Today's Focus: Cybersecurity, Data Security & Cloud Security — Monday, 20 July 2026
CISA is responding to active exploitation of on-premises Microsoft SharePoint Server: a 14 July hardening alert was followed by Known Exploited Vulnerabilities catalog additions on 14 July (CVE-2026-56164) and 16 July (CVE-2026-58644, exploited as a zero-day before the 14 July patches). KEV listing starts remediation clocks for federal civilian agencies under Binding Operational Directive 26-04 — and the reported 17 and 19 July deadlines have now passed. Attackers are stealing IIS machine keys for persistence, so patching alone doesn't end the incident. All supported versions (Subscription Edition, 2019, 2016) are affected. CISA alert, 14 Jul 2026
On the Calendar This Week
27 Jul — Federal Secure Cloud Advisory Committee holds its first public-facing meeting of 2026 (7 days).
28 Jul — FedRAMP Ready designation retires; submit or convert before the cut-off (8 days).
1 Aug — California Delete Act: DROP deletion-processing duty binds registered data brokers (12 days).
2 Aug — Comments close on China's rewritten Internet Information Service Administrative Measures (13 days).
3 Aug — FedRAMP 20x Class A pipeline opens (14 days).
Also Today
China rewrites its foundational internet measures. The CAC's second-round draft (6 chapters, 94 articles) adds real-name verification, 6-month log retention, and AI-agent security duties, with fines up to RMB 10M. China-exposed providers: assess and comment by 2 August. CAC notice
FedRAMP Marketplace now shows your remediation status to everyone. Since 17 July, listings carry a "Certified (In Remediation)" status, a Corrective Action Plan indicator, and a Certification History log. Review your listing and brief sales teams — remediation posture is now competitive intelligence. FedRAMP changelog
CMMC review is under way. The Pentagon's review team first met 16 July; RFI responses are due 14 August and the report is expected late September. Keep NIST SP 800-171 self-assessments current — False Claims Act exposure continues through the Phase II suspension. CMMC RFI on SAM.gov
Deadline Alert
China's Internet Information Service Measures consultation closes 2 August (13 days) — the one comment window in this domain closing within two weeks.
One Thing to Do Today
Patch all on-premises SharePoint now, then rotate IIS machine keys and hunt for persistence predating the patch — key theft survives patching.
Related briefings: EU critical-entity designations due Friday · Korea's platform-content law takes effect tomorrow
Tomorrow's Focus: Privacy & personal data protection.
CyberEyeQ — Actionable Regulatory Intelligence · [email protected]
