Reg S-P Clock Ran Out: Then The Breaches Began
On July 14, 2026, Microsoft patched an actively exploited SharePoint zero-day (CVE-2026-56164), CISA added it to the Known Exploited Vulnerabilities catalog with a 72-hour federal deadline, and support for SharePoint Server 2016 and 2019 officially ended. Three events, one date. Here is what every on-premises operator should do this week.
-

Canvas Breach Update: Reports Set to Resume for California’s 116 Community Colleges
The April-May 2026 Canvas breach put student data at all 116 California community colleges in scope. Instructure paused detailed breach reports over a ShareFile threat that has since cleared. Here’s what was exposed, what California’s breach-notification law actually requires, and the four steps to take this week.
-

Business Email Compromise at Credit Unions: How Attackers Redirect Wire Payments and What Stops Them
Business email compromise costs U.S. organizations billions each year, and credit unions are prime targets. Here is how attackers redirect wire and ACH payments, the four most common scenarios, and the layered controls (DMARC, out-of-band verification, and staff training) that actually stop them.
