BARR Advisory Senior Consultant Kevin Lewis has picked out five security and compliance headlines from the past month that you need to know. Take a look to find out what our consulting team has been reading this July—plus, scroll to see Kevin’s CISO Pick of the Month to find out where the BARR team is headed next month. ✈️
The Department of War announced that it is suspending plans to transition to CMMC Phase II requirements, which were originally scheduled to take effect on Nov. 10, 2026, while they launch a 60-day study into the future of the CMMC program. Don’t let your guard down just yet—defense contractors remain contractually obligated to protect federal data under DFARS clause 252.204-7012. Phase I self-assessment requirements also remain firmly in place.
Read more ➡️
CISA is warning administrators to immediately patch three actively exploited security flaws impacting all supported self-hosted SharePoint Server versions. Attackers are leveraging these vulnerabilities to bypass authentication, execute remote code, and deploy malware, with hundreds of exposed servers currently remaining unpatched. Federal agencies face a strict July 17 deadline to secure affected servers, and all organizations should prioritize Microsoft’s latest patches and restrict external access to SharePoint Central Administration.
Read more ➡️
IT services giant Accenture has confirmed a security breach after a threat actor known as “888” began offering 35 GB of allegedly stolen corporate data for sale on a cybercrime forum. Accenture asserts the issue is isolated and remediated with no operational impact. The breach serves as yet another security headache for the company, which previously faced a 2021 LockBit ransomware attack and a 2024 third-party leak by this same threat actor.
Read more ➡️
Apple has filed a lawsuit against OpenAI, alleging a former engineer exploited a zero-day authentication bug to steal confidential files shortly after transitioning to the AI company. According to the complaint, the engineer utilized an unreturned work laptop and the network access of an acquaintance to siphon proprietary specifications and unreleased product data. Upon discovering the vulnerability, the employee reportedly messaged a colleague, “LOL, I found out I can access the [network storage], so funny.” Apple has since patched the flaw.
Read more ➡️
Microsoft just released its largest Patch Tuesday ever, fixing more than 200 vulnerabilities driven by a surge in AI-assisted discovery. This massive release includes an actively exploited Microsoft Defender bug and a critical, “wormable” core Windows flaw. Security teams should move quickly to make these updates.
Read more ➡️
Connect with BARR at Black Hat 🎩
Members of the BARR Advisory team will be at Black Hat in Las Vegas on August 5-6! Will we see you there? 👀
We’d love to learn about where your cybersecurity and compliance program is headed and share some quick tips and insights. Book time now so we don’t miss the chance to connect with you!
Want to get these insights straight to your inbox? Subscribe to Take5, our monthly newsletter featuring top security and compliance headlines, events, and resources—brought to you by CISOs from BARR’s cybersecurity consulting team.