September 2025

Facebook  Linkedin  X

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

CMMC Phase I to start November 10, 2025


The department is planning to implement the program’s three-tier model in four phases over the course of the next three years. In phase 1, which will begin Nov. 10, solicitations will require CMMC Level 1 or Level 2 self-assessments where applicable, with CMMC Level 2 third-party assessments required where applicable 12 months later and Level 3 assessments performed by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center required where applicable 12 months after that.

Full implementation — when all solicitations and contracts will include applicable CMMC level requirements as a condition of contract award — is set to be reached on Nov. 10, 2028.


See: https://www.nationaldefensemagazine.org/articles/2025/9/9/cmmc-phase-1-to-begin-nov-10

DIB in a Cyber Crunch


The Pentagon’s new cybersecurity mandate is coming in hot – and nearly half the defense industry is playing catch-up. A Kiteworks survey found that many contractors are unprepared for the Department of Defense’s (DOD) Cybersecurity Maturity Model Certification (CMMC), set to begin its phased rollout on Nov. 10. Of 461 surveyed organizations, 44% lack full encryption, 65% still rely on manual compliance processes, and only 17% have AI governance in place – raising serious concerns as AI adoption surges.


With thousands of businesses affected and the clock ticking, failure to meet standards could mean losing out on future defense contracts. Read the full report here.


https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-over-half-dod-cmmc-suppliers-fail-governance.pdf


For assistance with cybersecurity and preparations for CMMC, reach out to Matt Frost, Government Contract Specialist at mattf@wispro.org

FBI warns of 3-phase scam that is draining bank accounts


(NEXSTAR) – A multi-phase scam credited with emptying the financial accounts of numerous Americans – many of whom were nearing the age of retirement – is again making headlines after the FBI recently issued a warning.


Unlike many scams, “Phantom Hacker” attacks often come in three distinct phases, each building on the last to thoroughly convince the victim to allow access to their funds.


https://www.msn.com/en-us/money/personalfinance/fbi-warns-of-3-phase-scam-that-is-draining-bank-accounts/ar-AA1LA2tZ

FBI Warning—Do Not Use These Websites On Your Phone Or PC


The FBI has issued multiple warnings over the last year, as fake websites steal millions of dollars from citizens. These have included holiday discount websites, charity websites after emergencies and disasters, even fake document converters. But the FBI’s latest warning is a surprise. No one is safe from attack — not even the bureau itself.


“Threat actors are spoofing the FBI Internet Crime Complaint Center (IC3) government website,” the bureau warned on September 19. The www.ic3.gov website is included in all the bureau’s warnings as attacks and scams surge across the U.S. It’s a reporting and information tool. But now it’s being faked for “possible malicious activity.”


https://www.forbes.com/sites/zakdoffman/2025/09/23/fbi-warning-do-not-use-these-websites-on-your-phone-or-pc/

The End is Near. Are you ready?


That’s right, Microsoft’s support for Windows 10 will be ending next month. Upgrading to a new software version can be a hassle. It takes time to learn new features and even how to do the most basic of tasks.

We agree, switching (converting) can be a hassle.


Here is what is a bigger hassle – being affected by a security gap and being impacted by a cyber intrusion.


When Microsoft ceases support for Windows 10, that equates to support for security and system updates. Not every update is an entry point for a cyber attack although some may be.


Also, if the choice is made to remain with Windows 10 and you are a member of the DIB, remember to update your System Security Plan to reflect this decision. Additionally, the plan should probably discuss, alternative measures which will be taken to provide the necessary security.

Zero Trust – a new security paradigm worth learning about


“For decades, security was built on the premise of implicit trust within the network perimeter. The zero trust model demands a complete reversal of this thinking,” Deo notes. “Shifting an entire organization to a ‘never trust, always verify’ culture is a significant and difficult change.”


https://www.csoonline.com/article/4048002/88-of-cisos-struggle-to-implement-zero-trust.html


For more information on Zero Trust, reach out to Matt Frost, Government Contract Specialist at mattf@wispro.org

Chinese Spies Impersonated US Lawmaker to Deliver Malware to Trade Groups: Report 


China’s APT41 sent out malicious emails on behalf of Rep. John Moolenaar to collect information ahead of US-China trade talks.


The email was from a non-government domain. There were attachments and the attachments contained malware (spyware).


Chinese Spies Impersonated US Lawmaker to Deliver Malware to Trade Groups: Report - SecurityWeek


Remember – review and follow your organization’s protocols for processing email and opening either links or attachments.


Beyond potentially being a costly inconvenience, DFARS 252.204-7012 paragraphs (c) and (d) require specific actions including reporting a cyber incident and submitting the malicious software to DoD Cyber Crime Center (DC3).

Updates can be a hassle – Don’t ignore them


**This applies to all updates not just updates for Chrome.

Google on Tuesday released Chrome 140 to the stable channel with patches for six vulnerabilities, including a four reported by external researchers.


The most severe of the bugs is CVE-2025-9864, a high-severity use-after-free issue in the V8 JavaScript engine that was reported by the Yandex Security Team.


The latest Chrome iteration is now rolling out as versions 140.0.7339.80/81 for Windows and macOS, and as version 140.0.7339.80 for Linux. The extended stable channel has been updated to Chrome 140.0.7339.81 for both Windows and macOS.


For Windows users check your version of Chrome by opening Chrome. Click on the three dots. Scroll down, click on Help and click on About Google Chrome. The version being used will be shown along with instructions for any suggested actions.

Apple Warns All iPhone Users—Do Not Use Google Chrome


Apple’s warning is clear — stop using Google Chrome. The world’s most popular browser is as dominant on mobiles as it is PCs. And right now it’s surging, stealing market share from Apple. But Apple is fighting back.


“Switch to a browser that protects your privacy," Apple says. “Safari includes state-of-the-art features that defend you against cross-site tracking, hides your IP address from known trackers, and more. Unlike Chrome, Safari truly helps protect your privacy.”


https://www.forbes.com/sites/zakdoffman/2025/09/22/apple-warns-all-iphone-users-do-not-use-google-chrome/

Automotive Titan Stellantis Discloses Data Breach


The company says customer contact information was stolen from a third-party service provider’s platform.

 

“The big concern here is that the trust we hand off between SaaS platforms, identity providers, and even security tools has become the real attack surface. Defending against that means testing how that trust could be abused and cutting off the paths before attackers get there,” Sharma added.


https://www.securityweek.com/automotive-titan-stellantis-discloses-data-breach/

5 questions CISOs should ask vendors


Persistent, persuasive, and sometimes misleading, vendor pitches are a constant in a CISO’s inbox. To separate value from noise, security leaders rely on key questions that test whether a product solves real problems.


https://www.csoonline.com/article/4059801/5-questions-cisos-should-ask-vendors.html

CISA Kicks Off Cyber Awareness Month


For some people, October means bringing out the Halloween decorations and going pumpkin picking. For those in the federal IT community, it also marks the start of Cybersecurity Awareness Month. The Department of Homeland Security (DHS) and its Cybersecurity and Infrastructure Security Agency (CISA) component today announced the official beginning of Cybersecurity Awareness Month 2025. CISA will run the national campaign throughout October, arming partner agencies and small and medium businesses with tools and resources to harden networks. This year’s theme – Building a Cyber Strong America – puts critical infrastructure front and center, with a push for cyber basics: turning on multi-factor authentication, updating software, requiring strong passwords, and reporting phishing. Acting CISA Director Madhu Gottumukkala stressed that critical infrastructure “is the backbone of our daily lives,” and urged partners – especially SLTT governments – to “make resilience routine” so America stays secure.

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

OTHER NEWS

Announcing New Sessions

Previously Cyber Fridays, Now Thursdays


If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements. 





Registration and more information can be found at wispro.org/wpi-events/featured-webinars

  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe