- July 2025 -

Facebook  Linkedin  X

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

CMMC – current projections


CMMC continues in the rule making process and until this phase is completed, current cybersecurity requirements remain in effect. Those requirements include, creation of a System Security Plan (SSP), assessment of the SSP against DoD’s Self-assessment tool, determine the score and post the score and related information to the SPRS database as required by DFARS 252.204-7020. *Note: Active SAM registration is required to access the SPRS database. DFARS 252.204-7012 includes additional compliance requirements including the requirement to flowdown DFARS 252.204-7012.


It is currently believed that all regulatory requirements will be completed in Calendar year 2025 and after that, CMMC requirement will begin to be included in solicitations/contracts.


Members of the DIB should have a sense whether they will be required to certify in accordance with CMMC L1 or L2. Companies that have questions concerning the levels are invited to call WPI at 414-270-3600 and speak to Matt Frost.


Companies that have a feel as to whether they will be required to certify as CMMC L1 or L2 should visit https://dodcio.defense.gov/CMMC/Documentation/ and download the appropriate Scoping Document and Assessment Guide.


The official site to contact businesses certified to complete the required assessments is https://cyberab.org

Arrington Urges Bold Action on Cybersecurity During Chapter Luncheon

 

The defense industrial base, she stressed, is not just a vendor network but an essential extension of the warfighter's arsenal. Ethical and resilient supply chains, streamlined bureaucracy and a laser focus on mission impact over administrative hurdles are central to the DOD's transformation efforts. Arrington closed with a powerful reminder: "We don't fight wars alone-we fight them with you."


Arrington outlined several critical priorities shaping the DOD's future technology posture. She emphasized that zero trust is mandatory, not optional, with full compliance expected by 2027. Cybersecurity Maturity Model Certification (CMMC) must be embraced as a cultural shift, not just a compliance checklist. Legacy processes like Risk Management Framework and traditional authority to operate are being replaced by real-time monitoring platforms like EMAS, powered by AI tools. New initiatives such as SWIFT (Software Fast Track) are cutting acquisition timelines, while an urgent call for data standardization-across cloud, identity management and applications-underscored the need to turn raw information into actionable advantage.

https://www.afcea.org/signal/chapternews/index.cfm

Caveat Emptor – “of where they get their third party audits”


“In a separate interview, Stacy Bostjanick, the chief of defense industrial base cybersecurity in the DoD’s office of the chief information officer, told Breaking Defense that companies, especially smaller ones, need to be wary of where they get their third party audits to become level three CMMC certified.


“I highly recommend that anybody who is looking to become certified reach out to the different cloud service providers and MSPs [managed service providers] out there. You need to shop. You need to know what you’re shopping for and understand the Cyber AB [accreditation body] has a marketplace that they’re gonna put those capabilities out there so companies can discover them,” she said.


Broadly, she cautioned companies to “do your homework, because we have unfortunately been made aware of some snake oil salesman out there, some slimy characters that’ll come in and say, ‘Yeah, give me $100,000 I’ll get you CMMC certified in two days,’ and they’re not telling them the right stuff. Make sure you are buyer beware.”


Copied from: Downloaded Breaking Defense e-book: Defense Cybersecurity in Focus

Access Control is one of NIST 800-171 r2’s 14 Cybersecurity Family Topics.


The first requirement of this family goes to the heart of this article. Requirement 3.1.1 requires organizations to Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).


The following article addresses issues related to identify proofing. It also provides a link to a recent study. The study shows that identity fraud is not limited to one point in the customer’s journey. The study also states that Identify Fraud occurs the most when a user name and password are the sole means of authentication.


Smaller companies often balk at the need to address Access Control. They see their size as a protective measure.


Identity & Access


Identity Is the New Perimeter: Why Proofing and Verification Are Business Imperatives


The future of secure digital engagement depends on continuous identity verification and proofing that can scale with risk.


“Digital transformation has unlocked new opportunities – not just for innovation and growth, but also for cybercriminals seeking to exploit personal and sensitive information. According to the Future of Global Identity Verification report (PDF), more than two-thirds (69%) of organizations have experienced an increase in fraud attempts. …”


Read more: https://www.securityweek.com/identity-is-the-new-perimeter-why-proofing-and-verification-are-business-imperatives/


For the report see: https://img.en25.com/Web/DocuSign/%7B8c8f1acb-0f78-497c-9747-67a0b7261d17%7D_The_Future_of_Global_Identity_Verification.pdf

The Call from the FBI is likely a fake!


A phone call from someone claiming to be the FBI might sound scary, but it’s often a scam. These criminals spoof phone numbers to make it look like the call is real. They sound official, use real-sounding names, and might say you’re in trouble unless you act fast.


Their goal is to panic you into sending money or sharing personal info. The FBI does not make threats over the phone. If a call feels wrong, hang up immediately and stay calm.

Important note: Microsoft Products near end of life/support


In mid-October 2025, several Microsoft products will reach their end of life/support. Companies that haven’t transitioned to another product should consider beginning this process. As companies decide to remain with a non-supported product, a key question to consider is the vulnerability to cyber attacks and is the company prepared to deal with those issues.


Both Office 2016 and 2019 are nearing the end of their lives in October 2025.


Also, Microsoft will cease supporting Windows 10 on October 14, 2025.

https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281


https://support.microsoft.com/en-us/office/end-of-support-for-office-2016-and-office-2019-818c68bc-d5e5-47e5-b52f-ddf636cf8e16


https://www.csoonline.com/article/4016345/end-of-life-for-microsoft-office-puts-malicious-macros-in-the-security-spotlight.html

Microsoft makes Windows 10 extended security updates free, but there’s a catch


Microsoft revealed last year that it will charge consumers $30 for a year of extra security updates to Windows 10. Now, it’s allowing consumers to enroll into its Extended Security Updates (ESU) free of charge ahead of the Windows 10 end of support on October 14th. But there’s a catch.


https://www.msn.com/en-us/money/other/microsoft-makes-windows-10-extended-security-updates-free-but-there-s-a-catch/ar-AA1Hl4nY

Microsoft to Preview New Windows Endpoint Security Platform After CrowdStrike Outage 


Microsoft is preparing a private preview of new Windows endpoint security platform capabilities to help antimalware vendors create solutions that run outside the kernel.

 

Microsoft on Thursday shared an update on the progress of its resiliency initiative, triggered by the highly disruptive CrowdStrike incident that occurred last year.

 

In July 2024, organizations around the world suffered significant service outages after many of their Windows computers that had been running security software from CrowdStrike crashed. 

 

https://www.securityweek.com/microsoft-to-preview-new-windows-endpoint-security-platform-after-crowdstrike-outage/

Do you have a Plan B?


Cellcom cyber incident should be wakeup call for other companies, expert says


“(WLUK) -- Cellcom continues to work to fully restore its services following a recent cyber incident that has impacted customers' ability to make phone calls and send text messages.

The incident occurred earlier this summer. Both phone service and text messaging and other services were affected.


https://fox11online.com/news/local/cellcom-cyber-incident-should-be-wakeup-call-for-other-companies-expert-says

The most effective phishing QR code is a new drug and alcohol policy supposedly from HR


Phishing emails presumably from IT or HR remain the most potent, with Zoom clips from managers, HR training info, and email server warnings luring in employees.


Phishing emails that appear to be internal and come from the IT or HR department are the emails that trick the most users, according to KnowBe4’s Q1 2025 Phishing Report.


https://www.csoonline.com/article/3986048/emails-from-it-or-hr-falling-into-the-phishing-trap.html

The 8 security metrics that matter most


“When it comes to assessing cybersecurity performance, the truth can be found in the numbers. Here are the essential KPIs to measure, monitor, and improve to ensure highly effective cyber operations.


KPIs and metrics are indispensable for evaluating the effectiveness of enterprise cyber defenses. These crucial tools open insights into system vulnerabilities, threat patterns, and incident response efficiency. In a time of growing digital reliance, KPIs and metrics play an vital role in security decision-making, ensuring enterprise preparedness against ever-evolving cyber threats.”


https://www.csoonline.com/article/3979024/the-8-security-metrics-that-matter-most.html


The metrics discussed in this article may not be a good fit for your business. Nevertheless, the idea has merit. The question – how do we know that the cybersecurity measures we have in place are functioning as intended? What metric(s) can be used to identify issues and trigger the necessary response.

Man Who Hacked Organizations to Advertise Security Services Pleads Guilty


Nicholas Michael Kloster has pleaded guilty to computer hacking after targeting at least two organizations.

 

A Kansas City man who hacked into the systems of multiple organizations in an effort to advertise his cybersecurity services has pleaded guilty, authorities announced on Wednesday.


Nicholas Michael Kloster, 32, was charged last year with accessing a protected computer and obtaining information, and reckless damage to a protected computer during unauthorized access.


https://www.securityweek.com/man-who-hacked-organizations-to-advertise-security-services-pleads-guilty/

North Korean hackers are luring employees at web3 and crypto-related organizations into installing Nim-compiled macOS malware via fake Zoom software updates, SentinelOne reports.

 

The observed attacks follow an infection chain recently attributed to Pyongyang APT BlueNoroff: hackers impersonate a victim’s trusted contact to invite them over Telegram to schedule a meeting via the popular Calendly scheduling platform.


The victim then receives an email containing a link to a Zoom meeting, and is instructed to run a malicious script posing as a Zoom SDK update. The script’s execution triggers a multi-stage infection chain leading to the deployment of malicious binaries that SentinelOne collectively tracks as NimDoor

 

https://www.securityweek.com/north-korean-hackers-use-fake-zoom-updates-to-install-macos-malware/


Wait! Don’t click, Pause – verify. Threats and attacks are designed to fall beneath a normal level of scrutiny. Be watchful for something that may seem like “Oh, this is routine.” Installing an update to Zoom, what could be more routine?

The Silent Epidemic: Infostealers and the Evolution of Cybercrime in 2025


"Infostealers" have transformed from niche threats into the backbone of modern cybercrime, fueling a $4.88 million average breach cost in 2024. In this article we synthesize the latest threat intelligence to expose critical inaccuracies in mainstream cybersecurity narratives and provide evidence-based defenses against these stealthy data predators


The New Anatomy of Infostealers


Infostealers are advanced malware engineered to covertly harvest credentials, financial data, and session cookies. Unlike traditional malware, they prioritize stealth over disruption, operating undetected for months. Modern variants like Lumma Stealer exemplify this evolution — written in C++/ASM with LLVM obfuscation, they evade decompilers and execute via syscalls to bypass security hooks.


The Silent Epidemic: Infostealers and the Evolution of Cybercrime in 2025 - Lexology

AI Cybersecurity: A Playbook For Value-Driven Cyber Defense


AI won’t erase cyber risk, but when precisely applied, it can tilt the odds toward defenders. Executives need to be prepared for both AI-powered defenses and AI-driven threats.”


Read more: https://www.forbes.com/councils/forbesbusinesscouncil/2025/07/14/ai-cybersecurity-a-playbook-for-value-driven-cyber-defense/

If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

OTHER NEWS

Announcing New Sessions

Previously Cyber Fridays, Now Thursdays


If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements. 





Registration and more information can be found at wispro.org/wpi-events/featured-webinars

  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe