Share this emailCopy the public link or share it on your favorite channel.
Weekly News Context August 7
Here's everything important that happened in the cybers this week, complete with a cat in a black hat!

Nobody at USDA Asked About the Firewall

Nobody at USDA Asked About the Firewall
Archer Daniels Midland is mostly out of the False Claims Act woods, and the story of how it got there is the most useful ruling on cyber-FCA enforcement in years. Nobody sued. Nobody settled. The relator, Mark Pannek, lost on paper, in a memorandum and order from Judge Sanjay Harjani of the Northern District of Illinois dated September 2, 2026, …

Blog

Read more

The CMMC Pause Isn't a Holiday

The CMMC Pause Isn't a Holiday
This week, two things happened involving the same federal document. On September 9, Washington Technology reported that the Cybersecurity Maturity Model Certification (CMMC) Phase 2 suspension had been "locked in with binding regulation," a step change from a mere pause that would make reversal harder. The same week, the analysts at RedSpin compared the new document line by line against …

Blog

Read more

Four Years, Fourteen Lawsuits, $136 Million in Revenue: what OneTouchPoint's ransomware bill actually added up to

Four Years, Fourteen Lawsuits, $136 Million in Revenue: what OneTouchPoint's ransomware bill actually added up to
On November 18, 2026, a Wisconsin state judge in Waukesha County will convene a final approval hearing for a class action settlement arising from a ransomware attack that began on April 27, 2022. Four years, six months, and a courtroom transfer separate the two dates, along with fourteen lawsuits, three failed mediations, a partially successful motion to dismiss, and one …

Blog

Read more

The EU CRA Reporting Deadline Is Friday. Here's What US Manufacturers Actually Need to Do.

The EU CRA Reporting Deadline Is Friday. Here's What US Manufacturers Actually Need to Do.
If you build software or hardware with digital elements and you sell it into Europe, the EU Cyber Resilience Act (CRA) stops being a someday problem this Friday, September 11. That's when the regulation's reporting obligations start. It's not a registration deadline and not a paperwork deadline. It's the moment the duty to notify regulators kicks in, with a 24-hour …

Blog

Read more

The Ransom Was the Cheap Part

The Ransom Was the Cheap Part
In March 2023, LockBit demanded $10 million from MCNA Dental. Management refused, the attackers published 700 GB of stolen data two days later, and everyone moved on. That refusal tends to get framed as courage in breach retrospectives. It wasn't. It was a capital allocation decision made without anyone pricing the alternatives, and the invoice is now public. Call it …

Blog

Read more

Black Hat/DEF CON 2026

  • If you're still there, safe travels home!
Thanks, and have a great weekend! This newsletter is published every Friday I'm in the office.