CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse
CISA and NIST published NIST IR 8587, final guidance for protecting identity tokens from forgery, theft, replay, and signing-key compromise.
NIST Interagency Report 8587 (September 15, 2026) expands the IA-13 'Identity Providers and Authorization Servers' control from NIST SP 800-53 R5.1.1, guiding federal agencies and cloud providers on SSO, identity federation, and machine-to-machine authentication. It requires hardware-backed signing-key storage for moderate-impact systems, 90-day key rotation for high-impact systems, token lifetimes under one hour, and sender-constrained mechanisms such as mutual TLS and DPoP. The report cites incidents including forged SAML assertions that exposed over 60,000 emails from a federal agency. It also extends guidance to agentic AI systems using signed tokens and urges post-quantum cryptography migration planning.
Post-quantum cryptography adoption and the national security implications
Opinion analysis argues quantum computing favors nation-state espionage, leaving lagging post-quantum adoption at critical infrastructure exposed to harvest-now-decrypt-later attacks.
A CSO Online opinion piece argues that the extreme cost and infrastructure requirements of quantum computers will concentrate cryptographically relevant quantum capability among nation-states and a few corporations, favoring espionage and economic espionage over criminal monetization. It highlights harvest-now-decrypt-later risk to long-lived secrets, expert warnings such as Filippo Valsorda's, and diverging CRQC timelines with Google suggesting possibly 2029. The piece predicts governments, banks, and targeted sectors will adopt PQC first while utilities, small hospitals, and local government lag, widening exploitable gaps in critical infrastructure reminiscent of Salt Typhoon-style access.
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.
Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.
CMMC Hit Pause, the FAR Council Hit Play
DoD paused CMMC Phase 2 pending a 60-day review while a proposed FAR Council rule would extend NIST 800-171 Rev 3 to all federal contractors.
The Department of Defense suspended CMMC Phase 2 third-party certification requirements, but Phase 1 self-assessments under DFARS 252.204-7021 remain in force since November 2025, and prime contractors are still directing suppliers to proceed. A CMMC Reform Task Force must report recommendations to the DoD CIO within 60 days, likely by September or October 2026. Separately, the FAR Council's proposed CUI rule from June 23 would apply NIST 800-171 Revision 3, 72-hour incident reporting, and flowdown obligations to all FAR-based federal contracts, not just the defense industrial base. False Claims Act exposure grows as DIBCAC assessment teams now cooperate directly with the DOJ.