Facebook  Linkedin  X

June 2026

NEWS & UPDATES

Welcome to the WPI Cyber Newsletter, a monthly publication from the Wisconsin Procurement Institute (WPI), Wisconsin's Apex Accelerator


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

NEWS & UPDATES

Defense Contractors Face Expansion of National Security Disclosure and Mitigation Requirements to Unclassified Contracts


Highlights

  • Proposed rule published 7 May 2026 with responses due 6 July 2026
  • Applicable to contracts greater than $5 million, OTSB, and SB
  • Applicable to subcontractors at any tier when the value of the subcontract exceeds $5 million US.
  • Commercial exemption is narrow
  • Award requires completion of Standard Form (SF) 328, Certificate Pertaining to Foreign Interests, along with supporting documentation and contact information for each beneficial owner
  • Contracting Officers must validate “Eligible” NISS status
  • Requirements apply to all awards initial and others
  • Submission of an offer constitutes a representation that the information is current, accurate, and complete.


https://www.jdsupra.com/legalnews/defense-contractors-face-expansion-of-6905161/

View the full text and submit comments through the Federal Register DFARS Case 2021-D011 portal.

 

Trump Signs National Security Memorandum to Strengthen Cybersecurity of Military and Intelligence Systems


President Donald Trump has signed a new National Security Presidential Memorandum aimed at strengthening the cybersecurity of the federal government’s most sensitive military and intelligence networks and modernizing how those systems are governed across agencies.


The June 12 memorandum (NSPM-12) focuses on National Security Systems (NSS), which include computer networks that process classified information or directly support military, intelligence, and national security missions. According to the White House, the directive is intended to address evolving cyber threats and establish a more unified approach to protecting critical government systems.


Read more



Pentagon builds cyberdefence for critical infrastructure


The Pentagon is preparing a new framework to defend U.S. critical infrastructure against cyberattacks. This is no longer only about protecting military networks, but about keeping the state functioning during a major cyber crisis.


https://defence24.com/defence-policy/pentagon-builds-cyberdefence-for-critical-infrastructure

 

Cyber Security Evaluation Tool (CSET®)


The Cyber Security Evaluation Tool (CSET®) provides a systematic, disciplined, and repeatable approach for evaluating an organization’s security posture. CSET is a desktop software tool that guides asset owners and operators through a step-by-step process to evaluate industrial control system (ICS) and information technology (IT) network security practices. Users can evaluate their own cybersecurity stance using many recognized government and industry standards and recommendations.


For information on downloading and installing this software see:

Downloading and Installing CSET® | CISA


Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here’s What Cyber Criminals Are Actually Doing


Every summer, hundreds of millions of people book flights, reserve hotels, and plan vacations online. And every summer, cyber criminals show up to take advantage of exactly that. Check Point Research tracked the threat landscape heading into the 2026 summer travel season, and what they found should give travelers pause before they click “confirm booking.”


The hospitality sector is under targeted attack


The hospitality, travel, and recreation sector recorded 2,291 average weekly cyberattacks per organization in May 2026, a 24% increase compared to the same month last year.


https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-are-surging-in-2026-growing-122-over-the-last-3-years-heres-what-cyber-criminals-are-actually-doing/

 

Cyberattackers are walking into physical facilities: FBI


One group is sending people posing as contractors or IT support to gain access to servers, steal files and demand ransom — sometimes within an hour, FBI and Google reports show.


https://www.facilitiesdive.com/news/cyber-attackers-are-walking-into-physical-facilities-fbi/822497/

 

‘Harvest now, decipher later’: The quantum threat few are preparing for


Most orgs recognize quantum’s looming threat to encryption but just 1 in 20 have a strategy in place.


Here’s how firms from the cybersecurity and financial sectors are addressing the risk.

Quantum technology may feel far off but certain risks are already with us in the form of “harvest now, decrypt later” — an attack vector in which malicious actors steal data now for a future in which they have access to quantum computational tools capable of breaking encryption deployed by most companies today to protect their data.


Read more: https://www.csoonline.com/article/4180902/reap-now-decipher-later-thats-the-approach-to-cybersecurity-in-the-quantum-age.html

 

Hidden beneath AI chips, Chinese-made circuit boards raise national security concerns in U.S.


Printed circuit boards sit underneath almost every chip, a necessity in nearly every electronic. They make up a quiet but crucial piece of the booming artificial intelligence market, and represent a growing problem for the U.S., because nearly all AI circuit boards, for Nvidia and others, are made in China.


Circuit boards present all sorts of opportunities for adversaries to sneak through malicious components. That vulnerability has created national security concerns so significant that the U.S. Defense Department is requiring most of its purchases to come from the dwindling number of domestic factories.


See: https://www.cnbc.com/2026/06/03/beneath-nvidia-ai-chips-chinese-pcbs-raise-security-concerns-in-us.html

 

Cyber insurance policyholders facing heavier scrutiny in underwriting, claims


Cyberinsurance Concerns – there are many to consider. The following are some of the topics covered in the following article.


The impact of a supply chain attacks, the need for governance, security controls and mitigations in place, the small percentage of small and medium companies with cyber insurance and “how insured companies must manage the incident response process. “


Cyber insurance companies may not be viewed as a sound source of cyber information. However, these companies must understand and model cyber-risk to survive. As such, their ideas also have merit. For companies seeking Cyber Insurance, the requirements of these companies will be just that – requirements.


https://www.cybersecuritydive.com/news/cyber-insurance-policyholders-facing-heavier-scrutiny-underwriting-claims/822089/

 

Russia's Military Hackers Targeted Home Routers Across 23 States. Here's What to Do


Federal agencies disrupted the attack but were direct about what comes next. These five router security steps are the responsibility of individual owners.


For years, a unit of Russia's military intelligence agency quietly turned ordinary home routers into tools of espionage. The GRU group known as APT28, the same outfit behind the 2016 DNC hack and a string of attacks on NATO targets, exploited unpatched firmware and unchanged default passwords to compromise thousands of devices across 23 US states, redirecting internet traffic through servers under Russian control and harvesting credentials along the way. Federal agents disrupted the operation in April under a court order. What they couldn't do from a distance was fix the underlying vulnerabilities. That requires five steps from you.


https://www.cnet.com/home/internet/russias-military-hackers-targeted-home-routers-across-23-states-heres-what-to-do

 

Justice Department, FBI Disable 13 Websites Backed by Suspected Chinese Agents That Sought Sensitive U.S. Information from Security Clearance Holders


Thirteen internet domains used to target U.S. persons, including current and former security clearance holders with access to classified and sensitive U.S. government information, were seized today by federal authorities.


“These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty bound to protect,” said Assistant Attorney General for National Security John A. Eisenberg. “Anyone approached online with offers of easy income for vague ‘consulting’ work should treat those overtures with extreme caution and remain vigilant for warning signs of malicious targeting.”


Full press release: https://www.justice.gov/opa/pr/justice-department-fbi-disable-13-websites-backed-suspected-chinese-agents-sought-sensitive

 

Lessons for Businesses Using Cookies, Pixels, and Consent Banners

 

A recent federal court decision offers important lessons for businesses that use cookies, pixels, and other tracking technologies on consumer-facing websites. Although the court dismissed one federal wiretap claim with leave to amend, it allowed other privacy claims to proceed, including claims under California’s pen register statute and common law intrusion upon seclusion.


https://natlawreview.com/article/lessons-businesses-using-cookies-pixels-and-consent-banners

 

For the 2nd time in weeks, Microsoft packages laced with credential stealer


Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents. Packages run self-replicating stealer as soon as they’re opened by an AI agent.


In all, multiple researchers said, 73 packages were flagged as malicious when automated systems on GitHub blocked them on the platform.


The incident is the second supply-chain attack in as many months to breach an official Microsoft repository account.


See the following article for full details:

https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/

 

AI – Friend or Foe: It depends.

GenAI: The Risk That Grows With Every New Tool Adopted


Enterprise GenAI adoption showed no signs of slowing in May, and neither did the exposure risks that come with it.


  • 1 in every 25 GenAI prompts from enterprise networks carried a high risk of sensitive data leakage
  • 91% of organizations using GenAI tools regularly were touched by this risk
  • A further 22% of prompts contained potentially sensitive information
  • Organizations ran an average of 9 different GenAI tools during the month
  • The average enterprise user sent 70 GenAI prompts per month


Every new tool adopted without a governance framework in place is another surface where credentials, intellectual property, and internal data can slip out quietly. The exposure does not announce itself.


https://blog.checkpoint.com/research/global-cyber-attacks-ease-in-may-2026-but-ransomware-surges-48-as-threats-reorganize/

 

When “We Take Security Seriously” Isn’t Enough: Lessons from the FTC’s Illuminate Order

 

On June 5, 2026, the Federal Trade Commission gave final approval to a modified order against Illuminate Education Inc., closing out an enforcement action that should command the attention of any executive whose company collects, stores, or processes sensitive consumer data. The case is a clean illustration of how the gap between a company’s privacy promises and its actual security practices can translate into binding federal obligations.

https://natlawreview.com/article/when-we-take-security-seriously-isnt-enough-lessons-ftcs-illuminate-order

 

Tests suggest Russian satellites can jam GPS on a continental scale

 

Russian satellites have been identified as the cause of mysterious, seconds-long bursts of GPS interference across Europe—a rare example of human-made GPS interference coming from space. But uncertainty still hangs over whether such interference is intentional and if it could be more powerfully weaponized as GPS jamming with continental reach in the future.

 

The discovery came from an investigation detailed in a June 2 preprint paper by Todd Humphreys and his student Zach Clements at The University of Texas at Austin, along with Argyris Kriezis at Stanford University in California. By sifting through public data from ground-based stations with global navigation satellite system (GNSS) receivers, they identified a pattern of high-powered interference lasting less than 10 seconds each time but simultaneously detectable by ground stations across Europe from Norway to Spain to Poland, and even reaching as far west as Greenland and Canada.

 

https://arstechnica.com/space/2026/06/tests-suggest-russian-satellites-can-jam-gps-on-a-continental-scale/


If your organization needs assistance meeting Federal or Department of Defense cyber security requirements, contact Marc Violante, Director of Federal Market Strategies at marcv@wispro.org, or Matt Frost, Government Contract Specialist at mattf@wispro.org

OTHER NEWS

If you are currently, or are planning to be, a contractor or subcontractor supporting the Defense Industrial Base (DIB) you are required to comply with the newly finalized CMMC requirements. 


  • June 25 – Cybersecurity Requirements for Non-Department of War Contractors and Suppliers
  • July 16 – A Guide to Strong Supporting Documentation
  • August 27 – Determining Your Real CMMC Compliance Responsibilities


Registration and more information can be found at wispro.org/wpi-events/featured-webinars

  • Be sure to follow WPI on social media (Facebook, LinkedIn, X) for regular updates on events, news and opportunities.
WPI 10437 Innovation Dr. Suite 320, Milwaukee, WI 53226 414-270-3600
Newsletter Editor: Doug Clemons, dougc@wispro.org 
Facebook  Linkedin  X

Not currently a subscriber to WPI's Newsletters?

Click Here to Subscribe