🔧 AI Nachrichten Even the King of England has his hesitations about AI(17.09.2026 um 19:26 Uhr)
📰 IT Security Nachrichten[Virtual Event] Cybersecurity Outlook 2027(03.12.2026 um 17:00 Uhr)
⚠️ Malware / Trojaner / VirenBrevo supply-chain attack injected ClickFix scripts on customer sites(17.09.2026 um 19:11 Uhr)
📰 IT Security NachrichtenRabattprogramm "PayPal+" startet: Wie viel sparen Kunden tatsächlich?(17.09.2026 um 19:26 Uhr)
📰 IT Security NachrichtenpearOS is the MacOS of Linux, and the latest version is better than ever(17.09.2026 um 19:30 Uhr)
📰 IT NachrichtenWill Apple enter the server business?(17.09.2026 um 16:09 Uhr)
🔧 AI Nachrichten Even the King of England has his hesitations about AI(17.09.2026 um 19:26 Uhr)
📰 IT Security Nachrichten[Virtual Event] Cybersecurity Outlook 2027(03.12.2026 um 17:00 Uhr)
⚠️ Malware / Trojaner / VirenBrevo supply-chain attack injected ClickFix scripts on customer sites(17.09.2026 um 19:11 Uhr)
📰 IT Security NachrichtenRabattprogramm "PayPal+" startet: Wie viel sparen Kunden tatsächlich?(17.09.2026 um 19:26 Uhr)
📰 IT Security NachrichtenpearOS is the MacOS of Linux, and the latest version is better than ever(17.09.2026 um 19:30 Uhr)
📰 IT NachrichtenWill Apple enter the server business?(17.09.2026 um 16:09 Uhr)
🎥 IT Security Video 🕛 vor 1 Monat 4 Min Lesezeit SECURITY-FEED
0

AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468

↗ Quelle (YouTube)
🗣️ Stimme:
📺
YouTube

Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0

Interview with Keith Hollender, CEO and Co-Founder of Arcova



Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem



As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.



In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.



Keith also shares how Arcova’s practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova’s continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.



Segment Resources:

- https://arcova.com/sectors/

- https://arcova.com/category/blog/



For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova



Topic: CMMC Pause creating chaos among federal contractors



This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide.

The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.



I think Howard Holton nails it here when he says:



"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."



PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.



What this means:



- Phase II is paused

- Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)

- NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required

- 60-day review aims to reform CMMC

- DoW opened an RFI for industry perspectives on what they should do

- CMMC characterized as a "compliance burden" and "red tape"

- False Claims Act and DOJ's cyber-fraud enforcement are still on the table



More resources:



- CIO Davies' post on Twitter

- Administrator of the Small Business Administration, Kelly Loeffler's post

- A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)



Weekly Enterprise News



Finally, in the enterprise security news,



1. will AI eliminate more cybersecurity jobs than it creates?

2. Linus’s law, amended

3. the biggest patch Tuesday ever

4. AI context bombs

5. AI workflows are a security disaster

6. people using AI in areas they don’t understand

7. ransomware crews are hitting legal firms hard

8. lessons learned from CISA’s recent github leak

9. demystify your USB cables!



All that and more, on this episode of Enterprise Security Weekly.



Visit https://www.securityweekly.com/esw for all the latest episodes!



Show Notes: https://securityweekly.com/esw-468

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Microsoft turned Windows 11’s lock screen into MSN hell, now it’s undoing most of it
1 Quelle
Web apps are freezing in Microsoft Edge, and the fix is a real hassle
1 Quelle
Bitwarden 2026.9 Server Archiv - Deskmodder.de
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468

Thematisch verwandte Begriffe: Security, Scale, CMMC, phase · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...