Cybersecurity firm Forrester recently issued its annual report, Top Cybersecurity Threats in 2026, which outlines “the most critical risks organizations need to plan for.”

The report predicts the top threats that organizations will face in 2026 based on recent trends and observations. The top five threats expected in 2026 include:

  1. Near autonomous attacks from a nation-state.
  2. Concerns over agent threats.
  3. Non-negotiable AI software supply chain.
  4. Provenance and IAM risks of AI agents.
  5. Digital sovereignty spans regions and tech stacks.

The threats listed above stem from the widespread accessibility of AI models and the ability for AI tools and AI agents to ingest vast amounts of data, learn from it, and operate at unprecedented speed and scale. These capabilities enable the automation and expansion of increasingly sophisticated cybersecurity attacks, the use of shadow AI beyond an organization’s governance and visibility, and heightened supply chain risks. Together, these challenges create significant compliance concerns, reduce organizational control, and increase overall cybersecurity exposure.

The report outlines the most significant risks organizations face in 2026,  including the growing challenges posed by AI, and underscores the importance of implementing a robust AI governance program as a critical strategic priority

On September 10, 2025, the U.S. Department of Defense (DoD) issued the CMMC Procurement Rule, which made cybersecurity compliance a condition of doing business with that agency by requiring contractors and subcontractors to meet specified security standards before accessing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). We previously covered the CMMC Procurement Rule and its requirements in detail here.

Less than a year later, on July 13, 2026, the DoD issued guidance pausing the next scheduled step in the CMMC rollout, which had been expected in November 2026 and would have expanded the use of more formal third-party and government-led assessments. The DoD’s memorandum ties the pause to DoD’s broader effort to reduce acquisition process, speed delivery of new capabilities, and avoid placing unnecessary burdens on small and non-traditional businesses in the Defense Industrial Base.

Contractors should understand that the CMMC Phase 2 suspension changes the assessment process, not the underlying cybersecurity obligations. In addition, the “Phase 2” pause should not be confused with CMMC Levels 1 and 2. The phases refer to the DoD’s rollout schedule, while the levels refer to the type and sensitivity of information a contractor handles and the corresponding cybersecurity requirements. During the suspension, program managers and requiring activities may include only CMMC Level 1 self-assessments or CMMC Level 2 self-assessments in procurement documents. They may not require Level 2 third-party assessments by a C3PAO or Level 3 assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) during this period.

Even so, the DoD stated that DFARS 252.204-7012 remains in effect, and that baseline compliance with NIST SP 800-171 Rev. 2 will continue to be enforced through self-assessments and select government-led assessments. That means federal contractors still need to be able to show that they are protecting federal information properly. Level 1 applies to FCI, such as non-public information provided by or generated for the government under a contract, and is tied to FAR 52.204-21, which sets basic safeguarding requirements for contractor information systems, such as limiting system access to authorized users, controlling physical access to systems, and using basic protections against malicious code. Level 2 applies where CUI is involved, such as technical drawings, specifications, or other sensitive government information that requires safeguarding, and remains aligned with NIST SP 800-171 Rev. 2, a more detailed set of security controls for protecting that information, including requirements for access control, incident response, system monitoring, and security assessment.

The guidance also affects live procurements. If a solicitation or requirements package included a Level 2 C3PAO or Level 3 DIBCAC requirement, DoD personnel must initiate amendments, and contracting officers or agreements officers must issue corresponding solicitation amendments “as soon as practicable.” Existing contracts or agreements containing those requirements are also to be modified.

Federal contractors should monitor solicitations, amendments, and contract modifications closely, but they should not pause cybersecurity work. The DoD’s Chief Information Officer is conducting a 60-day review of CMMC to ensure the Defense Industrial Base remains secure without imposing significant burdens on small and non-traditional businesses. Until the DoD issues further guidance after that review, contractors should keep policies, system security plans, plans of action, and self-assessment records current and supportable.  

California’s privacy regulator has launched its first-ever audit, signaling a new phase of active oversight under the California Consumer Privacy Act (CCPA) and its amendments. The California Privacy Protection Agency (CPPA) is focusing on delivery and transportation apps in the gig economy, examining how platforms collect and use personal information from both consumers and workers, and how individuals can exercise rights to know what data is collected, how it is used, and with whom it is shared.

The agency’s choice of sector is notable. Gig economy platforms (i.e., food delivery and transportation apps) often rely on highly sensitive and operationally important data, including geolocation data, behavioral and performance metrics, biometric data, communications records, and other information that may be used to make decisions about assignments, ratings, compensation, and account status. According to the CPPA, hundreds of consumer complaints and public comments during rulemaking in part prompted the audit by with officials noting particular concern about the rapid evolution of employee monitoring technologies and AI-enabled data practices.

As part of the audit, the CPPA plans to review platform policies and practices, request documentation and data, interview company personnel, and directly test app processes. The agency‘s inquiries will be narrowly focused and it plans to publish an industry compliance report similar to the Federal Trade Commission’s Rule 6(b) market studies. For companies operating in or adjacent to the gig economy, the audit is a reminder to pressure-test privacy notices, rights-request workflows, data sharing disclosures, employee and contractor privacy practices, retention schedules, and governance around sensitive data and automated decision-making before regulators come knocking.

California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request appears, delete the consumer’s personal information within 45 days and direct applicable service providers and contractors to do the same. Once the information is deleted, the data broker generally may not sell or share new personal information about that consumer unless the consumer indicates otherwise.

Companies that collect, buy, sell, or share Californians’ personal information should carefully evaluate whether they fall under California’s broad definition of a “data broker.” In general, a data broker is a business that knowingly collects and sells personal information to third parties about consumers with whom tit does not have a direct relationship. This can include businesses outside California, and the analysis may be more complicated for companies using third-party tracking technologies, purchasing personal information from others, or selling data collected indirectly. Data brokers also must register annually with the California Privacy Protection Agency between January 1 and January 31 and provide detailed disclosures, including categories of personal information collected and whether personal information is sold or shared with certain recipients, such as generative AI developers.

The penalties are significant: failures to register can trigger $200-per-day penalties, and failures to honor deletion requests can result in $200 per deletion request for each day the information is not deleted. Companies that may fall under California’s definition of a “data broker” should prepare now by confirming whether registration is required, mapping California personal information flows, identifying vendors and contractors that may need deletion instructions, and building a documented process to check DROP at least every 45 days. Even companies that do not intend to collect information from California consumers should revisit their data sources and screening practices, as the CPPA has already shown interest in out-of-state businesses that handle Californians’ personal information.

A new study by the AI Security Institute (AISI), Cheating Behaviour in Frontier Model Evaluation, found “cheating behaviour in all of our capability evaluations,” and outlines “the implications as models grow more capable.”

AISI defined “cheating” as “taking an action that is out of scope for the task or explicitly disallowed by the rules, in order to achieve a goal through a shortcut, workaround, or unintended solution that the task was not meant to, or should not, permit.” Sounds like cheating to me.

AISI found that “every model” it tested “attempted to cheat.” Even when called out on it, the models “did not reliably report this behaviour when asked, and often did not reason about it in their chain-of-thoughts, suggesting that detecting cheating will likely require robust monitoring methods.” That said, AISI notes that based on its review, to the best of its knowledge, “no model has successfully cheated (i.e. not been caught) in the results we report.”

To test the models, AISI tasked the models with evaluating cybersecurity capabilities, with specific, controlled and defined scope and tasks. It found that every model tested “cheated,” going “outside the scope or takes an action that the rules explicitly prohibit.” Importantly, the models were not asked to cheat or go outside the tasks and scope—they did so on their own.

When AISI asked the models if they went outside the scope or tasks, they only acknowledged the behavior and “described it as wrong” less than 50% of the time. AISI concludes that asking a model if it is cheating or going beyond the tasks assigned is not an effective way to monitor output. It also found that cheating is not in a model’s chain-of-thought reasoning, and therefore, this too, is an “insufficient method” for detecting cheating.

Why do we care if a model is cheating? The most obvious one is that if models go beyond specified tasks and scope, cheating can be “especially dangerous in domains where verifying success is hard, such as AI safety and security research, or where the cost of unintended actions may be very high, such as cyber operations or military decision-making.” It can also affect the efficiency of the use of the AI models if additional verification is needed. Finally, as models become more capable, their cheating behavior may become harder to detect and “more damaging when successful.”

AISI posits that models should not be trusted when they self-declare that they are not cheating. They suggest that users monitor and detect cheating by “combining manual review with additional tools such as the LLM monitor.” As models become more capable, “a more fundamental fix would be to train the models not to cheat in the first place.” Those developing AI models should take this recommendation to heart now, before AI models train themselves to evade cheating behavior detection. Train AI models not to cheat now, during development, so the problem does not become worse.

Major League Baseball’s (MLB) move to restrict dugout iPad functionality is a reminder that AI governance is showing up everywhere, including in the middle of professional baseball games. According to reports, MLB disabled custom tablet tabs after concerns that teams were using AI-powered tools to support real-time decisions on substitutions, pitch calling, and other in-game strategy. The league’s concern appears less about technology generally, and more about preserving the line between permitted data access and automated strategic recommendations during live competition.

That line matters. Sports have always evolved with analytics, video, scouting systems, and performance data, but AI changes the speed, scale, and nature of decision support. A tool that helps a team review video before a game feels very different from one that recommends the next pitch in real time. Once AI starts influencing live decisions, leagues must answer harder questions: What tools are fair? What level of automation is acceptable? Who is accountable for the decision? And how can rules keep pace when technology moves faster than the rulebook?

The takeaway extends well beyond baseball. Organizations adopting AI need clear use-case boundaries, not just broad permission to “use technology.” MLB’s crackdown shows why governance must be specific: what the system can access, when it can be used, who can rely on it, and which decisions must remain human-led. Whether the setting is a dugout, a trading desk, a hospital, or a hiring situation, the same principle applies: AI may be powerful, but without thoughtful guardrails, it can quickly move from helpful tool to rule-changing force.

It’s hard to believe that today’s post marks the publication of our 500th Privacy Tip. What a milestone!

We started publishing Tips because readers kept asking me about ways to protect themselves from scams, how to keep up with the latest threats, and how to stay informed about emerging technology. Feedback has been overwhelmingly positive, so we will continue publishing the Tips and helping readers navigate the technology landscape—an environment that often feels like the Wild West, with new developments emerging every day.

To commemorate the 500th Privacy Tip, I thought it apropos to recap the top ways to protect your privacy from a cybersecurity perspective.

  1. Update your devices with patches as soon as you get the notice from the manufacturer. Patching is necessary to protect your device from vulnerabilities.
  2. Maintain strong passphrases and change them often.
  3. Use multi-factor authentication on all your online accounts but beware of multifactor authentication fatigue.
  4. Limit use of public Wi-Fi networks and use virtual private networks whenever possible.
  5. Obtain your free credit report frequently to catch any fraudulently opened accounts .
  6. Properly dispose of all electronic devices, including SIM cards.
  7. Beware of imposter scams.
  8. Strengthen children’s privacy.
  9. Don’t give personal information to a generative AI tool.
  10. Beware of, and protect yourself from, threat actors using AI in attacks.

We hope these Tips continue to educate and provide practical solutions for navigating the rapidly evolving risk landscape that technology and AI create in our lives. To dive deeper into putting these Tips to work, check out this guide. We look forward to to providing another 500 practical tips on how to stay safe.

A joint cybersecurity advisory from the United States and 12 allied nations was released this week warning critical infrastructure operators that Russian state-sponsored hackers from Federal Security Service (FSB) Center 16 are actively exploiting poorly configured and vulnerable networking devices to break into systems.

The threat group, also known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, has been scanning the internet for routers with default or weak passwords, or unpatched old Cisco vulnerabilities.

The agencies “strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers.”

The industries that have been targeted include: “communications, defense industrial base, energy, financial services, government services and facilities, especially organizations at the state and local level, and healthcare and public health.” The advisory provides details of techniques used, and mitigation actions to deploy. Tracking these techniques and applying the mitigation actions should be a priority for critical infrastructure organizations.

Last week, we wrote about the newly enacted New Jersey data broker law. On July 10, 2026, the New Jersey Attorney General’s Division of Consumer Affairs published an alert clarifying that covered data brokers and data collectors will not need to register or pay registration fees until the Division launches the required public registry, which is expected in spring 2027. The first registration period is anticipated to run from April 1, 2027, through June 30, 2027, with additional guidance to come before then. The alert also notes that the Division plans to issue further guidance on other aspects of the law, including its restrictions on the sale or licensing of sensitive data.

Although some enforcement activity may be delayed while the registry and guidance are developed, businesses that collect, sell, license, or otherwise handle New Jersey consumer data should consider using this period to assess whether the law applies and what compliance steps may be needed.

On July 8, 2026, the Federal Communications Commission (FCC) Enforcement Bureau entered into a consent decree with Voximplant, Inc., a voice and video call platform, to resolve an investigation into whether the company failed to comply with the FCC’s robocall mitigation rules. The FCC’s robocall mitigation framework is designed to make the voice calling ecosystem more transparent and help law enforcement identify and stop illegal robocall traffic more efficiently.

A central part of that framework is the Robocall Mitigation Database (RMD), where covered voice service providers must file certifications and robocall mitigation plans describing how they address illegal robocall traffic, such as spoofed and spam calls. The FCC’s rules also require providers to submit information about their business identity, responsible contacts, role in the call chain, caller ID authentication practices, enforcement history, and commitment to respond within 24 hours to traceback requests seeking to identify the source and path of suspected illegal calls.

Under the consent decree, Voximplant admitted that its RMD certification was noncompliant and agreed to implement a compliance plan. The FCC found that Voximplant had not updated its RMD certification and robocall mitigation plan after amended requirements took effect. The consent decree also notes that, after Voximplant was removed from the RMD, it was identified in 20 tracebacks as the originating provider for suspected illegal robocalls. For the FCC, the issue was not only that Voximplant’s RMD filing was deficient, but that the suspected illegal robocall traffic was being traced back to Voximplant’s network, and the missing RMD information concerned the safeguards providers must document to show how they prevent that kind of traffic.

The consent decree requires Voximplant to operationalize robocall compliance through a senior compliance officer, written procedures, employee training, periodic reporting, and prompt updates to its RMD certification. It also requires 24-hour traceback responses and enhanced diligence on customers and upstream providers, including verifying customer identity and confirming that upstream providers have active RMD certifications. These obligations underscore that providers should treat robocall mitigation as an ongoing compliance function.

The FCC’s consent decree came one day after 49 State Attorneys General urged the FCC to tighten oversight of the numbering practices that help bad actors disguise illegal robocalls. Their concern was that, as caller ID protections have made basic spoofing harder, scammers have adapted by using real or easily obtained phone numbers to make fraudulent calls look legitimate. The Attorneys General supported stronger certification, reporting, tracing, and diligence requirements for companies that obtain, assign, or resell numbers, with a particular focus on practices that let callers rotate through numbers or use trial numbers to evade detection.

Together, the FCC consent decree and the Attorneys General letter point to a broader enforcement shift: regulators are scrutinizing not only what providers certify, but how they police the traffic moving through their networks. For voice providers, robocall compliance now turns on whether they can show active controls, including accurate filings, documented mitigation practices, prompt traceback responses, and diligence on customers and counterparties. When illegal traffic starts ringing alarms, regulators expect providers to pick up.