• Forging Trust
  • Posts
  • CMMC Phase II: What Happens Next? + GTIA Trustmark

CMMC Phase II: What Happens Next? + GTIA Trustmark

IT channel and business news with a focus on regulatory compliance.

🛑 Pentagon Pulls the Brake on CMMC Phase 2: What MSPs Need to Know Right Now

CMMC Phase 2's C3PAO audit requirement is suspended for 60 days pending a task force review. The task force will report in mid-September 2026, after which requirements will be reinstated, restructured, delayed further, or formally amended through rulemaking. Full repeal is not legally simple and is not what officials are signaling.

In the meantime: NIST SP 800-171 is enforced. DFARS 252.204-7012 is enforced. Annual affirmations are legally binding personal attestations. The False Claims Act applies to every SPRS score your clients have submitted. And MSPs — the providers with the most access to CUI environments — remain the most under-regulated entities in the entire DIB compliance ecosystem…

🎙️ Podcast: Where MSP Responsibility Actually Starts in PCI Compliance

Using Stripe, Square, Shopify, or a hosted checkout can shrink your PCI scope, but it does not make PCI disappear. This episode of Get NIST-y gets into where MSP responsibility actually starts, where it should stop, and why payment page scripts are not “just a marketing thing.”

⚒️ Blacksmith and the GTIA Trustmark

Managed service providers and solution providers need practical ways to turn cybersecurity standards into repeatable operational workflows. Blacksmith’s new support for the GTIA Cybersecurity Trustmark framework is built to do exactly that, giving partners a more streamlined path to manage, operationalize, and demonstrate progress toward the Trustmark inside the Blacksmith platform…

⚠️ Threat Updates

đź”´ LabubaRAT Disguises Itself as an NVIDIA Driver to Establish Persistent Remote Access (7/14/26)

A previously undocumented Rust-based remote access trojan (RAT) named LabubaRAT is masquerading as NVIDIA's container runtime toolkit — dropping onto systems as nvidia-sysruntime.exe — to blend into environments where NVIDIA drivers are expected and trusted . Discovered by Blackpoint Cyber, the implant is architecturally sophisticated: rather than hard-coding its command-and-control (C2) server, it accepts runtime configuration via command-line arguments or a single Base64-encoded parameter, allowing the same compiled binary to be reused across completely different infrastructure, organizations, and campaigns without recompilation. MSPs should block execution of any unsigned binary with NVIDIA branding from non-standard paths, alert on nvidia-sysruntime.exe process creation outside of C:\Program Files\NVIDIA Corporation\, watch for new SQLite database files in unexpected user directories (where LabubaRAT stores its configuration), and treat any outbound DNS or HTTPS traffic to pipicka[.]xyz as a confirmed indicator of compromise. » More Info

đź”´ SeasonalInvite Campaign Abuses Fake eCards to Install RMM Tools on Windows and macOS (7/15/26)

A six-month phishing campaign tracked as SeasonalInvite by Forescout Research has been deploying legitimate Remote Monitoring and Management (RMM) tools as persistent backdoors since at least January 2026, using rotating seasonal lures — tax notices, Valentine's cards, Easter invites, spring RSVPs — to trick users into double-clicking what appear to be greeting card downloads. The campaign is notable for its scale (959 phishing domains, 2,658 traffic distribution gate pages), its cross-platform reach (Windows and macOS), and its confirmed abuse of four RMM tools MSPs know well: ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr. MSPs should immediately audit RMM tenant enrollments for unsanctioned relay domains, block installations of any approved RMM tool from user-writable paths (Downloads, Temp), alert on browser-to-interpreter-to-installer-to-RMM process chains, and train users that legitimate eCards and event invitations will never require approving a UAC prompt or installing remote access software. » More Info

🗨️ Parting Words

“Do what you can, with what you have, where you are." — Theodore Roosevelt 

Find the Blacksmith Team…

…on demand with 
Get NIST-y on Spotify!

Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!