Skip to main content
Logo-300x300-colored-3
  • Home
  • Services
    • Offensive Security
    • Defensive Security
    • Privacy Engineering
    • AI Advisory
    • AI Assessment
    • AI Integration
  • Products
  • About
    • About Us
    • FAQ's
  • Resources
    • Blog
    • In The Media
    • Podcasts
    • All Resources
Get a Free Assessment
Back to Blog
Government Security Cyber Defense Compliance

CMMC's Third-Party Assessments Are Paused. The Standard of Care Isn't

Denis Calderone July 20, 2026 11 min read
Table of Contents

    On July 13 the Department of War suspended Phase 2 of CMMC, the third party certification requirement that was set to start this November. Half the defense industrial base exhaled. The other half is furious.

    Let me put my bias on the table before I say anything else. I do not run a C3PAO and I do not sell certifications. My work is readiness and cyber security advisory and consulting, so I have no certificate revenue to protect and no reason to tell you the sky is falling. That said, I have spent years helping companies build toward CMMC, so I know exactly what this pause feels like for the people who were mid-journey.

    Here is what moved and what did not.

    The suspension killed the third party assessment requirement, along with the later phases that would have followed. Phase 1 is still here. You still self assess against NIST 800-171. You still post your score in SPRS and sign the annual affirmation. DFARS 252.204-7012 has required contractors to protect covered defense information since 2017, and it is fully intact. All 110 controls are still the standard. Nothing about the level of security expected of you got easier. The only piece that went away is the outside party who was going to check your work.

    image (70)

    This pause was coming, and the government knew it

    You will see a lot of relief being expressed online this week from those excited that their mad dash to tighten up their program and get the C3PAO in place, along with the spend that goes with it, was just put on hold. Be careful with that. The relief is well earned, but do not let the excitement lull you into inaction. You might not have to pay for a C3PAO anymore, but you still have a compliance program to run, like it or not, and your obligation has not really changed.

    There is a wide gap between killing a payment for a certificate and killing your investment in real security. I will come back to that. But first, let me be fair to the decision itself. The delivery model was broken anyway, and it was broken in a way that was documented well before July.

    Back in March, the Government Accountability Office published a report warning that DoD had never assessed whether the private sector could supply enough assessors to run the program. DoD concurred. So the government's own auditor said the capacity did not exist, and the department agreed in writing.

    The numbers say the same thing. The SBA put more than a hundred thousand small firms into the Phase 2 pipeline against roughly a hundred approved assessors. It estimated the cost of a third party certification at close to $600,000 for a small company, and just under $400,000 even for a firm that only had to self assess. A shop doing four million dollars a year cannot carry a six figure compliance bill, and a hundred assessors cannot clear a hundred thousand companies this decade. The program was pricing out the exact small innovators it was supposed to protect, and in turn locking them out. So the suspension is really the arithmetic catching up with the policy. It was inevitable.

    image (71)

    What always bothered me about CMMC

    I see a real tension here. CMMC was trying to do two hard things at once. It wanted to verify that contractors were genuinely protecting sensitive data, because years of self-attestation had failed and adversaries had walked off with real program information. It also wanted to keep the industrial base wide enough to build what the country needs, including the small and nontraditional shops that have the technology but not the compliance infrastructure. At the scale the program demanded, those two goals ran straight into each other, and that is what broke. But that collision was about the machinery not the responsibility.

    Strip away the abstraction and that responsibility lands on a person. Somewhere in your company a manager is responsible for protecting that data and has to sign their name to say it is handled. That was that manager's responsibility with CMMC in force. It is the same manager's responsibility with CMMC on hold. Lawyers call it a standard of care. On the floor it is just the person whose neck is on the line. CMMC never created that responsibility. It only graded it. And the grade is the only thing that changed.

    You are the last set of eyes now

    In January 2021, a Massachusetts defense contractor called MORSECORP told the government its NIST 800-171 score was 104, near the top of a scale that runs from -203 to 110. That score was wrong. They found out just how wrong a year later, when the company brought in an outside firm to run a gap analysis and the real number came back at -142. MORSE left the inflated 104 on the books and kept winning work on it. It did not correct the number until a federal subpoena forced the issue years later, and last year it paid 4.6 million dollars to settle the False Claims Act case that followed.

    image (72)

    Notice who paid that bill? The company that signed the number, and nobody else. And it was not blindsided. An outside firm had already told MORSE the real score. It buried that finding and left the inflated number in place. The assessment did its job. The company refused to listen, and the bill came due.

    That is what an outside look is really for; it tells you whether you are actually meeting the bar, in time to fix the gaps before you put your name behind the number. Phase 2 was about to make that outside assessment mandatory for everyone handling CUI. The suspension pulled that requirement, and DoD has ordered it stripped out of active contracts. The price for getting your security wrong did not get pulled with it.

    And the government auditor did not vanish along with the commercial one. DIBCAC still runs government led assessments, and the memo says those continue. For a manufacturer that means someone can still walk your floor and look at whether your business network is genuinely separated from your machine controllers, which a paper checklist was never going to catch anyway.

    The Justice Department's cyber fraud effort is fully operational, and the incentives behind it are only getting stronger. The whistleblower who flagged MORSE collected $851,000, and the plaintiffs' bar now has a playbook for these cases. Crowell & Moring is already warning DOJ could turn toward false Phase 1 self-assessments next. Read that as the pressure heating up, not cooling down.

    You cannot put this back in the box

    The primes spent the last five years building CMMC compliance into how they operate, and they are under the exact same rules you are. DFARS 7012 and the False Claims Act do not stop at the prime's front door. When a prime hands you CUI, your security becomes their exposure, because a breach at a sub, or a false attestation from one, lands on the prime that vouched for its supply chain. They need their subs secure to protect themselves, and regardless, no press release out of Washington is going to rewrite your subcontract.

    The compliance standard is already heavily operationalized. Consider RTX. It bakes your CMMC status into its annual supplier registration process and will not issue a purchase order to a supplier handling CUI without it. Or Lockheed, which requires a green rating in its Exostar questionnaire as a condition of staying on the program. General Dynamics Mission Systems demands a minimum SPRS score of 88, no waivers. None of that is tied to the November date, and none of it moved this week. If you supply a major prime, your obligation this morning is the same as it was last week.

    So the compliance program still exists along with the mandate, and all that we've lost is the professional validation process. The prime is already pulling your NIST 800-171 SPRS score out of the system by CAGE code, and until now the plan was to use the C3PAO certificate as the clean outside stamp that told them your reported score was accurate and trustworthy. That stamp is now gone. What is left in their hands is self-reported: your SPRS score and whatever their own questionnaire tells them. The prime is still holding all of its own liability, and I am guessing that with the independent check pulled out from under them, they are not going to shrug and trust the honor system. I am thinking it is more likely that this pause only ups the scrutiny of the SPRS score, and that this is not the moment to be carrying a number you cannot back up.

    Do not mistake a memo for a repeal

    Remember, this is just a pause. The rule itself is still on the books, codified in federal regulation, published last September and effective in November. A memo can stop the clock. Unwinding a final rule takes formal rulemaking, and that runs for months or years.

    The last administration paused the first version of CMMC in 2021 for its own review. It came back as CMMC 2.0 with the same bones, and the contractors who tore their programs down spent the next three years catching up. My money says this returns in some form, probably leaner, quite possibly after the next election. And whatever it looks like in the end, there is a good chance it comes back less bureaucratic and more focused on real risk management. Whoever dismantles everything now is going to feel it later.

    So what actually makes sense

    Davies used a phrase in the memo that I would frame on a wall, "tangible cyber hygiene rather than bureaucratic red tape." She is describing where the money should have been going all along. Look, I am not here to knock compliance. It has its place and the checkboxes matter. But in more than twenty years doing this work, I have watched plenty of smart CIOs confuse a passing audit with a true measure of their actual risk.

    So maybe you are miffed. You poured real effort into marching toward CMMC and the finish line just moved. None of it is wasted. You already know 800-171 cold from chasing that certificate. Point that same momentum at the framework itself. Test the controls regularly and model the realistic threats that target your enterprise specifically. Do that and you come out of this pause more secure than the certificate would ever have made you. And if the DoW changes its mind and a new certificate requirement lands on you, you will already be ready for it.

    The bottom line

    The certificate is on hold. What you owe when you hold government data has not moved an inch. That standard of care hasn't changed at all. All the pause really did was pull out the independent outside check that would have validated your attested score. You still sign the attestation. Now no one checks that number but you. So be careful how you reach it. They suspended the certificate. Nobody suspended the standard of care.

    image (73)

    Sources

    • Department of War, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 13, 2026 (war.gov)
    • DoW CIO Memorandum 26-P-1023, "CMMC Reform," July 13, 2026
    • U.S. SBA, "SBA Commends U.S. Department of War's Suspension of CMMC Phase II," July 13, 2026 (cost figures, assessor capacity)
    • GAO-26-107955, "Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation," March 12, 2026
    • U.S. DOJ, "Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations," March 26, 2025
    • Crowell & Moring LLP, "Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review," July 2026 (crowell.com)
    • Federal News Network, DefenseScoop, Breaking Defense, National Defense Magazine, coverage of July 13, 2026
    • 32 CFR Part 170 (CMMC Program rule), Federal Register, October 15, 2024 (effective December 16, 2024)
    • DFARS 252.204-7021 (48 CFR CMMC acquisition rule), Federal Register, September 10, 2025 (effective November 10, 2025)
     
    Share
    Tags: Government Security Cyber Defense Compliance
    Denis Calderone
    Denis Calderone

    As CTO of Suzu Labs, Denis Calderone draws on over 30 years of IT experience and 25 years in information security. He founded and led a security consultancy for over 17 years before its global acquisition, and now channels that experience into Suzu Labs, where he sets technical direction while overseeing cyber delivery, including penetration testing and a full host of advisory services. His approach is vendor-agnostic and operationally grounded, cutting through noise to deliver practical, sustainable risk management. He pairs deep industry expertise with early AI adoption to ensure security is built-in, not bolted on.

    Stay ahead of the threat landscape

    AI security insights, threat intelligence, and research from our team. No spam, unsubscribe anytime.

    Subscribe
    ← Previous The Training Tax

    Latest Posts

    View All
    CMMC's Third-Party Assessments Are Paused. The Standard of Care Isn't
    Government Security
    Jul 20, 2026 Denis Calderone

    CMMC's Third-Party Assessments Are Paused. The Standard of Care Isn't

    On July 13 the Department of War suspended Phase 2 of CMMC, the third party certification requirement that was set to ...

    Read More: CMMC's Third-Party Assessments Are Paused. The Standard of Care Isn't
    The Training Tax
    AI Economics
    Jul 20, 2026 Jacob Krell

    The Training Tax

    At a Glance Training is a one-time bill. Inference compounds.GPT-4 cost over $100M to train. Serving GPT-4o at ...

    Read More: The Training Tax
    Top 7 AI Security Risks in 2026
    Cybersecurity
    Jul 10, 2026 Hannah Perez

    Top 7 AI Security Risks in 2026

    Quick guide: 7 AI security risks every CISO should know Data poisoning: Attackers corrupt training datasets to ...

    Read More: Top 7 AI Security Risks in 2026
    Enterprise AI Security Solutions for Mid-Sized Tech 2026
    AI Security
    Jul 08, 2026 Hannah Perez

    Enterprise AI Security Solutions for Mid-Sized Tech 2026

    Finding the Right AI Security Partner for Your Growing Tech Company Your engineering team just deployed a new ...

    Read More: Enterprise AI Security Solutions for Mid-Sized Tech 2026
    The AI Industry's Prescott Moment
    LLM
    Jun 30, 2026 Jacob Krell

    The AI Industry's Prescott Moment

    Intel killed its fastest chip in 2004 because clock speed had become the wrong metric. AI is approaching the same ...

    Read More: The AI Industry's Prescott Moment
    The Kylie Effect: How Meta Just Normed the Smart Glasses Privacy Dilemma
    Data Privacy
    Jun 30, 2026 Hannah Perez

    The Kylie Effect: How Meta Just Normed the Smart Glasses Privacy Dilemma

    When tech companies first tried to put cameras on our faces, the public reaction was loud, clear, and overwhelmingly ...

    Read More: The Kylie Effect: How Meta Just Normed the Smart Glasses Privacy Dilemma
    The Extortion Market Has Matured, And the Response Industry Is Part of It
    Threat Intelligence
    Jun 25, 2026 Denis Calderone

    The Extortion Market Has Matured, And the Response Industry Is Part of It

    In May, a criminal extortion group told 9,000 schools to hire breach coaches and negotiate ransom payments ...

    Read More: The Extortion Market Has Matured, And the Response Industry Is Part of It
    The ICS Exploit Pipeline Is Built for Destruction, Not Theft
    Vulnerability Management
    Jun 22, 2026 Jacob Krell

    The ICS Exploit Pipeline Is Built for Destruction, Not Theft

    The vulnerability pipeline feeding ICS attackers is structurally optimized for breaking infrastructure, not stealing ...

    Read More: The ICS Exploit Pipeline Is Built for Destruction, Not Theft
    973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
    Prompt Injection
    Jun 17, 2026 Jacob Krell

    973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security

    At a Glance AI security tooling adoption lags behind AI coding tool adoption by an order of magnitude. Download ratios: ...

    Read More: 973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
    The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
    AI Governance
    May 28, 2026 Jacob Krell

    The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It

    On May 20, 2026, Verizon published the 2026 Data Breach Investigations Report with a dedicated AI section built on ...

    Read More: The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
    The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
    Mean Time to Exploit
    May 21, 2026 Jacob Krell

    The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower

    On May 20, 2026, Verizon published the [2026 Data Breach Investigations ...

    Read More: The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
    The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code
    Cybersecurity
    May 20, 2026 Jacob Krell

    The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code

    GitHub's 3,800 Repositories Stolen Through a Single IDE Extension On May 19, 2026, a single VS Code extension on a ...

    Read More: The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code
    The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability
    May 20, 2026 Hannah Perez

    The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability

    If you think a basic pop-up banner that reads "By continuing to browse this site, you accept cookies" protects your ...

    Read More: The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability
    Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore
    Data Privacy
    May 19, 2026 Jacob Krell

    Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore

    In April 2026 alone, the ShinyHunters extortion group breached ADT (5.5 million customers), Amtrak (2.1 million ...

    Read More: Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore
    Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.
    Vulnerability Management
    May 05, 2026 Jacob Krell

    Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.

    Mandiant's M-Trends 2026 report puts estimated mean time to exploit at negative seven days. That number should reset ...

    Read More: Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.
    When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance
    Prompt Injection
    Apr 30, 2026 Hannah Perez

    When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance

    When AI Billing Breaks Trust: Lessons from the Claude Code Backlash AI adoption is accelerating, but trust is still ...

    Read More: When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance
    From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield
    Cybersecurity
    Apr 29, 2026 Suzu Labs

    From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield

    Cybersecurity doesn’t start with tools, it starts with mindset. In this episode featuring Aaron Colclough, we get a ...

    Read More: From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield
    When Elite Cyber Teams Can't Crack Web Security
    Cybersecurity
    Apr 23, 2026 Jacob Krell

    When Elite Cyber Teams Can't Crack Web Security

    HTB's 2025 benchmark tested 796 security teams. Only 21% passed web security challenges. The Security Illusion Security ...

    Read More: When Elite Cyber Teams Can't Crack Web Security
    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Cybersecurity
    Apr 22, 2026 Jacob Krell

    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them

    In today's security landscape, some of the most dangerous vulnerabilities aren't flagged by automated scanners at all. ...

    Read More: The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Suzu Labs Acquires Emulated Criminals
    Apr 20, 2026 Hannah Perez

    Suzu Labs Acquires Emulated Criminals

    Bridging the gap between theory and the threat reality, Suzu Labs is proud to announce the acquisition of Emulated ...

    Read More: Suzu Labs Acquires Emulated Criminals
    The Wall Around Claude 4.7 Does Not Extend to Dread
    Cybersecurity
    Apr 17, 2026 Suzu Labs

    The Wall Around Claude 4.7 Does Not Extend to Dread

    Anthropic released Claude Opus 4.7 on April 16, 2026 with automated cybersecurity safeguards and a Cyber Verification ...

    Read More: The Wall Around Claude 4.7 Does Not Extend to Dread
    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    youtube
    Apr 10, 2026 Jacob Krell

    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control

    Earlier this year, YouTube began rolling out a row of algorithmically recommended videos at the top of the ...

    Read More: The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    The AI Revolution: How Jobs Will Change by 2030
    Cybersecurity
    Apr 07, 2026 Suzu Labs

    The AI Revolution: How Jobs Will Change by 2030

    Host Phillip Wylie sits down with Nicolas Chaillan to discuss the sobering reality of AI replacement, the critical need ...

    Read More: The AI Revolution: How Jobs Will Change by 2030
    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    Generative AI
    Apr 01, 2026 Hannah Perez

    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?

    In late 2024, Sydney tech entrepreneur Paul Conyngham was told his rescue dog, Rosie, had months to live. She was ...

    Read More: The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    Cybersecurity
    Mar 30, 2026 Suzu Labs

    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone

    The world of cybersecurity has undergone a massive transformation in just a few decades. In this episode of Simply ...

    Read More: From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    While TSA Made Headlines, CISA Went Dark
    Critical Infrastructure
    Mar 30, 2026 Jacob Krell

    While TSA Made Headlines, CISA Went Dark

    The Department of Homeland Security has been partially shut down for over 45 days. In that time, 460 TSA officers have ...

    Read More: While TSA Made Headlines, CISA Went Dark
    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    AI Security
    Mar 30, 2026 Suzu Labs

    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks

    In cybersecurity, we often operate in silos. The red team breaks things, the blue team fixes them, and management ...

    Read More: The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    Claude Mythos and the Cybersecurity Risk That Was Already Here
    Threat Intelligence
    Mar 27, 2026 Jacob Krell

    Claude Mythos and the Cybersecurity Risk That Was Already Here

    On March 26, Anthropic confirmed the existence of Claude Mythos, an unreleased AI model described internally as "a step ...

    Read More: Claude Mythos and the Cybersecurity Risk That Was Already Here
    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Critical Infrastructure
    Mar 26, 2026 Mike Bell

    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It

    Rapid7's research reveals China-linked kernel implants deep inside telecom signaling infrastructure. Here's what ...

    Read More: BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    Cybersecurity
    Mar 23, 2026 Hannah Perez

    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026

    We are incredibly proud to announce a monumental achievement. At this year’s Global InfoSec Awards 2026, hosted by ...

    Read More: Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Cybersecurity
    Mar 17, 2026 Suzu Labs

    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity

    In the world of cybersecurity, we often talk about "gatekeeping" or the "skills gap," but rarely do we find individuals ...

    Read More: From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    Cybersecurity
    Mar 16, 2026 Phillip Wylie

    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss

    The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss In this episode of Simply Offensive, ...

    Read More: Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Critical Infrastructure
    Mar 13, 2026 Denis Calderone

    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time

    On March 12, medical technology giant Stryker confirmed a cyberattack that wiped devices across 79 countries. The ...

    Read More: From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    Social Engineering
    Mar 09, 2026 Suzu Labs Intelligence

    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation

    Executive Summary Even Realities markets its G2 smart glasses as the privacy-conscious alternative to Meta Ray-Bans. ...

    Read More: Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    Threat Intelligence
    Mar 06, 2026 Mike Bell

    The Company Reviewing Your Meta Glasses Footage Has a Security Problem

    Last week, Swedish journalists revealed that Meta sends video footage from Meta Ray-Ban smart glasses to human data ...

    Read More: The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    CTF
    Mar 03, 2026 Jacob Krell

    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

    View White Paper Abstract: Agentic AI systems are compressing competitive hacking timelines faster than the ...

    Read More: The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Cybersecurity
    Mar 03, 2026 Phillip Wylie

    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell

    In this thought-provoking episode of Simply Offensive, host Philip Wylie sits down with Jacob Krell, a penetration ...

    Read More: Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Anthropic and Claude: 2026 AI Powerhouse
    Supply Chain Security
    Feb 26, 2026 Hannah Perez

    Anthropic and Claude: 2026 AI Powerhouse

    In early 2026, the image of Anthropic as a cautious, safety-oriented "research lab" has effectively been replaced by ...

    Read More: Anthropic and Claude: 2026 AI Powerhouse
    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Cybersecurity
    Feb 24, 2026 Phillip Wylie

    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle

    In this episode of Simply Offensive, host Philip Wylie welcomes Darius Houle, an Application Security (AppSec) and ...

    Read More: Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Cybersecurity
    Feb 17, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown

    In the latest episode of the Simply Offensive podcast, host Philip Wylie sat down with Matt Brown, a renowned hardware ...

    Read More: Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Cybersecurity
    Feb 12, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs

    In today’s rapidly evolving technological landscape, the convergence of artificial intelligence (AI) and cybersecurity ...

    Read More: Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Threat Intelligence
    Feb 10, 2026 Phillip Wylie

    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss

    Beyond the Pentest: Why Adversarial Emulation is the Future of Defensive Training Many organizations operate under the ...

    Read More: Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Under Armour Breach: What The Forum Data Actually Shows
    Threat Intelligence
    Jan 30, 2026 Mike Bell

    Under Armour Breach: What The Forum Data Actually Shows

    On January 18, 2026, the Everest ransomware group made good on their threat and released Under Armour customer data to ...

    Read More: Under Armour Breach: What The Forum Data Actually Shows
    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Briefing Room
    Jan 29, 2026 Dahvid Schloss

    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers

    This article is in reference to our newest POC hosted on GitHub here: https://github.com/Emulated-Criminals/SilentFrame ...

    Read More: SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Brightspeed Breach: Crimson Collective and the Infostealer Problem
    Threat Intelligence
    Jan 20, 2026 Mike Bell

    Brightspeed Breach: Crimson Collective and the Infostealer Problem

    Recently Crimson Collective claimed they breached Brightspeed and grabbed 1 million+ customer records. The list of data ...

    Read More: Brightspeed Breach: Crimson Collective and the Infostealer Problem
    When Grid Data Goes Dark Web
    Power Grid
    Jan 19, 2026 Mike Bell

    When Grid Data Goes Dark Web

    Inside a threat actor's critical infrastructure targeting In January 2026, 139 gigabytes of engineering data from a ...

    Read More: When Grid Data Goes Dark Web
    The $150,000 Password
    Critical Infrastructure
    Jan 19, 2026 Mike Bell

    The $150,000 Password

    How one threat actor turned stolen credentials into a global breach portfolio Between December 2025 and January 2026, a ...

    Read More: The $150,000 Password
    Seeing Everything, Understanding Nothing
    Briefing Room
    Jan 16, 2026 Dahvid Schloss

    Seeing Everything, Understanding Nothing

    To help you get a head start on making your environment safer and in keeping with the theme of January’s “New Year, New ...

    Read More: Seeing Everything, Understanding Nothing
    New Year, New Priorities - So, what to fix first?
    Briefing Room
    Jan 08, 2026 Dahvid Schloss

    New Year, New Priorities - So, what to fix first?

    The most common phrase we hear from our prospects is, “We are overwhelmed, and we aren’t sure what to tackle first.” ...

    Read More: New Year, New Priorities - So, what to fix first?
    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Briefing Room
    Nov 21, 2025 Dahvid Schloss

    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)

    Repository purpose: this research was to evaluate the feasiabilty of using Alternate Data Stream (ADS) in staging and ...

    Read More: UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Logo copy 3-1

    Fortified Security. Intelligent Innovation.

    +1 (702) 766-6257
    P.O. Box 750111
    Las Vegas, Nevada 89136

    Follow Us

    About

    • About Us
    • Contact
    • FAQ's

    Solutions

    • AI Advisory
    • AI Assessment
    • Offensive Security
    • Defensive Security
    • Privacy Engineering
    • Adversarial Operations
    • Social Engineering
    • Products

    Resources

    • Blog
    • In The Media
    • Podcasts
    © 2026 All rights reserved.
    • Privacy Policy
    • Terms & Conditions