Cyber Security Intelligence Dashboard

EDS Threat Intel · Hardening Playbooks · Incident Simulations

Subscribe to the EDS Intelligence Drop

Weekly threat briefs, hardening playbooks, and incident response scenarios — delivered to your inbox every Monday.

Topics:
Filter:

The Brief

Threat Intel & Compliance Feed

6 items
MEDIUMadvisory

NIST CSF 2.0 Updates: New Govern Function and Compliance Roadmap

NIST Cybersecurity Framework 2.0 introduces the Govern function, emphasizing risk management strategy, roles, and policy. Organizations should align existing programs to the updated structure.

Impact: Organizations using NIST CSF for compliance and risk programs must update mappings and incorporate governance practices.

CRITICALCVE-2026-3104cve

CVE-2026-3104: Critical RCE in Pulse Secure VPN Appliances

Unauthenticated remote code execution vulnerability in Pulse Connect Secure allows attackers to execute arbitrary commands via crafted HTTP requests to the admin interface.

Impact: All unpatched Pulse Secure VPN gateways exposed to the internet. Full system compromise, credential theft, and network pivoting possible.

LOWhsoc update

SOC Optimization: Reducing MTTD with Automated Triage Playbooks

EDS SOC has deployed automated triage playbooks for top 10 alert types, reducing mean time to detect from 47 minutes to under 4 minutes for high-fidelity alerts.

Impact: MDR clients benefit from faster response times and reduced alert fatigue for security teams.

MEDIUMttp

New MDR Detection Coverage: Living-off-the-Land Techniques

EDS MDR has expanded detection coverage for LOLBin abuse — PowerShell, WMI, certutil, and mshta used by ransomware operators for execution and persistence.

Impact: Clients on EDS MDR now have enhanced visibility into fileless malware techniques that evade traditional signature-based AV.

HIGHadvisory

CMMC 2.0 Final Rule: What Defense Contractors Must Prepare by Q4

The CMMC 2.0 final rule is now in effect. Level 1 self-assessments are mandatory, and Levels 2-3 require third-party assessment. Defense contractors must map current controls to NIST SP 800-171 Rev 3.

Impact: All DoD contractors handling CUI must achieve required CMMC level to retain contract eligibility. Non-compliance risks contract loss and debarment.

CRITICALthreat actor

Active Threat Actor Campaign: Supply Chain Attacks on Defense Subcontractors

APT group tracked as "SilentForge" is targeting Tier 3-4 defense subcontractors via compromised software update mechanisms. At least 8 confirmed breaches in the last 30 days.

Impact: Defense industrial base suppliers with immature supply chain security programs. Attackers gain persistent access via trusted update channels.

The Blueprint

Technical Hardening Guide

0/6

Enable Windows Defender Cloud Protection

Activate cloud-delivered protection and automatic sample submission for real-time threat intelligence.

PowerShell
Set-MpPreference -CloudDeliveryEnabled $true
Set-MpPreference -SubmitSamplesConsent SendSafeSamples
Set-MpPreference -MAPSReporting Advanced

Disable SMBv1 Protocol

SMBv1 is legacy and vulnerable to EternalBlue-class attacks. Disable it across all endpoints.

PowerShell
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force

Enable Advanced Audit Logging

Turn on process creation, logon, and object access auditing for forensic visibility.

PowerShell
auditpol /set /subcategory:"Process Creation" /success:enable
auditpol /set /subcategory:"Logon" /success:enable /failure:enable
auditpol /set /subcategory:"Logoff" /success:enable

Block Lateral Movement Ports

Restrict RDP and WinRM to admin subnets only via Windows Firewall.

PowerShell
New-NetFirewallRule -DisplayName "Block RDP Public" -Direction Inbound -RemoteAddress any -Protocol TCP -LocalPort 3389 -Action Block -Profile Public
New-NetFirewallRule -DisplayName "Block WinRM Public" -Direction Inbound -RemoteAddress any -Protocol TCP -LocalPort 5985 -Action Block -Profile Public

Enforce MFA for All Admin Accounts

Require multi-factor authentication for every privileged account. No exceptions for service accounts.

Verify Patch Baseline

Audit all endpoints for missing critical security updates from the last Patch Tuesday cycle.

PowerShell
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10 HotFixID, Description, InstalledOn

The Dojo

Incident Response Simulation

SCORE0/3
What Would You Do?Scenario 1 of 3

Ransomware Detected on Workstation

Your EDR alerts on a finance department workstation showing mass file encryption activity. The user reports their desktop wallpaper changed to a ransom note. What is your immediate action?

The Shield

Workforce Development & Veteran Transition

Mission Readiness

EDS bridges the gap between military service and civilian cybersecurity careers. Through our Cyber Dojo Academy and HSOC partnership, we provide veterans with the training, certifications, and real-world mission experience needed to defend the digital frontier.

150+
Veterans Trained
12
Partner Orgs
85%
Placement Rate